Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs GitHub comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Application Security Tools
3rd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
70
Ranking in other categories
Static Application Security Testing (SAST) (3rd), Vulnerability Management (21st), Static Code Analysis (2nd), API Security (3rd), DevSecOps (2nd), Risk-Based Vulnerability Management (8th)
GitHub
Ranking in Application Security Tools
6th
Average Rating
8.8
Reviews Sentiment
7.5
Number of Reviews
93
Ranking in other categories
Version Control (3rd)
 

Mindshare comparison

As of May 2025, in the Application Security Tools category, the mindshare of Checkmarx One is 10.3%, down from 14.8% compared to the previous year. The mindshare of GitHub is 0.8%, down from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
 

Featured Reviews

Rohit Kesharwani - PeerSpot reviewer
Provides good security analysis and security identification within the source code
We integrate Checkmarx into our software development cycle using GitLab's CI/CD pipeline. Checkmark has been the most helpful for us in the development stage. The solution's incremental scanning feature has impacted our development speed. The solution's vulnerability detection is around 80% to 90% accurate. I would recommend Checkmarx to other users because it is one of the good tools for doing security analysis and security identification within the source code. Overall, I rate Checkmarx a nine out of ten.
Pervez Roy - PeerSpot reviewer
Very good for collaboration on software projects
We use GitHub for code repository alongside Bitbucket GitHub is very good for collaboration on software projects. We prefer Bitbucket for commercial use, while GitHub is used for open source. You can get the differences, history of changes, and version control for various pull requests. You can…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The identification of verification-related security vulnerabilities is really important and one of the key things. It also identifies vulnerabilities for any kind of third-party tool coming into the system or any third-party tools that you are using, which is very useful for avoiding random hacking."
"I like that you don't have to compile the code in order to execute static code analysis. So, it's very handy."
"The most valuable feature is the application tracking reporting."
"The only thing I like is that Checkmarx does not need to compile."
"It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc)."
"The reports are very good because they include details on the code level, and make suggestions about how to fix the problems."
"The main benefit to using this solution is that we find vulnerabilities in our software before the development cycle is complete."
"Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
"The tool is valuable because it helps us work in a distributed environment with multiple people across different locations and time zones. We have a common repository that everyone works on, which would be tough to manage manually. GitHub helps us maintain this single source of truth. Everyone can check out their own branches, which is important for our branching strategies. We can fork, check out feature branches, work on our code, and merge back into parent branches for deployment. This is crucial when multiple people are working on the same codebase."
"We've found the technical support to be very helpful."
"The technical support of the solution is good, and our company has used it for GitHub upgrades."
"GitHub is easy, secure, and widely documented."
"The deployment is fast since we just have to run the script, and once it's done, it takes a few minutes."
"GitHub allows us the option to push files from a non-UA method or directly upload files from the UA. You can integrate GitHub with Jenkins to do CI/CD."
"We can make a private repository."
"Complication free with good ability for third-party integrations."
 

Cons

"The statistics module has a function that allows you to show some statistics, but I think it's limited. Maybe it needs more information."
"Checkmarx could improve the solution reports and false positives. The false positives could be reduced. For example, we have alerts that are tagged as vulnerabilities but when you drill down they are not."
"It is an expensive solution."
"The lack of ability to review compiled source code. It would then be able to compete with other scanning tools, such as Veracode."
"I can't create a business case with multiple-factor authentication."
"Checkmarx needs improvement in its Dynamic Application Security Testing (DAST) and API security features."
"The pricing can get a bit expensive, depending on the company's size."
"I think the CxAudit tool has room for improvement. At the beginning you can choose a scan of a project, but in any event the project must be scanned again (wasting time)."
"I faced one or two breakdowns. That said, they lasted only for a few seconds or a minute."
"There is nothing that I find that needs improvement in GitHub."
"The integration with Visual Studio Code could be more streamlined."
"We would like this solution to have a more user-friendly interface."
"The descriptions within Github could be more user-friendly to show the trees of Gitflow."
"GitHub could add more security features. I am not sure how secure it is. If they provide more security features, then it can be used in more official applications."
"I think one area where GitHub could improve is its search and navigation functionality within repositories. For example, we use IDEs like IntelliJ or Visual Studio Code when developing code. These IDEs allow us to easily navigate from one piece of code to another file where a method is being called. It would be really helpful if the solution could add this navigation feature."
"One thing GitHub could do is probably the same thing as what Sourcetree does. When solving merge conflicts, it would be helpful to have tooltips within the actions to know what changes could happen next when resolving a conflict."
 

Pricing and Cost Advice

"We have purchased an annual license to use this solution. The price is reasonable."
"It is an expensive solution."
"It's relatively expensive."
"I believe pricing is better compared to other commercial tools."
"It is a good product but a little overpriced."
"The tool's pricing is fine."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone."
"I haven't had to pay anything for GitHub, I use the free version."
"The tool offers a free program. As you go, you can upgrade from the community version to the professional one. I believe it costs about ten dollars per person, per month."
"We have an enterprise licensing agreement, and I am not part of the finance department so I can't say how much it costs."
"If there are only 10 people using a particular repository, then GitHub is free. But if we increase the number of users, we need to pay the normal charge for GitHub."
"GitHub is an open-source product, but when using the free-to-use version, anyone can see the code we're working on."
"I use the free version of GitHub."
"We are currently paying nothing for GitHub."
"GitHub is a cost-effective solution."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
849,686 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
14%
Manufacturing Company
10%
Government
5%
Financial Services Firm
13%
Manufacturing Company
12%
Computer Software Company
12%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about GitHub?
The control is the most valuable feature as developers can work on a single code.
What is your experience regarding pricing and costs for GitHub?
The pricing of GitHub depends on the choice of solutions, such as building one's own GitHub Runners to save money or using GitHub's Runners with extra costs. The pricing is considered reasonable an...
What needs improvement with GitHub?
There are still areas for improvement with GitHub Actions and their deployment workflows, as they have made significant progress but are not yet polished. Occasionally, stability can be an issue, t...
 

Comparisons

 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Dominion Enterprises, NASA, Braintree, SAP, CyberAgent
Find out what your peers are saying about Checkmarx One vs. GitHub and other solutions. Updated: April 2025.
849,686 professionals have used our research since 2012.