Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs JFrog DevOps Cloud Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 7, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in DevSecOps
5th
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (23rd), Container Security (23rd), Static Code Analysis (3rd), API Security (6th), Dynamic Application Security Testing (DAST) (4th), Risk-Based Vulnerability Management (10th), Application Security Posture Management (ASPM) (3rd)
JFrog DevOps Cloud Platform
Ranking in DevSecOps
12th
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
3
Ranking in other categories
Software Supply Chain Security (16th)
 

Mindshare comparison

As of October 2025, in the DevSecOps category, the mindshare of Checkmarx One is 14.9%, down from 20.1% compared to the previous year. The mindshare of JFrog DevOps Cloud Platform is 1.0%. It is calculated based on PeerSpot user engagement data.
DevSecOps Market Share Distribution
ProductMarket Share (%)
Checkmarx One14.9%
JFrog DevOps Cloud Platform1.0%
Other84.1%
DevSecOps
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Fredierick Saladas - PeerSpot reviewer
Provides superior integration options and comprehensive reporting features
The product could benefit from enhanced integration capabilities with older software systems and more customizable reporting options. Improved support for mobile devices would also be advantageous, allowing team members to access the system more effectively while on the go. In the next release, we would like to see advanced analytics features, including predictive analytics to help forecast project outcomes. Additionally, a more robust mobile app with offline capabilities would be valuable for remote work scenarios.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Apart from software scanning, software composition scanning is valuable."
"It can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security."
"We use the solution for dynamic application testing."
"The solution is scalable, but other solutions are better."
"Our static operation security has been able to identify more security issues since implementing this solution."
"The main benefit to using this solution is that we find vulnerabilities in our software before the development cycle is complete."
"The value you can get out of the speedy production may be worth the price tag."
"The UI is very intuitive and simple to use."
"I appreciate the features in JFrog DevOps Cloud Platform, especially the efficient file management where downloads and uploads are optimized, saving time. The storage efficiency is also great as it avoids redundancy, which is crucial for our team. It is also quite easy to use, especially for basic commands through the command line. It's straightforward for us internally, and our data is well-hosted on their servers, which makes data location and querying fast and efficient. Moving our storage to JFrog has streamlined our development cycle by eliminating duplicated data, which previously took up extra space locally. This efficiency is crucial for our workflow, although network speeds still play a significant role in performance."
"The most valuable features include task tracking and reporting capabilities."
"They have a professional service team that works alongside their engineering and performance teams."
 

Cons

"The statistics module has a function that allows you to show some statistics, but I think it's limited. Maybe it needs more information."
"The tool is currently quite static in terms of finding security vulnerabilities. It would be great if it was more dynamic and we had even more tools at our disposal to keep us safe. It would help if there was more scanning or if the process was more automated."
"I would like to see the tool’s pricing improved."
"The solution's user interface could be improved because it seems outdated."
"One area for improvement in Checkmarx is pricing, as it's more expensive than other products."
"Updating and debugging of queries is not very convenient."
"It would be really helpful if the level of confidence was included, with respect to identified issues."
"We have received some feedback from our customers who are receiving a large number of false positives."
"We have encountered stability issues lately, particularly with frequent 500 internal server errors. Despite efforts from our DevOps team to adjust settings, these issues persist, affecting our workflow, especially with machine learning data uploads. Overall, while it's beneficial for storage and accessibility, stability issues need improvement for seamless operations. The occasional occurrence of internal server errors takes several minutes to resolve on their own and can disrupt workflows. Another concern is that sometimes files appear to be successfully uploaded, but then they cannot be downloaded, with no error message indicating the issue during the upload process. This inconsistency needs to be addressed by JFrog to ensure reliable functionality for users like us."
"The product could benefit from enhanced integration capabilities with older software systems and more customizable reporting options."
"Our locations are in different environments, so the remote server takes time to catch up, causing replication delays. The engineering team suggested that this issue would be resolved, but I'm not sure if it has been addressed yet. This is more of a feature enhancement that we suggested."
 

Pricing and Cost Advice

"Before implementing the product I would evaluate if it is really necessary to scan so many different languages and frameworks. If not, I think there must be a cheaper solution for scanning Java-only applications (which are 90% of our applications)."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"It is an expensive solution."
"I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone."
"The price of Checkmarx could be reduced to match their competitors, it is expensive."
"The license has a vague language around P1 issues and the associated support. Make sure to review these in order to align them with your organizational policies."
"The average deal size was usually anywhere between $120K to $175K on an annual basis, which could be divided across 12 months."
"It is the right price for quality delivery."
"Regarding pricing, I focus on the platform's interface and user communication rather than costs."
"The product pricing is competitive but worth negotiating for volume discounts or longer-term contracts."
report
Use our free recommendation engine to learn which DevSecOps solutions are best for your needs.
869,202 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
13%
Manufacturing Company
10%
Government
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business30
Midsize Enterprise9
Large Enterprise38
No data available
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What needs improvement with JFrog DevOps Cloud Platform?
The product could benefit from enhanced integration capabilities with older software systems and more customizable reporting options. Improved support for mobile devices would also be advantageous,...
What advice do you have for others considering JFrog DevOps Cloud Platform?
Overall, the solution has been a great asset to our team. I advise investing time in the initial setup and training to leverage its capabilities fully. Ensure you clearly understand your needs and ...
What is your experience regarding pricing and costs for JFrog DevOps Cloud Platform?
The product pricing is competitive but worth negotiating for volume discounts or longer-term contracts. Licensing options are flexible, but ensure you understand the terms and any additional costs ...
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Information Not Available
Find out what your peers are saying about Checkmarx One vs. JFrog DevOps Cloud Platform and other solutions. Updated: September 2025.
869,202 professionals have used our research since 2012.