Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs NinjaOne comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Zafran Security
Sponsored
Ranking in Vulnerability Management
16th
Average Rating
9.6
Reviews Sentiment
7.8
Number of Reviews
6
Ranking in other categories
Continuous Threat Exposure Management (CTEM) (1st)
Checkmarx One
Ranking in Vulnerability Management
23rd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Container Security (22nd), Static Code Analysis (3rd), API Security (4th), Dynamic Application Security Testing (DAST) (4th), DevSecOps (4th), Risk-Based Vulnerability Management (9th)
NinjaOne
Ranking in Vulnerability Management
25th
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
18
Ranking in other categories
Network Monitoring Software (32nd), Server Monitoring (8th), IT Service Management (ITSM) (8th), Remote Access (20th), Mobile Device Management (MDM) (6th), IT Alerting and Incident Management (11th), Remote Monitoring and Management (RMM) (2nd), Patch Management (9th), MSP Backup (3rd), Unified Endpoint Management (UEM) (9th)
 

Mindshare comparison

As of August 2025, in the Vulnerability Management category, the mindshare of Zafran Security is 0.9%, up from 0.0% compared to the previous year. The mindshare of Checkmarx One is 0.9%, up from 0.4% compared to the previous year. The mindshare of NinjaOne is 0.7%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management
 

Featured Reviews

Israel Cavazos Landini - PeerSpot reviewer
Weekly insights and risk analysis facilitate informed security decisions
I appreciate the weekly insights Zafran provides, which include critical topics for networks and IT security, allowing us to evaluate which insights apply to our environment. The organization score feature is valuable to keep the leadership team updated on how our infrastructure fares security-wise. The applicable risk level versus base risk level feature is beneficial because prior to Zafran, we only used the base risk level, but now understand that risk depends on the asset itself. Zafran is an excellent tool.
Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Jörg Köhler - PeerSpot reviewer
Enhances remote access and integration with third-party tools
I use NinjaOne for managing smaller clients, specifically their devices and software, for small to medium businesses. I provide remote management services through NinjaOne. It allows clients to use NinjaOne for remote access to their computers for home office purposes. This feature is highly…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Zafran is an excellent tool."
"Zafran has become an indispensable tool in our cybersecurity arsenal."
"We saw benefits from Zafran Security almost immediately after deploying it."
"We are able to see the real risk of a vulnerability on our environment with our security tools."
"Overall, we have seen about eighty-seven percent reduction of the number of vulnerabilities that require urgency to remediate, specifically the number of criticals."
"Helps us check vulnerabilities in our SAP Fiori application."
"From my point of view, it is the best product on the market."
"The features and technologies are very good. The flexibility and the roadmap have also been very good. They're at the forefront of delivering the additional capabilities that are required with cloud delivery, etc. Their ability to deliver what customers require and when they require is very important."
"The solution communicates where to fix the issue for the purpose of less iterations."
"What I like best about Checkmarx is that it has fewer false positives than other products, giving you better results."
"The most valuable feature is the application tracking reporting."
"Both automatic and manual code review (CxQL) are valuable."
"It can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security."
"The policies are probably the most valuable features. They're similar in function to Microsoft group policies where we can have it monitor certain things or push out software on a schedule. I would rate the policies eight out of 10. They're robust, I could monitor most of the things that Windows Performance Monitoring keeps tabs on."
"The most valuable feature we have found currently is probably patch management."
"The most valuable features of NinjaOne include remote desktop management, support and assistive tools, and screen sharing."
"NinjaOne's best feature is its monitoring."
"It helps us to be able to have visibility into the overall performance of the servers, laptops, and desktops that we are managing currently."
"The software's automation tools have solved critical deployment problems for small businesses."
"It just works as advertised and serves the purpose for which we got it."
"NinjaOne has a feature where we can create custom scripts that we can run on devices remotely."
 

Cons

"The dashboarding and reporting functionality of Zafran Security is an area that definitely could use some improvements."
"Initially, we were somewhat concerned about the scalability of Zafran due to our large asset count and the substantial amount of information we needed to process."
"I think the ability to have some enhanced reporting capabilities is something they can improve on, as they have good reports but we have asked for some specific reporting enhancements."
"Checkmarx has a slightly difficult compilation with the CI/CD pipeline."
"We have received some feedback from our customers who are receiving a large number of false positives."
"They can support the remaining languages that are currently not supported. They can also create a different model that can identify zero-day attacks. They can work on different patterns to identify and detect zero-day vulnerability attacks."
"They should make it more container-friendly and optimized for the CI pipeline. They should make it a little less heavy. Right now, it requires a SQL database, and the way the tool works is that it has an engine and then it has an analysis database in which it stores the information. So, it is pretty heavy from that perspective because you have to have a full SQL Server. They're working on something called Checkmarx Light, which is a slim-down version. They haven't released it yet, but that's what we need. There should be something a little more slimmed down that can just run the analysis and output the results in a format that's readable as opposed to having a full, really big, and thick deployment with a full database server."
"Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
"Checkmarx could improve the speed of the scans."
"Creating and editing custom rules in Checkmarx is difficult because the license for the editor comes at an additional cost, and there is a steep learning curve."
"The reports are good, but they still need to be improved considering what the UI offers."
"The solution could improve by optimizing the internet connection being used."
"The NinjaOne distribution server is highly dependent on an active directory."
"The remote connectivity could be better. It works most of the time, but sometimes, there are issues."
"I want NinjaOne to improve the reports."
"The network monitoring needs to be improved."
"I would like to see the software reduced to focus on inventory or remote help tools since many of its current functionalities are not needed."
"The inclusion of XENServer and Proxmox as virtual platforms in NinjaOne is currently missing."
"The graphical user interface could be improved."
 

Pricing and Cost Advice

Information not available
"I believe pricing is better compared to other commercial tools."
"The pricing was not very good. This is just a framework which shouldn’t cost so much."
"Before implementing the product I would evaluate if it is really necessary to scan so many different languages and frameworks. If not, I think there must be a cheaper solution for scanning Java-only applications (which are 90% of our applications)."
"The number of users and coverage for languages will have an impact on the cost of the license."
"The solution is costly."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"The interface used to create custom rules comes at an additional cost."
"We have a subscription license that is on a yearly basis, and it's a pretty competitive solution."
"We got a pretty good deal. It was fairly affordable."
"NinjaOne is a little expensive but is still cheaper than competitors like Acronis or Veeam."
"The pricing is reasonable and cheaper than ConnectWise."
"We currently pay $1.20 per device on a monthly basis."
"Its pricing is great."
"NinjaRMM uses a subscription model."
"NinjaOne's price is fine since my workplace is an educational institution, so we get the product at a really good price considering that we do not pay taxes, making the prices very fair and worth the product."
"It roughly costs $400 a month. It provides a good value because of the number of tools that you get in the solution. I would rate it a four out of five in terms of pricing. There are no additional costs other than the standard licensing fees."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Computer Software Company
10%
Manufacturing Company
8%
Healthcare Company
5%
Financial Services Firm
20%
Computer Software Company
13%
Manufacturing Company
10%
Government
6%
Computer Software Company
13%
Government
8%
Retailer
7%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Zafran Security?
Since we stood Zafran Security up in our private cloud, we handle the maintenance on our side. As we opted not to use...
What needs improvement with Zafran Security?
In terms of areas for improvement, Zafran Security is doing a really great job as a new and emerging company. Oftenti...
What is your primary use case for Zafran Security?
My use cases for Zafran Security revolve around two primary areas. One is around vulnerability management and priorit...
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as ...
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about NinjaOne?
NinjaOne helps us view the status of software patching, whether the PC is locked or unlocked.
What is your experience regarding pricing and costs for NinjaOne?
The price or licensing of NinjaOne is a little bit high.
What needs improvement with NinjaOne?
The network monitoring needs to be improved.
 

Overview

 

Sample Customers

Information Not Available
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Status Pros, Mitchell and Company
Find out what your peers are saying about Checkmarx One vs. NinjaOne and other solutions. Updated: July 2025.
865,384 professionals have used our research since 2012.