Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs OpenText Static Application Security Testing comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 19, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.5
Organizations saw ROI with Checkmarx One via improved development speed, cost savings, and enhanced security, despite quantification challenges.
Sentiment score
6.8
OpenText Static Application Security Testing received mixed reviews, praising cost savings and partnerships, but highlighting challenges in quantifying ROI.
 

Customer Service

Sentiment score
7.1
Checkmarx One offers fast, expert support, though some users note resolution delays and additional support charges.
Sentiment score
6.7
Generally positive with dedicated teams, though some seek improvements in ticket system and responsiveness for OpenText support.
The technical support has been good because we always received answers to our questions.
The customer service and support for Fortify Static Code Analyzer are better than those for LoadRunner.
 

Scalability Issues

Sentiment score
7.1
Checkmarx One excels in scalability, integration, and automation, efficiently managing various organizational sizes though licensing can be restrictive.
Sentiment score
7.8
OpenText SAST is scalable for various project sizes but needs improvement in speed and infrastructure management.
 

Stability Issues

Sentiment score
7.2
Checkmarx One is reliable with some performance issues during large scans; user ratings vary from six to ten.
Sentiment score
7.5
OpenText Static Application Security Testing is reliable and stable, with improvements since version 19.10, and benefits from proper training.
I would rate the stability of this solution a nine on a scale of 1 to 10 where one is low stability and 10 is high.
I would rate the product stability as an eight.
The stability of Fortify Static Code Analyzer is generally good.
 

Room For Improvement

Checkmarx One needs enhanced false positive reduction, language support, CD integration, pricing, UI, reporting, and automation improvements.
OpenText SAST faces high costs, complex use, false positives, and needs better integration, language support, and feature enhancements.
It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from.
We would appreciate if the AI could give us more information about improvements and reduce the number of false positives, but this solution doesn't have this function yet.
While it includes all the OWASP top factors, AI has come into the picture, so those updates should also be considered.
It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers.
 

Setup Cost

Checkmarx One offers high quality and performance, though its pricing varies and is often seen as expensive yet competitive.
Enterprise users find OpenText Static Application Security Testing's pricing high but consider it economical compared to other major solutions.
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs.
My experience with the pricing, setup costs, and licensing has been good.
 

Valuable Features

Checkmarx One provides comprehensive vulnerability analysis with intuitive features, efficient reporting, CI/CD integration, and extensive language support.
OpenText SAST enhances security by automating vulnerability detection, integrating across tools, and providing detailed remediation and compliance guidance.
My experience with the initial setup of Checkmarx One is straightforward; it is not complex compared to other tools that I have tried.
Fortify Static Code Analyzer has the capability of giving fewer false positives compared to other tools.
The most impactful feature of Fortify Static Code Analyzer in identifying vulnerabilities is the ratio of total number of vulnerabilities to false positives.
The most valuable feature of Fortify Static Code Analyzer is its extensive language support, covering many languages from legacy ones to the newest.
 

Categories and Ranking

Checkmarx One
Ranking in Static Code Analysis
3rd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (24th), API Security (5th), DevSecOps (4th), Risk-Based Vulnerability Management (9th)
OpenText Static Application...
Ranking in Static Code Analysis
2nd
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
19
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2025, in the Static Code Analysis category, the mindshare of Checkmarx One is 17.5%, down from 24.2% compared to the previous year. The mindshare of OpenText Static Application Security Testing is 11.7%, up from 10.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Code Analysis
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Aphiwat Leetavorn. - PeerSpot reviewer
Provides extensive language support and enhances secure coding practices
The deployment of Fortify Static Code Analyzer needs to be simplified. It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers. This change would facilitate easier installations and ensure all necessary components are connected and ready to use.
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
858,435 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
14%
Manufacturing Company
10%
Government
5%
Financial Services Firm
30%
Computer Software Company
13%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
My experience with the pricing, setup costs, and licensing has been good. We have the scan machines, and we are planning to request more from Micro Focus now. We have calls every month or every oth...
What needs improvement with Fortify Static Code Analyzer?
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less ...
 

Also Known As

No data available
Fortify Static Code Analysis SAST
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Information Not Available
Find out what your peers are saying about Checkmarx One vs. OpenText Static Application Security Testing and other solutions. Updated: June 2025.
858,435 professionals have used our research since 2012.