Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs ReShaper comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Static Code Analysis
3rd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (24th), API Security (5th), DevSecOps (4th), Risk-Based Vulnerability Management (9th)
ReShaper
Ranking in Static Code Analysis
6th
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2025, in the Static Code Analysis category, the mindshare of Checkmarx One is 17.5%, down from 24.2% compared to the previous year. The mindshare of ReShaper is 2.5%, down from 5.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Code Analysis
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
reviewer1465254 - PeerSpot reviewer
Detects, analyzes, and fixes any coding issues
When it's integrated with a weak server machine, the performance isn't that great. It starts up slowly and even crashes at times. If they optimized some of the modules within the ReSharper extension, it would be smoother and faster. Sometimes when the machine is a bit overloaded, it causes it to crash and you need to disable the extension and then re-enabled it. It's not really a stability issue, it probably depends on the machine, but they should consider the fact that not all people have strong machines with high hardware specifications. As long as you have a good processor it will work smoothly, but regarding minimum requirements, it needs to be revisited.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is the application tracking reporting."
"The most valuable feature is the simple user interface."
"What I like best about Checkmarx is that it has fewer false positives than other products, giving you better results."
"The UI is very intuitive and simple to use."
"The most valuable features of Checkmarx are its integration with multiple SCM solutions and CICD tools, its ability to scale according to user licenses, and the quick scanning process."
"The value you can get out of the speedy production may be worth the price tag."
"The most valuable feature for me is the Jenkins Plugin."
"The identification of verification-related security vulnerabilities is really important and one of the key things. It also identifies vulnerabilities for any kind of third-party tool coming into the system or any third-party tools that you are using, which is very useful for avoiding random hacking."
"The most valuable feature of ReShaper is that it provides continuously scanning of the data in real-time. ReShaper has a really good mechanism and process, they have a decent system."
"It comes with many features and supports almost all of the coding languages available."
 

Cons

"The validation process needs to be sped up."
"I would like to see the tool’s pricing improved."
"As the solution becomes more complex and feature rich, it takes more time to debug and resolve problems. Feature-wise, we have no complaints, but Checkmarx becomes harder to maintain as the product becomes more complex. When I talk to support, it takes them longer to fix the problem than it used to."
"The integration could improve by including, for example, DevSecOps."
"It would be really helpful if the level of confidence was included, with respect to identified issues."
"Integration into the SDLC (i.e. support for last version of SonarQube) could be added."
"It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."
"The solution sometimes reports a false auditable code or false positive."
"When it's integrated with a weak server machine, the performance isn't that great. It starts up slowly and even crashes at times."
"ReShaper could improve by increasing the performance of the scans. Their application is taking too much CPU. The processing is taking too many CPU resources which causes the system to slow down."
 

Pricing and Cost Advice

"The price of Checkmarx could be reduced to match their competitors, it is expensive."
"The pricing was not very good. This is just a framework which shouldn’t cost so much."
"The interface used to create custom rules comes at an additional cost."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"Before implementing the product I would evaluate if it is really necessary to scan so many different languages and frameworks. If not, I think there must be a cheaper solution for scanning Java-only applications (which are 90% of our applications)."
"I believe pricing is better compared to other commercial tools."
"It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing."
"As far as I know, the licensing isn't very cheap."
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
859,129 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
Computer Software Company
21%
Comms Service Provider
9%
Financial Services Firm
9%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
Ask a question
Earn 20 points
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Information Not Available
Find out what your peers are saying about Checkmarx One vs. ReShaper and other solutions. Updated: June 2025.
859,129 professionals have used our research since 2012.