Try our new research platform with insights from 80,000+ expert users

Checkmarx Software Composition Analysis vs OpenText Static Application Security Testing comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx Software Composit...
Average Rating
9.0
Reviews Sentiment
7.6
Number of Reviews
13
Ranking in other categories
Software Composition Analysis (SCA) (8th)
OpenText Static Application...
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
19
Ranking in other categories
Static Code Analysis (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Checkmarx Software Composition Analysis is designed for Software Composition Analysis (SCA) and holds a mindshare of 2.6%, down 2.8% compared to last year.
OpenText Static Application Security Testing, on the other hand, focuses on Static Code Analysis, holds 10.1% mindshare, down 10.4% since last year.
Software Composition Analysis (SCA) Market Share Distribution
ProductMarket Share (%)
Checkmarx Software Composition Analysis2.6%
Black Duck16.7%
Snyk13.1%
Other67.6%
Software Composition Analysis (SCA)
Static Code Analysis Market Share Distribution
ProductMarket Share (%)
OpenText Static Application Security Testing10.1%
Veracode22.1%
Checkmarx One14.6%
Other53.199999999999996%
Static Code Analysis
 

Featured Reviews

Tharindu Malwenna - PeerSpot reviewer
Efficient library identification and upgrade suggestions improve application security
We have many third-party libraries in our organization. I used Checkmarx Software Composition Analysis to identify all the libraries we use and determine whether they are used or unused within the application Checkmarx Software Composition Analysis provides identification of libraries and…
Aphiwat Leetavorn. - PeerSpot reviewer
Provides extensive language support and enhances secure coding practices
The deployment of Fortify Static Code Analyzer needs to be simplified. It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers. This change would facilitate easier installations and ensure all necessary components are connected and ready to use.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the strong points of this solution is that it allows you to incorporate it into a CICB pipeline. It has the ability to do incremental scans. If you scan a very large application, it might take two hours to do the initial scan. The subsequent scans, as people are making changes to the app, scan the Delta and are very fast. That's a really nice implementation. The way they have incorporated the functionality of the incremental scans is something to be aware of. It is quite good. It has been very solid. We haven't really had any issues, and it does what it advertises to do very nicely."
"It is very easy and user friendly. It never requires any kind of technical support. You can do everything on your own."
"I appreciate the user-friendly interface. The GUI is excellent, providing detailed information on outdated versions, including version numbers and the flow of library calls. This allows me to plan and prioritize library changes based on potential vulnerabilities, even if the affected library is indirectly used in my project. The tool offers specific guidance on addressing these issues."
"The customer service and support were good."
"Checkmarx unifies all the features in its service."
"The product is stable and scalable."
"We were able to reduce the number of vulnerable libraries by 50%, leading to significant operational improvement."
"It is a stable solution...It is a scalable solution."
"Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like password credentials and access keys embedded in the code."
"The most valuable features include its ability to detect vulnerabilities accurately and its integration with our CI/CD pipeline."
"I like Fortify Software Security Center or Fortify SSC. This tool is installed on each developer's machine, but Fortify Software Security Center combines everything. We can meet there as security professionals and developers. The developers scan their code and publish the results there. We can then look at them from a security perspective and see whether they fixed the issues. We can agree on whether something is a false positive and make decisions."
"You can really see what's happening after you've developed something."
"The integration Subset core integration, using Jenkins is one of the good features."
"The reference provided for each issue is extremely helpful."
"Fortify Static Code Analyzer's most valuable features are its ability to provide best practices for fixing code and its examples and capabilities to address security problems in the code. It effectively identifies security vulnerabilities by analyzing the code and offering insights on improving it."
"We are satisfied with this solution."
 

Cons

"The solution could improve by determining the success factor of an upgrade, which is currently lacking."
"API security is an area with shortcomings that needs improvement."
"Parts of the implementation process could improve by making it more user-friendly."
"Instant updates for end users to identify vulnerabilities as soon as possible will make Checkmarx Software Composition Analysis better. The UI of the solution could also be improved."
"The solution could improve by determining the success factor of an upgrade, which is currently lacking."
"Some of the recommendations provided by the product are generic. Even if the recommendations provided by the product are of low level, the appropriate ones can help users deal with vulnerabilities."
"Checkmarx Software Composition Analysis should improve dynamic analysis."
"Personally, I currently use it as a standalone tool without integrating it with other systems, and it meets my needs adequately. As a suggestion, I request on considering to add a "what if" feature to the application. Currently, when the tool identifies issues and suggests updates, if I want to explore different scenarios, I need to prepare another file, turn it into a ZIP, and run the analysis again. It would be more convenient if there was a "what if" option in the GUI. This feature could simulate a run, allowing me to quickly check the impact of changing one or more files or versions without the need for a full rerun."
"Not all languages are supported in Fortify."
"The deployment of Fortify Static Code Analyzer needs to be simplified."
"Their licensing is expensive."
"It comes with a hefty licensing fee."
"The generation of false positives should be reduced."
"The pricing is a bit high."
"Fortify's software security center needs a design refresh."
"The price can be improved."
 

Pricing and Cost Advice

"It is a little bit high priced. It would be better if it was a little less expensive."
"Pricing for Checkmarx Software Composition Analysis needs to be competitive."
"The license model is somewhat perplexing as it comprises multiple aspects that can be confusing for customers. The model is determined by the number of registered users and the number of projects being scanned, along with a third component that adds to the complexity."
"My customers need to pay for the licensing part, and they need to opt for an annual subscription."
"We don't have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage."
"The setup costs and pricing for Fortify may vary depending on the organization's needs and requirements."
"There is a licensing fee, and if you bring them to the company and you want them to do the installation and the implementation in the beginning, there is a separate cost. Similarly, if you want consultation or training, there is a separate cost. I see it as suitable only for enterprises. I do not see it suitable for a small business or individual use."
"I rate the pricing of Fortify Static Code Analyzer as a seven out of ten since it is a bit expensive."
"It has a couple of license models. The one that we use most frequently is called their flexible deployment. We use this one because it is flexible and based on the number of code-contributing developers in the organization. It includes almost everything in the Fortify suite for one developer price. It gives access to not just the secure code analyzer (SCA) but also to FSC, the secure code. It gives us accessibility to scan central, which is the decentralized scanning farm. It also gives us access to the software security center, which is the vulnerability management platform."
"From our standpoint, we are significantly better off with Fortify due to the favorable pricing we secured five years ago."
"Although I am not responsible for the budget, Fortify SAST is expensive."
"The price of Fortify Static Code Analyzer could be reduced."
"The licensing is expensive and is in the 50K range."
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
866,778 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
32%
Manufacturing Company
10%
Computer Software Company
8%
Insurance Company
5%
Financial Services Firm
28%
Computer Software Company
13%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business7
Large Enterprise8
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise3
Large Enterprise11
 

Questions from the Community

What do you like most about Checkmarx Software Composition Analysis?
The tool's visual scan analysis shows me all the libraries' vulnerabilities and license types. It helps identify the most complex issues with licenses. It provides good visibility. SCA shows me all...
What is your experience regarding pricing and costs for Checkmarx Software Composition Analysis?
Pricing is complex and high for small organizations but offers great benefits for larger organizations. It is notably different compared to competitors like GitHub Advanced Security.
What needs improvement with Checkmarx Software Composition Analysis?
The solution could improve by determining the success factor of an upgrade, which is currently lacking.
What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
My experience with the pricing, setup costs, and licensing has been good. We have the scan machines, and we are planning to request more from Micro Focus now. We have calls every month or every oth...
What needs improvement with Fortify Static Code Analyzer?
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less ...
 

Also Known As

CxSCA
Fortify Static Code Analysis SAST
 

Overview

 

Sample Customers

AXA, Liveperson, Aaron's, Playtech, Morningstar
Information Not Available
Find out what your peers are saying about Black Duck, Snyk, Veracode and others in Software Composition Analysis (SCA). Updated: August 2025.
866,778 professionals have used our research since 2012.