We performed a comparison between Checkmarx One and Kiuwan based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."It gives the proper code flow of vulnerabilities and the number of occurrences."
"The ability to track the vulnerabilities inside the code (origin and destination of weak variables or functions)."
"The main thing we find valuable about Checkmarx is the ease of use. It's easy to initiate scans and triage defects."
"Scan reviews can occur during the development lifecycle."
"The most valuable feature for me is the Jenkins Plugin."
"We use the solution to validate the source code and do SAST and security analysis."
"The report function is the solution's greatest asset."
"From my point of view, it is the best product on the market."
"We use Kiuwan to locate the source of application vulnerabilities."
"The solution offers very good technical support."
"I find it immensely helpful because it's not just about generating code; it's about ensuring efficiency in the execution."
"I've tried many open source applications and the remediation or correction actions that were provided by Kiuwan were very good in comparison."
"I've found the reporting features the most helpful."
"The solution has a continuous integration process."
"I have found the security and QA in the source code to be most valuable."
"Software analytics for a lot of different languages including ABAP."
"They should make it more container-friendly and optimized for the CI pipeline. They should make it a little less heavy. Right now, it requires a SQL database, and the way the tool works is that it has an engine and then it has an analysis database in which it stores the information. So, it is pretty heavy from that perspective because you have to have a full SQL Server. They're working on something called Checkmarx Light, which is a slim-down version. They haven't released it yet, but that's what we need. There should be something a little more slimmed down that can just run the analysis and output the results in a format that's readable as opposed to having a full, really big, and thick deployment with a full database server."
"The pricing can get a bit expensive, depending on the company's size."
"The interactive application security testing, or IAST, the interactive part where you're looking at an application that lives in a runtime environment on a server or virtual machine, needs improvement."
"Its user interface could be improved and made more friendly."
"We would like to be able to run scans from our local system, rather than having to always connect to the product server, which is a longer process."
"It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."
"When we first ran it on a big project, there wasn't enough memory on the computer. It originally ran with eight gigabytes, and now it runs with 32. The software stopped at some point, and while I don't think it said it ran out of memory, it just said "stopped" and something else. We had to go to the logs and send them to the integrator, and eventually, they found a memory issue in the logs and recommended increasing the memory. We doubled it once, and it didn't seem enough. We doubled it again, and it helped."
"I would like to see the tool’s pricing improved."
"It could improve its scalability abilities."
"Kiuwan's support has room for improvement. You can only open a ticket is through email, and the support team is outside of our country. They should have a support number or chat."
"I would like to see better integration with the Visual Studio and Eclipse IDEs."
"The development-to-delivery phase."
"I would like to see additional languages supported."
"The configuration hasn't been that good."
"It would be beneficial to streamline calls and transitions seamlessly for improved functionality."
"Integration of the programming tools could be improved."
Checkmarx One is ranked 3rd in Application Security Tools with 67 reviews while Kiuwan is ranked 21st in Application Security Tools with 23 reviews. Checkmarx One is rated 7.6, while Kiuwan is rated 8.6. The top reviewer of Checkmarx One writes "The report function is a great, configurable asset but sometimes yields false positives". On the other hand, the top reviewer of Kiuwan writes "Though a stable tool, the UI needs improvement". Checkmarx One is most compared with SonarQube, Veracode, Fortify on Demand and Snyk, whereas Kiuwan is most compared with SonarQube, Veracode, Snyk, Fortify on Demand and SonarCloud. See our Checkmarx One vs. Kiuwan report.
See our list of best Application Security Tools vendors and best Application Security Testing (AST) vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.