Try our new research platform with insights from 80,000+ expert users

CodeScan Static Code Analysis vs Veracode comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CodeScan Static Code Analysis
Ranking in Static Application Security Testing (SAST)
38th
Average Rating
0.0
Number of Reviews
0
Ranking in other categories
No ranking in other categories
Veracode
Ranking in Static Application Security Testing (SAST)
2nd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
207
Ranking in other categories
Application Security Tools (2nd), Container Security (8th), Software Composition Analysis (SCA) (3rd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (1st)
 

Mindshare comparison

As of December 2025, in the Static Application Security Testing (SAST) category, the mindshare of CodeScan Static Code Analysis is 0.6%, up from 0.0% compared to the previous year. The mindshare of Veracode is 5.8%, down from 10.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Market Share Distribution
ProductMarket Share (%)
Veracode5.8%
CodeScan Static Code Analysis0.6%
Other93.6%
Static Application Security Testing (SAST)
 

Featured Reviews

Use CodeScan Static Code Analysis?
Leave a review
reviewer2703864 - PeerSpot reviewer
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
Onboarding developers successfully while improving code security through IDE integration
Regarding room for improvement, we have some problems when onboarding new projects because the build process has to be done in a certain way, as Veracode analyzes the binaries and not the code by itself alone. If the process is not configured correctly, it doesn't work. That's one of the things that we are discussing with Veracode. Something positive that we've been able to do is submit formal feature requests to them, and they are working on them; they've already solved some of them. This encourages us to propose new ideas and improvements. Another improvement that we asked for this use case is to be able to configure how Veracode Fix proposes and fixes because sometimes it makes proposals using libraries that go against our architecture design made by the enterprise architecture team. For example, we want them to propose using another library, and that's something we already asked Veracode, and they are working on it. We want to specify when you see this kind of vulnerability, you can only propose these two options.
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
879,310 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Performing Arts
22%
Outsourcing Company
20%
Energy/Utilities Company
18%
University
8%
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business70
Midsize Enterprise44
Large Enterprise113
 

Questions from the Community

Ask a question
Earn 20 points
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What do you like most about Veracode Static Analysis?
I like its integration with GitHub. I like using it from GitHub. I can use the GitHub URL and find out the vulnerabilities.
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

No data available
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

1. Atlassian 2. Cisco 3. Google 4. IBM 5. Intel 6. Microsoft 7. Oracle 8. SAP 9. VMware 10. Amazon Web Services 11. Facebook 12. LinkedIn 13. Netflix 14. Spotify 15. Tesla 16. Uber 17. Airbnb 18. Dropbox 19. Square 20. Snapchat 21. Pinterest 22. Yelp 23. Mozilla 24. Mozilla Foundation 25. Red Hat 26. Canonical 27. SUSE 28. CentOS 29. Fedora 30. Ubuntu
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about SonarSource Sàrl, Veracode, Checkmarx and others in Static Application Security Testing (SAST). Updated: November 2025.
879,310 professionals have used our research since 2012.