Try our new research platform with insights from 80,000+ expert users

Coverity Static vs HCL AppScan comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 15, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Coverity Static
Ranking in Static Application Security Testing (SAST)
5th
Average Rating
7.8
Reviews Sentiment
6.5
Number of Reviews
43
Ranking in other categories
No ranking in other categories
HCL AppScan
Ranking in Static Application Security Testing (SAST)
14th
Average Rating
7.6
Reviews Sentiment
5.9
Number of Reviews
43
Ranking in other categories
Application Security Tools (15th), Dynamic Application Security Testing (DAST) (1st)
 

Mindshare comparison

As of October 2025, in the Static Application Security Testing (SAST) category, the mindshare of Coverity Static is 6.0%, down from 7.3% compared to the previous year. The mindshare of HCL AppScan is 2.5%, down from 2.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Market Share Distribution
ProductMarket Share (%)
Coverity Static6.0%
HCL AppScan2.5%
Other91.5%
Static Application Security Testing (SAST)
 

Featured Reviews

Jaile Sebes - PeerSpot reviewer
Resolving critical software issues demands faster implementation and better integration
We use Coverity primarily to find issues such as software bugs and memory leaks, especially in C++ and C# projects. It helps us identify deadlocks, synchronization issues, and product crashes Coverity has been instrumental in resolving product crashes by detecting various issues like deadlocks.…
AnshulTomar - PeerSpot reviewer
Scalable platform with efficient static and dynamic testing features
We use the product for Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST). By integrating AppScan into our CI/CD pipelines, aligned with Agile methodologies, we ensure that security testing becomes an integral part of the software development lifecycle The…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Coverity is easy to use and easy to integrate with CI."
"It provides reports about a lot of potential defects."
"Coverity provides excellent compliance and other features, which is a very good part."
"The solution has improved our code quality and security very well."
"The solution has helped to increase staff productivity and improved our work significantly by approximately 20 percent."
"Provides software security, and helps to find potential security bugs or defects."
"Coverity is easy to set up and has a less lengthy process to find vulnerabilities."
"Coverity is quite stable and we haven’t had any issues or any downtime."
"The solution is easy to use."
"The solution offers services in a few specific development languages."
"You can easily find particular features and functions through the UI."
"The UI was very intuitive."
"It is a stable solution...It is a scalable solution...The initial setup or installation of HCL AppScan is easy."
"The most valuable feature of the solution is Postman."
"AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further."
"It identifies all the URLs and domains on its own and then performs tests and provides the results."
 

Cons

"Reporting engine needs to be more robust."
"The solution needs to improve its false positives."
"They could improve the usability. For example, how you set things up, even though it's straightforward, it could be still be easier."
"Coverity concerns its dashboards and reporting."
"There should be additional IDE support."
"The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming."
"The tool needs to improve its reporting."
"The solution is a bit complex to use in comparison to other products that have many plugins."
"AppScan is too complicated and should be made more user-friendly."
"AppScan needs to improve its handling of false positives."
"They could incorporate AI to enhance vulnerability detection and improve the product's reporting capabilities."
"The solution could improve by having a mobile version."
"They have to improve support."
"We would like to integrate with some of the other reporting tools that we're planning to use in the future."
"There is room for improvement in the pricing model."
"Visibility is an issue for us. Our partners do not know we have integrations with some of IBM products."
 

Pricing and Cost Advice

"This is a pretty expensive solution. The overall value of the solution could be improved if the price was reduced. Licensing is done on an annual basis."
"Offers varying prices for different companies"
"Depending on the usage types, one has to opt for different types of licenses from Coverity, especially to be able to use areas like report viewing or report generation."
"I would rate Coverity's pricing as a nine out of ten. It's already very expensive, and it's a problem for us to get more licenses due to the price. The pricing model has some good aspects - for example, a personal license gives access to all languages without code limitations, which is better than some competitors. However, it's still a lot of money for us to spend."
"Coverity is very expensive."
"The pricing is on the expensive side, and we are paying for a couple of items."
"Coverity’s price is on the higher side. It should be lower."
"The solution is affordable."
"The product is moderately priced, though it's an investment due to extensive code analysis needs."
"The price is very expensive."
"The tool was expensive."
"Pricing was the main reason that we went ahead with this solution as they were the lowest in the market."
"I would rate the product's pricing a nine out of ten. The product's pricing is expensive compared to the features that they offer."
"With the features, that they offer, and the support, they offer, AppScan pricing is on a higher level."
"The price of HCL AppScan is okay, in my opinion. You just buy HCL AppScan and don't pay anything anymore, meaning it is just a one-time purchase."
"AppScan is a little bit expensive. IBM needs to work a little bit on the pricing model, decreasing the license cost."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
872,706 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
32%
Computer Software Company
13%
Financial Services Firm
7%
Healthcare Company
4%
Computer Software Company
15%
Financial Services Firm
12%
Government
10%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise6
Large Enterprise31
By reviewers
Company SizeCount
Small Business13
Midsize Enterprise6
Large Enterprise31
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What do you like most about Coverity?
The solution has improved our code quality and security very well.
What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
AppScan needs to improve its handling of false positives. It also requires enhancements in customer support, similar to what Veracode provides. Regularly scheduling calls with clients to discuss fe...
What is your primary use case for HCL AppScan?
The primary use case for AppScan is for security purposes. I compare AppScan with other tools such as Veracode. We use AppScan for vulnerability detection and auto-remediation of vulnerabilities wi...
 

Also Known As

Synopsys Static Analysis
IBM Security AppScan, Rational AppScan, AppScan
 

Overview

 

Sample Customers

SAP, Mega International, Thales Alenia Space
Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
Find out what your peers are saying about Coverity Static vs. HCL AppScan and other solutions. Updated: September 2025.
872,706 professionals have used our research since 2012.