No more typing reviews! Try our Samantha, our new voice AI agent.

Coverity Static vs OWASP Zap comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 22, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Coverity Static
Ranking in Static Application Security Testing (SAST)
12th
Average Rating
7.8
Reviews Sentiment
6.5
Number of Reviews
43
Ranking in other categories
No ranking in other categories
OWASP Zap
Ranking in Static Application Security Testing (SAST)
16th
Average Rating
7.6
Reviews Sentiment
7.3
Number of Reviews
41
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Static Application Security Testing (SAST) category, the mindshare of Coverity Static is 2.5%, down from 7.4% compared to the previous year. The mindshare of OWASP Zap is 2.7%, down from 5.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Coverity Static2.5%
OWASP Zap2.7%
Other94.8%
Static Application Security Testing (SAST)
 

Featured Reviews

SP
Lead Information Security at GEP Worldwide at ReBIT
Helps us identify security vulnerabilities in the development phase and provides a plugin for the developer IDE
The initial setup is good. When I use the product to scan the code in the DevOps pipeline, the issue coverage can be greater, which can help speed up risk identification in the CI/CD pipeline. That is one area where improvement can be made. Corresponding steps can be taken for that. It integrates with most of the tools, like ticketing tools, configuration tools, Jenkins, and the pipeline. That is fantastic.
Amit Beniwal - PeerSpot reviewer
Project Manager at Al Hassan LLC
Simplifies vulnerability discovery and has high quality support
There are areas for improvement with OWASP Zap, particularly in the alignment of vulnerabilities concerning CVSS scores. Sometimes, a vulnerability initially categorized as high severity may be reduced to medium or low over time after security patches are applied. This alignment with the present severity score and CVSS score could be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution has helped to increase staff productivity and improved our work significantly by approximately 20 percent."
"Coverity integrates with issue-tracking systems like Jira and provides email notifications, alerts, and other features."
"The most valuable feature of Coverity is its software security feature called the Checker. If you share some vulnerability or weakness then the software can find any potential security bug or defect. The code integration tool enables some secure coding standards and implements some Checkers for Live Duo. So we can enable secure coding and Azure in this tool. So in our software, we can make sure our software combines some industry supervised data."
"The product has been beneficial in logging functionality, allowing me to categorize vulnerabilities based on severity. This aids in providing updated reports on subsequent scans."
"The most valuable feature is that there were not a whole lot of false positives, at least on the codebases that I looked at."
"This solution is easy to use."
"The most valuable feature is the integration with Jenkins."
"It's very stable."
"The interface is easy to use."
"​It has improved my organization with faster security tests.​"
"The solution has tightened our security and that of our clients who depend on it."
"The community edition updates services regularly. They add new vulnerabilities into the scanning list."
"ZAP is easy to use. The automated scan is a powerful feature. You can simulate attacks with various parameters. ZAP integrates well with SonarQube."
"OWASP is quite matured in identifying the vulnerabilities."
"The valuable features are that it's very simple to use and the user interface is very good, particularly for beginners so they can start the application easily."
"The scalability of this product is very good."
 

Cons

"We use GitHub and Gitflow, and Coverity does not fit with Gitflow. I have to create a screen for our branches, and it's a pain for developers. It has been difficult to integrate Coverity with our system."
"The product lacks sufficient customization options."
"We'd like it to be faster."
"The product should include more customization options. The analytics is not as deep as compared to SonarQube."
"Coverity concerns its dashboards and reporting."
"Some features are not performing well, like duplicate detection and switch case situations."
"The tool needs to improve its reporting."
"I am not a fan of using both SOAP and REST APIs and Coverity offers a mix of functionality depending on the interface used."
"It's possibly just a limitation of the product itself but sometimes it won't scan a particular website so you have to manually go in and make some configuration changes."
"Zap could improve by providing better reports for security and recommendations for the vulnerabilities."
"It would be nice to have a solid SQL injection engine built into Zap."
"The documentation needs to be improved because I had to learn everything from watching YouTube videos."
"The product should allow users to customize the report based on their needs."
"The product reporting could be improved."
"I'd also like to see an improvement in test reports because we get too many false positives."
"OWASP Zap could benefit from a noise cancellation feature like that of Burp Suite Professional, where AI helps reduce certain non-critical findings."
 

Pricing and Cost Advice

"The tool was fairly priced."
"It is expensive."
"The price is competitive with other solutions."
"I would rate the tool's pricing a one out of ten."
"The pricing is on the expensive side, and we are paying for a couple of items."
"This is a pretty expensive solution. The overall value of the solution could be improved if the price was reduced. Licensing is done on an annual basis."
"The pricing is very reasonable compared to other platforms. It is based on a three year license."
"Coverity’s price is on the higher side. It should be lower."
"The tool is open-source."
"It is open source, and we can scan freely."
"This solution is open source and free."
"OWASP ZAP is a free tool provided by OWASP’s engineers and experts. There is an option to donate."
"It is highly recommended as it is an open source tool."
"As Zap is free and open-source, with tons of features similar to those of commercial solutions, I would definitely recommend trying it out."
"We have used the freeware version. I believe Zap only has freeware."
"OWASP Zap is free to use."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
908,834 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
28%
Computer Software Company
9%
Financial Services Firm
7%
Comms Service Provider
5%
Computer Software Company
10%
Financial Services Firm
9%
University
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise6
Large Enterprise31
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise11
Large Enterprise22
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What needs improvement with Coverity?
The price is a concern, and there are a lot of false positives coming through. Support with Coverity is adequate, but they take a longer time to respond. The core support is not straightforward, an...
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What is your experience regarding pricing and costs for OWASP Zap?
OWASP might be cost-effective, however, people prefer to use the free edition available as open source.
What needs improvement with OWASP Zap?
The improvement that has to be done for APIs focuses on manual activities where the feature exists, but it is not at the same level as what Burp Suite does with intercepting and tools such as Postm...
 

Also Known As

Synopsys Static Analysis
No data available
 

Overview

 

Sample Customers

SAP, Mega International, Thales Alenia Space
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Find out what your peers are saying about Coverity Static vs. OWASP Zap and other solutions. Updated: August 2026.
908,834 professionals have used our research since 2012.