No more typing reviews! Try our Samantha, our new voice AI agent.

Coverity Static vs SonarQube vs Veracode comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of April 2026, in the Static Application Security Testing (SAST) category, the mindshare of Coverity Static is 3.8%, down from 8.0% compared to the previous year. The mindshare of SonarQube is 17.7%, down from 25.9% compared to the previous year. The mindshare of Veracode is 4.8%, down from 10.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
SonarQube17.7%
Veracode4.8%
Coverity Static3.8%
Other73.7%
Static Application Security Testing (SAST)
 

Featured Reviews

KT
Software Engineering Manager at Visteon Corporation
Using tools for compliance is beneficial but cost concerns persist
We have been using Coverity for quite a long period. It has been fine for our needs. I would rate Coverity between eight to nine, though the cost is high. I would rate their support from Coverity as six. That is the main complaint, but we still appreciate having it.
KH
Sr Software Engineering Supervisor at Mozarc Medical
Gains control over rule customization and achieves reliable vulnerability assessment
The deployment process took me about 2 or 3 hours to deploy SonarQube Server (formerly SonarQube), although I do not remember exactly since it was done about 2 years back. Currently, about 10 of my developers are using SonarQube Server (formerly SonarQube) in my company. I do not have plans to increase the usage of SonarQube Server (formerly SonarQube) in the future as there will not be any requirement to increase. I am a senior software engineer and supervisor at Mozark Medical. My corporate email address is karthik.k.a.r.t.h.i.k.h.a.r.p.a.n.h.a.l.l.i@mozarkmedical.com. Overall, I would rate SonarQube Server (formerly SonarQube) as a 9 out of 10.
reviewer2703864 - PeerSpot reviewer
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
Onboarding developers successfully while improving code security through IDE integration
Regarding room for improvement, we have some problems when onboarding new projects because the build process has to be done in a certain way, as Veracode analyzes the binaries and not the code by itself alone. If the process is not configured correctly, it doesn't work. That's one of the things that we are discussing with Veracode. Something positive that we've been able to do is submit formal feature requests to them, and they are working on them; they've already solved some of them. This encourages us to propose new ideas and improvements. Another improvement that we asked for this use case is to be able to configure how Veracode Fix proposes and fixes because sometimes it makes proposals using libraries that go against our architecture design made by the enterprise architecture team. For example, we want them to propose using another library, and that's something we already asked Veracode, and they are working on it. We want to specify when you see this kind of vulnerability, you can only propose these two options.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a scalable solution."
"The most valuable feature is that there were not a whole lot of false positives, at least on the codebases that I looked at."
"One of the most valuable features is Contributing Events. That particular feature helps the developer understand the root cause of a defect. So you can locate the starting point of the defect and figure out exactly how it is being exploited."
"It has the lowest false positives."
"The most valuable feature of Coverity is its software security feature called the Checker. If you share some vulnerability or weakness then the software can find any potential security bug or defect. The code integration tool enables some secure coding standards and implements some Checkers for Live Duo. So we can enable secure coding and Azure in this tool. So in our software, we can make sure our software combines some industry supervised data."
"If you have enough budget, it is one of the best solutions right now."
"It's pretty stable. I rate the stability of Coverity nine out of ten."
"This product has definitely helped our organization, and based on what I have heard from the development team, they have found a lot of issues before code goes into production."
"If you want to have your code scanned and timed then this is a good tool."
"SonarQube is easy for me; I am recruiting buggy code with this, and it is reporting, showing that this code should not be like this and the reason for it, such as advising when you should declare a static function or why you should or should not initialize a variable, which is an amazing feature."
"All the features of the solution are quite good."
"The customizable dashboard and ability to include results and coverage from unit test and other static analysis code tools."
"The most valuable feature of this solution is that it is free."
"The product has a friendly UI that is easy to use and understand."
"SonarQube is scalable. My company has 50 users."
"The reports from SonarCloud are very good."
"I like Veracode's ease of integration and onboarding. You can quickly and easily get started with a new project or application. That's one area where Veracode shines relative to other tools we've evaluated. Other tools need more work or an engineer to do the setup. With Veracode, you can do the onboarding in a few steps quickly."
"The solution is a specialist in SAST that you can rely on, and code scanning is fast with current, updated algorithms."
"All three of Veracode's offerings are valuable: SCA, SAST, and DAST. It helps identify security loopholes right in the development phase, allowing developers to get feedback around what kind of vulnerabilities exist as soon as they check in the code or even before that in their IDE."
"I don't have to have a team of developers behind me that keep up with all the latest threats because the subscription service they provide for me does that."
"Static code scanning is the most valuable feature."
"For our customers, they know that we go through another level of application security with our application, one our competitors don't use."
"It helps me to detect vulnerabilities."
"Developer Sandboxes help move scanning earlier within the SDLC."
 

Cons

"Reporting engine needs to be more robust. Custom reporting is a must have."
"Zero-day vulnerability identification can be an add-on feature that Coverity can provide."
"I had tried integrating the tool with Azure DevOps, but the report I got stated that my team faced many challenges."
"There is an extra step in my organization that involves uploading to servers, which adds overhead."
"It should be easier to specify your own validation routines and sanitation routines."
"The solution is a bit complex to use in comparison to other products that have many plugins."
"The price is a concern, and there are a lot of false positives coming through."
"It should be easier to specify your own validation routines and sanitation routines."
"SonarQube needs some improvement in its ability to find security-related issues."
"SonarQube Server (formerly SonarQube) could be improved on the reporting front. Instead of grouping, I would prefer to scan the code as part of development and then generate a report on a daily basis among different units or projects, which is currently complicated."
"A better design of the interface and add some new rules."
"Improvements could be made in terms of security. I would like to see dynamic code analysis in the next version of the software."
"The solution could improve by providing more advanced technologies."
"When we have a thousand products published over it, we expect it to be more efficient in terms of serving requests from the browser."
"I have found this solution creates more noise than competitors."
"SonarQube can improve by scanning the internal library which currently it does not do. We are looking for a solution for this."
"Veracode can improve the licensing model as it is a bit confusing."
"I am expecting some AI-related features in it. Also, if someone is using AI-generated code, Veracode should be able to detect that."
"Once your report has been generated, you need to review the report with consultation team, especially if it is too detailed on the development side or regarding the language. Then, you need some professional help from their end to help you understand whatever has been identified. Scheduling consultation takes a longer time. So, if you are running multiple reports at the same time, then you need to schedule a multiple consultation times with one of their developers. There are few developers on their end who work can work with your developers, and their schedules are very tight."
"The scanning process could be more streamlined as it has certain limitations when performing manual scans. It has some checks when the content is in ZIP format or other formats, which takes two or three more steps than Fortify does."
"We are testing Veracode's software composition analysis, but we're having trouble integrating it with SVN. It works out of the box when you use Git but doesn't work as well with other tools like SVN. It's more geared toward Git"
"There were some additional manual steps or work involved that we should not have needed to do."
"I found that there were far too many warnings and some false positives."
"The solution does not support Dynamic Application Security Testing."
 

Pricing and Cost Advice

"It is expensive."
"I would rate Coverity's pricing as a nine out of ten. It's already very expensive, and it's a problem for us to get more licenses due to the price. The pricing model has some good aspects - for example, a personal license gives access to all languages without code limitations, which is better than some competitors. However, it's still a lot of money for us to spend."
"This is a pretty expensive solution. The overall value of the solution could be improved if the price was reduced. Licensing is done on an annual basis."
"The licensing fees are based on the number of lines of code."
"Depending on the usage types, one has to opt for different types of licenses from Coverity, especially to be able to use areas like report viewing or report generation."
"I rate Coverity's price a ten on a scale of one to ten, where one is cheap and ten is expensive."
"The tool was fairly priced."
"Offers varying prices for different companies"
"The price of the solution could be reduced."
"This is open source."
"The development license cost is reasonable, and we've had no concerns about SonarQube when it comes to cost."
"Compared to similar solutions, SonarQube was more accessible to us and had more benefits, with regards to size of the code base and supported languages. Apart from the Enterprise licensing fee, there are no additional costs."
"It's a bit expensive for us. The currency rate of the dollar is a problem but it may be fine for other countries."
"We are using the Developer Edition and the cost is based on the amount of code that is being processed."
"Some of the plugins that were previously free are not free now."
"We are using the open-source version, which is available free of cost."
"It's very expensive, especially when you are a very small organization. If you're using Veracode at an individual level, for example, you're a developer or you run agents, the pricing might not affect you, but if you're using it at a company level to troubleshoot security issues, the pricing is not quite favorable. It may affect ROI."
"The pricing is a little on the high side but since we combine our product into one suite, it is easy to do and works well for us."
"Without getting too specific, I'd say the average yearly cost is around $50,000. The costs include licensing and maintenance support."
"Veracode is one of the more expensive solutions in the market, but it is worth the expense because of the eLearning and the security consultations; everything is included in the license."
"Compared to the typical software composition analysis solutions, Veracode is not so costly, although the static analysis part of it is a little costlier."
"It can be expensive to do this, so I would just make sure that you're getting the proper number of licenses. Do your analysis. Make sure you know exactly what it is you need, going in."
"From a cost perspective, it seems okay, although we will probably evaluate alternatives next time it's up for renewal because for us, it's a relatively high cost, and we want to make sure that we are using our resources most appropriately."
"Pricing-wise, I find it a bit expensive because it's based on the number of users requesting access to Veracode."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
885,728 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
31%
Computer Software Company
10%
Financial Services Firm
7%
Comms Service Provider
4%
Manufacturing Company
13%
Financial Services Firm
13%
Computer Software Company
12%
Comms Service Provider
5%
Financial Services Firm
15%
Computer Software Company
12%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise6
Large Enterprise31
By reviewers
Company SizeCount
Small Business42
Midsize Enterprise24
Large Enterprise79
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise45
Large Enterprise114
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and securi...
What needs improvement with Coverity?
The price is a concern, and there are a lot of false positives coming through. Support with Coverity is adequate, but...
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which ...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. Son...
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to...
What do you like most about Veracode Static Analysis?
I like its integration with GitHub. I like using it from GitHub. I can use the GitHub URL and find out the vulnerabil...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
What needs improvement with Veracode Static Analysis?
Veracode can improve to stand in this market. They do not have to do much; they just need to improve their UI experie...
 

Comparisons

 

Also Known As

Synopsys Static Analysis
Sonar, SonarQube Cloud
Crashtest Security , Veracode Detect
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

SAP, Mega International, Thales Alenia Space
Snowflake, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about SonarSource Sàrl, Veracode, Checkmarx and others in Static Application Security Testing (SAST). Updated: March 2026.
885,728 professionals have used our research since 2012.