Try our new research platform with insights from 80,000+ expert users

Coverity vs HCL AppScan comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Coverity
Ranking in Static Application Security Testing (SAST)
4th
Average Rating
7.8
Reviews Sentiment
6.5
Number of Reviews
42
Ranking in other categories
No ranking in other categories
HCL AppScan
Ranking in Static Application Security Testing (SAST)
10th
Average Rating
7.8
Reviews Sentiment
6.9
Number of Reviews
43
Ranking in other categories
Application Security Tools (14th), Dynamic Application Security Testing (DAST) (1st)
 

Mindshare comparison

As of May 2025, in the Static Application Security Testing (SAST) category, the mindshare of Coverity is 7.5%, up from 6.6% compared to the previous year. The mindshare of HCL AppScan is 2.6%, up from 2.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
 

Featured Reviews

Md. Shahriar Hussain - PeerSpot reviewer
Offers impressive reporting features with user-friendliness and high scalability
The solution can be easily setup but requires heavy integration due to the multiple types of port and programming languages involved. Comparing the resource requirements of the solution I would say it can be installed effortlessly. I would rate the initial setup an eight out of ten. A professional needs some pre-acquired knowledge to manage Coverity's deployment process, but the local solution partners provide support well enough for trouble-free deployment. The overall deployment process of Coverity took around two and a half hours in our organization. The deployment duration depends upon the operating system and resources including high-end RAM and CPU processors.
Rishi Anupam - PeerSpot reviewer
A stable and scalable scanning solution with good reporting feature
The solution is used for the vulnerabilities scan on the network side The reporting part is the most valuable feature. The penetration testing feature should be included. I have been using the solution for four years. It is a stable solution. I rate it seven out of ten. It is a scalable…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Provides software security, and helps to find potential security bugs or defects."
"The solution effectively identifies bugs in code."
"Coverity is scalable."
"The reporting feature is up to the mark."
"It has the lowest false positives."
"It's very stable."
"I like Coverity's capability to scan codes once we push it. We don't need more time to review our colleagues' codes. Its UI is pretty straightforward."
"Coverity is easy to use and easy to integrate with CI."
"The most valuable feature of the solution is the scanning or security part."
"It highlights, with several grades of severity, the types of vulnerabilities, so we can focus on the most severe security vulnerabilities in the code."
"It is a stable solution...It is a scalable solution...The initial setup or installation of HCL AppScan is easy."
"It has certainly helped us find vulnerabilities in our software, so this is priceless in the end."
"It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings."
"We are now deploying less defects to production."
"We leverage it as a quality check against code."
"The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase."
 

Cons

"Coverity is not a user-friendly product."
"Sometimes, vulnerabilities remain unidentified even after setting up the rules."
"We actually specified several checkers, but we found some checkers had a higher false positive rate. I think this is a problem. Because we have to waste some time is really the issue because the issue is not an issue. I mean, the tool pauses or an issue, but the same issue is the filter now.Some check checkers cannot find some issues, but sometimes they find issues that are not relevant, right, that are not really issues. Some customisation mechanism can be added in the next release so that we can define our Checker. The Modelling feature provided by Coverity helps in finding more information for potential issues but it is not mature enough, it should be mature. The fast testing feature for security testing campaign can be added as well. So if you correctly integrate it with the training team, maybe you can help us to find more potential issues."
"The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming."
"It would be great if we could customize the rules to focus on critical issues."
"Reporting engine needs to be more robust."
"The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming."
"The solution needs to improve its false positives."
"Improving usability could enhance the overall experience with AppScan. It would be beneficial to make the solution more user-friendly, ensuring that everyone can easily navigate and utilize its features."
"AppScan needs to improve its handling of false positives."
"One thing which I think can be improved is the CI/CD Integration"
"The penetration testing feature should be included."
"​IBM Security AppScan Source is rather hard to use​."
"The databases for HCL are small and have room for improvement."
"It has crashed at times."
"There is room for improvement in the pricing model."
 

Pricing and Cost Advice

"This is a pretty expensive solution. The overall value of the solution could be improved if the price was reduced. Licensing is done on an annual basis."
"I would rate the tool's pricing a one out of ten."
"The tool's price is somewhere in the middle. It's neither cheap nor expensive. I would rate the pricing a five out of ten."
"Coverity is quite expensive."
"The tool was fairly priced."
"The licensing fees are based on the number of lines of code."
"The solution is affordable."
"The price is competitive with other solutions."
"The product is moderately priced, though it's an investment due to extensive code analysis needs."
"I rate the product's price a seven on a scale of one to ten, where one is low, and ten is high. HCL AppScan is an expensive tool."
"HCL AppScan is expensive."
"Our clients are willing to pay the extra money. It is expensive."
"The solution is cheap."
"The price is very expensive."
"AppScan is a little bit expensive. IBM needs to work a little bit on the pricing model, decreasing the license cost."
"I would rate the product's pricing a nine out of ten. The product's pricing is expensive compared to the features that they offer."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
849,686 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
33%
Computer Software Company
14%
Financial Services Firm
7%
Government
4%
Computer Software Company
18%
Financial Services Firm
14%
Government
11%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What do you like most about Coverity?
The solution has improved our code quality and security very well.
What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
AppScan needs to improve its handling of false positives. It also requires enhancements in customer support, similar to what Veracode provides. Regularly scheduling calls with clients to discuss fe...
What is your primary use case for HCL AppScan?
The primary use case for AppScan is for security purposes. I compare AppScan with other tools such as Veracode. We use AppScan for vulnerability detection and auto-remediation of vulnerabilities wi...
 

Comparisons

 

Also Known As

Synopsys Static Analysis
IBM Security AppScan, Rational AppScan, AppScan
 

Overview

 

Sample Customers

SAP, Mega International, Thales Alenia Space
Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
Find out what your peers are saying about Coverity vs. HCL AppScan and other solutions. Updated: April 2025.
849,686 professionals have used our research since 2012.