Try our new research platform with insights from 80,000+ expert users

Defensics Fuzzing vs SonarQube Server (formerly SonarQube) comparison

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Defensics Fuzzing
Average Rating
8.6
Number of Reviews
4
Ranking in other categories
Fuzz Testing Tools (5th)
SonarQube Server (formerly ...
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
116
Ranking in other categories
Application Security Tools (1st), Static Application Security Testing (SAST) (1st), Software Development Analytics (1st)
 

Mindshare comparison

While both are Quality Assurance solutions, they serve different purposes. Defensics Fuzzing is designed for Fuzz Testing Tools and holds a mindshare of 22.4%, up 17.4% compared to last year.
SonarQube Server (formerly SonarQube), on the other hand, focuses on Application Security Tools, holds 22.4% mindshare, down 26.5% since last year.
Fuzz Testing Tools
Application Security Tools
 

Featured Reviews

SK
Product security tests for switches and router sections
Codenomicon Defensics should be more advanced for the testing sector. It should be somewhat easy and flexible to install. What I see in the documentation isn't that. Even if something doesn't malfunction, sometimes it is hard to install and execute. The product needs video documentation. This would help a lot more.
Sthembiso Zondi - PeerSpot reviewer
Consistent improvements in code quality and security with effective integration and reliable technical support
The features of SonarQube Server (formerly SonarQube) that I find most useful are the suggestions received from reviewing the code. When they review the code, they provide suggestions on how to fix it, and we find those very useful from a development perspective. We use SonarQube Server's (formerly SonarQube) centralized management and visualization of code quality metrics on the dashboard because that's the executive dashboard that we send to the executives to show where we are in terms of quality, security, and where the company can improve. We use that for organizational improvement purposes. The ability to tailor metrics tracking in SonarQube Server (formerly SonarQube) has been beneficial to my team. There are team-specific dashboards which are related to specific repositories they utilize, and we have that aggregative dashboard that shows the whole organization's performance. We can drill down per specific repository, which makes it easier for the team to improve specific things.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Whatever the test suit they give, it is intelligent. It will understand the protocol and it will generate the test cases based on the protocol: protocol, message sequence, protocol, message structure... Because of that, we can eliminate a lot of unwanted test cases, so we can execute the tests and complete them very quickly."
"The product is related to US usage with TLS contact fees, i.e. how more data center connections will help lower networking costs."
"We have found multiple issues in our embedded system network protocols, related to buffer overflow. We have reduced some of these issues."
"The static code analysis of the solution is the most important aspect for us. When it comes to security breaches within the code, we can leverage some rules to allow us to identify the repetition in our code and the possible targets that we may have. It makes it very easy to review our code for security purposes."
"SonarQube is good for checking and maintaining code quality."
"The reporting and the results are quick. It gets integrated within the pipeline well."
"If code coverage is a low number then that's of great value to me."
"There is a free version."
"When comparing other static code analysis tools, SonarQube has fewer false-positive issues being reported. They have a lot of support for different tech stacks. It covers the entire developer community which includes Salesforce or it could be the regular Java.net project. It has actually sufficed all the needs in one tool for static code analysis."
"Engineers have also learned from the results and have improved themselves as engineers. This will help them with their careers."
"Using SonarQube has helped us to identify areas of technical debt to work on, resulting in better code, fewer vulnerabilities, and fewer bugs."
 

Cons

"It does not support the complete protocol stack. There are some IoT protocols that are not supported and new protocols that are not supported."
"Sometimes, when we are testing embedded devices, when we trigger the test cases, the target will crash immediately. It is very difficult for us to identify the root cause of the crash because they do not provide sophisticated tools on the target side. They cover only the client-side application... They do not have diagnostic tools for the target side. Rather, they have them but they are very minimal and not very helpful."
"Codenomicon Defensics should be more advanced for the testing sector. It should be somewhat easy and flexible to install."
"New plug-ins should be integrated into SonarCloud to give more flexibility to the product."
"The product must improve security analysis."
"We did have some trouble with the LDAP integration for the console."
"The tool needs to be more compatible with C/C++ language"
"The product needs to integrate other security tools for security scanning."
"It would be better if SonarQube provided a good UI for external configuration."
"The exporting capabilities could be improved. Currently, exporting is fully dependent on the SonarQube environment."
"I think the code security can be improved."
 

Pricing and Cost Advice

"Licensing is a bit expensive."
"I use the full trial version of SonarQube."
"We did not purchase a license (required for C++ support), but this option was considered."
"It's an open-source solution, with no additional costs."
"SonarQube is a fairly affordable solution for a larger scale if you have a specific role or specific department for secure code."
"The price of this solution is more expensive than competitors. However, it works better than competitors."
"The development license cost is reasonable, and we've had no concerns about SonarQube when it comes to cost."
"SonarQube enterprise, I am not sure of the price but from what I understand they are charging a fee. It's is not clear if it is an annual fee or a one-off."
"SonarQube is a cost-effective solution."
report
Use our free recommendation engine to learn which Fuzz Testing Tools solutions are best for your needs.
865,164 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
20%
Manufacturing Company
16%
Financial Services Firm
8%
Media Company
6%
Financial Services Firm
16%
Computer Software Company
14%
Manufacturing Company
13%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Ask a question
Earn 20 points
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
 

Also Known As

Codenomicon Defensics
Sonar
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Coriant, CERT-FI, Next Generation Networks
Information Not Available