Try our new research platform with insights from 80,000+ expert users

Fortify Static Code Analyzer vs Klocwork comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.8
Fortify Static Code Analyzer identifies vulnerabilities early, enhancing ROI by preventing security breaches, though ROI varies among users.
Sentiment score
7.9
Klocwork enhances efficiency and code quality, saving time and simplifying compliance, positively impacting organizational operations.
The main ROI factors include efficiency and how we meet compliance standards for various automotive requirements.
 

Customer Service

Sentiment score
6.7
Fortify Static Code Analyzer's support is responsive and proactive, with some delays in enhancements, and users prefer live chat.
Sentiment score
7.3
Klocwork customer service is responsive and knowledgeable, offering efficient global support but needs better prioritization in ticket management.
The technical support has been good because we always received answers to our questions.
The customer service and support for Fortify Static Code Analyzer are better than those for LoadRunner.
The issue is not about the knowledge of the support but about the prioritization of the tickets they handle.
The customer support team is very responsive, proactive, and engages in conversations to ensure our needs are met.
During the initial phase when I did interact with the vendor, the support was satisfactory.
 

Scalability Issues

Sentiment score
7.8
Fortify Static Code Analyzer is praised for scalability and resource management, despite some scaling time improvement needs.
Sentiment score
7.2
Klocwork effectively supports diverse team sizes and projects with configurable options for static code analysis and scalability.
Fortify Static Code Analyzer integrates well and is scalable.
Klocwork supports our scalability needs without issues, even as project volumes increase.
The program-to-program enablement is scalable.
 

Stability Issues

Sentiment score
7.5
Fortify Static Code Analyzer is stable with good performance if system requirements and guidelines are properly followed.
Sentiment score
7.2
Klocwork is stable and reliable but requires high computing power and may face update and GUI challenges.
The stability of Fortify Static Code Analyzer is generally good.
I would rate the product stability as an eight.
Installation is easy, and the solution is stable.
 

Room For Improvement

Fortify Static Code Analyzer needs language support and integration improvements, modern interface, affordable pricing, and AI-enhanced vulnerability management.
Klocwork requires improvements in language support, dynamic analysis, integration, and flexibility, reducing false positives and enhancing user experience.
We are not ready to transfer our code without control to AI instruments.
It would be really helpful to include trending vulnerabilities and how to manage them.
It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers.
We would like Klocwork to connect to Git and notify developers of issues tied to specific commits.
Klocwork sometimes provides too many additional warnings which require expertise to manage.
There are too many warnings, and it requires expertise to determine the correct category for them.
 

Setup Cost

Fortify Static Code Analyzer offers flexible enterprise licensing, competitive pricing, and comprehensive tools, but with potentially high costs.
Klocwork offers flexible enterprise pricing with varied license types, competitive costs, and suitability for different organization sizes and needs.
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs.
My experience with the pricing, setup costs, and licensing has been good.
It is less expensive than Coverity.
Klocwork was competitively priced, making it a cost-effective solution for us.
Klocwork's pricing seems attractive, as it uses a per-user license model that does not have a lot of overhead.
 

Valuable Features

Fortify Static Code Analyzer enhances code security with broad language support, real-time feedback, and seamless integration for risk management.
Klocwork improves code quality and development efficiency with advanced analysis features, CI/CD integration, and multi-language support.
Fortify Static Code Analyzer has the capability of giving fewer false positives compared to other tools.
The most impactful feature of Fortify Static Code Analyzer in identifying vulnerabilities is the ratio of total number of vulnerabilities to false positives.
The most valuable feature of Fortify Static Code Analyzer is its extensive language support, covering many languages from legacy ones to the newest.
The most valuable feature of Klocwork is the static analysis tools, which help identify potential security threats and errors.
Its integration with the CI/CD pipeline has helped streamline the software development process.
It takes just half a day to set up.
 

Categories and Ranking

Fortify Static Code Analyzer
Ranking in Static Code Analysis
2nd
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
19
Ranking in other categories
No ranking in other categories
Klocwork
Ranking in Static Code Analysis
5th
Average Rating
8.0
Reviews Sentiment
7.1
Number of Reviews
24
Ranking in other categories
Application Security Tools (18th), Static Application Security Testing (SAST) (16th)
 

Mindshare comparison

As of June 2025, in the Static Code Analysis category, the mindshare of Fortify Static Code Analyzer is 11.7%, up from 10.0% compared to the previous year. The mindshare of Klocwork is 4.0%, up from 3.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Code Analysis
 

Featured Reviews

Aphiwat Leetavorn. - PeerSpot reviewer
Provides extensive language support and enhances secure coding practices
The deployment of Fortify Static Code Analyzer needs to be simplified. It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers. This change would facilitate easier installations and ensure all necessary components are connected and ready to use.
AnirbanSarkar - PeerSpot reviewer
Lets you find defects during the development phase, so you don't have to wait till the development is over to find and address flaws
What needs improvement in Klocwork, compared to other products in the market, is the dashboard or reporting mechanisms that need to be a bit more flexible. The Klocwork dashboard could be improved. Though it's good, it's not as good as some of the other products in the market, which is a problem. The reporting could be more detailed and easier to sort out because sorting in Klocwork could be a bit more time-consuming, mainly when sorting defects based on filters, compared to how it's done on other tools such as Coverity. What I'd like added in the next release of Klocwork is the peer code review Cahoots which used to be a part of Klocwork, and the architecture analysis and both have been taken out of Klocwork. I found the two critical for specific deployments, so if those can be brought back to Klocwork, that would be very good.
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
856,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
29%
Computer Software Company
13%
Manufacturing Company
10%
Government
7%
Educational Organization
24%
Manufacturing Company
22%
Computer Software Company
11%
Comms Service Provider
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs. There are some features that require additional purchases,...
What needs improvement with Fortify Static Code Analyzer?
I'm not sure if Fortify Static Code Analyzer has AI capabilities. Currently, this solution doesn't quite have what we need. For example, it cannot build a vulnerability rating using AI based on our...
What do you like most about Klocwork?
It's integrated into our CI, continuous integration.
What is your experience regarding pricing and costs for Klocwork?
Klocwork was competitively priced, making it a cost-effective solution for us.
What needs improvement with Klocwork?
We would like Klocwork to connect to Git and notify developers of issues tied to specific commits. Currently, this feature is absent, but we have suggested it to the team.
 

Also Known As

Fortify Static Code Analysis SAST
No data available
 

Overview

 

Sample Customers

Information Not Available
ACCESS Co Ltd, Risk-AI, Winbond Electronics, Bristol-Myers Squibb Pharmaceutical Research Institute, University of Southern California, Alebra Technologies, SIMULIA, Risk Management Solutions, Brigham Young University, SRD, HRL
Find out what your peers are saying about Fortify Static Code Analyzer vs. Klocwork and other solutions. Updated: April 2025.
856,873 professionals have used our research since 2012.