Try our new research platform with insights from 80,000+ expert users

GitHub Advanced Security vs SonarQube comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 5, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

GitHub Advanced Security
Ranking in Application Security Tools
10th
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
12
Ranking in other categories
No ranking in other categories
SonarQube
Ranking in Application Security Tools
1st
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
134
Ranking in other categories
Static Application Security Testing (SAST) (1st), Software Development Analytics (1st)
 

Mindshare comparison

As of December 2025, in the Application Security Tools category, the mindshare of GitHub Advanced Security is 5.8%, down from 7.5% compared to the previous year. The mindshare of SonarQube is 19.2%, down from 26.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools Market Share Distribution
ProductMarket Share (%)
SonarQube19.2%
GitHub Advanced Security5.8%
Other75.0%
Application Security Tools
 

Featured Reviews

Sabna Sainudeen - PeerSpot reviewer
Director, Application Security at Carlsberg
Seamlessly integrates into developer environment for streamlined code scanning
GitHub Advanced Security should look into API security issues, which they currently do not. Additionally, open-source security vulnerabilities are not getting updated in a timely manner. There are features in GitHub Advanced Security that cannot be used within Microsoft, which is strange since they are the same company. It should also focus on developing a software bill of materials (SBOM) to see all open software used in one place.
KH
Sr Software Engineering Supervisor at Mozarc Medical
Gains control over rule customization and achieves reliable vulnerability assessment
The deployment process took me about 2 or 3 hours to deploy SonarQube Server (formerly SonarQube), although I do not remember exactly since it was done about 2 years back. Currently, about 10 of my developers are using SonarQube Server (formerly SonarQube) in my company. I do not have plans to increase the usage of SonarQube Server (formerly SonarQube) in the future as there will not be any requirement to increase. I am a senior software engineer and supervisor at Mozark Medical. My corporate email address is karthik.k.a.r.t.h.i.k.h.a.r.p.a.n.h.a.l.l.i@mozarkmedical.com. Overall, I would rate SonarQube Server (formerly SonarQube) as a 9 out of 10.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"GitHub Advanced Security's secret scanning is good."
"GitHub Advanced Security is a very developer-friendly solution that is integrated within my development environment."
"It ensures user passwords or sensitive information are not accidentally exposed in code or reports."
"The product's most valuable features are security scan, dependency scan, and cost-effectiveness."
"The best features of GitHub Advanced Security are its flexibility and the multiple options it has compared to other tools."
"Dependency scanning is a valuable feature."
"GitHub provides advanced security, which is why the customers choose this tool; it allows them to rely solely on GitHub as one platform for everything they need."
"GitHub Advanced Security uses artificial intelligence in the backend, specifically CodeQL, to analyze code and provide fewer but more reliable findings, so there are less false positives."
"SonarQube is scalable. My company has 50 users."
"The software quality gate streamlines the product's quality."
"We have worked with the support from SonarQube and we have had good experiences."
"It has very good scalability and stability."
"SonarQube Server (formerly SonarQube) is very stable."
"SonarQube is designed well making it easy to use, simple to identify issues and find solutions to problems."
"I find SonarQube Cloud to be very user-friendly with an easy-to-use interface."
"The initial setup is simple. It requires some security, but it's simple."
 

Cons

"A more refined approach, categorizing and emphasizing specific vulnerabilities, would be beneficial."
"Maybe make it compatible with more programming languages. Have a customized ruleset where the end-user can create their own rules for scanning."
"The report limitations are the main issue."
"An area of GitHub Advanced Security that has room for improvement is customization."
"There could be DST features included in the product."
"GitHub Advanced Security should look into API security issues, which they currently do not. Additionally, open-source security vulnerabilities are not getting updated in a timely manner."
"For GitHub Advanced Security, I would like to see more support for various programming languages."
"We used additional third-party solutions, but we replaced them with GitHub Advanced Security, even though I do not have a very good opinion about GitHub Advanced Security."
"SonarQube could improve its static application security testing as per the industry standard."
"Monitoring is a feature that can be improved in the next version."
"The documentation needs improvement on optimizing build time for seamless CI/CD integration with our Android apps."
"A robust credential scanner would be a huge bonus as it would remove the need for yet another niche product."
"Ease of use/interface."
"We had some issues where the Quality Gate check sometimes gets stuck and it is unclear."
"Expression of common vulnerabilities and exposures is not always current."
"I am not very pleased with the technical debt computation."
 

Pricing and Cost Advice

"The solution is expensive."
"The current licensing model, which relies on active commitments, poses challenges, particularly in predicting and managing growth."
"A low cost long-term solution for non-critical situations."
"We did not purchase a license (required for C++ support), but this option was considered."
"It is very expensive. Its price should be improved."
"The costs for this application, for the kind of job it does, are pretty decent."
"We're using their free Community Edition version."
"It's an open-source product."
"It's a bit expensive for us. The currency rate of the dollar is a problem but it may be fine for other countries."
"This product is open source and very convenient."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
877,451 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
11%
Manufacturing Company
8%
Government
7%
Financial Services Firm
14%
Computer Software Company
14%
Manufacturing Company
14%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise4
Large Enterprise7
By reviewers
Company SizeCount
Small Business41
Midsize Enterprise24
Large Enterprise79
 

Questions from the Community

What do you like most about GitHub Advanced Security?
It is a stable solution...It is a scalable solution as it can handle new applications along with the analysis part.
What needs improvement with GitHub Advanced Security?
An area of GitHub Advanced Security that has room for improvement is customization.
What is your primary use case for GitHub Advanced Security?
I use GitHub Advanced Security. I work with GitHub. I am an implementer of GitHub. For migrations, my clients and I typically use GitHub Advanced Security.
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
 

Also Known As

No data available
Sonar, SonarQube Cloud
 

Overview

Find out what your peers are saying about GitHub Advanced Security vs. SonarQube and other solutions. Updated: December 2025.
877,451 professionals have used our research since 2012.