Try our new research platform with insights from 80,000+ expert users

GitLab Premium vs Veracode comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

GitLab Premium
Ranking in Application Security Tools
23rd
Average Rating
8.4
Reviews Sentiment
5.6
Number of Reviews
4
Ranking in other categories
No ranking in other categories
Veracode
Ranking in Application Security Tools
2nd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Static Application Security Testing (SAST) (2nd), Container Security (8th), Software Composition Analysis (SCA) (3rd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (1st)
 

Featured Reviews

Bharadwaj Deepak Mohapatra - PeerSpot reviewer
DevOps Engineer at ENTERPRISE SYSTEM SOLUTIONS LIMITED
Have managed internal projects efficiently but face challenges with user interface and navigation
When discussing improvements for GitLab Premium, the main area is the GUI. GitHub's GUI is very good, offering many collaboration options and the ability to customize dashboards. GitHub's look and feel is superior, but GitLab Premium's dashboard is very simple. Regarding capabilities lacking in GitLab Premium, the main concern is the GUI. For example, in GitHub, there is a right side profile where settings can be directly accessed, and there is a direct section for developer mode with clear segregation. In GitLab Premium, when accessing users, confusion sometimes arises between root user and main user. There is an option for groups, but it is not direct. When clicking on groups, it goes to another section where groups must be found. This hierarchy could be more straightforward and direct. The biggest drawbacks of GitLab Premium are GUI and configuration. GUI is the primary concern, but other aspects are good.
reviewer2703864 - PeerSpot reviewer
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
Onboarding developers successfully while improving code security through IDE integration
Regarding room for improvement, we have some problems when onboarding new projects because the build process has to be done in a certain way, as Veracode analyzes the binaries and not the code by itself alone. If the process is not configured correctly, it doesn't work. That's one of the things that we are discussing with Veracode. Something positive that we've been able to do is submit formal feature requests to them, and they are working on them; they've already solved some of them. This encourages us to propose new ideas and improvements. Another improvement that we asked for this use case is to be able to configure how Veracode Fix proposes and fixes because sometimes it makes proposals using libraries that go against our architecture design made by the enterprise architecture team. For example, we want them to propose using another library, and that's something we already asked Veracode, and they are working on it. We want to specify when you see this kind of vulnerability, you can only propose these two options.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"GitLab Premium is much more reliable, quicker, faster, and basically easier to operate compared to GitHub."
"The biggest benefit from GitLab Premium is that both repository management systems are good, as both GitHub and GitLab are valuable, and the main advantage is that GitLab Premium has community support, making it good in all aspects for small organizations."
"The main benefits from advanced CI/CD capabilities in GitLab Premium include automation to pull and merge the codes together, and it's all done automatically."
"The main benefits I received from GitLab Premium are that I save money and streamline my management process of applications."
"One thing that I like about Veracode is that it is quite a good tool for dynamic application testing."
"One of the best things they offer is the scalability. The fact that you can work with it through the cloud means that if you have unintegrated business units, you don't have to worry about having a solution on-prem and having the network connection; you don't have to worry about giving up source code, you are just sending your binary files for most of the applications. So it scales much faster."
"I like Veracode's static analysis. It was one of the core development tools when I worked with a telecommunication company where we were delivering new features for various applications and purposes each week, such as CRM, data channels, compliance, traffic data, etc."
"The static scan and the detailed reports, which include issue information and permissions, are the most valuable features."
"The most valuable feature is Veracode SDP, which allows for something related to third-party vulnerabilities. When we build a product, we use a lot of third-party libraries instead of building everything from scratch. We just use a library which is already been built; we just use that component in our product. Sometimes, these libraries may have bugs or issues, and it's hard to keep track of them because we use thousands of them."
"Ad-hoc scanning during the development cycle and reports for audits are valuable features."
"Before Veracode, the application was deployed to the production server and there would be a lot of bugs and issues. Once we implemented the Veracode scan, the full deployment issues were drastically reduced."
"We like the fact that all the issues are identified and that Veracode provides sufficient information on how to resolve them."
 

Cons

"The automation part could be improved. Nowadays AI is being actively used, and if we could integrate something like ChatGPT with GitLab Premium, it would be easier for us to check logs and debug faster."
"The biggest drawbacks of GitLab Premium are GUI and configuration. GUI is the primary concern, but other aspects are good."
"There should be more APIs, especially in SCA, to get some results or automate some things."
"If Veracode was more diversified, as far as the number of platforms and the number of applications it could do in our favor, we would be using it even more. But there are a number of platforms it doesn't support. For example, I know they support C+, .NET, and Java, but there are certain platforms they don't support and that was disappointing."
"We would like the consolidation of all the different modules. This would help, so then we would be able to see analytics and results on one screen, like a single pane of glass."
"From the usability perspective, it is not up to date with the latest trends. It looks very old. Tools such as Datadog, New Relic, or infrastructure security tools, such as AWS Cloud, seem very user-friendly. They are completely web-based, and you can navigate through them pretty quickly, whereas Veracode is very rigid. It is like an old-school enterprise application. It does the job, but they need to invest a little more on the usability front."
"A nice addition would be if it could be extended for scenarios with custom cleansers."
"The area with the most room for improvement is the speed and responsiveness of the query, as it is usually very slow."
"Its cost and the long scanning times for large applications are the areas for improvement."
"Reporting. Some of the reporting features of Veracode do need improvement. They do not have the most robust access to data. That would be a bit more beneficial to a lot of our clients as well as our actual in-house staff. I've been talking to our program management at Veracode about that, and that is actually on their radar to have that improved, I think actually this year."
 

Pricing and Cost Advice

Information not available
"The pricing is fair."
"Its pricing is fair."
"Depending on the number of users, my company makes payments toward the solution's licensing costs."
"It is expensive. It depends on the use case, but it is very hard to find a pricing page on their website. Instead, they need to analyze your use case, but without knowing the entire project and how you're going to be using Veracode, how many scans you're going to do, if yours is a small business, it is very expensive and it affects ROI."
"Compared to other similar products, the licensing and pricing are definitely competitive. If you see Checkmarx as the market leader, then we are talking about Veracode being a fraction of the cost. You also have to consider your hidden costs: you need a team to maintain it, a server, and resources. From that point of view, Veracode is great because the cost is really a fraction of many competitors."
"Its cost for what we needed it for was too high. It wasn't too high for other companies and it was competitively priced, but for us, it just didn't fit. We did plan to use it and increase the usage. In the end, it may have been abandoned because of the cost, but I'm not a hundred percent sure. So, even though we had planned on using it more and more, because of the cost and the business conditions of things, we didn't have the opportunity to really use it more."
"I think licensing needs to be changed or updated so that it works with adjustments. Pricing is expensive compared to the amount of scanning we perform."
"Veracode is expensive. Some of its products are expensive. I don't think it's way more expensive than its competitors. The dynamic is definitely worth it, as I think it's cheaper than the competitors. The static scan is a little bit more expensive, around 20 percent more expensive. The manual pen test is more expensive, but it is an expensive service because it's a manual pen test and we also do retests. I don't think it is way more expensive than the competitors, but it's about 15 to 20 percent more expensive."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
879,853 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business70
Midsize Enterprise44
Large Enterprise114
 

Questions from the Community

What needs improvement with GitLab Premium?
GitLab Premium is quite solid now, though there is always room for improvement. They provide a feature for integrating it with provisioning tools such as Terraform and others, but if they could pro...
What advice do you have for others considering GitLab Premium?
I require clarification on which feedback about the effectiveness of GitLab Premium for audit events you are asking about. Overall, I give GitLab Premium a final rating of nine out of ten for the p...
What is your experience regarding pricing and costs for GitLab Premium?
GitLab Premium is affordable in terms of pricing, while GitHub is a bit pricier. If working with a much more complex and vast organization at the enterprise level, GitHub would be the choice. If op...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What do you like most about Veracode Static Analysis?
I like its integration with GitHub. I like using it from GitHub. I can use the GitHub URL and find out the vulnerabilities.
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Comparisons

No data available
 

Also Known As

No data available
Crashtest Security , Veracode Detect
 

Overview

Information not available
 

Sample Customers

Information Not Available
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about GitLab Premium vs. Veracode and other solutions. Updated: December 2025.
879,853 professionals have used our research since 2012.