We performed a comparison between HCL AppScan, Klocwork, and SonarQube based on real PeerSpot user reviews.
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Tools."The solution is easy to use."
"It has certainly helped us find vulnerabilities in our software, so this is priceless in the end."
"IBM AppScan has made our work easy, as we can do four to five scans of websites at a time, which saves time when it comes to vulnerability."
"The solution offers services in a few specific development languages."
"The most valuable feature of the solution is Postman."
"We are now deploying less defects to production."
"It's generally a very user-friendly tool. Anyone can easily learn how to scan"
"The HCL AppScan turnaround time for Burp Suite or any new feature request is pretty good, and that is why we are sticking with the HCL."
"The most valuable feature of Klocwork is finding defects while you're doing the coding. For example, if you have an IDE plug-in of Klocwork on Visual Studio or Eclipse, you can find the faults; similar to using spell check on Word, you can find out defects during the development phase, which means that you don't have to wait till the development is over to find the flaws and address the deficiencies. I also find language support in Klocwork good because it used to support only C, C++, C#, and Java, but now, it also supports Java scripts and Python."
"The reporting helps us understand the trend of our results and whether we improve over time. We can see the history within Klocwork's server architecture and know that we're making things better. It creates a great story for our management. We can demonstrate value and how our software is developing over time."
"There is a central Klocwork server at our headquarter in France so we connect the client directly to the server on-premises remotely."
"One can increase the number of vendors, so the solution is scalable."
"The ability to create custom checkers is a plus."
"Klocwork's most valuable feature is the static code analysis feature. It detects the potential problem earlier to allow the developer to receive feedback quickly and then address it before it becomes a problem."
"We like using the static analysis and code refactoring, which are very valuable because of our requirements to meet safety critical levels and reliability."
"The tool helps the team to think beforehand about corner cases or potential bugs that might arise in real-time."
"It easily ties into our continuous integration pipeline."
"The initial setup is simple. It requires some security, but it's simple."
"All the features of the solution are quite good."
"The most valuable function is its usability."
"It helps our developers work more efficiently as we can identify things in a code prior to it being pushed to where it needs to go."
"Improve the code coverage and evaluates the technical steps and percentage of code being resolved."
"The most valuable feature of this solution is that it is free."
"This has improved our organization because it has helped to find Security Vulnerabilities."
"AppScan is too complicated and should be made more user-friendly."
"They could add a software component analysis tool."
"Many silly false positives are produced."
"They should have a better UI for dashboards."
"The solution often has a high number of false positives. It's an aspect they really need to improve upon."
"I think being able to search across more containers, especially some of the docker elements. We need a little tighter integration there. That's the only thing I can see at this point."
"Visibility is an issue for us. Our partners do not know we have integrations with some of IBM products."
"There is not a central management for static and dynamic."
"Every update that we receive requires of us a lengthy and involved process."
"This solution could be improved if they offered support of more languages including Ada and Golang. They currently only support seven languages."
"The main problem is that since it only parses the code, the warnings or the problems that are given as a result of the report can sometimes require a lot of effort to analyze."
"I would like to see better codes between projects and a more user-friendly desktop in the next release."
"We bought Klocwork, but it was limited to one little program, but the program is now sort of failing. So, we have a license for usage on a program that is sort of failing, and we really can't use the license on anything else."
"I believe it should support more languages, such as Python and JavaScript."
"We'd like to see integration with Agile DevOps and Agile methodologies."
"What needs improvement in Klocwork, compared to other products in the market, is the dashboard or reporting mechanisms that need to be a bit more flexible. The Klocwork dashboard could be improved. Though it's good, it's not as good as some of the other products in the market, which is a problem. The reporting could be more detailed and easier to sort out because sorting in Klocwork could be a bit more time-consuming, mainly when sorting defects based on filters, compared to how it's done on other tools such as Coverity."
"SonarQube could be improved by implementing inter-procedural code analysis capabilities, allowing for a more comprehensive detection of defects and vulnerabilities across the entire codebase."
"In the next release, I would like to have notifications because now, it is a bit difficult. I think that's a feature which we could add there and it would benefit the users as well. For every full request, they should be able to see their bugs or vulnerability directly on the surface."
"The security in SonarQube could be better."
"From a reporting perspective, we sometimes have problems interpreting the vulnerability scan reports. For example, if it finds a possible threat, our analysts have to manually check the provided reports, and sometimes we have issues getting all the data needed to properly verify if it's accurate or not."
"The solution could improve by having better-consulting services."
"The interface could be a little better and should be enhanced."
"There are limitations to the free version that limit development options as far as languages."
"You may need to purchase add-ons to get the useability you desire."