Try our new research platform with insights from 80,000+ expert users

HCL AppScan vs SonarQube Cloud (formerly SonarCloud) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 21, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
2.1
HCL AppScan enhances architecture with fewer errors and improved security, achieving 50% return and 20% cost savings.
Sentiment score
4.9
SonarQube Cloud helps improve code quality and save costs, though ROI measurement is challenging due to rising expenses.
It is easily integrable with the CI/CD pipeline and supports multiple projects with its extensive plugin options.
The product is designed for bigger clients, while smaller companies are often put aside.
 

Customer Service

Sentiment score
5.4
HCL AppScan's support is responsive with mixed reviews, facing regional challenges and lagging behind competitors like Veracode.
Sentiment score
6.4
SonarQube Cloud offers good community support but needs better documentation and technical engagement, with mixed feedback on support responsiveness.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
Integrating it into different solutions is straightforward.
The customer service and support for SonarQube Cloud are responsive and helpful.
Some of my teammates have interacted with support by raising tickets, and their issues were successfully resolved.
 

Scalability Issues

Sentiment score
4.9
HCL AppScan is scalable yet varies by license, integration issues, infrastructure compatibility, and CI/CD pipeline design effectiveness.
Sentiment score
5.5
SonarQube Cloud is praised for scalability, though billing and comparisons suggest areas for improvement and expansion potential.
There are limitations, and it seems to have fewer capabilities than Veracode.
It has been used in multiple projects and performs well.
SonarQube Cloud is a scalable product, and I rate its scalability at seven out of ten.
 

Stability Issues

Sentiment score
6.8
HCL AppScan is stable and reliable, with minor hardware issues, improved by recent upgrades enhancing performance and stability.
Sentiment score
6.8
SonarQube Cloud is stable and reliable but needs improved documentation, integration, onboarding, and community support for better usability.
From my team's feedback, it is almost an eight out of ten.
It is a quite stable solution.
 

Room For Improvement

HCL AppScan requires improvements in vulnerability detection, usability, integration, performance, support, pricing, and language/codebase compatibility to stay competitive.
SonarQube Cloud users seek improvements in reporting, integration, customization, and documentation, alongside dynamic analysis and automated vulnerability detection.
I need a solution that can bring together three key areas: vulnerabilities, static scanning, and misarchitecture.
I would like to see SonarQube Cloud provide more detailed solutions for fixing code issues, especially solutions related to CVEs.
Static code analysis is good, but the product lacks dynamic code scanning capabilities, an area where Veracode excels.
 

Setup Cost

HCL AppScan is considered expensive but cost-effective, with varied pricing opinions influenced by its premium features and discounts.
SonarQube Cloud's pricing is scalable yet potentially costly for smaller companies, though efficient for minimizing repeated scans.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
SonarQube Cloud is roughly equivalent in cost to Veracode, maybe a little cheaper.
From my experience, SonarQube Cloud (formerly SonarCloud) is very expensive for small companies.
We used the open-source version of SonarQube Cloud for its minimum features and did not license its extensive capabilities.
 

Valuable Features

HCL AppScan detects vulnerabilities, integrates with agile processes, offers scalability, user-friendly features, and AI-enhanced rapid scanning for security.
SonarQube Cloud enhances code quality with seamless CI/CD integration, detailed reports, and supports startups and mid-sized businesses.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
I find SonarQube Cloud very easy to use and simple to integrate initially.
It suggests fixes where needed, enabling the team to code better and maintain high code quality.
The most valuable features of SonarQube Cloud (formerly SonarCloud) include code inspection, addressing technical debt, and identifying security vulnerabilities.
 

Categories and Ranking

HCL AppScan
Ranking in Static Application Security Testing (SAST)
14th
Average Rating
7.6
Reviews Sentiment
5.9
Number of Reviews
43
Ranking in other categories
Application Security Tools (15th), Dynamic Application Security Testing (DAST) (1st)
SonarQube Cloud (formerly S...
Ranking in Static Application Security Testing (SAST)
9th
Average Rating
8.2
Reviews Sentiment
6.2
Number of Reviews
17
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2025, in the Static Application Security Testing (SAST) category, the mindshare of HCL AppScan is 2.5%, down from 2.6% compared to the previous year. The mindshare of SonarQube Cloud (formerly SonarCloud) is 4.2%, down from 5.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Market Share Distribution
ProductMarket Share (%)
SonarQube Cloud (formerly SonarCloud)4.2%
HCL AppScan2.5%
Other93.3%
Static Application Security Testing (SAST)
 

Featured Reviews

AnshulTomar - PeerSpot reviewer
Scalable platform with efficient static and dynamic testing features
We use the product for Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST). By integrating AppScan into our CI/CD pipelines, aligned with Agile methodologies, we ensure that security testing becomes an integral part of the software development lifecycle The…
Archana Verma - PeerSpot reviewer
Provides valuable insights on code vulnerabilities and integrates seamlessly with CI/CD pipelines
I find SonarQube Cloud to be very user-friendly with an easy-to-use interface. It provides detailed code smell reports and insights on hotspots, which can later represent security vulnerabilities. It gives precise reports compared to Coverity and has a slightly lower number of false positives. It is integrated easily with the CI/CD pipeline, saving time and cost. It provides information on upcoming vulnerability details and loopholes that might turn into vulnerabilities.
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
872,655 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
12%
Government
10%
Manufacturing Company
9%
Computer Software Company
16%
Manufacturing Company
10%
Financial Services Firm
10%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business13
Midsize Enterprise6
Large Enterprise31
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise3
Large Enterprise4
 

Questions from the Community

What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
AppScan needs to improve its handling of false positives. It also requires enhancements in customer support, similar to what Veracode provides. Regularly scheduling calls with clients to discuss fe...
What is your primary use case for HCL AppScan?
The primary use case for AppScan is for security purposes. I compare AppScan with other tools such as Veracode. We use AppScan for vulnerability detection and auto-remediation of vulnerabilities wi...
What do you like most about SonarCloud?
Recently, they introduced support for mono reports and microservices, which is a noteworthy development as it provides a more detailed view of each service.
What is your experience regarding pricing and costs for SonarCloud?
From my experience, SonarQube Cloud (formerly SonarCloud) is very expensive for small companies. It would be a great improvement if the price for smaller companies were reduced, as I do not have th...
What needs improvement with SonarCloud?
Sometimes, there are tracking issues. It has its own graphical GUI where we can track everything. Since most of our projects are open source, there are multiple features which can be improved. For ...
 

Also Known As

IBM Security AppScan, Rational AppScan, AppScan
No data available
 

Overview

 

Sample Customers

Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
Information Not Available
Find out what your peers are saying about HCL AppScan vs. SonarQube Cloud (formerly SonarCloud) and other solutions. Updated: September 2025.
872,655 professionals have used our research since 2012.