

Acunetix and SonarQube operate in the security and code quality domain. Acunetix appears to have the advantage in application security thanks to its detailed vulnerability scanning and integration with CI/CD, whereas SonarQube is stronger in code quality assurance with its extensive language support and code coverage analysis.
Features: Acunetix facilitates quick scan setups and produces comprehensive vulnerability reports. It excels at detecting SQL injection and XSS vulnerabilities. Continuous integration within DevOps environments and CI/CD tools enhances its utility in application security. SonarQube is noted for its extensive language support, offering tools for measuring code quality over time. It supports a wide range of programming languages and allows integration with CI/CD pipelines to automate code quality analysis.
Room for Improvement: Acunetix users often note its high pricing and suggest enhanced transparency and improvements in API testing and handling large-scale scans. Reduction in false positives and minimizing manual retesting are recommended. SonarQube faces criticism for its static scanning limitations, need for dynamic analysis capabilities, and better integration with DevOps environments. Users call for improved documentation and community support as well as lower pricing compared to other security tools.
Ease of Deployment and Customer Service: Acunetix offers deployment flexibility with options for on-premises, public, and hybrid clouds, though the cost is a major consideration. Technical support gets mixed reviews with some praising the 24/7 availability despite slow response times. SonarQube supports various deployment environments and benefits from strong community support, especially for the open-source edition, although some users find commercial support lacking.
Pricing and ROI: Acunetix is often seen as expensive with an inflexible domain-based pricing structure, yet it provides good ROI by improving security posture over time. Despite higher costs, the value delivered is deemed reasonable. SonarQube offers a free community edition, making it accessible, while its enterprise version is priced by lines of code, which some users find restrictive. Its contribution to code quality and reduction in technical debt suggest its value for organizations focusing on code assurance.
It saves a significant amount of time by covering attack surfaces.
I have seen a return on investment, as Acunetix helps reduce the man-days and effort needed for scanning bulk applications through automated assessments.
It is easily integrable with the CI/CD pipeline and supports multiple projects with its extensive plugin options.
I have seen a return on the investment from SonarQube Server (formerly SonarQube) because the value it adds relates to static code analysis and vulnerability assessments needed for our FDA approval process.
We see productivity increasing based on the fact that the code review is mostly automated, allowing the developer to fix the code themselves before assigning it to someone else to review, thus receiving that ROI.
For high-severity issues, they reach out within two to three hours, and for critical issues, a response is received within 15 minutes.
The technical support from Invicti is very good and fast.
Support staff not being familiar with the problem.
The community support is quite effective.
The customer service and support for SonarQube Cloud are responsive and helpful.
Integrating it into different solutions is straightforward.
Acunetix can handle increasing workloads and more applications easily.
There are limitations, and it seems to have fewer capabilities than Veracode.
It has been used in multiple projects and performs well.
I would rate the scalability of SonarQube Server as a 10 because we can configure the server to scan multiple projects based on the number of lines.
I think SonarQube Server (formerly SonarQube) is stable, and we did not face any problems unless there was a power outage or if the LAN cable was plugged out.
SonarQube is stable since we use it consistently; it performs reliably with minimal downtime, analyzing our code within our pipeline as a part of it.
It is widely used by most enterprise customers, making it a known and reliable tool.
The main concern is related to false positives; Acunetix needs to work on identifying valid and invalid findings.
I could supply it with maybe a Swagger file or a JSON file, and Acunetix would pick it up, scan all the endpoints according to the OWASP Top Ten, and give me remediation and actionable remediation reports.
Acunetix should have better integration with newer tools such as GitHub and Azure DevOps.
There is another website called Code Warrior that really takes you through the entire journey, so you can truly understand what the issue is along with some actual coding examples.
An AI feature should be integrated into SonarQube to resolve issues quickly; optimizing scanning performance for very large repositories and providing faster analysis times would enhance the developer experience, especially in large code bases with frequent commits.
I would like to see SonarQube Cloud provide more detailed solutions for fixing code issues, especially solutions related to CVEs.
The pricing cost is affordable for small and mid-sized organizations, and when compared to Checkmarx, it is significantly affordable, as Checkmarx is quite expensive.
We secured a special licensing model for penetration testing companies, which is cost-effective.
The pricing of Acunetix is pretty expensive and could be improved.
I would rate the pricing for SonarQube Server (formerly SonarQube) as an 8, where 1 is very cheap and 10 is very expensive, because Coverity is very expensive, and while SonarQube is not cheap, it is still less expensive than Coverity.
They always offer around a two-year contract, but we always take a one-year contract because it's expensive.
A more flexible pricing model would be beneficial since licensing by line of code can lead to quickly increasing costs.
Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.
The solution is excellent at detecting SQL injection and cross-site scripting vulnerabilities.
The best feature Acunetix offers is the centralized dashboard and the quality of reports it generates, which includes various options for selecting reports and developer options for directly sharing the reports with developers.
Now they have the capability of software composition analysis, which is a win-win situation and a great advantage because under one umbrella, you can get multiple scanning capabilities.
SonarQube provides strong security and governance capabilities by enforcing secure coding standards and consistent code quality across all teams.
Some of the static code analysis capabilities are the most beneficial.
| Product | Mindshare (%) |
|---|---|
| SonarQube | 10.6% |
| Acunetix | 2.4% |
| Other | 87.0% |


| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 7 |
| Large Enterprise | 19 |
| Company Size | Count |
|---|---|
| Small Business | 45 |
| Midsize Enterprise | 24 |
| Large Enterprise | 80 |
Acunetix is a robust web application security testing tool offering rapid scanning, user-friendly interfaces, and accurate vulnerability detection with minimal false positives. It supports both cloud and on-premises deployment, making it versatile for various security needs.
Acunetix is distinguished by its capability to identify critical vulnerabilities such as cross-site scripting and SQL injection with high precision. It integrates seamlessly with CI/CD tools, supporting continuous scanning and large-scale application management. The centralized dashboard and detailed automated reporting streamline operations. Despite its benefits, users suggest improvements like reducing false positives, flexible pricing, and enhanced API scanning. Better integration with platforms like GitHub and Azure DevOps is sought, alongside more comprehensive customization and faster scanning. Mobile application scanning and improved team collaboration tools are also desired.
What features make Acunetix stand out?Acunetix is widely implemented across industries undertaking web application security assessments, including those requiring penetration testing and vulnerability assessment. It ensures applications meet security protocols and complies with standards while fitting into CI/CD workflows for secure pre-release checks.
SonarQube leads automated code review, enhancing code quality and security in AI-driven SDLCs. It analyzes pull requests, providing developers with actionable feedback and AI-driven fixes before code merges. Trusted by top enterprises, it supports SaaS and self-managed deployments.
SonarQube supports a wide range of programming languages and integrates seamlessly with CI/CD tools like Jenkins. It is renowned for its static code analysis, code coverage, and security vulnerability detection. While its open-source foundation and scalability are praised, users seek enhanced integration across multiple languages, better security features, and improved documentation. Despite challenges, its ability to automate code inspections and ensure compliance with coding standards makes it essential in software development processes, facilitating continuous improvement.
What are the most important features?In industries like finance, healthcare, and automotive, SonarQube is leveraged for static code analysis, automating code inspections, and ensuring compliance with stringent standards. Teams integrate it into their CI/CD pipelines to maintain high-quality code, identify security vulnerabilities, and enhance code maintainability.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.