

OpenText Core Application Security and Sonatype Lifecycle compete in the application security category. Sonatype Lifecycle appears to have the upper hand due to its effective integration with IDEs and a low false-positive rate, which optimizes developer productivity.
Features: OpenText Core Application Security offers comprehensive scanning capabilities including SAST and DAST, providing a detailed dashboard for vulnerability tracking. It is particularly valued for early detection of security issues during development and providing detailed analysis and remediation suggestions. Sonatype Lifecycle is highly effective in managing open-source components, offering low false-positive rates and insights into component vulnerabilities. It provides actionable data and alternative recommendations for developers and integrates well with IDEs, enhancing seamless vulnerability detection during development cycles.
Room for Improvement: OpenText Core Application Security requires enhancements for integrating newer technologies and reducing scan times. False positives pose a recurring challenge, impacting development flow. It also lacks complete dynamic application security testing capabilities. Sonatype Lifecycle could improve its reporting flexibility and expand its language support. Users suggest the need for smoother integration with DevOps tools, enhanced real-time scan notifications, and better training resources, emphasizing clearer delineation between libraries and applications in reports.
Ease of Deployment and Customer Service: OpenText offers flexible deployment options, including on-premises, cloud, and hybrid solutions. However, customer feedback highlights slow support response times. Sonatype is praised for its responsive and effective global customer support. Its setup process is efficient, with clear guidance and robust integration capabilities, whereas OpenText could benefit from more streamlined setup processes in complex environments and enhanced initial support.
Pricing and ROI: OpenText Core Application Security's pricing is deemed high but justified by comprehensive security offerings, especially for large enterprises focused on security infrastructure, with users acknowledging its cost-effectiveness in enhancing security posture and reducing threats. Sonatype Lifecycle's pricing is competitive yet perceived as high due to advanced features and detailed research supporting vulnerability data. It offers scalable licensing models appealing to enterprises, emphasizing long-term cost savings through improved security and reduced breach risks.
There is definitive ROI if OpenText Core Application Security is deployed properly; it substantially reduces efforts in securing the solution while averting various application-related risks.
The open-source section of the code lifecycle is being automatically secured by Sonatype Lifecycle, which also offers a firewall for these repositories and SBOM manager.
We have seen cost savings and efficiency improvements as we now know what happens in what was previously a black box.
Support tickets often stay open for one month to three months, which leads to customer frustration.
I had direct interaction with them, which facilitated how we onboarded Fortify.
The technical support from OpenText is very good.
They are helpful when we raise any tickets.
Technical support from Sonatype is not much needed.
Customer support is responsive, typically replying in under two hours
If a customer wants to know the tools and the technology used for their application to scan their application, they provide less information on that.
OpenText Core Application Security is highly scalable; it is running on the cloud, and elasticity is one of the best points of a cloud environment.
Fortify is superior to many solutions because of its scalability and that it does not require massive compute capabilities for its SAST and sandboxing features.
JFrog is easier to configure for high availability as it does not require extra components.
The scalability of Sonatype Lifecycle is robust, especially with its SaaS offering and ease of resource scaling, whether horizontally or vertically.
OpenText Core Application Security is stable and has minimal downtime, benefitting from AWS cloud availability.
Sonatype Lifecycle is very stable, especially in the binary repository management use case for managing binary artifacts.
Sonatype Lifecycle is stable technologically with minimal encountered issues.
It would be beneficial if Fortify could check for CVEs (Common Vulnerabilities and Exposures) in third-party libraries, which I currently use a separate dependency checker tool for.
One thing I would highlight is if Fortify can focus more on the centralized dashboard of the tools because nowadays, tools such as SentinelOne also exist for identifying security issues, but they have a centralized dashboard that merges their cloud solution and application security side solution together.
I would say OpenText Core Application Security is not very user-friendly in terms of price; it is quite high.
We also noticed a lack of detailed information for configuring Sonatype Lifecycle for high availability and data recovery.
The visibility and clarity instructions are lacking. Users, especially those less experienced, are often baffled by the breadth of Sonatype Lifecycle Nexus IQ server's capabilities and may not know where to start.
Sonatype Container can accommodate bigger file sizes for artifacts and improve performance, especially when dealing with large files.
For larger numbers like our case with 1,000 user licenses, JFrog becomes much more cost-effective, roughly ten times cheaper than Sonatype.
The price and cost revolve primarily around the deployment aspect.
Fortify helps me find serious issues, such as developers inadvertently leaving access tokens, including API access tokens, in the source code.
On demand you have two levels of reports: the first from the tool, which is the same as we can get from Fortify on-premises, and a next level reporting made by experts from OpenText, leading to a more condensed and precise report as level three.
Additionally, you can integrate Fortify in CICD pipeline, so you get real-time updates about the security issues in your pipeline.
The integration into our CICD pipeline enables us to continuously monitor code changes and identify new vulnerabilities.
The most valuable feature for us is Sonatype Lifecycle's capability in identifying vulnerabilities.
Its management features are effective, and the UI is clear, making it easy to upload and manage artifacts.
| Product | Mindshare (%) |
|---|---|
| Sonatype Lifecycle | 2.0% |
| OpenText Core Application Security | 3.2% |
| Other | 94.8% |


| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 8 |
| Large Enterprise | 45 |
| Company Size | Count |
|---|---|
| Small Business | 13 |
| Midsize Enterprise | 8 |
| Large Enterprise | 31 |
OpenText Core Application Security offers robust features like static and dynamic scanning, real-time vulnerability tracking, and seamless integration with development platforms, designed to enhance code security and reduce operational costs.
OpenText Core Application Security is a cloud-based, on-demand service providing accurate and deep scanning capabilities with detailed reporting. Its integrations with development platforms ensure an enhanced security layer in the development lifecycle, benefiting users by lowering operational costs and facilitating efficient remediation. The platform addresses needs for intuitive interfaces, API support, and comprehensive vulnerability assessments, helping improve code security and accelerate time-to-market. Despite its strengths, challenges exist around false positives, report clarity, and language support, alongside confusing pricing and package options. Enhancements are sought in areas like CI/CD pipeline configuration, report visualization, scan times, and integration with third-party tools such as GitLab, container scanning, and software composition analysis.
What features define OpenText Core Application Security?Industries like mobile applications, e-commerce, and banking leverage OpenText Core Application Security for its ability to identify vulnerabilities such as SQL injections. Integrating seamlessly with DevSecOps and security auditing processes, this tool supports developers in writing safer code, ensuring secure application deployment and enhancing software assurance.
Sonatype Lifecycle enables enterprises to manage software risk efficiently with automation and robust data, facilitating quicker issue resolution throughout the software development lifecycle.
Sonatype Lifecycle reduces software development risks by providing automation and high-quality data management for open source and AI risks across the complete SDLC. Features like Golden Pull Requests, smart recommendations, reachability analysis, and zero effort fixes help streamline remediation and prevent breaking changes. This ensures contextual policy enforcement for unique security, legal, and quality standards. Sonatype Lifecycle delivers vulnerability, license, quality, and architectural insights, emphasizing real risk prioritization and offering comprehensive enterprise reporting to enhance security measures.
What are the most important features?Sonatype Lifecycle is leveraged across industries for security vulnerability scanning and license management during software development. Integrated into CI/CD pipelines, it automates third-party dependency checks and ensures governance, bolstering software supply chain security. Companies gain insights into application artifacts, ensuring compliance and aiding teams in addressing library issues across multiple programming languages.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.