Parasoft SOAtest and SonarQube Cloud compete in the software testing and code quality space. Parasoft SOAtest's extensive API and web service testing capabilities give it an edge in complex testing environments, while SonarQube Cloud excels in code quality analysis and security vulnerability detection for developers.
Features: Parasoft SOAtest supports a wide array of protocols and scripting languages, offering script automation and data-driven test capabilities, making it ideal for comprehensive API testing. Its integration with CI tools is robust, allowing seamless automation in enterprise settings. SonarQube Cloud specializes in continuous code quality analysis and security vulnerability checks, providing real-time insights into code health and minimizing vulnerabilities with minimal maintenance. Its effectiveness in identifying code issues at the developer level is a key strength.
Room for Improvement: Parasoft SOAtest users find its usability challenging, lacking an intuitive design and comprehensive reporting. Configuration issues, workspace corruption, and tool integration are areas needing enhancement. SonarQube Cloud could benefit from improved flexibility and documentation, especially during initial setup. Users identify infrastructure setup and report quality as areas for potential improvement, despite reduced false positives.
Ease of Deployment and Customer Service: SOAtest is typically on-premises, with praised customer support and technical assistance. However, troubleshooting complex scenarios is limited without external resources. SonarQube Cloud's public cloud deployment is easy with low maintenance but faces challenges in SaaS configuration and customization. Its customer service is adequate, though users suggest improving interaction efficiency.
Pricing and ROI: Parasoft SOAtest is often considered expensive due to its features, with complexity in licensing seen as a barrier for widespread use. The ROI from automation benefits is noted by users. SonarQube Cloud is viewed as cost-effective, with pricing based on code lines analyzed, suiting smaller teams. Larger code volumes can increase costs. Both products are valued investments, reflecting their respective strengths in test automation and code analysis efficiency.
We found Parasoft SOAtest to be quick in building up test patterns, allowing us to create complex tests efficiently.
It is easily integrable with the CI/CD pipeline and supports multiple projects with its extensive plugin options.
The product is designed for bigger clients, while smaller companies are often put aside.
The customer service and support for SonarQube Cloud are responsive and helpful.
Integrating it into different solutions is straightforward.
There are limitations, and it seems to have fewer capabilities than Veracode.
It has been used in multiple projects and performs well.
SonarQube Cloud is a scalable product, and I rate its scalability at seven out of ten.
It is a quite stable solution.
From my team's feedback, it is almost an eight out of ten.
It did not support enough of the protocols or cryptography formats we needed, which led us to create our own solutions.
Static code analysis is good, but the product lacks dynamic code scanning capabilities, an area where Veracode excels.
To improve SonarQube Cloud (formerly SonarCloud), it should excel in all these domains.
I would like to see SonarQube Cloud provide more detailed solutions for fixing code issues, especially solutions related to CVEs.
Parasoft SOAtest is expensive, but it was acquired because the company was dissatisfied with Quick Test Pro.
From my experience, SonarQube Cloud (formerly SonarCloud) is very expensive for small companies.
SonarQube Cloud is roughly equivalent in cost to Veracode, maybe a little cheaper.
We used the open-source version of SonarQube Cloud for its minimum features and did not license its extensive capabilities.
Parasoft SOAtest is very good at ensuring tests don't pass or fail until they genuinely pass or fail.
I use SonarQube Cloud (formerly SonarCloud) to check the quality of developer code and identify vulnerabilities.
The most valuable features of SonarQube Cloud (formerly SonarCloud) include code inspection, addressing technical debt, and identifying security vulnerabilities.
It is integrated easily with the CI/CD pipeline, saving time and cost.
Parasoft SOAtest delivers fully integrated API and web service testing capabilities that automate end-to-end functional API testing. Streamline automated testing with advanced codeless test creation for applications with multiple interfaces (REST & SOAP APIs, microservices, databases, and more).
SOAtest reduces the risk of security breaches and performance outages by transforming functional testing artifacts into security and load equivalents. Such reuse, along with continuous monitoring of APIs for change, allows faster and more efficient testing.
SonarQube Cloud offers static code analysis and application security testing, seamlessly integrating into CI/CD pipelines. It's a vital tool for identifying vulnerabilities and ensuring code quality before deployment.
SonarQube Cloud is widely used for its ability to integrate with tools like GitHub, Jenkins, and Bitbucket, providing critical feedback at the pull request level. It's designed to help organizations maintain clean code by acting as a quality gate. This service supports development methodologies including sprints and Kanban for ongoing vulnerability management. While appreciated for its dashboard and integration capabilities, some users find initial setup challenging and note the need for enhanced documentation. The recent addition of mono reports and microservices support offers deeper insights into security and code quality, though container testing limitations and false positives are noted drawbacks. Manual intervention is sometimes required to address detailed reporting, with external tools being necessary for comprehensive analysis. Notifications for larger teams during serious issues and streamlined integration of new features are also areas of improvement.
What are the key features of SonarQube Cloud?In specific industries, SonarQube Cloud finds application in finance and healthcare where code integrity and security are paramount. It allows teams to identify critical vulnerabilities early and ensures that software development aligns with industry regulations and standards. By continuously analyzing code, it aids organizations in deploying secure and reliable applications, fostering trust and compliance.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.