We performed a comparison between SonarCloud and SonarQube based on our users’ reviews in four categories. After reading all of the collected data, you can find our conclusion below.
Comparison Result: Based on the parameters we compared, SonarQube comes out ahead of SonarCloud. Although both products have valuable features and can be estimated as high-end solutions, our reviewers found that SonarCloud lacks technical support.
"SonarCloud is overall a good tool for identifying code smells, bugs, and code duplication, but we've found that using Android Lint is more effective for our needs."
"The solution provides continuous code analysis which has improved the quality of our code. It can raise alarms on vulnerabilities with immediate reports on the dashboard. Few things are false positives and we can customize the rules."
"The solution can be installed locally."
"Its dashboard provides a unified view of various code quality metrics, including code duplication, unit test coverage, and security hotspots."
"For what it is meant to do, it works pretty well."
"The reports from SonarCloud are very good."
"The most valuable feature of SonarCloud is its overall performance."
"I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is."
"The product itself has a friendly UI."
"We use this solution for qualitative coding. We make use of the SonarLint plugin as well as the dashboard."
"SonarQube is good in terms of code review and to report on basic vulnerabilities in your applications."
"This solution has the capability to analyze source code in almost all the languages in the market."
"It helps our developers work more efficiently as we can identify things in a code prior to it being pushed to where it needs to go."
"The solution's user interface is very user-friendly."
"I like that it helps us maintain our work quality and code security."
"My focus is mainly on the DevOps pipeline side of things, and from my perspective, the ease of use and configuration is valuable. It is pretty straightforward to take a deployment pipeline or CI/CD pipeline and integrate SonarQube into it."
"We had some issues with the scanner."
"It would be helpful if notifications could go out to an extra person."
"SonarCloud's UI needs enhancement."
"The reports could improve by providing more information. We are not able to use the reports in our operation until they are improved. Additionally, if the vendor provided more customization capabilities it would be a benefit."
"The documentation needs improvement on optimizing build time for seamless CI/CD integration with our Android apps."
"I've been told by the developers that the solution is too limited. It's not testing enough within the containers."
"There's room for improvement in the configuration process, particularly during the initial setup phase."
"The solution needs to improve its customization and flexibility."
"The product must improve security analysis."
"I am not very pleased with the technical debt computation."
"The time it took for me to do the whole process was approximately two hours because I had to download, read the documentation, and do the configurations."
"We did have some trouble with the LDAP integration for the console."
"The exporting capabilities could be improved. Currently, exporting is fully dependent on the SonarQube environment."
"The solution is a bit lacking on the security side, in terms of finding and identifying vulnerabilities."
"The handling of the contents of Docker container images could be better."
"A better design of the interface and add some new rules."
SonarCloud is ranked 10th in Application Security Testing (AST) with 10 reviews while SonarQube is ranked 1st in Application Security Testing (AST) with 108 reviews. SonarCloud is rated 8.4, while SonarQube is rated 8.0. The top reviewer of SonarCloud writes "Beneficial vulnerability discovery, simple to maintain, and proactive support". On the other hand, the top reviewer of SonarQube writes "Easy to integrate and has a plug-in that supports both C and C++ languages". SonarCloud is most compared with Veracode, Checkmarx One, OWASP Zap, GitLab and Coverity, whereas SonarQube is most compared with Checkmarx One, Coverity, Veracode, Snyk and Sonatype Lifecycle. See our SonarCloud vs. SonarQube report.
See our list of best Application Security Testing (AST) vendors.
We monitor all Application Security Testing (AST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.