No more typing reviews! Try our Samantha, our new voice AI agent.

SonarQube vs Trend Micro Cloud App Security [EOL] comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 26, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

SonarQube
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
137
Ranking in other categories
Application Security Tools (1st), Static Application Security Testing (SAST) (1st), Software Development Analytics (1st)
Trend Micro Cloud App Secur...
Average Rating
8.2
Reviews Sentiment
6.2
Number of Reviews
9
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Vitthal Gole - PeerSpot reviewer
Devops Engineer at AIQOD
Automated code checks have improved quality gates and prevent weak code from reaching production
SonarQube could improve by reducing false positives in its static code analysis; while its detection capabilities are strong, some findings require manual verification, increasing developers' workload. More accurate analysis would enhance productivity, and SonarQube would benefit from enhanced AI-powered recommendations for fixing issues. For instance, in our pipeline, if it fails during SonarQube stage, we could check the dashboard for identified issues involving code smells, bugs, or duplicacy. An AI feature should be integrated into SonarQube to resolve issues quickly; optimizing scanning performance for very large repositories and providing faster analysis times would enhance the developer experience, especially in large code bases with frequent commits. For anyone planning to implement SonarQube, I advise starting by defining coding standards first and integrating Quality Gates into the pipeline. You can customize quality profiles to match project requirements; rather than relying entirely on default rules, you can adjust settings for stronger detection and enforcement. Organizations with advanced security, branch analysis, and governance features might consider commercial editions based on their needs.
Anuradha Buluwala - PeerSpot reviewer
Head of Technical at Connex Information Technologies Pvt Ltd
Useful for cloud data protection, particularly for email and file-sharing systems
For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a single SASE solution. It should be similar to competitors like Palo Alto. The solution should also expand integration from the public cloud to the private cloud and add Cloud DLP and CASB features.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable function is its usability."
"The fact that the solution does security scanning is valuable."
"Any developer can easily identify issues using the process flow or steps provided by SonarQube. In terms of integration, SonarQube makes it quite easy, simplifying the steps for users."
"The initial setup is simple. It requires some security, but it's simple."
"The product is simple."
"I would absolutely recommend this solution to another company."
"The reports from SonarCloud are very good."
"The solution's user interface is very user-friendly."
"The most valuable feature of Trend Micro Cloud App Security is its stability across all platforms."
"Our business emails are very important and Trend Micro Cloud App Security has provided a high level of protection. Additionally, there are updating the solution frequently."
"The initial setup is pretty straightforward."
"It has more intelligence features than other vendors."
"Trend Micro Cloud App is easy to use and easy to install."
"Dependable with ease of integration with other security products."
"This is a very dependable solution and we are able to have a lot of Trend Micro security products integrated between each other."
"I find Trend Micro Cloud App Security useful for scanning our email boxes. We can scan them one by one, which is a good feature. It's not just gateway-level protection - we integrate the email system with it. They have special protection and parameters for phishing emails."
 

Cons

"We have tens of millions of code to be analyzed and processed. There can be some performance degradation if we are applying Sonar Link to large code or code that is complex. When the code had to be analyzed is when we ran into the main issues. There were several routines involved to solve those performance issues but this process should be improved."
"I've been told by the developers that the solution is too limited. It's not testing enough within the containers."
"There are times that we have the database crash."
"There is need for support for the additional languages and ease of use in adding new rules for detecting issues."
"The reporting is good, but I am not able to download a specific report as a PDF, so downloading reports is something that should be looked at."
"When that one place has a low coverage for the most basic rules (OWASP top 10 for example) it starts to lose its value add."
"Predefined rules/overriding rules caused some issues."
"Code security scanning could be improved."
"The cost of the license is on the high side."
"They should provide separate corporate-level licenses for two to three instances."
"The granulation of the policy setup needs to be better. Right now, it is too basic."
"The solution's technical support services could be better."
"The price of the solution could improve by being lower."
"There is room for improvement in the DLP component of Trend Micro Cloud App Security."
"It would be great if Trend Mail Cloud App Security would be joined with a web security solution, making it a multiple-network solution."
"For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a single SASE solution. It should be similar to competitors like Palo Alto."
 

Pricing and Cost Advice

"Can try developer version for 14 days on the free trial."
"We are using the open-source version, which is available free of cost."
"The developer edition is based on cost per lines of code."
"We have a license with 125,000 lines of code. We did not purchase a lot of lines but it is specific to our code environment."
"My guess is that we have a yearly subscription. We use it quite extensively, so a monthly license wouldn't make sense. Yearly subscriptions are usually cheaper. In addition to the standard licensing fee, there is just the cost of running the hardware where it is hosted."
"SonarQube is an open-source product that can be used free of charge."
"We did not purchase a license (required for C++ support), but this option was considered."
"There is both a free and licensed version. The free version has limitations on development languages and support."
"The pricing of the solution could be better."
"The solution's price is mid-ranged."
"The cost of the license is on the high side. It's a yearly subscription."
"The product's pricing is reasonable compared to other vendors."
"The price of Trend Micro Cloud App Security is expensive for regular users. There are not any hidden fees. First-time users of the solution should purchase implementation packages or professional services."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
13%
Computer Software Company
11%
Comms Service Provider
6%
Performing Arts
13%
Manufacturing Company
9%
Comms Service Provider
8%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise24
Large Enterprise80
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise1
Large Enterprise2
 

Questions from the Community

Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What needs improvement with Trend Micro Cloud App Security?
For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a single SASE solution. It should be similar to competitors like Palo Alto. The solut...
What is your primary use case for Trend Micro Cloud App Security?
We use the solution for cloud data protection, particularly for email and file-sharing systems. It integrates with Microsoft Office 365 and Google Suite to scan mailboxes for spam, viruses, and phi...
What advice do you have for others considering Trend Micro Cloud App Security?
We chose the solution because they've been Gartner leaders for over 15 years, have a good customer base, and are a well-established company. I'd rate the product an eight out of ten.
 

Also Known As

Sonar, SonarQube Cloud
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Snowflake, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.
MedImpact Healthcare Systems, ClubCorp USA, Copa Airlines, Aava, Azra Solutions, BSN INET Co, Ltd, Carhartt
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Application Security Tools. Updated: July 2026.
908,800 professionals have used our research since 2012.