Try our new research platform with insights from 80,000+ expert users

Veracode vs Wiz comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.6
Veracode enhances code security and quality, saves time and costs, supports compliance, and boosts client trust and retention.
Sentiment score
5.3
Wiz enhances ROI by improving asset management, reducing vulnerabilities, lowering operational costs, and offering comprehensive security coverage.
The scanners of Veracode bring status of the weaknesses in the current infrastructure. It scans and provides reports regarding the servers, the network, and the applications running on those servers.
Senior Solutions Architect at IDS Comercial
Regarding price, the evaluation should focus on how efficiently they will recover their investment, considering the time saved through the use of Veracode Fix, for example, and the ability to fix code at dev time compared to the problems faced when fixing after the product is already deployed.
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
We did see a return on investment with Veracode, as we segregated our remediation efforts, which reduced our time to delivery as well as the number of engineers needed to help us in delivering a secure solution.
DevSecOps Engineer at a tech services company with 11-50 employees
We have seen ROI from Wiz and we continued to see value in Wiz.
CyberSecurity Sr Manager at a retailer with 10,001+ employees
We estimate a cost reduction of around 35% to 50%, or even more, due to consolidating our security management into one platform.
CISO at a retailer with 11-50 employees
I have seen a return on investment with Wiz by reducing our budget spent on other tools, saving time, and needing fewer employees.
Senior Program Manager, Security at Eventbrite
 

Customer Service

Sentiment score
7.2
Veracode support is praised for expertise and responsiveness, but some users report delays and unhelpful interactions with complex issues.
Sentiment score
7.7
Wiz customer service is highly praised for responsiveness and efficiency, though documentation access could improve, with strong follow-up support.
Access to the engineering team is crucial for faster feedback on the product fix process.
Principal Architect at a consultancy with 11-50 employees
I have communicated with the technical support of Veracode a couple of times, and this was a really great experience because these professionals know their material.
Application Security Specialist at Herrenknecht
They share detailed information via email, including screenshots or further clarification about the issue.
DevSecOps Engineer at a tech services company with 1,001-5,000 employees
On a scale from 1 to 10, I would give Wiz's support a 10.
Specialist - Information Security at a tech vendor with 1,001-5,000 employees
The vendor was readily available to assist us over calls, clarifying both technical aspects and theoretical insights.
Cyber Security Engineer at a consultancy with 10,001+ employees
We have a dedicated channel with Wiz and are always in communication with them.
AWS Cloud Security Engineer at a tech services company with 51-200 employees
 

Scalability Issues

Sentiment score
7.5
Veracode offers impressive scalability, efficiently handling growth and multiple applications, despite some licensing challenges, earning high user ratings.
Sentiment score
7.6
Wiz offers highly scalable, efficient cloud performance, easily integrating into existing systems, despite manageable cost challenges.
Cloud solutions are easier to scale than on-premise solutions.
Senior Solutions Architect at IDS Comercial
It has a good capacity to scale effectively.
Lead Automation Quality Engineer in Leading UK Bank at a consultancy with 10,001+ employees
Implementing these features into our normal CI/CD was good, so I can say that scalability is really good.
Application Security Specialist at Herrenknecht
We have deployed Wiz in three organizations on AWS, each with approximately 70 to 80 accounts, totaling more than 120 accounts.
AWS Cloud Security Engineer at a tech services company with 51-200 employees
Scalability-wise, I rate the solution a ten out of ten.
Business Line Manager at S2E
Our environment quadrupled in size. We didn’t have to make any adjustments or configuration changes; it just accommodated the growth.
Principal Engineer at Aviatrix
 

Stability Issues

Sentiment score
7.8
Veracode is highly reliable with minimal downtime and issues, though occasional scan speed and false positive concerns exist.
Sentiment score
7.5
Wiz is highly stable, with minimal downtime and issues, quickly addressed minor concerns, and prompt support appreciated by users.
If the Veracode server is down, we experience many issues during the scan.
Lead Automation Quality Engineer in Leading UK Bank at a consultancy with 10,001+ employees
It's not that easy to onboard, but once they have been onboarded on the platform, and the pipeline configured alongside the product configured, it works effectively.
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
The stability of Wiz has been good, with no downtime, bugs, or glitches.
Senior Engineering Manager, Data & AI at Omnissa
Stability-wise, I rate the solution an eight to nine out of ten.
Business Line Manager at S2E
The solution is very stable.
Security Solutions Architect - Cloud Security Consultant at a consultancy with 10,001+ employees
 

Room For Improvement

Veracode users face false positives, outdated UI, integration issues, slow scans, and desire flexible pricing and improved support.
Wiz users seek enhanced reporting, workflows, and integration, with improvements in scanning, dashboards, security capabilities, alerts, and cost efficiency.
If it could be integrated directly with code repositories such as Bitbucket or GitHub, without the need to create a pipeline to upload and decode code, it would simplify the code scan process significantly.
We had issues with scanning large applications. Scanning took a lot of time, so we kept it outside the DevOps pipeline to avoid delaying deployments.
Lead Automation Quality Engineer in Leading UK Bank at a consultancy with 10,001+ employees
A nice addition would be if it could be extended for scenarios with custom cleansers.
IT App Security Senior Analyst at a transportation company with 10,001+ employees
We would like to see preventive controls that can be applied through Wiz to protect against vulnerabilities that we're not going to be able to remediate immediately.
CyberSecurity Sr Manager at a retailer with 10,001+ employees
One significant area for improvement would be increasing automation. While they excel at identifying issues, we need assistance in minimizing the human hours required for tasks.
Principal Engineer at Aviatrix
We need an agent that can be installed, or that can overview all the containers and Kubernetes so that it can detect malicious activities that are happening in them.
SOC Manager at a real estate/law firm with 1,001-5,000 employees
 

Setup Cost

Veracode's pricing is costly, but its features suit large enterprises; smaller businesses should consider alternatives due to budget constraints.
Enterprise buyers have mixed feelings about Wiz's pricing, finding it either fair or expensive with transparency concerns.
It's not the most expensive solution.
Senior Solutions Architect at IDS Comercial
Overall, Veracode's pricing is lower and more scalable than many alternatives in the market.
DevSecOps Engineer at a tech services company with 1,001-5,000 employees
If there's a security gap, you'll never know the cost or effect.
We are paying 250k per year.
Project Manager at Hilti
In some cases, it has a very aggressive price, so very cheap.
Business Line Manager at S2E
I don’t think there’s anyone else out there offering the same level, scale, or efficiency.
Principal Engineer at Aviatrix
 

Valuable Features

Veracode provides comprehensive code analysis, vulnerability management, and integration tools, enhancing security and supporting complex project needs efficiently.
Wiz provides contextual visibility, comprehensive risk evaluation, and automation to enhance security management and reduce operational workload.
It offers confidence by preventing exposure to vulnerabilities and helps ensure that we are not deploying vulnerable code into production.
Site Leader (India) at Industrial Scientific
The best features in Veracode include static analysis and the early detection of vulnerable libraries; it integrates with tools such as Jenkins.
It fixes issues directly in the IDE while you're doing it.
IT App Security Senior Analyst at a transportation company with 10,001+ employees
The feature leads to minimal false positives and a low volume of alerts, which is highly valuable for our operations.
Cloud Security Lead at a computer software company with 5,001-10,000 employees
It's highly customizable, allowing us to manage many custom features effectively.
Project Manager at Hilti
Regarding compliance and governance, Wiz streamlines our vulnerability management to meet specific needs effectively.
CISO at a retailer with 11-50 employees
 

Categories and Ranking

Veracode
Ranking in Container Security
8th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
207
Ranking in other categories
Application Security Tools (2nd), Static Application Security Testing (SAST) (2nd), Software Composition Analysis (SCA) (3rd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (1st)
Wiz
Ranking in Container Security
2nd
Average Rating
9.0
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Vulnerability Management (1st), Cloud Workload Protection Platforms (CWPP) (2nd), Cloud Security Posture Management (CSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (1st), Data Security Posture Management (DSPM) (1st), Compliance Management (1st), Cloud Detection and Response (CDR) (1st)
 

Mindshare comparison

As of December 2025, in the Container Security category, the mindshare of Veracode is 3.2%, down from 4.5% compared to the previous year. The mindshare of Wiz is 14.2%, down from 16.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Container Security Market Share Distribution
ProductMarket Share (%)
Wiz14.2%
Veracode3.2%
Other82.6%
Container Security
 

Featured Reviews

reviewer2703864 - PeerSpot reviewer
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
Onboarding developers successfully while improving code security through IDE integration
Regarding room for improvement, we have some problems when onboarding new projects because the build process has to be done in a certain way, as Veracode analyzes the binaries and not the code by itself alone. If the process is not configured correctly, it doesn't work. That's one of the things that we are discussing with Veracode. Something positive that we've been able to do is submit formal feature requests to them, and they are working on them; they've already solved some of them. This encourages us to propose new ideas and improvements. Another improvement that we asked for this use case is to be able to configure how Veracode Fix proposes and fixes because sometimes it makes proposals using libraries that go against our architecture design made by the enterprise architecture team. For example, we want them to propose using another library, and that's something we already asked Veracode, and they are working on it. We want to specify when you see this kind of vulnerability, you can only propose these two options.
Marcel Velica - PeerSpot reviewer
Senior Program Manager, Security at Eventbrite
Unified cloud visibility has transformed our risk prioritization and reduced alert fatigue while improving collaboration across security and DevSecOps teams
The standout features of Wiz that make it valuable for me include good multi-cloud environment support, data governance, shadow IT detection, DevSecOps governance, automation, level reporting, threat detection, and good infrastructure detection. Wiz has positively impacted my organization by implementing zero trust authorization, providing good reporting that shows the top attack path, critical assets, overall risk posture, and demonstrating AI and ML workload capabilities towards my team, as well as good infrastructure detection and vulnerability detection accuracy with security posture management at massive scale and identity exposure. There is a massive reduction in risk exposure, immediate visibility across the entire cloud estate, reduced noise and better prioritization, stronger DevSecOps collaboration, continuous compliance instead of ad hoc panic, faster incident response with real context, significant cost savings through tool consolidation, and stronger AI and data governance.
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
879,259 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
Financial Services Firm
16%
Computer Software Company
13%
Manufacturing Company
9%
Healthcare Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business70
Midsize Enterprise44
Large Enterprise113
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise8
Large Enterprise18
 

Questions from the Community

Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What do you like most about Veracode Static Analysis?
I like its integration with GitHub. I like using it from GitHub. I can use the GitHub URL and find out the vulnerabilities.
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
What do you like most about Wiz?
With Wiz, we get timely alerts for leaked data or any vulnerabilities already existing in our environment.
What is your experience regarding pricing and costs for Wiz?
My experience with pricing, setup cost, and licensing for Wiz was through an RFP where they offered us a good price, and the licensing was a flexible solution based on our business.
What needs improvement with Wiz?
I feel there is a delay in detection, though I am uncertain whether this is due to our implementation disadvantage. Wiz can detect all the issues, threats, and security vulnerabilities, but the del...
 

Comparisons

 

Also Known As

Crashtest Security , Veracode Detect
No data available
 

Overview

 

Sample Customers

Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Wiz is the fastest growing software company ever - $100M ARR in 18 months: Wiz becomes the fastest-growing software company ever | Wiz Blog  Discover why companies, including Salesforce, Morgan Stanley, Fox, and Bridgewater choose Wiz as their cloud security partner. Read their success stories here: Customers | Wiz
Find out what your peers are saying about Veracode vs. Wiz and other solutions. Updated: December 2025.
879,259 professionals have used our research since 2012.