Try our new research platform with insights from 80,000+ expert users

Veracode vs Wiz Code comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex Cloud by Palo Alto N...
Sponsored
Ranking in Application Security Posture Management (ASPM)
6th
Average Rating
8.4
Reviews Sentiment
5.6
Number of Reviews
9
Ranking in other categories
Vulnerability Management (27th), Cloud Workload Protection Platforms (CWPP) (13th), Cloud Security Posture Management (CSPM) (18th), Cloud-Native Application Protection Platforms (CNAPP) (12th), Data Security Posture Management (DSPM) (12th), Software Supply Chain Security (7th), Cloud Infrastructure Entitlement Management (CIEM) (6th), Cloud Detection and Response (CDR) (4th)
Veracode
Ranking in Application Security Posture Management (ASPM)
1st
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (2nd), Container Security (8th), Software Composition Analysis (SCA) (3rd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st)
Wiz Code
Ranking in Application Security Posture Management (ASPM)
8th
Average Rating
8.6
Reviews Sentiment
4.4
Number of Reviews
3
Ranking in other categories
Vulnerability Management (38th), Risk-Based Vulnerability Management (13th), Cloud Security Remediation (1st), Continuous Threat Exposure Management (CTEM) (6th)
 

Featured Reviews

AP
Assistant Security Architect at Cloudnomics
Automated investigations have cut incident response time and now improve compliance monitoring
As per my experience with Cortex Cloud by Palo Alto Networks, the UI could be simpler. There are few features which are very hidden, such as those in software bill of materials and compliance policies. Palo Alto Networks could make the UI a bit easier to navigate. Apart from this, all other things are good. Detection and response features are good, and the visibility, especially in the CI/CD pipeline, is also very good. Infrastructure as Code visibility is good. I don't think there is much scope of improvement regarding detection and response. However, they can improve operational efficiency and the UI. I feel that some features which are hidden could be shown on the home page or front page, which would make a significant difference.
reviewer2703864 - PeerSpot reviewer
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
Onboarding developers successfully while improving code security through IDE integration
Regarding room for improvement, we have some problems when onboarding new projects because the build process has to be done in a certain way, as Veracode analyzes the binaries and not the code by itself alone. If the process is not configured correctly, it doesn't work. That's one of the things that we are discussing with Veracode. Something positive that we've been able to do is submit formal feature requests to them, and they are working on them; they've already solved some of them. This encourages us to propose new ideas and improvements. Another improvement that we asked for this use case is to be able to configure how Veracode Fix proposes and fixes because sometimes it makes proposals using libraries that go against our architecture design made by the enterprise architecture team. For example, we want them to propose using another library, and that's something we already asked Veracode, and they are working on it. We want to specify when you see this kind of vulnerability, you can only propose these two options.
reviewer2618736 - PeerSpot reviewer
Security Manager at a consultancy with 10,001+ employees
Continuous code security has reduced vulnerabilities and provides real-time risk visibility
I have a big improvement in mind for Wiz Code, not a small improvement. When I look at tools such as vulnerability detection tools, I focus on how the reporting could help fast-track risk mitigations. I don't want folks to just look at the severity rating, whether it's critical, high, or medium. I would love to see how that presents a risk. Meaning that if a particular vulnerability is compromised, it could be a low severity, but if it's compromised, what business impact does it have? With capabilities we have in AI and other technologies, I think we could do much more than just sharing vulnerability ratings or severity ratings for folks to act on. That approach is outdated. Something that communicates the value would make sense and could help drive or change habits. That's what I'm thinking, and that's why I say it's a big one, not just something small.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Previously with Cortex Cloud by Palo Alto Networks, I deployed this product for one of my customers, and after three to four months, they said that previously they had around four hours of MTTR, and now it has reduced to just 15 to 20 minutes."
"Overall, Cortex Cloud by Palo Alto Networks is a technically strong product, and I rate it ten out of ten."
"The most beneficial aspect of Cortex Cloud by Palo Alto Networks and Palo Alto in general is that there is a single platform for all cloud providers for securitization."
"I have absolutely seen improvements in our incident close rates, with mean time to detect and respond reduced significantly, sometimes by at least forty to fifty percent."
"The most valuable features I have found in Cortex Cloud by Palo Alto Networks are those that we provided to customers in a stock environment, as we have done some POCs and tried to check how it can help different organizations, and this same solution has been positioned for multiple customers."
"The AI and automation features in detecting and responding to high-risk threats are impressive; it's one of the best tools regarding AI technology and unifies security in one platform in real-time, improving vulnerability analysis, incident response, and compliance reporting."
"From a technical standpoint or pricing, Cortex Cloud by Palo Alto Networks is a stronger solution in the market at the moment compared to other products from ConnectWise or Symantec."
"Cortex Cloud by Palo Alto Networks has impacted our organization positively by keeping our machines secure and our team using the dashboard to find issues quickly."
"It pinpoints the errors. Its accuracy is very interesting. It also elaborates on flaws, meaning it provides you with details about what is valid or not and how something can be fixed."
"The Veracode technical support is very good. They are responsive and very knowledgeable."
"Their dashboard is really good, overall. In my opinion, it's one of the best in the market, and I say that because we have used other service providers."
"The integrated IDE tool enables users to get instant feedback in real-time on the code itself, rather than waiting for it to go through the CI/CD pipeline and get the result."
"I believe the static analysis is Veracode's best and most valuable feature. Software composition analysis is a feature that most people don't use, and we don't use SCA for most of our applications. However, this is an essential feature because it provides insight into the third-party libraries we use."
"You can easily integrate it with Azure DevOps. This is an added value because we work with Azure DevOps. Veracode is natively supported and we don't have to work with APIs."
"It has an easy-to-use interface."
"I don't have much experience with the solution yet. We're looking at integrating Manual Penetration Testing with JIRA and Bamboo and then building that into a CICD model, so the integration is the most valuable feature so far."
"In my opinion, all the security features Wiz Code offers are the best."
"The best features with Wiz Code give you a reasonable picture when it comes to vulnerabilities, which means you see the usual severity levels, you also get to see references on how to remediate vulnerabilities, and the fact that it has a visual dashboard helps all stakeholders, especially folks who need to remediate, to get that picture correctly and then take action."
"Wiz Code has positively impacted my organization through the unified platform that gives the ability to shift left in security and detect issues before they go into production."
 

Cons

"From the commercial perspective, we have some limitations because Palo Alto has a minimum number of users of endpoints set at 200, which is quite high for the Italian market."
"Cortex Cloud by Palo Alto Networks is creating some confusion in terms of names because this is recent."
"The negative aspects or areas for improvement in the product include the fact that the cost might be a bit high, which challenges commercials, but not technically."
"In my opinion, Cortex Cloud by Palo Alto Networks can be improved by addressing forensic information collection and storage, although I cannot suggest specific things right now, based on what customers might need."
"Some aspects of the GUI can be confusing and make it difficult for me to find certain options or navigate where needed."
"As per my experience with Cortex Cloud by Palo Alto Networks, the UI could be simpler."
"Overall, I rate Cortex Cloud by Palo Alto Networks as an eight out of ten. I think that it could improve on price, as I know that the Google solution has the best price, and this is one of the conditions."
"The pricing is high, making ROI challenging to justify, especially during transitions between solutions."
"To be able to upload source codes without being compiled. That’s one feature that drives us to see other sources."
"The on-platform reporting needs to be opened up much more. We'd like to be able to look at the inspection data from a trending perspective in a much more open manner. I need to be able to sort and filter much more flexibly than I can today."
"We would like a way to mark entire modules as "safe." The lack of this feature hasn't stopped us previously, it just makes our task more tedious at times. That kind of feature would save us time."
"An area for improvement I found in Veracode is the connectivity because currently, my company uses a plugin for the dev-ops cloud-based connectivity. A pretty helpful feature would be if Veracode gives a direct code for connecting to the Oracle server directly and authenticating it via a unique server."
"False positives are a problem. Sometimes the flow paths are not accurate and don't represent real attack vectors, but this happens with every application that performs static analysis of the code. But it's under control. The number of false positives is not so high that it is unmanageable on our side."
"The solution does take a bit more time when we use it for multiple processes."
"The language version support could be improved."
"The user interface could be more sleek. Some scanning requirements aren't flexible. Some features take some time for new users to understand (like what exactly "modules" are)."
"I have a big improvement in mind for Wiz Code, not a small improvement."
 

Pricing and Cost Advice

Information not available
"The price of Veracode Static Analysis is on the higher side."
"The pricing is pretty high."
"The pricing depends on the functionality each client desires."
"As compared to others, it is a costly solution. It is overpriced, and many organizations with a limited budget cannot afford it. That is why they are going for other tools, but those tools are not that effective. Veracode is better in terms of quality. If you want good service, you have to pay for it."
"Compared to other similar products, the licensing and pricing are definitely competitive. If you see Checkmarx as the market leader, then we are talking about Veracode being a fraction of the cost. You also have to consider your hidden costs: you need a team to maintain it, a server, and resources. From that point of view, Veracode is great because the cost is really a fraction of many competitors."
"Veracode is affordable for large organizations, but its pricing may be out of reach for small and medium companies."
"We pay based on the number of developers working on a particular project."
"To my knowledge, licensing for Veracode Static Analysis is paid yearly by my company."
Information not available
report
Use our free recommendation engine to learn which Application Security Posture Management (ASPM) solutions are best for your needs.
883,760 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
9%
Manufacturing Company
9%
Performing Arts
8%
Outsourcing Company
7%
Financial Services Firm
16%
Computer Software Company
12%
Manufacturing Company
11%
Government
6%
Manufacturing Company
13%
Financial Services Firm
11%
Computer Software Company
9%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise1
Large Enterprise2
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise44
Large Enterprise115
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Cortex Cloud by Palo Alto Networks?
The solution is costly, with high-end capabilities suitable for enterprises. It is less affordable for startups or sm...
What needs improvement with Cortex Cloud by Palo Alto Networks?
From the commercial perspective, we have some limitations because Palo Alto has a minimum number of users of endpoint...
What is your primary use case for Cortex Cloud by Palo Alto Networks?
I use Cortex Cloud by Palo Alto Networks to secure cloud infrastructure during cloud transformation. For example, whe...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. Son...
What do you like most about Veracode Static Analysis?
I like its integration with GitHub. I like using it from GitHub. I can use the GitHub URL and find out the vulnerabil...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
What is your experience regarding pricing and costs for Wiz Code?
I have no idea about the pricing, setup cost, and licensing for Wiz Code.
What needs improvement with Wiz Code?
I have a big improvement in mind for Wiz Code, not a small improvement. When I look at tools such as vulnerability de...
What is your primary use case for Wiz Code?
Folks deploying infrastructure with Terraform code need to verify that those deployments do not have vulnerability co...
 

Also Known As

No data available
Crashtest Security , Veracode Detect
Dazz.io
 

Overview

 

Sample Customers

Information Not Available
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Information Not Available
Find out what your peers are saying about Veracode vs. Wiz Code and other solutions. Updated: February 2026.
883,760 professionals have used our research since 2012.