Try our new research platform with insights from 80,000+ expert users

Veracode vs Xygeni comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex Cloud by Palo Alto N...
Sponsored
Ranking in Application Security Posture Management (ASPM)
9th
Average Rating
9.0
Reviews Sentiment
4.8
Number of Reviews
3
Ranking in other categories
Vulnerability Management (35th), Cloud Workload Protection Platforms (CWPP) (17th), Cloud Security Posture Management (CSPM) (21st), Cloud-Native Application Protection Platforms (CNAPP) (16th), Data Security Posture Management (DSPM) (13th), Software Supply Chain Security (14th), Cloud Infrastructure Entitlement Management (CIEM) (7th), Cloud Detection and Response (CDR) (8th)
Veracode
Ranking in Application Security Posture Management (ASPM)
1st
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
207
Ranking in other categories
Application Security Tools (2nd), Static Application Security Testing (SAST) (2nd), Container Security (8th), Software Composition Analysis (SCA) (3rd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st)
Xygeni
Ranking in Application Security Posture Management (ASPM)
11th
Average Rating
9.0
Reviews Sentiment
7.2
Number of Reviews
1
Ranking in other categories
Application Security Tools (22nd), Software Composition Analysis (SCA) (13th), Software Supply Chain Security (15th)
 

Featured Reviews

Nuno-Santos - PeerSpot reviewer
Cybersecurity Analyst at a tech services company with 11-50 employees
Has improved real-time threat detection and unified cloud protection through AI and automation
Cortex Cloud by Palo Alto Networks is creating some confusion in terms of names because this is recent. They changed the names of the products and are now clarifying their offer. The family of the products is not easy to follow because it's very recent. Regarding the generative AI security tool, I know for sure it's Agentic. Based on my experience with Palo Alto, I can suggest what Cortex Cloud by Palo Alto Networks could make better or what additional functions could be added. This is the best tool in the market. It's not the time to tell what they could do better because it's a recent tool. The market is now adopting it. Our experience doesn't show that they need to do more.
reviewer2703864 - PeerSpot reviewer
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
Onboarding developers successfully while improving code security through IDE integration
Regarding room for improvement, we have some problems when onboarding new projects because the build process has to be done in a certain way, as Veracode analyzes the binaries and not the code by itself alone. If the process is not configured correctly, it doesn't work. That's one of the things that we are discussing with Veracode. Something positive that we've been able to do is submit formal feature requests to them, and they are working on them; they've already solved some of them. This encourages us to propose new ideas and improvements. Another improvement that we asked for this use case is to be able to configure how Veracode Fix proposes and fixes because sometimes it makes proposals using libraries that go against our architecture design made by the enterprise architecture team. For example, we want them to propose using another library, and that's something we already asked Veracode, and they are working on it. We want to specify when you see this kind of vulnerability, you can only propose these two options.
Óscar Jesús García Pérez - PeerSpot reviewer
Chief Information Security Officer at Adaion
Provides us with efficient security management without sacrificing operational speed
Xygeni offers a powerful combination of features: * ASPM with its centralized view and prioritization * Open-source security features help us identify and manage vulnerabilities in real time within our open-source dependencies. This proactive approach prevents security breaches that could originate from third-party code. * Secrets security, its secrets management features prevent accidental exposure of sensitive data, such as API keys or passwords, within our codebase. This eliminates a major security risk and protects our infrastructure from unauthorized access. Xygeni provides us with efficient security management without sacrificing operational speed. This empowers our team to build secure software with confidence and focus on core development activities.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I have seen several benefits from using Cortex Cloud by Palo Alto Networks: It was easy to use and easy to migrate from the IBM platform."
"Overall, Cortex Cloud by Palo Alto Networks is a technically strong product, and I rate it ten out of ten."
"The AI and automation features in detecting and responding to high-risk threats are impressive; it's one of the best tools regarding AI technology and unifies security in one platform in real-time, improving vulnerability analysis, incident response, and compliance reporting."
"Vericode's policy reporting for ensuring compliance with industry standards and regulations is great. I"
"It eases integration into our workflow. Veracode is part of our Jenkins build, so whenever we build our software, Jenkins will automatically submit the code bundle over to Veracode, which automatically kicks off the static analysis. It sends an email when it's done, and we look at the report."
"Veracode has impacted our overall security posture because we are from a security background."
"The coding standards in our development group have improved. From scanning our code we've learned the patterns and techniques to make our code more secure. An example would be SQL injection. We have mitigated all the SQL injection in our applications."
"The source composition analysis component is great because it gives our developers some comfort in using new libraries."
"This static analysis helps ensure a secure application rollout across all environments."
"The integration capabilities with our existing development tools are very good."
"Because it is a SaaS offering, I do not have to support the infrastructure."
"The visibility of our open-source supply chain dependencies and real-time detection of vulnerabilities have been invaluable."
 

Cons

"Overall, I rate Cortex Cloud by Palo Alto Networks as an eight out of ten. I think that it could improve on price, as I know that the Google solution has the best price, and this is one of the conditions."
"Cortex Cloud by Palo Alto Networks is creating some confusion in terms of names because this is recent."
"Some aspects of the GUI can be confusing and make it difficult for me to find certain options or navigate where needed."
"Reporting. Some of the reporting features of Veracode do need improvement. They do not have the most robust access to data. That would be a bit more beneficial to a lot of our clients as well as our actual in-house staff. I've been talking to our program management at Veracode about that, and that is actually on their radar to have that improved, I think actually this year."
"We would like the consolidation of all the different modules. This would help, so then we would be able to see analytics and results on one screen, like a single pane of glass."
"One area for improvement is the navigation in the UI. For junior developers or newcomers to the team, it can be confusing. The UI doesn't clearly bundle together certain elements associated with a scan. While running a scan, there are various aspects linked to it, but in the UI, they appear separate. It would be beneficial if they could redesign the UI to make it more intuitive for users."
"In the last month or so, I had a problem with the APIs when doing some implementations. The Veracode support team could be more specific and give me more examples. They shouldn't just copy the URL for a doc and send it to me."
"The false positive rates were quite high in our case."
"It can take time to find options if you don’t use the interface a lot. At some point, a bit of interface restyling may help."
"Veracode's SAST, DAST, and SCA are pretty good with respect to industry standards, but with regard to container security, they are in either beta or alpha testing. They need to get that particular feature up and running so that they take care of the container security part."
"Raw file scans and dynamic scans would be an improvement, instead of dealing with code binaries."
"There should be more configuration options that make it easier to target the issues that are more important in your organization's context."
 

Pricing and Cost Advice

Information not available
"No issues, the pricing seems reasonable."
"I wouldn't really recommend Veracode for a small firm, because it might be a little pricey for them. But for a large organization, with more than 1,000 applications in the enterprise, there are tiered levels of pricing."
"For the value we get out of it, coupled with the live defect review sessions, we find it an effective value for the money. We are a larger organization."
"Regarding licensing, pay very close attention to what applications you're going to need to do dynamic scanning for, versus static. Right now, the way the licensing is set up, if you don't have any static elements for a website, you can certainly avoid some costs by doing more dynamic licenses. You need to pay very close attention to that, because if you find out later that you have static code elements - like Java scripts, etc. - that you want to have scanned statically, having the two licenses bundled together will actually save you money."
"Pricing/licensing is complicated."
"Veracode is expensive. But the solution is worth it."
"It can be expensive to do this, so I would just make sure that you're getting the proper number of licenses. Do your analysis. Make sure you know exactly what it is you need, going in."
"The licensing is fair, it is time-limited (e.g. one year) but there is a size cap for every app. If your applications are big (due third-party libraries, for example) you should discuss this beforehand and explore suitable agreements."
Information not available
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
879,259 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Performing Arts
11%
Financial Services Firm
9%
Manufacturing Company
9%
Computer Software Company
8%
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
Comms Service Provider
34%
Retailer
16%
Security Firm
12%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business70
Midsize Enterprise44
Large Enterprise113
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Cortex Cloud by Palo Alto Networks?
The solution is costly, with high-end capabilities suitable for enterprises. It is less affordable for startups or sm...
What needs improvement with Cortex Cloud by Palo Alto Networks?
There are areas that could be improved from Palo Alto's side. I think that we need to start using the AI module becau...
What is your primary use case for Cortex Cloud by Palo Alto Networks?
Our main use cases involve working with QRadar, which is the IBM solution. We are now starting to migrate customers t...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. Son...
What do you like most about Veracode Static Analysis?
I like its integration with GitHub. I like using it from GitHub. I can use the GitHub URL and find out the vulnerabil...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
What is your experience regarding pricing and costs for Xygeni?
The setup is very easy. I highly recommend Xygeni to any organization looking to bolster its SDLC security.
What needs improvement with Xygeni?
There should be more configuration options that make it easier to target the issues that are more important in your o...
What is your primary use case for Xygeni?
We use Xygeni to harden our CI/CD pipelines in Azure DevOps. Our software is mainly in Python, but we also use Javasc...
 

Also Known As

No data available
Crashtest Security , Veracode Detect
No data available
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Information Not Available
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
BKool, Onum, Napptive, Fintonic, Adaion, Metricool, Arexdata, ...
Find out what your peers are saying about SonarSource Sàrl, Veracode, Checkmarx and others in Application Security Tools. Updated: November 2025.
879,259 professionals have used our research since 2012.