Try our new research platform with insights from 80,000+ expert users

Veracode vs Xygeni comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Veracode
Ranking in Application Security Tools
2nd
Ranking in Software Composition Analysis (SCA)
3rd
Ranking in Application Security Posture Management (ASPM)
2nd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
204
Ranking in other categories
Static Application Security Testing (SAST) (2nd), Container Security (8th), Static Code Analysis (1st)
Xygeni
Ranking in Application Security Tools
22nd
Ranking in Software Composition Analysis (SCA)
13th
Ranking in Application Security Posture Management (ASPM)
8th
Average Rating
9.0
Reviews Sentiment
7.2
Number of Reviews
1
Ranking in other categories
Software Supply Chain Security (15th)
 

Mindshare comparison

As of September 2025, in the Application Security Tools category, the mindshare of Veracode is 8.0%, down from 10.5% compared to the previous year. The mindshare of Xygeni is 0.2%, up from 0.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools Market Share Distribution
ProductMarket Share (%)
Veracode8.0%
Xygeni0.2%
Other91.8%
Application Security Tools
 

Featured Reviews

Kv Rao - PeerSpot reviewer
Integrates pipelines smoothly and fortifies code against vulnerabilities
I use Veracode in multiple places including static code analysis, penetration testing, and dynamic code analysis. It is part of our pipeline and integrates well with Bitbucket and Git pipelines The ease of integration with Bitbucket pipelines and Git pipelines is vital for us. Veracode allows us…
Óscar Jesús García Pérez - PeerSpot reviewer
Provides us with efficient security management without sacrificing operational speed
Xygeni offers a powerful combination of features: * ASPM with its centralized view and prioritization * Open-source security features help us identify and manage vulnerabilities in real time within our open-source dependencies. This proactive approach prevents security breaches that could originate from third-party code. * Secrets security, its secrets management features prevent accidental exposure of sensitive data, such as API keys or passwords, within our codebase. This eliminates a major security risk and protects our infrastructure from unauthorized access. Xygeni provides us with efficient security management without sacrificing operational speed. This empowers our team to build secure software with confidence and focus on core development activities.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"There are quite a few features that are very reliable, like the newly launched Veracode Pipelines Scan, which is pretty awesome. It supports the synchronous pipeline pretty well. We been using it out of the Jira plugin, and that is fantastic."
"The good thing about Veracode is that when one scans the respective application code, all the people who are part of the transformation project can update their reviews. If there are any security flaws or vulnerabilities identified, they are able to provide sufficient justification or details about the security flaws."
"In my experience, Veracode is one of the most powerful tools available in the market from a security perspective. It is a market leader in source code analysis."
"What's important for me, from Veracode, is the all-in-one metrics location. I can see where everything is across the entire portfolio of applications I have in this program, and I can report out on it."
"The Static and Dynamic Analysis capabilities are very valuable to us. They've improved the speed of the inspection process."
"Veracode has a nice API that they provide to allow for custom things to be built, or automation. We actually have integrated Veracode into our software development cycle using their API. We actually are able to automatically, every time a new build of a software is completed, submit that application, kick off a scan, and we get results in a much more automated fashion."
"Veracode has impacted our overall security posture because we are from a security background. Every week, we review the dashboards of open findings."
"One of the valuable features is that it gives us the option of static scanning. Most tools of this type are centered around dynamic scanning. Having a static scan is very important."
"The visibility of our open-source supply chain dependencies and real-time detection of vulnerabilities have been invaluable."
 

Cons

"I would like to see expanded coverage for supporting more platforms, frameworks, and languages."
"The scanning is a little slow, but other than that it's fine. It's usually when the binaries get up into the multi-hundred megabyte size."
"The feature that allows me to read which mitigation answer was submitted, and to approve it, requires me to use do so in different screens. That makes it a little bit more complicated because I have to read and then I have to go back and make sure it falls under the same number ID number. That part is a little bit complicated from my perspective, because that's what I use the most."
"Third-party library scanning would be very useful to have. When I was researching this a year ago, there was not a third-party library scan available. This would be a nice feature to have because we are now running through some assessments and finding out which tool can do it since this information needs to be captured. Since Veracode is a security solution, this should be related."
"Veracode can improve the price model and how they bill the final offer to customers. It's based on the amount of traffic. For example, you can buy 1 gigabyte distributed across various applications, and each one can consume part of the whole allotment of traffic data."
"It should include more informational, low level, vulnerability summaries and groupings. Large related groups of low level vulnerabilities may amount to a design flaw or another avenue for attack."
"It needs better APIs, reporting that I can easily query through the APIs and, preferably, a license model that I can predict."
"Veracode scans provide a higher number of false positives."
"There should be more configuration options that make it easier to target the issues that are more important in your organization's context."
 

Pricing and Cost Advice

"Veracode is expensive. Some of its products are expensive. I don't think it's way more expensive than its competitors. The dynamic is definitely worth it, as I think it's cheaper than the competitors. The static scan is a little bit more expensive, around 20 percent more expensive. The manual pen test is more expensive, but it is an expensive service because it's a manual pen test and we also do retests. I don't think it is way more expensive than the competitors, but it's about 15 to 20 percent more expensive."
"The cost has been a barrier to wider use here. I think my team is the only one at the university. Other folks might like to use it, but it's pretty pricey. You could see what else is in the market, but I hear that's the price for most solutions. You might not find a better deal in the market, or it might be an incomplete solution. I mean, for the level of interaction we get with Veracode staff, it's been pretty good."
"Costs are reasonable. No special infrastructure is required and the license model is good."
"There is a fee to scale up the solution which I consider expensive."
"Aside from the standard licensing fees, we also have to pay for a competent Success Manager."
"Its cost for what we needed it for was too high. It wasn't too high for other companies and it was competitively priced, but for us, it just didn't fit. We did plan to use it and increase the usage. In the end, it may have been abandoned because of the cost, but I'm not a hundred percent sure. So, even though we had planned on using it more and more, because of the cost and the business conditions of things, we didn't have the opportunity to really use it more."
"Licensing is pretty flexible. It's a little bit weird, it's by the size of the binary, which is a strange way to license a product. So far they've been pretty flexible about it."
"The pricing is a little on the high side but since we combine our product into one suite, it is easy to do and works well for us."
Information not available
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
867,370 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
16%
Manufacturing Company
9%
Insurance Company
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise43
Large Enterprise112
No data available
 

Questions from the Community

Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What do you like most about Veracode?
The SAST and DAST modules are great.
What is your experience regarding pricing and costs for Veracode?
The product’s price is a bit higher compared to other solutions. However, the tool provides good vulnerability and database features. It is worth the money.
What is your experience regarding pricing and costs for Xygeni?
The setup is very easy. I highly recommend Xygeni to any organization looking to bolster its SDLC security.
What needs improvement with Xygeni?
There should be more configuration options that make it easier to target the issues that are more important in your organization's context. There are different kinds of scanners, each of them targe...
What is your primary use case for Xygeni?
We use Xygeni to harden our CI/CD pipelines in Azure DevOps. Our software is mainly in Python, but we also use Javascript and Csharp. Xygeni detects issues on our open-source third-party dependenci...
 

Comparisons

 

Also Known As

Crashtest Security , Veracode Detect
No data available
 

Overview

 

Sample Customers

Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Information Not Available
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Tools. Updated: August 2025.
867,370 professionals have used our research since 2012.