I am using the latest version for my business. I personally do product evaluations, and this product has improved the efficiency of my work.
Chief Specialist at a government with 501-1,000 employees
The product improves the quality of my work, but the usability could be improved
Pros and Cons
- "The solution has helped to increase staff productivity and improved our work significantly by approximately 20 percent."
- "They could improve the usability. For example, how you set things up, even though it's straightforward, it could be still be easier."
What is our primary use case?
How has it helped my organization?
The product improves the way that we do product evaluations.
What is most valuable?
It improves the quality of my work.
What needs improvement?
They could improve the usability. For example, how you set things up, even though it's straightforward, it could be still be easier.
Buyer's Guide
Coverity
August 2025

Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,384 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability works quite well.
What do I think about the scalability of the solution?
The scalability is good enough.
How are customer service and support?
We haven't had any problems with the product so far.
Which solution did I use previously and why did I switch?
We did not have another solution before. We decided to purchase Coverity because the way we were working previously wasn't efficient. So, we were trying to improve our efficiency.
How was the initial setup?
The initial setup was straightforward.
What was our ROI?
We have seen ROI.
The solution has helped to increase staff productivity and improved our work significantly by approximately 20 percent.
Which other solutions did I evaluate?
This solution seemed to fit our purposes.
What other advice do I have?
Try it out for yourself, and decide whether it's useful for you.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Sr. Manager/Sr. Architect at Cognizant
It has the lowest false positives with customizable triage options
Pros and Cons
- "It has the lowest false positives."
- "Reporting engine needs to be more robust."
What is our primary use case?
We did a comprehensive evaluation on a number of critical parameters in the environment that we are in. Other popular tools that we evaluated failed to meet our expectations.
How has it helped my organization?
- Ease of development teams to adopt.
- Faster scanning
- Lowest false positives
- No unnecessary bloating of a huge defect list.
These have helped us to focus on the things which need attention.
What is most valuable?
- Lowest false positive rate
- Faster scanning time
- Inline context-sensitive help and other supportive artifacts which help developers.
- Customizable triage options
- Integrations with CI/CD tools, etc.
What needs improvement?
For how long have I used the solution?
Less than one year.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Coverity
August 2025

Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,384 professionals have used our research since 2012.
Consaltant at a tech consulting company with 501-1,000 employees
An easy-to-set-up solution used to find vulnerabilities in C++ codes, but its user interface could be improved
Pros and Cons
- "Coverity is easy to set up and has a less lengthy process to find vulnerabilities."
- "The solution's user interface and quality gate could be improved."
What is our primary use case?
We are working on medical devices, and the code base is written in C++. We use Coverity to find the vulnerability in those C++ codes.
What is most valuable?
Coverity is easy to set up and has a less lengthy process to find vulnerabilities.
What needs improvement?
The solution's user interface and quality gate could be improved.
For how long have I used the solution?
I have been using Coverity for four months.
What do I think about the stability of the solution?
Coverity has good stability.
I rate Coverity more than eight out of ten for stability.
What do I think about the scalability of the solution?
Around 20 to 25 developers use Coverity in our organization.
I rate Coverity a seven to eight out of ten for scalability.
Which solution did I use previously and why did I switch?
We use SonarQube for Java-based projects and Coverity for C and C++-based projects.
How was the initial setup?
The solution’s initial setup is simple.
What other advice do I have?
Overall, I rate Coverity a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2025
Product Categories
Static Application Security Testing (SAST)Popular Comparisons
SonarQube Server (formerly SonarQube)
GitLab
Snyk
Checkmarx One
Veracode
OpenText Core Application Security
OWASP Zap
SonarQube Cloud (formerly SonarCloud)
Acunetix
HCL AppScan
PortSwigger Burp Suite Professional
Qualys Web Application Scanning
Klocwork
Semgrep
Invicti
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?
- What Application Security Solution Do You Use That Is DevOps Friendly?
- Which is the most comprehensive open source Web Security Testing tool?
- What is the best Application Security Testing platform?
- When evaluating Application Security Testing, what aspect do you think is the most important to look for?
- SAST vs. DAST: Which is better for application security testing?
- What tools do you rely on for building a DevSecOps pipeline?
- What does the Log4j/Log4Shell vulnerability mean for your company?