Try our new research platform with insights from 80,000+ expert users
Estefania Ramirez - PeerSpot reviewer
Application Security Auditor at Softtek
Real User
Great app analysis, support, and pricing
Pros and Cons
  • "The app analysis is the most valuable feature as I know other solutions don't have that."
  • "The solution could use more rules."

What is our primary use case?

We use the product only as a solution for defect code, to find more build liabilities in the code.

How has it helped my organization?

The product allows us to find vulnerabilities while testing our apps. 

What is most valuable?

The app analysis is the most valuable feature as I know other solutions don't have that.

It's a good tool. The interface, support, pricing, and integration do not have any limitations.

What needs improvement?

The solution could use more rules. For example, if I have a lot of rules in many languages, it helps my company as having access to more rules works for us.

We'd like a bit more integration.

Buyer's Guide
Coverity Static
October 2025
Learn what your peers think about Coverity Static. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,778 professionals have used our research since 2012.

For how long have I used the solution?

I've been using the solution for maybe three months. 

What do I think about the stability of the solution?

The solution is stable. There are no bugs or glitches and it doesn't crash or freeze. It's reliable and the performance has been good overall. 

What do I think about the scalability of the solution?

We find the solution to be scalable. 

I'm not sure exactly how many people are using the product.

I can't say if we have plans to increase usage or not in the future. 

How are customer service and support?

We haven't had any issues with technical support. They are helpful and responsive. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We also use SonarQube.

In the past, I used Checkmarx and Fortify, and Coverity had the better price.

How was the initial setup?

I have access only to the interface part and I didn't do the configuration of the tool. I do not handle the initial setup of the product.

As I recall, the deployment itself only took days. 

What about the implementation team?

Our company managed the setup in-house without the help of outside vendors. 

What's my experience with pricing, setup cost, and licensing?

We find the pricing to be reasonable.

What other advice do I have?

We're a customer and end-user.

We are using a recent version of the solution. 

I'd like potential new users to be aware that it's a good tool to implement basic code.

I'd rate the solution nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Junior Software Engineer at NAVER Corp
Real User
Has a straightforward UI and helps to scan codes
Pros and Cons
  • "I like Coverity's capability to scan codes once we push it. We don't need more time to review our colleagues' codes. Its UI is pretty straightforward."
  • "The product should include more customization options. The analytics is not as deep as compared to SonarQube."

What is most valuable?

I like Coverity's capability to scan codes once we push it. We don't need more time to review our colleagues' codes. Its UI is pretty straightforward. 

What needs improvement?

The product should include more customization options. The analytics is not as deep as compared to SonarQube. 

For how long have I used the solution?

I have been using the product for one month. 

What do I think about the stability of the solution?

I would rate Coverity's stability a ten out of ten. 

What do I think about the scalability of the solution?

I would rate the product's scalability an eight out of ten. My company has three users for the tool. 

How was the initial setup?

I would rate the tool's setup a seven out of ten. The deployment gets completed in a couple of minutes. 

What's my experience with pricing, setup cost, and licensing?

I would rate the tool's pricing a one out of ten. 

What other advice do I have?

Coverity's documentation is pretty straightforward and I would rate it a seven out of ten. The solution is cheap and provides us with a dedicated server. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Coverity Static
October 2025
Learn what your peers think about Coverity Static. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,778 professionals have used our research since 2012.
Yantao Zhao - PeerSpot reviewer
Software Integration Engineer at Thales
Real User
Top 5Leaderboard
Powerful capabilities, reliable, and good support
Pros and Cons
  • "The most valuable feature of Coverity is the wrapper. We use the wrapper to build the C++ component, then we use the other code analysis to analyze the code to the build object, and then send back the result to the SonarQube server. Additionally, it is a powerful capabilities solution."
  • "Coverity could improve the ease of use. Sometimes things become difficult and you need to follow the guides from the website but the guides could be better."

What is our primary use case?

We use Coverity because we have a SonarQube server and we have a lot of software components that use different languages, such as Java, C, C++, and above. For C and C++ components we use Coverity.

What is most valuable?

The most valuable feature of Coverity is the wrapper. We use the wrapper to build the C++ component, then we use the other code analysis to analyze the code to the build object, and then send back the result to the SonarQube server. Additionally, it is a powerful capabilities solution.

What needs improvement?

Coverity could improve the ease of use. Sometimes things become difficult and you need to follow the guides from the website but the guides could be better.

For how long have I used the solution?

I have been using Coverity for approximately four years.

What do I think about the stability of the solution?

Coverity is stable.

What do I think about the scalability of the solution?

The scalability of Coverity is good. We have more than around 15 software components and other components involved.

We have 20 developers that are using the solution in my organization.

How are customer service and support?

We had support from Coverity for the first six months of usage but later we did not.

I rate the support from Coverity a four out of five.

Which solution did I use previously and why did I switch?

We have used other solutions, such as SonarQube.

How was the initial setup?

In the beginning, it takes two weeks to learn how to set up Coverity, but later the maintenance work is very easy. The beginning involves soft code, that we need to set up before using SonarQube, we have created SonarQube property itself for every component and inside we need to copy different options for Coverity. We had global Coverity roles or vendors we had to allow it to work with global rules and according to the component itself and the setup. The full implementation process can take approximately one month to complete.

What about the implementation team?

We have two teams to set up the server and install Coverity. I set up the project in Coverity and the different roles in the soft code. The developers use Coverity in their daily work.

What other advice do I have?

My advice to other is the first few steps of using Coverity takes time. It's better to have an experienced user to support it. For new users, it will be hard for them to set it up. If they can get someone to support it directly at the beginning it would be better because for me it's very hard at the beginning for a few weeks.

And on a scale from one to 10, how would you rate Coverity?

I rate Coverity an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1316571 - PeerSpot reviewer
Automation Practice Leader at a financial services firm with 10,001+ employees
Real User
Improves security by detecting vulnerabilities in code, but it needs integration with popular development environments
Pros and Cons
  • "Coverity is quite stable and we haven’t had any issues or any downtime."
  • "I would like to see integration with popular IDEs, such as Eclipse."

What is our primary use case?

I am the administrator and I use this solution to do the calibrating and security scanning of the code in my bank. We are trying to find any vulnerabilities in our code and we are integrating the process with our DevOps.

What is most valuable?

The most valuable feature is the ability to find vulnerabilities in our code.

What needs improvement?

I would like to see integration with popular IDEs, such as Eclipse. If Coverity were available as a plugin then developers could use it to find security issues while they are coding because right now, as we are using Coverity, it is a reactive way of finding vulnerabilities. We need to find these kinds of problems during the coding phase, rather than waiting for the code to be analyzed after it is written.

For how long have I used the solution?

I have been working with Coverity for about eight months.

What do I think about the stability of the solution?

Coverity is quite stable and we haven’t had any issues or any downtime.

What do I think about the scalability of the solution?

We did not have to scale drastically on any of our applications, so it would be difficult for me to judge how scalable it is. Because of the price, we only purchased 20 licenses. We do plan on scaling the number of users and increasing our usage.

How are customer service and technical support?

The technical support is quite responsive and most of the time, we received a response really quickly. We have not had any timeline-related issues with them.

Which solution did I use previously and why did I switch?

We did not use another solution before Coverty, although in my previous company, I used Veracode.

We also use SonarQube for code analysis.

Compared to SonarQube, Coverity finds more vulnerabilities. SonarQube is stronger on core quality, such as duplicate lines of code, but the security issues are found by Coverity.

SonarQube is available as a plugin for development environments such as Eclipse, which allows us to find vulnerabilities proactively.

SonarQube was easier to deploy and I did not require assistance from the vendor for installation or configuration.

How was the initial setup?

We found that during installation and configuration, it takes pipelines for continuous integration and continuous deployment. It was a bit challenging because the necessary base integration was not easy to configure.

It took us slightly over a week to deploy, whereas, with SonarQube, we were able to complete it in less than a day. It was due to complexities in Coverity that it took us more than a week. The complexities were related to missing API features and hooks.

What about the implementation team?

I had assistance from the vendor, Synopsys, during the deployment.

What's my experience with pricing, setup cost, and licensing?

Coverity is quite expensive. Generally, for security scanning products, the pricing is very expensive. Some solutions have pricing that is based on the number of millions of lines of code, but Coverity is priced based on the number of users.

I believe that pricing based on the number of lines of codes is cheaper than billing on a per-user basis. If we have 400 or 500 developers and each needs a license then it will be cheaper to have a solution where the cost depends on the size of the code.

What other advice do I have?

We also purchased Black Duck Binary Analysis and the Black Duck Hub from Synopsys.

My advice for anybody who is implementing this solution is to try to best capture security issues while the code is being written, rather than waiting until it is compiling. It’s easier and much more cost-effective to find vulnerabilities at the earlier, code-writing stage.

The other thing to keep in mind is that you should not rely on one approach to code security. You need to make sure that binary security is also in place, which is not done using Coverity. Any company that wants to secure its environment will need multiple levels of security scanning, and only one of these is handled by Coverity. The second one, binary scanning, can be done by using Black Duck or Veracode. This continues onto other security concerns, such as network scanning.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Project Manager at a manufacturing company with 11-50 employees
Real User
Top 10
A stable solution that has deep scanning capabilities
Pros and Cons
  • "The product has deeper scanning capabilities."
  • "The tool needs to improve its reporting."

What is most valuable?

The product has deeper scanning capabilities. 

What needs improvement?

The tool needs to improve its reporting. 

For how long have I used the solution?

I have been working with the product for one and a half years. 

What do I think about the stability of the solution?

The product's stability is good. 

What do I think about the scalability of the solution?

The product is scalable since it can integrate CI/CD tools. My company has 10 users for the product. 

How are customer service and support?

The solution's support is fast. 

How would you rate customer service and support?

Positive

How was the initial setup?

The solution's setup is easy. 

What's my experience with pricing, setup cost, and licensing?

The tool's price is somewhere in the middle. It's neither cheap nor expensive. I would rate the pricing a five out of ten. 

What other advice do I have?

I would rate the solution a ten out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Architect at a comms service provider with 10,001+ employees
Real User
Stable solution with good technical support service
Pros and Cons
  • "It is a scalable solution."
  • "Sometimes, vulnerabilities remain unidentified even after setting up the rules."

What is our primary use case?

We use the solution to scan the static code and identify vulnerabilities. We can verify the rules and scripting during various applications' implementation processes.

What is most valuable?

The solution has a low false positive rate compared to other vendors. Also, it can scan complex codes. In addition, it has the best features for trial analysis, integration, and language support.

What needs improvement?

Sometimes, vulnerabilities are not identified even after setting up the automated scanning rules. They should include a feature combining automated scanning tools with manual code reviews for better output.

For how long have I used the solution?

I have been using the solution for five years.

What do I think about the stability of the solution?

I rate the solution's stability a nine out of ten.

What do I think about the scalability of the solution?

It is a scalable solution. We can quickly scan around 100 DLS using it. I rate its scalability a nine.

How are customer service and support?

I interact with the solution's technical support team in terms of tuning the tool and improvements. They acknowledge the emails and respond to them quickly.

How would you rate customer service and support?

Positive

How was the initial setup?

The solution integrates well with different tools. Thus, its setup process is relatively straightforward.

What's my experience with pricing, setup cost, and licensing?

The solution is affordable. I rate its pricing a six out of ten.

What other advice do I have?

I recommend the solution to others and rate it a ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Angestellter at a computer software company with 11-50 employees
Real User
A scalable and easy-to-use solution that can be easily deployed
Pros and Cons
  • "The product is easy to use."
  • "Sometimes it's a bit hard to figure out how to use the product’s UI."

What is our primary use case?

I use the solution for static analysis.

What is most valuable?

The product has good API documentation. I’m quite happy with it. The product is easy to use.

What needs improvement?

Sometimes it's a bit hard to figure out how to use the product’s UI.

For how long have I used the solution?

I have been using the solution for some years.

What do I think about the stability of the solution?

I have not faced any issues with the product’s stability.

What do I think about the scalability of the solution?

The solution is scalable. Four people in my organization use the solution.

How was the initial setup?

The initial setup is easy.

What other advice do I have?

I am using the latest version of the product. I have also used Clang Static Analyzer. People planning to use the solution should try the open-source version first to understand how it works. We must have the paid version of the product to get all the resources and documentation. Overall, I rate the product an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1643271 - PeerSpot reviewer
Vice President at a tech vendor with 1,001-5,000 employees
Real User
Static analysis solution that exposes existing and future vulnerabilities
Pros and Cons
  • "The ability to scan code gives us details of existing and potential vulnerabilities. What really matters for us is to ensure that we are able to catch vulnerabilities ahead of time."
  • "When I put my code into Coverity for scanning, the code information of the product is in the system. The solution could be improved by providing a SBOM, a software bill of material."

What is our primary use case?

We use this solution to scan our products. We've integrated with our build system and it automatically completes the scanning.

What is most valuable?

The ability to scan code gives us details of existing and potential vulnerabilities. What really matters for us is to ensure that we are able to catch vulnerabilities ahead of time.

What needs improvement?

When I put my code into Coverity for scanning, the code information of the product is in the system. The solution could be improved by providing a SBOM, a software bill of material. They could also integrate a software composition analysis scan. This would make my job a bit easier.

There is scope for Coverity to look beyond static analysis. Most of people that I have spoken to use Coverity from a pure static analysis perspective. However, we also need to be able to view dynamic pages and APIs using dynamic scanning and SES scans. Currently we would need to use another solution to be able to do this. 

For how long have I used the solution?

I have been using this solution for 10 years.

What do I think about the stability of the solution?

This is a stable solution.

What do I think about the scalability of the solution?

This is a scalable solution.

How are customer service and support?

From a support perspective, they are pretty responsive. I would rate them a five out of five. 

What was our ROI?

The the last ten years, our company has derived value from using this solution. We continuously evaluate our tech stack and if a better solution came along, we would consider it if it provided more value. 

What's my experience with pricing, setup cost, and licensing?

This is a pretty expensive solution. The overall value of the solution could be improved if the price was reduced. Licensing is done on an annual basis. 

There are other new tools like Veracode, Java Icon and Javascript which are better than Coverity when it comes to visualization. Their cost is significantly lower compared to Synopsys. 

What other advice do I have?

Coverity is really good with CC+ and legacy technologies. However, there are other products that are probably as good or even better than Coverity when it comes to Java or cloud applications. 

If someone were to ask me what tool I would recommend, my answer would depend on what technology they're using and what their use case is. My advice would be based on how they're going to use the product and what they're expecting from the tool.

I would rate this solution an eight out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Coverity Static Report and get advice and tips from experienced pros sharing their opinions.
Updated: October 2025
Buyer's Guide
Download our free Coverity Static Report and get advice and tips from experienced pros sharing their opinions.