- Good set of checkers for static code analysis, cyber security
- Possibility of creating custom checkers- Good and easy integration into continuous integration (CI)
- The whole package offers a lot of possibilities: add-ons for Eclipse, standalone clients, access via web site, support, documentation, command line.
Senior Embedded Software Engineer at a engineering company with 10,001+ employees
It provides a good set of checks for static code analysis and cybersecurity. While coding, developers see code violations. Global variables sometimes generate false positives.
What is most valuable?
How has it helped my organization?
More and more departments are targeting static code analysis now, as they see the benefits. Klocwork with its capabilities is helping with this, providing the integration. The advantage is that while coding, developers see code violations.
What needs improvement?
- Global variables sometimes generate false positives. Variables with global scopes sometimes produce False Positives. It means, I get violations from KW which after personal analysis turn out to be not true. At the moment it seems Klocwork is not able to track the values of variables with global scope. Thus the tool makes assumptions for the value range. It occurs that I get violations due to values which simply cannot occur > as the global variables are not tracked. This is annoying and time consuming. One simpler thing on variables with global scope: unused variables with global scope cannot be detected by checkers. This is highly recommended to have it in order to clean the code.
- The preprocessor needs better integration for custom checkers as the tool focuses more on static code analysis; after preprocessing the file.- Updating from one version to the other takes too much time. The process somehow needs too much CPU power.
- Once there are bugs detected and accepted by KW, it takes some time to integrate the changes. This means that what does not fit on the Rogue Wave road map is not definitely considered.
For how long have I used the solution?
I have used it for four years.
Buyer's Guide
Klocwork
December 2025
Learn what your peers think about Klocwork. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,853 professionals have used our research since 2012.
What do I think about the stability of the solution?
I did not encounter any stability issues; only that the update process takes too long. Here, the process could be speeded up.
What do I think about the scalability of the solution?
Scalability is good, from small teams to multisite project teams.
How are customer service and support?
Technical support is good (7/10).
Which solution did I use previously and why did I switch?
I previously used PC-lint. I switched because KW is more mature.
How was the initial setup?
Initial setup is going well; very straightforward and following its documentation.
Which other solutions did I evaluate?
I evaluated QAC/QAC++, LDRA Testbed.
What other advice do I have?
A good thing is that you are rapidly ramped up and can use the tool.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Klocwork Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Static Code AnalysisPopular Comparisons
SonarQube
Snyk
GitLab
Checkmarx One
Veracode
Coverity Static
OpenText Core Application Security
Mend.io
Sonatype Lifecycle
PortSwigger Burp Suite Professional
OpenText Static Application Security Testing
HCL AppScan
Semgrep
CodeSonar
Polyspace Code Prover
Buyer's Guide
Download our free Klocwork Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?
- Which application security solutions include both vulnerability scans and quality checks?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- SAST vs. DAST: Which is better for application security testing?















