Try our new research platform with insights from 80,000+ expert users

What is SonarQube?

Featured SonarQube reviews

SonarQube mindshare

As of November 2025, the mindshare of SonarQube in the Application Security Tools category stands at 19.3%, down from 25.8% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Application Security Tools Market Share Distribution
ProductMarket Share (%)
SonarQube Server (formerly SonarQube)19.3%
Checkmarx One10.4%
Veracode6.9%
Other63.4%
Application Security Tools

PeerResearch reports based on SonarQube reviews

TypeTitleDate
CategoryApplication Security ToolsNov 5, 2025Download
ProductReviews, tips, and advice from real usersNov 5, 2025Download
ComparisonSonarQube vs VeracodeNov 5, 2025Download
ComparisonSonarQube vs Checkmarx OneNov 5, 2025Download
ComparisonSonarQube vs GitHub Advanced SecurityNov 5, 2025Download
Suggested products
TitleRatingMindshareRecommending
Snyk4.06.0%100%49 interviewsAdd to research
GitLab4.22.3%97%87 interviewsAdd to research
 
 
Key learnings from peers

Valuable Features

Room for Improvement

ROI

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
Company SizeCount
Small Business36
Midsize Enterprise20
Large Enterprise60
By reviewers
By visitors reading reviews
Company SizeCount
Small Business1612
Midsize Enterprise1118
Large Enterprise5102
By visitors reading reviews

Top industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
14%
Government
6%
Comms Service Provider
5%
Insurance Company
4%
Retailer
4%
Healthcare Company
4%
University
3%
Educational Organization
3%
Energy/Utilities Company
3%
Media Company
2%
Construction Company
2%
Outsourcing Company
2%
Real Estate/Law Firm
2%
Non Profit
2%
Consumer Goods Company
2%
Transportation Company
2%
Legal Firm
2%
Performing Arts
1%
Aerospace/Defense Firm
1%
Hospitality Company
1%
Pharma/Biotech Company
1%
Wholesaler/Distributor
1%
Recreational Facilities/Services Company
1%
Logistics Company
1%
Engineering Company
1%

Compare SonarQube with alternative products

Learn more about SonarQube

Related questions

 
SonarQube Reviews Summary
Author infoRatingReview Summary
Sr Software Engineering Supervisor at Mozarc Medical4.5I use SonarQube Server for static code analysis to detect build vulnerabilities, valuing its rule control despite ongoing scanning issues. Transitioning from Coverity, I see ROI due to its FDA approval, essential for our reports.
Head of Software Engineering at ronaldmariah@gmail.com4.5I use SonarQube Server for static code analysis to enhance code quality and manage technical debt. Its valuable features include code suggestions and customizable metric tracking, though it could improve by integrating AI. It replaced AppScan, offering better functionality.
Security Analyst at Dover Corporation4.0I use SonarQube Cloud daily on Microsoft Azure for security checks, finding it user-friendly with precise reports and easy CI/CD integration. It saves time, offers detailed code insights, but could improve UI and provide more elaborate solutions for CVEs.
IT Officer (Solution Architect) at World Bank4.0I've used SonarQube Server for years to monitor code quality through static analysis and test coverage, finding it effective overall, though reporting can be complex and improvements in AI and IDE integration would enhance the experience.
CEO at a computer software company with 1-10 employees3.5I primarily use SonarQube Cloud for static code analysis because it's easy to integrate and use. However, it needs improved vulnerability detection compared to Veracode, which I find more complex but with better capabilities. I haven't calculated ROI yet.
Architect at sigpsc inc4.5I use SonarQube Cloud for scanning code quality and identifying vulnerabilities, noting its excellent integration into YAML pipelines. However, I find it lacks in covering vulnerabilities, static scanning, and misarchitecture comprehensively, and it caters more to larger clients.
consultant at a computer software company with 1,001-5,000 employees4.0I use SonarQube Cloud for code inspection, managing technical debt, and identifying security vulnerabilities. Its integration with CI/CD tools is invaluable, though it lacks dynamic code scanning. The interface is superior, and it's a great fit for several languages and platforms.
Distinguish Engineer at Gtmhub4.5I use SonarQube Server for static code analysis in our Jenkins CI builds, primarily on Golang projects. It effectively identifies code issues and improvements. Although satisfied, potential enhancements could include bill of materials functionality. We switched from Snyk for cost efficiency.