We are using this solution for analyzing sales, profit, and FI documents. We are using the HR section as well.
Senior System Analyst at a tech services company with 1,001-5,000 employees
User-friendly, easy to access, and it has good training documentation
Pros and Cons
- "The most valuable features are that it is user-friendly, easy to access, and they provide good training files."
- "Monitoring is a feature that can be improved in the next version."
What is our primary use case?
How has it helped my organization?
SonarQube simplified some of the processes and made others more complex.
What is most valuable?
The most valuable features are that it is user-friendly, easy to access, and they provide good training files. Ability to manage and customize reports. Sonar also models the relationship between packages and classes
What needs improvement?
It would be better if the users could have quick access to the features.
Monitoring is a feature that can be improved in the next version.
Buyer's Guide
SonarQube Server (formerly SonarQube)
July 2025

Learn what your peers think about SonarQube Server (formerly SonarQube). Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,164 professionals have used our research since 2012.
For how long have I used the solution?
I have been using SonarQube for three years.
What do I think about the stability of the solution?
This solution is stable. Stability is not an issue for us.
What do I think about the scalability of the solution?
It's scalable. Scaling is not a problem.
How are customer service and support?
Because of the sanctions in our country, we cannot contact technical support directly.
Which solution did I use previously and why did I switch?
How was the initial setup?
The initial setup was straightforward. It was a normal installation.
It took approximately five days to deploy.
What's my experience with pricing, setup cost, and licensing?
It's a bit expensive for us. The currency rate of the dollar is a problem but it may be fine for other countries.
This solution provides good features for users.
What other advice do I have?
Before implementing, they should have more knowledge about the performance, and the features. It will be helpful in learning the hardware also.
If you have good resources for the performance, you won't worry about it. It will also be dependent on your information, and how much knowledge you have.
I would rate SonarQube an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Good code review and reporting of basic vulnerabilities in your applications
Pros and Cons
- "SonarQube is good in terms of code review and to report on basic vulnerabilities in your applications."
- "It does not provide deeper scanning of vulnerabilities in an application, on a live session. This is something we are not happy about. Maybe the reason for that is we are running the community edition currently, but other editions may improve on that aspect."
What is our primary use case?
We are using it for scanning our web applications, some internal applications and using it for code reviews.
What is most valuable?
SonarQube is good in terms of code review and to report on basic vulnerabilities in your applications. The code writing standard of SonarQube is good. It may be better in other editions but as we don't use those we're not able to find out with SonarQube. We are using the community, developer version for 14 days. If this version is successful we will go to the full version. We're using it on-premises.
What needs improvement?
It does not provide deeper scanning of vulnerabilities in an application, on a live session. This is something we are not happy about. Maybe the reason for that is we are running the community edition currently, but other editions may improve on that aspect.
For how long have I used the solution?
We have been using SonarQube for one year.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
SonarQube is scalable.
How was the initial setup?
SonarQube was easy to setup.
Which other solutions did I evaluate?
We considered using Fortify.
What other advice do I have?
I would rate SonarQube an eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
SonarQube Server (formerly SonarQube)
July 2025

Learn what your peers think about SonarQube Server (formerly SonarQube). Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,164 professionals have used our research since 2012.
Director Product Development at Mycom Osi
Reasonably priced, provides good code coverage and improves quality
Pros and Cons
- "The code coverage feature is very good."
- "If the product could assist us with fixing issues by giving us more pointers then it would help to resolve more of the warnings without such a commitment in terms of time."
What is our primary use case?
We use SonarQube for determining code coverage, finding bugs, and searching for security-related issues in our development environment.
What is most valuable?
The code coverage feature is very good.
What needs improvement?
When performing the code coverage function, there are a lot of warnings that come up and you may not have time to solve them. You need to have the ability to overrule warnings or issues because it may not be possible to commit the time to resolve them immediately. If the product could assist us with fixing issues by giving us more pointers then it would help to resolve more of the warnings without such a commitment in terms of time.
SonarQube needs some improvement in its ability to find security-related issues.
For how long have I used the solution?
I have been using SonarQube for the past seven or eight years.
What do I think about the stability of the solution?
We have not found any bugs or had trouble with stability. We have had some minor hiccups, here and there, but otherwise, we are fine.
What do I think about the scalability of the solution?
We have not found any issues with respect to scalability.
How are customer service and technical support?
I have not personally been in contact with technical support. I believe that our team recently had contact with them when we migrated to the newer version, and we received help from their support agent.
Which solution did I use previously and why did I switch?
I have also used Veracode and when comparing the two, I find that Veracode is better at finding security-related issues during the static code analysis. At the same time, during my PoC with Veracode, they did not claim to be able to provide everything that SonarQube does.
How was the initial setup?
I was not involved in the initial setup. However, I do know that it can be set up within one or two days.
What about the implementation team?
We have an in-house team for deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
I am satisfied with the pricing.
What other advice do I have?
In general, I am very satisfied with SonarQube and I highly recommend it. If you are looking for full coverage and quality improvement then it is the best product to use.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Technical Architect at a insurance company with 51-200 employees
Provides continuous inspection of code quality
Pros and Cons
- "The product itself has a friendly UI."
- "We could use some team support, but since we are using the community version, it's not available."
What is our primary use case?
I'm a user also, but I'm also responsible for information security.
I am the principal of security in the office. I'm the one that actually advises people about enhancing or incorporating information security aspects. Right now, we are using a community version. We have yet to subscribe for the enterprise license because we need more disciplined developers first.
Within our organization, there are roughly 14 people using this solution.
We use it to find the scoop, or the use, for peer review for the developers. It will require more time, to get used to it and to get trained. My team is very small and I am part of the development team — I'm in the security team but I'm also part of the development team. I am helping to build this along with the team.
What is most valuable?
The product itself has a friendly UI. It's easy to use and we understand how to manage the admin control panel, it's really quick. It's really easy to perform admin jobs using the control panel.
The tools are really easy to use. With the coding, we can build a bunch of rules that apply for each programming language, for example, CSS, Java, and more. Even with the community version, we can still set up rules. We accommodate them and they give us the best quality. It's been a great experience so far.
What needs improvement?
We could use some team support, but since we are using the community version, it's not available.
Also, because we are using the community version, we have some problems from time to time regarding the SSO logins.
Sometimes you need more time to configure things, to edit some profiles.
SonarQube has come to the end of the project phase. The development team doesn't really utilize this because it's in the product development phase. They need more paths and delivery — they don't really care about security. But now, since we are also certified technical security, we can go ahead and provide that for them.
In short, communication needs to be better.
Automation could be better. Sometimes by default, you need to configure some rules regarding detection. You need to have some parameters set regarding false-positive risk.
For how long have I used the solution?
We have had SonarQube for over a year, but we have only been using it for the past two months.
How are customer service and technical support?
With the use of community version, we already have utilized and carried out our needs to fulfil application security at the earlier stage with small medium SDLC Team.
How was the initial setup?
The initial setup was very straightforward. Overall, deployment took roughly one week.
What other advice do I have?
There are so many qualitative tools other than SonarQube, but I think it's the only platform that is open-source; however, it doesn't cover you end-to-end — from the static, dynamic, and interactive source.
Once we're done with SonarQube, we will switch to a proprietary tool, like Qualys — something that provides more end-to-end — but before we can do that, we need more people who know how to properly run the software.
Overall, I would recommend SonarQube for your initial software quality.
On a scale from one to ten, I would give this solution a rating of eight.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior/Lead Software Engineer at a government with 51-200 employees
Stable with good static code analysis but needs better security
Pros and Cons
- "The static code analysis of the solution is the most important aspect for us. When it comes to security breaches within the code, we can leverage some rules to allow us to identify the repetition in our code and the possible targets that we may have. It makes it very easy to review our code for security purposes."
- "There are sometimes security breaches in our code, which aren't be caught by SonarQube. In the security area, SonarCube has to improve. It needs to better compete with other products."
What is most valuable?
When it comes to security, this solution is pretty great.
The static code analysis of the solution is the most important aspect for us. When it comes to security breaches within the code, we can leverage some rules to allow us to identify the repetition in our code and the possible targets that we may have. It makes it very easy to review our code for security purposes.
The solution is quite stable.
You can scale the solution if you need to.
What needs improvement?
In terms of solving for security breaches in the code, we are looking for different tools to help us catch things much sooner. Right now, we're not doing so well on this front. Therefore, we are looking for some other options in the market. I'm not the one who is tasked with looking at the moment, however, we are actively seeking out a more effective option for the static code analysis.
There are sometimes security breaches in our code, which aren't be caught by SonarQube. In the security area, SonarCube has to improve. It needs to better compete with other products.
The solution could offer some sort of alert feature. We've had an incident, where somebody removed the solution from the pipeline and there were a couple of code instances that were pushed and married with the codebase without passing through SonarQube. It would be nice if we were alerted to that. If the solution is off-line or turned off, we'd like to be able to tell so that we can decide if it should be on or if it was a mistake.
It would be great if it could support testing and configurations a bit more.
For how long have I used the solution?
We've only been working with the solution for one year. It hasn't been that long.
What do I think about the stability of the solution?
The solution is very stable. We don't have any issues with its reliability. It's been quite good so far.
What do I think about the scalability of the solution?
The architecture that we have is not that big, however, from the scalability point of view, SonarQube supports scalability quite well.
At the moment, we have a hybrid working model on the vendor side, as well as on the in-house team. The in-house team has 5 members and the vendor has maybe 20 people, more or less. All in all, we can say we have about 25 people using the solution at any given time.
Which solution did I use previously and why did I switch?
We did not previously use a different solution. It was always manual code reviewing via the most experienced team members who would offer guidance on adjustments.
What's my experience with pricing, setup cost, and licensing?
Right now, we are not using the enterprise features of the solution. I don't know about the licensing as I was not the one who introduced SonarQube into the pipeline. I believe we are using the free community edition and therefore aren't actually paying any money for it.
Which other solutions did I evaluate?
I did an exercise a couple of months ago with my colleague. After this, I listed other products and their security aspects. I don't know if we found a solution that can offer us better features for security. I don't know if we will keep SonarQube in the pipeline or we will sell the product and get another product. I'm not sure at this point.
What other advice do I have?
We're just customers. We don't have a business relationship with the company.
I believe we are using the latest version of the solution, however, I don't know the exact number.
I would advise others considering the solution to consider the level of security they need. If they are very concerned about security and the application is very sensitive, then SonarQube may not be the best option and they should seek out other products.
Overall, I would rate the solution seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Independent Consultant at Klusener Consultancy
Reliable inspection with a quality indication system
Pros and Cons
- "The overall quality of the indicator is good."
- "I am not very pleased with the technical debt computation."
What is our primary use case?
We use this solution for auditing our system.
What is most valuable?
The overall quality of the indicator is good.
What needs improvement?
I am not very pleased with the technical debt computation, it's a bit arbitrary.
The codification metrics could also be improved.
For how long have I used the solution?
I have been using the open-source version, on and off, for the past few years.
What do I think about the scalability of the solution?
The scalability is ok, but if you want to process large portfolios, it breaks down.
How are customer service and technical support?
The technical support is reasonable.
How was the initial setup?
The initial setup was reasonable.
What's my experience with pricing, setup cost, and licensing?
There is a licensing fee, but I don't know the exact cost because I use this solution in partnership with other companies.
Which other solutions did I evaluate?
I have experience with Parasoft and other similar tools.
What other advice do I have?
I would absolutely recommend this solution to another company.
On a scale from one to ten, I would give this solution a rating of eight. I would give it a higher rating if the technical debt computation was improved.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security consultant at a computer software company with 1,001-5,000 employees
Enables the developers to code securely and comes with a free community edition
Pros and Cons
- "It's a great product. If you are in a hurry and just want to focus on the functional requirements of any kind of project, SonarQube is highly helpful. It enables the developers to code securely. SonarQube has a Community edition, which is open source and free. There are also three proprietary or paid versions: Enterprise edition, Data Center edition, and Developer edition."
- "If I configure a project in SonarQube, it generates a token. When we're compiling our code with SonarQube, we have to provide the token for security reasons. If IP-based connectivity is established with the solution, the project should automatically be populated without providing any additional token. It will be easy to provide just the IP address. It currently supports this functionality, but it makes a different branch in the project dashboard. From the configuration and dashboard point of view, it should have some transformations. There can be dashboard integration so that we can configure the dashboard for different purposes."
What is our primary use case?
We are a security organization, and we deploy security solutions and applications related to network for our clients. We mostly focus on open source products because clients don't like to have proprietary products because of the available budget for their different projects. We try to find the possible solution, and then we deploy the solution for them. Deployments are done on the AWS cloud as well as on-premises.
I came to know that there is a SonarQube solution that is used for clean and secure coding purposes and bug fixes in a large DevOps team. That's why I have deployed SonarQube. Currently, I'm testing SonarQube to demonstrate to my higher department what this tool can do. We are testing this solution for one of our clients, who may use it for two or three use cases during static code analysis and the software development life cycle.
What is most valuable?
It's a great product. If you are in a hurry and just want to focus on the functional requirements of any kind of project, SonarQube is highly helpful. It enables the developers to code securely.
SonarQube has a Community edition, which is open source and free. There are also three proprietary or paid versions: Enterprise edition, Data Center edition, and Developer edition.
What needs improvement?
If I configure a project in SonarQube, it generates a token. When we're compiling our code with SonarQube, we have to provide the token for security reasons. If IP-based connectivity is established with the solution, the project should automatically be populated without providing any additional token. It will be easy to provide just the IP address. It currently supports this functionality, but it makes a different branch in the project dashboard.
From the configuration and dashboard point of view, it should have some transformations. There can be dashboard integration so that we can configure the dashboard for different purposes.
For how long have I used the solution?
It has been just three days since I deployed this solution. I have just configured the Community edition of SonarQube, and now I am searching for some Java products to test the solution.
Which solution did I use previously and why did I switch?
I have previously created a report comparing SonarQube with other products such as Micro Focus Fortify. SonarQube is way ahead than Micro Focus Fortify because SonarQube has a cloud solution. Micro Focus Fortify does not support cloud-based hosting.
How was the initial setup?
The initial setup was simple for me. It was very straightforward and to the point. The documentation was also very much to the point and perfectly explained.
There are open source solutions for the Linux environment that let you automatically deploys everything in the new environment by using a specific file, but SonarQube doesn't have that file. That would be a plus point.
What about the implementation team?
I deployed it myself. Because of our Linux environment, it took me around three hours. I was reading the documentation and learning about configuration-related parameters while deploying this solution.
What's my experience with pricing, setup cost, and licensing?
For the Community edition, there is no extra cost. It's totally free. The Enterprise edition, Data Center edition, and Developer edition are the paid versions.
Which other solutions did I evaluate?
We have already used SonarLint. I am considering both SonarLint and SonarQube.
What other advice do I have?
I always talk in favor of secure programming, secure coding. SonarQube is easy for me. I am recruiting buggy code with this, and it is reporting. It shows that this code should not be like this and the reason for it. For example, it shows that you should declare a static function, or why you should or should not initialize a variable. This is an amazing feature. I am enjoying testing SonarQube, but I don't know what is the feedback from a developer's point of view.
I highly recommend SonarQube. I would rate this solution a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
DevSecOps Lead at a tech services company with 11-50 employees
Detects problems before source code is even compiled, but improvements are needed to reduce the false positives
Pros and Cons
- "Before you even compile, it can catch known vulnerability issues or patterns."
- "Our developers have complained about the Quality Gates and the number of false positives that this product reports."
What is our primary use case?
Our software developers use SonarQube to catch any issues that can be found by using static code analysis. My understanding is that it checks the core complexity by evaluating the coding rules to make sure of things such as the correct classes are private.
How has it helped my organization?
The developers are rejecting the idea that this product is useful.
What is most valuable?
Before you even compile, it can catch known vulnerability issues or patterns.
What needs improvement?
Our developers have complained about the Quality Gates and the number of false positives that this product reports. Their older code is breaking and with the Quality Gate on the pipeline, they are not able to safely release at this point. This means that they have to add a lot of things to the whitelist, so there is room for improvement in this regard.
For how long have I used the solution?
We have been using SonarQube for less than six months. We have not yet onboarded it for production.
What do I think about the stability of the solution?
I have not seen any problems in terms of stability, although it has not been onboarded yet. Once that happens, we may see more problems.
What do I think about the scalability of the solution?
We have not tried to scale yet.
How was the initial setup?
The initial setup involved downloading the open-source code and installing it in a container.
What about the implementation team?
I was responsible for setting up this tool in our company.
What's my experience with pricing, setup cost, and licensing?
We are using the open-source version, which is available free of cost.
Which other solutions did I evaluate?
We evaluated other open-source products and found that SonarQube was the best one of the set.
What other advice do I have?
This product is regularly updated by the open-source community, although the changes are often project-specific and may not help in the general case.
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free SonarQube Server (formerly SonarQube) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Software Development AnalyticsPopular Comparisons
CrowdStrike Falcon Cloud Security
GitHub Advanced Security
OpenText Core Application Security
SonarQube Cloud (formerly SonarCloud)
Sonatype Lifecycle
PortSwigger Burp Suite Professional
Buyer's Guide
Download our free SonarQube Server (formerly SonarQube) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is SonarQube the best tool for static analysis?
- Which gives you more for your money - SonarQube or Veracode?
- What Is The Biggest Difference Between Fortify on Demand And SonarQube?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- How does SonarQube instance relate to the license?
- Which software is ideal for code quality and security?
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?