Try our new research platform with insights from 80,000+ expert users
reviewer1276710 - PeerSpot reviewer
Associate Consultant at a comms service provider with 201-500 employees
Consultant
Feb 11, 2020
Efficient at finding vulnerabilities but the number of false positives should be reduced
Pros and Cons
  • "The most valuable feature is the efficiency of the tool in finding vulnerabilities."
  • "The most valuable feature is the efficiency of the tool in finding vulnerabilities."
  • "A high number of false positives are reported and this should be reduced."
  • "A high number of false positives are reported and this should be reduced."

What is our primary use case?

I am a consultant and SourceClear is one of the solutions that I use to provide services.

This solution is used by people who want to verify the security of their own applications.

What is most valuable?

The most valuable feature is the efficiency of the tool in finding vulnerabilities.

What needs improvement?

A high number of false positives are reported and this should be reduced.

For how long have I used the solution?

I have been using SourceClear for about a year and a half.

Buyer's Guide
Veracode
March 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.

What do I think about the stability of the solution?

This is a stable solution.

What do I think about the scalability of the solution?

We have no complaints about scalability. We have between 200 and 300 clients.

How are customer service and support?

We have not been in touch with Veracode's technical support.

Which solution did I use previously and why did I switch?

We have also used Checkmarx, where you can train the tool for false positives and ultimately reduce them.

How was the initial setup?

The initial setup is a little bit complex.

What about the implementation team?

It would be better to have some assistance when implementing this solution.

What other advice do I have?

Overall, SourceClear is working fine for us and our main complaint is in regard to the high number of false positives. Nonetheless, I would recommend Checkmarx over SourceClear.

I would rate this solution a six out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
SeshagiriSriram - PeerSpot reviewer
Head IT Architecture at a tech vendor with 11-50 employees
Real User
Jun 19, 2019
Enables us to perform security checks with ease
Pros and Cons
  • "We used it for performing security checks. We have many Java applications and Android applications. Essentially it was used for checking the security validations for compliance purposes."
  • "My point is that Veracode is very good, and I would strongly recommend it."
  • "One of the things that we have from a reporting point of view, is that we would love to see a graphical report. If you look through a report for something that has come back from Veracode, it takes a whole lot of time to just go through all the pages of the code to figure out exactly what it says. We know certain areas don’t have the greatest security features but those are usually minor and we don’t want to see those types of notifications."
  • "The only issue that we have is uploading the code, the process of actually uploading and getting our results back; all of that is a little cumbersome."

What is our primary use case?

We used it for performing security checks. We have many Java applications and Android applications. Essentially it was used for checking the security validations for compliance purposes.

How has it helped my organization?

Technically there is nothing wrong with Veracode. The only issue that we have here is uploading the code, the process of actually uploading and getting our results back. All of that is a little cumbersome. 

What needs improvement?

Technically there is nothing wrong with Veracode. The only issue that we have is uploading the code, the process of actually uploading and getting our results back. All of that is a little cumbersome. 

One of the things that we have from a reporting point of view, is that we would love to see a graphical report. If you look through a report for something that has come back from Veracode, it takes a whole lot of time to just go through all the pages of the code to figure out exactly what it says. We know certain areas don’t have the greatest security features but those are usually minor and we don’t want to see those types of notifications. So we would like to see a kind of a graphical representation of the problem areas. I would like to know which file is the biggest source of issues for me so that I can focus on resolving the issue, as a project manager. With how it is now, I am able to do this but I have to take out the whole PDF file and extract it. It takes up a lot of my time. I would like to see better strategic reporting. It would be great to get better graphical reporting.

For how long have I used the solution?

We have been using it for three years.

What do I think about the stability of the solution?

Stability is very good and there were no issues. I will give it five stars.

What do I think about the scalability of the solution?

It's very good; really very good. I would strongly recommend that. Technically I would be expecting a double concept for Veracode. I would still say this is one of the best products ever on that website. I don't have any issues with the scalability. 

How are customer service and technical support?

I had no technical issues at all.

How was the initial setup?

The initial setup can be a little complex for people or for organizations that don't have technical skills. Another small thing is that you need to have one person who's fluent and technically knowledgeable to help during the upload process. But otherwise, it's pretty much straightforward. It's not an issue, it's perfect.

What other advice do I have?

I would strongly recommend doing an internal analysis first, before setting it across to Veracode to proceed and to use it more as a final verification point. My point is that Veracode is very good, and I would strongly recommend it. I have seen other solutions on the market and that's why I say: don't waste your time on other products, just get Veracode.

I would rate it an eight out of ten. Not a ten because of the reporting issues I mentioned that I would like to see improved.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Veracode
March 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
Senior Solutions Architect at NessPRO Italy
Real User
Jun 12, 2019
A well supported and valuable tool that was part of our DevSecOps process
Pros and Cons
  • "I have used this solution in multiple projects for vulnerability testing and finding security leaks within the code."
  • "I would recommend Veracode."
  • "Ideally, I would like better reporting that gives me a more concise and accurate description of what my pain points are, and how to get to them."
  • "I found that there were far too many warnings and some false positives."

What is our primary use case?

I have used this solution in multiple projects for vulnerability testing and finding security leaks within the code.

How has it helped my organization?

We were embracing Veracode as a process in our DevSecOps, although I have not personally used this solution for the past eight months.

What needs improvement?

This is not a very elaborate application. I think that the suggestions are between thirty-five and eighty percent accurate, with most cases being about seventy-five percent. Some of them are references where you have to go and determine whether they are direct threats, or not.

At the point in time when we were using this solution, we had older coders and the way Veracode tests for vulnerabilities may have been affected by the code style. I found that there were far too many warnings and some false positives. Of course, this comes with every product, and there are multiple tools that are used.

Ideally, I would like better reporting that gives me a more concise and accurate description of what my pain points are, and how to get to them.

What do I think about the stability of the solution?

In the context of a dev or UIT environment, I'll say that it is fairly stable. However, I would not be able to give ratings for stability in a production environment because I have no experience with it.

How are customer service and technical support?

Technical support was good and I was very happy with them.

We did not have that many issues to start with. They conducted training, and there was an architect that was working directly with me to answer everything. He was fairly knowledgeable. In the beginning, when we wanted to understand the product, he gave us great pointers. He provided very nice documentation that we followed and we were able to establish with the infrastructure team.

Which solution did I use previously and why did I switch?

I have used multiple tools similar to Veracode that integrate with the IDE.

How was the initial setup?

The initial setup was straightforward. What I recall is that it was not really difficult and we had optimal support. They also provided us with documentation to help set up integration with tools such as Jenkins.

What other advice do I have?

When it comes to DevSecOps, in the industry it is still under adoption. With the advent of the cloud and code being there, or on other public platforms, many people have embraced it or are in the process doing so. 

My advice for anybody interested in implementing this solution is to be really careful when choosing your tools. Be very proactive and up-front on the requirements of your systems, because no tool is perfect. You need to find the best fit for each particular use case. I would do a thorough analysis.

As a solution architect, I do small POCs and run initiatives on products to find out various aspects. For example, the technical feasibility of the product is an important aspect. Other important ones are usability, testing, and implementation. Normally, I select at least three products and do a comparative analysis based on the POC. After this, I recommend a particular solution.

I would recommend Veracode. There are plusses and minuses to this solution, but given the chance to use it again I would definitely do so. Every product has its own flaws, but for my use case, it did fit very well.

I would rate this solution an eight and a half out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user920715 - PeerSpot reviewer
Managing Principal Consultant at a tech vendor with 11-50 employees
Real User
Jun 12, 2019
Easy to scale and does a good job, but only for a limited number of technologies
Pros and Cons
  • "The most valuable feature comes from the fact that it is cloud-based, and I can scale up without having to worry about any other infrastructure needs."
  • "The most valuable feature comes from the fact that it is cloud-based, and I can scale up without having to worry about any other infrastructure needs."
  • "I would like to see expanded coverage for supporting more platforms, frameworks, and languages."
  • "My advice for anybody who is interested in implementing this solution is to ensure that your technology is actually supported because the coverage is quite patchy."

What is our primary use case?

Our primary use case for this solution is application security.

What is most valuable?

The most valuable feature comes from the fact that it is cloud-based, and I can scale up without having to worry about any other infrastructure needs.

What needs improvement?

This solution does a good job, but it is limited to only a few technologies. I would like to see expanded coverage for supporting more platforms, frameworks, and languages.

Specifically, I would like to see support for mobile frameworks like Xaramin and React JS, as well as extended support for iOS applications.

For how long have I used the solution?

Five years.

What do I think about the scalability of the solution?

This solution is quite scalable.

We have approximately fifty users, but we definitely have plans to add more.

How are customer service and technical support?

I have used their technical support and they are quite good.

Which solution did I use previously and why did I switch?

We did not use another solution prior to this one.

How was the initial setup?

The initial setup of this solution is straightforward.

What's my experience with pricing, setup cost, and licensing?

This solution is on the pricey side. They have just streamlined the licensing and they have a number of flexible options available, so overall it is quite good, albeit pricey.

Which other solutions did I evaluate?

We evaluated other options, but we chose Veracode.

What other advice do I have?

My advice for anybody who is interested in implementing this solution is to ensure that your technology is actually supported because the coverage is quite patchy. It is possible that if you use a framework or a language that Veracode does not support then it will give quite poor results.

I would rate this solution a six out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
AVP, IS Manager at a financial services firm with 1,001-5,000 employees
Real User
Dec 18, 2018
Substantially reduces the number of unmitigated flaws in our code
Pros and Cons
  • "The volume of unmitigated flaws in our applications has been substantially reduced."

    What is our primary use case?

    We use Veracode to scan custom-developed code for flaws.

    How has it helped my organization?

    • The volume of unmitigated flaws in our applications has been substantially reduced.
    • In terms of AppSec best practices, the team at Veracode has provided industry benchmarks against which we are measuring our improvement.
    • Our customers have benefited from the added security assurance of our applications, although they may not know it.

    What is most valuable?

    The identification of flaws.

    What needs improvement?

    We would like to see improvement in reporting, in particular, end dates on mitigations.

    For how long have I used the solution?

    Three to five years.

    What do I think about the stability of the solution?

    The solution is very stable.

    What do I think about the scalability of the solution?

    It has handled all the expansion we have required from it.

    How is customer service and technical support?

    Technical support is highly competent.

    How was the initial setup?

    It was already implemented when I joined the organization. However, we have expanded greatly.

    What's my experience with pricing, setup cost, and licensing?

    We are about to enter discussions for renewal. I have heard there may be some changes to pricing. I will reserve judgment until the discussions are complete.

    What other advice do I have?

    I would recommend it. It covers all our custom-developed applications and will expand as new applications and services are added.

    We have 50-plus users of Veracode. Their roles include InfoSec, developers, development managers, QA, and configuration management. In terms of deployment and maintenance, we have four people in configuration management and InfoSec.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    ChiefInfaf47 - PeerSpot reviewer
    Chief Information Security Officer with 501-1,000 employees
    Real User
    Nov 19, 2018
    Helped us address our critical vulnerabilities through static scanning
    Pros and Cons
    • "One of the valuable features is that it gives us the option of static scanning. Most tools of this type are centered around dynamic scanning. Having a static scan is very important."
    • "Right now, I couldn't ask another thing from them."
    • "However, they were quick to comment that the product is too expensive and that there are too many false positives which take too much time to remediate."

    What is our primary use case?

    We use it for static checking.

    How has it helped my organization?

    We are a state agency, we're not a private-sector company. What we're able to do is take our main web-based application, which is not only for internal use but which the citizens of Ohio also use, and we can run this application, and others as well, through Veracode to ensure that we've done our job, our due diligence.

    We print out a report, we see the rating of the vulnerabilities that have been found: "critical" and "high", "moderate" and "low." We've been able to go from having critical vulnerabilities to where we're now into the more moderate range. We've shown improvement through the years. We can provide that information to our superiors, and to people who come in and audit us, to show that we've made progress on scanning.

    When we find a vulnerability, we do pass it on to our developers and they've been able to go in and adjust the code so that the vulnerability is no longer there. The goal, of course, is that these findings will help them as they develop new code so that these vulnerabilities are not a part of the next application. We run a follow-up scan to make sure the vulnerability has been cleared.

    The benefit, at this point, has been more internal than for our customers. Obviously we don't want them to have a problem so that they could then, theoretically, actually see the benefit. We try to be proactive.

    What is most valuable?

    • Having the option of static scanning. Most tools of this type are centered around dynamic scanning. Having a static scan is very important.
    • Utilizing the software as a service. We do the scanning of the compiled code ourselves but it's on their servers, which is a plus.
    • Technical support is available if needed and that is advantageous.
    • Having online education and training is also advantageous. 

    What needs improvement?

    I attended a meeting of one of the security organizations I am associated with. At the meeting were security professionals from several major retail companies. The topic of discussion happened to be application development security. When the question was asked concerning what tools are being used, many of these major retail companies said they are using Veracode. However, they were quick to comment that the product is too expensive and that there are too many false positives which take too much time to remediate.

    For how long have I used the solution?

    More than five years.

    What do I think about the stability of the solution?

    The stability is very good. They haven't had too many updates or upgrades. They did a major upgrade several years ago but it came out just fine. It has been a really good product.

    What do I think about the scalability of the solution?

    I'd call us a "mid-range" agency, so it's not like we have a ton of applications that we're changing and updating. It's good for us, but I can't really answer how scalable it is because we're not really big.

    How is customer service and technical support?

    I don't believe that the team has had any problem going on to the website, downloading the static code, or running scans. They do it quite often without any issue and are able to read the report and rectify whatever vulnerability has been discovered. There has not been a problem walking through those steps. It's been pretty straightforward. And if our team has any problems, we've got access to someone that we can schedule a call with to work out the issues.

    We haven't had to call tech support too often, but when we have had to call them, support has been good in terms of resolution time.

    How was the initial setup?

    I was involved, on a cursory level, with the setup. Our implementation strategy was to focus on our main web-based application. The way that they developed the application here was under one static set of code, so we could scan this code and, in essence, be able to check the vulnerability of most of the applications from the different business in our agency.

    What about the implementation team?

    We did not use an integrator or a third-party. We did it with the help of Veracode.

    What was our ROI?

    We are a state agency, so we're not for profit. I tell everybody we don't make money, we spend money. To frame it in the context of the public sector, I think we are giving our citizens peace of mind. When they come in to write a permit, and we send them to a service that collects payment, that jumping-off point is secure and safe. It would be more in those terms, rather than the bottom line.

    In the public sector, return on investment is not a term that is easily understood because we do not invest. But total cost of ownership is something that we can put our arms around. When we think about potential data breaches, Veracode has certainly helped us. When you think about the cost of the product and that I have one person, not ten people, running this tool, the total cost of ownership is low. I have no devices or servers, I didn't have to do any of that here onsite. It's all in the cloud. The total cost of ownership, given the services they provide, is very low, in my opinion.

    What's my experience with pricing, setup cost, and licensing?

    We're always looking to save the taxpayers' money. I used to tell my vendors, sharpen those pencils and make the tip laser-sharp. When it can be, I want it to be less expensive, but you get what you pay for too. Vendors need to be fair and I think Veracode has been fair.

    We use their SaaS solution and it's just an annual subscription.

    Which other solutions did I evaluate?

    The state of Ohio decided to bring AppScan in and that's an IBM tool. IBM became a major vendor in the state of Ohio. But what happened is that AppScan does not offer static code vulnerability checking; dynamic is something they do offer, but it's not as complete and comprehensive as a static scan is. Even the state has gone away from AppScan, but we were looking at it, we were starting to get set up for it. But evidently, other agencies haven't found it to be as useful. So we're not going that direction, we're staying with Veracode. 

    There would have been cost savings associated with going with AppScan but we decided, because the state was not going that way, that we were not going that way either.

    What other advice do I have?

    I would absolutely recommend Veracode. I've suggested to one of the larger agencies that they implement the solution and that they come to see what we've experienced and how we use the tool.

    I really like Veracode. That is one of the reasons that we brought them onboard ten years ago. Of course, they were new back then. The different aspects of the offerings that Veracode provides to their customers are somewhat unique and, right now, I couldn't ask another thing from them.

    We have approximately 30 Java developers and four or five testers. There are also project managers using it. We have one person who manages running of the scans and that person might have one or two other people to help.

    We haven't really been utilizing it to its full potential. We probably utilize it once or twice per quarter. We are planning to increase the capacity that we've purchased. However, we're getting ready to elect a new governor in Ohio. With that election, things will change, according to his or her desires. Right now, we're in a holding pattern waiting for November to come and go.

    In terms of integrating the solution into our existing software development lifecycle, because we started so long ago - before the software development lifecycle was fully implemented - we were doing Veracode testing just because it was a good idea. Then we actually developed a lifecycle. We got into scrums and it just naturally worked its way in, so when we actually hired a testing group, Veracode was already a part of the process.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    it_user673734 - PeerSpot reviewer
    Chief Technology Officer at a tech vendor with 201-500 employees
    Real User
    Nov 19, 2018
    Increases our confidence in the security of our sever-side and mobile apps
    Pros and Cons
    • "It has an easy-to-use interface."
    • "It gives us more confidence in the application security of the products we scan."
    • "We would like a way to mark entire modules as "safe." The lack of this feature hasn't stopped us previously, it just makes our task more tedious at times. That kind of feature would save us time."
    • "We would like a way to mark entire modules as "safe." The lack of this feature hasn't stopped us previously, it just makes our task more tedious at times."

    What is our primary use case?

    We use it for security scanning of SaaS and mobile software that we develop: one server-side and two mobile applications. Most customers require SAST and DAST scanning in order to purchase.

    How has it helped my organization?

    It gives us more confidence in the application security of the products we scan. We use it as part of our AppSec best practices. 

    What is most valuable?

    It has an easy-to-use interface.

    What needs improvement?

    We would like a way to mark entire modules as "safe." The lack of this feature hasn't stopped us previously, it just makes our task more tedious at times. That kind of feature would save us time.

    What do I think about the stability of the solution?

    We have never had any problems with the solution.

    What do I think about the scalability of the solution?

    It has always worked for us, we haven't found any issues. There have been no problems with scanning small and large objects.

    How are customer service and technical support?

    Technical support is excellent. It meets our needs.

    Which solution did I use previously and why did I switch?

    We had no previous solution. Our choice of Veracode was due to Veracode being a customer and requiring that we use their tool to scan our solution.

    How was the initial setup?

    The initial setup was straightforward. As it's a SaaS solution, it took no time to set up. But because I didn't take training, I spent a bit of time figuring out the product. No implementation (or strategy for implementation) was required, beyond some simple configuration settings.

    What's my experience with pricing, setup cost, and licensing?

    No issues, the pricing seems reasonable.

    Which other solutions did I evaluate?

    We evaluated no other products for SAST when we started using Veracode. 

    What other advice do I have?

    Be aware that the first run will find a lot of issues, many of which are not real issues; it will take time to understand that. Don't change object names as that will confuse it. Make sure you get development buy-in early.

    We're looking to expand its use within the development organization and are looking into another license. Currently, we have four users of the solution, myself (security) and developers. The four of us also maintain it.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    it_user941793 - PeerSpot reviewer
    Global Presales Head - Security Assurance at Wipro Technologies
    Real User
    Oct 17, 2018
    Provides faster scans but with a higher number of false positives
    Pros and Cons
    • "Veracode provides faster scans compared to other static analysis security testing tools."
    • "Veracode provides faster scans compared to other static analysis security testing tools."
    • "Veracode scans provide a higher number of false positives."
    • "The overall reporting structure is complicated, and it's difficult to understand the report."
    • "Veracode scans provide a higher number of false positives."

    What is our primary use case?

    Static application security testing, which is the primary use case. 

    There were different web applications which were scanned using this tool.

    How has it helped my organization?

    Veracode scans provide a higher number of false positives. Also, the overall reporting structure is complicated, and it's difficult to understand the report.

    What is most valuable?

    Veracode provides faster scans compared to other static analysis security testing tools.

    What needs improvement?

    Veracode should provide support to more software languages, like ABAP.

    For how long have I used the solution?

    Less than one year.
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1384917 - PeerSpot reviewer
    reviewer1384917Director, Customer Advocacy at a tech vendor with 501-1,000 employees
    Real User

    Thank you for taking the time to share your experience with Veracode. We appreciate your time and hope all is going well. Please let me know if there's anything I can do to help.  My role is new here and I'm working to check in with customers who have taken effort to comment on their Veracode solutions.

    Buyer's Guide
    Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.
    Updated: March 2026
    Buyer's Guide
    Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.