Try our new research platform with insights from 80,000+ expert users
Global Presales Head - Security Assurance at Wipro Technologies
Real User
Provides faster scans but with a higher number of false positives
Pros and Cons
  • "Veracode provides faster scans compared to other static analysis security testing tools."
  • "Veracode scans provide a higher number of false positives."
  • "The overall reporting structure is complicated, and it's difficult to understand the report."

What is our primary use case?

Static application security testing, which is the primary use case. 

There were different web applications which were scanned using this tool.

How has it helped my organization?

Veracode scans provide a higher number of false positives. Also, the overall reporting structure is complicated, and it's difficult to understand the report.

What is most valuable?

Veracode provides faster scans compared to other static analysis security testing tools.

What needs improvement?

Veracode should provide support to more software languages, like ABAP.

Buyer's Guide
Veracode
May 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.

For how long have I used the solution?

Less than one year.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1384917 - PeerSpot reviewer
reviewer1384917Director, Customer Advocacy at Veracode
Real User

Thank you for taking the time to share your experience with Veracode. We appreciate your time and hope all is going well. Please let me know if there's anything I can do to help.  My role is new here and I'm working to check in with customers who have taken effort to comment on their Veracode solutions.

PeerSpot user
Executive Director at Parthenon-EY
Real User
It has almost completely eliminated the presence of SQLi vulnerabilities. Needs more timely support for newer languages and framework versions.
Pros and Cons
  • "It has almost completely eliminated the presence of SQLi vulnerabilities."
  • "It gives feedback to developers on the effectiveness of their secure coding practices."
  • "It needs more timely support for newer languages and framework versions."

What is our primary use case?

  • Scanning web-facing applications for potential security weaknesses.
  • Helping to document the introduction of technical debt in our code bases.

How has it helped my organization?

  • It gives feedback to developers on the effectiveness of their secure coding practices.  
  • It has almost completely eliminated the presence of SQLi vulnerabilities.

What is most valuable?

  • Multiple languages and framework support: We can use one tool for our SAST needs.
  • Developers report liking the IDE integration provided by this tool.

What needs improvement?

  • More timely support for newer languages and framework versions.  
  • Integration with Slack is another request from our developers.

For how long have I used the solution?

Trial/evaluations only.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Veracode
May 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
reviewer923928 - PeerSpot reviewer
Team Lead / Architect at a tech services company with 1,001-5,000 employees
Real User
We use its static analysis during development to eliminate vulnerability issues
Pros and Cons
  • "We use Veracode static analysis during development to eliminate vulnerability issues"
  • "I have found the user interface extremely helpful in prioritizing issues."
  • "They should improve on the static scanning time."

What is our primary use case?

I use Veracode to run scans on .NET applications, web applications and Windows/fat form applications. I also use it to make deployments in three-tier environments: the application server tier, web server tier and the database tier.

How has it helped my organization?

  • Veracode has improved our penetration testing process. 
  • We use Veracode static analysis during development to eliminate vulnerability issues.

What is most valuable?

  • I have found the user interface extremely helpful in prioritizing issues.
  • It allows me to prioritize the work to help resolve an issue.

What needs improvement?

They should improve on the static scanning time.

For how long have I used the solution?

Three to five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user

We have heard the need for faster scan times and I see this was an area you wanted to see improvement. I wanted to give you an update regarding our Static scanning. We recently extended the Veracode Static Analysis product family to include three purpose-built scan types:

• IDE Scan, which provides fast, automated security feedback to developers in the IDE, in seconds
• Pipeline Scan, a new, first-of-its-kind offering, which runs on every build and provides security feedback on code at a team level, with a median scan time of 90 seconds
• Policy Scan, which returns a full security assessment of the code before release, in a median scan time of 8 minutes

If you would like more information on our static analysis improvements let me know!

Managing Director at Harrods
Real User
Provides the capability to track remediation and the handling of identified vulnerabilities. The application does not support API or Dynamic Application Security Testing
Pros and Cons
  • "Allows us to track the remediation and handling of identified vulnerabilities."
  • "Provides the capability to track remediation and the handling of identified vulnerabilities."
  • "The security team can track the remediation and risk acceptance statistics."
  • "The solution does not support Dynamic Application Security Testing."
  • "The current version of the application does not support testing for API."

What is our primary use case?

We are planning on introducing a static code analysis tool to support a DevOps effort in our environment. The objective of the solution is to allow the team to identify vulnerabilities in the source code and improve the hygiene of the developed code before deployment.

How has it helped my organization?

This is currently still under evaluation, and it is pending review and assessment against other static code analysis solutions.

What is most valuable?

The solution provides the capability for the application teams to track remediation and the handling of identified vulnerabilities. The system provides workflow capabilities for the application teams to send the completed scans to the security teams for their review. In addition, the security team can track the remediation and risk acceptance statistics.

What needs improvement?

The solution currently does not support Dynamic Application Security Testing which is an important facet of application security testing. In addition, the current version of the application does not support testing for API.

For how long have I used the solution?

Trial/evaluations only.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Associat7de6 - PeerSpot reviewer
Associate Director
Real User
Provides security of different Shadow IT activities in our environment, however there are limitations on reporting causing bottlenecks
Pros and Cons
  • "The tech support has been very much on the forefront of contacting customers. They help us by making sure all the processes have been outlined and are being followed. They regularly look with us at the whole platform process."
  • "It provides security of different Shadow IT activities in our environment, especially around application development and website hosting."
  • "We would like the consolidation of all the different modules. This would help, so then we would be able to see analytics and results on one screen, like a single pane of glass."
  • "Once your report has been generated, you need to review the report with consultation team, especially if it is too detailed on the development side or regarding the language. Then, you need some professional help from their end to help you understand whatever has been identified. Scheduling consultation takes a longer time. So, if you are running multiple reports at the same time, then you need to schedule a multiple consultation times with one of their developers. There are few developers on their end who work can work with your developers, and their schedules are very tight."

What is our primary use case?

Application security scanning.

How has it helped my organization?

It has helped us identify all the applications flaws, especially with so many open source licenses available to the developers. With this product, it allows you to plug in all those gaps where you may open up the backdoors. This tool has helped us everyday with our goal to plug in all those gaps.

We help make changes from the initial NAS that we sign up with the vendors and any third party who might be involved in our telephone activities. They have to ensure that phone is a standby application and security tool, plus we also make the changes in the workflow for any application. Before it is deployed into operations, it has to have a security certificate which proves that it has a Veracode application security certification on it and all the flaws that have been identified have been removed.

What is most valuable?

It has several components in that help you identify abilities in the core. It also provides security of different Shadow IT activities in our environment, especially around application development and website hosting.

What needs improvement?

They are already working on, but we are looking forward to seeing it. We would like the consolidation of all the different modules. This would help, so then we would be able to see analytics and results on one screen, like a single pane of glass. 

Once your report has been generated, you need to review the report with consultation team, especially if it is too detailed on the development side or regarding the language. Then, you need some professional help from their end to help you understand whatever has been identified. Scheduling consultation takes a longer time. So, if you are running multiple reports at the same time, then you need to schedule a multiple consultation times with one of their developers. There are few developers on their end who work can work with your developers, and their schedules are very tight. Therefore, you have the report ready if you want a consultation, then it sometimes takes more than three to four days to arrange a meeting. I feel to wait four days to get a consultation and understand the report around the whatever has been identified is a bottleneck. 

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

We have not seen any major downtime.

How are customer service and technical support?

I would rate their technical support as a nine out of 10.

The tech support has been very much on the forefront of contacting customers. They help us by making sure all the processes have been outlined and are being followed. They regularly look with us at the whole platform process. Therefore, they have been quite helpful.

They have an account manager for personal relations between the customer and their technical people. This person takes care of bringing them the right person to address any issues that we have.

Two years back, Veracode was having issues. It was taking a long time to start the application, and we worked with their technical support. They also have been constantly improving the platform.

Which solution did I use previously and why did I switch?

We did not previously use another solution.

How was the initial setup?

It was a bit complex initially when we started, because we had not been previously exposed to any such tool.

It is a SaaS tool. So, towards the end, we did not have to install anything. We just needed an account for the platform to upload the build. There was an initial issue, because people were not previously exposed to this type of process, and it was something new that they were being asked to do.

What was our ROI?

It has helped us reduce our overall time to remedy any validity, which can be found after being rolled out and put into production. Though, I cannot give you the number. It is always better to safeguard the environment rather than being hacked or have production downtime. In three years, we have not had any breaches or we seen any reduction in Shadow IT.

What's my experience with pricing, setup cost, and licensing?

It is pricey. There is a lot of value in the product, but it is a costly tool.

The customer should demand better turnaround times for the money that they are paying, especially around the reporting and standing up processes that we need to go through. It needs much more technical information on the platform with a tool that can help with information or have 24/7 support available, then it will be worth the price that we are paying, because right now, we don't have many options. There are not may companies who are in the market for Veracode, who want this type of in-depth analysis and examination. That is why customers, with the money that they are paying, have room for improvement in the scope of the Veracode product. 

I recommend going for a one-year licensing with CA, because currently they are the leaders in this field with more features and a much better turn around time with a cheaper position, but there are a lot of new companies coming up in the market and they are building up their platforms. I suggest just not to get tied up with a long-term commitment, because I have seen with Black Duck that they are almost one-third of the price of the big platforms. Once there are the same features and functionality (or lot better performance) available in the market, people are going to migrate away from this platform. The market is changing so fast, and with the Black Duck acquisition, it is also expected that we may get a solution with a much faster platform with much better service at a cheaper price.

Which other solutions did I evaluate?

We did a PoC with Black Duck.

What other advice do I have?

I would rate the product as an eight out of 10 for recommend it to colleagues.

I would rate the overall product as a seven out of 10.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user802140 - PeerSpot reviewer
Product Manager at GMS
Real User
All areas of the solution could use some improvement. It helps me to detect vulnerabilities.
Pros and Cons
  • "It helps me to detect vulnerabilities."
  • "All areas of the solution could use some improvement."

What is our primary use case?

We are Veracode partners/distributors in Quito, Ecuador. 

At this moment, I am reviewing the solution. 

How has it helped my organization?

It helps me to detect vulnerabilities.

What is most valuable?

I use the SAST feature the most.

What needs improvement?

All areas of the solution could use some improvement.

For how long have I used the solution?

Trial/evaluations only.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are Veracode partners/distributors in Quito, Ecuador.
PeerSpot user
it_user873405 - PeerSpot reviewer
Lead Security Engineer at a tech vendor with 201-500 employees
Real User
Our customers get the security of bug-free code, but raw file scans would help
Pros and Cons
  • "Scanning of .war and .jar is key for us."
  • "Raw file scans and dynamic scans would be an improvement, instead of dealing with code binaries."

What is our primary use case?

SAST. We have not yet integrated it into our software development lifecycle as it doesn't have the feature that enables us to integrate it with our repository.

How has it helped my organization?

It helps in achieving secure programming. Veracode provides us with industry best practices according to OWASP, CERT, and SANS. Our customers get the security of bug-free code and assurance regarding the application.

What is most valuable?

Scanning of .war and .jar.

What needs improvement?

Raw file scans and dynamic scans would be an improvement, instead of dealing with code binaries.

For how long have I used the solution?

Trial/evaluations only.

What do I think about the stability of the solution?

No stability issues yet.

What do I think about the scalability of the solution?

No scalability issues yet.

Which solution did I use previously and why did I switch?

We used SonarQube but to improve security in SAST we choose this.

How was the initial setup?

Setup is straightforward.

What's my experience with pricing, setup cost, and licensing?

The pricing is good for static code analysis.

Which other solutions did I evaluate?

Checkmarx, SonarQube.

What other advice do I have?

Implement this solution if you see WAF and SOC in your future.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user877104 - PeerSpot reviewer
VP Worldwide Delivery Acceleration at a financial services firm
Real User
Improved our security posture without the overhead of supporting infrastructure
Pros and Cons
  • "Because it is a SaaS offering, I do not have to support the infrastructure."
  • "Some important languages are not supported."
  • "We have encountered occasional issues with scalability."

What is our primary use case?

SAST vulnerability scanning. Veracode is embedded in our release pipeline.

How has it helped my organization?

It improved our security posture. In terms of cost savings relating to code fixes since implementing Veracode, I'm not sure there are any. How do you quantify reputational damage from a security breach? However, they have provided AppSec best practices and guidance to our security and development teams through our support agreement, weekly meetings, and annual review.

What is most valuable?

Because it is a SaaS offering, I do not have to support the infrastructure.

What needs improvement?

Some important languages are not supported.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

We have encountered occasional issues with scalability.

How is customer service and technical support?

Tech support is excellent.

How was the initial setup?

The initial setup was extremely straightforward.

What's my experience with pricing, setup cost, and licensing?

Negotiate for the best deal.

Which other solutions did I evaluate?

Fortify, App Scanner, Checkmarx.

What other advice do I have?

Make sure the supported  languages align with your developers.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.