Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Technical Program Manager at a engineering company with 10,001+ employees
Real User
The coverage it provides of the last vulnerabilities reported and of the programming languages is valuable.
Pros and Cons
  • "The coverage of the last vulnerabilities reported."
  • "To be able to upload source codes without being compiled. That’s one feature that drives us to see other sources."

How has it helped my organization?

We decided to begin a partnership with Veracode, so we can improve our services and provide the customers that trust us with a platform capable to report vulnerabilities and also delegate and keep tracking of the remediation until the applications score 100% on stability before they go to production.

What is most valuable?

  • Customer and professional support
  • Live sessions and training
  • The coverage of the last vulnerabilities reported
  • The coverage of the programming languages

What needs improvement?

  • To be able to upload source codes without being compiled. That’s one feature that drives us to see other sources.

Compiled code means that the code written is stored in binaries for machine reading only. Veracode reads only those binaries (compiled code). The other way to have the code is “Source Code written only”, a process where you don’t compile and anyone is able to read line by line the code.

This example might seem weird, but maybe will clear things out:

Binary Code (Supported by Veracode):

11110001011000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 00010 010

11110001011000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 11110 010

1111000101000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 00010 0101

Source Code:

public class HelloWorld {

public static void main(String[] args) {

// Prints "Hello, World" to the terminal window.

System.out.println("Hello, World");

}

}

What do I think about the stability of the solution?

When tracking source code vulnerabilities, sometimes it’s possible that the tool loses the path of the issues when the source code has been modified significantly.

Buyer's Guide
Veracode
July 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,384 professionals have used our research since 2012.

How are customer service and support?

Customer Service:

Customer and platform support is one of the best in the field. The experts are skilled and can have as many meetings and researches as needed.

Technical Support:

The Veracode support team excels with help of their experts capable to solve most of the situations, and taking advantage of the variety of their members to delegate issues and problems to solve.

Which solution did I use previously and why did I switch?

I use a portfolio of tools for security consulting, but Veracode is the main app I rely on because customers are happy to be able to track the status of each individual issue or vulnerability.

How was the initial setup?

Initial setup is very complex, requiring security knowledge, but it’s easy when experts guide you through all the process. Even after months of use, the Veracode experts are always there to help you on both the workflow and the dashboard tool.

What's my experience with pricing, setup cost, and licensing?

Veracode is a very complete tool; that drives you to invite customers, the apps team, developers and even the product and marketing team to navigate through the whole application. Its complexity makes it quite expensive, but it’s all worth it, with all the engineering in the background.

Which other solutions did I evaluate?

Before choosing this product, many tools were tested, such as HPE WebInspect, AppScan, Checkmarx, etc. Those tools are good, and do their jobs really well. Veracode has many pros that involve a human touch, which is something a consulting firm, customers and big companies want from the information technology field.

What other advice do I have?

I recommend exhausting all resources and gaining knowledge from different security tools, before making a decision. Veracode is not cheap, but it is a tool capable of giving dynamic, static and even manual scan results in one platform. Veracode is one of very few options out there, and the very best.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user335091 - PeerSpot reviewer
Senior Security Consultant at a retailer with 1,001-5,000 employees
Real User
We were able to easily integrate static code testing into the SDLC process, moving from the waterfall to the agile methodology while still able to integrate Veracode testing within both.

Valuable Features

Static code analysis is a valuable feature.

Improvements to My Organization

We were able to easily integrate static code testing into the SDLC process. We moved from the waterfall to the agile methodology, and were still able to integrate Veracode testing within both methodologies.

Room for Improvement

It's been over a year since I used the product. But when I did, I found there were too many false positives.

Use of Solution

I used it for one year.

Deployment Issues

No issues encountered.

Stability Issues

No issues encountered.

Scalability Issues

No issues encountered.

Customer Service and Technical Support

Customer Service:

8/10

Technical Support:

8/10

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Veracode
July 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,384 professionals have used our research since 2012.
Jesus Montes Ceron - PeerSpot reviewer
Architect of solutions at IPComMx
Reseller
Top 20
Utilized for scanning containers and integrated within DevOps workflows
Pros and Cons
  • "The coverage of backdoors attacks on security that's the most valuable for my clients."
  • "There is room for improvement in documentation."

What is our primary use case?

We used Barracuda for scanning containers. And in all in DevOps workflow.

What is most valuable?

The coverage of backdoors attacks on security that's the most valuable for my clients.

What needs improvement?

There is room for improvement in documentation. Maybe the documentation about how to configure something. It is difficult to get the expected result. 

For how long have I used the solution?

I have been using this solution for two years. 

What do I think about the stability of the solution?

It's stable. It works very well in the parameter like an enterprise solution. We don't have any problems with that.

How are customer service and support?

We are very pleased with the support.

How would you rate customer service and support?

Positive

How was the initial setup?

I would rate my experience with the initial setup a six out of ten, where one is difficult and ten is easy to set up. 

What about the implementation team?

We work on the deployment process. The solution is deployed both on-prem and in the cloud environment.

The solution doesn't require any maintenance. 

What was our ROI?

It took two years to see ROI for our clients.

What's my experience with pricing, setup cost, and licensing?

Veracode is expensive. But the solution is worth it. 

What other advice do I have?

Overall, I would rate the solution a nine out of ten. It is a good solution for security. In my personal opinion, there are not many products like Veracode in the market. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2025
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.