Checkmarx One is an enterprise cloud-native application security platform focused on providing cross-tool, correlated results to help AppSec and developer teams prioritize where to focus time and resources.
Product | Market Share (%) |
---|---|
Checkmarx One | 10.3% |
SonarQube Server (formerly SonarQube) | 22.4% |
Veracode | 8.8% |
Other | 58.5% |
Type | Title | Date | |
---|---|---|---|
Category | Application Security Tools | Aug 29, 2025 | Download |
Product | Reviews, tips, and advice from real users | Aug 29, 2025 | Download |
Comparison | Checkmarx One vs SonarQube Server (formerly SonarQube) | Aug 29, 2025 | Download |
Comparison | Checkmarx One vs Veracode | Aug 29, 2025 | Download |
Comparison | Checkmarx One vs GitHub Advanced Security | Aug 29, 2025 | Download |
Title | Rating | Mindshare | Recommending | |
---|---|---|---|---|
SonarQube Server (formerly SonarQube) | 4.0 | 22.4% | 81% | 116 interviewsAdd to research |
Wiz | 4.5 | N/A | 95% | 22 interviewsAdd to research |
Company Size | Count |
---|---|
Small Business | 22 |
Midsize Enterprise | 9 |
Large Enterprise | 34 |
Company Size | Count |
---|---|
Small Business | 718 |
Midsize Enterprise | 462 |
Large Enterprise | 2513 |
Checkmarx One offers comprehensive application scanning across the SDLC:
Checkmarx One provides everything you need to secure application development from the first line of code through deployment and runtime in the cloud. With an ever-evolving set of AppSec engines, correlation and prioritization features, and AI capabilities, Checkmarx One helps consolidate expanding lists of AppSec tools and make better sense of results. Its capabilities are designed to provide an improved developer experience to build trust with development teams and ensure the success of your AppSec program investment.
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech
Case Study: Liveperson Implements Innovative Secure SDLC
Author info | Rating | Review Summary |
---|---|---|
Specialist Leader at Deloitte | 4.5 | I work as a partner with Checkmarx One and find its initial setup straightforward, although hybrid deployment is preferred. The tool shows clear ROI, but automated code fixing would enhance its capabilities. Enterprise clients benefit from its effective security scans. |
Project Manager at Selfemployeed | 4.0 | We integrated Checkmarx One into our development pipelines, leveraging its strong SAST and SCA features for efficient code scanning. Improvements are needed in DAST and API security. Overall, it enhances our security practices and offers a good ROI. |
Manager, Engineering at 7-Eleven | 4.5 | I use Checkmarx One for source code validation and security analysis, which helps identify vulnerabilities and offer improvement recommendations. Although its user interface is outdated, it was chosen over SonarQube due to better security analysis capabilities. |
Security Consultant at IBM Thailand | 4.0 | Since switching to Checkmarx One, our static code analysis process has become significantly faster and more efficient, reducing time to production. The tool's cloud-based platform simplifies deployment, though managing multiple projects simultaneously requires improvement. It offers substantial time and workload savings. |
Technical Lead at a computer software company with 10,001+ employees | 3.5 | We use Checkmarx One to check vulnerabilities in our banking products at the build level. The report function is the most valuable feature, though it occasionally identifies false positives. We didn’t use a different solution previously. |
Software Engineer at a manufacturing company with 10,001+ employees | 3.5 | I use Checkmarx One for scanning code vulnerabilities, and it's developer-friendly, though non-developers might struggle. It could improve CI/CD pipeline integration and Codebashing features. I've tried Veracode and FOSSA but can't compare them extensively. |
Penetration Tester & Information Security Expert at a comms service provider with 11-50 employees | 4.5 | I use Checkmarx One for identifying code vulnerabilities during development, appreciating its precise issue tracking. However, the software's memory requirements and unclear communication of internal issues need improvement. An easier false positive reporting system would be beneficial. |
Senior Software Engineering Manager at a financial services firm with 10,001+ employees | 4.0 | We use Checkmarx One primarily for static comprehension testing and appreciate its effective administration features for team management. However, improvements are needed in benefits, dashboard capabilities, and secret scanning. It's comparable to Veracode, with no significant differences noted. |