No more typing reviews! Try our Samantha, our new voice AI agent.
Checkmarx Software Composition Analysis Logo

Checkmarx Software Composition Analysis Reviews

Vendor: Checkmarx
4.5 out of 5

What is Checkmarx Software Composition Analysis?

Featured Checkmarx Software Composition Analysis reviews

Checkmarx Software Composition Analysis mindshare

As of June 2026, the mindshare of Checkmarx Software Composition Analysis in the Software Composition Analysis (SCA) category stands at 2.8%, up from 2.5% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Software Composition Analysis (SCA) Mindshare Distribution
ProductMindshare (%)
Checkmarx Software Composition Analysis2.8%
Snyk11.1%
Black Duck SCA9.2%
Other76.9%
Software Composition Analysis (SCA)

PeerResearch reports based on Checkmarx Software Composition Analysis reviews

TypeTitleDate
CategorySoftware Composition Analysis (SCA)Jun 23, 2026Download
ProductReviews, tips, and advice from real usersJun 23, 2026Download
ComparisonCheckmarx Software Composition Analysis vs SnykJun 23, 2026Download
ComparisonCheckmarx Software Composition Analysis vs VeracodeJun 23, 2026Download
ComparisonCheckmarx Software Composition Analysis vs Black Duck SCAJun 23, 2026Download
Suggested products
TitleRatingMindshareRecommending
Snyk4.111.1%100%51 interviewsAdd to research
GitLab4.23.5%97%91 interviewsAdd to research
 
 
Key learnings from peers

Valuable Features

Room for Improvement

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
Company SizeCount
Small Business5
Large Enterprise6
By reviewers
By visitors reading reviews
Company SizeCount
Small Business36
Midsize Enterprise28
Large Enterprise100
By visitors reading reviews

Top industries

By visitors reading reviews
Financial Services Firm
21%
Manufacturing Company
8%
Construction Company
8%
Insurance Company
6%
Computer Software Company
5%
Comms Service Provider
5%
Performing Arts
4%
Government
4%
Energy/Utilities Company
4%
Media Company
3%
Transportation Company
3%
Outsourcing Company
3%
Wholesaler/Distributor
2%
Hospitality Company
2%
Educational Organization
2%
Marketing Services Firm
2%
Healthcare Company
2%
Logistics Company
2%
Pharma/Biotech Company
2%
Real Estate/Law Firm
2%
University
2%
Retailer
1%
Non Profit
1%
Legal Firm
1%
Consumer Goods Company
1%
Leisure / Travel Company
1%
Agriculture
1%
Engineering Company
1%
Security Firm
1%
Sports Company
1%
Wellness & Fitness Company
1%

Compare Checkmarx Software Composition Analysis with alternative products

Learn more about Checkmarx Software Composition Analysis

Checkmarx Software Composition Analysis customers

Related questions

 
Checkmarx Software Composition Analysis Reviews Summary
Author infoRatingReview Summary
Senior Application Security Engineer at a newspaper with 5,001-10,000 employees4.0I used Checkmarx Software Composition Analysis to identify third-party libraries and determine their usage, which helped us reduce vulnerable libraries by 50%. It provides valuable feature suggestions but could improve in assessing upgrade success factors.
VP Software Developer/Architect at a financial services firm with 5,001-10,000 employees4.0I use Checkmarx's SCA for regular code vulnerability scanning. Its configurability and easy-to-understand security results are valuable. However, improvements in handling false positives and clearer RESTful API access could enhance its effectiveness.
Sr Manager consultant - Digital assurance Services at adrosonic4.5I've used Checkmarx Software Composition Analysis in banking and insurance projects, appreciating its rules and coverage. While it's more costly than alternatives like Veracode and SonarQube, its security and static analysis justify consideration despite pricing and DAST improvement needs.
Penetration Tester & Information Security Expert at a comms service provider with 11-50 employees4.5I use Checkmarx Software Composition Analysis to check library versions for vulnerabilities. The user-friendly GUI helps prioritize changes with specific guidance. An integrated "what if" simulation feature would enhance convenience by allowing impact checks without full reanalysis.
Cyber Security Engineer at Rah Infotech Pvt Ltd4.5I review developer code using Checkmarx Software Composition Analysis to find vulnerabilities, which are then addressed collaboratively. The tool integrates easily with Java tools like Eclipse, though it has occasional crashes and lacks robust API security. I also use Rapid7 and Qualys.
Sr. Director Global Solutions Development at a energy/utilities company with 10,001+ employees4.5I use Checkmarx Software Composition Analysis to scan software for security vulnerabilities. The comprehensive security scan is its most valuable feature, though the implementation process could be more user-friendly. I haven't used or considered similar solutions.
Senior Security Analyst (AppSec) at ELETROBRAS5.0I integrated Checkmarx Software Composition Analysis into our CI/CD pipeline. It excels at identifying vulnerabilities, offering visibility and remediation recommendations. Though dynamic analysis needs improvement, it shows fewer false positives than Fortify SCA, enhancing our development process.
Founder & Chairman at Endpoint-labs Cyber Security R&D4.5I rate Checkmarx SCA highly for identifying open-source vulnerabilities and license issues; it's stable, scalable, and easy to set up. However, I'm disappointed by the declining quality of its customer support.
System Engineer at a manufacturing company with 5,001-10,000 employees5.0I value Checkmarx SCA for early security and legal risk detection in open-source. However, I find its pricing uncompetitive and performance slow, with scans taking hours. Setup was easy, and support is good.
Sr. Director Global Solutions Development at a energy/utilities company with 10,001+ employees4.5I find Checkmarx SCA very stable, integrating well into CICD with fast incremental scans. While setup was straightforward and support responsive, its high price is a concern, and I'm still assessing MuleSoft compatibility.
Tharindu Malwenna - PeerSpot reviewer
Tharindu Malwenna
Senior Application Security Engineer at a newspaper with 5,001-10,000 employees
Dec 11, 2024
Efficient library identification and upgrade suggestions improve application security
DS
Dmitriy Savin
VP Software Developer/Architect at a financial services firm with 5,001-10,000 employees
Sep 1, 2023
Identified and fixed security vulnerabilities in our code, such as a SQL injection vulnerability.
Sujata Sujata Ghadage - PeerSpot reviewer
Sujata Sujata Ghadage
Sr Manager consultant - Digital assurance Services at adrosonic
Mar 14, 2024
Offers great security in the area of vulnerability detection
MH
Moti Huberman
Penetration Tester & Information Security Expert at a comms service provider with 11-50 employees
Jan 16, 2024
The GUI is excellent, providing detailed information on outdated versions
Harsh Soni - PeerSpot reviewer
Harsh Soni
Cyber Security Engineer at Rah Infotech Pvt Ltd
Jun 1, 2023
Along with a straightforward initial setup phase in place, good technical support is also provided
reviewer1337412 - PeerSpot reviewer
reviewer1337412
Sr. Director Global Solutions Development at a energy/utilities company with 10,001+ employees
Apr 14, 2023
Comprehensive security scan, helpful support, and high availability
AS
Abner Santos
Senior Security Analyst (AppSec) at ELETROBRAS
Apr 1, 2024
Has visual scan analysis feature that shows all libraries' vulnerabilities and license types
Cuneyt KALPAKOGLU Phd. - PeerSpot reviewer
Cuneyt KALPAKOGLU Phd.
Founder & Chairman at Endpoint-labs Cyber Security R&D
Mar 31, 2023
Efficiently identifies any open-source components that may contain vulnerabilities
reviewer1915431 - PeerSpot reviewer
reviewer1915431
System Engineer at a manufacturing company with 5,001-10,000 employees
Jul 17, 2022
Has a straightforward setup, identifies vulnerabilities, and offers good technical support
reviewer1504092 - PeerSpot reviewer
reviewer1504092
Sr. Director Global Solutions Development at a energy/utilities company with 10,001+ employees
Feb 5, 2021
A solid, stable, and easy-to-deploy solution that allows you to incorporate it into a CICB pipeline and has the ability to do incremental scans