Coverity gives you the speed, ease of use, accuracy, industry standards compliance, and scalability that you need to develop high-quality, secure applications. Coverity identifies critical software quality defects and security vulnerabilities in code as it’s written, early in the development process, when it’s least costly and easiest to fix. With the Code Sight integrated development environment (IDE) plugin, developers get accurate analysis in seconds in their IDE as they code. Precise actionable remediation advice and context-specific eLearning help your developers understand how to fix their prioritized issues quickly, without having to become security experts.
Product | Market Share (%) |
---|---|
Coverity | 7.0% |
SonarQube Server (formerly SonarQube) | 22.1% |
Checkmarx One | 10.0% |
Other | 60.9% |
Type | Title | Date | |
---|---|---|---|
Category | Static Application Security Testing (SAST) | Aug 29, 2025 | Download |
Product | Reviews, tips, and advice from real users | Aug 29, 2025 | Download |
Comparison | Coverity vs SonarQube Server (formerly SonarQube) | Aug 29, 2025 | Download |
Comparison | Coverity vs Veracode | Aug 29, 2025 | Download |
Comparison | Coverity vs Checkmarx One | Aug 29, 2025 | Download |
Title | Rating | Mindshare | Recommending | |
---|---|---|---|---|
SonarQube Server (formerly SonarQube) | 4.0 | 22.1% | 81% | 116 interviewsAdd to research |
GitLab | 4.2 | 2.4% | 97% | 85 interviewsAdd to research |
Company Size | Count |
---|---|
Small Business | 8 |
Midsize Enterprise | 5 |
Large Enterprise | 22 |
Company Size | Count |
---|---|
Small Business | 398 |
Midsize Enterprise | 311 |
Large Enterprise | 2144 |
Coverity seamlessly integrates automated security testing into your CI/CD pipelines and supports your existing development tools and workflows. Choose where and how to do your development: on-premises or in the cloud with the Polaris Software Integrity Platform (SaaS), a highly scalable, cloud-based application security platform. Coverity supports more than 20 languages and 200 frameworks and templates.
Coverity was previously known as Synopsys Static Analysis.
SAP, Mega International, Thales Alenia Space
Author info | Rating | Review Summary |
---|---|---|
Lead Information Security at GEP Worldwide at ReBIT | 4.5 | I use Coverity for code scanning to identify security vulnerabilities early in the development phase. Its valuable feature is the IDE plugin for real-time security checks. Improvement could include detecting zero-day vulnerabilities. Coverity is more user-friendly and feature-rich compared to alternatives like Checkmarx. |
Senior Software Architect at a tech vendor with 10,001+ employees | 4.0 | We use Coverity to detect software bugs and memory leaks in C++ and C# projects, valuing its interprocedural analysis capabilities. Despite its slow implementation and high license cost, it offers better security analysis compared to SonarQube. |
Software Engineering Manager at Visteon Corporation | 4.0 | I use Coverity in my company for its excellent compliance features, but its high price and frequent false positives are concerns. The support takes too long, so we switched to a more cost-effective platform that better suits our needs. |
Software Quality Expert at Endress+Hauser AG | 3.0 | Coverity excels in identifying critical vulnerabilities with its detailed analysis but struggles with submodule automation. Its interface is less intuitive than SonarQube’s, yet its analysis quality is superior. Improved usability and responsiveness, especially for C++, would enhance its appeal. |
Information Security Analyst at Banglalink | 4.5 | Coverity allows me to implement security benchmarks and identify code issues before production. Its user-friendly interface and reporting are valuable, though updates to reflect current OWASP standards are needed. I found it more user-friendly than other solutions during evaluation. |
Senior Solutions Architect at Telstra | 4.0 | I work on multiple projects, and Coverity provides robust security, quality checks, and efficient disk space usage compared to CodeSonar. Its excellent integration with IDEs and CI/CD tools enhances shift-left testing while reducing defect identification costs. |
Software Engineer at a manufacturing company with 10,001+ employees | 3.5 | I use Coverity for static code analysis to enhance security, finding it easy to integrate with CI. Despite some server upload overhead and initial reporting challenges, it offers good scalability and straightforward deployment. |
Technical Architect at Elastic Care Inc | 5.0 | I used Coverity to perform security scans on our healthcare application to meet FDA requirements, which effectively identified vulnerabilities and integrated well with CI/CD. However, it needs customization for prioritizing issues to focus on critical ones. |