Our primary use case for this solution is SAST, Static Application Security Testing.
Cyber Security Analyst at a tech vendor with 1,001-5,000 employees
The static operation security has been able to identify more security issues since implementing this solution
Pros and Cons
- "Our static operation security has been able to identify more security issues since implementing this solution."
- "It would be really helpful if the level of confidence was included, with respect to identified issues."
What is our primary use case?
How has it helped my organization?
Our static operation security has been able to identify more security issues since implementing this solution.
What is most valuable?
There are many good features like site integration, but the most valuable feature for us is the XL scan of source code.
What needs improvement?
It would be really helpful if the level of confidence was included, with respect to identified issues. Some competitors have this feature, and it helps a lot to concentrate on the real findings.
Buyer's Guide
Checkmarx One
May 2025

Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
For how long have I used the solution?
One year.
What do I think about the stability of the solution?
In general, stability is good, although sometimes it crashes. We use this product daily, and I would rate the stability a four out of five.
What do I think about the scalability of the solution?
The scalability is very good.
How are customer service and support?
Technical support for this solution is very effective. Each time we have had questions, the answers they provided have been very clear and comprehensive.
Which solution did I use previously and why did I switch?
Prior to this solution, we were using IBM Security AppScan. We had many, many issues with the application, along with complaints about the deployment time. The main reason we switched is that it was not updated, and it did not support certain technologies. For example, it did not support Visual Studio 2017, so we had to switch to a new solution.
How was the initial setup?
The initial setup for this solution is straightforward.
It took less that one day to deploy.
What about the implementation team?
We handled the implementation in-house.
What was our ROI?
We have not yet seen ROI.
Which other solutions did I evaluate?
We did evaluate other options.
What other advice do I have?
If people are in need of static application security, then I would recommend this product.
I would rate this solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Security test engineer at a tech vendor with 10,001+ employees
Communicates where to fix the issue for less iterations. Resolutions should be provided for installation issues due to internal security policies.
Pros and Cons
- "The solution communicates where to fix the issue for the purpose of less iterations."
- "The resolutions should also be provided. For example, if the user faces any problem regarding an installation due to the internal security policies of their company, there should be a resolution offered."
How has it helped my organization?
Now we have information about which specific sections have to be fixed. We can now remove the issue from most of the sections.
What is most valuable?
The solution communicates where to fix the issue for the purpose of less iterations.
What needs improvement?
The resolutions should also be provided. For example, if the user faces any problem regarding an installation due to the internal security policies of their company, there should be a resolution offered.
What do I think about the stability of the solution?
There were no stability issues.
What do I think about the scalability of the solution?
There were no scalability issues.
How are customer service and technical support?
I would give technical support a rating of 8/10.
Which solution did I use previously and why did I switch?
We switched solutions due to the client's requirements.
What's my experience with pricing, setup cost, and licensing?
I faced a few issues in the installation due to my local policies. The customer support was very helpful.
Which other solutions did I evaluate?
We looked at other tools, such as HPE Security and ZAP solutions.
What other advice do I have?
Go for it, if you want testing on the code level.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Checkmarx One
May 2025

Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
Software Engineer Intern at Connex Information Technologies
Easy to deploy, scalable, and user-friendly UI
Pros and Cons
- "The UI is user-friendly."
- "The plugins for the development environment have room for improvements such as for Android Studio and X code."
What is our primary use case?
We use the solution for our international customers.
What is most valuable?
The UI is user-friendly.
The Fast feature for static application security testing is the most valuable.
What needs improvement?
The plugins for the development environment have room for improvements such as for Android Studio and X code.
For how long have I used the solution?
I have been using the solution for two months.
What do I think about the stability of the solution?
I give the stability a seven out of ten.
What do I think about the scalability of the solution?
I give the scalability a nine out of ten.
The scalability is based on the number of licenses. We currently have five licenses.
How are customer service and support?
The technical support is quick to respond.
How would you rate customer service and support?
Positive
How was the initial setup?
I give the initial setup an eight out of ten. The deployment takes about ten minutes.
What about the implementation team?
The implementation was completed by a consultant.
What's my experience with pricing, setup cost, and licensing?
The solution is costly. I give the solution a six out of ten for price.
What other advice do I have?
I give the solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Business Analyst at a tech services company with 201-500 employees
It made our organization more efficient with our whole code scan/deployment process for our software applications.
Pros and Cons
- "It is a stable product."
- "Most valuable features include: ease of use, dashboard. interface and the ability to report."
- "It is an expensive solution."
What is our primary use case?
Our primary use case solution is for code scanning.
How has it helped my organization?
It has made our organization more efficient with our whole code scan/deployment process for our software applications.
What is most valuable?
The most valuable features are:
- Ease of use
- Dashboard
- Interface
- Report
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
I have not had an issue with stability of the product.
What do I think about the scalability of the solution?
There have been no issues with scalability that I am aware of.
How are customer service and technical support?
I have not needed the use of technical support.
Which solution did I use previously and why did I switch?
Previously, we considered: Veracode, SonarQube, Fortify and IBM Security AppScan.
How was the initial setup?
I was not involved in the initial setup of the solution.
What was our ROI?
One should consider:
- Visual studio
- Report generation
- If the solution can be on-prem
- Pricing
What's my experience with pricing, setup cost, and licensing?
It is an expensive solution.
What other advice do I have?
Be cautious of the one-year subscription date. Once it expires, your price will go up.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Architect at Photon Interactive
It gives the proper code flow of vulnerabilities and the number of occurrences
Pros and Cons
- "It shows in-depth code of where actual vulnerabilities are."
- "It gives the proper code flow of vulnerabilities and the number of occurrences."
- "It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."
What is our primary use case?
I have used it for source code scanning of security vulnerabilities. It seems to be a good tool. It gives the proper code flow of vulnerabilities and the number of occurrences.
How has it helped my organization?
We have scanned various applications with it. It works fine, although we need to check manually for false positive issues.
What is most valuable?
After scanning, it shows in-depth code of where actual vulnerabilities are, which helps us to analyze them.
What needs improvement?
It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use.
For how long have I used the solution?
One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director and Co-Founder at Ushiro-tec
The Best Fix Location & Payments Features Can Save Time Mitigating Network Configurations
Pros and Cons
- "The most valuable features of Checkmarx are the Best Fix Location and the Payments option because you can save a lot of time trying to mitigate the configuration. Using these tools can save you a lot of time."
- "With Checkmarx, normally you need to use one tool for quality and you need to use another tool for security. I understand that Checkmarx is not in the parity space because it's totally different, but they could include some free features or recommendations too."
What is our primary use case?
We use Checkmarx to review the source code for the external applications that we expose to the cloud or other servers on the internet.
How has it helped my organization?
We received two main benefits from Checkmarx:
- Better Security
- Saving Time
I recommend Checkmarx to be sure that your development has robust security. For your team management, Checkmarx has a very nice feature to check out manual staff in the process.
What is most valuable?
The most valuable features of Checkmarx are the Best Fix Location and the Payments option because you can save a lot of time trying to mitigate the configuration. Using these tools can save you a lot of time.
What needs improvement?
Checkmarx could probably do something to improve their license model. If you have a small company, or if you have a small team with just one or two applications, the entry-level price is too high for such a company.
You can find all the solutions offered by Checkmarx through other solutions providers. That is why this type of company needs to be more flexible.
In this space, you have a security code and also you have a quality code. It is totally different in terms of investment. In terms of functionality, there are a lot of differences between the various competing products.
With Checkmarx, normally you need to use one tool for quality and you need to use another tool for security. I understand that Checkmarx is not in the parity space because it's totally different, but they could include some free features or recommendations too.
The problem with Checkmarx lies with the pricing and licensing, not the product itself. The product is very good.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
Checkmarx is a good product, certainly stable.
What do I think about the scalability of the solution?
The scalability is good. We haven't had any problems with it.
How are customer service and technical support?
Our experience with technical support is good. They have a lot of expert staff on their customer service lines. We have had no problems with their technical support services.
Which solution did I use previously and why did I switch?
We used Veracode for some time and it's also a good solution. Veracode fits better for small companies. It's more automatic.
Checkmarx is more complete and they have more features to support our development team and security team requirements.
In general, Checkmarx is a better solution, but it's more complicated, especially in terms of the price for a small company.
How was the initial setup?
Our deployment of Checkmarx took a couple of days, at max, a week.
What about the implementation team?
The setup was a long time back, but I know that we did not use a reseller or consultant for the deployment.
Which other solutions did I evaluate?
We evaluated some products from a company in Spain. Checkmarx provided better functionality and options for us.
What other advice do I have?
We have a small team. It is about four people in total. We do not require that many staff for the deployment and maintenance of Checkmarx.
We are testing the solution in a small local company. Our idea is to expand the use of it to our clients in the West.
In this space, you can have different points of view and if only you are looking for a solution to do a check in your auditory report, then you can choose anyone.
If you really are worried about your business, i.e. about your development sites or development environments, Checkmarx is a great solution.
I would rate Checkmarx a nine out of ten because of the price, but technically for me, it is a 10.
I would rate Checkmarx with a nine because it would be perfect at a more functional level, and could be better at providing these features for parity.
If you research what Checkmarx is offering in their package distribution, you get exactly what they promise up front, so they are not lying.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Innovation Consultant (Security Analyst) at a tech services company with 1,001-5,000 employees
It makes it easier to identify code vulnerabilities by presenting the flow of malicious input and fixing it.
Pros and Cons
- "Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
- "Some of the descriptions were found to be missing or were not as elaborate as compared to other descriptions. Although, they could be found across various standard sources but it would save a lot of time for developers, if this was fixed."
How has it helped my organization?
We have been using this product extensively for a lot of applications to identify as well as employ proper remediation which makes the application secure including information issues which might get neglected with a manual code review process.
What is most valuable?
Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application. It therefore makes it easier to identify these as well as fix them.
What needs improvement?
Checkmarx has the detailed description of all the vulnerabilities which it identifies after the source code scan. These descriptions are just a click away. Some of the descriptions were found to be missing or were not as elaborate as compared to other descriptions. Although, they could be found across various standard sources but it would save a lot of time for developers, if this was fixed.
What do I think about the stability of the solution?
We have not yet encountered any stability issues.
What do I think about the scalability of the solution?
The solution provides high scalability. I am not sure about the limit of scans but it is sufficiently high. However, the issues which we faced were related to database backup. Unfortunately, Checkmarx doesn't do any automated backups which is quite inconvenient.
How are customer service and technical support?
I would rate the technical support as average. We never had to communicate much with the technical team but based on my knowledge the response from their end was delayed.
Which solution did I use previously and why did I switch?
I am not aware of any previous solutions.
How was the initial setup?
The setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
It is a good product but a little overpriced.
Which other solutions did I evaluate?
I don't have much idea about other options since the organization had already purchased the product before I joined.
What other advice do I have?
Better to look out for other products available in the market as well.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Minimal configuration, simple setup, and useful user interface
Pros and Cons
- "The most valuable feature of Checkmarx is the user interface, it is very easy to use. We do not need to configure anything, we only have to scan to see the results."
- "Checkmarx could improve the speed of the scans."
What is our primary use case?
Checkmarx is used for application security, we can detect the stability and other details on how to fix issues.
What is most valuable?
The most valuable feature of Checkmarx is the user interface, it is very easy to use. We do not need to configure anything, we only have to scan to see the results.
What needs improvement?
Checkmarx could improve the speed of the scans.
For how long have I used the solution?
I have been using Checkmarx for approximately half a year.
What do I think about the scalability of the solution?
We have five people in our company that uses Checkmarx, we do not plan to increase usage.
How are customer service and support?
I have used the support from Checkmarx.
Which solution did I use previously and why did I switch?
I have not used another before Checkmarx.
How was the initial setup?
The initial setup of Checkmarx was very easy. The process took approximately one hour. We only need to provide information.
What about the implementation team?
We have five people that are supporting Checkmarx in our company.
What other advice do I have?
This solution is one of the easiest solutions I have used. We have professional services set it up for us but the scans are not enough for us.
I rate Checkmarx an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Vulnerability Management Static Code Analysis API Security DevSecOps Risk-Based Vulnerability ManagementPopular Comparisons
SonarQube Server (formerly SonarQube)
GitLab
SentinelOne Singularity Cloud Security
Veracode
Coverity
Mend.io
OWASP Zap
CrowdStrike Falcon Cloud Security
SonarQube Cloud (formerly SonarCloud)
Fortify on Demand
Orca Security
GitHub Advanced Security
JFrog Xray
Sonatype Lifecycle
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Checkmarx or Veracode. Which should we choose?
- What is the Biggest Difference Between Checkmarx and Fortify?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?