

Acunetix and SonarQube are competitors in the cybersecurity and code quality assurance category. Acunetix has an advantage in web-based testing capabilities, while SonarQube leads in code analysis and integration with CI/CD pipelines.
Features: Acunetix offers web-based testing capabilities with a focus on vulnerability scanning and interactive application security testing (IAS), known for its low false-positive rate. It provides flexibility for web application security and reporting features. SonarQube supports multiple programming languages and excels in static code analysis. It provides detailed checks for coding standards and offers strong integration into continuous integration and delivery pipelines.
Room for Improvement: Acunetix could improve its database features and work on reducing false positives, especially for cross-site scripting vulnerabilities. Its pricing and licensing model could be more flexible to accommodate users with multiple subdomains. SonarQube needs to enhance its security features, improve support for modern programming languages, and better handle false positives. Additionally, introducing advanced AI features would enhance its security offerings.
Ease of Deployment and Customer Service: Both products support hybrid and cloud deployment options. Acunetix offers satisfactory technical support, though improved response times are suggested. SonarQube provides community support, which is helpful but lacks the speed of enterprise-level assistance. SonarQube's open-source nature offers flexibility, but more direct support may be required for complex issues. Both systems are effective in decentralized settings with proactive guidance from Acunetix and community-driven solutions from SonarQube.
Pricing and ROI: Acunetix has increased pricing, leading some users to question the cost-to-value ratio. Despite its capability for good vulnerability detection and improving security posture, the rising costs are a concern. SonarQube is considered cost-effective, especially the Community Edition, due to its open-source nature. When using the enterprise version, the costs are justified by the range of plugins and customization options, resulting in ROI through enhanced code quality and security.
It saves a significant amount of time by covering attack surfaces.
I have seen a return on investment, as Acunetix helps reduce the man-days and effort needed for scanning bulk applications through automated assessments.
I have seen a return on investment with Acunetix, including time saved and cost reduction, because it provides us threats on our web application servers.
It is easily integrable with the CI/CD pipeline and supports multiple projects with its extensive plugin options.
I have seen a return on the investment from SonarQube Server (formerly SonarQube) because the value it adds relates to static code analysis and vulnerability assessments needed for our FDA approval process.
We see productivity increasing based on the fact that the code review is mostly automated, allowing the developer to fix the code themselves before assigning it to someone else to review, thus receiving that ROI.
For high-severity issues, they reach out within two to three hours, and for critical issues, a response is received within 15 minutes.
The technical support from Invicti is very good and fast.
Support staff not being familiar with the problem.
The community support is quite effective.
The customer service and support for SonarQube Cloud are responsive and helpful.
Integrating it into different solutions is straightforward.
Acunetix can handle increasing workloads and more applications easily.
Acunetix's scalability for my growing needs is great; it is a very scalable product compared to others.
There are limitations, and it seems to have fewer capabilities than Veracode.
It has been used in multiple projects and performs well.
I would rate the scalability of SonarQube Server as a 10 because we can configure the server to scan multiple projects based on the number of lines.
I did not need to reach customer support because the product is very stable.
I think SonarQube Server (formerly SonarQube) is stable, and we did not face any problems unless there was a power outage or if the LAN cable was plugged out.
From my team's feedback, it is almost an eight out of ten.
It is a quite stable solution.
The main concern is related to false positives; Acunetix needs to work on identifying valid and invalid findings.
Acunetix should have better integration with newer tools such as GitHub and Azure DevOps.
I believe Acunetix can improve customer support, as the dedicated support staff are often unfamiliar with problems and troubleshooting, leading to communication gaps that delay issue resolution.
I would like to see SonarQube Cloud provide more detailed solutions for fixing code issues, especially solutions related to CVEs.
I need a solution that can bring together three key areas: vulnerabilities, static scanning, and misarchitecture.
Static code analysis is good, but the product lacks dynamic code scanning capabilities, an area where Veracode excels.
The pricing cost is affordable for small and mid-sized organizations, and when compared to Checkmarx, it is significantly affordable, as Checkmarx is quite expensive.
We secured a special licensing model for penetration testing companies, which is cost-effective.
The pricing of Acunetix is pretty expensive and could be improved.
I would rate the pricing for SonarQube Server (formerly SonarQube) as an 8, where 1 is very cheap and 10 is very expensive, because Coverity is very expensive, and while SonarQube is not cheap, it is still less expensive than Coverity.
They always offer around a two-year contract, but we always take a one-year contract because it's expensive.
The freemium version of SonarQube Server offers excellent value, especially compared to the high costs of Snyk.
Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.
The solution is excellent at detecting SQL injection and cross-site scripting vulnerabilities.
The best feature Acunetix offers is the centralized dashboard and the quality of reports it generates, which includes various options for selecting reports and developer options for directly sharing the reports with developers.
Some of the static code analysis capabilities are the most beneficial.
I find SonarQube Cloud very easy to use and simple to integrate initially.
It gives precise reports compared to Coverity and has a slightly lower number of false positives.
| Product | Market Share (%) |
|---|---|
| SonarQube | 16.9% |
| Acunetix | 2.1% |
| Other | 81.0% |

| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 7 |
| Large Enterprise | 17 |
| Company Size | Count |
|---|---|
| Small Business | 41 |
| Midsize Enterprise | 24 |
| Large Enterprise | 79 |
Acunetix Web Vulnerability Scanner is an automated web application security testing tool that audits your web applications by checking for vulnerabilities like SQL Injection, Cross site scripting, and other exploitable vulnerabilities.
SonarQube leads automated code review, enhancing code quality and security in AI-driven SDLCs. It analyzes pull requests, providing developers with actionable feedback and AI-driven fixes before code merges. Trusted by top enterprises, it supports SaaS and self-managed deployments.
SonarQube supports a wide range of programming languages and integrates seamlessly with CI/CD tools like Jenkins. It is renowned for its static code analysis, code coverage, and security vulnerability detection. While its open-source foundation and scalability are praised, users seek enhanced integration across multiple languages, better security features, and improved documentation. Despite challenges, its ability to automate code inspections and ensure compliance with coding standards makes it essential in software development processes, facilitating continuous improvement.
What are the most important features?In industries like finance, healthcare, and automotive, SonarQube is leveraged for static code analysis, automating code inspections, and ensuring compliance with stringent standards. Teams integrate it into their CI/CD pipelines to maintain high-quality code, identify security vulnerabilities, and enhance code maintainability.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.