No more typing reviews! Try our Samantha, our new voice AI agent.

Aikido Security vs Checkmarx One comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
3.7
Cortex Cloud by Palo Alto Networks boosts efficiency and ROI with XSOAR integrations, though ROI quantification can be challenging.
Sentiment score
8.4
Aikido Security enhances efficiency, reduces costs, simplifies compliance, and increases productivity by automating and consolidating security tasks.
Sentiment score
5.6
Checkmarx One enhances security by automating vulnerability detection, reducing costs, and improving development efficiency through CI/CD integration.
The solution provides a good ROI, especially for regular customers, offering discounts for three-year licenses.
Senior Consultant at a tech vendor with 10,001+ employees
I don't think the tool in itself is very capable of doing that, but we have XSOAR and other tool integrations done on the platform, so this can be accomplished.
Technical Solutions Architect at IBM
Aikido Security caught a critical remote code execution vulnerability in my Python machine learning pipelines before it reached production.
Product Manager at Zidio development
Since we got rid of that, our productivity has increased, I believe, by thirty-two percent.
SecOps Engineer at IriusRisk
We were expecting to complete the compliance in a month, but I figured out Aikido Security could do it within a week for all our 13 repositories.
Co-Founder & CTO at Mango Giraffe
Overall, between the fast scanning, automation, automatic reporting, and easy detection, it has reduced manual effort enough that we did not need an extra reviewer, even as our codebase or team size grew.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
Based on my interactions with the clients, I can tell that there is a return on investment because if something is not profitable and it's not helping to save costs or vulnerabilities, clients wouldn't come back to renew their license year after year.
Chief Technology Officer at 3CS Aquarah Limited
 

Customer Service

Sentiment score
6.6
Cortex Cloud's customer service is praised for prompt, knowledgeable support and effective troubleshooting, earning high user ratings.
Sentiment score
7.4
Aikido Security's customer service is efficient, responsive, and provides technical, proactive support with highly valued resources for quick issue resolution.
Sentiment score
7.0
Checkmarx One support is praised for quick responses and knowledgeable staff, despite some reporting delays in technical support.
If I make it a high priority, they have resolved one query within 20 minutes.
Assistant Security Architect at Cloudnomics
If local Indian support cannot resolve an issue, global tech support aligns promptly within the agreed SLA.
Senior Consultant at a tech vendor with 10,001+ employees
Fast response times and knowledgeable staff who understand the intricacies of the system.
Principle Cloud Architect at a tech services company with 11-50 employees
Aikido Security was the easiest to use, the easiest to onboard, and the one with the most active customer support.
SecOps Engineer at IriusRisk
Their team proactively reached out after signup to ensure we were set up correctly.
Product Manager at Zidio development
Most issues were resolved through documentation links, configuration guidance, or clarification around findings.
Software Developer at Bisag-N
If you raise a support case with Checkmarx, it is handled smoothly.
Senior Specialist at a tech vendor with 10,001+ employees
The customer support team is amazing and they provide on-phone call, email support, and on-website support.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
I have relied on Checkmarx One customer support hundreds of times for several things, and Checkmarx One support is very proactive and very responsive.
Chief Technology Officer at 3CS Aquarah Limited
 

Scalability Issues

Sentiment score
4.5
Palo Alto's Cortex Cloud is scalable and efficient, with easy onboarding, but can be costly for higher licenses.
Sentiment score
7.9
Aikido Security scales efficiently with multiple projects and teams, though organizational challenges and minor performance lags may occur.
Sentiment score
7.0
Checkmarx One is scalable for large workloads, but some users report challenges with configurations and licensing requirements.
For stability, scalability, mean time to response, and potential incident investigation improvements, I would give it a nine or probably even a ten.
Business Development Team Lead at a tech vendor with 201-500 employees
Onboarding endpoints and assets on Cortex Cloud by Palo Alto Networks is very easy.
Assistant Security Architect at Cloudnomics
The platform is able to auto-shut certain resources that are not in use through the agentless scan feature.
Technical Solutions Architect at IBM
That kind of reliability becomes invisible when it works well, which is exactly what you want from a security tool running in your CI/CD pipelines.
Product Manager at Zidio development
Scalability with Aikido Security has been good, as new teams continue to be added without significant performance issues.
Software Developer at Bisag-N
Aikido Security scales well by supporting multiple projects, repositories, and development teams on a single platform.
Full Stack Developer at Sri Krishna Arts and Science
Approximately four billion lines of code are being scanned monthly.
Cyber Security Expert at Nestle
Since it is cloud-based, the infrastructure and PaaS, IaaS, and SaaS are taken care of by the cloud marketplace.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Checkmarx One's scalability has changed my organization because the strong collaboration between the development and security team helps us to do things much faster.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
 

Stability Issues

Sentiment score
7.8
Cortex Cloud by Palo Alto Networks is praised for its stability, reliability, and seamless security performance without latency or issues.
Sentiment score
8.8
Aikido Security is consistently reliable with no major disruptions, displaying dependable performance and precise security findings despite occasional delays.
Sentiment score
7.3
Checkmarx One is generally stable but faces issues with large codebases, memory use, and session inconsistencies.
My impression of Cloud Runtime Security in stopping attacks in real-time is that I have never had an issue where it has let something through, causing an outage or concerns to the customer.
Business Development Team Lead at a tech vendor with 201-500 employees
However, now in Cortex Cloud, I have not seen any lag or buffer.
Assistant Security Architect at Cloudnomics
My evaluation of how stable and reliable Cortex Cloud by Palo Alto Networks is very positive.
Technical Solutions Architect at IBM
The platform has been reliable and provides accurate security findings.
Full Stack Developer at Sri Krishna Arts and Science
Aikido Security has been stable, and there have been no major outages affecting workflow.
Software Developer at Bisag-N
I would rate the stability of this solution a nine on a scale of 1 to 10 where one is low stability and 10 is high.
Specialist Leader at Deloitte
Checkmarx One is often down when the cloud provider experiences issues.
Cyber Security Expert at Nestle
 

Room For Improvement

Cortex Cloud's interface and costs challenge users, with needs for improved integration, efficiency, and identity management features.
Users want improved Jira integration, customization, niche language support, faster scans, better documentation, alerts, and affordable pricing.
Checkmarx One needs enhancements in accuracy, speed, integration, UI, support, pricing, and features for enterprise usability.
Regarding the generative AI security tool, I know for sure it's Agentic.
Cybersecurity Analyst at a tech services company with 11-50 employees
The solution is quite premium in cost compared to alternatives such as Wiz.
Principle Cloud Architect at a tech services company with 11-50 employees
There is not a clear MSP model compared to other vendors such as CrowdStrike.
Business Development Manager For Palo Alto Networks at a tech services company with 1,001-5,000 employees
Deeper customization around policies and reporting would be beneficial, since some organizations have specific compliance requirements and the customization can feel limited compared to larger, enterprise-focused platforms.
Software Developer at Bisag-N
I would love to see a Terraform module for Aikido Security.
SecOps Engineer at IriusRisk
I had a certain object with a UUID that was being considered as a private secret key or API key, which was not the case.
Co-Founder & CTO at Mango Giraffe
Integration into the IDE being used would be beneficial so that code does not need to be uploaded to the website and an IDE-friendly report could be generated.
Senior Software Engineer at a financial services firm with 10,001+ employees
It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from.
Specialist Leader at Deloitte
If you can improve the speed optimization, it takes around 30 to 40 minutes for checking a build. If you can make it within five minutes or 10 minutes, that would be great.
Senior Software Engineer at Tech Mahindra Limited
 

Setup Cost

Checkmarx One is often costly but provides quality and security, with costs varying by team size and selected modules.
The solution is costly, with high-end capabilities suitable for enterprises.
Senior Consultant at a tech vendor with 10,001+ employees
Today, it is smart and easy to calculate the licenses.
Cloud Security Manager at T-Systems International GmbH
I used the free trial, which was sufficient for evaluating the platform and its core features.
Full Stack Developer at Sri Krishna Arts and Science
For a small team under 50 developers, normal expenses come under 30 to 60K.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Due to the number of years I've implemented Checkmarx One, there are rebates and discounts from the OEM which makes it a lot more profitable.
Chief Technology Officer at 3CS Aquarah Limited
The pricing should be reasonable, matching what we are paying for.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
 

Valuable Features

Cortex Cloud enhances security management with AI-driven threat detection, automation, and seamless CI/CD integration, reducing response times significantly.
Aikido Security offers an intuitive interface, seamless integrations, and effective tools to enhance productivity and streamline security workflows.
Checkmarx One offers comprehensive vulnerability scanning, seamless CI/CD integration, and enhances productivity with ease of use and automation.
AI/ML aids in anticipating remediation for misconfigurations and vulnerabilities, and automatic remediation can be easily configured.
Senior Consultant at a tech vendor with 10,001+ employees
Cortex Cloud by Palo Alto Networks has reduced the time spent on incident investigations, and if I had to estimate, I would say it has cut our investigation time in half.
Sr. Compliance Analyst at a computer software company with 51-200 employees
This simplifies the management of shared responsibility among different people and entities, allowing you to use one single tool instead of having dozens of different tools to orchestrate and integrate.
Business Development Manager For Palo Alto Networks at a tech services company with 1,001-5,000 employees
We were able to get all codebase vulnerability fixes within a week for all our 13 or 14 repositories that we had.
Co-Founder & CTO at Mango Giraffe
Security shifted left, meaning issues were caught during development rather than after deployment.
Product Manager at Zidio development
My favorite feature is the dependency vulnerability scanning because it quickly identifies the risk in third-party packages, which saves me time in finding vulnerabilities.
Full Stack Developer at Sri Krishna Arts and Science
Since replacing the previous tool, SAST and SCA scans are conducted in a couple of minutes instead of hours or days.
Cyber Security Expert at Nestle
The best features Checkmarx One offers, over the past years, include broad language and technical support that Checkmarx provides, covering most languages.
Senior Specialist at a tech vendor with 10,001+ employees
Checkmarx One has positively impacted our organization as we tend to find vulnerabilities very early in the development cycle.
Product security engineer at a tech vendor with 10,001+ employees
 

Categories and Ranking

Cortex Cloud by Palo Alto N...
Sponsored
Ranking in Application Security Posture Management (ASPM)
7th
Average Rating
8.6
Reviews Sentiment
5.7
Number of Reviews
11
Ranking in other categories
Vulnerability Management (29th), Cloud Workload Protection Platforms (CWPP) (13th), Cloud Security Posture Management (CSPM) (16th), Cloud-Native Application Protection Platforms (CNAPP) (11th), Data Security Posture Management (DSPM) (11th), Software Supply Chain Security (6th), Cloud Infrastructure Entitlement Management (CIEM) (7th), Cloud Detection and Response (CDR) (6th)
Aikido Security
Ranking in Application Security Posture Management (ASPM)
11th
Average Rating
8.6
Reviews Sentiment
7.7
Number of Reviews
6
Ranking in other categories
Application Security Tools (20th), Static Application Security Testing (SAST) (15th), Web Application Firewall (WAF) (27th), Container Security (30th), Software Composition Analysis (SCA) (12th), Static Code Analysis (9th), Cloud Security Posture Management (CSPM) (23rd), Dynamic Application Security Testing (DAST) (9th), DevSecOps (9th)
Checkmarx One
Ranking in Application Security Posture Management (ASPM)
3rd
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
81
Ranking in other categories
Application Security Tools (2nd), Static Application Security Testing (SAST) (2nd), Vulnerability Management (15th), Container Security (14th), Static Code Analysis (2nd), API Security (4th), Dynamic Application Security Testing (DAST) (2nd), DevSecOps (2nd), Risk-Based Vulnerability Management (10th), AI Security (2nd)
 

Featured Reviews

SJ
Technical Solutions Architect at IBM
Cloud security has improved as AI-driven runtime protection detects threats and reduces incidents
In my opinion, Cortex Cloud by Palo Alto Networks could be improved or enhanced in various ways. I don't have an idea about that yet because for that you actually need to use two or three different other tools to make a basic comparison. If you ask me how good the tool is, I would fairly rate it quite high. The tool is very popular, and customers can already see that it is one of the cloud leaders in the security space. The platform had a very good feature which provides documentation links about how to use a specific feature on the UI. It takes you to the proper documentation page where it suggests what to do and tells you about the steps that need to be done for a resource deployment. My thoughts about improving the product which I believe could greatly aid vendors is that it used to be a very user-friendly tool, but now they have incorporated everything under one umbrella. It has XDR, XSOAR, and Cortex Cloud by Palo Alto Networks. Before, we used to have separate modules and separate environments for each of these capabilities or features. Right now, it is a little complex and users would take their own time to know the tool better. This is something that would have been way better, but I would say there would be different opinions on this. Talking about user-friendliness, it has decreased now.
B Goswami - PeerSpot reviewer
Product Manager at Zidio development
Security has shifted left and now catches vulnerabilities early in our development workflow
There are a few areas for improvement. The first is scan speed. For large repositories, initial scans can be slow. Incremental scanning helps, but full scans still take considerable time. The second thing is the false positive rate. While Auto-Triage is good, it is not perfect. Occasionally, genuine issues get filtered out and real false positives slip through. The third one is remediation guidance. Aikido Security tells you what is vulnerable, but sometimes the fix suggestions are generic. More specific, actionable remediation steps would save developer time. The fourth one is IDE integrations. It currently works best in CI/CD pipelines. A proper VS Code or JetBrains plugin for real-time scanning while coding would be a significant improvement. From a customer point of view, the following things could change. The first thing is documentation for custom rules. Aikido Security allows you to create custom scanning rules, but the documentation for this feature is surprisingly thin. I spent considerable time in community forums and with trial and error just to configure basic custom rules. Step-by-step guides with real-world examples would make this feature much more accessible. The second thing is better Slack and communication integrations. Currently, security alerts come through email and dashboard notifications, but our team lives in Slack. A more configurable Slack integration that sends contextual alerts directly to the relevant developer, not just a generic channel notification, would dramatically improve response time. The third one is historical trend reporting. While Aikido Security shows current vulnerability status well, generating historical reports showing security posture improvement over time is limited. For presenting security progress to management or stakeholders, better exportable trend reports would be very valuable.
Shahzad Shahzad - PeerSpot reviewer
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Enable secure development workflows while identifying opportunities for faster scans and improved AI guidance
Checkmarx One is a very strong platform, but there are several areas where it can improve to support modern DevSecOps workflows even better. For example, better real-time developer guidance is needed. The IDE plugin should offer richer AI-powered auto-fixes similar to SNYK Code or GitHub Copilot Security, as current guidance is good but not deeply contextual for large-scale enterprise codebases. This matters because it reduces developer friction and accelerates shift-left adoption. More transparency control over the correlation engines is another need. The correlation engine is powerful but not fully transparent. Users want to understand why vulnerabilities were correlated or de-prioritized, which helps AppSec teams trust the prioritization logic. Faster SAST scan and more language coverage is needed since SAST scan can still be slow for very large mono-repos and there is limited deep support for new language frameworks like Rust and Go, along with advanced coverage for serverless-specific frameworks. This matters because large organizations want sub-minute scans in CI/CD as cloud-native ecosystems evolve fast. A strong API security module is another area for enhancement. API security scanning could be improved with active testing, API discovery, full Swagger, OpenAPI, drift detection, and schema-based fuzzing. This is important as API attacks are one of the biggest AppSec risks in 2025. Checkmarx One is strong, but I see a few areas for improvement including faster SAST scanning for large mono-repos, deeper language framework support, more transparent correlation logic, and stronger API security that includes discovery and runtime context. The IDE plugin could offer more AI-assisted fixes, and the SBOM lifecycle tracking can evolve further. Enhancing integration with SIEM and SOAR would also make enterprise adoption smoother, and these improvements would help developers and AppSec teams move faster with more accuracy.
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
17%
Construction Company
11%
Financial Services Firm
8%
Outsourcing Company
7%
Comms Service Provider
12%
Manufacturing Company
11%
Financial Services Firm
10%
Computer Software Company
8%
Financial Services Firm
16%
Manufacturing Company
9%
Computer Software Company
8%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise2
Large Enterprise2
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise9
Large Enterprise46
 

Questions from the Community

What is your experience regarding pricing and costs for Cortex Cloud by Palo Alto Networks?
I am not fully aware of the pricing and licensing of Cortex Cloud by Palo Alto Networks. The pricing is also based on...
What needs improvement with Cortex Cloud by Palo Alto Networks?
In my opinion, Cortex Cloud by Palo Alto Networks could be improved or enhanced in various ways. I don't have an idea...
What is your primary use case for Cortex Cloud by Palo Alto Networks?
The usual use cases for Cortex Cloud by Palo Alto Networks that I have been working with mostly are as simple as dete...
What needs improvement with Aikido Security?
I think Aikido Security could be improved by addressing its Jira integration, which I feel needs a bit of work. For m...
What is your primary use case for Aikido Security?
My main use case for Aikido Security is to utilize it as part of our vulnerability management program, where we also ...
What advice do you have for others considering Aikido Security?
Since switching to Aikido Security, I have noticed a positive impact on my team's productivity with measurable result...
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as ...
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed Ap...
What is your experience regarding pricing and costs for Checkmarx?
Checkmarx One is a premium solution, so budget accordingly. Make sure you understand how licensing scales with additi...
 

Overview

 

Sample Customers

Information Not Available
FinTech GoCardless ZIP CertifID HealthTech Dental Intelligence PE & Group Techstars Cronos Group Security Tech Human Security Tines HR Tech Simployer Recruitee Agency November Five Other Lighthouse (Hospitality Tech) Smokeball (LegalTech) Runna (B2C Tech) GEA Group (Manufacturing) Community fibre (Telecom) n8n (Software Development)
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Find out what your peers are saying about Aikido Security vs. Checkmarx One and other solutions. Updated: June 2026.
900,644 professionals have used our research since 2012.