Try our new research platform with insights from 80,000+ expert users

Black Duck vs Fortify Static Code Analyzer comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.2
Black Duck improved efficiency by identifying vulnerabilities early, saving time, streamlining audits, reducing manual effort, and enhancing code security.
Sentiment score
8.3
Fortify Static Code Analyzer offers early vulnerability detection, cost savings, and enhances ROI by mitigating security risks effectively.
If you're using it on critical external programs where there is regulatory compliance on ensuring that the source code is clean from open-source, there's substantial ROI.
 

Customer Service

Sentiment score
9.3
Black Duck support is praised for professionalism and speed, but faces inconsistent feedback, response delays, and suggests chatbot integration improvements.
Sentiment score
6.7
Fortify Static Code Analyzer support is responsive and proactive, though users suggest adding live chat for improved efficiency.
There are some pain points with the response time and first-level support quality.
The customer service and support for Fortify Static Code Analyzer are better than those for LoadRunner.
The technical support has been good because we always received answers to our questions.
 

Scalability Issues

Sentiment score
8.0
Black Duck is scalable, praised for cloud support and integration, but pricing may deter smaller firms despite versatility.
Sentiment score
8.0
Fortify Static Code Analyzer is highly scalable, efficiently integrating with DevOps, and supports diverse environments with ScanCentral feature.
I would rate the scalability of Black Duck 8 or 9.
Fortify Static Code Analyzer integrates well and is scalable.
 

Stability Issues

Sentiment score
8.0
Black Duck is highly stable, reliable, with minimal issues; users recommend against transitioning to Hub due to potential problems.
Sentiment score
7.5
Fortify Static Code Analyzer is stable and reliable, but proper hardware, network, and training are essential for optimal performance.
The stability of Fortify Static Code Analyzer is generally good.
 

Room For Improvement

Black Duck needs better integration, speed, UI, documentation, pricing, security, scalability, and support for improved user experience.
Fortify Static Code Analyzer needs better language support, integration, user-friendliness, and prioritized vulnerability results to meet user demands.
It can improve on the security side of it, specifically vulnerabilities identification.
There are areas for improvement such as false positives and the scanning of containers.
Black Duck does not have the SBOM management part.
We are not ready to transfer our code without control to AI instruments.
It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers.
 

Setup Cost

Black Duck's pricing ranges from $10,000 to $70,000, with unlimited users for code size, though some find it expensive.
Fortify Static Code Analyzer offers comprehensive security tools with flexible licensing but is expensive, best for enterprises not small businesses.
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs.
 

Valuable Features

Black Duck excels in vulnerability scanning, license management, and policy management, offering strong UI and seamless Docker integration.
Fortify Static Code Analyzer offers flexible integration, strong vulnerability detection, and comprehensive language support, ideal for efficient DevOps security.
The most valuable feature of Black Duck is the composition analysis feature, which is effective for security risk management.
Black Duck's ability to identify dependencies very accurately has been most valuable in identifying and mitigating risks.
The software composition analysis is most effective for security risk management.
The most valuable feature of Fortify Static Code Analyzer is its extensive language support, covering many languages from legacy ones to the newest.
The most impactful feature of Fortify Static Code Analyzer in identifying vulnerabilities is the ratio of total number of vulnerabilities to false positives.
 

Categories and Ranking

Black Duck
Average Rating
7.6
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
Software Composition Analysis (SCA) (1st)
Fortify Static Code Analyzer
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
18
Ranking in other categories
Static Code Analysis (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Black Duck is designed for Software Composition Analysis (SCA) and holds a mindshare of 19.3%, down 22.7% compared to last year.
Fortify Static Code Analyzer, on the other hand, focuses on Static Code Analysis, holds 11.9% mindshare, up 9.5% since last year.
Software Composition Analysis (SCA)
Static Code Analysis
 

Featured Reviews

Saravanan_Radhakrishnan - PeerSpot reviewer
Enables applications to be secure, but it must provide more open APIs
The product enables other applications to be secure. We use it to onboard 400 to 500 applications into the DevOps platform, protect them, and have a secure environment. The tool integrates well with different technologies, application stacks, and databases. The APIs are available. We can read the blogs in the community for open-source compliance and security. The community feeds are important. Black Duck is a leader in Gartner. It is a reliable solution.
Vishal Dhamke - PeerSpot reviewer
An expansive platform that comes with a comprehensive set of security rules and patterns to identify vulnerabilities
Setting up Fortify Static Application Security Testing (SAST) involves several steps to ensure that the tool is correctly configured and integrated into your development workflow say for instance Installation, License Activation, User Access and Permissions, Integration with Development Environment, Project Configuration, Custom Rules and Policies, etc. The initial setup is very easy, have used the enterprise version and a standalone version. The enterprise version definitely takes an ample amount of time to deploy because it needs to have a server along with other logistics in place along with a proper RBAC. The enterprise version would take an ample amount of time, but the standard version is just a few clicks. A team of four to five people is required for the maintenance and frequent updates are required to keep all the signatures up to date. I would rate the setup a nine out of ten.
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
851,604 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Manufacturing Company
16%
Computer Software Company
13%
Insurance Company
4%
Financial Services Firm
29%
Computer Software Company
13%
Manufacturing Company
11%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does WhiteSource compare with Black Duck?
We researched Black Duck but ultimately chose WhiteSource when looking for an application security tool. WhiteSource is a software solution that enables agile open source security and license compl...
What do you like most about Black Duck?
The cloud option of the product is always available and a positive aspect of the solution.
What is your experience regarding pricing and costs for Black Duck?
The price charged by Black Duck is exorbitant. For the features provided by the product, I would not want to pay a high price. There are many other products in the market that offer better features...
What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs. There are some features that require additional purchases,...
What needs improvement with Fortify Static Code Analyzer?
The deployment of Fortify Static Code Analyzer needs to be simplified. It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack...
 

Also Known As

Blackduck Hub, Black Duck Protex, Black Duck Security Checker
Fortify Static Code Analysis SAST
 

Overview

 

Sample Customers

Samsung, Siemens, ScienceLogic, BryterCX, Dynatrace
Information Not Available
Find out what your peers are saying about Black Duck, Veracode, Snyk and others in Software Composition Analysis (SCA). Updated: May 2025.
851,604 professionals have used our research since 2012.