Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs GitHub comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Application Security Tools
3rd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
70
Ranking in other categories
Static Application Security Testing (SAST) (3rd), Vulnerability Management (24th), Static Code Analysis (2nd), API Security (4th), DevSecOps (2nd), Risk-Based Vulnerability Management (10th)
GitHub
Ranking in Application Security Tools
6th
Average Rating
8.8
Reviews Sentiment
7.5
Number of Reviews
93
Ranking in other categories
Version Control (3rd)
 

Mindshare comparison

As of May 2025, in the Application Security Tools category, the mindshare of Checkmarx One is 10.3%, down from 14.8% compared to the previous year. The mindshare of GitHub is 0.8%, down from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
 

Featured Reviews

Rohit Kesharwani - PeerSpot reviewer
Provides good security analysis and security identification within the source code
We integrate Checkmarx into our software development cycle using GitLab's CI/CD pipeline. Checkmark has been the most helpful for us in the development stage. The solution's incremental scanning feature has impacted our development speed. The solution's vulnerability detection is around 80% to 90% accurate. I would recommend Checkmarx to other users because it is one of the good tools for doing security analysis and security identification within the source code. Overall, I rate Checkmarx a nine out of ten.
Pervez Roy - PeerSpot reviewer
Very good for collaboration on software projects
We use GitHub for code repository alongside Bitbucket GitHub is very good for collaboration on software projects. We prefer Bitbucket for commercial use, while GitHub is used for open source. You can get the differences, history of changes, and version control for various pull requests. You can…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Helps us check vulnerabilities in our SAP Fiori application."
"The most valuable feature is that it actually identifies the different criteria you can set to meet whatever standards you're trying to get your system accredited for."
"It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc)."
"Less false positive errors as compared to any other solution."
"Both automatic and manual code review (CxQL) are valuable."
"Overall, the ability to find vulnerabilities in the code is better than the tool that we were using before."
"The feature that I have found most valuable is that its number of false positives is less than the other security application platforms. Its ease of use is another good feature. It also supports most of the languages."
"One of the most valuable features is it is flexible."
"The product's initial setup phase is easy but it is always good to connect with GitHub's team that manages APIs."
"The control is the most valuable feature as developers can work on a single code."
"The product helps our team collaborate across different locations."
"The learning curve is small."
"The most valuable feature is help offered by the community for open-source projects."
"GitHub is the best tool for source repositories."
"I would rate the stability a ten out of ten."
"The initial setup was straightforward."
 

Cons

"Checkmarx being Windows only is a hindrance. Another problem is: why can't I choose PostgreSQL?"
"I would like to see the DAST solution in the future."
"We are trying to find out if there is a way to identify the run-time null values. I am analyzing different tools to check if there is any tool that supports run-time null value identification, but I don't think any of the tools in the market currently supports this feature. It would be helpful if Checkmarx can identify and throw an exception for a null value at the run time. It would make things a lot easier if there is a way for Checkmarx to identify nullable fields or hard-coded values in the code. The accessibility for customized Checkmarx rules is currently limited and should be improved. In addition, it would be great if Checkmarx can do static code and dynamic code validation. It does a lot of security-related scanning, and it should also do static code and dynamic code validation. Currently, for security-related validation, we are using Checkmarx, and for static code and dynamic code validation, we are using some other tools. We are spending money on different tools. We can pay a little extra money and use Checkmarx for everything."
"Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
"In terms of dashboarding, the solution could provide a little more flexibility in terms of creating more dashboards. It has some of its own dashboards that come out of the box. However, if I have to implement my own dashboards that are aligned to my organization's requirements, that dashboarding feature has limited capability right now."
"The Dynamic Application Security Testing (DAST) feature should be better."
"We have received some feedback from our customers who are receiving a large number of false positives."
"The reports are good, but they still need to be improved considering what the UI offers."
"Specifically, I want the solution to offer AI-based merging support, as it is the only area where the product has certain shortcomings."
"GitHub should provide more integration in their next release, including integrating with Jenkins, CI/CD and Jira."
"It is difficult to merge a code or restore it to an older version."
"It would be beneficial if GitHub provided some security scanning for new libraries to ensure that there are no viruses in it."
"I would want to see some form of code security scanning implemented."
"This solution could be improved if migration was fully automated to make it easy, for example, to migrate repositories into GitHub."
"GitHub could add some more security features."
"From the recruiting standpoint, I would like to see email IDs and phone numbers and a brief introduction about their profile."
 

Pricing and Cost Advice

"Checkmarx is comparatively costlier than other products, which is why some of the customers feel reluctant to go for it, though performance-wise, Checkmarx can compete with other products."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"The price of Checkmarx could be reduced to match their competitors, it is expensive."
"For around 250 users or committers, the cost is approximately $500,000."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"This solution is expensive. The customized package allows you to buy additional users at any time."
"It's relatively expensive."
"We have a subscription license that is on a yearly basis, and it's a pretty competitive solution."
"The basic licensing model is free, and if you need to have technical support and such things, then it does cost something. You only need to pay extra if you need technical support."
"We have an enterprise licensing agreement, and I am not part of the finance department so I can't say how much it costs."
"It’s an open-source solution."
"We pay a subscription-based yearly licensing fee for the solution."
"GitHub is an open-source product, but when using the free-to-use version, anyone can see the code we're working on."
"If there are only 10 people using a particular repository, then GitHub is free. But if we increase the number of users, we need to pay the normal charge for GitHub."
"I am using the free version of the solution. However, there are some costs my organization pays."
"The licensing model for GitHub is user-based. Whenever the new developer joins we have to get a new license and register their ID. The overall price of the solution is reasonable."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
851,604 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
14%
Manufacturing Company
10%
Government
5%
Financial Services Firm
13%
Computer Software Company
12%
Manufacturing Company
11%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about GitHub?
The control is the most valuable feature as developers can work on a single code.
What is your experience regarding pricing and costs for GitHub?
The pricing of GitHub depends on the choice of solutions, such as building one's own GitHub Runners to save money or using GitHub's Runners with extra costs. The pricing is considered reasonable an...
What needs improvement with GitHub?
There are still areas for improvement with GitHub Actions and their deployment workflows, as they have made significant progress but are not yet polished. Occasionally, stability can be an issue, t...
 

Comparisons

 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Dominion Enterprises, NASA, Braintree, SAP, CyberAgent
Find out what your peers are saying about Checkmarx One vs. GitHub and other solutions. Updated: April 2025.
851,604 professionals have used our research since 2012.