No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco SecureX [EOL] vs SonarQube comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 5, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco SecureX [EOL]
Average Rating
9.0
Reviews Sentiment
8.2
Number of Reviews
13
Ranking in other categories
No ranking in other categories
SonarQube
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
137
Ranking in other categories
Application Security Tools (1st), Static Application Security Testing (SAST) (1st), Software Development Analytics (1st)
 

Featured Reviews

Dene Lewis - PeerSpot reviewer
Head of Technical Strategy and Direction CAE Technology Services Ltd at CAE Technology Services Limited
A scalable SaaS based platform that helps with cyber threat intelligence and automated hunting
I would rate Cisco SecureX a ten out of ten. I find the product to be a fantastic platform. If you are eligible, start using it straight away. The best way to evaluate it is to start using it and see where it fits within your organization. I think it helps our customers really deliver their SecOps goals, and I see it as a core foundation of CAE's own security strategy going forward. Our partnership with Cisco is one that was built on trust over a long period of time. This has enabled us to work together to be able to provide the solutions that our customers need to drive their organizations forward. The value we add as a reseller is being able to work closer with our customers, understand them, and get intimate with their organizations. That enables us to offer them the right solutions that will help them achieve their goals.
Vitthal Gole - PeerSpot reviewer
Devops Engineer at AIQOD
Automated code checks have improved quality gates and prevent weak code from reaching production
SonarQube could improve by reducing false positives in its static code analysis; while its detection capabilities are strong, some findings require manual verification, increasing developers' workload. More accurate analysis would enhance productivity, and SonarQube would benefit from enhanced AI-powered recommendations for fixing issues. For instance, in our pipeline, if it fails during SonarQube stage, we could check the dashboard for identified issues involving code smells, bugs, or duplicacy. An AI feature should be integrated into SonarQube to resolve issues quickly; optimizing scanning performance for very large repositories and providing faster analysis times would enhance the developer experience, especially in large code bases with frequent commits. For anyone planning to implement SonarQube, I advise starting by defining coding standards first and integrating Quality Gates into the pipeline. You can customize quality profiles to match project requirements; rather than relying entirely on default rules, you can adjust settings for stronger detection and enforcement. Organizations with advanced security, branch analysis, and governance features might consider commercial editions based on their needs.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The automation and orchestration tools are the most valuable features."
"It has evolved a lot, just that monitoring piece to the current Orchestrator piece. The additional analytics are there. They now have something called Insight, which can basically take data from Microsoft Azure AD and Intune to give us information about our endpoints. This is detailed information about the endpoints, from Secure Endpoint and all these different products. So, it is just constantly evolving. Every time that it evolves, we have more information with more visibility. There are more features that we have that just make everything so much easier, and it is in one place. I don't have to keep going back and forth. I don't have to go to Secure Endpoint and ISE to get the data. I don't have to go to Intune on Microsoft to get the information. It is all in one place."
"I like that I don't have to jump around to five different products and log into five different places to view the data that it returns."
"The SecureX solution has the best impact for the customer because it has all the visibility of my applications and my users' applications."
"Our customers find the product's third-party integrations valuable. Our customers are also impressed with the tool's capability to pick up third-party threat feeds and use that as part of the decision-making process."
"It is one of my favorite things that has ever been built."
"SecureX takes all the separate pieces of security within your company, adds in intelligence from different sites and services on the internet, and makes them work together."
"Integrates well with our existing security infrastructure."
"The static code analysis of the solution is the most important aspect for us. When it comes to security breaches within the code, we can leverage some rules to allow us to identify the repetition in our code and the possible targets that we may have. It makes it very easy to review our code for security purposes."
"The most valuable features are the dashboard reports and the ease of integrating it with Jenkins."
"One of the most valuable features of SonarQube is its ability to detect code quality during development."
"The most valuable feature of SonarQube I have found to be the configuration that has allowed us to make adjustments to the demands of the code review, giving a specified classification regarding the skill and prioritization, and it is easy for me to review and improve my code."
"The most valuable features are the segregation containment and the suspension of product services."
"It is very good at identifying technical debt."
"It is very good because it offers a lot of features in terms of code review, quality check, and more."
"I am only interested in the security features in SonarQube."
 

Cons

"The front-end work controls the new algorithm and the firewall rules. The search feature of these rules could be improved."
"The automation and orchestration could be simpler."
"They could expand into more areas."
"The documentation can be improved and the on-prem integration. The set of applications that it was integrated with wasn't comprehensive."
"If they could make the Cisco Umbrella piece a little bit more advanced or easier to manage, that would help. We use it for filtering and when you compare it to a normal content filter, it lacks some functionality."
"Enhancing automation capabilities could further improve the product."
"Sometimes it's a little slow so that is also something Cisco should check."
"I would like it to integrate with another solution, e.g., DNA. I would like it to connect to that solution, but not the security aspect."
"There could be better integration with other products. It could have more functionality, and the updates could be faster."
"SonarQube could improve by adding automatic creation of tasks after scanning and more support for the Czech language."
"The solution could improve the management reports by making them easier to understand for the technical team that needs to review them."
"It would be better if SonarQube provided a good UI for external configuration."
"There are a lot of features missing in the free version of SonarQube that I want to have that already exist in Checkmarx."
"The handling of the contents of Docker container images could be better."
"In terms of what can be improved, the areas that need more attention in the solution are its architecture and development."
"The time it took for me to do the whole process was approximately two hours because I had to download, read the documentation, and do the configurations."
 

Pricing and Cost Advice

"For the value you get, the pricing of the solution is excellent."
"The pricing is the best part of this solution. It is free if you buy Umbrella or Duo Security. It is also a good solution."
"It would be nice if they had a different pricing model. Most of our budget for projects goes towards Cisco."
"The pricing is competitive, especially for education institutions. Licensing can be a little bit difficult to navigate, especially with resellers with Cisco, but for us it has been pretty easy."
"It is free. It can't get any better than that."
"It comes free with all Cisco products. So, it is a good price."
"The product is absolutely free to any customer. As such, the only thing one must keep in mind is that as long as he already has one Cisco security product, irregardless of what that product is, SecureX is available for free."
"You can spend less money for another solution, but if you really want to have a good solution you have to pay. We are happy that we are getting such a good solution for what we are spending."
"The solution is cheaper than other products."
"We are using the open-source community version, but there are enterprise licenses available."
"SonarQube is an open-source product that can be used free of charge."
"We have a license with 125,000 lines of code. We did not purchase a lot of lines but it is specific to our code environment."
"The development license cost is reasonable, and we've had no concerns about SonarQube when it comes to cost."
"It is very expensive. Its price should be improved."
"We're using their free Community Edition version."
"I think comparing the product to competitors it should be less expensive."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
24%
Construction Company
14%
Marketing Services Firm
8%
Comms Service Provider
6%
Manufacturing Company
13%
Financial Services Firm
13%
Computer Software Company
11%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise7
Large Enterprise3
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise24
Large Enterprise80
 

Questions from the Community

Ask a question
Earn 20 points
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
 

Also Known As

Kenna.AppSec, Kenna.VI
Sonar, SonarQube Cloud
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

NHS, Rackspace, UNC Pembroke, University of North Carolina at Charlotte, Missing Piece
Snowflake, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Application Security Tools. Updated: September 2026.
913,806 professionals have used our research since 2012.