

OpenText Core Application Security and CodeSonar compete in the vulnerability management category, each offering unique strengths to safeguard code security throughout the software lifecycle. OpenText seems to have the upper hand with its wider language support and comprehensive scanning speed, while CodeSonar excels in runtime error detection and precise log configurations.
Features: OpenText Core Application Security effectively integrates into DevOps workflows, enhancing proactive security by scanning a broad range of languages, offering a comprehensive scanning dashboard and seamless integration for security-enhanced development. CodeSonar focuses on runtime error detection and dead code analysis, providing specialized support for languages like C and C++. Its precise log configuration is a notable feature that aids in detailed performance analysis.
Room for Improvement: OpenText Core Application Security faces challenges related to scan times and false positives, with users seeking better development tool integration and improved AI capabilities. It also needs enhanced support for complex websites and reduced latency. CodeSonar could enhance its offering by extending language support beyond C and C++, simplifying the initial setup, and improving integration with industry coding standards.
Ease of Deployment and Customer Service: OpenText Core Application Security offers flexible deployment options in cloud, on-premises, and hybrid settings, although slow customer service response times have been noted. CodeSonar's deployment in both cloud and on-premises environments is accompanied by generally positive support feedback, known for being more responsive than OpenText. Technical support enhancements remain necessary for both products.
Pricing and ROI: OpenText Core Application Security is perceived as expensive, justified by its high security value and reduced bug densities, offering flexible licensing yet at a cost. CodeSonar, also considered pricey based on code line scans, is seen as a worthy investment for its reliability and scanning capabilities that meet demanding security requirements.
| Product | Mindshare (%) |
|---|---|
| OpenText Core Application Security | 3.1% |
| CodeSonar | 1.1% |
| Other | 95.8% |


| Company Size | Count |
|---|---|
| Small Business | 5 |
| Midsize Enterprise | 1 |
| Large Enterprise | 2 |
| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 8 |
| Large Enterprise | 45 |
CodeSonar offers a potent tool for static code analysis, adept in detecting runtime errors and security vulnerabilities, with a fast deployment process and scalable capabilities. Its quick analysis and efficient web interface provide a strong basis for code quality validation.
CodeSonar specializes in identifying runtime errors, dead code, and security threats while providing features like code surfing and browsing. It offers a highly efficient web interface, though users find initial setup complex and highlight the need for better static analysis, broader language support beyond C and C++, and an improved licensing model. Despite these challenges, its integration with Jenkins and technical guidance support makes it a reliable choice for teams in defense and software quality assessment. Deployment is quick and easy, yet initial costs are a common concern among users.
What are the key features of CodeSonar?CodeSonar is primarily implemented in industries like defense and companies prioritizing code quality. Teams utilize its static code analysis and threat detection capabilities, integrating with Jenkins for continuous integration workflows. Security checks post-builds and technical support are common, aiding in effective defect management.
OpenText Core Application Security offers robust features like static and dynamic scanning, real-time vulnerability tracking, and seamless integration with development platforms, designed to enhance code security and reduce operational costs.
OpenText Core Application Security is a cloud-based, on-demand service providing accurate and deep scanning capabilities with detailed reporting. Its integrations with development platforms ensure an enhanced security layer in the development lifecycle, benefiting users by lowering operational costs and facilitating efficient remediation. The platform addresses needs for intuitive interfaces, API support, and comprehensive vulnerability assessments, helping improve code security and accelerate time-to-market. Despite its strengths, challenges exist around false positives, report clarity, and language support, alongside confusing pricing and package options. Enhancements are sought in areas like CI/CD pipeline configuration, report visualization, scan times, and integration with third-party tools such as GitLab, container scanning, and software composition analysis.
What features define OpenText Core Application Security?Industries like mobile applications, e-commerce, and banking leverage OpenText Core Application Security for its ability to identify vulnerabilities such as SQL injections. Integrating seamlessly with DevSecOps and security auditing processes, this tool supports developers in writing safer code, ensuring secure application deployment and enhancing software assurance.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.