No more typing reviews! Try our Samantha, our new voice AI agent.

Coverity Static vs ERPScan SMART Cybersecurity Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Coverity Static
Average Rating
7.8
Reviews Sentiment
6.5
Number of Reviews
43
Ranking in other categories
Static Application Security Testing (SAST) (12th)
ERPScan SMART Cybersecurity...
Average Rating
0.0
Number of Reviews
1
Ranking in other categories
Application Security Tools (40th)
 

Mindshare comparison

Coverity Static and ERPScan SMART Cybersecurity Platform aren’t in the same category and serve different purposes. Coverity Static is designed for Static Application Security Testing (SAST) and holds a mindshare of 2.5%, down 7.4% compared to last year.
ERPScan SMART Cybersecurity Platform, on the other hand, focuses on Application Security Tools, holds 0.7% mindshare, up 0.2% since last year.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Coverity Static2.5%
SonarQube13.3%
Checkmarx One8.8%
Other75.4%
Static Application Security Testing (SAST)
Application Security Tools Mindshare Distribution
ProductMindshare (%)
ERPScan SMART Cybersecurity Platform0.7%
SonarQube11.8%
Checkmarx One8.0%
Other79.5%
Application Security Tools
 

Featured Reviews

SP
Lead Information Security at GEP Worldwide at ReBIT
Helps us identify security vulnerabilities in the development phase and provides a plugin for the developer IDE
The initial setup is good. When I use the product to scan the code in the DevOps pipeline, the issue coverage can be greater, which can help speed up risk identification in the CI/CD pipeline. That is one area where improvement can be made. Corresponding steps can be taken for that. It integrates with most of the tools, like ticketing tools, configuration tools, Jenkins, and the pipeline. That is fantastic.
TO
Consulting Partner, Cyber Security Delivery - Africa at DeltaGRiC Consulting
Good core scanning, a helpful GDPR assessment template and very good technical support
The core scanning, the scanning process, has got a very nice pass management module. It's fantastic. The last time we did it, the customer was trying to make the SAP system match the GDPR process. We were able to use it for that benchmark. It was very important. The GDPR assessment template that is being used in the process application benchmark and analyzing landscape came in very handy. It was very useful because it also gave notifications.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has the lowest false positives."
"Considering the analysis part and the benchmarking process involving the product that my company carried out, the solution is good for finding bugs and violations"
"In my opinion, the most effective Coverity feature for identifying critical vulnerabilities is the extra checks, which offers deep analysis."
"The most valuable feature is that there were not a whole lot of false positives, at least on the codebases that I looked at."
"The security analysis features are the most valuable features of this solution."
"I encountered a bug with Coverity, and I opened a ticket. Support provided me with a workaround. So it's working at the moment, or at least it seems to be."
"The interface of Coverity is quite good, and it is also easy to use."
"What I find most effective about Coverity is its low rate of false positives. I've seen other platforms with many false positives, but with Coverity, most vulnerabilities it identifies are genuine. This allows me to focus on real issues."
"The core scanning, the scanning process, has got a very nice pass management module, and the GDPR assessment template that is being used in the process application benchmark and analyzing landscape came in very handy and was very useful because it also gave notifications."
"The core scanning, the scanning process, has got a very nice pass management module. It's fantastic."
 

Cons

"I had tried integrating the tool with Azure DevOps, but the report I got stated that my team faced many challenges."
"When I put my code into Coverity for scanning, the code information of the product is in the system. The solution could be improved by providing a SBOM, a software bill of material."
"Right now, the Coverity executable is around 1.2GB to download. If they can reduce it to approximately 600 or 700MB, that would be great. If they decrease the executable, it will be much easier to work in an environment like Docker."
"The product lacks sufficient customization options."
"I would like to see integration with popular IDEs, such as Eclipse."
"We're currently facing a primary challenge with automation using Coverity. Each developer has a license and can perform manual checks, and we also have a nightly build that analyzes the entire software. The main issue is that the tool can't look behind submodules in our code base, so it doesn't see changes stored there."
"I am not a fan of using both SOAP and REST APIs and Coverity offers a mix of functionality depending on the interface used."
"Coverity is too costly, which is why we are trying other tools."
"The anomaly detection could be improved."
"The solution is generally good, but it's not seamless."
 

Pricing and Cost Advice

"The pricing is on the expensive side, and we are paying for a couple of items."
"Depending on the usage types, one has to opt for different types of licenses from Coverity, especially to be able to use areas like report viewing or report generation."
"The licensing fees are based on the number of lines of code."
"I would rate the tool's pricing a one out of ten."
"The tool's price is somewhere in the middle. It's neither cheap nor expensive. I would rate the pricing a five out of ten."
"Coverity’s price is on the higher side. It should be lower."
"I would rate the pricing a six out of ten, where one is low, and ten is high price."
"The tool was fairly priced."
Information not available
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
28%
Computer Software Company
9%
Financial Services Firm
7%
Comms Service Provider
5%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise6
Large Enterprise31
No data available
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What needs improvement with Coverity?
The price is a concern, and there are a lot of false positives coming through. Support with Coverity is adequate, but they take a longer time to respond. The core support is not straightforward, an...
Ask a question
Earn 20 points
 

Also Known As

Synopsys Static Analysis
No data available
 

Overview

 

Sample Customers

SAP, Mega International, Thales Alenia Space
Wired
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Static Application Security Testing (SAST). Updated: August 2026.
908,800 professionals have used our research since 2012.