No more typing reviews! Try our Samantha, our new voice AI agent.

Defensics Protocol Fuzzing vs SonarQube comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Defensics Protocol Fuzzing
Average Rating
8.6
Number of Reviews
4
Ranking in other categories
Fuzz Testing Tools (4th)
SonarQube
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
137
Ranking in other categories
Application Security Tools (1st), Static Application Security Testing (SAST) (1st), Software Development Analytics (1st)
 

Mindshare comparison

While both are Quality Assurance solutions, they serve different purposes. Defensics Protocol Fuzzing is designed for Fuzz Testing Tools and holds a mindshare of 14.4%, down 22.4% compared to last year.
SonarQube, on the other hand, focuses on Application Security Tools, holds 11.8% mindshare, down 23.4% since last year.
Fuzz Testing Tools Mindshare Distribution
ProductMindshare (%)
Defensics Protocol Fuzzing14.4%
PortSwigger Burp Suite Professional35.5%
GitLab31.3%
Other18.799999999999997%
Fuzz Testing Tools
Application Security Tools Mindshare Distribution
ProductMindshare (%)
SonarQube11.8%
Checkmarx One8.0%
Snyk5.1%
Other75.1%
Application Security Tools
 

Featured Reviews

SK
Senior Technical Lead at HCL Technologies
Product security tests for switches and router sections
Codenomicon Defensics should be more advanced for the testing sector. It should be somewhat easy and flexible to install. What I see in the documentation isn't that. Even if something doesn't malfunction, sometimes it is hard to install and execute. The product needs video documentation. This would help a lot more.
Vitthal Gole - PeerSpot reviewer
Devops Engineer at AIQOD
Automated code checks have improved quality gates and prevent weak code from reaching production
SonarQube could improve by reducing false positives in its static code analysis; while its detection capabilities are strong, some findings require manual verification, increasing developers' workload. More accurate analysis would enhance productivity, and SonarQube would benefit from enhanced AI-powered recommendations for fixing issues. For instance, in our pipeline, if it fails during SonarQube stage, we could check the dashboard for identified issues involving code smells, bugs, or duplicacy. An AI feature should be integrated into SonarQube to resolve issues quickly; optimizing scanning performance for very large repositories and providing faster analysis times would enhance the developer experience, especially in large code bases with frequent commits. For anyone planning to implement SonarQube, I advise starting by defining coding standards first and integrating Quality Gates into the pipeline. You can customize quality profiles to match project requirements; rather than relying entirely on default rules, you can adjust settings for stronger detection and enforcement. Organizations with advanced security, branch analysis, and governance features might consider commercial editions based on their needs.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have found multiple issues in our embedded system network protocols, related to buffer overflow. We have reduced some of these issues."
"The stability of this product is great; we tested it under multiple constraints and even on cloud services it is absolutely stable."
"ROI was 100%. Since there are no product suites available that provide the level of testing available with Codenomicon, the development, quality and security assurance departments know that the investment was correct."
"Whatever the test suit they give, it is intelligent; it will understand the protocol and it will generate the test cases based on the protocol: protocol, message sequence, protocol, message structure, and because of that, we can eliminate a lot of unwanted test cases so we can execute the tests and complete them very quickly."
"The product is related to US usage with TLS contact fees, i.e. how more data center connections will help lower networking costs."
"Simple and straightforward GUI."
"It has improved our options for offering products to our clients that can better meet their needs, lower costs, and improves code quality and basic security."
"SonarQube ensures that we release a good quality of code to our customers."
"I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is."
"SonarQube is designed well making it easy to use, simple to identify issues and find solutions to problems."
"The solution is stable."
"This solution is simple to use and can be quickly deployed."
"Some of the static code analysis capabilities are the most beneficial."
"The static code analysis is very good, and in the banking sector, we have found several vulnerabilities and many issues in the source code."
 

Cons

"You can't implement proprietary ciphering algorithms, nor can you modify protocol models if you need to test customized public protocols."
"It does not support the complete protocol stack. There are some IoT protocols that are not supported and new protocols that are not supported."
"Sometimes, when we are testing embedded devices, when we trigger the test cases, the target will crash immediately. It is very difficult for us to identify the root cause of the crash because they do not provide sophisticated tools on the target side. They cover only the client-side application... They do not have diagnostic tools for the target side. Rather, they have them but they are very minimal and not very helpful."
"Codenomicon Defensics should be more advanced for the testing sector. It should be somewhat easy and flexible to install."
"It requires understanding the Defensics protocol."
"SonarQube could be improved with more dynamic testing—basically, now, it's a static code analysis scan. For example, when the developer writes the code and does the corresponding unit test, he can cover functional and non-functional. So the SonarQube could be improved by helping to execute unit tests and test dynamically, using various parameters, and to help detect any vulnerabilities. Currently, it'll just give the test case and say whether it passes or fails—it won't give you any other input or dynamic testing. They could use artificial intelligence to build a feature that would help developers identify and fix issues in the early stages, which would help us deliver the product and reduce costs. Another area with room for improvement is in regard to automating things, since the process currently needs to be done manually."
"There could be better integration with other products. It could have more functionality, and the updates could be faster."
"There isn't a very good enterprise report. They also do not have an application report."
"There is no automation. You need to put the code there and test."
"SonarQube Cloud could improve its vulnerability detection compared to Veracode. Additionally, it has fewer capabilities, which prompted us to use Veracode."
"There are times that we have the database crash."
"When we have a thousand products published over it, we expect it to be more efficient in terms of serving requests from the browser."
"The worst about this tool I think is the upgrade method, and it's really easy to wreck the database when upgrading."
 

Pricing and Cost Advice

"Licensing is a bit expensive."
"I do not know about the pricing as I am using the community edition, which is free. But I compared the pricing with Sigma, and it is higher than SonarQube."
"The tool's pricing is reasonable."
"There are many different packages with different pricing options available. We are able to try what we have and if we need extra features we can upgrade the license."
"The costs for this application, for the kind of job it does, are pretty decent."
"SonarQube enterprise, I am not sure of the price but from what I understand they are charging a fee. It's is not clear if it is an annual fee or a one-off."
"We use the tool's community edition."
"Compared to similar solutions, SonarQube was more accessible to us and had more benefits, with regards to size of the code base and supported languages. Apart from the Enterprise licensing fee, there are no additional costs."
"Some of the plugins that were previously free are not free now."
report
Use our free recommendation engine to learn which Fuzz Testing Tools solutions are best for your needs.
908,834 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
11%
Manufacturing Company
9%
Comms Service Provider
7%
Financial Services Firm
13%
Manufacturing Company
13%
Computer Software Company
11%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise24
Large Enterprise80
 

Questions from the Community

Ask a question
Earn 20 points
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
 

Also Known As

Codenomicon Defensics
Sonar, SonarQube Cloud
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Coriant, CERT-FI, Next Generation Networks
Snowflake, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.