Try our new research platform with insights from 80,000+ expert users

Fortify Static Code Analyzer vs ReShaper comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortify Static Code Analyzer
Ranking in Static Code Analysis
3rd
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
18
Ranking in other categories
No ranking in other categories
ReShaper
Ranking in Static Code Analysis
9th
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Static Code Analysis category, the mindshare of Fortify Static Code Analyzer is 11.9%, up from 9.5% compared to the previous year. The mindshare of ReShaper is 2.7%, down from 5.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Code Analysis
 

Featured Reviews

Aphiwat Leetavorn. - PeerSpot reviewer
Provides extensive language support and enhances secure coding practices
The deployment of Fortify Static Code Analyzer needs to be simplified. It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers. This change would facilitate easier installations and ensure all necessary components are connected and ready to use.
reviewer1465254 - PeerSpot reviewer
Detects, analyzes, and fixes any coding issues
When it's integrated with a weak server machine, the performance isn't that great. It starts up slowly and even crashes at times. If they optimized some of the modules within the ReSharper extension, it would be smoother and faster. Sometimes when the machine is a bit overloaded, it causes it to crash and you need to disable the extension and then re-enabled it. It's not really a stability issue, it probably depends on the machine, but they should consider the fact that not all people have strong machines with high hardware specifications. As long as you have a good processor it will work smoothly, but regarding minimum requirements, it needs to be revisited.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features include its ability to detect vulnerabilities accurately and its integration with our CI/CD pipeline."
"Automating the Jenkins plugins and the build title is a big plus."
"Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like password credentials and access keys embedded in the code."
"You can really see what's happening after you've developed something."
"We've found the documentation to be very good."
"Its flexibility is most valuable. It is such a flexible tool. It can be implemented in a number of ways. It can do anything you want it to do. It can be fully automated within a DevOps pipeline. It can also be used in an ad hoc, special test case scenario and anywhere in between."
"The reference provided for each issue is extremely helpful."
"The integration Subset core integration, using Jenkins is one of the good features."
"It comes with many features and supports almost all of the coding languages available."
"The most valuable feature of ReShaper is that it provides continuously scanning of the data in real-time. ReShaper has a really good mechanism and process, they have a decent system."
 

Cons

"It comes with a hefty licensing fee."
"It can be tricky if you want to exclude some files from scanning. For instance, if you do not want to scan and push testing files to Fortify Software Security Center, that is tricky with some IDEs, such as IntelliJ. We found that there is an Exclude feature that is not working. We reported that to them for future fixing. It needs some work on the plugins to make them consistent across IDEs and make them easier."
"The generation of false positives should be reduced."
"Not all languages are supported in Fortify."
"I'm not sure if Fortify Static Code Analyzer has AI capabilities. Currently, this solution doesn't quite have what we need."
"Fortify's software security center needs a design refresh."
"The generation of false positives should be reduced."
"Their licensing is expensive."
"ReShaper could improve by increasing the performance of the scans. Their application is taking too much CPU. The processing is taking too many CPU resources which causes the system to slow down."
"When it's integrated with a weak server machine, the performance isn't that great. It starts up slowly and even crashes at times."
 

Pricing and Cost Advice

"The price of Fortify Static Code Analyzer could be reduced."
"Although I am not responsible for the budget, Fortify SAST is expensive."
"It has a couple of license models. The one that we use most frequently is called their flexible deployment. We use this one because it is flexible and based on the number of code-contributing developers in the organization. It includes almost everything in the Fortify suite for one developer price. It gives access to not just the secure code analyzer (SCA) but also to FSC, the secure code. It gives us accessibility to scan central, which is the decentralized scanning farm. It also gives us access to the software security center, which is the vulnerability management platform."
"There is a licensing fee, and if you bring them to the company and you want them to do the installation and the implementation in the beginning, there is a separate cost. Similarly, if you want consultation or training, there is a separate cost. I see it as suitable only for enterprises. I do not see it suitable for a small business or individual use."
"From our standpoint, we are significantly better off with Fortify due to the favorable pricing we secured five years ago."
"The licensing is expensive and is in the 50K range."
"The setup costs and pricing for Fortify may vary depending on the organization's needs and requirements."
"I rate the pricing of Fortify Static Code Analyzer as a seven out of ten since it is a bit expensive."
"As far as I know, the licensing isn't very cheap."
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
852,764 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
29%
Computer Software Company
13%
Manufacturing Company
11%
Government
7%
Computer Software Company
20%
Financial Services Firm
10%
Comms Service Provider
9%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs. There are some features that require additional purchases,...
What needs improvement with Fortify Static Code Analyzer?
The deployment of Fortify Static Code Analyzer needs to be simplified. It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack...
Ask a question
Earn 20 points
 

Also Known As

Fortify Static Code Analysis SAST
No data available
 

Overview

Find out what your peers are saying about Fortify Static Code Analyzer vs. ReShaper and other solutions. Updated: April 2025.
852,764 professionals have used our research since 2012.