

HCL AppScan and SonarQube compete in the code vulnerability detection category. Based on various comparisons, SonarQube seems to have the upper hand due to its comprehensive code quality coverage and more flexible pricing model.
Features: HCL AppScan is known for its web scan capabilities, dynamic scanning, and integration with Security Development Lifecycle, supporting a wide range of languages. SonarQube is recognized for its extensive support of programming languages, static code analysis, and integration with CI/CD pipelines, offering in-depth insights and community-driven plugin support.
Room for Improvement: AppScan could enhance its management of false positives, improve technical support, and offer better CI/CD integration. Users also seek additional language support and an easier user experience. SonarQube needs to boost its security scanning capabilities, manage false positives better, and simplify its integration process. Users also desire dynamic testing features and improved handling of large codebases.
Ease of Deployment and Customer Service: AppScan can be deployed across public cloud, hybrid cloud, and on-premises environments. Customer feedback suggests varied satisfaction with technical support, though improvement is noted post-transition from IBM. SonarQube supports multiple deployment methods with generally positive support feedback, although some users highlight a need for more training resources. Regional disparities somewhat hinder AppScan's support, more so than SonarQube's.
Pricing and ROI: HCL AppScan is perceived as expensive, yet it offers ROI through reduced vulnerabilities. Pricing adjustments could make it more accessible. SonarQube provides a free community edition and offers competitive licensing for advanced features. Its pricing structure is deemed more flexible and affordable, appealing to budget-conscious teams.
It is easily integrable with the CI/CD pipeline and supports multiple projects with its extensive plugin options.
I have seen a return on the investment from SonarQube Server (formerly SonarQube) because the value it adds relates to static code analysis and vulnerability assessments needed for our FDA approval process.
We see productivity increasing based on the fact that the code review is mostly automated, allowing the developer to fix the code themselves before assigning it to someone else to review, thus receiving that ROI.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
The community support is quite effective.
The customer service and support for SonarQube Cloud are responsive and helpful.
Integrating it into different solutions is straightforward.
There are limitations, and it seems to have fewer capabilities than Veracode.
It has been used in multiple projects and performs well.
I would rate the scalability of SonarQube Server as a 10 because we can configure the server to scan multiple projects based on the number of lines.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
I think SonarQube Server (formerly SonarQube) is stable, and we did not face any problems unless there was a power outage or if the LAN cable was plugged out.
From my team's feedback, it is almost an eight out of ten.
It is a quite stable solution.
If I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present.
There is another website called Code Warrior that really takes you through the entire journey, so you can truly understand what the issue is along with some actual coding examples.
I would like to see SonarQube Cloud provide more detailed solutions for fixing code issues, especially solutions related to CVEs.
I need a solution that can bring together three key areas: vulnerabilities, static scanning, and misarchitecture.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
I would rate the pricing for SonarQube Server (formerly SonarQube) as an 8, where 1 is very cheap and 10 is very expensive, because Coverity is very expensive, and while SonarQube is not cheap, it is still less expensive than Coverity.
They always offer around a two-year contract, but we always take a one-year contract because it's expensive.
The freemium version of SonarQube Server offers excellent value, especially compared to the high costs of Snyk.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
I have utilized its interactive application security testing, as well as both static application security testing, dynamic application security testing, and IAST.
Some of the static code analysis capabilities are the most beneficial.
I find SonarQube Cloud very easy to use and simple to integrate initially.
It gives precise reports compared to Coverity and has a slightly lower number of false positives.
| Product | Mindshare (%) |
|---|---|
| SonarQube | 12.7% |
| HCL AppScan | 2.3% |
| Other | 85.0% |


| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
| Company Size | Count |
|---|---|
| Small Business | 43 |
| Midsize Enterprise | 24 |
| Large Enterprise | 79 |
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
SonarQube leads automated code review, enhancing code quality and security in AI-driven SDLCs. It analyzes pull requests, providing developers with actionable feedback and AI-driven fixes before code merges. Trusted by top enterprises, it supports SaaS and self-managed deployments.
SonarQube supports a wide range of programming languages and integrates seamlessly with CI/CD tools like Jenkins. It is renowned for its static code analysis, code coverage, and security vulnerability detection. While its open-source foundation and scalability are praised, users seek enhanced integration across multiple languages, better security features, and improved documentation. Despite challenges, its ability to automate code inspections and ensure compliance with coding standards makes it essential in software development processes, facilitating continuous improvement.
What are the most important features?In industries like finance, healthcare, and automotive, SonarQube is leveraged for static code analysis, automating code inspections, and ensuring compliance with stringent standards. Teams integrate it into their CI/CD pipelines to maintain high-quality code, identify security vulnerabilities, and enhance code maintainability.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.