HCL AppScan and SonarQube Server both compete in the software security and code quality management category. Based on user feedback, HCL AppScan is favored for its comprehensive security features, while SonarQube Server is praised for its cost-effectiveness, especially its free community edition.
Features: HCL AppScan excels in vulnerability detection for web and dynamic applications, supports QR code scanning, and integrates with multiple languages. It also provides robust threat analysis and remediation guidance. SonarQube Server is known for its thorough static code analysis, seamless integration with CI/CD pipelines, and support for a wide range of programming languages. It aids developers in maintaining strong code quality through customizable quality gates and dashboards.
Room for Improvement: HCL AppScan could enhance its extensibility and tool integration, reduce false positives, and offer improved technical support. SonarQube Server could benefit from better dynamic analysis capabilities, increased accuracy in security assessments, and enhanced integration with popular development environments.
Ease of Deployment and Customer Service: HCL AppScan allows cloud and on-premises deployments but experiences challenges with customer service, especially post-IBM transition. SonarQube Server offers flexibility across various environments, including private and public clouds, with a supportive open-source community. However, improving technical documentation and enterprise edition customer service is suggested.
Pricing and ROI: HCL AppScan is considered expensive, with pricing seen as a barrier despite demonstrating ROI through vulnerability reduction. SonarQube Server is lauded for its free community edition's substantial functionality and transparent pricing for paid versions, with the enterprise edition offering features that justify its cost.
I have seen a return on the investment from SonarQube Server (formerly SonarQube) because the value it adds relates to static code analysis and vulnerability assessments needed for our FDA approval process.
We see productivity increasing based on the fact that the code review is mostly automated, allowing the developer to fix the code themselves before assigning it to someone else to review, thus receiving that ROI.
It's more about maintaining standards and being able to prevent issues before they occur.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
They showed us where we can actually get those granular level reporting extracted for Excel, which was a quick guide.
I would rate the technical support for SonarQube Server (formerly SonarQube) as a 10 because we have not faced any specific issues that required us to contact tech support, which is a very rare case.
The community support is quite effective.
I find SonarQube Server (formerly SonarQube) very scalable because we're able to create a new repository and integrate all the tools on that project and it just works.
I would rate the scalability of SonarQube Server as a 10 because we can configure the server to scan multiple projects based on the number of lines.
I think SonarQube Server (formerly SonarQube) is stable, and we did not face any problems unless there was a power outage or if the LAN cable was plugged out.
We need to change it to more of a portfolio report, where configuring or setting up things on the portfolio requires tagging at the ADO level.
As soon as I see that they've got a new feature that integrates AI that is not as generative as other GenAI platforms that actually generate the code and help developers develop faster, I believe that capability is lacking.
If I fix some vulnerabilities today, they reappear in the next scan, and there will be completely different issues that need to be fixed.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
I would rate the pricing for SonarQube Server (formerly SonarQube) as an 8, where 1 is very cheap and 10 is very expensive, because Coverity is very expensive, and while SonarQube is not cheap, it is still less expensive than Coverity.
They always offer around a two-year contract, but we always take a one-year contract because it's expensive.
The freemium version of SonarQube Server offers excellent value, especially compared to the high costs of Snyk.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
The most valuable features of SonarQube Server (formerly SonarQube) for us include having control of the rules, enabling and disabling them.
Some of the static code analysis capabilities are the most beneficial.
We use SonarQube Server's centralized management and visualization of code quality metrics on the dashboard because that's the executive dashboard that we send to the executives to show where we are in terms of quality, security, and where the company can improve.
Product | Market Share (%) |
---|---|
SonarQube Server (formerly SonarQube) | 20.5% |
HCL AppScan | 2.5% |
Other | 77.0% |
Company Size | Count |
---|---|
Small Business | 13 |
Midsize Enterprise | 6 |
Large Enterprise | 31 |
Company Size | Count |
---|---|
Small Business | 32 |
Midsize Enterprise | 21 |
Large Enterprise | 75 |
IBM Security AppScan enhances web application security and mobile application security, improves application security program management and strengthens regulatory compliance. By scanning your web and mobile applications prior to deployment, AppScan enables you to identify security vulnerabilities and generate reports and fix recommendations.
SonarQube Server enhances code quality and security via static code analysis. It detects vulnerabilities, improves standards, and reduces technical debt, integrating into CI/CD pipelines.
SonarQube Server is a comprehensive tool for enhancing code quality and security. It offers static code analysis to identify vulnerabilities, improve coding standards, and reduce technical debt. By integrating into CI/CD pipelines, it provides automated checks for adherence to best practices. Organizations use it for code inspection, security testing, and compliance, ensuring development environments with better maintainability and fewer issues.
What are the key features of SonarQube Server?Many industries implement SonarQube Server to uphold coding standards, maintain security protocols, and streamline their software development lifecycle. In sectors like finance and healthcare, adhering to regulations and ensuring reliable software is critical, making SonarQube Server invaluable. It is often integrated into CI/CD pipelines, ensuring that code changes meet set standards before deployment. This approach enhances productivity and maintains compliance with industry-specific requirements.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.