No more typing reviews! Try our Samantha, our new voice AI agent.

Kiuwan vs SonarQube comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Kiuwan
Ranking in Application Security Tools
29th
Ranking in Static Application Security Testing (SAST)
27th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
23
Ranking in other categories
No ranking in other categories
SonarQube
Ranking in Application Security Tools
1st
Ranking in Static Application Security Testing (SAST)
1st
Average Rating
8.0
Reviews Sentiment
7.1
Number of Reviews
135
Ranking in other categories
Software Development Analytics (1st)
 

Mindshare comparison

As of June 2026, in the Application Security Tools category, the mindshare of Kiuwan is 1.2%, up from 1.2% compared to the previous year. The mindshare of SonarQube is 12.7%, down from 24.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools Mindshare Distribution
ProductMindshare (%)
SonarQube12.7%
Kiuwan1.2%
Other86.1%
Application Security Tools
 

Featured Reviews

Mustufa Bhavnagarwala - PeerSpot reviewer
CyberRisk Solution Advisor at a consultancy with 10,001+ employees
Though a stable tool, the UI needs improvement
Kiuwan can improve its UI a little more. The user experience can be made better. Kiuwan offers a user interface that is similar to the one offered by Windows 7 or Windows 98, which I saw when I ran the tool and tried to scan the repository to find the security issues. The product's UI has certain shortcomings, where improvements are required.
Sathyamurthi Natarajan - PeerSpot reviewer
IT Officer (Solution Architect) at World Bank
We maintain high code standards with effective static code analysis and integration
SonarQube Server (formerly SonarQube) could be improved on the reporting front. Instead of grouping, I would prefer to scan the code as part of development and then generate a report on a daily basis among different units or projects, which is currently complicated. We need to change it to more of a portfolio report, where configuring or setting up things on the portfolio requires tagging at the ADO level.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It provides value by offering options to enhance both code quality and the security of the company."
"Lifecycle features, because they permit us to show non-technical people the risk and costs hidden into the code due to bad programming practices."
"Kiuwan has enabled us to give our customers peace of mind through early identification of code vulnerabilities and remediation before delivery to the customer."
"Customer service is excellent."
"The solution will measure your development team, give a KPI for the CISO, reduce the time it takes to find and correct coding errors, and more."
"We have had an improvement of 20% in our time to market and it significantly improved the quality of our code."
"We are using this solution to increase the quality of our software and to test the vulnerabilities in our tools before the customers find them."
"Saving time and money by automatically identifying problems is unbelievable."
"It is a very good tool for analysis despite its limitations."
"The most valuable features are the analysis and detection of issues within the application code."
"We use SonarQube to find vulnerabilities in the source code, for better code quality, and code security."
"The features of SonarQube that I find most valuable for identifying code smells are its comprehensive code analysis capabilities, which cover various aspects of code sustainability."
"It provides you with many features, as it does with the premium model, but there are still extra features that can be purchased if needed."
"The SaaS solution for checking code without execution and dealing with security issues is valuable."
"I like that it has a better dashboard compared to Clockwork. It's also stable."
"The ability to tailor metrics tracking with SonarQube Server (formerly SonarQube) has been beneficial to my team and stakeholders as we are able to get portfolio reports and project-wise reports, though there are areas for improvement."
 

Cons

"In Kiuwan there are sometimes duplicates found in the dependency scan under the "insights" tab. It's unclear to me why these duplicates are appearing, and it would be helpful if the application teams could investigate further."
"The product's UI has certain shortcomings, where improvements are required."
"We faced a lot of problems with the initial setup and support gave us difficulties around the installation."
"The next release should include more flexibility in the reporting."
"Improvement could be made with the integration of the programming tools."
"More languages and frameworks would enhance this tool."
"It could improve its scalability abilities."
"The solution seems to give us a lot of false positives. This could be improved quite a bit."
"SonarCloud can improve the false positives. Sometimes the gates sometimes act a little weird, and we then need to manually go and mark the false positive."
"The worst about this tool I think is the upgrade method, and it's really easy to wreck the database when upgrading."
"SonarQube Cloud needs improvements in dynamic code analysis. Static code analysis is good, but the product lacks dynamic code scanning capabilities, an area where Veracode excels."
"We could use some team support, but since we are using the community version, it's not available."
"The solution has a very shallow SAST scanning; that is something that can be improved."
"The only thing I don't like is that they removed the design libraries and dependencies-checking features from v5.2."
"The security in SonarQube could be better."
"Any suggestions for potential improvements may include bill of materials functionality."
 

Pricing and Cost Advice

"It follows a subscription model. I think the price is somewhere in the middle."
"The price of Kiuwan is lower than that of other tools on the market."
"This solution is cheaper than other tools."
"Kiuwan is an open-source solution and free to use."
"Nothing special. It's a very fair model."
"I recommend contacting a sales person who will create the best plan payment plan for you, as we did."
"Check with your account manager."
"A low cost long-term solution for non-critical situations."
"The current pricing is quite cheap."
"It's an open-source product."
"Can try developer version for 14 days on the free trial."
"The solution is cheaper than other products."
"The developer edition is based on cost per lines of code."
"As a user and a consumer of this solution, it can be pricey for my company to support and use, even though there are many benefits. For this reason, we use the free version. In the future, as our product cycles develop and evolve at a more steady pace, we hope to invest in the licensing for this tool."
"SonarQube enterprise, I am not sure of the price but from what I understand they are charging a fee. It's is not clear if it is an annual fee or a one-off."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
11%
University
11%
Manufacturing Company
8%
Computer Software Company
8%
Financial Services Firm
13%
Manufacturing Company
13%
Computer Software Company
12%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise4
Large Enterprise6
By reviewers
Company SizeCount
Small Business43
Midsize Enterprise24
Large Enterprise79
 

Questions from the Community

Ask a question
Earn 20 points
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
 

Comparisons

 

Also Known As

No data available
Sonar, SonarQube Cloud
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

DHL, BNP Paribas, Zurich, AXA, Ernst & Young, KFC, Santander, Latam, Ferrovial
Snowflake, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.
Find out what your peers are saying about Kiuwan vs. SonarQube and other solutions. Updated: June 2026.
900,644 professionals have used our research since 2012.