Try our new research platform with insights from 80,000+ expert users

Veracode vs Wiz comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.6
Veracode enhances security, reduces costs, and boosts efficiency, with varied ROI perceptions, but some struggle to quantify it financially.
Sentiment score
6.3
Wiz enhances company value with time savings, security efficiency, cost reduction, asset management, and increased feature adoption despite regional costs.
The scanners of Veracode bring status of the weaknesses in the current infrastructure. It scans and provides reports regarding the servers, the network, and the applications running on those servers.
Regarding price, the evaluation should focus on how efficiently they will recover their investment, considering the time saved through the use of Veracode Fix, for example, and the ability to fix code at dev time compared to the problems faced when fixing after the product is already deployed.
We have seen ROI from Wiz and we continued to see value in Wiz.
We estimate a cost reduction of around 35% to 50%, or even more, due to consolidating our security management into one platform.
 

Customer Service

Sentiment score
7.2
Veracode's customer service is praised for expertise and responsiveness, though variability and time zones can affect efficiency.
Sentiment score
7.8
Wiz receives high marks for customer service, despite initial contact challenges and regional support gaps, thanks to effective communication tools.
Access to the engineering team is crucial for faster feedback on the product fix process.
I have communicated with the technical support of Veracode a couple of times, and this was a really great experience because these professionals know their material.
They share detailed information via email, including screenshots or further clarification about the issue.
We have a dedicated channel with Wiz and are always in communication with them.
The solution's technical support was excellent.
Century Data has an engineering team who support the initial calls with a local Knowledge base.
 

Scalability Issues

Sentiment score
7.4
Veracode efficiently scales, supports large applications and users, integrates seamlessly, providing fast results with minimal challenges or performance issues.
Sentiment score
8.2
Wiz excels in scalability and integration, efficiently managing large-scale operations, though costs and remediation workflows need improvement.
Cloud solutions are easier to scale than on-premise solutions.
It has a good capacity to scale effectively.
Implementing these features into our normal CI/CD was good, so I can say that scalability is really good.
We have deployed Wiz in three organizations on AWS, each with approximately 70 to 80 accounts, totaling more than 120 accounts.
Scalability-wise, I rate the solution a ten out of ten.
Our environment quadrupled in size. We didn’t have to make any adjustments or configuration changes; it just accommodated the growth.
 

Stability Issues

Sentiment score
7.8
Veracode is highly stable with minimal downtime, effective workload handling, and no significant operational issues reported by users.
Sentiment score
8.2
Users express high confidence in Wiz's reliability, with minor issues quickly resolved and stability rated eight to ten.
If the Veracode server is down, we experience many issues during the scan.
It's not that easy to onboard, but once they have been onboarded on the platform, and the pipeline configured alongside the product configured, it works effectively.
Stability-wise, I rate the solution an eight to nine out of ten.
The solution is very stable.
We haven't encountered any outages or issues with reports not running, finishing, or data being incomplete or inaccurate.
 

Room For Improvement

Veracode needs improvements in false positives, interface, speed, reporting, tool integration, language support, cost, APIs, and documentation.
Users seek enhanced reporting, integration, security, and cost-effectiveness on Wiz, including better remediation, alerts, and scanning capabilities.
If it could be integrated directly with code repositories such as Bitbucket or GitHub, without the need to create a pipeline to upload and decode code, it would simplify the code scan process significantly.
We had issues with scanning large applications. Scanning took a lot of time, so we kept it outside the DevOps pipeline to avoid delaying deployments.
A nice addition would be if it could be extended for scenarios with custom cleansers.
We would like to see preventive controls that can be applied through Wiz to protect against vulnerabilities that we're not going to be able to remediate immediately.
One significant area for improvement would be increasing automation. While they excel at identifying issues, we need assistance in minimizing the human hours required for tasks.
We need an agent that can be installed, or that can overview all the containers and Kubernetes so that it can detect malicious activities that are happening in them.
 

Setup Cost

Veracode's pricing is high, valued for features, but complex and costly for small organizations, justified for large enterprises.
Enterprise users value Wiz for its comprehensive security, despite higher costs and some confusion over advanced features and pricing.
It's not the most expensive solution.
Overall, Veracode's pricing is lower and more scalable than many alternatives in the market.
If there's a security gap, you'll never know the cost or effect.
We are paying 250k per year.
In some cases, it has a very aggressive price, so very cheap.
I don’t think there’s anyone else out there offering the same level, scale, or efficiency.
 

Valuable Features

Veracode offers static code analysis, integrates with development tools, provides remediation guidance, and enhances security while ensuring scalability and compliance.
Wiz enhances cloud security with risk evaluation, visibility, and incident detection using user-friendly dashboards and automated analysis.
It offers confidence by preventing exposure to vulnerabilities and helps ensure that we are not deploying vulnerable code into production.
The best features in Veracode include static analysis and the early detection of vulnerable libraries; it integrates with tools such as Jenkins.
It fixes issues directly in the IDE while you're doing it.
The feature leads to minimal false positives and a low volume of alerts, which is highly valuable for our operations.
It's highly customizable, allowing us to manage many custom features effectively.
Regarding compliance and governance, Wiz streamlines our vulnerability management to meet specific needs effectively.
 

Categories and Ranking

Veracode
Ranking in Container Security
8th
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
204
Ranking in other categories
Application Security Tools (2nd), Static Application Security Testing (SAST) (2nd), Software Composition Analysis (SCA) (3rd), Static Code Analysis (1st), Application Security Posture Management (ASPM) (1st)
Wiz
Ranking in Container Security
2nd
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
24
Ranking in other categories
Vulnerability Management (3rd), Cloud Workload Protection Platforms (CWPP) (2nd), Cloud Security Posture Management (CSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (1st), Data Security Posture Management (DSPM) (1st), Compliance Management (1st), Cloud Detection and Response (CDR) (1st)
 

Mindshare comparison

As of October 2025, in the Container Security category, the mindshare of Veracode is 3.4%, down from 4.7% compared to the previous year. The mindshare of Wiz is 15.7%, down from 16.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Container Security Market Share Distribution
ProductMarket Share (%)
Wiz15.7%
Veracode3.4%
Other80.9%
Container Security
 

Featured Reviews

Kv Rao - PeerSpot reviewer
Integrates pipelines smoothly and fortifies code against vulnerabilities
I use Veracode in multiple places including static code analysis, penetration testing, and dynamic code analysis. It is part of our pipeline and integrates well with Bitbucket and Git pipelines The ease of integration with Bitbucket pipelines and Git pipelines is vital for us. Veracode allows us…
Wellington Franham - PeerSpot reviewer
Enhanced security profiling and predictive analysis in diverse industries
We are a partner and develop Wiz opportunities here in Brazil and Latin America. We already have some customers using Wiz as a DSPM platform. We use it in various industries, like retail, where it is used for security profiling and predictive analysis to identify risks. There is also a global…
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
868,787 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
15%
Manufacturing Company
9%
Insurance Company
6%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
10%
Healthcare Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise43
Large Enterprise112
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise6
Large Enterprise11
 

Questions from the Community

Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What do you like most about Veracode Static Analysis?
I like its integration with GitHub. I like using it from GitHub. I can use the GitHub URL and find out the vulnerabilities.
What is your experience regarding pricing and costs for Veracode Static Analysis?
When considering pricing, Veracode stands out due to its lower cost per service and more scalable options. It offers nearly five security testing features within its own service, making it a compet...
What do you like most about Wiz?
With Wiz, we get timely alerts for leaked data or any vulnerabilities already existing in our environment.
What is your experience regarding pricing and costs for Wiz?
I don't know how much we pay, but I do know that Wiz charges a lot. However, they're offering a good product, so it might be fair. I haven't seen the exact numbers.
What needs improvement with Wiz?
It would be better if, when you get an alert type, you are able to view the regex or alert logic without having to dig through all the different options; it is difficult to find where the alert log...
 

Comparisons

 

Also Known As

Crashtest Security , Veracode Detect
No data available
 

Overview

 

Sample Customers

Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Wiz is the fastest growing software company ever - $100M ARR in 18 months: Wiz becomes the fastest-growing software company ever | Wiz Blog  Discover why companies, including Salesforce, Morgan Stanley, Fox, and Bridgewater choose Wiz as their cloud security partner. Read their success stories here: Customers | Wiz
Find out what your peers are saying about Veracode vs. Wiz and other solutions. Updated: September 2025.
868,787 professionals have used our research since 2012.