Try our new research platform with insights from 80,000+ expert users
Senior Manager at MediaTek
Real User
A good and stable solution that has significant software security feature for detecting potential risks
Pros and Cons
  • "The most valuable feature of Coverity is its software security feature called the Checker. If you share some vulnerability or weakness then the software can find any potential security bug or defect. The code integration tool enables some secure coding standards and implements some Checkers for Live Duo. So we can enable secure coding and Azure in this tool. So in our software, we can make sure our software combines some industry supervised data."
  • "We actually specified several checkers, but we found some checkers had a higher false positive rate. I think this is a problem. Because we have to waste some time is really the issue because the issue is not an issue. I mean, the tool pauses or an issue, but the same issue is the filter now.Some check checkers cannot find some issues, but sometimes they find issues that are not relevant, right, that are not really issues. Some customisation mechanism can be added in the next release so that we can define our Checker. The Modelling feature provided by Coverity helps in finding more information for potential issues but it is not mature enough, it should be mature. The fast testing feature for security testing campaign can be added as well. So if you correctly integrate it with the training team, maybe you can help us to find more potential issues."

What is our primary use case?

We have to prepare our software solution for our customers. So in our environment, my cycle. We have a seven hour phase and requirement for design, implement testing, And before testing, we used this tool to clean up our potential feedback as our use case.

.


How has it helped my organization?

This product improves functionality and efficiency.

We cannot find any issues in the early stages.


What is most valuable?

The most valuable feature of Coverity is its software security feature called the Checker. If you share some vulnerability or weakness then the software can find any potential security bug or defect. The code integration tool enables some secure coding standards and implements some Checkers for Live Duo. So we can enable secure coding and Azure in this tool. So in our software, we can make sure our software combines some industry supervised data.



What needs improvement?

We actually specified several checkers, but we found some checkers had a higher false positive rate. I think this is a problem. Because we have to waste some time is really the issue because the issue is not an issue. I mean, the tool pauses or an issue, but the same issue is the filter now.Some check checkers cannot

find some issues, but sometimes they find issues that are not relevant, right, that are not really issues.

Some customisation mechanism can be added in the next release so that we can define our Checker. The Modelling feature provided by Coverity helps in finding more information for potential issues but it is not mature enough, it should be mature. The fast testing feature for security testing campaign can be added as well. So if you correctly integrate it with the training team, maybe you can help us to find more potential issues.


Buyer's Guide
Coverity
July 2025
Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
860,632 professionals have used our research since 2012.

For how long have I used the solution?

We've been using this solution for over 10 years. 

What do I think about the stability of the solution?

The solution is stable.

I rate it eight out of ten.


What do I think about the scalability of the solution?

It is a scalable solution. Several thousand users are using the solution , precisely five thousand software engineers. We plan to increase the usage in future because our software engineer, we are to in their software coding or deployments in our engineering team. We try to integrate this tool into some other tool.


How are customer service and support?

The technical support is reasonable. 

I rate them seven out of ten.


How would you rate customer service and support?

Neutral

How was the initial setup?

I was not involved in the deployment process. Ten partner lines are required for the setting up and launch of the tool.


What was our ROI?

I have seen a Return on Investment.


What other advice do I have?

I rate the solution eight out of ten.


Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Mirza Prangon - PeerSpot reviewer
Solutions Architect at Hitachi High-Tech America
Real User
Stable and scalable, but screens cannot be added to branches easily
Pros and Cons
  • "The most valuable feature of Coverity is that it shows examples of what is actually wrong with the code."
  • "We use GitHub and Gitflow, and Coverity does not fit with Gitflow. I have to create a screen for our branches, and it's a pain for developers. It has been difficult to integrate Coverity with our system."

What is our primary use case?

We use Coverity to help with code security and code vulnerability.

What is most valuable?

The most valuable feature of Coverity is that it shows examples of what is actually wrong with the code.

What needs improvement?

We use GitHub and Gitflow, and Coverity does not fit with Gitflow. I have to create a screen for our branches, and it's a pain for developers. It has been difficult to integrate Coverity with our system.

In the next release, I would like to have the ability to easily add screens to branches myself as a developer.

For how long have I used the solution?

I've been using this solution for about five years.

What do I think about the stability of the solution?

It is a stable product.

What do I think about the scalability of the solution?

It's scalable, and approximately 200 developers use Coverity in my organization. We have 10 administrators at present.

How are customer service and support?

Technical support is good, but they do not have a user ticketing system. Therefore, we have to go through an to administrator to get support. For the support itself, I would give a rating of eight out of ten.

How would you rate customer service and support?

Positive

What's my experience with pricing, setup cost, and licensing?

The pricing is on the expensive side, and we are paying for a couple of items.

What other advice do I have?

My advice would be to look at other solutions and evaluate on-premises or SaaS options.

Overall, I would rate Coverity at six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Coverity
July 2025
Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
860,632 professionals have used our research since 2012.
Iswarya R - PeerSpot reviewer
Assistant Manager at Tata Communications Ltd
Real User
On-prem dynamic static analysis solution that is easy to use and is reasonably priced
Pros and Cons
  • "This solution is easy to use."
  • "The level of vulnerability that this solution covers could be improved compared to other open source tools."

What is our primary use case?

We have been working on a POC for this solution. It is an on-prem solution and we have 50 internal users. 

What is most valuable?

This solution is easy to use. 

What needs improvement?

The level of vulnerability that this solution covers could be improved compared to other open source tools. The UI could also be improved. We also cannot directly report the vulnerability. We need to add filters to projects and only then can we download reports. 

For how long have I used the solution?

I have been using this solution for three months. 

What do I think about the stability of the solution?

This is a stable solution. 

What's my experience with pricing, setup cost, and licensing?

The pricing is very reasonable compared to other platforms. It is based on a three year license. 

What other advice do I have?

I would rate this solution a seven out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Solutions Architect at a computer software company with 11-50 employees
Real User
Broad integration capacity and works with more languages than some competitors
Pros and Cons
  • "One of the most valuable features is Contributing Events. That particular feature helps the developer understand the root cause of a defect. So you can locate the starting point of the defect and figure out exactly how it is being exploited."
  • "Right now, the Coverity executable is around 1.2GB to download. If they can reduce it to approximately 600 or 700MB, that would be great. If they decrease the executable, it will be much easier to work in an environment like Docker."

What is our primary use case?

We write thousands of lines of code on a daily basis, and we cannot say that our code is free because there are a lot of other developers contributing to the source code and things like that. And this process is prone to human error, defects in the source code, etc.

How has it helped my organization?

To automate detection, we use Coverity's static analysis, which has a low false-positive ratio. That's because Coverity's analysis engine includes 20-plus patented technologies. A lot of other static analysis tools use pattern-based analysis, but Coverity's is flow based. That's why we ended up using it. Coverity is helping us identify some of the critical defects at the early stages of the development life cycle. So overall, it is giving us a greater ROI and making our application more mature and robust.

What is most valuable?

One of the most valuable features is Contributing Events. That particular feature helps the developer understand the root cause of a defect. So you can locate the starting point of the defect and figure out exactly how it is being exploited. So contributing Events lets you create that kind of a workflow. 

We also need a tool that works in an environment that isn't dependent on the built environment. You point it to a folder. Then the tool picks it up, runs the scan, and gives you the report. That feature is available in Coverity. So you don't have to rely upon build artifacts or developer artifacts. So these are the two key features we use daily, and we've gotten good results. 

What needs improvement?

Coverity's UI is the one thing that needs improvement. Technically speaking, it's doing an outstanding job otherwise. Also, they could reduce their executable size. Right now, the Coverity executable is around 1.2GB to download. If they can reduce it to approximately 600 or 700MB, that would be great. If they decrease the executable, it will be much easier to work in an environment like Docker.

For how long have I used the solution?

I've been using it for the past two years.

What do I think about the stability of the solution?

This product has been in the industry for more than 30 years, so it's pretty robust.

How are customer service and support?

Coverity has a decent SLA. The moment you purchase the tool, you also get an SLA agreement with all the email support. They have email support, call support, as well as WebEx and Zoom sessions on demand. Of course, that depends on the nature of the technical issue. If it's simple, it can be resolved with a couple of email exchanges, but if it really needs some attention, they're happy to get on a call. They've even delivered some custom patches as well. 

Which solution did I use previously and why did I switch?

I used CodeSonar a few years back. Both tools have their advantages. In any static analysis tool, the first stage is the instrumentation of the source code. It'll try to capture the skeleton of your source code. So when I compare them based on the first phase alone, Coverity is far better than CodeSonar. 

They both use a similar technique, but CodeSonar uses up way more storage resources. For example, to scan a 1GB code base, CodeSonar generates more than 5GB of instrumented files for every 1GB of code base. In total, that is 6GB. Coverity generates 500MB extra on top of 1GB, so that equals 1.5GB all in. That's a huge difference. CodeStar would eat up my disc space and hardware resources when I used it, whereas Coverity is minimal. 

In terms of checkers, both CodeSonar and Coverity cover a good length and breadth, especially for C and C++ programming languages. But CodeSonar focuses only on four languages—C, C++, Java, and C#—only four programming languages, whereas Coverity supports more than 20-plus programming languages.

Also, the two are comparable with respect to their plugin offerings, but there are crucial differences. For example, CodeSonar only focuses on well-known integrations, like Jenkins and JIRA, but you cannot expect all customers to use the same tools. Coverity supports almost all CI/CD tools, including Jenkins and Bamboo. It also integrates with service providers like Azure DevOps Pipelines, AWS CodePipelines that CodeSonar hasn't added yet. The plugins are available in the marketplace, and you don't have to pay extra. You just have to download it from the marketplace, hook the plugin in your pipeline, and ready to use kind of approach. So these are some of the major use cases, three major use cases I would say when you compare apples to apples with CodeSonar and Coverity.

How was the initial setup?

Setting up Coverity is pretty simple. It comes with a normal executable. You just double click, follow the wizard, and complete the setup. It also have on screen instructions as well, which makes it pretty easy and cool. Deployment is a much broader question. It depends on how many projects you are trying to scan using Coverity and whether you are integrating this static analysis solution with your CI/CD setup, ID, bug tracking, etc. That all factors in to the total deployment time. So if we're talking about overall deployment, including bug tracking, integration, email notification, CI/CD integration, and everything, it took us 15 to 20 days to onboard 600 projects with 20 users, including all integration.

We don't have a lot of maintenance. There is a major release every quarter, and we get information on new upgrades, patches, and things like that. And we do have the option to not upgrade. The maintenance is mostly covered by the vendor itself, meaning they deliver the patches and upgrades on time. So I don't see that as a hurdle right now. It's been taken care of.

What's my experience with pricing, setup cost, and licensing?

I'm not sure about the licensing. My commercial team deals with that.

What other advice do I have?

I rate Coverity nine out of 10. It's a good choice. If you plan to use Coverity, you should read through the manual to really understand its settings. You have to tune the Coverity engine to get the best research and scalability out of it. A Coverity recently added some smart features that automatically compute the hardware requirements in your current machine. It automatically scales up. For example, it can detect how much multi-core CPU power it needs to run an analysis and how much memory is required, so it makes resources available for other applications running on the same machine. That intelligence has been built on. So initially, I recommend going over the fundamentals and fine-tuning it based on one's own requirements.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Archana Verma - PeerSpot reviewer
Security Analyst at Dover Corporation
Real User
Top 20
Provides software security and helps find potential security bugs or defects
Pros and Cons
  • "Provides software security, and helps to find potential security bugs or defects."
  • "The product lacks sufficient customization options."

What is our primary use case?

We use this tool for call scans in order to improve call quality. We implement testing and this tool cleans up our potential feedback. We are a semiconductor company and provide software solutions to our clients. I'm a senior manager. 

How has it helped my organization?

Coverity has improved our functionality and efficiency.

What is most valuable?

This product provides software security, and helps to find potential security bugs or defects with its checker feature. The solution also enables us to implement secure coding. 

What needs improvement?

We've found that there is a quite high false positive rate. It's a problem because we end up wasting time on something that's not an issue. The tracker reports too many issues that are not relevant. I'd like to see some kind of customization mechanism in the future. 

For how long have I used the solution?

We've been using this solution for over 10 years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable, we have several thousand users. 

How are customer service and support?

The technical support is reasonable. 

How would you rate customer service and support?

Neutral

What other advice do I have?

I rate this solution eight out of 10. 

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Engineer at a computer software company with 5,001-10,000 employees
Real User
Identify any flow issues in the code but lacks in some features
Pros and Cons
  • "It's very stable."
  • "Some features are not performing well, like duplicate detection and switch case situations."

What is our primary use case?

We use Coverity to scan our code and identify any flow issues in the code that need to be fixed.

What is most valuable?

Coverity is the most popular product for scanning the code. It's much better than other products like Clockwork, PC Link, and other similar products. It's a better scanning product than others.

What needs improvement?

The sales strategy needs to improve. First of all, Coverity will give you a low price; then, one year later, they will raise the price. So it becomes expensive later.

Moreover, Coverity is not doing good in terms of some specific features. For example, in the for loop, they can only check the point of the plus statement and cannot handle the sub-encryption. It can only handle the increase and not the decreased logic. So they will miss critical issues in some conditions.

In future releases, the price and policy could be improved, and also the script for the loop.

For how long have I used the solution?

I have been using Coverity for one year and a half. We don't use the latest version, just a version from about half a year before.

There's not much difference between that and the latest version, just minor changes. 

What do I think about the stability of the solution?

It's very stable. I would rate it a nine. The stability of Coverity was very good. 

What do I think about the scalability of the solution?

I would rate scalability a seven out of ten. 

However, we stopped using Coverity due to pricing issues. I don't have the exact number, but only a few in my department used it for security tasks. They were common employees and engineers.

How are customer service and support?

In the beginning,  customer service and support were very helpful, but now I would say their helpfulness is maybe a six out of ten.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is easy. It just takes a couple of minutes. I could do it myself. Coverity gave me a document with instructions, and the installation was successful. There is a guide for installation.

Moreover, the maintenance of Coverity doesn't require many people. It was done by maybe one or two engineers.

What's my experience with pricing, setup cost, and licensing?

We use the yearly-based license. I would rate the pricing a three out of ten, where one is very expensive, and ten is not expensive at all.

What other advice do I have?

Overall, I would rate Coverity a seven out of ten. I can rate it higher because there are a few areas of improvement in Coverity. The first problem is the pricing. The second one is some features not performing well, like duplicate detection and switch case situations.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Software Engineer at AMD
Real User
A stable and scalable solution for core static analysis
Pros and Cons
  • "The solution effectively identifies bugs in code."
  • "The solution is a bit complex to use in comparison to other products that have many plugins."

What is our primary use case?

Our company has 500 developers and engineers who the solution for C/C++ core static analysis. One engineer handles all ongoing maintenance. 

What is most valuable?

The solution effectively identifies bugs in code. 

What needs improvement?

The solution is a bit complex to use in comparison to other products that have many plugins.

More features could be included for finding bugs and analyzing code. For example, more information could be included to explain errors such as memory leaks. 

For how long have I used the solution?

I have been using the solution for one year. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How are customer service and support?

Technical support is helpful and responsive. 

I rate support an eight out of ten. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have not used another solution. 

What other advice do I have?

I would recommend the solution if it includes more features. 

I rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Jaile Sebes - PeerSpot reviewer
Senior Software Architect at a tech vendor with 10,001+ employees
Real User
Top 5Leaderboard
Easy to set up with good static order analysis but is expensive
Pros and Cons
  • "We were very comfortable with the initial setup."
  • "We'd like it to be faster."

What is our primary use case?

We primarily use the solution for quality purposes. We also use it for security. That's one subset of quality. However, it's used for more dynamic behavior, such as memory leaks, et cetera. 

What is most valuable?

They have a good memory-related box and a static order analysis that's very good, especially around leaks.

We were very comfortable with the initial setup.

It is stable.

What needs improvement?

The cost is very high.

They don't have SonarQube compatibility with the dashboard, which is a big negative. They were actually arrogant for not providing it. We wanted to see all the problems in a single SonarQube dashboard, and we can't do that. They need SonarQube integration. They claim that they have SonarQube integration, yet it is not there.

We'd like it to be faster.

The solution could always use a bit more security. 

For how long have I used the solution?

I've been using the solution for around 12 years. 

What do I think about the stability of the solution?

I consider the solution very stable. There are no bugs or glitches and it doesn't crash or freeze. It is reliable. 

That said, when we are doing security analysis on bigger projects, it can be slow. 

What do I think about the scalability of the solution?

To scale, you need more hardware. That way it is scalable. That said, it is already handling quite a big amount. We have a specific problem when analyzing security in a big project. It can get slow. 

I'd rate it four out of five in its ability to scale. 

We have around 200 people using the solution currently. 30 to 40 use it on a daily basis. 

We do not have plans to increase usage based on the cost. We're actually looking for an alternative.

How are customer service and support?

Support is not so good. They're too slow. In contrast, Clockwork has very good support.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We've used Clockwork before. However, it has the same issues as this product. They're more for C# and C++.

How was the initial setup?

The solution was very simple to set up. The frontend, backend, and UI are very good and easy to navigate.

I'd rate the initial setup process a four out of five in terms of how easy it was.

What's my experience with pricing, setup cost, and licensing?

It is an expensive solution. 

Their sales team is very arrogant. 

I don't like their licensing mechanism. Everything is on very unfriendly terms. 

There are other tools you can use that are free and open-source. 

In a collaborative environment, they are very tricky. When it comes to looking at the bugs on a web interface, they try to block them. When you discuss it with them, they are quite unfriendly. Once you got stuck into the tool, they know that it's hard to leave due to the history. When you get into a tool, you need the history since the history needs to be built up, and therefore, over time, you have a dependency on the tool.

I'd rate the product a three out of five in terms of affordability.

What other advice do I have?

We're a customer.

I would rate the solution seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2025
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros sharing their opinions.