Try our new research platform with insights from 80,000+ expert users
Sr. Manager/Sr. Architect at Cognizant
Real User
It has the lowest false positives with customizable triage options
Pros and Cons
  • "It has the lowest false positives."
  • "Reporting engine needs to be more robust."

What is our primary use case?

We did a comprehensive evaluation on a number of critical parameters in the environment that we are in. Other popular tools that we evaluated failed to meet our expectations.

How has it helped my organization?

  • Ease of development teams to adopt.
  • Faster scanning
  • Lowest false positives
  • No unnecessary bloating of a huge defect list.

These have helped us to focus on the things which need attention.

What is most valuable?

  • Lowest false positive rate
  • Faster scanning time
  • Inline context-sensitive help and other supportive artifacts which help developers.
  • Customizable triage options
  • Integrations with CI/CD tools, etc.

What needs improvement?

  • Reporting engine needs to be more robust.
  • Custom reporting is a must have.
  • Perhaps, the availability of connectors to popular open source BI tools, such as BIRT, JasperReports, or Pentaho may add value.
Buyer's Guide
Coverity
July 2025
Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
861,524 professionals have used our research since 2012.

For how long have I used the solution?

Less than one year.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Jay-Prakash - PeerSpot reviewer
Consaltant at a tech consulting company with 501-1,000 employees
Real User
Top 20
An easy-to-set-up solution used to find vulnerabilities in C++ codes, but its user interface could be improved
Pros and Cons
  • "Coverity is easy to set up and has a less lengthy process to find vulnerabilities."
  • "The solution's user interface and quality gate could be improved."

What is our primary use case?

We are working on medical devices, and the code base is written in C++. We use Coverity to find the vulnerability in those C++ codes.

What is most valuable?

Coverity is easy to set up and has a less lengthy process to find vulnerabilities.

What needs improvement?

The solution's user interface and quality gate could be improved.

For how long have I used the solution?

I have been using Coverity for four months.

What do I think about the stability of the solution?

Coverity has good stability.

I rate Coverity more than eight out of ten for stability.

What do I think about the scalability of the solution?

Around 20 to 25 developers use Coverity in our organization.

I rate Coverity a seven to eight out of ten for scalability.

Which solution did I use previously and why did I switch?

We use SonarQube for Java-based projects and Coverity for C and C++-based projects.

How was the initial setup?

The solution’s initial setup is simple.

What other advice do I have?

Overall, I rate Coverity a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Coverity
July 2025
Learn what your peers think about Coverity. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
861,524 professionals have used our research since 2012.
Architect at a comms service provider with 10,001+ employees
Real User
Stable solution with good technical support service
Pros and Cons
  • "It is a scalable solution."
  • "Sometimes, vulnerabilities remain unidentified even after setting up the rules."

What is our primary use case?

We use the solution to scan the static code and identify vulnerabilities. We can verify the rules and scripting during various applications' implementation processes.

What is most valuable?

The solution has a low false positive rate compared to other vendors. Also, it can scan complex codes. In addition, it has the best features for trial analysis, integration, and language support.

What needs improvement?

Sometimes, vulnerabilities are not identified even after setting up the automated scanning rules. They should include a feature combining automated scanning tools with manual code reviews for better output.

For how long have I used the solution?

I have been using the solution for five years.

What do I think about the stability of the solution?

I rate the solution's stability a nine out of ten.

What do I think about the scalability of the solution?

It is a scalable solution. We can quickly scan around 100 DLS using it. I rate its scalability a nine.

How are customer service and support?

I interact with the solution's technical support team in terms of tuning the tool and improvements. They acknowledge the emails and respond to them quickly.

How would you rate customer service and support?

Positive

How was the initial setup?

The solution integrates well with different tools. Thus, its setup process is relatively straightforward.

What's my experience with pricing, setup cost, and licensing?

The solution is affordable. I rate its pricing a six out of ten.

What other advice do I have?

I recommend the solution to others and rate it a ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2025
Buyer's Guide
Download our free Coverity Report and get advice and tips from experienced pros sharing their opinions.