We've integrated Coverity into our CI/CD pipeline to check our source code against quality gates before deployment. It alerts us to issues so we can halt the pipeline, fix critical problems, and then run it again.
App Security at FineLabs
Helps to check source code against quality gates before deployment
Pros and Cons
- "What I find most effective about Coverity is its low rate of false positives. I've seen other platforms with many false positives, but with Coverity, most vulnerabilities it identifies are genuine. This allows me to focus on real issues."
- "The solution needs to improve its false positives."
What is our primary use case?
What is most valuable?
What I find most effective about Coverity is its low rate of false positives. I've seen other platforms with many false positives, but with Coverity, most vulnerabilities it identifies are genuine. This allows me to focus on real issues.
As for code remediation, although I can fix issues myself as a security engineer, the tool provides helpful remediation guidance for each vulnerability. It lists how to fix each issue, which I find useful. The solution has increased our development speed.
What needs improvement?
The solution needs to improve its false positives.
For how long have I used the solution?
I have been using the product for one and a half years.
Buyer's Guide
Coverity Static
March 2026
Learn what your peers think about Coverity Static. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,933 professionals have used our research since 2012.
What do I think about the scalability of the solution?
I rate the tool's scalability a nine out of ten. We have 20-25 users who use it daily.
How was the initial setup?
I rate the solution's deployment ease a nine out of ten, and it can be completed in a few minutes.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is comparable to other products.
What other advice do I have?
I rate the overall solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director at a healthcare company with 10,001+ employees
Useful in areas like code quality and secure code analysis but needs to offer easy integration capabilities
Pros and Cons
- "The tool as it is can be used for code quality improvement."
- "I had tried integrating the tool with Azure DevOps, but the report I got stated that my team faced many challenges."
What is our primary use case?
I use my company's solution for code quality and secure code analysis.
What is most valuable?
The tool as it is can be used for code quality improvement. Whatever rules are in the tool are useful.
What needs improvement?
I don't use it directly on a day-to-day basis.
I expect the product to offer ease of integration with the built pipelines. I had tried integrating the tool with Azure DevOps, but the report I got stated that my team faced many challenges. I do not know the exact details.
For how long have I used the solution?
I have been using Coverity for a few years.
Which solution did I use previously and why did I switch?
I use Coverity simultaneously with Fortify but for different purposes.
What's my experience with pricing, setup cost, and licensing?
I don't deal with the pricing.
What other advice do I have?
I am satisfied with the product.
The tool is used for specific use cases like embedded systems.
I would not recommend the tool for web application technologies, Java, or cloud-native technologies since the tool is meant for embedded codes.
I rate the tool a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Coverity Static
March 2026
Learn what your peers think about Coverity Static. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,933 professionals have used our research since 2012.
Works at a comms service provider with 1-10 employees
Performs static application security testing on various code bases, including Java, PHP, and HTML
Pros and Cons
- "The product has been beneficial in logging functionality, allowing me to categorize vulnerabilities based on severity. This aids in providing updated reports on subsequent scans."
- "The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming."
- "The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming."
What is our primary use case?
My primary use case is performing static application security testing on various code bases, including Java, PHP, and HTML. I use it to create review reports of assets and categorize the issues based on severity.
What is most valuable?
The product has been beneficial in logging functionality, allowing me to categorize vulnerabilities based on severity. This aids in providing updated reports on subsequent scans.
What needs improvement?
The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming.
For how long have I used the solution?
I have been using Coverity for about two to three months, between June 2023 and August 2023.
What do I think about the stability of the solution?
There were occasional issues with lag during the initial setup and scans, especially in a cloud environment.
How are customer service and support?
Due to the subscription-based model, I had to contact customer service, mainly to add new users. Response times varied, sometimes taking more than a week.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I had experience with SonarQube as an alternative. Coverity excelled in code scanning because it did not require installation prerequisites. Its reports are also clear and informational. It provides us with a better idea of troubleshooting vulnerabilities.
How was the initial setup?
The initial setup was elaborate and somewhat complicated. The information from the Synopsys website was more than enough. First-time users will struggle with many tools, packages, and libraries. Deployment took 30 minutes to complete. Two to three resources were involved in the process.
What about the implementation team?
An integrator helped with the tool's deployment.
What other advice do I have?
I rate the solution a nine out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Database security at a consultancy with 201-500 employees
A comprehensive solution for SaaS support providing detailed report and security advisor
What is our primary use case?
We use the solution for SaaS support.
What is most valuable?
The most valuable feature is the security advisor. It also provides a very detailed report.
What needs improvement?
Triage history has many bugs and needs to be improved. There could be a subsection. The solution could provide a graphical representation like other tools.
We have OS 2021, which is not the latest one. It should be updated regularly.
For how long have I used the solution?
I have been using Coverity for almost a year.
What do I think about the stability of the solution?
The product is stable.
I rate the solution’s stability a nine out of ten.
What do I think about the scalability of the solution?
Our organization has 20-30 users using this solution.
I rate the solution’s scalability an eight out of ten.
How are customer service and support?
Technical support has expert hours and is available anytime. Also, we don't need to raise a ticket now because we have direct support from Coverity.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are exploring Black Duck, which has more precise things. Coverity has a clear view. The report is very much clear rather than confusing like other tools. It also has a PDF option, and it gives precise information.
How was the initial setup?
The initial setup is simple.
What's my experience with pricing, setup cost, and licensing?
The solution has higher pricing. The price should be based on the user count. Suppose there is a ten-user license per pack. However, this could be adjusted to five users if needed.
What other advice do I have?
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
On-prem dynamic static analysis solution that is easy to use and is reasonably priced
Pros and Cons
- "This solution is easy to use."
- "The level of vulnerability that this solution covers could be improved compared to other open source tools."
What is our primary use case?
We have been working on a POC for this solution. It is an on-prem solution and we have 50 internal users.
What is most valuable?
This solution is easy to use.
What needs improvement?
The level of vulnerability that this solution covers could be improved compared to other open source tools. The UI could also be improved. We also cannot directly report the vulnerability. We need to add filters to projects and only then can we download reports.
For how long have I used the solution?
I have been using this solution for three months.
What do I think about the stability of the solution?
This is a stable solution.
What's my experience with pricing, setup cost, and licensing?
The pricing is very reasonable compared to other platforms. It is based on a three year license.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Software Architect at a tech vendor with 10,001+ employees
Easy to set up with good static order analysis but is expensive
Pros and Cons
- "We were very comfortable with the initial setup."
- "We'd like it to be faster."
What is our primary use case?
We primarily use the solution for quality purposes. We also use it for security. That's one subset of quality. However, it's used for more dynamic behavior, such as memory leaks, et cetera.
What is most valuable?
They have a good memory-related box and a static order analysis that's very good, especially around leaks.
We were very comfortable with the initial setup.
It is stable.
What needs improvement?
The cost is very high.
They don't have SonarQube compatibility with the dashboard, which is a big negative. They were actually arrogant for not providing it. We wanted to see all the problems in a single SonarQube dashboard, and we can't do that. They need SonarQube integration. They claim that they have SonarQube integration, yet it is not there.
We'd like it to be faster.
The solution could always use a bit more security.
For how long have I used the solution?
I've been using the solution for around 12 years.
What do I think about the stability of the solution?
I consider the solution very stable. There are no bugs or glitches and it doesn't crash or freeze. It is reliable.
That said, when we are doing security analysis on bigger projects, it can be slow.
What do I think about the scalability of the solution?
To scale, you need more hardware. That way it is scalable. That said, it is already handling quite a big amount. We have a specific problem when analyzing security in a big project. It can get slow.
I'd rate it four out of five in its ability to scale.
We have around 200 people using the solution currently. 30 to 40 use it on a daily basis.
We do not have plans to increase usage based on the cost. We're actually looking for an alternative.
How are customer service and support?
Support is not so good. They're too slow. In contrast, Clockwork has very good support.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We've used Clockwork before. However, it has the same issues as this product. They're more for C# and C++.
How was the initial setup?
The solution was very simple to set up. The frontend, backend, and UI are very good and easy to navigate.
I'd rate the initial setup process a four out of five in terms of how easy it was.
What's my experience with pricing, setup cost, and licensing?
It is an expensive solution.
Their sales team is very arrogant.
I don't like their licensing mechanism. Everything is on very unfriendly terms.
There are other tools you can use that are free and open-source.
In a collaborative environment, they are very tricky. When it comes to looking at the bugs on a web interface, they try to block them. When you discuss it with them, they are quite unfriendly. Once you got stuck into the tool, they know that it's hard to leave due to the history. When you get into a tool, you need the history since the history needs to be built up, and therefore, over time, you have a dependency on the tool.
I'd rate the product a three out of five in terms of affordability.
What other advice do I have?
We're a customer.
I would rate the solution seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Software Integration Engineer at Thales
Powerful capabilities, reliable, and good support
Pros and Cons
- "The most valuable feature of Coverity is the wrapper. We use the wrapper to build the C++ component, then we use the other code analysis to analyze the code to the build object, and then send back the result to the SonarQube server. Additionally, it is a powerful capabilities solution."
- "Coverity could improve the ease of use. Sometimes things become difficult and you need to follow the guides from the website but the guides could be better."
What is our primary use case?
We use Coverity because we have a SonarQube server and we have a lot of software components that use different languages, such as Java, C, C++, and above. For C and C++ components we use Coverity.
What is most valuable?
The most valuable feature of Coverity is the wrapper. We use the wrapper to build the C++ component, then we use the other code analysis to analyze the code to the build object, and then send back the result to the SonarQube server. Additionally, it is a powerful capabilities solution.
What needs improvement?
Coverity could improve the ease of use. Sometimes things become difficult and you need to follow the guides from the website but the guides could be better.
For how long have I used the solution?
I have been using Coverity for approximately four years.
What do I think about the stability of the solution?
Coverity is stable.
What do I think about the scalability of the solution?
The scalability of Coverity is good. We have more than around 15 software components and other components involved.
We have 20 developers that are using the solution in my organization.
How are customer service and support?
We had support from Coverity for the first six months of usage but later we did not.
I rate the support from Coverity a four out of five.
Which solution did I use previously and why did I switch?
We have used other solutions, such as SonarQube.
How was the initial setup?
In the beginning, it takes two weeks to learn how to set up Coverity, but later the maintenance work is very easy. The beginning involves soft code, that we need to set up before using SonarQube, we have created SonarQube property itself for every component and inside we need to copy different options for Coverity. We had global Coverity roles or vendors we had to allow it to work with global rules and according to the component itself and the setup. The full implementation process can take approximately one month to complete.
What about the implementation team?
We have two teams to set up the server and install Coverity. I set up the project in Coverity and the different roles in the soft code. The developers use Coverity in their daily work.
What other advice do I have?
My advice to other is the first few steps of using Coverity takes time. It's better to have an experienced user to support it. For new users, it will be hard for them to set it up. If they can get someone to support it directly at the beginning it would be better because for me it's very hard at the beginning for a few weeks.
And on a scale from one to 10, how would you rate Coverity?
I rate Coverity an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Application Security Auditor at Softtek
Great app analysis, support, and pricing
Pros and Cons
- "The app analysis is the most valuable feature as I know other solutions don't have that."
- "The solution could use more rules."
What is our primary use case?
We use the product only as a solution for defect code, to find more build liabilities in the code.
How has it helped my organization?
The product allows us to find vulnerabilities while testing our apps.
What is most valuable?
The app analysis is the most valuable feature as I know other solutions don't have that.
It's a good tool. The interface, support, pricing, and integration do not have any limitations.
What needs improvement?
The solution could use more rules. For example, if I have a lot of rules in many languages, it helps my company as having access to more rules works for us.
We'd like a bit more integration.
For how long have I used the solution?
I've been using the solution for maybe three months.
What do I think about the stability of the solution?
The solution is stable. There are no bugs or glitches and it doesn't crash or freeze. It's reliable and the performance has been good overall.
What do I think about the scalability of the solution?
We find the solution to be scalable.
I'm not sure exactly how many people are using the product.
I can't say if we have plans to increase usage or not in the future.
How are customer service and support?
We haven't had any issues with technical support. They are helpful and responsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We also use SonarQube.
In the past, I used Checkmarx and Fortify, and Coverity had the better price.
How was the initial setup?
I have access only to the interface part and I didn't do the configuration of the tool. I do not handle the initial setup of the product.
As I recall, the deployment itself only took days.
What about the implementation team?
Our company managed the setup in-house without the help of outside vendors.
What's my experience with pricing, setup cost, and licensing?
We find the pricing to be reasonable.
What other advice do I have?
We're a customer and end-user.
We are using a recent version of the solution.
I'd like potential new users to be aware that it's a good tool to implement basic code.
I'd rate the solution nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Coverity Static Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Static Application Security Testing (SAST)Popular Comparisons
SonarQube
Checkmarx One
Veracode
Acunetix
OpenText Core Application Security
OWASP Zap
PortSwigger Burp Suite Professional
HCL AppScan
Qualys Web Application Scanning
Semgrep
Invicti
Klocwork
Parasoft SOAtest
Buyer's Guide
Download our free Coverity Static Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?
- What Application Security Solution Do You Use That Is DevOps Friendly?
- Which is the most comprehensive open source Web Security Testing tool?
- What is the best Application Security Testing platform?
- When evaluating Application Security Testing, what aspect do you think is the most important to look for?
- SAST vs. DAST: Which is better for application security testing?
- What tools do you rely on for building a DevSecOps pipeline?
- What does the Log4j/Log4Shell vulnerability mean for your company?




















