We are working on medical devices, and the code base is written in C++. We use Coverity to find the vulnerability in those C++ codes.
Consaltant at a tech consulting company with 501-1,000 employees
An easy-to-set-up solution used to find vulnerabilities in C++ codes, but its user interface could be improved
Pros and Cons
- "Coverity is easy to set up and has a less lengthy process to find vulnerabilities."
- "The solution's user interface and quality gate could be improved."
What is our primary use case?
What is most valuable?
Coverity is easy to set up and has a less lengthy process to find vulnerabilities.
What needs improvement?
The solution's user interface and quality gate could be improved.
For how long have I used the solution?
I have been using Coverity for four months.
Buyer's Guide
Coverity Static
August 2026
Learn what your peers think about Coverity Static. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,834 professionals have used our research since 2012.
What do I think about the stability of the solution?
Coverity has good stability.
I rate Coverity more than eight out of ten for stability.
What do I think about the scalability of the solution?
Around 20 to 25 developers use Coverity in our organization.
I rate Coverity a seven to eight out of ten for scalability.
Which solution did I use previously and why did I switch?
We use SonarQube for Java-based projects and Coverity for C and C++-based projects.
How was the initial setup?
The solution’s initial setup is simple.
What other advice do I have?
Overall, I rate Coverity a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Junior Software Engineer at NAVER Corp
Has a straightforward UI and helps to scan codes
Pros and Cons
- "I like Coverity's capability to scan codes once we push it. We don't need more time to review our colleagues' codes. Its UI is pretty straightforward."
- "The product should include more customization options. The analytics is not as deep as compared to SonarQube."
What is most valuable?
I like Coverity's capability to scan codes once we push it. We don't need more time to review our colleagues' codes. Its UI is pretty straightforward.
What needs improvement?
The product should include more customization options. The analytics is not as deep as compared to SonarQube.
For how long have I used the solution?
I have been using the product for one month.
What do I think about the stability of the solution?
I would rate Coverity's stability a ten out of ten.
What do I think about the scalability of the solution?
I would rate the product's scalability an eight out of ten. My company has three users for the tool.
How was the initial setup?
I would rate the tool's setup a seven out of ten. The deployment gets completed in a couple of minutes.
What's my experience with pricing, setup cost, and licensing?
I would rate the tool's pricing a one out of ten.
What other advice do I have?
Coverity's documentation is pretty straightforward and I would rate it a seven out of ten. The solution is cheap and provides us with a dedicated server.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Coverity Static
August 2026
Learn what your peers think about Coverity Static. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,834 professionals have used our research since 2012.
Project Associate at a tech vendor with 10,001+ employees
Stable solution with good technical support service
Pros and Cons
- "It is a scalable solution."
- "Sometimes, vulnerabilities remain unidentified even after setting up the rules."
What is our primary use case?
We use the solution to scan the static code and identify vulnerabilities. We can verify the rules and scripting during various applications' implementation processes.
What is most valuable?
The solution has a low false positive rate compared to other vendors. Also, it can scan complex codes. In addition, it has the best features for trial analysis, integration, and language support.
What needs improvement?
Sometimes, vulnerabilities are not identified even after setting up the automated scanning rules. They should include a feature combining automated scanning tools with manual code reviews for better output.
For how long have I used the solution?
I have been using the solution for five years.
What do I think about the stability of the solution?
I rate the solution's stability a nine out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. We can quickly scan around 100 DLS using it. I rate its scalability a nine.
How are customer service and support?
I interact with the solution's technical support team in terms of tuning the tool and improvements. They acknowledge the emails and respond to them quickly.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution integrates well with different tools. Thus, its setup process is relatively straightforward.
What's my experience with pricing, setup cost, and licensing?
The solution is affordable. I rate its pricing a six out of ten.
What other advice do I have?
I recommend the solution to others and rate it a ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Coverity Static Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Static Application Security Testing (SAST)Popular Comparisons
SonarQube
Checkmarx One
Veracode
PortSwigger Burp Suite Professional
Acunetix
OpenText Core Application Security
OWASP Zap
HCL AppScan
Invicti
Semgrep
Aikido Security
Qualys Web Application Scanning
Parasoft SOAtest
Buyer's Guide
Download our free Coverity Static Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?
- What Application Security Solution Do You Use That Is DevOps Friendly?
- Which is the most comprehensive open source Web Security Testing tool?
- What is the best Application Security Testing platform?
- When evaluating Application Security Testing, what aspect do you think is the most important to look for?
- SAST vs. DAST: Which is better for application security testing?
- What tools do you rely on for building a DevSecOps pipeline?
- What does the Log4j/Log4Shell vulnerability mean for your company?
















