We did a comprehensive evaluation on a number of critical parameters in the environment that we are in. Other popular tools that we evaluated failed to meet our expectations.
Sr. Manager/Sr. Architect at Cognizant
It has the lowest false positives with customizable triage options
Pros and Cons
- "It has the lowest false positives."
- "Ease of development teams to adopt."
- "Reporting engine needs to be more robust."
- "Reporting engine needs to be more robust. Custom reporting is a must have."
What is our primary use case?
How has it helped my organization?
- Ease of development teams to adopt.
- Faster scanning
- Lowest false positives
- No unnecessary bloating of a huge defect list.
These have helped us to focus on the things which need attention.
What is most valuable?
- Lowest false positive rate
- Faster scanning time
- Inline context-sensitive help and other supportive artifacts which help developers.
- Customizable triage options
- Integrations with CI/CD tools, etc.
What needs improvement?
Buyer's Guide
Coverity Static
May 2026
Learn what your peers think about Coverity Static. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,244 professionals have used our research since 2012.
For how long have I used the solution?
Less than one year.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consaltant at a tech consulting company with 501-1,000 employees
An easy-to-set-up solution used to find vulnerabilities in C++ codes, but its user interface could be improved
Pros and Cons
- "Coverity is easy to set up and has a less lengthy process to find vulnerabilities."
- "The solution's user interface and quality gate could be improved."
What is our primary use case?
We are working on medical devices, and the code base is written in C++. We use Coverity to find the vulnerability in those C++ codes.
What is most valuable?
Coverity is easy to set up and has a less lengthy process to find vulnerabilities.
What needs improvement?
The solution's user interface and quality gate could be improved.
For how long have I used the solution?
I have been using Coverity for four months.
What do I think about the stability of the solution?
Coverity has good stability.
I rate Coverity more than eight out of ten for stability.
What do I think about the scalability of the solution?
Around 20 to 25 developers use Coverity in our organization.
I rate Coverity a seven to eight out of ten for scalability.
Which solution did I use previously and why did I switch?
We use SonarQube for Java-based projects and Coverity for C and C++-based projects.
How was the initial setup?
The solution’s initial setup is simple.
What other advice do I have?
Overall, I rate Coverity a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Coverity Static
May 2026
Learn what your peers think about Coverity Static. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,244 professionals have used our research since 2012.
Junior Software Engineer at NAVER Corp
Has a straightforward UI and helps to scan codes
Pros and Cons
- "I like Coverity's capability to scan codes once we push it. We don't need more time to review our colleagues' codes. Its UI is pretty straightforward."
- "The product should include more customization options. The analytics is not as deep as compared to SonarQube."
What is most valuable?
I like Coverity's capability to scan codes once we push it. We don't need more time to review our colleagues' codes. Its UI is pretty straightforward.
What needs improvement?
The product should include more customization options. The analytics is not as deep as compared to SonarQube.
For how long have I used the solution?
I have been using the product for one month.
What do I think about the stability of the solution?
I would rate Coverity's stability a ten out of ten.
What do I think about the scalability of the solution?
I would rate the product's scalability an eight out of ten. My company has three users for the tool.
How was the initial setup?
I would rate the tool's setup a seven out of ten. The deployment gets completed in a couple of minutes.
What's my experience with pricing, setup cost, and licensing?
I would rate the tool's pricing a one out of ten.
What other advice do I have?
Coverity's documentation is pretty straightforward and I would rate it a seven out of ten. The solution is cheap and provides us with a dedicated server.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Coverity Static Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Static Application Security Testing (SAST)Popular Comparisons
SonarQube
Checkmarx One
Veracode
Acunetix
PortSwigger Burp Suite Professional
OpenText Core Application Security
OWASP Zap
HCL AppScan
Semgrep
Qualys Web Application Scanning
Invicti
Klocwork
Parasoft SOAtest
Buyer's Guide
Download our free Coverity Static Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?
- What Application Security Solution Do You Use That Is DevOps Friendly?
- Which is the most comprehensive open source Web Security Testing tool?
- What is the best Application Security Testing platform?
- When evaluating Application Security Testing, what aspect do you think is the most important to look for?
- SAST vs. DAST: Which is better for application security testing?
- What tools do you rely on for building a DevSecOps pipeline?
- What does the Log4j/Log4Shell vulnerability mean for your company?
















