Try our new research platform with insights from 80,000+ expert users
Conformity Controller at STET
Real User
Top 5
Stable, with good documentation but the pricing is a bit high
Pros and Cons
  • "We've found the documentation to be very good."
  • "The pricing is a bit high."

What is most valuable?

The solution has been quite stable over the years.

We've found the documentation to be very good.

When there are issues, there is a lot of explanation about what they are and how to solve problems. Communication is very clear. 

What needs improvement?

The pricing is a bit high. 

We have not enough for really sharing between with editor. Therefore, we have to use an older version of a product.

For how long have I used the solution?

We've used the solution for 12 or so years at this point. It's been well over a decade. We've used it for quite a while.

What do I think about the stability of the solution?

The stability of the solution is pretty good. There are no bugs or glitches. It doesn't crash or freeze. It's pretty reliable. 

Buyer's Guide
Fortify Static Code Analyzer
May 2025
Learn what your peers think about Fortify Static Code Analyzer. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.

How are customer service and support?

Technical support is good. When we put in requests, we get feedback and results. Older requests get treated with priority, and newer requests go into a queue. 

What's my experience with pricing, setup cost, and licensing?

The pricing of the solution is a bit high. It would be nice if it was more competitive.

Which other solutions did I evaluate?

While we do want to continue to use the product, we want to negotiate with Microsoft about the licensing. in the meantime, we will likely evaluate a few other options.

What other advice do I have?

We're just an end-user and a customer. We don't have a business relationship with Fortify.

We are not using the latest version of the solution right now. We're waiting for the Fortify version with PCI DSS 4.0.

I'd rate the solution at a six out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Abner Silva - PeerSpot reviewer
Cloud Security Analyst at a agriculture with 1-10 employees
Real User
Top 5Leaderboard
Identifies issues like password credentials and access keys embedded in the code
Pros and Cons
  • "Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like password credentials and access keys embedded in the code."
  • "The product shows false positives for Python applications."

What is our primary use case?

We use the tool for web-based applications. 

What is most valuable?

Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like password credentials and access keys embedded in the code.

I have integrated the solution with GitLab, Jira, and ITSM. 

What needs improvement?

The product shows false positives for Python applications. 

What other advice do I have?

I haven't customized many rules, but some customizations that have been applied have been particularly useful in our pipeline. For instance, if our application is found to be very vulnerable, we don't proceed with deployment. We utilize static analysis, and the pipeline is halted until the vulnerabilities are addressed. Similarly, I've applied this approach in Fortify Static Code Analyzer and Checkmark SCA to stop the execution pipeline for highly vulnerable applications.

I utilize validation in the code to manage false positives in the results. In this case, the application helps identify false positives, and I spend extra time validating them. 

I would recommend Fortify Static Code Analyzer for .NET applications and not for Python ones. I rate it an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user