No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer988890 - PeerSpot reviewer
VP Delivery & Customer Success at a computer software company with 11-50 employees
Real User
Jan 12, 2022
Mature, saves time in finding defects, and is simple to maintain
Pros and Cons
  • "The most valuable feature is the Incremental analysis."
  • "It saves a lot of time when it comes to finding defects, it's basically inputted in every access we do."
  • "I believe it should support more languages, such as Python and JavaScript."

What is our primary use case?

Klocwork is part of the DevOps process. It is scaling the code on every request.

How has it helped my organization?

It saves a lot of time when it comes to finding defects, it's basically inputted in every access we do.

What is most valuable?

The most valuable feature is the Incremental analysis.

What needs improvement?

I believe it should support more languages, such as Python and JavaScript.

I would like to see dynamic analysis as well.

Buyer's Guide
Klocwork
June 2026
Learn what your peers think about Klocwork. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.

For how long have I used the solution?

I have been working with Klocwork for seven years.

We are using version 2021.2.

What do I think about the stability of the solution?

Klocwork is very stable and very mature.

What do I think about the scalability of the solution?

It is very scalable.

In our organization, we have 50 users.

It is used on a daily basis. It's one of the most important tools that every developer has.

How are customer service and support?

The support is good. We have no problems with the support.

Which solution did I use previously and why did I switch?

We used Coverity in the past, but they shifted their focus, and we switched to Klocwork.

How was the initial setup?

The initial setup is straightforward.

It is simple to set up and can be done by any developer.

The initial deployment took a couple of days.

We have one person, working half-time to maintain this solution. That is all that is needed.

What about the implementation team?

I didn't require any assistance because I installed it myself.

What was our ROI?

We have seen a return on investment. Each developer invests at least half an hour a day less on defects. 

What's my experience with pricing, setup cost, and licensing?

Licensing fees are paid annually, but they also have a perpetual license.

There are no additional costs.

What other advice do I have?

I would recommend, first creating a baseline of their source code with all of the issues, and then handling the new issues on a daily basis while gradually resolving the old ones.

I would rate Klocwork a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Deputy Manager Quality Assurance at eInfochips
Real User
Jun 8, 2021
Easy installation for regular code scanning of C, C++ and MISRA rules, but updates are lengthy and involved
Pros and Cons
  • "Technical support is quite good."
  • "Every update that we receive requires of us a lengthy and involved process."

What is our primary use case?

We are using the latest version.

We use the solution for regular code scanning for C and C++, as well as for MISRA rules

What needs improvement?

When an upgrade is carried out it must be done on both the server and client side, which can make it a bit hectic for all projects to be configured on the private server. Every update that we receive requires of us a lengthy and involved process.

The project reporting status dashboard should also be addressed. As I am on the compliance team, I must open every project to resolve all issues.  The solution does not provide consolidated views. Meanwhile, Kuiwan has a very good feature on its dashboard.

Moreover, Klocwork makes a limited number of languages available to the user, only four. In addition, a good consolidated dashboard, in respect of compliance, would be nice to see.

For how long have I used the solution?

I have been working with Klocwork for seven or eight years.

How are customer service and technical support?

Technical support is quite good. We have a vendor partner in India and they do a good job of supporting us. 

How was the initial setup?

Klocwork was easy to install. But, as we are using an on-premises server, our client's configuration needs are different. Since this is on the user's machine the installation part is easy. Yet, the receipt of frequent updates means that time which could be spent on the project side is consumed by that of development.

What's my experience with pricing, setup cost, and licensing?

When it comes to licensing, the solution has two packages, one for a fixed and the other for a floating server. The former is more cost effective than the latter. 

What other advice do I have?

We are currently using SonarQube for other languages, those of Python and Android.

At present, we make use of both the Klocwork and SonarQube tools. However, as we wish to have a combined tool, we are planning to switch to Kuiwan.

I rate Klocwork as a seven out of 10. 

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
PeerSpot user
Buyer's Guide
Klocwork
June 2026
Learn what your peers think about Klocwork. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
Senior Product Specialist at Meteonic Innovation Pvt. Ltd.
Real User
Top 20Leaderboard
Oct 29, 2022
On-the-fly analysis and incremental analysis are the best parts, and its detection rate is very high for C and C++
Pros and Cons
  • "On-the-fly analysis and incremental analysis are the best parts of Klocwork, and currently we are using both of these features very effectively."
  • "Modern languages, such as Angular and .NET, should be included as a part of Klocwork. They have recently added Kotlin as a part of their project, but we would like to see more languages in Klocwork. That's the reason we are using Coverity as a backup for some of the other languages."
  • "Modern languages, such as Angular and .NET, should be included as a part of Klocwork."

What is our primary use case?

We are using it for C and C++ to find security vulnerabilities in our source code. It is a static application security testing (SAST) tool.

What is most valuable?

On-the-fly analysis and incremental analysis are the best parts of Klocwork. Currently, we are using both of these features very effectively.

What needs improvement?

Modern languages, such as Angular and .NET, should be included as a part of Klocwork. They have recently added Kotlin as a part of their project, but we would like to see more languages in Klocwork. That's the reason we are using Coverity as a backup for some of the other languages. 

I would like to see some more new guidelines added. As you know, this Klocwork tool is fully compliant with MISRA, CERT, and CWE, but a few coding guidelines are still not supported by Klocwork.

For how long have I used the solution?

I have been using it for around eight years.

What do I think about the stability of the solution?

We have been using Klocwork for many years. That itself speaks of its stability in our organization.

What do I think about the scalability of the solution?

We have been trying to scale up this particular tool. We are not only using Klocwork. We are also using other SAST solutions because security cannot be handled by only using one particular tool. Klocwork is the oldest one, but we are using SonarQube and Coverity to filter out more and more defects from our source code. So, it's not really scalable itself, but with the help of other tools, we managed to scale to organization needs.

Currently, we have nine users who are using it in our organization. It is used once a week to give the reports to our security team, and they act on those reports to filter out all the vulnerabilities.

How are customer service and support?

They're hyperresponsive. They have regular calls to see what exactly we are doing with Klocwork and how we are doing. They are super responsive. They are knowledgeable. I would rate them a five out of five.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I used Kiuwan earlier, but I used it for open source. It was primarily to find open sources in our entire source code. It supports modern languages. It has more languages than Klocwork.

How was the initial setup?

It is an on-premise solution. It is not very difficult to set up on our premises. It is easy to install and easy to use. I would rate it a five out of five in terms of the setup.

What other advice do I have?

If your source code is in C or C++, you should be using Klocwork. We have compared the results of different tools like SonarQube and Coverity with Klocwork. Klocwork was able to find a better number of defects in the source code than SonarQube and Coverity. At times, both Coverity and SonarQube missed some of the defects such as null pointer dereference, memory leak issues, etc. The detection rate of Klocwork is very high for C and C++.

I would rate Klocwork an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1184322 - PeerSpot reviewer
Software Chief Engineer at a transportation company with 10,001+ employees
Real User
Nov 21, 2019
It allows our team members to collaborate, but the codes between projects need to improve
Pros and Cons
  • "One can increase the number of vendors, so the solution is scalable."
  • "I really like Klocwork's server client build because it allows collaboration between the team members."
  • "I would like to see better codes between projects and a more user-friendly desktop in the next release."
  • "There are many things that can be improved. The code used between projects is one of the very painful points in Klocwork."

What is our primary use case?

Our primary use case of Klocwork is for static project analysis and for getting ratios.

What is most valuable?

I really like Klocwork's server client build because it allows collaboration between the team members. It takes the ratios and it has a portal where one can justify the issues.

What needs improvement?

There are many things that can be improved. The code used between projects is one of the very painful points in Klocwork. So if you are using a code and the product is shared between projects, you have to analyze the different projects just to comment if it is good or to justify it in the different projects. And the solutions they provide for the issues, are not fully correct. So this is the main issue is using the code between projects.

For how long have I used the solution?

I have been using Klocwork for around four months now.

What do I think about the stability of the solution?

I think the solution is fairly stable. We've had some issues in the GUI, and even in the server portal and in the server application. We've also had issues with an outside application that is  also a GUI client. So I will say it is stable but there are some issues.

What do I think about the scalability of the solution?

One can increase the number of vendors, so the solution is scalable. We currently have around 3,000 users.

How are customer service and technical support?

We don't deal with the technical team directly, because we have a service line. So if I have an issue, we report to our service line and they report to the technical support team.

How was the initial setup?

The initial setup wasn't complex - it was really straightforward.

What other advice do I have?

My advice to others would be that they should determine their use case before buying the program. If they have many codes, I would not recommend it. If they have a separate project where not many codes are shared between projects, I will recommend it. 

I would like to see better codes between projects and a more user-friendly desktop in the next release. 

On a scale from one to 10, I rate this product a seven.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
TMS Product Architect with 10,001+ employees
Real User
Nov 19, 2019
Enables us to resolve violations but it needs integration with Agile DevOps and Agile methodologies
Pros and Cons
  • "There is a central Klocwork server at our headquarter in France so we connect the client directly to the server on-premises remotely."
  • "We consider it a stable product."
  • "For an improved product, we'd like to see integration with Agile DevOps and Agile methodologies."

What is our primary use case?

I'm a product architect and belong to a classic management system team. We're a Klocwork customer. We have around 50-60 developers in the team and I'm involved in the utilization of the tool and I am familiar with its capability. We've just started using the latest version which is the first one that's compatible with .NET framework 4.7.2. The previous version was not fully compatible with Visual Studio 2017.

In our case, the use is for static code analysis for each baseline in order to see what kind of violation we have.

Parallel to that, we use the results and apply some refactoring in order to solve this violation. For us, the violation is considered the highest priority according to our risk assessment model.

What needs improvement?

For an improved product, we'd like to see integration with Agile DevOps and Agile methodologies. Some capability of the tool that allows us to trigger the status analysis report based on actions like regular builds. We would like to have better integration with Microsoft Agile DevOps tools. This would save us a lot of time. In addition, we also sometimes experience issues with false-positive detections - phantom issues.

For the previous version, we realized it wasn't possible to have a quick dashboard for the number of violations. A feature like business intelligence or code coverage could be included. 

For how long have I used the solution?

I've been using Klocwork since I joined the company over two years ago.

What do I think about the stability of the solution?

We consider it a stable product.

What do I think about the scalability of the solution?

I didn't have the chance to test it deeply.

How are customer service and technical support?

I haven't had direct contact with technical support. 

Which solution did I use previously and why did I switch?

Where I worked previously we used SonarQube. I have also used the Microsoft standard rule set by Visual Studio. 

How was the initial setup?

The initial setup is quite straightforward and the configuration from the client-side is also simple. The more difficult part aspect relates to the definition of the rule sets. For instance, if we want to compare a list of rule sets coming from external sources other than Klocwork we don't have native tools. We need to bring the profile list from Microsoft or from another static analysis tool or measuring tool and embed it inside Klocwork. The profiles need to be merged using Excel or something similar.

What about the implementation team?

They provide support and knowledge about the tool. So if we are not able to use a particular function, we ask the central team.

What's my experience with pricing, setup cost, and licensing?

I'm not involved in the financial or licensing aspect of the solution. 

What other advice do I have?

We use Klocwork in two different configurations, on-prem and cloud. Basically we can summarize on-premises. We connect the client directly to the server on-premises remotely. But for certain products and features, we also use a local server that is on-premise but with different configurations. In this case, the server is deployed with some rule set and configured in a certain manner locally with the second option of redirecting the connection directly to our headquarter.

I would recommend the latest version. In the roadmap of the product, a lot of improvements have been made. We are currently on hold with moving over to this tool because of the license but once we're able to, we'll import our profiles from the previous version to the new one.

The previous version was not compatible with the .NET framework. 4.7.2 it didn't fully consider the retargeting option of C++

I would rate Klocwork seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Software Solutions Engineer at Meteonic Innovation Pvt. Ltd.
User
Jul 9, 2019
It has saved a lot of time in developing a code through on the fly analysis mode
Pros and Cons
  • "Klocwork has reduced the manual analysis for a lot of scenarios like checking for internal standards and has saved a lot of time in developing code through the on the fly analysis mode."

    What is our primary use case?

    Our main test case is to check for some of our internal standards which we usually do manually. But when we got Klocwork, it completely changed the scenario. We are writing a simple logic for checking our internal standards without much overhead. 

    One more is on the fly analysis which is the most important feature which Klocwork provides I believe. 

    How has it helped my organization?

    • It has reduced the manual analysis for a lot of scenarios like checking for internal standards.
    • It has saved a lot of time in developing a code through on the fly analysis mode.
    • Klocwork team is regularly updating their checkers which is the good one where we can get more accurate and new kind of issues or bugs in our code can be identified.

    What is most valuable?

    First will be the on the fly analysis as it is reducing the time for developing a code. One more best thing is the reports section which is very nice to understand. Also the support which is available for Industry Standards as well as we can also write our own internal standards and we can check during the analysis.

    What needs improvement?

    Not much as of now. But I am feeling Klocwork should support more number of languages like other static code analyzers do. Right now Klocwork has supportability available only to C, C++, Java, and C#. 

    For how long have I used the solution?

    Still implementing.

    How are customer service and technical support?

    Very good.

    Which solution did I use previously and why did I switch?

    I evaluated some other tools, but I don't want to reveal the names of these tools. I didn't find them as good tools when compared with Klocwork. 

    How was the initial setup?

    It has a straightforward setup from my scenario. Just installing a few .exe files. Not much complexity is involved in this.

    What about the implementation team?

    Vendor team. Very good, and they are friendly.

    What's my experience with pricing, setup cost, and licensing?

    I don't know much about cost and licensing as my management is looking at these things.

    Which other solutions did I evaluate?

    I evaluated some other tools, but I don't want to reveal the names of these tools. I didn't find them as good tools when compared with Klocwork.

    What other advice do I have?

    Not much as of now.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Specialist at a non-tech company with 5,001-10,000 employees
    Real User
    Jun 16, 2019
    Good stability and tech support and the setup is straightforward
    Pros and Cons
    • "Klocwork is a good product, but keep in mind that before building the code you have to get a report."
    • "Now the only issue we have is that whenever we need to get the code we have to build it first. Then we can get the report."

    What is our primary use case?

    We currently use Klocwork mainly for static code analysis.

    What needs improvement?

    Now the only issue we have is that whenever we need to get the code we have to build it first. Then we can get the report. Without building the source code we have to get the static code and the source code. That's what we are looking into. It would be better if they could provide a solution for this issue, regarding code building, when compiling the report.

    I would like to see a dashboard added to provide a clear look and feel. The dashboard would then supplement the users to enable them to get a quick view of the content, as long is it is clear. A presentational dashboard would be good.

    For how long have I used the solution?

    We've been using Klocwork for two years.

    What do I think about the stability of the solution?

    The stability is good. We can run it on multiple machines without an issue.

    What do I think about the scalability of the solution?

    We have a server license here for two servers and ten users.

    How are customer service and technical support?

    The technical support is good. They support us whenever we need it.

    How was the initial setup?

    The initial setup was straightforward, not too complicated.

    What other advice do I have?

    Klocwork is a good product, but keep in mind that before building the code you have to get a report. Then you use the code. If you don't need to get a report after building the source code then this is a good solution for you. I prefer this tool.

    I would rate Klocwork as eight out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    PeerSpot user
    Sr. Software Solution Engineer at Meteonic Innovation Pvt Ltd at Meteonic Innovation Pvt. Ltd.
    Real User
    Jan 9, 2019
    We were able to produce the non-defective code at the developer's desktop
    Pros and Cons
    • "Unlike other static code analysis tools, Klocwork integrates seamlessly into desktop IDEs, build systems, continuous integration tools, and any team's natural workflow."

      What is our primary use case?

      our primary use case was to find and fix all possible static vulnerabilities like Buffer over flow, null pointer check, array out of bounds, concurrency violations, etc.., We work on Linux platform with gcc compiler. 

      How has it helped my organization?

      It has helped our organization to produce the non-defective code right at the developer's desktop. So we were able to deliver releases on time.

      What is most valuable?

      The pre-checkin code review, industry standard checks, continuous integration (CI) and customized checkers are the most valuable features.

      What needs improvement?

      It would be nice to consider having more language support ability. Currently Klocwork supports C/C++, Java and C#, (Android*)

      For how long have I used the solution?

      More than five years.

      What do I think about the stability of the solution?

      Klocwork is very stable. i have seen Klocwork running on 40 million lines of code without any problem. 

      What do I think about the scalability of the solution?

      Klocwork has almost all the features what an advanced Static code analyser should have. 

      How are customer service and technical support?

      Customer Service:

      Customer service is great. We are getting responses from support within a day. The local support (I am from India) is also good.

      Technical Support:

      Technical support from Klocwork is great. The Klocwork documentations are available online so we hardly contact the Klocwork support.

      Which solution did I use previously and why did I switch?

      We were using three Open Source static analyzers and faced lots of false-positives and false-negatives. Klocwork has given us better results with real issues.

      How was the initial setup?

      Setup was straightforward with the installation shields (a single .exe for Windows and .sh file for Linux).

      What about the implementation team?

      For the very first time, the vendor team had helped us in the deployment. Their support was great. From the second time onwards, our internal team was able to upgrade and install with the help of online documentations.

      What was our ROI?

      We got what we have expected. Klocwork worth the price. 

      What's my experience with pricing, setup cost, and licensing?

      The Klocwork tool is worth the price that they have quoted.

      Which other solutions did I evaluate?

      we have evaluated multiple open source tools and few commercial tools.

      What other advice do I have?

      Unlike other static code analysis tools, Klocwork integrates seamlessly into desktop IDEs, build systems, continuous integration tools, and any team's natural workflow. Mirroring how code is developed at any stage, Klocwork prevents defects and finds vulnerabilities on-the-fly, as code is being written.

      Klocwork also helps prioritize work with SmartRank, the revolutionary new recommendation engine that prioritizes issues and helps select which ones to work on first.

      Take prioritized, corrective action immediately to deliver more secure and reliable code.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      PeerSpot user
      .Net Developer at Sure Shield Infotech
      Real User
      Jan 2, 2019
      The on-the-fly analysis reduces the time for developing code and report generation
      Pros and Cons
      • "First will be the on-the-fly analysis as it is reducing the time for developing code and report generation."
      • "Support for AUTOSAR C++14 by adding a new taxonomy that you can use to ensure compliance with the AUTOSAR C++14 Standard, release 18-03."

      What is our primary use case?

      Our main test case is to check for some of our internal standards which we usually do manually. But when we got Klocwork, it completely changed the scenario. We are writing a simple logic for checking our internal standards without much overhead.

      How has it helped my organization?

      One more is on-the-fly analysis which is the most important feature, and CI which Klocwork provides I believe.

      What is most valuable?

      • First will be the on-the-fly analysis as it is reducing the time for developing code and report generation.
      • One more best thing is the reports section which is very nice to understand.

      What needs improvement?

      Support for AUTOSAR C++14 by adding a new taxonomy that you can use to ensure compliance with the AUTOSAR C++14 Standard, release 18-03.

      For how long have I used the solution?

      Three to five years.

      What's my experience with pricing, setup cost, and licensing?

      I don't know much about cost and licensing as my management is looking at these things.

      Which other solutions did I evaluate?

      No.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Prasad D - PeerSpot reviewer
      Senior H.R - DevOps & Infrastructure Recruitment Consultant at Meteonic Innovation Pvt. Ltd.
      Real User
      Dec 30, 2018
      Support to a vast number of IDEs and so on
      Pros and Cons
      • "Using Klocwork, we have cleared all these issues without much difficulty."

        What is our primary use case?

        My primary case would be checking for memory related issues and some null pointer issues where Klocwork is too strong in this section. We used to check these issues most often, and Klocwork is the one which provides us this clear way.

        How has it helped my organization?

        We are very concerned about these issues for some of the critical projects which are very important for us. Using Klocwork, we have cleared all these issues without much difficulty.

        What is most valuable?

        • Its vast checkers supportability
        • Custom checker creation
        • Industry standards supportability
        • Support to a vast number of IDEs and so on.

        What needs improvement?

        Nothing much as of now. I feel Klocwork is going in a great way. The one thing I personally feel is that Klocwork must increase their support to some other languages.

        For how long have I used the solution?

        One to three years.
        Disclosure: My company does not have a business relationship with this vendor other than being a customer.
        PeerSpot user
        Buyer's Guide
        Download our free Klocwork Report and get advice and tips from experienced pros sharing their opinions.
        Updated: June 2026
        Buyer's Guide
        Download our free Klocwork Report and get advice and tips from experienced pros sharing their opinions.