We currently use Klocwork mainly for static code analysis.
Specialist at a non-tech company with 5,001-10,000 employees
Good stability and tech support and the setup is straightforward
Pros and Cons
- "Now the only issue we have is that whenever we need to get the code we have to build it first. Then we can get the report."
What is our primary use case?
What needs improvement?
Now the only issue we have is that whenever we need to get the code we have to build it first. Then we can get the report. Without building the source code we have to get the static code and the source code. That's what we are looking into. It would be better if they could provide a solution for this issue, regarding code building, when compiling the report.
I would like to see a dashboard added to provide a clear look and feel. The dashboard would then supplement the users to enable them to get a quick view of the content, as long is it is clear. A presentational dashboard would be good.
For how long have I used the solution?
We've been using Klocwork for two years.
What do I think about the stability of the solution?
The stability is good. We can run it on multiple machines without an issue.
Buyer's Guide
Klocwork
July 2025

Learn what your peers think about Klocwork. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
861,524 professionals have used our research since 2012.
What do I think about the scalability of the solution?
We have a server license here for two servers and ten users.
How are customer service and support?
The technical support is good. They support us whenever we need it.
How was the initial setup?
The initial setup was straightforward, not too complicated.
What other advice do I have?
Klocwork is a good product, but keep in mind that before building the code you have to get a report. Then you use the code. If you don't need to get a report after building the source code then this is a good solution for you. I prefer this tool.
I would rate Klocwork as eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Sr. Software Solution Engineer at Meteonic Innovation Pvt Ltd at Meteonic Innovation Pvt. Ltd.
We were able to produce the non-defective code at the developer's desktop
What is our primary use case?
our primary use case was to find and fix all possible static vulnerabilities like Buffer over flow, null pointer check, array out of bounds, concurrency violations, etc.., We work on Linux platform with gcc compiler.
How has it helped my organization?
It has helped our organization to produce the non-defective code right at the developer's desktop. So we were able to deliver releases on time.
What is most valuable?
The pre-checkin code review, industry standard checks, continuous integration (CI) and customized checkers are the most valuable features.
What needs improvement?
It would be nice to consider having more language support ability. Currently Klocwork supports C/C++, Java and C#, (Android*)
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
Klocwork is very stable. i have seen Klocwork running on 40 million lines of code without any problem.
What do I think about the scalability of the solution?
Klocwork has almost all the features what an advanced Static code analyser should have.
How are customer service and technical support?
Customer Service:
Customer service is great. We are getting responses from support within a day. The local support (I am from India) is also good.
Technical Support:
Technical support from Klocwork is great. The Klocwork documentations are available online so we hardly contact the Klocwork support.
Which solution did I use previously and why did I switch?
We were using three Open Source static analyzers and faced lots of false-positives and false-negatives. Klocwork has given us better results with real issues.
How was the initial setup?
Setup was straightforward with the installation shields (a single .exe for Windows and .sh file for Linux).
What about the implementation team?
For the very first time, the vendor team had helped us in the deployment. Their support was great. From the second time onwards, our internal team was able to upgrade and install with the help of online documentations.
What was our ROI?
We got what we have expected. Klocwork worth the price.
What's my experience with pricing, setup cost, and licensing?
The Klocwork tool is worth the price that they have quoted.
Which other solutions did I evaluate?
we have evaluated multiple open source tools and few commercial tools.
What other advice do I have?
Unlike other static code analysis tools, Klocwork integrates seamlessly into desktop IDEs, build systems, continuous integration tools, and any team's natural workflow. Mirroring how code is developed at any stage, Klocwork prevents defects and finds vulnerabilities on-the-fly, as code is being written.
Klocwork also helps prioritize work with SmartRank, the revolutionary new recommendation engine that prioritizes issues and helps select which ones to work on first.
Take prioritized, corrective action immediately to deliver more secure and reliable code.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Klocwork
July 2025

Learn what your peers think about Klocwork. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
861,524 professionals have used our research since 2012.
.Net Developer at Sure Shield Infotech
The on-the-fly analysis reduces the time for developing code and report generation
What is our primary use case?
Our main test case is to check for some of our internal standards which we usually do manually. But when we got Klocwork, it completely changed the scenario. We are writing a simple logic for checking our internal standards without much overhead.
How has it helped my organization?
One more is on-the-fly analysis which is the most important feature, and CI which Klocwork provides I believe.
What is most valuable?
- First will be the on-the-fly analysis as it is reducing the time for developing code and report generation.
- One more best thing is the reports section which is very nice to understand.
What needs improvement?
Support for AUTOSAR C++14 by adding a new taxonomy that you can use to ensure compliance with the AUTOSAR C++14 Standard, release 18-03.
For how long have I used the solution?
Three to five years.
What's my experience with pricing, setup cost, and licensing?
I don't know much about cost and licensing as my management is looking at these things.
Which other solutions did I evaluate?
No.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior H.R - DevOps & Infrastructure Recruitment Consultant at Meteonic Innovation Pvt. Ltd.
Support to a vast number of IDEs and so on
What is our primary use case?
My primary case would be checking for memory related issues and some null pointer issues where Klocwork is too strong in this section. We used to check these issues most often, and Klocwork is the one which provides us this clear way.
How has it helped my organization?
We are very concerned about these issues for some of the critical projects which are very important for us. Using Klocwork, we have cleared all these issues without much difficulty.
What is most valuable?
- Its vast checkers supportability
- Custom checker creation
- Industry standards supportability
- Support to a vast number of IDEs and so on.
What needs improvement?
Nothing much as of now. I feel Klocwork is going in a great way. The one thing I personally feel is that Klocwork must increase their support to some other languages.
For how long have I used the solution?
One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Its strong Capability in On the fly analysis
Pros and Cons
- "The ability to create custom checkers is a plus."
- "I hope that in each new release they add new features relating to the addition of checkers, improving their analysis engines etc."
What is our primary use case?
Our primary use case is to check our Internal Standards which is always a burden because it involves lot of manual checking. We are using Klocwork for this by writing some algorithms and implementing it in Klocwork. Klocwork is very strong in this section.
How has it helped my organization?
As said earlier checking our industry standards is main burden which involves lot of manual work. Now Klocwork has completely removed this and we are very easily checking our internal standards.
What is most valuable?
The ability to create custom checkers, which is an important part of most of the projects. Its on the fly capability is very good.
What needs improvement?
Nothing as of now. I hope that in each new release they add new features relating to the addition of checkers, improving their analysis engines etc. In the near future I will discuss additional features that need to be added.
For how long have I used the solution?
Still implementing.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and technical support?
Technical Support is very good. They took only hours to resolve most of my issues.
Which solution did I use previously and why did I switch?
I didn't use any tools other than Klocwork.
How was the initial setup?
Initial setup is straightforward. There is no complexity in the initial setup.
What about the implementation team?
I have implemented it with the help of a vendor team. They are really very good with Klocwork.
What's my experience with pricing, setup cost, and licensing?
It is worth it for the price that the vendor quoted.
Which other solutions did I evaluate?
I evaluated two other tools, which were not matched with Klocwork at any point. I don't want to reveal the names of the tools.
What other advice do I have?
Support for more languages would be helpful since this is my trustworthy tool. One more advice from my side would be to do some webinars on Klocwork will be helpful for some new users.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Embedded Software Developer at a tech services company with 10,001+ employees
The tool has good support for static analysis
Pros and Cons
- "The tool helps the team to think beforehand about corner cases or potential bugs that might arise in real-time."
- "We like using the static analysis and code refactoring, which are very valuable because of our requirements to meet safety critical levels and reliability."
- "The way to define the rules is too complex. The definition/rules for static analysis could be automated according to various SILs, so as to avoid confusion."
What is our primary use case?
We are using Klocwork to perform static code analysis of our solutions towards an embedded project. The project is built on an RTOS, and the relevant middleware and applications are developed in C++.
How has it helped my organization?
The tool helps the team to think beforehand about corner cases or potential bugs that might arise in real-time. This, in turn, increases the efficiency of the project as well as the team.
What is most valuable?
We like using the static analysis and code refactoring, which are very valuable because of our requirements to meet safety critical levels and reliability.
What needs improvement?
The way to define the rules is too complex. The definition/rules for static analysis could be automated according to various SILs, so as to avoid confusion.
It should be semi-flexible. However, this may be due to my limited experience.
For how long have I used the solution?
Less than one year.
How is customer service and technical support?
The tool has good support for static analysis.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Software Engineer at a manufacturing company
One of the best tools available for static analysis. There are some false warnings issued.
What is most valuable?
It is one of the best tools available for static analysis.
How has it helped my organization?
This tool was already rolled out in our projects at Delphi Technical Center in Bangalore, India. Though we had a QAC tool for MISRA checks, Klocwork was preferred for complete code base static analysis before projects go to production.
For all GM projects, this tool is used to perform static analysis. It provides a nice report, so all manual efforts in analyzing the code base are completely removed.
What needs improvement?
There are some false warnings found which eventually are not considered for a fix after the team reviewed the source code.
For how long have I used the solution?
We have been using the system for around three years.
What do I think about the stability of the solution?
It is quite stable, reliable and has not shown any difference in the results for multiple runs.
What do I think about the scalability of the solution?
We have not tried to scale yet, but it was sufficient for our current projects.
How are customer service and technical support?
We have not encountered any problems at my level. I have no idea how the technical support is.
Which solution did I use previously and why did I switch?
We were using QAC and Klocwork at my previous company. At my current organization, we use Polyspace.
How was the initial setup?
The setup was in place when I arrived.
What's my experience with pricing, setup cost, and licensing?
I have no idea about pricing.
Which other solutions did I evaluate?
I was not involved in the tool evaluation process.
What other advice do I have?
I recommend this tool as one of the best to be used for static analysis and should at least be tried.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Embedded Software Engineer at a engineering company with 10,001+ employees
It provides a good set of checks for static code analysis and cybersecurity. While coding, developers see code violations. Global variables sometimes generate false positives.
What is most valuable?
- Good set of checkers for static code analysis, cyber security
- Possibility of creating custom checkers- Good and easy integration into continuous integration (CI)
- The whole package offers a lot of possibilities: add-ons for Eclipse, standalone clients, access via web site, support, documentation, command line.
How has it helped my organization?
More and more departments are targeting static code analysis now, as they see the benefits. Klocwork with its capabilities is helping with this, providing the integration. The advantage is that while coding, developers see code violations.
What needs improvement?
- Global variables sometimes generate false positives. Variables with global scopes sometimes produce False Positives. It means, I get violations from KW which after personal analysis turn out to be not true. At the moment it seems Klocwork is not able to track the values of variables with global scope. Thus the tool makes assumptions for the value range. It occurs that I get violations due to values which simply cannot occur > as the global variables are not tracked. This is annoying and time consuming. One simpler thing on variables with global scope: unused variables with global scope cannot be detected by checkers. This is highly recommended to have it in order to clean the code.
- The preprocessor needs better integration for custom checkers as the tool focuses more on static code analysis; after preprocessing the file.- Updating from one version to the other takes too much time. The process somehow needs too much CPU power.
- Once there are bugs detected and accepted by KW, it takes some time to integrate the changes. This means that what does not fit on the Rogue Wave road map is not definitely considered.
For how long have I used the solution?
I have used it for four years.
What do I think about the stability of the solution?
I did not encounter any stability issues; only that the update process takes too long. Here, the process could be speeded up.
What do I think about the scalability of the solution?
Scalability is good, from small teams to multisite project teams.
How are customer service and technical support?
Technical support is good (7/10).
Which solution did I use previously and why did I switch?
I previously used PC-lint. I switched because KW is more mature.
How was the initial setup?
Initial setup is going well; very straightforward and following its documentation.
Which other solutions did I evaluate?
I evaluated QAC/QAC++, LDRA Testbed.
What other advice do I have?
A good thing is that you are rapidly ramped up and can use the tool.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Klocwork Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Static Code AnalysisPopular Comparisons
SonarQube Server (formerly SonarQube)
GitLab
Snyk
Checkmarx One
Veracode
Coverity
Mend.io
OpenText Core Application Security
SonarQube Cloud (formerly SonarCloud)
OpenText Static Application Security Testing
HCL AppScan
PortSwigger Burp Suite Professional
Semgrep
CodeSonar
Polyspace Code Prover
Buyer's Guide
Download our free Klocwork Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?
- Which application security solutions include both vulnerability scans and quality checks?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- SAST vs. DAST: Which is better for application security testing?