Try our new research platform with insights from 80,000+ expert users
SonarQube Cloud (formerly SonarCloud) Logo

SonarQube Cloud (formerly SonarCloud) pros and cons

Vendor: Sonar
4.1 out of 5

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

SonarQube Cloud (formerly SonarCloud) provides excellent reports for discovering vulnerabilities, security weak points, and security hotspots.
SonarQube Cloud allows the elimination of security issues at the developer level, preventing problems from reaching production.
The tool is praised for its overall performance and ability to perform continuous code analysis, improving code quality with immediate reporting of vulnerabilities.
SonarQube Cloud offers a unified dashboard view of code quality metrics, including code duplication, unit test coverage, and security hotspots.
It has recently introduced support for mono reports and microservices, enhancing its capability to provide detailed views of each service.

CONS

SonarQube Cloud (formerly SonarCloud) lacks comprehensive testing within containers and experiences issues with the scanner.
False positives are frequent, requiring manual adjustments, and its gates sometimes malfunction.
The solution could benefit from better integration within CI/CD pipelines, as overall integration is missing.
Reports need to offer more information and customization capabilities for operational use.
Vulnerability detection and dynamic code analysis need improvement compared to Veracode.
 

SonarQube Cloud (formerly SonarCloud) Pros review quotes

reviewer1992327 - PeerSpot reviewer
Dec 11, 2023
SonarCloud is overall a good tool for identifying code smells, bugs, and code duplication, but we've found that using Android Lint is more effective for our needs.
Huzaifa Asif - PeerSpot reviewer
Dec 12, 2023
Recently, they introduced support for mono reports and microservices, which is a noteworthy development as it provides a more detailed view of each service.
reviewer1871532 - PeerSpot reviewer
May 29, 2022
I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is.
Learn what your peers think about SonarQube Cloud (formerly SonarCloud). Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,295 professionals have used our research since 2012.
SenthuranPooranananthan - PeerSpot reviewer
Apr 25, 2022
The most valuable features of SonarCloud are the ability to discover vulnerabilities, security weak points, security hotspots, and all the feedback that comes into the feature branch. You can deploy the code with the security, you can eliminate the problem at the developer level rather than identifying the problem in the productions.
Diego Moreo - PeerSpot reviewer
Oct 7, 2024
The SaaS solution for checking code without execution and dealing with security issues is valuable.
Archana Verma - PeerSpot reviewer
Feb 24, 2025
I find SonarQube Cloud to be very user-friendly with an easy-to-use interface.
reviewer933816 - PeerSpot reviewer
Apr 18, 2025
The most valuable features of SonarQube Cloud (formerly SonarCloud) include code inspection, addressing technical debt, and identifying security vulnerabilities.
HT
Jun 24, 2021
For what it is meant to do, it works pretty well.
RG
Apr 9, 2025
It is the best product we use for easy integration into YAML pipelines for scanning.
reviewer2356089 - PeerSpot reviewer
Feb 18, 2025
I find SonarQube Cloud very easy to use and simple to integrate initially.
 

SonarQube Cloud (formerly SonarCloud) Cons review quotes

reviewer1992327 - PeerSpot reviewer
Dec 11, 2023
The documentation needs improvement on optimizing build time for seamless CI/CD integration with our Android apps.
Huzaifa Asif - PeerSpot reviewer
Dec 12, 2023
There's room for improvement in the configuration process, particularly during the initial setup phase.
reviewer1871532 - PeerSpot reviewer
May 29, 2022
CI/CD pipeline is part of a whole chain of design, development, and production, and it's becoming increasingly crucial to optimize the various tools across different stages. However, it's still a silo approach because the full integration is missing. This isn't just an issue with SonarCloud. It's a general problem with tooling.
Learn what your peers think about SonarQube Cloud (formerly SonarCloud). Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,295 professionals have used our research since 2012.
SenthuranPooranananthan - PeerSpot reviewer
Apr 25, 2022
SonarCloud can improve the false positives. Sometimes the gates sometimes act a little weird. We then need to manually go and mark the false positive.
Diego Moreo - PeerSpot reviewer
Oct 7, 2024
Reporting features are missing in SonarCloud.
Archana Verma - PeerSpot reviewer
Feb 24, 2025
The UI can be improved.
reviewer933816 - PeerSpot reviewer
Apr 18, 2025
SonarQube Cloud needs improvements in dynamic code analysis. Static code analysis is good, but the product lacks dynamic code scanning capabilities, an area where Veracode excels.
HT
Jun 24, 2021
I've been told by the developers that the solution is too limited. It's not testing enough within the containers.
RG
Apr 9, 2025
I need a solution that can bring together three key areas: vulnerabilities, static scanning, and misarchitecture. Currently, to achieve our expectations, we have to use more than one product, as some products excel at scanning for vulnerabilities but are poor at checking code quality.
reviewer2356089 - PeerSpot reviewer
Feb 18, 2025
SonarQube Cloud could improve its vulnerability detection compared to Veracode.