No more typing reviews! Try our Samantha, our new voice AI agent.
Chief Solutions Officer at CleverIT B.V.
Reseller
Jan 10, 2021
Easy to deploy and applicable for various uses
Pros and Cons
  • "I do recommend SonarQube because it is an easy tool that you can deploy and configure, and after that you can measure the history of your obligation and integrate it with other tools like GitLab or GitHub or Azure DevOps to do quality code analysis."
  • "In terms of what can be improved, the areas that need more attention in the solution are its architecture and development."

What is our primary use case?

I am now working in a consultancy company and I work with different clients in different industries. For this reason I implement, for example, a delivery pipeline with the process whereby we need to validate the quality gate of the quality code. Meaning, the developer creates the unit testing and the code coverage, but grants the code coverage for a specific person. In other cases, we used to see what the technical depth was to see if if there are any bugs in the applications - the web application, mobile application and different languages, like, C-Sharp, JavaScript or Java, et cetera.

We deploy SonarQube on-premise on a Linux server and our pipelines were created with GitLab and Azure DevOps. Meaning that Azure DevOps and GitLab are the tools that do the build and release process.

We use Microsoft Azure and Google Cloud Platform a little.

What is most valuable?

In terms of most valuable feature, when you compute SonarQube you need to install an extension. This extension depends on the version control. You need to install different extensions or work with a specific language to use as the extensions, all of which I work in with different projects.

What needs improvement?

In terms of what can be improved, the areas that need more attention in the solution are its architecture and development.

Additionally, the QA team also needs work in different aspects. When you think about the support area - when the support team has an incident they need to do a hostage. When they do that they do a commit in the version control. These commits trigger a new build process and this process needs validation from SonarQube because we need to validate the quality of the software product for different cases and different aspects.

For how long have I used the solution?

I have been using SonarQube for about four years, with different versions.

Buyer's Guide
SonarQube
July 2026
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,834 professionals have used our research since 2012.

What do I think about the stability of the solution?

SonarQube works very well, but I prefer SonarCloud because the tendency of the technology world is to think less about the structure and more about the process and the value that this process provides.

What do I think about the scalability of the solution?

In terms of scalability, with proper configuration and deployment, there is higher availability.

I have companies with 20 users and I have customers with 100 users. We work with a big company in Chile and in some cases national companies, in other cases international companies. With the international companies the majority of them are more than 1,000 users.

I have a technical DevOps team. The majority of the time we implement the trial version so that we show the value of the tool to our clients and they understand about the pricing and the cost of the tool.

It depends on the maturity of the company. In some case, we have companies that don't know about SonarQube so we deploy it to show the value. In other cases we have clients with no SonarQube experience but they know the quality of the codes. In this case we provide a license. In the majority of the cases we provide the license or the subscription for SonarCloud. Other clients get access to SonarQube directly.

How are customer service and support?

I have never used technical support from the SonarQube support team.

I work very well with the documentation you find on the internet.

How was the initial setup?

The initial setup is straightforward the majority of time. It takes about two hours.

What about the implementation team?

I work in a consultancy company so we do the implementation. We deploy for our customers.

Which other solutions did I evaluate?

We did evaluate other options, for example Q1 and Veracode. In specific cases we created different aspects with different tools and these were the top peers that we would compare it to - Q1 and Veracode.

In terms of differences, Veracode is used more for the security of the development and you can configure the gates while thinking about software security and things like that. With Q1, the difference is the type of the license. In Q1 you have projects and you pay for the line. I know that SonarQube was changing the licensing plan. Right now, before you pay for a license, you pay for fair lines that you extend. This is the difference between these three tools.

What other advice do I have?

I do recommend SonarQube because it is an easy tool that you can deploy and configure. After that you can measure the history of your obligation and integrate it with other tools like GitLab or GitHub or Azure DevOps to do quality code analysis.

On a scale of one to ten, I would give SonarQube an eight. To give it a 10 and not an eight, I would like to see architecture development and the QA area improved.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
reviewer1108275 - PeerSpot reviewer
Security at a tech services company with 51-200 employees
Real User
Jan 7, 2021
Secures our code against threats and bugs, but needs better pipeline integration
Pros and Cons
  • "Apart from the security point of view, I like that it makes it easy to detect code smells and other issues in terms of code quality and standards."
  • "SonarQube lets us find security issues during development and testing so that we can release more secure and higher quality applications."
  • "From a reporting perspective, we sometimes have problems interpreting the vulnerability scan reports. For example, if it finds a possible threat, our analysts have to manually check the provided reports, and sometimes we have issues getting all the data needed to properly verify if it's accurate or not."
  • "From a reporting perspective, we sometimes have problems interpreting the vulnerability scan reports."

What is our primary use case?

We use SonarQube to help with our software development and testing. At the moment, we're mainly using it for static analysis and code inspection. We have an on-premises server and we connect to it from there.

Our main use case is testing software for security weaknesses, but we also use it to help eliminate code smells and to make sure our code is compliant with established coding standards.

How has it helped my organization?

SonarQube lets us find security issues during development and testing so that we can release more secure and higher quality applications.

What is most valuable?

Apart from the security point of view, I like that it makes it easy to detect code smells and other issues in terms of code quality and standards.

What needs improvement?

From a reporting perspective, we sometimes have problems interpreting the vulnerability scan reports. For example, if it finds a possible threat, our analysts have to manually check the provided reports, and sometimes we have issues getting all the data needed to properly verify if it's accurate or not.

This is especially important when considering false positives, and often we have issues getting all the necessary information from SonarQube in order to determine whether it is a true vulnerability or a false positive.

Another suggestion for improvement is that SonarQube could be better when it comes to integration with different development pipelines for continuous monitoring. For example, whether you are scanning manually or on-demand, we would like more ways to integrate SonarQube into our pipeline so that we can get reports quickly and automatically as we work.

For how long have I used the solution?

I have been using SonarQube for about two years now.

What do I think about the stability of the solution?

I have not run into major issues or bugs and it works well when it comes to stability.

What do I think about the scalability of the solution?

I don't think we have had any problem with traffic or things like that. 

How are customer service and technical support?

I don't have experience with SonarQube support because we do it all ourselves. 

Which solution did I use previously and why did I switch?

I have not used any other similar solutions in the past. SonarQube is the first of its kind in my experience.

How was the initial setup?

It's quite easy to set up, not too complex.

What's my experience with pricing, setup cost, and licensing?

The development license cost is reasonable, and we've had no concerns about SonarQube when it comes to cost.

What other advice do I have?

Personally, I can't compare it to other similar solutions like Fortify, but SonarQube does a good job when it comes to making sure our code is compliant with standards and free of any obvious security weaknesses. 

I would rate SonarQube a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
SonarQube
July 2026
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,834 professionals have used our research since 2012.
reviewer1073967 - PeerSpot reviewer
Project Manager, Senior Architect at a computer software company with 1,001-5,000 employees
Real User
Dec 31, 2020
Well featured, easily manageable, identifies production issues
Pros and Cons
  • "It is a good deal compared to all other tools on the market."
  • "I would recommend SonarQube; it is a good deal compared to all other tools on the market and certainly helped us, it is a good tool and should be definitely used."

    What is our primary use case?

    We decided to implement the solution to keep up to date with testing, security, and other issues with developments, such as bugs.

    What is most valuable?

    In regards to features, overall the product is good. It minimizes the difficulty or issues that we encountered during the production. We are using the open-sourced version and issues can easily be resolved.

    For how long have I used the solution?

    I have been using the solution for four to five years.

    What do I think about the stability of the solution?

    We are using everything that is open-source and this allows us when we have the regular day to day issues, our team works on them directly to identifying their causes and they resolve them quickly.

    What about the implementation team?

    We have our internal team that is very knowledgeable, experienced, and have extreme abilities that handle our needs.

    What's my experience with pricing, setup cost, and licensing?

    I think comparing the product to competitors it should be less expensive.

    What other advice do I have?

    I would recommend SonarQube. It is a good deal compared to all other tools on the market.  It certainly helped us, it is a good tool and should be definitely used.

    I rate SonarQube a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Senior System Analyst at a tech services company with 1,001-5,000 employees
    Real User
    Dec 12, 2020
    User-friendly, easy to access, and it has good training documentation
    Pros and Cons
    • "The most valuable features are that it is user-friendly, easy to access, and they provide good training files."
    • "Monitoring is a feature that can be improved in the next version."
    • "It's a bit expensive for us. The currency rate of the dollar is a problem but it may be fine for other countries."

    What is our primary use case?

    We are using this solution for analyzing sales, profit, and FI documents. We are using the HR section as well.

    How has it helped my organization?

    SonarQube simplified some of the processes and made others more complex.

    What is most valuable?

    The most valuable features are that it is user-friendly, easy to access, and they provide good training files. Ability to manage and customize reports. Sonar also models the relationship between packages and classes

    What needs improvement?

    It would be better if the users could have quick access to the features.

    Monitoring is a feature that can be improved in the next version.

    For how long have I used the solution?

    I have been using SonarQube for three years.

    What do I think about the stability of the solution?

    This solution is stable. Stability is not an issue for us.

    What do I think about the scalability of the solution?

    It's scalable. Scaling is not a problem.

    How are customer service and technical support?

    Because of the sanctions in our country, we cannot contact technical support directly.

    Which solution did I use previously and why did I switch?


    How was the initial setup?

    The initial setup was straightforward. It was a normal installation.

    It took approximately five days to deploy.

    What's my experience with pricing, setup cost, and licensing?

    It's a bit expensive for us. The currency rate of the dollar is a problem but it may be fine for other countries.

    This solution provides good features for users.

    What other advice do I have?

    Before implementing, they should have more knowledge about the performance, and the features. It will be helpful in learning the hardware also.

    If you have good resources for the performance, you won't worry about it. It will also be dependent on your information, and how much knowledge you have.

    I would rate SonarQube an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Backend Architect at Sngular
    Real User
    Dec 11, 2020
    It has very good scalability and stability
    Pros and Cons
    • "It has very good scalability and stability."
    • "We usually do the development in Java, and when we finish the development, we usually run the SonarQube tests and review the critical level, bugs, and security issues."
    • "We also use Fortify, which is another tool to find security errors. Fortify is a better security tool. It is better than SonarQube in finding errors. Sometimes, SonarQube doesn't find some of the errors that Fortify is able to find. Fortify also has a community, which SonarQube doesn't have. Its installation is a little bit complex. We need to install a database, install the product, and specify the version of the database and the product. They can simplify the installation and make it easier. We use docker for the installation because it is easier to use. Its dashboard needs to be improved. It is not intuitive. It is hard to understand the interface, and it can be improved to provide a better user experience."
    • "Fortify is a better security tool; it is better than SonarQube in finding errors, and sometimes SonarQube doesn't find some of the errors that Fortify is able to find."

    What is our primary use case?

    We usually do the development in Java, and when we finish the development, we usually run the SonarQube tests and review the critical level, bugs, and security issues. We also review the license and the web issues and try to solve them, and then pass again through SonarQube.

    We usually deploy it in the cloud, but sometimes we also have on-premises solutions.

    What is most valuable?

    It has very good scalability and stability.

    What needs improvement?

    We also use Fortify, which is another tool to find security errors. Fortify is a better security tool. It is better than SonarQube in finding errors. Sometimes, SonarQube doesn't find some of the errors that Fortify is able to find. Fortify also has a community, which SonarQube doesn't have.

    Its installation is a little bit complex. We need to install a database, install the product, and specify the version of the database and the product. They can simplify the installation and make it easier. We use docker for the installation because it is easier to use.

    Its dashboard needs to be improved. It is not intuitive. It is hard to understand the interface, and it can be improved to provide a better user experience.

    For how long have I used the solution?

    I have been using SonarQube for two years.

    What do I think about the stability of the solution?

    Its stability is very good.

    What do I think about the scalability of the solution?

    It has very good scalability. In my company, we have less than 15 users. They are mostly developers.

    How are customer service and technical support?

    I have not used the support.

    Which solution did I use previously and why did I switch?

    I have used Codestyle and a few other tools. SonarQube is similar to other tools.

    How was the initial setup?

    Its installation is a little bit complex. They can simplify the installation and make it easier.

    Which other solutions did I evaluate?

    We didn't evaluate other options. 

    What other advice do I have?

    I would rate SonarQube a nine out of ten.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Senior Manager at Digichorus Technologies
    Real User
    Nov 30, 2020
    Good code review and reporting of basic vulnerabilities in your applications
    Pros and Cons
    • "SonarQube is good in terms of code review and to report on basic vulnerabilities in your applications."
    • "It does not provide deeper scanning of vulnerabilities in an application, on a live session. This is something we are not happy about. Maybe the reason for that is we are running the community edition currently, but other editions may improve on that aspect."

    What is our primary use case?

    We are using it for scanning our web applications, some internal applications and using it for code reviews.

    What is most valuable?

    SonarQube is good in terms of code review and to report on basic vulnerabilities in your applications. The code writing standard of SonarQube is good. It may be better in other editions but as we don't use those we're not able to find out with SonarQube. We are using the community, developer version for 14 days. If this version is successful we will go to the full version. We're using it on-premises.

    What needs improvement?

    It does not provide deeper scanning of vulnerabilities in an application, on a live session. This is something we are not happy about. Maybe the reason for that is we are running the community edition currently, but other editions may improve on that aspect.

    For how long have I used the solution?

    We have been using SonarQube for one year.

    What do I think about the stability of the solution?

    It is stable.

    What do I think about the scalability of the solution?

    SonarQube is scalable.

    How was the initial setup?

    SonarQube was easy to setup.

    Which other solutions did I evaluate?

    We considered using Fortify.

    What other advice do I have?

    I would rate SonarQube an eight out of 10.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Anshuman Kishore - PeerSpot reviewer
    Director Product Development at Mycom Osi
    Real User
    Nov 27, 2020
    Reasonably priced, provides good code coverage and improves quality
    Pros and Cons
    • "The code coverage feature is very good."
    • "If you are looking for full coverage and quality improvement then it is the best product to use."
    • "If the product could assist us with fixing issues by giving us more pointers then it would help to resolve more of the warnings without such a commitment in terms of time."
    • "SonarQube needs some improvement in its ability to find security-related issues."

    What is our primary use case?

    We use SonarQube for determining code coverage, finding bugs, and searching for security-related issues in our development environment.

    What is most valuable?

    The code coverage feature is very good.

    What needs improvement?

    When performing the code coverage function, there are a lot of warnings that come up and you may not have time to solve them. You need to have the ability to overrule warnings or issues because it may not be possible to commit the time to resolve them immediately. If the product could assist us with fixing issues by giving us more pointers then it would help to resolve more of the warnings without such a commitment in terms of time.

    SonarQube needs some improvement in its ability to find security-related issues.

    For how long have I used the solution?

    I have been using SonarQube for the past seven or eight years.

    What do I think about the stability of the solution?

    We have not found any bugs or had trouble with stability. We have had some minor hiccups, here and there, but otherwise, we are fine.

    What do I think about the scalability of the solution?

    We have not found any issues with respect to scalability. 

    How are customer service and technical support?

    I have not personally been in contact with technical support. I believe that our team recently had contact with them when we migrated to the newer version, and we received help from their support agent.

    Which solution did I use previously and why did I switch?

    I have also used Veracode and when comparing the two, I find that Veracode is better at finding security-related issues during the static code analysis. At the same time, during my PoC with Veracode, they did not claim to be able to provide everything that SonarQube does. 

    How was the initial setup?

    I was not involved in the initial setup. However, I do know that it can be set up within one or two days.

    What about the implementation team?

    We have an in-house team for deployment and maintenance.

    What's my experience with pricing, setup cost, and licensing?

    I am satisfied with the pricing.

    What other advice do I have?

    In general, I am very satisfied with SonarQube and I highly recommend it. If you are looking for full coverage and quality improvement then it is the best product to use.

    I would rate this solution a nine out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Information Technology Technical Architect at a insurance company with 51-200 employees
    Real User
    Nov 3, 2020
    Provides continuous inspection of code quality
    Pros and Cons
    • "The product itself has a friendly UI."
    • "The product itself has a friendly UI, it's easy to use and we understand how to manage the admin control panel, it's really quick, and it's really easy to perform admin jobs using the control panel."
    • "We could use some team support, but since we are using the community version, it's not available."

    What is our primary use case?

    I'm a user also, but I'm also responsible for information security.

    I am the principal of security in the office. I'm the one that actually advises people about enhancing or incorporating information security aspects. Right now, we are using a community version. We have yet to subscribe for the enterprise license because we need more disciplined developers first.

    Within our organization, there are roughly 14 people using this solution.

    We use it to find the scoop, or the use, for peer review for the developers. It will require more time, to get used to it and to get trained. My team is very small and I am part of the development team — I'm in the security team but I'm also part of the development team. I am helping to build this along with the team.

    What is most valuable?

    The product itself has a friendly UI. It's easy to use and we understand how to manage the admin control panel, it's really quick. It's really easy to perform admin jobs using the control panel. 

    The tools are really easy to use. With the coding, we can build a bunch of rules that apply for each programming language, for example, CSS, Java, and more. Even with the community version, we can still set up rules. We accommodate them and they give us the best quality. It's been a great experience so far.

    What needs improvement?

    We could use some team support, but since we are using the community version, it's not available.

    Also, because we are using the community version, we have some problems from time to time regarding the SSO logins.

    Sometimes you need more time to configure things, to edit some profiles.

    SonarQube has come to the end of the project phase. The development team doesn't really utilize this because it's in the product development phase. They need more paths and delivery — they don't really care about security. But now, since we are also certified technical security, we can go ahead and provide that for them.

    In short, communication needs to be better.

    Automation could be better. Sometimes by default, you need to configure some rules regarding detection. You need to have some parameters set regarding false-positive risk. 

    For how long have I used the solution?

    We have had SonarQube for over a year, but we have only been using it for the past two months.

    How are customer service and technical support?

    With the use of community version, we already have utilized and carried out our needs to fulfil application security at the earlier stage with small medium SDLC Team.

    How was the initial setup?

    The initial setup was very straightforward. Overall, deployment took roughly one week.

    What other advice do I have?

    There are so many qualitative tools other than SonarQube, but I think it's the only platform that is open-source; however, it doesn't cover you end-to-end — from the static, dynamic, and interactive source.

    Once we're done with SonarQube, we will switch to a proprietary tool, like Qualys — something that provides more end-to-end — but before we can do that, we need more people who know how to properly run the software.

    Overall, I would recommend SonarQube for your initial software quality.

    On a scale from one to ten, I would give this solution a rating of eight.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1422195 - PeerSpot reviewer
    Director IT Security, CISO at a transportation company with 10,001+ employees
    Real User
    Oct 29, 2020
    Cost-effective with good out-of-the-box features
    Pros and Cons
    • "I like the by-default policies that are they, as they seem to cover most of what I need."
    • "This product is leading its class in the open-source community."
    • "The interface could be a little better and should be enhanced."

    What is our primary use case?

    I have used SonarQube for static code analysis. I am using it to assess my internal applications.

    What is most valuable?

    I like the by-default policies that are they, as they seem to cover most of what I need. I see that as an essential feature.

    What needs improvement?

    The interface could be a little better and should be enhanced.

    More support for integration with third-party products would be an improvement.

    For how long have I used the solution?

    I have been using SonarQube for more than five years.

    What do I think about the stability of the solution?

    I have not faced any bugs or glitches in SonarQube.

    How are customer service and technical support?

    I have not been in contact with technical support, although my teams would have definitely reached out.

    How was the initial setup?

    I would not say that the initial setup was complex, although it was not smooth enough. This was a mixed, hybrid set up because every environment has its own applications to deploy. That said, it was not so critical that we were no able to manage it.

    What about the implementation team?

    We have an in-house team in charge of maintenance. I have four people who are on payroll and an augmented staff of three more.

    What's my experience with pricing, setup cost, and licensing?

    SonarQube is an open-source product that can be used free of charge. It is a cost-effective solution.

    Which other solutions did I evaluate?

    You cannot really compare this product to commercial solutions. However, the features that it provides out of the box are very good.

    When it comes to other technologies, such as the Checkmarx of the world, they are better than SonarQube. This is something that they should look at as this project evolves.

    What other advice do I have?

    This product is leading its class in the open-source community. It is absolutely a product that I can recommend. I think that digital organizations that have budget constraints should look at this technology, and then they can evolve it as per their needs.

    In the future, I may look into deploying SonarQube in a hybrid model.

    I would rate this solution an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Senior/Lead Software Engineer at a government with 51-200 employees
    Real User
    Oct 27, 2020
    Stable with good static code analysis but needs better security
    Pros and Cons
    • "The static code analysis of the solution is the most important aspect for us. When it comes to security breaches within the code, we can leverage some rules to allow us to identify the repetition in our code and the possible targets that we may have. It makes it very easy to review our code for security purposes."
    • "When it comes to security, this solution is pretty great."
    • "There are sometimes security breaches in our code, which aren't be caught by SonarQube. In the security area, SonarCube has to improve. It needs to better compete with other products."

    What is most valuable?

    When it comes to security, this solution is pretty great.

    The static code analysis of the solution is the most important aspect for us. When it comes to security breaches within the code, we can leverage some rules to allow us to identify the repetition in our code and the possible targets that we may have. It makes it very easy to review our code for security purposes.

    The solution is quite stable.

    You can scale the solution if you need to.

    What needs improvement?

    In terms of solving for security breaches in the code, we are looking for different tools to help us catch things much sooner. Right now, we're not doing so well on this front.  Therefore, we are looking for some other options in the market. I'm not the one who is tasked with looking at the moment, however, we are actively seeking out a more effective option for the static code analysis. 

    There are sometimes security breaches in our code, which aren't be caught by SonarQube. In the security area, SonarCube has to improve. It needs to better compete with other products.

    The solution could offer some sort of alert feature. We've had an incident, where somebody removed the solution from the pipeline and there were a couple of code instances that were pushed and married with the codebase without passing through SonarQube. It would be nice if we were alerted to that. If the solution is off-line or turned off, we'd like to be able to tell so that we can decide if it should be on or if it was a mistake.

    It would be great if it could support testing and configurations a bit more. 

    For how long have I used the solution?

    We've only been working with the solution for one year. It hasn't been that long.

    What do I think about the stability of the solution?

    The solution is very stable. We don't have any issues with its reliability. It's been quite good so far.

    What do I think about the scalability of the solution?

    The architecture that we have is not that big, however, from the scalability point of view, SonarQube supports scalability quite well.

    At the moment, we have a hybrid working model on the vendor side, as well as on the in-house team. The in-house team has 5 members and the vendor has maybe 20 people, more or less. All in all, we can say we have about 25 people using the solution at any given time.

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution. It was always manual code reviewing via the most experienced team members who would offer guidance on adjustments.

    What's my experience with pricing, setup cost, and licensing?

    Right now, we are not using the enterprise features of the solution. I don't know about the licensing as I was not the one who introduced SonarQube into the pipeline. I believe we are using the free community edition and therefore aren't actually paying any money for it.

    Which other solutions did I evaluate?

    I did an exercise a couple of months ago with my colleague. After this, I listed other products and their security aspects. I don't know if we found a solution that can offer us better features for security. I don't know if we will keep SonarQube in the pipeline or we will sell the product and get another product. I'm not sure at this point.

    What other advice do I have?

    We're just customers. We don't have a business relationship with the company.

    I believe we are using the latest version of the solution, however, I don't know the exact number.

    I would advise others considering the solution to consider the level of security they need. If they are very concerned about security and the application is very sensitive, then SonarQube may not be the best option and they should seek out other products.

    Overall, I would rate the solution seven out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free SonarQube Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Buyer's Guide
    Download our free SonarQube Report and get advice and tips from experienced pros sharing their opinions.