Code exploration on the front-end, as well as the ability to import from Fortify, are valuable features.
Web Developer/DevOps Engineer with 501-1,000 employees
It allows for code exploration on the front-end as well as the ability to import from Fortify.
Pros and Cons
- "It is quality software, even if the plugins are often weaker than would be necessary to have a team centralize around it."
- "The Python code scan has so few rules that it is meaningless."
What is most valuable?
How has it helped my organization?
It allows for better collaboration of our team members on security findings.
What needs improvement?
The Python code scan has so few rules that it is meaningless.
The support for mobile applications is limited to Android Lint importing, although the Android Lint report is fine on it's own so what it he point of using it.
And the Fortify plugin is deprecated.
For how long have I used the solution?
I've used it for two years.
Buyer's Guide
SonarQube
February 2026
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
What was my experience with deployment of the solution?
It is quality software, even if the plugins are often weaker than would be necessary to have a team centralize around it. It is good for an open source project, but creating plugins is important and so complicated and not well documented that it is rarely done.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and support?
It is open source so I don't try to rely on their technical support.
How was the initial setup?
It was fairly straightforward, although some plugins depend on outside software to run, which is to be expected.
What about the implementation team?
We implemented it ourselves.
What's my experience with pricing, setup cost, and licensing?
It is free, so the price is good. If they had stronger plugins then we would gladly pay.
Which other solutions did I evaluate?
We evaluated the market, and because security scans are so different, there was not a good COTS or open source solution that met our needs so we went with the best open source solution, which was SonarQube.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
QA Engineer at a tech services company with 51-200 employees
It helps us to determine the maturity and quality of the coding of our software customers, preventing future crashes in the software.
Pros and Cons
- "This product helps us to determine the maturity and quality of the coding of our software customers, preventing future crashes in the software."
- "The worst about this tool I think is the upgrade method, and it's really easy to wreck the database when upgrading."
What is most valuable?
To create your own quality profiles and gates is really cool; you can apply different policies depending the maturity grade of the project are you dealing with.
Also, we use a lot the time machine tool to take important decisions to determine if the projects are going in the right direction.
Elastic search is really helpful and also there is a plug-in we use a lot named "3D Code Metrics" that gives us a quick overview about the general situation about the projects.
Also, the integration with different CVS', and the dependency search are nice and helpful features.
How has it helped my organization?
This product helps us to determine the maturity and quality of the coding of our software customers, preventing future crashes in the software. We get users used to developing clean code makes SonarQube a valuable tool. Also, we use it for our internal software development helping us to create a good quality software.
What needs improvement?
With the new SonarQube versions, the analysis time is increasing, and some projects are difficult to configure due to the different modules and languages that it uses. A few versions ago, it had a multi-language option which was really helpful.
For how long have I used the solution?
I've used it for over two years.
What was my experience with deployment of the solution?
The worst about this tool I think is the upgrade method, and it's really easy to wreck the database when upgrading. It would be better idea to make less versions, but make it easier and consistent to upgrade. Also, sometimes if you are using really old instances and you move to a new version it's possible to lose some information about projects.
Thanks to this tool we can improve old code were developers are not available anymore and display the projects filtering by different fields, we save a lot of time, and time is money.
What do I think about the stability of the solution?
Once it is up and running, we didn't find any big issues with the stability, but it's important to configure in the right way the properties file according with you system specifications.
How are customer service and technical support?
Customer Service:
I think is good, also there is a new forum named "https://sonarqubehispano.org/display/HOME/Bienvenido" for the spanish community who helps a lot to spanish quality assurance fellas.
Technical Support:I think is good, also there is a new forum, https://sonarqubehispano.org/display/HOME/Bienvenido for the Spanish language community which helps a lot.
Which solution did I use previously and why did I switch?
I used a few specific tools for the PHP language, that tools were really powerful (Codesniffer, PHPCPD, PHP Mess Detector among others) and provide a good information about the quality of our code. Nowadays, I am mixing that tools with SonarQube, but in shortly, I am thinking of using just SonarQube. The reason is that SonarQube is including more and more PHP rules in every PHP plugin version.
How was the initial setup?
After dealing with configuration files and SonarQube is up and running there is not a big problem to start working with it, SonarQube include some standard quality profiles that makes it easier for the beginners. Also, the option to configure your own dashboard with different widgets exists.
What about the implementation team?
I have experience with both of them and the main problem is not how the tool is working, but it's to make people follow the rules and change bad habits. However, I think that's a common challenge for our QA guild.
What's my experience with pricing, setup cost, and licensing?
Actually SonarQube offers a lot of free plug-ins for different languages, and we add additional paid plug-ins as well, such as PL/SQL, COBOL and Views, and our experience tell us that it is worth it.
Which other solutions did I evaluate?
Only one option we found competitive was CAST, but the prices and the functionality didn't convince us at all.
Disclosure: My company has a business relationship with this vendor other than being a customer. We are a SonarQube partner in Spain.
Buyer's Guide
SonarQube
February 2026
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
Software Developer at a tech services company with 501-1,000 employees
It supports over 20 programming languages and allows me to create custom coding rules.
Pros and Cons
- "I have fallen in love with SonarQube when I could've easily built custom rules checks."
- "Predefined rules/overriding rules caused some issues."
What is most valuable?
- Languages Support - over 20 programming languages
- Pre-commit check directly into Eclipse
- Issues Report into PreviewMode
- Custom coding rules
- Unit tests
- Duplication and code duplication check
- Custom-defined checks
How has it helped my organization?
I have fallen in love with SonarQube when I could've easily built custom rules checks. However, doing that manually checking takes tons of time.
What needs improvement?
- Explicit checks for issues
- Severity tab tweaks
- Optimization into the Settings, such as adding new features/customization
For how long have I used the solution?
I've used it for almost two years, starting with v4.3.3.
What was my experience with deployment of the solution?
Predefined rules/overriding rules caused some issues.
How are customer service and technical support?
6.5/10.
Which solution did I use previously and why did I switch?
- Squale
- Panopticode
- CodePro AnalytiX
How was the initial setup?
It was straightforward to install and setup, but complex to adapt to and learn.
What about the implementation team?
We used a vendor team.
Which other solutions did I evaluate?
I did not evaluated other options.
What other advice do I have?
I would advise you to think a lot before acting.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CTO at FPT Telecom
Automatically scans for code, detects vulnerabilities, and generates daily reports
Pros and Cons
- "It automatically scans for code, detects vulnerabilities, and generates daily reports."
- "After scanning our code and generating a report, it would be helpful if SonarQube could also generate a solution to fix vulnerabilities in the report."
What is our primary use case?
We used SonarQube during the development period and AppScan after the system was deployed on the production site.
What is most valuable?
SonarQube is integrated with the CI/CD infrastructure. It automatically scans for code, detects vulnerabilities, and generates daily reports. SonarQube's integration with the CI/CD infrastructure helps us reduce the effort to scan the code manually.
What needs improvement?
After scanning our code and generating a report, it would be helpful if SonarQube could also generate a solution to fix vulnerabilities in the report.
For how long have I used the solution?
I have been using SonarQube for six to seven years.
What do I think about the stability of the solution?
We haven’t faced any issues with the solution’s performance or stability.
How are customer service and support?
We don't have a support license for SonarQube. We currently use the open-source community, which provides us with much support from communities worldwide.
How was the initial setup?
The solution's initial setup is very easy. We have a team that handles the maintenance of SonarQube in the CI/CD environment.
What about the implementation team?
The solution's deployment takes about two weeks. We have a new software development project, and integrating it into the CI/CD system took about half a working day.
What's my experience with pricing, setup cost, and licensing?
We use the solution free of cost. SonarQube is a cost-efficient solution.
What other advice do I have?
I would recommend the solution to other users.
Overall, I rate the solution ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder at a tech services company with 11-50 employees
Works fine and provides good value for money
Pros and Cons
- "It is working fine. It provides a good value for money."
- "One thing to improve would be the integration. There is a steep learning curve to get it integrated."
What is our primary use case?
We use it as a gatekeeper for our external developers to follow the rules. If they don't comply with the rules within the source code, they cannot commit.
What is most valuable?
It is working fine. It provides good value for money.
What needs improvement?
One thing to improve would be the integration. There is a steep learning curve to get it integrated.
For how long have I used the solution?
I have been using this solution for maybe two years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is definitely scalable. Currently, we have six users.
How are customer service and technical support?
We didn't contact them.
Which solution did I use previously and why did I switch?
This was our first one.
How was the initial setup?
Its initial setup is okay. It is not too difficult. It probably took a couple of hours.
One developer is enough for its deployment.
What's my experience with pricing, setup cost, and licensing?
We pay €10 per month for this solution, which is good. It provides good value for money.
What other advice do I have?
I would recommend this solution to others. I would rate SonarQube a nine out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of consultory at a non-tech company with 1,001-5,000 employees
Straightforward installation, stable, and effective code analysis
Pros and Cons
- "The most valuable features are the analysis and detection of issues within the application code."
- "The solution could improve by providing more advanced technologies."
What is our primary use case?
We use SonarQube for testing, reviewing, and ensuring the quality of application code.
What is most valuable?
The most valuable features are the analysis and detection of issues within the application code.
What needs improvement?
The solution could improve by providing more advanced technologies.
For how long have I used the solution?
I have been using the solution within the last 12 months.
What do I think about the stability of the solution?
The SonarQube is stable.
How was the initial setup?
The installation is easy.
What's my experience with pricing, setup cost, and licensing?
The price of this solution is more expensive than competitors. However, it works better than competitors.
Which other solutions did I evaluate?
I have evaluated other solutions.
What other advice do I have?
I rate SonarQube an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Buyer's Guide
Download our free SonarQube Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Software Development AnalyticsPopular Comparisons
Checkmarx One
GitLab
Veracode
CrowdStrike Falcon Cloud Security
Coverity Static
GitHub Advanced Security
Acunetix
Mend.io
OpenText Core Application Security
OWASP Zap
Sonatype Lifecycle
PortSwigger Burp Suite Professional
GitGuardian Platform
HCL AppScan
Buyer's Guide
Download our free SonarQube Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is SonarQube the best tool for static analysis?
- Which gives you more for your money - SonarQube or Veracode?
- What Is The Biggest Difference Between Fortify on Demand And SonarQube?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- How does SonarQube instance relate to the license?
- Which software is ideal for code quality and security?
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?

















