No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1587588 - PeerSpot reviewer
Founder at a tech services company with 11-50 employees
Real User
Aug 11, 2021
Works fine and provides good value for money
Pros and Cons
  • "It is working fine. It provides a good value for money."
  • "We use it as a gatekeeper for our external developers to follow the rules; if they don't comply with the rules within the source code, they cannot commit."
  • "One thing to improve would be the integration. There is a steep learning curve to get it integrated."

What is our primary use case?

We use it as a gatekeeper for our external developers to follow the rules. If they don't comply with the rules within the source code, they cannot commit. 

What is most valuable?

It is working fine. It provides good value for money.

What needs improvement?

One thing to improve would be the integration. There is a steep learning curve to get it integrated.

For how long have I used the solution?

I have been using this solution for maybe two years.

Buyer's Guide
SonarQube
August 2026
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

It is definitely scalable. Currently, we have six users.

How are customer service and support?

We didn't contact them.

Which solution did I use previously and why did I switch?

This was our first one.

How was the initial setup?

Its initial setup is okay. It is not too difficult. It probably took a couple of hours.

One developer is enough for its deployment.

What's my experience with pricing, setup cost, and licensing?

We pay €10 per month for this solution, which is good. It provides good value for money.

What other advice do I have?

I would recommend this solution to others. I would rate SonarQube a nine out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Calinescu Tudor - PeerSpot reviewer
Security Project Leader at ATOSS AG
Real User
Aug 10, 2021
Plenty of features, but needs multiple other products to function well
Pros and Cons
  • "I am only interested in the security features in SonarQube. There are plenty of features other features, such as test coverage, code anomalies, and pointer access are handled by the business logic teams. They get the reports and they have to fix them in JIRA or Bugzilla."
  • "I am only interested in the security features in SonarQube."
  • "We have tens of millions of code to be analyzed and processed. There can be some performance degradation if we are applying Sonar Link to large code or code that is complex. When the code had to be analyzed is when we ran into the main issues. There were several routines involved to solve those performance issues but this process should be improved."

What is our primary use case?

SonarQube can be used to analyze application code. We are testing SonarQube with some of our other products. We use the Sonar Link plugin with Teamscale, which is then applied to the main product we are using.

What is most valuable?

I am only interested in the security features in SonarQube. There are plenty of features other features, such as test coverage, code anomalies, and pointer access are handled by the business logic teams. They get the reports and they have to fix them in JIRA or Bugzilla.

What needs improvement?

We have to combine several products in order to cover as many flaws that might exist in the code. We have to integrate several products to set the security functionality of the product. SonarQube should have better functionality to cover all areas of security limiting our need for other products.

We have tens of millions of code to be analyzed and processed. There can be some performance degradation if we are applying Sonar Link to large code or code that is complex. When the code had to be analyzed is when we ran into the main issues. There were several routines involved to solve those performance issues but this process should be improved.

For how long have I used the solution?

I have been using this solution for approximately three years.

What do I think about the stability of the solution?

There can be some stability issues.

Which solution did I use previously and why did I switch?

I have used Veracode.

Which other solutions did I evaluate?

I have evaluated many other solutions similar to SonarQube.

What other advice do I have?

I rate SonarQube a six out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
SonarQube
August 2026
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.
reviewer1643052 - PeerSpot reviewer
Manager, Software Development Engineering at a computer software company with 51-200 employees
Real User
Aug 8, 2021
Does well in scanning and vulnerability; lacking in some specific SAST capabilities
Pros and Cons
  • "Provides local scanning for developers."
  • "SonarQube does SAST and SCAs pretty well."
  • "Dynamic scanning is missing and there are some issues with security scanning."
  • "SonarQube is missing specific SAST capabilities."

What is our primary use case?

I'm a software development engineer and we are customers of SonarQube. 

What is most valuable?

SonarQube does SAST and SCAs pretty well. One of the important things for me, something that is different from a solution like Checkmarx, was that SonarQube had SonarLint that we can use for local scanning for developers. The product does well in scanning and vulnerability.  

What needs improvement?

SonarQube is missing specific SAST capabilities. In addition, when we have security issues we want to mitigate those and it seems that SonarQube doesn't persist with the mitigation. Each time it discovered a new scan it wiped out all the persistence that we had mitigated for previous vulnerabilities. Dynamic scanning is missing and there are issues with security scanning in terms of failing projects where it didn't pass a scan.

For how long have I used the solution?

I've been using this solution for three years. 

What do I think about the stability of the solution?

The solution is quite stable. 

How are customer service and technical support?

We don't have contact with technical support, any issues are solved by our operation team.

How was the initial setup?

The initial setup wasn't too complicated. We have a number of teams of developers and around 150 users together with an operations team who maintain the infrastructure. From a user perspective we scan at least once a day. 

Which other solutions did I evaluate?

I looked at Checkmarx but it wasn't as straightforward as SonarQube because it's only supporting Linux and maybe Windows, but I wasn't able to find any local scanning support for Mac computers, and that was an issue. I'd like to learn more about Checkmarx. 

What other advice do I have?

I would suggest looking at the pipelines and understanding usage scenarios in terms of what the customer is looking for. For instance, the mitigation persistence through the life cycle of a project is not there. For me, it's like a lack of tracking records of what to mitigate. It's something that you thought would be a part of the basics, but it's not there.

I think there's about 40% of the features I'd like to see that are missing in SonarQube, so I'd rate it a six out of 10.  

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sr DevOps Engineer at incatech
Real User
Jul 14, 2021
Open-source with great extensions and great for identifying bugs
Pros and Cons
  • "It helps our developers work more efficiently as we can identify things in a code prior to it being pushed to where it needs to go."
  • "You may need to purchase add-ons to get the useability you desire."

What is our primary use case?

We use the product in our pipeline. We primarily use it for development testing tool.

How has it helped my organization?

We can see what's being flagged by whatever requirements in the environment that we're going to. SonarCube has these rules that you set up. You can set the rules and adjust them. It allows us to either be at 80% or whatever the case may be. If you set up these conditions that can tighten down the developer's coding.

What is most valuable?

It's convenient due to the fact that it's open-source. 

We're able to identify bugs and those kinds of things before we actually push anything into a staging or production area. It helps our developers work more efficiently as we can identify things in a code prior to it being pushed to where it needs to go. It's a great little loop. You see this, fix it, take it back. Versus, putting something into an environment and then everything is all broken. It's a good development test tool. 

Nowadays you can add extensions, similar to what you can do with the Jenkins tool, the CICB tool, the build tool. Jenkins can have a lot of plugins that interface with a lot of vendors or it can do a lot of things. Just like Google Chrome where you can bring in an extension, you can do the same here. In SonarQube, you can add something by just adding an extension that you may have to pay extra for, However, that add-on has additional functionality that the base software may not necessarily have in its core.

For example, Fortify has some kind of special capability that they have for checking and SonarQube has created an extension that allows the Fortify extensions. Right now, I have Fortify, however, it's in this product at a very modular level.

What needs improvement?

The solution is still maturing a bit.

You may need to purchase add-ons to get the useability you desire.

For how long have I used the solution?

We've been using the solution for about two years at this point.

What's my experience with pricing, setup cost, and licensing?

The solution is open-source. It's free to use. 

What other advice do I have?

Not everybody uses SonarQube. However, if they do use SonarQube and they're trying to look for functionality, then an extension into SonarQube is the way to go. We, for example, love how we can have Fortify functionality via this product. I can't speak for all the other shops, right. That's just our workflow.

I'd rate the solution at a perfect ten out of ten. For what it does as far as static code analysis, it's pretty good.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1192836 - PeerSpot reviewer
Director of consultory at a non-tech company with 1,001-5,000 employees
Reseller
Jul 12, 2021
Straightforward installation, stable, and effective code analysis
Pros and Cons
  • "The most valuable features are the analysis and detection of issues within the application code."
  • "The solution could improve by providing more advanced technologies."

What is our primary use case?

We use SonarQube for testing, reviewing, and ensuring the quality of application code.

What is most valuable?

The most valuable features are the analysis and detection of issues within the application code.

What needs improvement?

The solution could improve by providing more advanced technologies.

For how long have I used the solution?

I have been using the solution within the last 12 months.

What do I think about the stability of the solution?

The SonarQube is stable.

How was the initial setup?

The installation is easy.

What's my experience with pricing, setup cost, and licensing?

The price of this solution is more expensive than competitors. However, it works better than competitors.

Which other solutions did I evaluate?

I have evaluated other solutions.

What other advice do I have?

I rate SonarQube an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
PeerSpot user
Senior Solutions Architec at OSENTERPRISE SAC
Real User
Jul 11, 2021
Installation straightforward, stable, and reliable
Pros and Cons
  • "The stability is good."
  • "The solution has helped us mitigate problems in applications before they were a bigger issue."
  • "The solution could improve by having better-consulting services."

What is our primary use case?

We are using this solution to check and monitor application code to ensure security quality.

How has it helped my organization?

The solution has helped us mitigate problems in applications before they were a bigger issue.

What needs improvement?

The solution could improve by having better-consulting services.

For how long have I used the solution?

I have been using SonarQube within the last 12 months.

What do I think about the stability of the solution?

The stability is good.

How was the initial setup?

The installation was straightforward, we have an internal team that does it.

What about the implementation team?

We have a team in our organization that does the implementation, configuration, and maintenance of the solution.

What's my experience with pricing, setup cost, and licensing?

The price of the solution could be reduced.

What other advice do I have?

I rate SonarQube a ten out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1620009 - PeerSpot reviewer
Head Innovation Hub at a tech services company with 201-500 employees
Real User
Jul 10, 2021
Helps in improving the coding style and allows us to customize the rules
Pros and Cons
  • "It assists during the development with SonarLint and helps the developer to change his approach or rather improve his coding pattern or style. That's one advantage I've seen. Another advantage is that we can customize the rules."
  • "Their dashboarding is very limited. They can improve their dashboards for multiple areas, such as security review, maintainability, etc. They have all this information, so they should publish all this information on the dashboard so that the users can view the summary and then analyze it further. This is something that I would like to see in the next version."
  • "It is very expensive."

What is our primary use case?

I have used it in my previous company. In my current company, which I have joined recently, we don't use any of these tools. That's why I want to implement something for the company. I have the Community Edition of SonarQube. I am using one version prior to the latest one.

It was integrated with our build pipeline, and we had also customized the rules for the quality gate. For each release that got through SonarQube, it gave the results in terms of whether it was releasable or not. 

SLA was another use case. We internally had a rule that in case there are severity defects, they need to be fixed. If there is a false positive, it needs to be justified. That's the way it was used.

What is most valuable?

It assists during the development with SonarLint and helps the developer to change his approach or rather improve his coding pattern or style. That's one advantage I've seen. Another advantage is that we can customize the rules. 

I did an evaluation of the Enterprise Edition. It has the Portfolio view, which means you can roll up all your projects to the Portfolio level, and then it gives a visualization of each and every project's state in terms of security and other vulnerabilities.

What needs improvement?

It is very expensive. That's something that can be improved. 

I'm not sure if the latest vulnerabilities are being updated. When I compare it with Fortify on Demand (FoD), every now and then, they get all the latest and greatest versions for all these vulnerabilities as a rule pack. I'm not very sure about how that works in SonarQube, and how frequently they are updating the vulnerability databases and other things.

Their dashboarding is very limited. They can improve their dashboards for multiple areas, such as security review, maintainability, etc. They have all this information, so they should publish all this information on the dashboard so that the users can view the summary and then analyze it further. This is something that I would like to see in the next version. 

The portfolio-level dashboard is currently available only in the Enterprise Edition. They can have a similar dashboard in the Community Edition or at least in the Developer Edition. The portfolio-level dashboard is also very limited currently. There is hardly one report.

For how long have I used the solution?

I have been using this solution for four years. 

What do I think about the stability of the solution?

It looks stable. So far, we haven't found any issues.

How are customer service and technical support?

I contacted them once or twice. I am very satisfied with their support. I didn't have any concerns in terms of support.

How was the initial setup?

It is straightforward. It takes very little time as compared to the other solutions.

What's my experience with pricing, setup cost, and licensing?

It is very expensive. Its price should be improved.

What other advice do I have?

I have worked on only two tools: one is Fortify on Demand, and the other one is SonarQube. Comparing these two, I would rate SonarQube an eight out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Senior Security Consultant at Tafhar IT Services
Consultant
Jun 27, 2021
Well priced, good for basic needs, but is too limited
Pros and Cons
  • "For what it is meant to do, it works pretty well."
  • "I've been told by the developers that the solution is too limited. It's not testing enough within the containers."

What is our primary use case?

The solution is a static code analysis tool. That's basically what we use it for in our organization.

What is most valuable?

We bought the solution due to the fact that it was the lowest price. 

For what it is meant to do, it works pretty well. 

It's good for analysis.

What needs improvement?

I've been told by the developers that the solution is too limited. It's not testing enough within the containers. For instance, it only checks for obvious code errors. They should work to improve this.

At that moment we needed to scan the codes that the developers are producing, we found out that we needed more features.

For how long have I used the solution?

I've been using the solution for six months or so now. It's been less than a year.

Which solution did I use previously and why did I switch?

The former product we used was Twistlock.

How was the initial setup?

I haven't had much experience with the initial setup. I can't speak to what the deployment or setup was like.

What's my experience with pricing, setup cost, and licensing?

The pricing is very good.

Which other solutions did I evaluate?

We're currently looking into other options.

We're either looking for an integrated product for the whole CICB pipeline, such as StackRox, or we're looking at Fishman from Palo Alto. We're also looking at individual products for the whole CICB pipeline. In fact, this afternoon we are having a meeting to further discuss what tools we will use, or what can we use for dependency decks in the whole CICB pipeline, and for us to get a container image.

What other advice do I have?

We're a customer and an end-user of the product. We don't have a business relationship with them. 

I'm not sure which version of the solution we're using.

I'd advise potential users to first check all the features to see if what they need is there and then check them off to ensure that SonarCloud fills all your needs.

It's a good product for its purpose.

I'd rate the solution at a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Rakesh Thakur - PeerSpot reviewer
Technical Architect at a insurance company with 1,001-5,000 employees
Real User
Jun 17, 2021
An open-source platform for the continuous inspection of code quality with a useful code security feature
Pros and Cons
  • "I like that it helps us maintain our work quality and code security."
  • "We were trying to serve two purposes; work quality and code security, with one tool."
  • "Code security could be better. They are already focusing on it, but I see a lot of improvement opportunities over there. I can see a lot of false positives in terms of security. They need to make the tests more accurate so that the false positives are not detected so frequently. It would also help if they provided us with an installer."

What is our primary use case?

We are application support vendors, and we develop applications for our clients. To maintain code quality, we were using SonarQube, and then we presented that to our clients in order to purchase that. That's where this whole thing got started. 

One thing that we were using it majorly for was our work quality. It usually helped us in automating the review and making it more gate-oriented. Recently we were able to see the latest features like security hotspots and all that.

We were trying to serve two purposes; work quality and code security, with one tool. That's where our inclination was more towards Sonar because other tools generally target code security only.

What is most valuable?

I like that it helps us maintain our work quality and code security.

What needs improvement?

Code security could be better. They are already focusing on it, but I see a lot of improvement opportunities over there. I can see a lot of false positives in terms of security. They need to make the tests more accurate so that the false positives are not detected so frequently. It would also help if they provided us with an installer. 

For how long have I used the solution?

I have been using SonarQube for about three or four years. However, in this organization, we have been using it for the last year or so.

What do I think about the scalability of the solution?

In Community Edition, I don't think that we have enough scalability options because it runs only on one instance, plus it runs only one scan at a time. It doesn't even provide a settings capability where multiple scans are running simultaneously. That's why we want to move to the Enterprise Edition because it gives you a possibility of parallel analysis of reports, and that could speed up things.

How are customer service and technical support?

We're using the Community Edition, and I think support comes only with the paid version. But we had an initial conversation with them, and we got our answers clarified. I certainly look forward to getting in touch with somebody from SonarCloud because I hear that they are separate entities. SonarSource people don't talk about SonarCloud. We want a contact whom we can speak to regarding our security-related concerns, privacy-related concerns, and how we can secure our code in their environment.

How was the initial setup?

The initial setup on-premise may take a while because you have to procure all the servers and do the reconfiguration yourself. But I think they have provided their steps very elaborately, and that certainly helps. However, you need to make an effort to set it up. It doesn't come with an installer, and you have to download it, extract it, then configure it to run on your server automatically with every server system. If they could have provided us with an installer setup, it could have made it much easier.

What's my experience with pricing, setup cost, and licensing?

We're using the Community Edition, and we don't pay for anything.

What other advice do I have?

On a scale from one to ten, I would give SonarQube a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1593939 - PeerSpot reviewer
Systems Analyst at a manufacturing company with 5,001-10,000 employees
Real User
Jun 13, 2021
Frees up time to focus on daily tasks, meet delivery requirements and deliver more reliable code
Pros and Cons
  • "SonarQube is a fantastic tool which saves us precious time."
  • "We did have some trouble with the LDAP integration for the console."

What is our primary use case?

We use the solution to do quality code analysis for keeping track of security hotspots. We also use it to avoid the delivery of problems as the result of new code from our partners who may be developing software for systems, making improvements and carrying out bug corrections. These are the features of SonarQube of which I am aware. 

What is most valuable?

SonarQube is a fantastic tool which saves us precious time. Prior to using the solution, all our code analysis was manual and this was very time consuming. The increase in the number of projects, including those involving the development team, meant that it was becoming increasingly challenging to keep up with our delivery schedules. SonarQube helped a lot in this regard. So too, the wonderful tool from Eclipse, SonarLint, was very helpful. These solutions allow the partners who develop our system, our code, to receive on-the-fly analysis of their computers. This affords delivery of a much more reliable code, something which allows us to focus our work on more aggregated value operations.

What needs improvement?

I am struggling to come up with an area needing improvement. I am a big fan of SonarQube. I do have familiarity with the solution, but not extensively on a daily basis in respect of development. 

This said, we did have some trouble with the LDAP integration for the console. 

For how long have I used the solution?

As our company is not primarily IT-related we are late comers when it comes to adopting new technology. As such, we started using the community version of SonarQube around eight to ten months ago. 

What about the implementation team?

I have limited personal experience working with the solution. I have a colleague who works with me and she is actually engaged in its operation. My role is to provide guidance in how to implement products. 

She works more in implementing the installation of the solution, in deploying the projects on SonarQube. But, I have a little more context with this tool.

What other advice do I have?

I am a customer of SonarQube. 

At the moment, SonarQube is deployed on-premises. We have an installation running in one of our servers.

When we deploy on-cloud, we normally use Amazon Web Services. 

I rate SonarQube as a ten out of ten, easily. I think its fantastic, a wonderful tool. Even if I don't use it directly, it frees me up to focus on other tasks in my daily routine. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free SonarQube Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free SonarQube Report and get advice and tips from experienced pros sharing their opinions.