We use it to check the code quality, and the code review to find out the vulnerabilities about the central codes like simplifications and codes. We also use it for security management.
Devops Engineer at a financial services firm with 10,001+ employees
Security hotspot feature identifies where your code is prone to have security issues
Pros and Cons
- "The most valuable feature is the security hotspot feature that identifies where your code is prone to have security issues."
- "In the next release, I would like to have notifications because now, it is a bit difficult. I think that's a feature which we could add there and it would benefit the users as well. For every full request, they should be able to see their bugs or vulnerability directly on the surface."
What is our primary use case?
What is most valuable?
The most valuable feature is the security hotspot feature that identifies where your code is prone to have security issues.
It also gives you a very good highlight of what's changed, and what has to be changed in the future.
Apart from that, there are many other good features as it's a code analytics platform. It also has a dashboard reporting feature, which is very good. I also like the ease of its integration with Jenkins.
Another valuable feature is the time snapshot that it provides for the code. It provides the code quality, the lagging, and the training features like what already has gone wrong and what is likely to go wrong. It's a very good feature for a project to have a dashboard where the users can find everything about their project at a single glance.
What needs improvement?
There are various standards that are followed. Awareness is a must.
Product awareness is something that I would recommend. If the users are not aware of how to use the product, they won't understand the features.
For how long have I used the solution?
I have been using SonarQube for three years.
Buyer's Guide
SonarQube
January 2026
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is quite stable. There are no kind of issues that we face on SonarQube. It's just about the awareness where the users are not aware of a feature and that's where we need to jump in and explain some of the features about how it works.
What do I think about the scalability of the solution?
It's definitely easy to scale.
How are customer service and support?
We do contact them based on the project team requirement. We contact them if they have to set up any specific kind of portfolio application and such application et cetera, internal.
Their support is good. They respond quickly. The response time is very good. They answer the queries within 24 to 48 hours. That's a plus for them. It's a very costly product, so we use the enterprise-level product. It does consume a lot of license cost for that.
Which solution did I use previously and why did I switch?
We used Fortify, it is also another tool for static code analysis. The security team used to use that, but not in our team because ours was a newly assembled team for the work.
How was the initial setup?
The initial setup is simple. It's basically an orchestration platform on which I manage around 400 SonarQube incentives.
It's a mass production environment. I'm currently managing around 400 plus teams who are using the product. We are trying to migrate it onto Kubernetes.
The setup takes around five to ten minutes as I have created automation.
It requires maintenance on the platform side, but not on the SonarQube side. Because there is a DB cleanup automatically inbuilt in Sonar, it does not require much to maintain within SonarQube itself.
It eats up a lot of memory. For a stack it's around 2.5GB. We use it on a daily basis.
What's my experience with pricing, setup cost, and licensing?
Everything is included in the standard licensing.
What other advice do I have?
Awareness about how to use the product is important. It's a very good product for developers because it gives you timely notifications about where the tool has gone wrong or what could go wrong in the future. That's popular for developers. It's very good for the stats about the product for architects
The metrics are how the budgeting should be done et cetera. These are the things that they can find out from the dashboard based on the lines of codes.
In the next release, I would like to have notifications because now, it is a bit difficult. I think that's a feature which we could add there and it would benefit the users as well. For every full request, they should be able to see their bugs or vulnerability directly on the surface.
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Software Delivery at a tech services company with 51-200 employees
Provides an automated gated procedure to ensure that engineers are able to deliver great, secure code to production
Pros and Cons
- "Engineers have also learned from the results and have improved themselves as engineers. This will help them with their careers."
What is our primary use case?
Our primary use case is to analyze source code for software bugs, technical debt, vulnerabilities, and test coverage. It provides an automated gated procedure to ensure that engineers are able to deliver great, secure code to production.
We plug this process into our process right from the start enabling the IDE integrations so that engineers can scan their code before submission. Following on from that we run the scans on every change that has been submitted for review.
This way we ensure that no core/fundamental issues are added to our codebases.
How has it helped my organization?
It has helped many of the organizations that I have worked at to improve overall security, quality, and test confidence within the codebases. It also provides this in a speed efficient way. Engineers now feel much more proud of their solution as they gain confidence from these scans and their results.
Engineers have also learned from the results and have improved themselves as engineers. This will help them with their careers.
We are also able to get reports on our suite and generate a quality rating for ourselves utilizing this data and more.
What is most valuable?
By far the quality gate controls. Without this, there would be no way to really utilize the power of this tool. We are able to automatically ensure that no code is delivered to production when it contains severe bugs or vulnerabilities.
The tight integration to source control also helps us to keep the engineers in the loop with any follow-up actions for issues reported.
Finally, the historical trend analysis gives us great insight into how we are improving based on our decisions, which are now driven by clear data.
What needs improvement?
It should keep up with newer technologies. As this is primarily open-source, it does require updates from the community. As such, there is sometimes a delay for new technologies to be covered by this too.
Particularly around the languages that the webpages state they support. The big benefit of Sonar is that it handles so many different languages, problems, and static analysis in one place.
When that one place has a low coverage for the most basic rules (OWASP top 10 for example) it starts to lose its value add.
For how long have I used the solution?
I have been using SonarQube for five years.
What do I think about the stability of the solution?
Good, I have not really had many issues with it. No major ones either.
What do I think about the scalability of the solution?
It all depends on where/how you are hosting it. The tool itself scales well.
Which solution did I use previously and why did I switch?
I have used Checkmarx and also tried a demo of Veracode.
Checkmarx was far too heavy-handed and only handled security concerns for a VERY large price tag.
Veracode is very good, however, the price vs a free solution was a deciding factor in many cases.
How was the initial setup?
It's very straightforward for a SaaS setup.
For a self-hosted setup, it is documented well and fairly easy.
What about the implementation team?
We implemented in-house.
What's my experience with pricing, setup cost, and licensing?
SonarQube will incur hosting costs. There are SaaS options available at competitive prices too.
Self-hosting SonarQube is subject to its open-source licenses documented on their website.
Which other solutions did I evaluate?
We also evaluated Checkmarx, Veracode and open source solutions specific to each programming language.
What other advice do I have?
Security analysis is a MUST.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
SonarQube
January 2026
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Director of Software Engineering at a computer software company with 201-500 employees
Helps to monitor and manage violations but improvement is needed in integration with third-party platforms and scalability
Pros and Cons
- "The tool helps us to monitor and manage violations. It manages the bugs and security violations."
- "SonarQube needs to improve its ease of use, integration with third-party platforms, and scalability."
What is most valuable?
The tool helps us to monitor and manage violations. It manages the bugs and security violations.
What needs improvement?
SonarQube needs to improve its ease of use, integration with third-party platforms, and scalability.
For how long have I used the solution?
I have been using the product for five years.
What do I think about the stability of the solution?
I rate the tool's stability a six out of ten.
What do I think about the scalability of the solution?
My company has 150 users for SonarQube.
How was the initial setup?
The tool's deployment is complex.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is reasonable.
What other advice do I have?
I rate the overall product a seven out of ten and would recommend it to others.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Infosec Consultant at a tech vendor with 11-50 employees
Has a user-friendly UI and can be used for secure code review
Pros and Cons
- "The solution's user interface is very user-friendly."
- "It would be a great add-on if SonarQube could update its database for vulnerabilities or plugging parts."
What is our primary use case?
We used SonarQube for secure code review.
What is most valuable?
The solution's user interface is very user-friendly. The solution also provides good efficiency.
What needs improvement?
It would be a great add-on if SonarQube could update its database for vulnerabilities or plugging parts.
For how long have I used the solution?
What do I think about the stability of the solution?
I rate the solution a seven out of ten for stability.
What do I think about the scalability of the solution?
I rate the solution a nine out of ten for scalability.
How was the initial setup?
On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup an eight out of ten.
What about the implementation team?
It takes around one hour to deploy SonarQube.
What's my experience with pricing, setup cost, and licensing?
SonarQube is a fairly affordable solution for a larger scale if you have a specific role or specific department for secure code. We didn't pay for SonarQube. We used a free version of the solution because we had a small amount of code.
What other advice do I have?
We used SonarQube for one project. To improve code quality, we do vulnerability assessment. We have an R&D department, and we collaborate with other teams to do any work related to secure code.
SonarQube simplified our code review process. Since we are new to secure code review, we mostly use freely available or impactful applications. That's why our R&D team suggested using SonarQube.
We use SonarQube to find vulnerabilities in the application code. The code is related to the application used by our client. We find vulnerabilities in their application, and we suggest solutions.
We have experienced challenges related to the client-side code. Sometimes, the server faces downtime, and our R&D team knows how to resolve such errors. It is easy to maintain the solution.
Overall, I rate the solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Infrastructure & Compliance & Cloud at a tech services company with 51-200 employees
Offers continuous code analysis which can improve the code quality
Pros and Cons
- "The solution provides continuous code analysis which has improved the quality of our code. It can raise alarms on vulnerabilities with immediate reports on the dashboard. Few things are false positives and we can customize the rules."
- "The solution needs to improve its customization and flexibility."
What is most valuable?
The solution provides continuous code analysis which has improved the quality of our code. It can raise alarms on vulnerabilities with immediate reports on the dashboard. Few things are false positives and we can customize the rules.
What needs improvement?
The solution needs to improve its customization and flexibility.
For how long have I used the solution?
I have been using the solution for ten days.
What do I think about the stability of the solution?
I would rate the product's stability an eight out of ten.
How are customer service and support?
We have received instant replies from the support but not actual answers. We contacted support regarding upgrading the edition.
How was the initial setup?
The tool's setup is not complex. Our engineers were not experienced and they took time to implement the product.
What other advice do I have?
The tool is simple and I would rate it an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Software Architect Sales Systems at a tech services company with 201-500 employees
A simple solution that helps with the static quality checks of codes
Pros and Cons
- "The product is simple."
- "The product's pricing could be lower."
What is our primary use case?
We use the tool to check our code. It's used for static quality checks.
What is most valuable?
The product is simple.
What needs improvement?
The product's pricing could be lower.
For how long have I used the solution?
I have been using the product for two years.
What do I think about the stability of the solution?
The tool is stable.
How was the initial setup?
The product is easy to deploy and update.
What's my experience with pricing, setup cost, and licensing?
We use the tool's community edition.
What other advice do I have?
I would rate the product an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Managing Consultant
It helps us detect vulnerabilities, but the integration with other tools in the CI/CD pipeline could be better
Pros and Cons
- "I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is."
- "CI/CD pipeline is part of a whole chain of design, development, and production, and it's becoming increasingly crucial to optimize the various tools across different stages. However, it's still a silo approach because the full integration is missing. This isn't just an issue with SonarCloud. It's a general problem with tooling."
What is our primary use case?
We have several development streams, so we want to standardize our tooling and not necessarily restrict each tool to one specific purpose. We have CI/CD pipelines, with cloud solutions on one side and solutions like GitHub and Jenkins on the other.
We use SonarCloud to scan code for vulnerabilities. The idea is to have that in a plan-do-check-act iterative way. Some development teams work in sprints with a scope of two weeks. For example, they define and finish their own user stories.
Others work in Kanban, which means they work on one user story and only go on to the next when that one is finished. But the underlying thing is we are continuously using SonarCloud to clean out vulnerabilities in software that has been developed in-house.
+
What needs improvement?
CI/CD pipeline is part of a whole chain of design, development, and production, and it's becoming increasingly crucial to optimize the various tools across different stages. However, it's still a silo approach because the full integration is missing. This isn't just an issue with SonarCloud. It's a general problem with tooling.
For how long have I used the solution?
We've used SonarCloud for nearly nine months, but we're slowly using it more and more.
What do I think about the scalability of the solution?
The services are small, so scalability is not relevant. If you say that the service is an application, then the functionality of the application is, by definition, small and fit for purpose. The scalability of having lots of increased functionality within a service is not an issue.
Scalability has more to do with the number of services or the full set of applications. A big company has multiple types of development going on that require SonarCloud. There are several services and applications that need to be scanned on a regular basis completely independently of each other. That's the issue. We're not hitting this threshold at the moment, so that's something we'll discover in the future as we add more to SonarCloud.
How was the initial setup?
I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is.
What's my experience with pricing, setup cost, and licensing?
I can't say what it costs off the top of my head, but I believe the license is based on the number of users and services. Generally, it's considered inexpensive.
The price is also based on the lines of code scanned. We use another solution instead of SonarCloud to scan third-party software. One thing is unclear. If you want to use SonarCloud for third-party software, you will reuse it for more services, but you only need to scan the latest version.
You only need to scan once to cover all services that you're developing to minimize the cost of the scans. It doesn't make sense to redo the same scan for the third-party library version, which is used by many services. You only need to do it once.
What other advice do I have?
I rate SonarCloud seven out of 10. That rating is more of an intuitive sense of the product based on many years of experience.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Team Lead at a tech services company with 1,001-5,000 employees
Reliable and secure solution used for qualitative coding, including the SonarLint plugin
Pros and Cons
- "We use this solution for qualitative coding. We make use of the SonarLint plugin as well as the dashboard."
- "We previously experienced issues with security but a segregated security violation has been implemented and the issues we experienced are being fixed."
What is our primary use case?
We use this solution for qualitative coding. We make use of the SonarLint plugin as well as the dashboard.
What needs improvement?
We previously experienced issues with security but a segregated security violation has been implemented and the issues we experienced are being fixed. We have also experienced duplications of rules within the system as well as code samples that are short of ten numbers.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
Most of the deployment was done by me. Once a certain level of complexity was involved, a team was used to validate and deploy those parts of the solution.
What other advice do I have?
I would recommend SonarQube to other users as it is a good solution and the security issues we experienced are being fixed.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free SonarQube Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Software Development AnalyticsPopular Comparisons
GitLab
Checkmarx One
Veracode
Coverity Static
CrowdStrike Falcon Cloud Security
GitHub Advanced Security
OpenText Core Application Security
OWASP Zap
Mend.io
Acunetix
Sonatype Lifecycle
PortSwigger Burp Suite Professional
HCL AppScan
HackerOne
Buyer's Guide
Download our free SonarQube Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is SonarQube the best tool for static analysis?
- Which gives you more for your money - SonarQube or Veracode?
- What Is The Biggest Difference Between Fortify on Demand And SonarQube?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- How does SonarQube instance relate to the license?
- Which software is ideal for code quality and security?
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?



















