We use the tool to check our code. It's used for static quality checks.
Software Architect Sales Systems at a tech services company with 201-500 employees
A simple solution that helps with the static quality checks of codes
Pros and Cons
- "The product is simple."
- "The product's pricing could be lower."
What is our primary use case?
What is most valuable?
The product is simple.
What needs improvement?
The product's pricing could be lower.
For how long have I used the solution?
I have been using the product for two years.
Buyer's Guide
SonarQube
January 2026
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,665 professionals have used our research since 2012.
What do I think about the stability of the solution?
The tool is stable.
How was the initial setup?
The product is easy to deploy and update.
What's my experience with pricing, setup cost, and licensing?
We use the tool's community edition.
What other advice do I have?
I would rate the product an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Managing Consultant
It helps us detect vulnerabilities, but the integration with other tools in the CI/CD pipeline could be better
Pros and Cons
- "I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is."
- "CI/CD pipeline is part of a whole chain of design, development, and production, and it's becoming increasingly crucial to optimize the various tools across different stages. However, it's still a silo approach because the full integration is missing. This isn't just an issue with SonarCloud. It's a general problem with tooling."
What is our primary use case?
We have several development streams, so we want to standardize our tooling and not necessarily restrict each tool to one specific purpose. We have CI/CD pipelines, with cloud solutions on one side and solutions like GitHub and Jenkins on the other.
We use SonarCloud to scan code for vulnerabilities. The idea is to have that in a plan-do-check-act iterative way. Some development teams work in sprints with a scope of two weeks. For example, they define and finish their own user stories.
Others work in Kanban, which means they work on one user story and only go on to the next when that one is finished. But the underlying thing is we are continuously using SonarCloud to clean out vulnerabilities in software that has been developed in-house.
+
What needs improvement?
CI/CD pipeline is part of a whole chain of design, development, and production, and it's becoming increasingly crucial to optimize the various tools across different stages. However, it's still a silo approach because the full integration is missing. This isn't just an issue with SonarCloud. It's a general problem with tooling.
For how long have I used the solution?
We've used SonarCloud for nearly nine months, but we're slowly using it more and more.
What do I think about the scalability of the solution?
The services are small, so scalability is not relevant. If you say that the service is an application, then the functionality of the application is, by definition, small and fit for purpose. The scalability of having lots of increased functionality within a service is not an issue.
Scalability has more to do with the number of services or the full set of applications. A big company has multiple types of development going on that require SonarCloud. There are several services and applications that need to be scanned on a regular basis completely independently of each other. That's the issue. We're not hitting this threshold at the moment, so that's something we'll discover in the future as we add more to SonarCloud.
How was the initial setup?
I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is.
What's my experience with pricing, setup cost, and licensing?
I can't say what it costs off the top of my head, but I believe the license is based on the number of users and services. Generally, it's considered inexpensive.
The price is also based on the lines of code scanned. We use another solution instead of SonarCloud to scan third-party software. One thing is unclear. If you want to use SonarCloud for third-party software, you will reuse it for more services, but you only need to scan the latest version.
You only need to scan once to cover all services that you're developing to minimize the cost of the scans. It doesn't make sense to redo the same scan for the third-party library version, which is used by many services. You only need to do it once.
What other advice do I have?
I rate SonarCloud seven out of 10. That rating is more of an intuitive sense of the product based on many years of experience.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
SonarQube
January 2026
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,665 professionals have used our research since 2012.
Team Lead at a tech services company with 1,001-5,000 employees
Reliable and secure solution used for qualitative coding, including the SonarLint plugin
Pros and Cons
- "We use this solution for qualitative coding. We make use of the SonarLint plugin as well as the dashboard."
- "We previously experienced issues with security but a segregated security violation has been implemented and the issues we experienced are being fixed."
What is our primary use case?
We use this solution for qualitative coding. We make use of the SonarLint plugin as well as the dashboard.
What needs improvement?
We previously experienced issues with security but a segregated security violation has been implemented and the issues we experienced are being fixed. We have also experienced duplications of rules within the system as well as code samples that are short of ten numbers.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
Most of the deployment was done by me. Once a certain level of complexity was involved, a team was used to validate and deploy those parts of the solution.
What other advice do I have?
I would recommend SonarQube to other users as it is a good solution and the security issues we experienced are being fixed.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Technical Architect at a tech services company with 501-1,000 employees
Effective vulnerability scanning, good support, and simple setup
Pros and Cons
- "SonarQube has a lot of value, it reviews the basic coding standards and security vulnerabilities of code that help to reduce issues."
- "SonarQube can improve by scanning the internal library which currently it does not do. We are looking for a solution for this."
What is our primary use case?
We are using SonarQube for scanning our services for issues as part of our IT department.
What is most valuable?
SonarQube has a lot of value, it reviews the basic coding standards and security vulnerabilities of code that help to reduce issues.
What needs improvement?
SonarQube can improve by scanning the internal library which currently it does not do. We are looking for a solution for this.
For how long have I used the solution?
I have been using SonarQube for approximately three years.
What do I think about the stability of the solution?
SonarQube is a stable solution.
What do I think about the scalability of the solution?
I have found SonarQube to be stable. However, we have not tested it with more than one million lines of code.
We have a server that SonarQube is running on and we have approximately 50 people using it.
How are customer service and support?
We have used technical support in the past but not recently.
I would rate the support from SonarQube a four out of five.
Which solution did I use previously and why did I switch?
I have used Veracode previously.
How was the initial setup?
The initial setup is straightforward for SonarQube.
What about the implementation team?
We did the implementation in-house.
The DevOps team handles the maintenance of SonarQube.
What's my experience with pricing, setup cost, and licensing?
We are using the Developer Edition and the cost is based on the amount of code that is being processed.
What other advice do I have?
If SonarQube meets the needs of your use case then I use it.
I rate SonarQube an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Information Manager at a tech services company with 10,001+ employees
Reliable with a nice web interface but needs better reporting
Pros and Cons
- "The solution offers a very good community edition."
- "There isn't a very good enterprise report."
What is most valuable?
We find it very similar to Fortify and has the same advantages.
The web interface is very good.
We have found the solution to be stable.
The solution offers a very good community edition.
What needs improvement?
There isn't a very good enterprise report. They also do not have an application report. We'd like for them to work on this aspect.
For how long have I used the solution?
I've used the solution for three years. I've used it for a while now.
What do I think about the stability of the solution?
In terms of stability, the solution is reliable and the performance is good. There are no bugs. It's not glitchy. It doesn't crash or freeze.
How are customer service and support?
I've never used technical support. I can't talk about how helpful they are, never spoken with them personally.
If I do need to troubleshoot, I tend to rely on the community and search for answers there.
Which solution did I use previously and why did I switch?
We've also used Fortify.
How was the initial setup?
I didn't participate in the installation process. I can't speak to how easy or difficult the process was.
What's my experience with pricing, setup cost, and licensing?
I use the community version of the product.
What other advice do I have?
We are a customer and an end-user.
I'd rate the solution at a seven out of ten. It's mostly reliable.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Quality Engineers/Automation Architect at a tech company with 201-500 employees
Quick deployment, scales well, and accurate reports
Pros and Cons
- "The reports from SonarCloud are very good."
- "We had some issues with the scanner."
What is our primary use case?
We use SonarCloud tools for all our 20 repositories and we are connecting the SonarCloud, from the Bitbucket pipeline.
What is most valuable?
The reports from SonarCloud are very good.
What needs improvement?
We had some issues with the scanner.
For how long have I used the solution?
I have been using SonarCloud for approximately three weeks.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
SonarCloud is scalable.
We plan to increase our package to the enterprise edition and decrease the lines of code in the future.
How are customer service and support?
We have not needed the support at this time.
Which solution did I use previously and why did I switch?
We previously used Codacy. We switch to SonarCloud because of their good reputation and we compared reports from both of them. SonarCloud seems to be more accurate. However, Codacy has a simpler installation. SonarCloud has more steps involved.
How was the initial setup?
The solution is straightforward to implement. Some of the implementations can be quick.
The installation of the framwork was a bit difficult, it could be improved.
What's my experience with pricing, setup cost, and licensing?
The price of SonarCloud could be less expensive. We are using the community version and the price should be more reasonable.
We have purchased a license for 2 million lines of code. However, we have 10 million lines of code but it would be too costly for us to have a license for all the amount.
What other advice do I have?
I would recommend SonarCloud to others.
I rate SonarCloud a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Development Team Lead at a financial services firm with 1,001-5,000 employees
IDE plugins are easy to use and integrate
Pros and Cons
- "Some of the most valuable features have been the latest up-to-date of the OWASP, the monitoring, the reporting, and the ease of use with the IDE plugins, in terms of integration."
- "SonarQube's detail in the security could be improved. It may be helpful to have additional details, with regards to Oracle PL/SQL. For example, it's neither as built nor as thorough as Java. For now, this is the only additional feature I would like to see."
What is our primary use case?
I use SonarQube for Google's web services, from a security perspective, as well as Oracle Forms, HTML Forms, and script.
SonarQube is deployed on-premises.
What is most valuable?
Some of the most valuable features have been the latest up-to-date of the OWASP, the monitoring, the reporting, and the ease of use with the IDE plugins, in terms of integration.
What needs improvement?
SonarQube's detail in the security could be improved. It may be helpful to have additional details, with regards to Oracle PL/SQL. For example, it's neither as built nor as thorough as Java. For now, this is the only additional feature I would like to see.
For how long have I used the solution?
I have been working with the Community Edition for at least ten years, and I have been working with the Enterprise version for about a year.
What do I think about the stability of the solution?
So far, we are happy and haven't had any issues with stability.
The only maintenance this product needs, for now, is just updates and patches.
SonarQube is an auditing requirement from our side and for our SDLC, so it is a gate in our SDLC.
What do I think about the scalability of the solution?
SonarQube is easy to scale. As we've opted for the Docker builds, we haven't had issues yet.
At this point, there are at least 300 people in my company who are working with SonarQube.
Which solution did I use previously and why did I switch?
I have minor experience with Q One. The main difference is in the licensing structure, with regards to lines of code. We have noticed that Q One has a bit more details, but support for various languages is lacking.
How was the initial setup?
The setup process of SonarQube is straightforward. Deployment took about a week, but the integration of the multiple teams—introducing them and getting them on board—took about a month.
What about the implementation team?
We implemented this solution through an in-house team.
What's my experience with pricing, setup cost, and licensing?
Compared to similar solutions, SonarQube was more accessible to us and had more benefits, with regards to size of the code base and supported languages. Apart from the Enterprise licensing fee, there are no additional costs.
What other advice do I have?
I rate SonarQube an eight out of ten.
To anyone who is looking into implementing SonarQube, I would recommend they look at what their requirements are, with regards to languages. If it's just Java, then the Community Edition is fine, but if there are any additional languages, then I would recommend Enterprise.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Staff DevOps Specialist at a computer software company with 201-500 employees
Greatly improves the quality, straightforward to use, and stable
Pros and Cons
- "My focus is mainly on the DevOps pipeline side of things, and from my perspective, the ease of use and configuration is valuable. It is pretty straightforward to take a deployment pipeline or CI/CD pipeline and integrate SonarQube into it."
- "A little bit more emphasis on security and a bit more security scanning features would be nice."
What is our primary use case?
It is mainly used as part of the CI/CD pipeline through Azure DevOps and Jenkins to do static code analysis.
We have the enterprise version. In terms of deployment, on-premise is the best description because they have their own cloud, but it is not a real cloud. It is like VMware.
How has it helped my organization?
In some instances, the project stakeholders were able to implement quality gate control for code coverage, security alerts, and things like that. It greatly improved the quality of the product. If our test code coverage is 80% and a person commits a change that brings the code coverage to below 80%, that code cannot be merged. We've been able to improve the quality of the products that we produce by using SonarQube. We are using it as a gate.
It is a great tool in a situation where you have a dynamic team, and you sometimes hire staff or subcontractors from other companies. It provided us with the ability to implement quality gates in our project. We could look at the data and see which developers were producing quality code and which developers were not too worried about the quality. It helped us out with our junior devs. I know of a few cases where having this system helped our junior devs in taking their skills one level up because we had set up a hard quality gate.
What is most valuable?
My focus is mainly on the DevOps pipeline side of things, and from my perspective, the ease of use and configuration is valuable. It is pretty straightforward to take a deployment pipeline or CI/CD pipeline and integrate SonarQube into it.
What needs improvement?
A little bit more emphasis on security and a bit more security scanning features would be nice.
It would also be nice if the discrepancy between the basic or free version and the enterprise version was less. In my opinion, some of the base functionality in the enterprise version should be in the basic version.
Currently, we have static code scanning, and we have the scanning of the Docker containers. It would be great if some sort of penetration testing could easily be implemented in SonarQube for deploying something and doing some basic security scans. Currently, we have to use third-party tools for that. If everything was all under one roof, it would be more comfortable, but I don't know if it is possible or feasible. It is a typical issue of centralization versus distribution. In our particular case, because we're using SonarQube for almost every other project, it would make sense, but that doesn't necessarily mean that it is the same case with everybody else.
For how long have I used the solution?
I have been using this solution for four years in my current job.
What do I think about the stability of the solution?
I don't think I ever had a problem.
What do I think about the scalability of the solution?
We haven't reached a point where it is anywhere near saturation. We haven't scaled it yet, and I don't know if it will ever happen. The way it is implemented right now is more than enough for what we need.
We have used it in almost all projects of our client. It is a part of their process. It is used extensively, and it will be used for any future work that they might have where they develop any code that can be analyzed with SonarQube.
We probably have 30 or 40 users. Their roles are developer team leads, developers, and DevOps people. These are the three roles of people who use it on a daily basis and look at the reports and work with the system. At some point, the data might be shown to the actual client or somebody else.
How are customer service and support?
I've never been in a situation where I needed their support.
Which solution did I use previously and why did I switch?
I don't think that we used anything else previously. SonarQube was the first one.
How was the initial setup?
It was straightforward. I wasn't technically involved in the deployment of SonarQube, but as far as I know, it was a matter of a few days.
What about the implementation team?
We probably just bought the license and did it ourselves. For its deployment and maintenance, we don't have a dedicated person. It is one of the many systems that our internal IT team manages.
What was our ROI?
I don't have that data. I don't think that we've ever calculated that.
What's my experience with pricing, setup cost, and licensing?
My guess is that we have a yearly subscription. We use it quite extensively, so a monthly license wouldn't make sense. Yearly subscriptions are usually cheaper.
In addition to the standard licensing fee, there is just the cost of running the hardware where it is hosted.
What other advice do I have?
It is pretty straightforward, but if you don't intend to use it as a gate, it would just be a waste of time. You should invest in implementing such tools only when you have a clear understanding of how their results are going to be a part of a business process.
I would rate it a 10 out of 10. I've never had any kind of problems with it. I have some products because of which I have had a bad day, but I never had a bad day because of it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free SonarQube Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Software Development AnalyticsPopular Comparisons
GitLab
Checkmarx One
Veracode
Coverity Static
CrowdStrike Falcon Cloud Security
GitHub Advanced Security
OpenText Core Application Security
Mend.io
OWASP Zap
Acunetix
Sonatype Lifecycle
PortSwigger Burp Suite Professional
HCL AppScan
HackerOne
Buyer's Guide
Download our free SonarQube Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is SonarQube the best tool for static analysis?
- Which gives you more for your money - SonarQube or Veracode?
- What Is The Biggest Difference Between Fortify on Demand And SonarQube?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- How does SonarQube instance relate to the license?
- Which software is ideal for code quality and security?
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?


















