We used SonarQube during the development period and AppScan after the system was deployed on the production site.
CTO at FPT Telecom
Automatically scans for code, detects vulnerabilities, and generates daily reports
Pros and Cons
- "It automatically scans for code, detects vulnerabilities, and generates daily reports."
- "After scanning our code and generating a report, it would be helpful if SonarQube could also generate a solution to fix vulnerabilities in the report."
What is our primary use case?
What is most valuable?
SonarQube is integrated with the CI/CD infrastructure. It automatically scans for code, detects vulnerabilities, and generates daily reports. SonarQube's integration with the CI/CD infrastructure helps us reduce the effort to scan the code manually.
What needs improvement?
After scanning our code and generating a report, it would be helpful if SonarQube could also generate a solution to fix vulnerabilities in the report.
For how long have I used the solution?
I have been using SonarQube for six to seven years.
Buyer's Guide
SonarQube Server (formerly SonarQube)
September 2025

Learn what your peers think about SonarQube Server (formerly SonarQube). Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
What do I think about the stability of the solution?
We haven’t faced any issues with the solution’s performance or stability.
How are customer service and support?
We don't have a support license for SonarQube. We currently use the open-source community, which provides us with much support from communities worldwide.
How was the initial setup?
The solution's initial setup is very easy. We have a team that handles the maintenance of SonarQube in the CI/CD environment.
What about the implementation team?
The solution's deployment takes about two weeks. We have a new software development project, and integrating it into the CI/CD system took about half a working day.
What's my experience with pricing, setup cost, and licensing?
We use the solution free of cost. SonarQube is a cost-efficient solution.
What other advice do I have?
I would recommend the solution to other users.
Overall, I rate the solution ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Product Manager | Senior Software Developer at RedShift II - Solutions
Coding quality assurance tool that comes with good DevOps implementation
Pros and Cons
- "This solution has the capability to analyze source code in almost all the languages in the market."
- "This is a well-rounded solution, however, some features could be made available on the free version. The price of the solution could be reduced."
What is our primary use case?
This solution has the capability to analyze source code in almost all the languages in the market.
What needs improvement?
This is a well-rounded solution, however, some features could be made available on the free version. The price of the solution could be reduced.
For how long have I used the solution?
I have used this solution for ten years.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution. We have been using it for all of our critical projects.
What was our ROI?
I have never made the calculations to understand the real value of this solution but I know that the return of investment is very good. If not, we wouldn't have continued to use it for the past 10 years.
What's my experience with pricing, setup cost, and licensing?
As a user and a consumer of this solution, it can be pricey for my company to support and use, even though there are many benefits. For this reason, we use the free version. In the future, as our product cycles develop and evolve at a more steady pace, we hope to invest in the licensing for this tool.
What other advice do I have?
This solution has evolved a lot in the last ten years.
It comes with good DevOps implementation and security, which is a big problem today.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
SonarQube Server (formerly SonarQube)
September 2025

Learn what your peers think about SonarQube Server (formerly SonarQube). Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
Software Engineer at a tech services company with 11-50 employees
Beneficial testing tool, helps developer become sharper, and makes software more secure
Pros and Cons
- "The solution can verify vulnerabilities, code smells, and hotspots. It makes the software more secure and it helps make a junior or novice developer sharper."
- "The software testing tool capability could improve. It does not always integrate well. You have to use a specific plugin and the plugin does not always go in Apple's applications."
What is our primary use case?
I use SonarQube for testing software.
What is most valuable?
The solution can verify vulnerabilities, code smells, and hotspots. It makes the software more secure and it helps make a junior or novice developer sharper.
What needs improvement?
The software testing tool capability could improve. It does not always integrate well. You have to use a specific plugin and the plugin does not always go in Apple's applications.
In the next release, they should add the ability to analyze containers.
For how long have I used the solution?
I have been using SonarQube for approximately three years.
What do I think about the scalability of the solution?
We have mostly software developers using this solution are there are approximately 50 using it.
Which solution did I use previously and why did I switch?
I have used Snyk and it is more catered to a different audience than SolarQube.SolarQube is more for software developers.
How was the initial setup?
The installation is straightforward, especially with the new Docker implementation.
What about the implementation team?
I did the implementation of the solution myself.
What's my experience with pricing, setup cost, and licensing?
The process of purchasing the solution could improve.
What other advice do I have?
This solution is a good static test tool for developers. It helps keep the maintainability and security of software.
I rate SonarQube an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder at a tech services company with 11-50 employees
Works fine and provides good value for money
Pros and Cons
- "It is working fine. It provides a good value for money."
- "One thing to improve would be the integration. There is a steep learning curve to get it integrated."
What is our primary use case?
We use it as a gatekeeper for our external developers to follow the rules. If they don't comply with the rules within the source code, they cannot commit.
What is most valuable?
It is working fine. It provides good value for money.
What needs improvement?
One thing to improve would be the integration. There is a steep learning curve to get it integrated.
For how long have I used the solution?
I have been using this solution for maybe two years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is definitely scalable. Currently, we have six users.
How are customer service and technical support?
We didn't contact them.
Which solution did I use previously and why did I switch?
This was our first one.
How was the initial setup?
Its initial setup is okay. It is not too difficult. It probably took a couple of hours.
One developer is enough for its deployment.
What's my experience with pricing, setup cost, and licensing?
We pay €10 per month for this solution, which is good. It provides good value for money.
What other advice do I have?
I would recommend this solution to others. I would rate SonarQube a nine out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of consultory at a non-tech company with 1,001-5,000 employees
Straightforward installation, stable, and effective code analysis
Pros and Cons
- "The most valuable features are the analysis and detection of issues within the application code."
- "The solution could improve by providing more advanced technologies."
What is our primary use case?
We use SonarQube for testing, reviewing, and ensuring the quality of application code.
What is most valuable?
The most valuable features are the analysis and detection of issues within the application code.
What needs improvement?
The solution could improve by providing more advanced technologies.
For how long have I used the solution?
I have been using the solution within the last 12 months.
What do I think about the stability of the solution?
The SonarQube is stable.
How was the initial setup?
The installation is easy.
What's my experience with pricing, setup cost, and licensing?
The price of this solution is more expensive than competitors. However, it works better than competitors.
Which other solutions did I evaluate?
I have evaluated other solutions.
What other advice do I have?
I rate SonarQube an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller

Buyer's Guide
Download our free SonarQube Server (formerly SonarQube) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Software Development AnalyticsPopular Comparisons
Coverity Static
CrowdStrike Falcon Cloud Security
GitHub Advanced Security
OpenText Core Application Security
SonarQube Cloud (formerly SonarCloud)
Sonatype Lifecycle
PortSwigger Burp Suite Professional
Buyer's Guide
Download our free SonarQube Server (formerly SonarQube) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is SonarQube the best tool for static analysis?
- Which gives you more for your money - SonarQube or Veracode?
- What Is The Biggest Difference Between Fortify on Demand And SonarQube?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- How does SonarQube instance relate to the license?
- Which software is ideal for code quality and security?
- What is the difference between Coverity and SonarQube?
- What is the biggest difference between Coverity and SonarQube?
- How would you decide between Coverity and Sonarqube?