We used SonarQube for secure code review.
The solution's user interface is very user-friendly. The solution also provides good efficiency.
It would be a great add-on if SonarQube could update its database for vulnerabilities or plugging parts.
I rate the solution a seven out of ten for stability.
I rate the solution a nine out of ten for scalability.
On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup an eight out of ten.
It takes around one hour to deploy SonarQube.
SonarQube is a fairly affordable solution for a larger scale if you have a specific role or specific department for secure code. We didn't pay for SonarQube. We used a free version of the solution because we had a small amount of code.
We used SonarQube for one project. To improve code quality, we do vulnerability assessment. We have an R&D department, and we collaborate with other teams to do any work related to secure code.
SonarQube simplified our code review process. Since we are new to secure code review, we mostly use freely available or impactful applications. That's why our R&D team suggested using SonarQube.
We use SonarQube to find vulnerabilities in the application code. The code is related to the application used by our client. We find vulnerabilities in their application, and we suggest solutions.
We have experienced challenges related to the client-side code. Sometimes, the server faces downtime, and our R&D team knows how to resolve such errors. It is easy to maintain the solution.
Overall, I rate the solution a nine out of ten.