The primary use case was scanning a single-digit number of applications. We scanned them about twice a year and that's about it. It was just to get the results. We used the results to gauge our security health.
Sr Director at a non-profit with 51-200 employees
Stable with good technical support and a moderately easy implementation process
Pros and Cons
- "The solution is stable. we've never had any issues surrounding its stability."
- "The cost of the solution is a little bit expensive. Expensive in the sense that there was a hundred percent increase in cost from last year to this year, which is certainly not justified."
What is our primary use case?
What is most valuable?
The feature that was most valuable to us was the ability to point locally in a quorum.
What needs improvement?
The cost of the solution is a little bit expensive. Expensive in the sense that there was a hundred percent increase in cost from last year to this year, which is certainly not justified.
The solution needs to be more flexible. It needs to work with clients more effectively.
Right now, the licensing model is based on the number of applications as opposed to being flexible and based on the number of developers or based on some other parameters. This constrains our company in terms of defining what an application is and doing the scans. We have an application with multiple deposit rates, but Veracode has a hard time recognizing the different components sitting in different depositories as one application.
The solution is pretty similar to others. There wasn't anything that was so startlingly different it would make us want to stay.
For how long have I used the solution?
I had been using the solution for a while, but I am currently in the process of moving off of it.
Buyer's Guide
Veracode
February 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,873 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable. we've never had any issues surrounding its stability.
What do I think about the scalability of the solution?
There's nothing to scale. Asking if the solution is scalable or not isn't applicable in this case. It's not an active load balancer. It's just a static scan. If it was dynamic, there may be a question around scalability, but it is not.
How are customer service and support?
Technical support team is quite good. However, if we're talking in terms of how Veracode recognizes clients and deals with them, I'd rate them as bad.
Which solution did I use previously and why did I switch?
We did not previously use a different solution. We've only used Veracode.
How was the initial setup?
The initial setup has a moderate level of difficulty. It's neither simple or complex.
What about the implementation team?
We handled the implementation ourselves.
What's my experience with pricing, setup cost, and licensing?
The solution recently doubled in price over the past year, which is why I've decided to move away from it. The price jump doesn't make sense. It's not like there was a sudden influx in new features or advancements.
Without getting too specific, I'd say the average yearly cost is around $50,000. The costs include licensing and maintenance support.
What other advice do I have?
I handle software composition analysis. Currently, I'm moving away from Veracode.
I don't know which version of the solution I am using currently. It's not quite the most up-to-date version.
If a company is looking for a long-term partner, and not just a transactional solution, I'd suggest a different company.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
DevOps and Cloud Architect at a marketing services firm with 51-200 employees
Great for automatic penetration testing and providing the ability to investigate problems
Pros and Cons
- "Provides the ability to understand the black zones in our system."
- "Security can always be improved."
What is our primary use case?
I'm the manager of DevOps and cloud architecture.
How has it helped my organization?
This product has given us the ability to investigate and understand the black zones in our system.
What is most valuable?
Veracode can emulate the most sophisticated attack and create unique or specific use cases around automatic penetration testing. It gives us the ability to investigate any sensitivities to vulnerabilities that we may have.
What needs improvement?
Security can always be improved. I'd like to know how we can better prevent intrusions to our systems and create risk analysis use cases and understand them. What is the level of risk for what we want to do? How can we understand the process better? I'd like to have a better overview of what's going on.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
There are three layers of technical support and we have used all of them over time. We are happy with the service they provide.
What other advice do I have?
It's important to understand your environment and know the specific use cases for your organization. Creating good orchestration application metrics is very important.
I rate this product eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Veracode
February 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,873 professionals have used our research since 2012.
Director of Solutions Architecture at VetsEZ
Penetration Testing solution used by development team for static code analysis
Pros and Cons
- "Our development team use this solution for static code analysis and pen testing."
- "The runtime code analysis could be improved so that we can see every element in one place."
What is our primary use case?
Our development team use this solution for static code analysis and pen testing.
What needs improvement?
The runtime code analysis could be improved so that we can see every element in one place.
For how long have I used the solution?
I have used this solution for two years.
What other advice do I have?
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Product Security Engineer at a tech services company with 5,001-10,000 employees
Good pipeline scanner, requires minimal maintenance, and helps easily reveal design flaws
Pros and Cons
- "With the pipeline scanner, it's easier for developers to scan their products, as they don't have to export anything from their computers. They can do everything with the command line on their computer."
- "Maybe the pipeline scanning doesn't support enough languages. It might only support Java and Python only, so that could be improved."
What is our primary use case?
I'm working on security reviews for our in-house products. We are trying to solve problems. The use case for Veracode is to discover flaws in design before our application reaches end customers. We are using Veracode as one of the tools to ensure that our products are following secure design guidelines.
How has it helped my organization?
We have some applications where Veracode found a potential XSS due improper input controls. Based on Veracode recommendations, I work with dev team and remediate the flaw. That's something that I would probably missed if I did only the manual code review.
What is most valuable?
We recently started working with pipeline scanner, which is quite useful. In Veracode, you need to import zip files for the source code. With the pipeline scanner, it's easier for developers to scan their products, as they can do everything via command line. When a scanner detects a flaw, it also generates a good explanation about that flaw and good references for mitigation. That's also very useful for us.
What needs improvement?
In terms of improvement, I don't have any valuable input. The application works fine and I don't have any negative feedback. Maybe pipeline scanner can be improved to support some additional language packages.
For how long have I used the solution?
I've used the solution for two years now. It hasn't been that long.
What do I think about the stability of the solution?
The solution is stable. I haven't experienced any hiccups in my work in any way.
How are customer service and support?
I haven't worked with Vercode's support and therefore cannot comment on how helpful or responsive they are.
Which solution did I use previously and why did I switch?
I don't have experience with other SAST products.
How was the initial setup?
This solution was already deployed when I was hired. I can't speak to what the deployment process was like.
The maintenance is minimal. I just need to create accounts for people who want to scan by themselves and that's it. It's easily maintainable.
What's my experience with pricing, setup cost, and licensing?
I don't have any insights on pricing. I don't handle any aspects of the licensing process so I can't speak to the overall costs or terms.
What other advice do I have?
We are accessing via a web browser to Veracode. I'm guessing it's some type of cloud deployment, hosted by Veracode.
We have a lot of applications that are scanned with Veracode. We did scans for some of our core products, as well as on-demand products, and web applications. I'm mostly working with web applications for now.
Based on my experience, new users should check as many features as they can, and also read the reports carefully. That way, they can get a full picture of how this product works.
I'd rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT security architect at a consumer goods company with 10,001+ employees
Effective static analysis, plenty of tools, but needs better support for languages
Pros and Cons
- "The main feature that I have found valuable is the solution's ability to find issues in static analysis. Additionally, there are plenty of useful tools."
- "The solution could improve the Dynamic Analysis Security Testing(DAST)."
What is our primary use case?
We are using this solution for static analysis.
What is most valuable?
The main feature that I have found valuable is the solution's ability to find issues in static analysis. Additionally, there are plenty of useful tools.
What needs improvement?
The solution could improve the Dynamic Analysis Security Testing(DAST).
There could be better support for different languages. It is very difficult in some languages to prepare the solution for the static analysis and this procedure is really hard for a pipeline, such as GitHub. They should make it easy to scan projects for any language like they do in other vendors, such as Checkmarx.
We have found there are a lot of false positives and the severity rating we have been receiving has been different compared to other vendor's solutions. For example, in Veracode, we receive a rating of low but in others solutions, we receive a rating of high when doing the glitch analysis.
For how long have I used the solution?
We have been using this solution for approximately six years.
How are customer service and technical support?
We have not had much free expert support from the vendor. We have had to have a team of highly skilled individuals to make the solution work.
How was the initial setup?
The initial setup is difficult. For example, in Android, if I need to scan an ordinary APK Android application, we need to generate the APK and when you are working in GitHub, you need to do a lot of work to make these combinations able to be scanned by Veracode.
What about the implementation team?
We did the implementation ourselves.
Which other solutions did I evaluate?
I have previously evaluated Checkmarx.
What other advice do I have?
The solution is good at finding issues and provide some very useful tools. I would advise those wanting to implement this solution to purchase professional support from the vendor. If you do not, you run the risk of having many problems such as the ones we have faced.
The DAST tool is very useful and is used in preproduction.
I rate Veracode a six out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Project Manager at a computer software company with 501-1,000 employees
Comprehensive features and good integrations but needs better documentation
Pros and Cons
- "It's comprehensive from a feature standpoint."
- "The reports on offer are too verbose."
What is most valuable?
The SAST feature is the most valuable aspect of the solution.
The stability has been quite good overall. The performance is reliable.
The scalability on offer is good. I don't see any constraints.
From a usability standpoint and the way it can be integrated into the pipelines, etc., it's very good.
It's comprehensive from a feature standpoint.
What needs improvement?
The reports on offer are too verbose. They might want to consider t restructuring their reports to better give a very good summary or overview in the first five or so pages and then go ahead and drill into the details of each and every vulnerability beyond that.
The documentation could be improved. They could, for example, provide more details in terms of how to fix issues related to sign-ups. There isn't enough detailed information out there to assist users.
For how long have I used the solution?
I joined this company very recently. Therefore, I've only used the solution for a few months. However, this company has used Veracode for at least the last two to three years. They've had it for a while.
What do I think about the stability of the solution?
The stability overall is quite reliable. There are no bugs or glitches. It doesn't crash or freeze. Its performance is very good.
What do I think about the scalability of the solution?
The solution can scale well. If a company is considering expanding, it should be able to do so without issue.
We do have a limited amount of users on the solution right now.
How are customer service and technical support?
I've never had a need, up to this point, to reach out to technical support. I haven't really come across any technical issues during my short tenure with the product. Therefore, I can't speak to how helpful or responsive they are. I don't have any insights I could share.
How was the initial setup?
We have a few team members that specialize in the solution.
Our team handles the maintenance of the solution.
What's my experience with pricing, setup cost, and licensing?
I don't have enough information to be able to comment on the cost of licensing the product. That's more of a sales question. I don't handle any aspect of that part of the solution.
What other advice do I have?
We are customers and end-users. We don't really have a business relationship with Veracode.
I'm more from the performance testing side of things. I've just added the security testing to my list of responsibilities recently.
We're using a mix of deployment models. We use both on-premises and cloud deployments.
It's a good tool. I've done some comparisons with both SAST and DAST. It gives us this end-to-end sort of feature that we appreciate. Therefore, rather than you doing SAST with one tool and DAST with another tool, I prefer going with Veracode, which offers both.
You can learn both static and dynamic scans with a single tool. You could effectively negotiate a price and do that. If you got some simple apps, from a CAC standpoint, I'd recommend folks to use Veracode.
I'd rate the solution at a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Executive Officer at Cybrella
Deployment was easy, configurable, and simple to manage
Pros and Cons
- "The installation was straightforward."
- "There needs to be better API integration to the development team's pipeline, which is something that is missing and needs to be improved."
What needs improvement?
There needs to be better API integration to the development team's pipeline, which is something that is missing and needs to be improved.
For how long have I used the solution?
We have been using the solution for approximately three months.
How was the initial setup?
The installation was straightforward.
What other advice do I have?
I rate Veracode Manual Penetration Testing a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder & CEO at a healthcare company with 1-10 employees
Easy to install, stable, scalable, and they have phenomenal and responsive support
Pros and Cons
- "My experience with Veracode across the board every time, in all products, the technology, the product, the service, and the salespeople is fabulous."
- "The pricing for qualified startups such as Neo4j could be improved."
What is our primary use case?
We use this solution for Digital Health.
How has it helped my organization?
This solution has helped us in developing a secured product.
What is most valuable?
Veracode is fantastic! All of the features are valuable.
My experience with Veracode across the board every time, in all products, the technology, the product, the service, and the salespeople are fabulous. They are engaging.
What needs improvement?
I would suggest charging the developer for training, as it's not very expensive.
Only charge for developer training because it's a service you give now and they may need to be technical support.
It costs them money to do that, but with the technology, an incremental user is negligible incremental costs, which doesn't really cost them. That's software economics.
I would like to see them only charge for developer training for the qualified startups and start charging for the licensing once the product goes into production, and available.
For how long have I used the solution?
I have several years of experience working with Veracode.
When we used this solution a year ago, we used the most current version.
What do I think about the stability of the solution?
It's a stable solution. I would rate stability a ten out of ten.
What do I think about the scalability of the solution?
It's a scalable product. My rating out of ten would be a ten, scalability-wise.
We have a software development manager and three other people who are using it.
How are customer service and technical support?
Technical support is phenomenal. They are fabulous and very responsive, it's amazing.
Which solution did I use previously and why did I switch?
Previously, I did not use another solution. Because I knew Veracode for many years, my approach with the company was that it was a startup and we need to do it securely. This is s why we went with Veracode.
How was the initial setup?
The initial setup was straightforward. It was extremely easy and took only a few hours to deploy.
What about the implementation team?
We have a team in-house to implement this solution.
What's my experience with pricing, setup cost, and licensing?
The pricing for qualified startups such as Neo4j could be improved.
It allows startups to develop a secure product, but it takes time for startups to get money for the products.
Veracode could provide the services, at a significantly lower price during that period with a condition that the moment that it becomes production, Veracode has to be paid.
If they would change that, it would be phenomenal for the entire industry and for them.
Licensing cost is on a yearly basis and there are no additional costs, the pricing is straightforward.
What other advice do I have?
At the time that we used this solution, we were a startup, the software may not have been that complex. It's not like Oracle.
My advice to others who are interested in using this solution is to pay attention to the full instructions.
I would rate Veracode Developer Training a ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Container Security Software Composition Analysis (SCA) Static Code Analysis Dynamic Application Security Testing (DAST) Application Security Posture Management (ASPM)Popular Comparisons
SonarQube
Snyk
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
Checkmarx One
GitLab
CrowdStrike Falcon Cloud Security
Coverity Static
Black Duck SCA
JFrog Xray
Orca Security
GitHub Advanced Security
Acunetix
Mend.io
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Which gives you more for your money - SonarQube or Veracode?
- Checkmarx or Veracode. Which should we choose?
- Would you recommend Veracode? What are some of your use cases?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- What do I scan when changing code in Veracode?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?
















