No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1345386 - PeerSpot reviewer
Senior Software Developer at a pharma/biotech company with 201-500 employees
Real User
Dec 4, 2020
A robust and full-featured solution that provides a good analysis of the vulnerabilities
Pros and Cons
  • "The analysis of the vulnerabilities and the results are the most valuable features."
  • "It pointed out some areas to be improved that we were not aware of, which was very helpful because if you don't know that there is a problem, you can't fix it."
  • "It can have more APIs and capabilities to handle other things well. We were doing a trial for it. There were two things that I looked at: one was uploading some Java-related content and the other was uploading database SQL files and having the review done on the quarterback. The Java portion of it worked fine, and it was pretty seamless, but the database portion was not. We uploaded some files to use for vulnerabilities, and the tell-all portion of it was pretty easy. We uploaded a war file and Java files, and we got the reports back on these. They were pretty clear to understand. We did the same thing for the database portion for the most part. However, the content wasn't getting uploaded in a predictable fashion, and it was slow and hard to get done. We had to do it over and over. After it indicated that the content was uploaded, there were no results. There were zero search findings. It was possibly a user error, something that we didn't do correctly, but they had acknowledged that it was something they were currently enhancing. This is something that could be made easier if they haven't already done that. I don't know how many releases they've had in that timeframe. I haven't looked at it since then. It was a trial period."
  • "However, the content wasn't getting uploaded in a predictable fashion, and it was slow and hard to get done."

What is our primary use case?

We used it for initial discovery and analysis and for reviewing the product. We were doing a trial. We had uploaded code on the Veracode server for analysis.

We used the cloud service or the cloud website where you could interact and identify the artifacts that you wanted to be reviewed, analyzed, and reported on. There was a plugin that we used with some of our IDs. It probably was Greenlight.

How has it helped my organization?

It pointed out some areas to be improved that we were not aware of. That was very helpful because if you don't know that there is a problem, you can't fix it.

What is most valuable?

The analysis of the vulnerabilities and the results are the most valuable features.

What needs improvement?

It can have more APIs and capabilities to handle other things well. We were doing a trial for it. There were two things that I looked at: one was uploading some Java-related content and the other was uploading database SQL files and having the review done on the quarterback. 

The Java portion of it worked fine, and it was pretty seamless, but the database portion was not. We uploaded some files to use for vulnerabilities, and the tell-all portion of it was pretty easy. We uploaded a war file and Java files, and we got the reports back on these. They were pretty clear to understand. We did the same thing for the database portion for the most part. However, the content wasn't getting uploaded in a predictable fashion, and it was slow and hard to get done. We had to do it over and over. After it indicated that the content was uploaded, there were no results. There were zero search findings. It was possibly a user error, something that we didn't do correctly, but they had acknowledged that it was something they were currently enhancing. This is something that could be made easier if they haven't already done that. I don't know how many releases they've had in that timeframe. I haven't looked at it since then. It was a trial period.

Buyer's Guide
Veracode
April 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,244 professionals have used our research since 2012.

What do I think about the stability of the solution?

It seemed fairly stable other than the database portion where the SQL files didn't seem to get uploaded.

What do I think about the scalability of the solution?

I didn't think there would be any concerns. We didn't exercise that. We didn't, in other words, try to upload gazillion artifacts and files. We just uploaded a few just to see how they handle it. It seemed fairly robust.

There were about ten Java and database developers who were using this solution. We were all collectively reviewing it and getting feedback on it.

How are customer service and support?

We didn't use their technical support.

Which solution did I use previously and why did I switch?

There was no other solution.

How was the initial setup?

I wasn't that involved in the setup. I was basically a reviewer after it was all done.

What about the implementation team?

I don't think there was any in-house work. I think it was just all on their server. We didn't have any equipment or any software per se other than just downloading a plugin or IDE, which essentially did the same sort of code analysis.

What's my experience with pricing, setup cost, and licensing?

Its cost for what we needed it for was too high. It wasn't too high for other companies and it was competitively priced, but for us, it just didn't fit. We did plan to use it and increase the usage. In the end, it may have been abandoned because of the cost, but I'm not a hundred percent sure. So, even though we had planned on using it more and more, because of the cost and the business conditions of things, we didn't have the opportunity to really use it more.

Which other solutions did I evaluate?

There were a few other solutions we had looked at, but they didn't seem to be as robust. They also didn't have good reviews. That's why we chose this solution.

What other advice do I have?

It is a robust software service for security analysis. It seemed to be pretty full-featured. We didn't exercise every single thing. Just a few of the features didn't seem to be up to snuff for our needs.

I would rate Veracode Manual Penetration Testing an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Raj Nachiappan - PeerSpot reviewer
Director of Solutions Architecture at VetsEZ
Real User
Jul 29, 2020
Easy to set up and it helps ensure that our code is secure
Pros and Cons
  • "The most valuable feature is the dynamic application security testing."
  • "In summary, I think that this is a good tool and I recommend it for helping with security in software development."
  • "In the future, I would like to see the RASP capability built-in."
  • "It takes a while to get a response to the software composition analysis. It is within an acceptable range but it could still be improved."

What is our primary use case?

We use Veracode to ensure that the software we are building is secure.

What is most valuable?

The most valuable feature is the dynamic application security testing.

What needs improvement?

It takes a while to get a response to the software composition analysis. It is within an acceptable range but it could still be improved.

In the future, I would like to see the RASP capability built-in.

For how long have I used the solution?

We have been using Veracode SCA for three months.

What do I think about the stability of the solution?

SCA is pretty stable.

What do I think about the scalability of the solution?

Scalability doesn't really apply to a software composition analysis tool.

How are customer service and technical support?

The technical support is pretty good. When I requested help they contacted me within an hour. I don't have any issues with them.

How was the initial setup?

The initial setup is pretty straightforward.

What other advice do I have?

In summary, I think that this is a good tool and I recommend it for helping with security in software development.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Veracode
April 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,244 professionals have used our research since 2012.
reviewer1359297 - PeerSpot reviewer
Software Engineer at a financial services firm with 501-1,000 employees
Real User
Jun 2, 2020
Source composition analysis component gives our developers comfort in using new libraries
Pros and Cons
  • "The source composition analysis component is great because it gives our developers some comfort in using new libraries."
  • "The source composition analysis component is great because it gives our developers some comfort in using new libraries."
  • "I think for us the biggest improvement would be to have an indicator when there's something wrong with a scan."
  • "The Veracode platform probably hasn't improved our organization overall, although through no fault of theirs."

What is our primary use case?

This was intended to scan all of our custom development efforts to ensure a certain level of (secure) code quality. Right now the scope of that effort is limited to web exposed systems but with maturity, we hope to increase that scope.

How has it helped my organization?

The Veracode platform probably hasn't improved our organization overall, although through no fault of theirs. Veracode is just one more tool that generates work for our developers.

What is most valuable?

The source composition analysis component is great because it gives our developers some comfort in using new libraries.

What needs improvement?

I think for us the biggest improvement would be to have an indicator when there's something wrong with a scan. For instance, we have CI scans that run automatically, and sometimes the files don't get upload and/or processed by Veracode. Now, there's a static scan that hasn't been completed, which blocks all future scans. The only way we know this is an issue is going into the Web UI, check each application, and look for stalled scans. This is time-consuming and frustrating.

For how long have I used the solution?

I have been using Veracode for three years.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1360623 - PeerSpot reviewer
VP Engineering at a tech services company with 201-500 employees
Real User
Jun 2, 2020
Source code composition analysis helps with vulnerabilities and license compliance
Pros and Cons
  • "Veracode is a valuable tool in our secure SDLC process."
  • "Source code composition analysis for vulnerabilities and license compliance is the most valuable feature."
  • "It needs better controls to include/exclude specific sections when creating a report that can be shared externally with customers and prospects."
  • "It needs better controls to include or exclude specific sections when creating a report that can be shared externally with customers and prospects."

What is our primary use case?

Our primary use cases are for comprehensive security assessment using static analysis, dynamic analysis, source code composition, and manual penetration tests. We also use it for security training for developers.                         

How has it helped my organization?

Veracode is a valuable tool in our secure SDLC process.                                                        

What is most valuable?

Source code composition analysis for vulnerabilities and license compliance is the most valuable feature.                                                                                                 

What needs improvement?

It needs better controls to include/exclude specific sections when creating a report that can be shared externally with customers and prospects.  

For how long have I used the solution?

I have been using Veracode for one year.

Which other solutions did I evaluate?

We also evaluated Synopsys.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Enterprise Architect at a computer software company with 1-10 employees
Real User
Mar 17, 2020
Excellent article scanning, good data support and great analysis
Pros and Cons
  • "The article scanning is excellent."
  • "The article scanning is excellent, the composition analysis and common CBEs attached to it are quite good, and the solution offers a lot of really great analysis with lots of good data support."
  • "The documentation is poor and the technical support isn't helpful."
  • "Their documentation is awful and their response time wasn't ideal."

What is our primary use case?

We primarily use the solution for article scanning.

What is most valuable?

The article scanning is excellent. 

The composition analysis and common CBEs attached to it are quite good.

The solution offers a lot of really great analysis. There's lots of good data support.

What needs improvement?

The licensing model could be improved. 

If they can provide an automatic upload model, that would be really good. Right now we have to upload the NK bucket hosting to get through the analysis. That is kind of cumbersome.

The documentation is poor and the technical support isn't helpful.

For how long have I used the solution?

We've been using the solution for three or four years.

What do I think about the scalability of the solution?

We don't plan on increasing usage. We are a product company. We have three products that are built. All of them go through this solution. We are not a services company. 

We have about 80 people on the solution currently. They are all developers.

How are customer service and technical support?

We did previously reach out to technical support. When we had to set up all of the automation, we contacted them for assistance. Their documentation is awful and their response time wasn't ideal.

How was the initial setup?

The initial setup was not complex. It was pretty straightforward. However, the integration and automation of the CI cloud was a nightmare. 

Deployment varies. sometimes it takes three months. Sometimes it only takes one hour. The average is one hour, but we have experienced much, much longer deployment times.

What's my experience with pricing, setup cost, and licensing?

I have no idea what the licensing costs on the solution are. Our IT team handles the details.

What other advice do I have?

We were part of the initiation when the company started. They introduced it and we began using the solution. We're just a customer.

For those companies hoping to automate the solution, I would not recommend it. It's too difficult for those heavily dependant on automation. However, for those companies who want to manually use it, I can recommend the solution. In those cases, it's easy to use even if you won't build it as a part of your automation test tools or on any internet server.

I'd rate them eight out of ten. I'd rate them higher, but they have bad automation and terrible documentation. Other than that, they are very good.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1258986 - PeerSpot reviewer
Enterprise Architect, VP at a financial services firm with 501-1,000 employees
Real User
Mar 17, 2020
Enables us to identify potential problems in applications and fix them before they are used in ways they should not be but has false positives
Pros and Cons
  • "This is a great tool for learning about potential vulnerabilities in code."
  • "The product helped improve our organization by helping us to identify potential problems in applications and fix them before they were used in a way that they should not be, and in essence, it helped enhance our security."
  • "There were some additional manual steps or work involved that we should not have needed to do."
  • "There were some additional manual steps or work involved that we should not have needed to do."

What is our primary use case?

The primary use case for us was looking for web applications that might have vulnerabilities that could be compromised. Specifically, I was managing a team and we had built a lot of applications as well as having purchased applications from vendors. We were working with a security team to go through and scan those applications for vulnerability using Software Composition Analysis. We were trying to avoid situations where somebody could do something that they should not be able to do like get at data.  

How has it helped my organization?

The product helped improve our organization by helping us to identify potential problems in applications and fix them before they were used in a way that they should not be. In essence, it helped enhance our security. I think another thing is that it did is it did kind of helped us with the general education level of staff working on the projects. Developers or technical stakeholders specifically were presented with the opportunity to understand things that maybe they did not before.  

We were not doing the training piece of the process when we were onboarding the product, but just adopting the platform definitely increased their awareness and knowledge about potential issues in development and application vulnerabilities.  

What is most valuable?

One of the best things about the solution is that I think it is kind of easy to get started using it. The pain of adoption is low. Once you got the code scanned, there is a lot of information that you have to plan time to go through and work with other teams to get things resolved or disposition.  

I think that it was easy to get started, but there was also definitely a learning curve in terms of people needing to understand what the reports meant and what to do about the information that they were getting.  

What needs improvement?

There is a concept called false positives where things might come up as a potential issue but they really are not. In our case specifically, we might get a false positive when a potential vulnerability is discovered through Veracode analysis, but the way that the application is built makes it so what appears to be a vulnerability is not really an issue. Stated a different way, even though there might be something that prevents that particular event from ever happening, the product does not correctly detect the safeguards or the impossibility of the issue arising.  

When a false positive gets reported by the Composition Analysis, it results in more work for you to do than you should have to. There is a lot of information to go through and so some of it is due to those false positives. You either have to do work to eliminate the false positives being identified, or you have to look at the alert and determine that it is harmless.  

As far as what might be added in future releases, more artificial intelligence capabilities would be desirable. I do not know if they have it now. Maybe one example could be to make more focused suggestions or give more information in the reports to locate the cause of the issues. It should be something that improves results over time so that people do not have to do as much work to understand the details.  

For how long have I used the solution?

I have been using Veracode Software Composition Analysis for probably around three years.  

What do I think about the stability of the solution?

I would say it is definitely stable. There were no problems with the platform itself. It has been reliable. We never had issues where we needed to call support.  

What do I think about the scalability of the solution?

I think the opportunities for scalability are good because we did not come upon issues that caused us to wonder about its limitations. We have not really pressed to find scalability problems. So my impression is that scalability is good. We did not experience issues due to bottlenecks or anything like that.  

Our group of users contained a mix of roles. It was developers, project managers, testers, information security analysts, and engineers. It was probably a total of around 30 to 40 people.  

For deployment and maintenance, there were really just like a couple of people. There was not a full-time dedicated need for it.  

How are customer service and technical support?

There were times when we had to deal with support when we ran scans and we were reviewing results. There were times when we needed to either open a ticket or talk to somebody who had some expertise in a specific area. That process was timely and they were responsive. So that was good.  

Veracode actually has a separate subscription that you can participate in that is something like a learning management catalog. I think that the training piece of support has definitely improved over the course of when we used it.  

Which solution did I use previously and why did I switch?

We did have a different product, but it was a little bit for a different purpose. We were using a different product but complemented the Veracode product. 

How was the initial setup?

The initial setup was pretty straight forward. That is part of it being an easy solution to get started with.  

The deployment started smaller in employing the product to analyze a subset of our applications. It initially was being employed to look at the vendor applications that we had. I would probably say that initial period was about three to six months. That effort was focused on one group and did not really include all of the technical people and developers.  

Once we saw what it could do, it got adopted and we rolled it out to more people. So we kind of employed it in stages. The first part, which was essentially a test period, was three to six months. Then pushing it out for broader adoption in the next part was another three to six months.  

What about the implementation team?

We did not use integrators. We did have the training and we did have professional services in the form of customer support from Veracode.  

What's my experience with pricing, setup cost, and licensing?

I do not remember the licensing costs off hand. I would probably estimate it to be between 50,000 to 75,000 in our case.  

What other advice do I have?

The advice that I would have for people who are new to the product would be to start with a proof of concept. This will help you to see how the product works with your process and people.  

The biggest lesson I have learned from using this solution is that it definitely increased my education on how to prevent application vulnerabilities earlier on and how not to repeat them. It also helped me as a manager to better understand how to guide and coach people.  

On a scale from one to ten where one the worst and ten is the best, I would rate this product probably as a  seven, if I am going back in time. I thought that there was room for improvement, but at the same time, it did what we needed it to do. We got what we expected. So I thought it was good, but I also think there were some additional manual steps or work involved that we should not have needed to do. That is really why I do not rate it with a higher number.  

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1227297 - PeerSpot reviewer
Sr Director at a non-profit with 51-200 employees
Real User
Mar 10, 2020
Stable with good technical support and a moderately easy implementation process
Pros and Cons
  • "The solution is stable. we've never had any issues surrounding its stability."
  • "The solution is stable, we've never had any issues surrounding its stability."
  • "The cost of the solution is a little bit expensive. Expensive in the sense that there was a hundred percent increase in cost from last year to this year, which is certainly not justified."
  • "The solution recently doubled in price over the past year, which is why I've decided to move away from it."

What is our primary use case?

The primary use case was scanning a single-digit number of applications. We scanned them about twice a year and that's about it. It was just to get the results. We used the results to gauge our security health.

What is most valuable?

The feature that was most valuable to us was the ability to point locally in a quorum.

What needs improvement?

The cost of the solution is a little bit expensive. Expensive in the sense that there was a hundred percent increase in cost from last year to this year, which is certainly not justified. 

The solution needs to be more flexible. It needs to work with clients more effectively. 

Right now, the licensing model is based on the number of applications as opposed to being flexible and based on the number of developers or based on some other parameters. This constrains our company in terms of defining what an application is and doing the scans. We have an application with multiple deposit rates, but Veracode has a hard time recognizing the different components sitting in different depositories as one application. 

The solution is pretty similar to others. There wasn't anything that was so startlingly different it would make us want to stay.

For how long have I used the solution?

I had been using the solution for a while, but I am currently in the process of moving off of it.

What do I think about the stability of the solution?

The solution is stable. we've never had any issues surrounding its stability.

What do I think about the scalability of the solution?

There's nothing to scale. Asking if the solution is scalable or not isn't applicable in this case. It's not an active load balancer. It's just a static scan. If it was dynamic, there may be a question around scalability, but it is not.

How are customer service and technical support?

Technical support team is quite good. However, if we're talking in terms of how Veracode recognizes clients and deals with them, I'd rate them as bad.

Which solution did I use previously and why did I switch?

We did not previously use a different solution. We've only used Veracode.

How was the initial setup?

The initial setup has a moderate level of difficulty. It's neither simple or complex.

What about the implementation team?

We handled the implementation ourselves.

What's my experience with pricing, setup cost, and licensing?

The solution recently doubled in price over the past year, which is why I've decided to move away from it. The price jump doesn't make sense. It's not like there was a sudden influx in new features or advancements.

Without getting too specific, I'd say the average yearly cost is around $50,000. The costs include licensing and maintenance support.

What other advice do I have?

I handle software composition analysis. Currently, I'm moving away from Veracode.

I don't know which version of the solution I am using currently. It's not quite the most up-to-date version.

If a company is looking for a long-term partner, and not just a transactional solution, I'd suggest a different company.

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1276710 - PeerSpot reviewer
Associate Consultant at a comms service provider with 201-500 employees
Consultant
Feb 11, 2020
Efficient at finding vulnerabilities but the number of false positives should be reduced
Pros and Cons
  • "The most valuable feature is the efficiency of the tool in finding vulnerabilities."
  • "The most valuable feature is the efficiency of the tool in finding vulnerabilities."
  • "A high number of false positives are reported and this should be reduced."
  • "A high number of false positives are reported and this should be reduced."

What is our primary use case?

I am a consultant and SourceClear is one of the solutions that I use to provide services.

This solution is used by people who want to verify the security of their own applications.

What is most valuable?

The most valuable feature is the efficiency of the tool in finding vulnerabilities.

What needs improvement?

A high number of false positives are reported and this should be reduced.

For how long have I used the solution?

I have been using SourceClear for about a year and a half.

What do I think about the stability of the solution?

This is a stable solution.

What do I think about the scalability of the solution?

We have no complaints about scalability. We have between 200 and 300 clients.

How are customer service and technical support?

We have not been in touch with Veracode's technical support.

Which solution did I use previously and why did I switch?

We have also used Checkmarx, where you can train the tool for false positives and ultimately reduce them.

How was the initial setup?

The initial setup is a little bit complex.

What about the implementation team?

It would be better to have some assistance when implementing this solution.

What other advice do I have?

Overall, SourceClear is working fine for us and our main complaint is in regard to the high number of false positives. Nonetheless, I would recommend Checkmarx over SourceClear.

I would rate this solution a six out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2026
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.