We are planning on introducing a static code analysis tool to support a DevOps effort in our environment. The objective of the solution is to allow the team to identify vulnerabilities in the source code and improve the hygiene of the developed code before deployment.
Managing Director at Harrods
Provides the capability to track remediation and the handling of identified vulnerabilities. The application does not support API or Dynamic Application Security Testing
Pros and Cons
- "Allows us to track the remediation and handling of identified vulnerabilities."
- "Provides the capability to track remediation and the handling of identified vulnerabilities."
- "The security team can track the remediation and risk acceptance statistics."
- "The solution does not support Dynamic Application Security Testing."
- "The current version of the application does not support testing for API."
What is our primary use case?
How has it helped my organization?
This is currently still under evaluation, and it is pending review and assessment against other static code analysis solutions.
What is most valuable?
The solution provides the capability for the application teams to track remediation and the handling of identified vulnerabilities. The system provides workflow capabilities for the application teams to send the completed scans to the security teams for their review. In addition, the security team can track the remediation and risk acceptance statistics.
What needs improvement?
The solution currently does not support Dynamic Application Security Testing which is an important facet of application security testing. In addition, the current version of the application does not support testing for API.
Buyer's Guide
Veracode
March 2025

Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
845,485 professionals have used our research since 2012.
For how long have I used the solution?
Trial/evaluations only.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Head IT Architecture at a tech vendor with 11-50 employees
Enables us to perform security checks with ease
Pros and Cons
- "We used it for performing security checks. We have many Java applications and Android applications. Essentially it was used for checking the security validations for compliance purposes."
- "One of the things that we have from a reporting point of view, is that we would love to see a graphical report. If you look through a report for something that has come back from Veracode, it takes a whole lot of time to just go through all the pages of the code to figure out exactly what it says. We know certain areas don’t have the greatest security features but those are usually minor and we don’t want to see those types of notifications."
What is our primary use case?
We used it for performing security checks. We have many Java applications and Android applications. Essentially it was used for checking the security validations for compliance purposes.
How has it helped my organization?
Technically there is nothing wrong with Veracode. The only issue that we have here is uploading the code, the process of actually uploading and getting our results back. All of that is a little cumbersome.
What needs improvement?
Technically there is nothing wrong with Veracode. The only issue that we have is uploading the code, the process of actually uploading and getting our results back. All of that is a little cumbersome.
One of the things that we have from a reporting point of view, is that we would love to see a graphical report. If you look through a report for something that has come back from Veracode, it takes a whole lot of time to just go through all the pages of the code to figure out exactly what it says. We know certain areas don’t have the greatest security features but those are usually minor and we don’t want to see those types of notifications. So we would like to see a kind of a graphical representation of the problem areas. I would like to know which file is the biggest source of issues for me so that I can focus on resolving the issue, as a project manager. With how it is now, I am able to do this but I have to take out the whole PDF file and extract it. It takes up a lot of my time. I would like to see better strategic reporting. It would be great to get better graphical reporting.
For how long have I used the solution?
We have been using it for three years.
What do I think about the stability of the solution?
Stability is very good and there were no issues. I will give it five stars.
What do I think about the scalability of the solution?
It's very good; really very good. I would strongly recommend that. Technically I would be expecting a double concept for Veracode. I would still say this is one of the best products ever on that website. I don't have any issues with the scalability.
How are customer service and technical support?
I had no technical issues at all.
How was the initial setup?
The initial setup can be a little complex for people or for organizations that don't have technical skills. Another small thing is that you need to have one person who's fluent and technically knowledgeable to help during the upload process. But otherwise, it's pretty much straightforward. It's not an issue, it's perfect.
What other advice do I have?
I would strongly recommend doing an internal analysis first, before setting it across to Veracode to proceed and to use it more as a final verification point. My point is that Veracode is very good, and I would strongly recommend it. I have seen other solutions on the market and that's why I say: don't waste your time on other products, just get Veracode.
I would rate it an eight out of ten. Not a ten because of the reporting issues I mentioned that I would like to see improved.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Veracode
March 2025

Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
845,485 professionals have used our research since 2012.
AVP, IS Manager at a financial services firm with 1,001-5,000 employees
Substantially reduces the number of unmitigated flaws in our code
What is our primary use case?
We use Veracode to scan custom-developed code for flaws.
How has it helped my organization?
- The volume of unmitigated flaws in our applications has been substantially reduced.
- In terms of AppSec best practices, the team at Veracode has provided industry benchmarks against which we are measuring our improvement.
- Our customers have benefited from the added security assurance of our applications, although they may not know it.
What is most valuable?
The identification of flaws.
What needs improvement?
We would like to see improvement in reporting, in particular, end dates on mitigations.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
It has handled all the expansion we have required from it.
How is customer service and technical support?
Technical support is highly competent.
How was the initial setup?
It was already implemented when I joined the organization. However, we have expanded greatly.
What's my experience with pricing, setup cost, and licensing?
We are about to enter discussions for renewal. I have heard there may be some changes to pricing. I will reserve judgment until the discussions are complete.
What other advice do I have?
I would recommend it. It covers all our custom-developed applications and will expand as new applications and services are added.
We have 50-plus users of Veracode. Their roles include InfoSec, developers, development managers, QA, and configuration management. In terms of deployment and maintenance, we have four people in configuration management and InfoSec.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Architect of solutions at IPComMx
Utilized for scanning containers and integrated within DevOps workflows
Pros and Cons
- "The coverage of backdoors attacks on security that's the most valuable for my clients."
- "There is room for improvement in documentation."
What is our primary use case?
We used Barracuda for scanning containers. And in all in DevOps workflow.
What is most valuable?
The coverage of backdoors attacks on security that's the most valuable for my clients.
What needs improvement?
There is room for improvement in documentation. Maybe the documentation about how to configure something. It is difficult to get the expected result.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the stability of the solution?
It's stable. It works very well in the parameter like an enterprise solution. We don't have any problems with that.
How are customer service and support?
We are very pleased with the support.
How would you rate customer service and support?
Positive
How was the initial setup?
I would rate my experience with the initial setup a six out of ten, where one is difficult and ten is easy to set up.
What about the implementation team?
We work on the deployment process. The solution is deployed both on-prem and in the cloud environment.
The solution doesn't require any maintenance.
What was our ROI?
It took two years to see ROI for our clients.
What's my experience with pricing, setup cost, and licensing?
Veracode is expensive. But the solution is worth it.
What other advice do I have?
Overall, I would rate the solution a nine out of ten. It is a good solution for security. In my personal opinion, there are not many products like Veracode in the market.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
DevOps and Cloud Architect at a marketing services firm with 51-200 employees
Great for automatic penetration testing and providing the ability to investigate problems
Pros and Cons
- "Provides the ability to understand the black zones in our system."
- "Security can always be improved."
What is our primary use case?
I'm the manager of DevOps and cloud architecture.
How has it helped my organization?
This product has given us the ability to investigate and understand the black zones in our system.
What is most valuable?
Veracode can emulate the most sophisticated attack and create unique or specific use cases around automatic penetration testing. It gives us the ability to investigate any sensitivities to vulnerabilities that we may have.
What needs improvement?
Security can always be improved. I'd like to know how we can better prevent intrusions to our systems and create risk analysis use cases and understand them. What is the level of risk for what we want to do? How can we understand the process better? I'd like to have a better overview of what's going on.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
There are three layers of technical support and we have used all of them over time. We are happy with the service they provide.
What other advice do I have?
It's important to understand your environment and know the specific use cases for your organization. Creating good orchestration application metrics is very important.
I rate this product eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director of Solutions Architecture at VetsEZ
Penetration Testing solution used by development team for static code analysis
Pros and Cons
- "Our development team use this solution for static code analysis and pen testing."
- "The runtime code analysis could be improved so that we can see every element in one place."
What is our primary use case?
Our development team use this solution for static code analysis and pen testing.
What needs improvement?
The runtime code analysis could be improved so that we can see every element in one place.
For how long have I used the solution?
I have used this solution for two years.
What other advice do I have?
I would rate this solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Compliance Officer at a financial services firm with 51-200 employees
Ad-hoc scanning during the development cycle, reporting for audits, are key features
Pros and Cons
- "Ad-hoc scanning during the development cycle and reports for audits are valuable features."
- "I would like to see these features: entering comments for internal tracking; entering a priority; reports that show the above."
What is our primary use case?
We test each major release of our software using Veracode static and dynamic testing. We also do manual penetration testing annually.
How has it helped my organization?
Ensures our code and system are 100% compliant. In terms of APPSec best practices and guidance to our team, the Knowledgebase available on the Veracode system is a great resource for our developers.
For our customers, the added security assurance is a requirement.
What is most valuable?
- Ad-hoc scanning during the development cycle
- Reports for audits
In terms of integrating Veracode into our existing software development lifecycle, there are regular milestones in the SDLC to perform Veracode scans.
What needs improvement?
- Entering comments for internal tracking
- Entering a priority
- Reports that show the above
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No issues with stability.
What do I think about the scalability of the solution?
No issues with scalability.
How are customer service and technical support?
Excellent.
Which solution did I use previously and why did I switch?
We did use a previous solution. It didn't satisfy our needs technically, and the customer service and its cost were not satisfactory.
How was the initial setup?
Easy.
What was our ROI?
We don't do a detailed enough analysis to reflect on any cost savings relating to code fixes made since we implemented Veracode.
What's my experience with pricing, setup cost, and licensing?
Negotiate some, but their prices are reasonable.
Which other solutions did I evaluate?
HPE Fortify.
What other advice do I have?
Have them guide you through your first scan - make sure to add hours to your initial contract for that.
I am very likely to recommend Veracode to colleagues.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Information Technology at a insurance company with 51-200 employees
Give us insight into code without having to upload it, saving a lot of NDA paperwork
Pros and Cons
- "Veracode static analysis allows us to pinpoint issues - from a simple hard-coded test password, to more serious issues - and saves us lot of time. For example, it raises a flag about a problematic third-party DLL before development invests time heavy using it."
- "It is great to have such insight into code without having to upload the source code at all. It saves a lot of NDA paperwork. The Visual Studio plugin allows the developer to seamlessly upload the code and get results as he works, with no manual upload. The code review function is great. It allows you to find flaws in source code."
- "It can take time to find options if you don’t use the interface a lot. At some point, a bit of interface restyling may help."
What is our primary use case?
We test two mission-critical web applications (C# Web forms).
How has it helped my organization?
We used to revise code with free tools (like VCG) but they are not even in the same universe. Veracode static analysis allows us to pinpoint issues - from a simple hard-coded test password, to more serious issues - and saves us lot of time. For example, it raises a flag about a problematic third-party DLL before development invests time heavy using it.
Also, from the very relevant results and issues that were pinpointed by Veracode, I can say that our customer security was greatly enhanced by its use.
What is most valuable?
It is great to have such insight into code without having to upload the source code at all. It saves a lot of NDA paperwork. The Visual Studio plugin allows the developer to seamlessly upload the code and get results as he works, with no manual upload. The code review function is great. It allows you to find flaws in source code, but the source code never leaves your workstation, it is all client side, no NDA needed.
What needs improvement?
It can take time to find options if you don’t use the interface a lot. At some point, a bit of interface restyling may help (but not now, now that I've learned it).
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No, we did not detect a single glitch or fault in a year. We once had a periodic maintenance activity on the Veracode platform during a deadline, but it was clearly announced in advance, so we just went around it and had no issues.
What do I think about the scalability of the solution?
No, you don’t have such concerns on Veracode. The process is really "launch and forget" (and wait for results).
How are customer service and technical support?
The team that assists us with it is just great, especially considering there is a language barrier for some of our employees. Veracode did its best to get those employees in the loop with the chance to attend the meeting, as well with the aid of written English.
Which solution did I use previously and why did I switch?
VCG (Visual Code Grepper) but I am not even going to compare them. VCG is as good as they come, but Veracode is a different breed. An application went through VCG and we were pretty confident. Then, Veracode results just blew us out of our shoes.
How was the initial setup?
I manage the Veracode suite for my company, and I was personally walked through the various steps. Once I was up and running, we had another two-hour session to explain to us how a proper Veracode assessment should be planned (developers, code reviewers). As a result, I believe we have not only a pretty solid code review process up and running, but this was all provided to us at no additional cost.
What we felt is that the Veracode guys want to enjoy and use their solution first. They are not pushing to get consultancy time if that can be avoided. If you need consultancy time you can have it and the prices are convenient. We did not. All the help came at no additional cost.
What was our ROI?
It is difficult to assert, but it helps a lot with maintaining compliance with our main customers, and helps us to pinpoint some specific issues. The cost of not having Veracode would be pretty high for us.
What's my experience with pricing, setup cost, and licensing?
The licensing and prices were upfront and clear. They stand behind everything that is said during the commercial phase and during the onboarding phase. Even the most irrelevant "that can be done" was delivered, no matter how important the request was.
The licensing is fair, it is time-limited (e.g. one year) but there is a size cap for every app. If your applications are big (due third-party libraries, for example) you should discuss this beforehand and explore suitable agreements.
Which other solutions did I evaluate?
Competitors were evaluated but seemed, at once, too bloated or not relevant to all our specific requests. We were not interested in buying a product (such as a standalone program) rather we were interested in getting a tool for creating a process, and Veracode is that.
What other advice do I have?
In terms of integrating Veracode into our existing software development lifecycle, as our two existing applications are quite mature, and not changed often, we have not taken steps to have Jenkins or another CI tool that would allow us to get the full power from the Veracode environment. We look forward doing it, starting with the next app that gets developed from scratch.
CA Veracode provided AppSec best practices and guidance to our security and development team during the kickoff phase. They offered assistance on specific code issues that were hard to fix, and guidance on preparing a credible set of rules for Veracode policy, all this at no additional cost.
As Veracode licensing is generally time-related, I suggest you start the subscription once everything is ready for consumption, assign a specific person to it and declaring it mandatory at the policy level. Losing two months of great value because the devs are too busy, or because they think they don’t need it, or they fear the results, or because no one is taking charge of the Veracode process, is really a pity. Once the clock starts ticking, try to take advantage as much as you can.
I would recommend Veracode to anyone involved in high-risk environments.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Container Security Software Composition Analysis (SCA) Penetration Testing Services Static Code Analysis Application Security Posture Management (ASPM)Popular Comparisons
SonarQube Server (formerly SonarQube)
GitLab
Snyk
Checkmarx One
Mend.io
Fortify on Demand
CrowdStrike Falcon Cloud Security
Sonatype Lifecycle
GitHub Advanced Security
Acunetix
PortSwigger Burp Suite Professional
HCL AppScan
Qualys Web Application Scanning
GitHub
Klocwork
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Which gives you more for your money - SonarQube or Veracode?
- Checkmarx or Veracode. Which should we choose?
- Would you recommend Veracode? What are some of your use cases?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- What do I scan when changing code in Veracode?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?