Introducing G2.ai, the future of software buying.Try now

Compare SonarQube and Veracode Application Security Platform

Save
    Log in to your account
    to save comparisons,
    products and more.
At a Glance
SonarQube
SonarQube
Star Rating
(125)4.5 out of 5
Market Segments
Enterprise (41.9% of reviews)
Information
Entry-Level Pricing
Free
Browse all 5 pricing plans
Veracode Application Security Platform
Veracode Application Security Platform
Star Rating
(25)3.8 out of 5
Market Segments
Enterprise (52.2% of reviews)
Information
Entry-Level Pricing
No pricing available
Learn more about Veracode Application Security Platform
AI Generated Summary
AI-generated. Powered by real user reviews.
  • Users report that Veracode Application Security Platform excels in its Static Code Analysis with a score of 9.0, indicating a robust capability to identify vulnerabilities early in the development process. In contrast, SonarQube Server also performs well in this area with a score of 9.3, but users mention that its Code Analysis features are particularly strong, scoring 9.1, which helps in maintaining code quality over time.
  • Reviewers mention that Veracode's Ease of Setup is a significant drawback, scoring only 5.7, which can lead to longer onboarding times. On the other hand, SonarQube Server has a much better score of 7.8, making it easier for teams to get started quickly.
  • G2 users highlight that Veracode's False Positives rate is a concern, with a score of 6.8, which can lead to unnecessary remediation efforts. In contrast, SonarQube Server has a better score of 7.8 in this area, indicating a more reliable detection mechanism that minimizes noise in vulnerability reports.
  • Users on G2 report that Veracode's Quality of Support is satisfactory, with a score of 8.0, but they also mention that SonarQube Server matches this score while providing a more extensive community and documentation resources, which can be beneficial for troubleshooting and learning.
  • Reviewers say that Veracode's Product Direction is a concern, scoring only 6.3, which raises questions about its future development and feature enhancements. In contrast, SonarQube Server has a more positive outlook with a score of 8.0, suggesting a more proactive approach to evolving its features based on user feedback.
  • Users report that Veracode's API / Integrations score of 7.7 indicates decent extensibility, but SonarQube Server shines with a score of 9.2, allowing for better integration with various development tools and enhancing overall workflow efficiency.
Pricing
Entry-Level Pricing
SonarQube
Community Edition
Free
Browse all 5 pricing plans
Veracode Application Security Platform
No pricing available
Free Trial
SonarQube
Free Trial is available
Veracode Application Security Platform
No trial information available
Ratings
Meets Requirements
8.8
108
8.1
19
Ease of Use
8.5
111
7.3
19
Ease of Setup
8.1
70
5.7
7
Ease of Admin
8.5
63
7.4
7
Quality of Support
8.2
91
8.0
18
Has the product been a good partner in doing business?
8.4
57
7.9
7
Product Direction (% positive)
8.6
105
6.3
19
Features by Category
Not enough data
Not enough data
Administration
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Analysis
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Testing
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Static Application Security Testing (SAST)Hide 14 FeaturesShow 14 Features
7.3
22
Not enough data
Administration
7.8
19
Not enough data
6.0
20
Not enough data
Analysis
7.4
21
Not enough data
8.0
20
Not enough data
8.9
22
Not enough data
9.0
22
Not enough data
Testing
6.6
18
Not enough data
5.9
19
Not enough data
6.0
21
Not enough data
6.9
18
Not enough data
6.8
17
Not enough data
8.2
21
Not enough data
6.9
21
Not enough data
Agentic AI - Static Application Security Testing (SAST)
Not enough data
Not enough data
Dynamic Application Security Testing (DAST)Hide 13 FeaturesShow 13 Features
Not enough data
8.5
7
Administration
Not enough data
7.9
7
Not enough data
9.2
6
Analysis
Not enough data
8.3
7
Not enough data
8.3
5
Not enough data
9.3
7
Not enough data
8.8
7
Not enough data
8.6
6
Testing
Not enough data
Not enough data
Not enough data
9.0
5
Not enough data
Not enough data
Not enough data
8.3
5
Not enough data
8.0
5
Not enough data
7.8
6
Not enough data
Not enough data
Performance
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Network
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Application
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Agentic AI - Vulnerability Scanner
Not enough data
Not enough data
Not enough data
Not enough data
Software Development Analytics ToolsHide 6 FeaturesShow 6 Features
8.0
33
Not enough data
Functionality
8.1
31
Not enough data
8.4
30
Not enough data
8.2
29
Not enough data
Management
7.7
27
Not enough data
7.5
25
Not enough data
7.8
27
Not enough data
8.1
11
Not enough data
Bug Reporting
7.7
10
Not enough data
8.0
10
Not enough data
8.3
10
Not enough data
Bug Monitoring
7.8
10
Not enough data
8.2
10
Not enough data
8.5
10
Not enough data
Agentic AI - Bug Tracking
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Software Composition AnalysisHide 6 FeaturesShow 6 Features
Not enough data
Not enough data
Functionality - Software Composition Analysis
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Effectiveness - Software Composition Analysis
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
7.5
37
Not enough data
Documentation
7.7
35
Not enough data
7.6
35
Not enough data
8.2
36
Not enough data
Security
6.9
33
Not enough data
7.0
32
Not enough data
7.9
33
Not enough data
Application Security Posture Management (ASPM)Hide 11 FeaturesShow 11 Features
8.6
7
Not enough data
Risk management - Application Security Posture Management (ASPM)
9.3
5
Not enough data
8.7
5
Not enough data
9.0
5
Not enough data
8.9
6
Not enough data
Integration and efficiency - Application Security Posture Management (ASPM)
7.8
6
Not enough data
8.6
6
Not enough data
Reporting and Analytics - Application Security Posture Management (ASPM)
7.8
6
Not enough data
Not enough data
Not enough data
8.3
5
Not enough data
Agentic AI - Application Security Posture Management (ASPM)
Not enough data
Not enough data
Not enough data
Not enough data
Software Bill of Materials (SBOM)Hide 6 FeaturesShow 6 Features
Not enough data
Not enough data
Functionality - Software Bill of Materials (SBOM)
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Management - Software Bill of Materials (SBOM)
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
AI Compliance
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Risk Management & Monitoring
Not enough data
Not enough data
Not enough data
Not enough data
AI Lifecycle Management
Not enough data
Not enough data
Access Control and Security
Not enough data
Not enough data
Collaboration and Communication
Not enough data
Not enough data
Agentic AI - AI Governance Tools
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Static Code AnalysisHide 3 FeaturesShow 3 Features
6.2
8
Not enough data
Agentic AI - Static Code Analysis
6.3
8
Not enough data
5.7
7
Not enough data
6.7
8
Not enough data
Not enough data
Not enough data
Cloud Visibility
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Security
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Identity
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Interactive Application Security Testing (IAST)Hide 1 FeatureShow 1 Feature
Not enough data
Not enough data
Agentic AI - Interactive Application Security Testing (IAST)
Not enough data
Not enough data
Categories
Categories
Shared Categories
SonarQube
SonarQube
Veracode Application Security Platform
Veracode Application Security Platform
SonarQube and Veracode Application Security Platform are categorized as Secure Code Review, Static Application Security Testing (SAST), Static Code Analysis, and Software Composition Analysis
Reviews
Reviewers' Company Size
SonarQube
SonarQube
Small-Business(50 or fewer emp.)
17.7%
Mid-Market(51-1000 emp.)
40.3%
Enterprise(> 1000 emp.)
41.9%
Veracode Application Security Platform
Veracode Application Security Platform
Small-Business(50 or fewer emp.)
17.4%
Mid-Market(51-1000 emp.)
30.4%
Enterprise(> 1000 emp.)
52.2%
Reviewers' Industry
SonarQube
SonarQube
Information Technology and Services
26.6%
Computer Software
21.8%
Financial Services
6.5%
Hospital & Health Care
3.2%
Computer & Network Security
3.2%
Other
38.7%
Veracode Application Security Platform
Veracode Application Security Platform
Information Technology and Services
30.4%
Hospital & Health Care
13.0%
Consumer Goods
8.7%
Computer Software
8.7%
Telecommunications
4.3%
Other
34.8%
Alternatives
SonarQube
SonarQube Alternatives
GitHub
GitHub
Add GitHub
GitLab
GitLab
Add GitLab
Semgrep
Semgrep
Add Semgrep
Kiuwan Code Security & Insights
Kiuwan Code Security & Insights
Add Kiuwan Code Security & Insights
Veracode Application Security Platform
Veracode Application Security Platform Alternatives
GitHub
GitHub
Add GitHub
Checkmarx
Checkmarx
Add Checkmarx
GitLab
GitLab
Add GitLab
HCL AppScan
HCL AppScan
Add HCL AppScan
Discussions
SonarQube
SonarQube Discussions
Monty the Mongoose crying
SonarQube has no discussions with answers
Veracode Application Security Platform
Veracode Application Security Platform Discussions
Monty the Mongoose crying
Veracode Application Security Platform has no discussions with answers