# Veracode Application Security Platform, ZAP by Checkmarx vs Checkmarx Comparison

| | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Star Rating** | 3.8 out of 5 | 4.7 out of 5 | 4.2 out of 5 | 
| **Total Reviews** | 25 | 14 | 37 | 
| **Largest Market Segment** | Enterprise (52.2% of reviews) | Small-Business (76.9% of reviews) | Enterprise (53.1% of reviews) | 
| **Entry Level Price** | No pricing available | Free | No pricing available | 

---
## Top Pros & Cons

### Veracode Application Security Platform

Pros:
- Security (5 reviews)
- Vulnerability Detection (5 reviews)

Cons:
- Expensive (2 reviews)
- Lack of Information (2 reviews)

### ZAP by Checkmarx

Pros:
- Ease of Use (6 reviews)
- Automation (5 reviews)

Cons:
- False Positives (3 reviews)
- Poor Documentation (2 reviews)

### Checkmarx

Pros:
- Implementation Ease (2 reviews)
- User Interface (2 reviews)

Cons:
- False Positives (1 reviews)
- Lacking Features (1 reviews)

---
## Ratings Comparison
| Rating | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
  | **Meets Requirements** | 8.1 (19 reviews) | 9.6 (12 reviews) | 8.6 (27 reviews) | 
  | **Ease of Use** | 7.3 (19 reviews) | 9.0 (12 reviews) | 8.2 (27 reviews) | 
  | **Ease of Setup** | 5.7 (7 reviews) | Not enough data | 7.7 (13 reviews) | 
  | **Ease of Admin** | 7.4 (7 reviews) | Not enough data | 7.9 (13 reviews) | 
  | **Quality of Support** | 8.0 (18 reviews) | 8.1 (12 reviews) | 8.3 (22 reviews) | 
  | **Has the product been a good partner in doing business?** | 7.9 (7 reviews) | Not enough data | 8.3 (12 reviews) | 
  | **Product Direction (% positive)** | 6.3 (19 reviews) | 10.0 (11 reviews) | 7.5 (23 reviews) | 

---
## Pricing

### Veracode Application Security Platform

#### Entry-Level Pricing

No pricing available

#### Free Trial

No information available

### ZAP by Checkmarx

#### Entry-Level Pricing

Plan: Open source

Price: Free

Key Features:
- Everything

[Learn more about ZAP by Checkmarx](https://www.g2.com/products/zap-by-checkmarx/reviews)

#### Free Trial

Yes

### Checkmarx

#### Entry-Level Pricing

No pricing available

#### Free Trial

Yes

---
## Features Comparison By Category

### Penetration Testing

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | N/A | N/A |
| **ZAP by Checkmarx** | 8.4/10 | 13 |
| **Checkmarx** | N/A | N/A |

#### Administration

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **API / Integrations** | Not enough data | 8.3 (12 reviews) | Not enough data | 
| **Extensibility** | Not enough data | 8.8 (12 reviews) | Not enough data | 
| **Reporting and Analytics** | Not enough data | 8.8 (12 reviews) | Not enough data | 

#### Analysis

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Issue Tracking** | Not enough data | 8.1 (12 reviews) | Not enough data | 
| **Reconnaissance** | Not enough data | 8.2 (12 reviews) | Not enough data | 
| **Vulnerability Scan** | Not enough data | 9.4 (12 reviews) | Not enough data | 

#### Testing

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Command-Line Tools** | Not enough data | 7.6 (12 reviews) | Not enough data | 
| **Manual Testing** | Not enough data | 7.5 (12 reviews) | Not enough data | 
| **Test Automation** | Not enough data | 8.6 (12 reviews) | Not enough data | 
| **Performance and Reliability** | Not enough data | 8.9 (12 reviews) | Not enough data | 

### Static Application Security Testing (SAST)

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | N/A | N/A |
| **ZAP by Checkmarx** | N/A | N/A |
| **Checkmarx** | 7.8/10 | 6 |

#### Administration

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **API / Integrations** | Not enough data | Not enough data | 8.3 (5 reviews) | 
| **Extensibility** | Not enough data | Not enough data | 8.3 (5 reviews) | 

#### Analysis

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Reporting and Analytics** | Not enough data | Not enough data | 8.6 (6 reviews) | 
| **Issue Tracking** | Not enough data | Not enough data | 8.1 (6 reviews) | 
| **Static Code Analysis** | Not enough data | Not enough data | 8.3 (6 reviews) | 
| **Code Analysis** | Not enough data | Not enough data | 8.7 (5 reviews) | 

#### Testing

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Command-Line Tools** | Not enough data | Not enough data | 7.7 (5 reviews) | 
| **Manual Testing** | Not enough data | Not enough data | 7.3 (5 reviews) | 
| **Test Automation** | Not enough data | Not enough data | Not enough data | 
| **Compliance Testing** | Not enough data | Not enough data | Not enough data | 
| **Black-Box Scanning** | Not enough data | Not enough data | Not enough data | 
| **Detection Rate** | Not enough data | Not enough data | Not enough data | 
| **False Positives** | Not enough data | Not enough data | 5.3 (5 reviews) | 

#### Agentic AI - Static Application Security Testing (SAST)

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Autonomous Task Execution** | Not enough data | Not enough data | Not enough data | 

### Dynamic Application Security Testing (DAST)

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | 8.5/10 | 7 |
| **ZAP by Checkmarx** | N/A | N/A |
| **Checkmarx** | N/A | N/A |

#### Administration

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **API / Integrations** | 7.9 (7 reviews) | Not enough data | Not enough data | 
| **Extensibility** | 9.2 (6 reviews) | Not enough data | Not enough data | 

#### Analysis

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Reporting and Analytics** | 8.3 (7 reviews) | Not enough data | Not enough data | 
| **Issue Tracking** | 8.3 (5 reviews) | Not enough data | Not enough data | 
| **Static Code Analysis** | 9.3 (7 reviews) | Not enough data | Not enough data | 
| **Vulnerability Scan** | 8.8 (7 reviews) | Not enough data | Not enough data | 
| **Code Analysis** | 8.6 (6 reviews) | Not enough data | Not enough data | 

#### Testing

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Manual Testing** | Not enough data | Not enough data | Not enough data | 
| **Test Automation** | 9.0 (5 reviews) | Not enough data | Not enough data | 
| **Compliance Testing** | Not enough data | Not enough data | Not enough data | 
| **Black-Box Scanning** | 8.3 (5 reviews) | Not enough data | Not enough data | 
| **Detection Rate** | 8.0 (5 reviews) | Not enough data | Not enough data | 
| **False Positives** | 7.8 (6 reviews) | Not enough data | Not enough data | 

### Vulnerability Scanner

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | N/A | N/A |
| **ZAP by Checkmarx** | N/A | N/A |
| **Checkmarx** | N/A | N/A |

#### Performance

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Issue Tracking** | Not enough data | Not enough data | Not enough data | 
| **Detection Rate** | Not enough data | Not enough data | Not enough data | 
| **False Positives** | Not enough data | Not enough data | Not enough data | 
| **Automated Scans** | Not enough data | Not enough data | Not enough data | 

#### Network

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Compliance Testing** | Not enough data | Not enough data | Not enough data | 
| **Perimeter Scanning** | Not enough data | Not enough data | Not enough data | 
| **Configuration Monitoring** | Not enough data | Not enough data | Not enough data | 

#### Application

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Manual Application Testing** | Not enough data | Not enough data | Not enough data | 
| **Static Code Analysis** | Not enough data | Not enough data | Not enough data | 
| **Black Box Testing** | Not enough data | Not enough data | Not enough data | 

#### Agentic AI - Vulnerability Scanner

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Autonomous Task Execution** | Not enough data | Not enough data | Not enough data | 
| **Proactive Assistance** | Not enough data | Not enough data | Not enough data | 

### Software Composition Analysis

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | N/A | N/A |
| **ZAP by Checkmarx** | N/A | N/A |
| **Checkmarx** | N/A | N/A |

#### Functionality - Software Composition Analysis 

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Language Support** | Not enough data | Not enough data | Not enough data | 
| **Integration** | Not enough data | Not enough data | Not enough data | 
| **Transparency** | Not enough data | Not enough data | Not enough data | 

#### Effectiveness - Software Composition Analysis

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Remediation Suggestions** | Not enough data | Not enough data | Not enough data | 
| **Continuous Monitoring** | Not enough data | Not enough data | Not enough data | 
| **Thorough Detection** | Not enough data | Not enough data | Not enough data | 

### Secure Code Review

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | N/A | N/A |
| **ZAP by Checkmarx** | N/A | N/A |
| **Checkmarx** | N/A | N/A |

#### Documentation

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Feedback** | Not enough data | Not enough data | Not enough data | 
| **Prioritization** | Not enough data | Not enough data | Not enough data | 
| **Remediation Suggestions** | Not enough data | Not enough data | Not enough data | 

#### Security

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **False Positives** | Not enough data | Not enough data | Not enough data | 
| **Custom Compliance** | Not enough data | Not enough data | Not enough data | 
| **Agility** | Not enough data | Not enough data | Not enough data | 

### Software Supply Chain Security Tools

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | N/A | N/A |
| **ZAP by Checkmarx** | N/A | N/A |
| **Checkmarx** | N/A | N/A |

#### Security

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Tampering** | Not enough data | Not enough data | Not enough data | 
| **Malicious Code** | Not enough data | Not enough data | Not enough data | 
| **Verification** | Not enough data | Not enough data | Not enough data | 
| **Security Risks** | Not enough data | Not enough data | Not enough data | 

#### Tracking

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Bill of Materials** | Not enough data | Not enough data | Not enough data | 
| **Audit Trails** | Not enough data | Not enough data | Not enough data | 
| **Monitoring** | Not enough data | Not enough data | Not enough data | 

### Software Bill of Materials (SBOM)

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | N/A | N/A |
| **ZAP by Checkmarx** | N/A | N/A |
| **Checkmarx** | N/A | N/A |

#### Functionality - Software Bill of Materials (SBOM)

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Format Support** | Not enough data | Not enough data | Not enough data | 
| **Annotations** | Not enough data | Not enough data | Not enough data | 
| **Attestation** | Not enough data | Not enough data | Not enough data | 

#### Management - Software Bill of Materials (SBOM)

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Monitoring** | Not enough data | Not enough data | Not enough data | 
| **Dashboards** | Not enough data | Not enough data | Not enough data | 
| **User Provisioning** | Not enough data | Not enough data | Not enough data | 

### Static Code Analysis

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | N/A | N/A |
| **ZAP by Checkmarx** | N/A | N/A |
| **Checkmarx** | N/A | N/A |

#### Agentic AI - Static Code Analysis

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Adaptive Learning** | Not enough data | Not enough data | Not enough data | 
| **Natural Language Interaction** | Not enough data | Not enough data | Not enough data | 
| **Proactive Assistance** | Not enough data | Not enough data | Not enough data | 

### AI AppSec Assistants

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | N/A | N/A |
| **ZAP by Checkmarx** | N/A | N/A |
| **Checkmarx** | N/A | N/A |

#### Performance - AI AppSec Assistants

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Remediation** | Not enough data | Not enough data | Not enough data | 
| **Real-time Vulnerability Detection** | Not enough data | Not enough data | Not enough data | 
| **Accuracy** | Not enough data | Not enough data | Not enough data | 

#### Integration - AI AppSec Assistants

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Stack Integration** | Not enough data | Not enough data | Not enough data | 
| **Workflow Integration** | Not enough data | Not enough data | Not enough data | 
| **Codebase Contextual Awareness** | Not enough data | Not enough data | Not enough data | 

### Interactive Application Security Testing (IAST)

| Product | Score | Reviews |
|---|---|---|
| **Veracode Application Security Platform** | N/A | N/A |
| **ZAP by Checkmarx** | N/A | N/A |
| **Checkmarx** | N/A | N/A |

#### Agentic AI - Interactive Application Security Testing (IAST)

| Feature | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Autonomous Task Execution** | Not enough data | Not enough data | Not enough data | 

---
## Categories
**Shared Categories (1):** [Dynamic Application Security Testing (DAST) Software](https://www.g2.com/categories/dynamic-application-security-testing-dast)

**Unique to Veracode Application Security Platform (10):** [Secure Code Review Software](https://www.g2.com/categories/secure-code-review), [AI AppSec Assistants](https://www.g2.com/categories/ai-appsec-assistants), [Static Application Security Testing (SAST) Software](https://www.g2.com/categories/static-application-security-testing-sast), [Penetration Testing Tools](https://www.g2.com/categories/penetration-testing-tools), [Vulnerability Scanner Software](https://www.g2.com/categories/vulnerability-scanner), [Static Code Analysis Tools](https://www.g2.com/categories/static-code-analysis), [Software Composition Analysis Tools](https://www.g2.com/categories/software-composition-analysis), [Interactive Application Security Testing (IAST) Software](https://www.g2.com/categories/interactive-application-security-testing-iast), [Software Bill of Materials (SBOM) Software](https://www.g2.com/categories/software-bill-of-materials-sbom), [Software Supply Chain Security Solutions](https://www.g2.com/categories/software-supply-chain-security-tools)

**Unique to ZAP by Checkmarx (1):** [Penetration Testing Tools](https://www.g2.com/categories/penetration-testing-tools)

**Unique to Checkmarx (5):** [AI AppSec Assistants](https://www.g2.com/categories/ai-appsec-assistants), [Static Application Security Testing (SAST) Software](https://www.g2.com/categories/static-application-security-testing-sast), [Secure Code Review Software](https://www.g2.com/categories/secure-code-review), [Static Code Analysis Tools](https://www.g2.com/categories/static-code-analysis), [Interactive Application Security Testing (IAST) Software](https://www.g2.com/categories/interactive-application-security-testing-iast)


---
## Reviewer Demographics

### By Company Size

| Segment | Veracode Application Security Platform | ZAP by Checkmarx | Checkmarx | 
|---|---|---|---|
| **Small-Business** | 17.4% | 76.9% | 18.8% | 
| **Mid-Market** | 30.4% | 7.7% | 28.1% | 
| **Enterprise** | 52.2% | 15.4% | 53.1% | 

### By Industry

#### Veracode Application Security Platform

- **Information Technology and Services:** 30.4%
- **Hospital &amp; Health Care:** 13.0%
- **Consumer Goods:** 8.7%
- **Computer Software:** 8.7%
- **Telecommunications:** 4.3%
- **Retail:** 4.3%
- **Research:** 4.3%
- **Media Production:** 4.3%
- **Logistics and Supply Chain:** 4.3%
- **Insurance:** 4.3%
- **Other:** 13.0%

#### ZAP by Checkmarx

- **Computer &amp; Network Security:** 41.7%
- **Information Technology and Services:** 25.0%
- **Computer Software:** 16.7%
- **Internet:** 8.3%
- **Hospital &amp; Health Care:** 8.3%

#### Checkmarx

- **Computer Software:** 15.6%
- **Information Technology and Services:** 15.6%
- **Banking:** 9.4%
- **Computer &amp; Network Security:** 9.4%
- **Automotive:** 6.3%
- **Investment Banking:** 3.1%
- **Internet:** 3.1%
- **International Trade and Development:** 3.1%
- **Insurance:** 3.1%
- **Legal Services:** 3.1%
- **Other:** 28.1%

---
## Alternatives

### Alternatives to Veracode Application Security Platform

- [SonarQube](https://www.g2.com/products/sonarqube/reviews) — 4.4/5 stars (141 reviews)
- [Invicti (formerly Netsparker)](https://www.g2.com/products/invicti-formerly-netsparker/reviews) — 4.6/5 stars (69 reviews)
- [GitHub](https://www.g2.com/products/github/reviews) — 4.7/5 stars (2353 reviews)
- [GitLab](https://www.g2.com/products/gitlab/reviews) — 4.5/5 stars (891 reviews)
- [Snyk](https://www.g2.com/products/snyk/reviews) — 4.5/5 stars (132 reviews)
- [Mend.io](https://www.g2.com/products/mend-io/reviews) — 4.3/5 stars (112 reviews)
- [HCL AppScan](https://www.g2.com/products/hcl-appscan/reviews) — 4.1/5 stars (76 reviews)
- [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews) — 4.5/5 stars (301 reviews)
- [Burp Suite](https://www.g2.com/products/burp-suite/reviews) — 4.8/5 stars (129 reviews)
- [Wiz](https://www.g2.com/products/wiz-wiz/reviews) — 4.7/5 stars (793 reviews)

### Alternatives to ZAP by Checkmarx

- [GitLab](https://www.g2.com/products/gitlab/reviews) — 4.5/5 stars (891 reviews)
- [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews) — 4.5/5 stars (301 reviews)
- [Acunetix by Invicti](https://www.g2.com/products/acunetix-by-invicti/reviews) — 4.1/5 stars (105 reviews)
- [Intruder](https://www.g2.com/products/intruder/reviews) — 4.8/5 stars (206 reviews)
- [Burp Suite](https://www.g2.com/products/burp-suite/reviews) — 4.8/5 stars (129 reviews)
- [Invicti (formerly Netsparker)](https://www.g2.com/products/invicti-formerly-netsparker/reviews) — 4.6/5 stars (69 reviews)
- [vPenTest](https://www.g2.com/products/vpentest/reviews) — 4.6/5 stars (232 reviews)
- [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews) — 4.6/5 stars (186 reviews)
- [Metasploit](https://www.g2.com/products/metasploit/reviews) — 4.6/5 stars (55 reviews)
- [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) — 4.5/5 stars (177 reviews)

### Alternatives to Checkmarx

- [SonarQube](https://www.g2.com/products/sonarqube/reviews) — 4.4/5 stars (141 reviews)
- [GitLab](https://www.g2.com/products/gitlab/reviews) — 4.5/5 stars (891 reviews)
- [GitHub](https://www.g2.com/products/github/reviews) — 4.7/5 stars (2353 reviews)
- [HCL AppScan](https://www.g2.com/products/hcl-appscan/reviews) — 4.1/5 stars (76 reviews)
- [Coverity](https://www.g2.com/products/coverity/reviews) — 4.2/5 stars (55 reviews)
- [OpenText Core Application Security](https://www.g2.com/products/opentext-core-application-security/reviews) — 4.1/5 stars (34 reviews)
- [Invicti (formerly Netsparker)](https://www.g2.com/products/invicti-formerly-netsparker/reviews) — 4.6/5 stars (69 reviews)
- [Snyk](https://www.g2.com/products/snyk/reviews) — 4.5/5 stars (132 reviews)
- [Mend.io](https://www.g2.com/products/mend-io/reviews) — 4.3/5 stars (112 reviews)
- [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews) — 4.5/5 stars (301 reviews)

---
## Top Discussions

### Veracode Application Security Platform

No discussions available for this product.

### ZAP by Checkmarx

No discussions available for this product.

### Checkmarx

- Title: [What is Checkmarx used for?](https://www.g2.com/discussions/what-is-checkmarx-used-for) — 2 comments
  > **Top comment:** "Checkmarx is a static code analysis tool used for SAST (Static application security testing)"
- Title: [What is Checkmarx used for?](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for) — 1 comment, 1 upvote
  > **Top comment:** "Checkmarx is an ultimate tool for Static code scan and analysis through code vulnerability testing, SCA and secret detections. They have a prebuilt engine to..."
- Title: [Which testing method does Checkmarx support?](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support) — 1 comment
  > **Top comment:** "Checkmarx does support all these testing methodologies -Sast, Dast, IAST, SCA "
- Title: [Does Checkmarx support DAST?](https://www.g2.com/discussions/does-checkmarx-support-dast) — 1 comment
  > **Top comment:** "You cannot test DAST Testing using Checkmarx"

---
**Source:** [G2.com](https://www.g2.com) | [Comparison Page](https://www.g2.com/compare/veracode-application-security-platform-vs-zap-by-checkmarx-vs-checkmarx)

