Introducing G2.ai, the future of software buying.Try now

Checkmarx Reviews & Product Details

Profile Status

This profile is currently managed by Checkmarx but has limited features.

Are you part of the Checkmarx team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Value at a Glance

Averages based on real user reviews.

Time to Implement

2 months

Perceived Cost

$$$$$

Checkmarx Integrations

(1)
Integration information sourced from real user reviews.

Checkmarx Media

Checkmarx Demo - Best Fix Location
CxSAST's Best Fix Location offers the most efficient place to remediate code to fix as many vulnerabilities as possible with one code change.
Checkmarx Demo - Checkmarx Reporting
Simple, user-friendly reporting for all your analytical needs.
Product Avatar Image

Have you used Checkmarx before?

Answer a few questions to help the Checkmarx community

Checkmarx Reviews (36)

Reviews

Checkmarx Reviews (36)

4.2
36 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Ján J.
JJ
SQA Engineer
Enterprise (> 1000 emp.)
"Great Automation and UI, But Needs Better Kotlin Support"
What do you like best about Checkmarx?

Helps to automate a security review of a codebase. Easy to implement into existing repositories. Nice intuitive user interface and good vulnerability descriptions with a hints where in code and how to fix. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Unfortunately Checkmarx reported a huge number of false positives for Kotlin based projects. Probably this language is poorly supported because there were no such issues in more popular languages like Java or Javascript. Review collected by and hosted on G2.com.

Verified User in Retail
AR
Enterprise (> 1000 emp.)
"Brilliant Code to Cloud Application"
What do you like best about Checkmarx?

Is so user friendly and it is very easy to become familiar with all the numerous features. Although I wasn't around for the implementation, I've found that it is relatively straightforward to integrate further functionality. The Scanning tools (IaC, SAST, SCA, API etc.) are all excellent and provide us with all the staus and visibility that we require. If we ever have issues that can't be resolved the Customer Support team at Checkmarx always are there to help us out. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

The dahsboards layour and display could be improved. Review collected by and hosted on G2.com.

Abhineet S.
AS
DevSecOps Engineer II
Mid-Market (51-1000 emp.)
"Best in class SAST solution in the market"
What do you like best about Checkmarx?

I like the SAST-ification thing in overall, it is having all offering varies from source code scans to sca, to license scanning and does a great job finding vulnerabilities. It is easy to use and visually easy to look around for the bugs. Similarly very optimized so that we can integrate with the CI/CD pipelines Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

The cost acquiring in all of the modules is pretty high. Review collected by and hosted on G2.com.

TM
Mid-Market (51-1000 emp.)
"Good Tool with good interfaces and edveloper friendly environment"
What do you like best about Checkmarx?

UI implementations are really good (Data Flow Matrixes)

suggestions are provided for the most suitable place to fix a set of vulnerabilities.

Most of the integrations are working seamlessly Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Support service is getting delayed sometimes

Some of the findings tend to be false positives

Scanning time is slow when compared with other tools.

Some of the IDE integrations aren't working as intended. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
UC
Mid-Market (51-1000 emp.)
"A good alternative in a fierceful market"
What do you like best about Checkmarx?

Integration with CI/CD is pretty fetatureful. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

High number of false positives unless you carefully tailor it to each project. Review collected by and hosted on G2.com.

sanjay s.
SS
Security Analyst
Small-Business (50 or fewer emp.)
"Checkmarx Review"
What do you like best about Checkmarx?

Checkmarx Tool Scans the code pretty well. Gives accurate results in-depth analysis can be done because checkmarx provides Flow of code from source till the values getting executed Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Checkmarx reports false positives issues a lot. If it's a big application code base it's tough to control the number of false positive issues to analyse.Reporting can also be improved Review collected by and hosted on G2.com.

Pankaj W.
PW
Specialist - Information Security
Enterprise (> 1000 emp.)
"Best tool for Source code scanning"
What do you like best about Checkmarx?

The most valuable features are the easy to understand interface, and it 's very user-friendly. Reduce the code using cxsast plugin. It will scan code line by line and find most of vulnerabilities. Very easy to use. Vulnerability report is awesome. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

UI should update. Reduce the false positive. Please upgrade rules set to avoid the false positive. Review collected by and hosted on G2.com.

Sujeet S.
SS
Technology Lead
Mid-Market (51-1000 emp.)
"Impressed with the Codebashing platform and AppSec awareness"
What do you like best about Checkmarx?

Checkmarx has an impressive Codebashing feature that has the edge over SonarQube. The application tracking-reporting feature is good too. I like the "delta-scan" feature as it is really good for cases when there are very frequent scans needed (e.g. with every major code commit, we don't want the entire source code scan to happen again). Having used both tools extensively (SonarQube and Checkmarx), I prefer Checkmarx overall. Checkmarx also fares better compared to peers when it comes to finding any vulnerabilities within the database. Since ours is a user-information driven applicaiton, it becomes even more imminent to identify the data-specfic vulnerabilities at the earliest. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Dashboarding could be better. The UI to show the current issue and the descriptive/suggestive text for the potential fix could be more "obvious" to the end-users. SonarQube scores over checkmarx in this regard.

Also, dashboarding could provide a little more flexibility towards the creation of new widgets.

One ore thing that I disliked about Checkmarx is that I could not find a free version in the market. Even for making an initial comparison, I had to contact the sales rep (the sales rep were pretty quick to respond, though). Review collected by and hosted on G2.com.

Verified User in Higher Education
UH
Enterprise (> 1000 emp.)
"To find any security vulnerabilities, Checkmarx is an awesome tool."
What do you like best about Checkmarx?

Easy to scan any application to find any security threats Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Even after marking false positives, the same issue sometimes still appears as a high or critical security issue. Review collected by and hosted on G2.com.

Verified User in Investment Banking
UI
Enterprise (> 1000 emp.)
"Be a step ahead by identifying vulnerability using checkmarx to"
What do you like best about Checkmarx?

It identifies all the security vulnerabilities making your code secure than ever before. It also categorises the vulnerability into different categories based on the risk associated. Can be easily integrated with your CI pipeline to have you code scan with every build Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

We can have a more better and user friendly UI to go through the report. Review collected by and hosted on G2.com.

Pricing Insights

Averages based on real user reviews.

Time to Implement

2 months

Perceived Cost

$$$$$

How much does Checkmarx cost?

Data powered by BetterCloud.

Estimated Price

$$k - $$k

Per Year

Based on data from 5 purchases.

Checkmarx Comparisons
Product Avatar Image
SonarQube
Compare Now
Product Avatar Image
Coverity
Compare Now
Product Avatar Image
OpenText Core Application Security
Compare Now
Product Avatar Image
Checkmarx
View Alternatives