--- title: Checkmarx Reviews meta\_title: 'Checkmarx Reviews 2026: Details, Pricing, & Features | G2' meta\_description: Filter 48 reviews by the users' company size, role or industry to find out how Checkmarx works for a business like yours. aggregate\_rating: rating\_value: 4.2 review\_count: 48 scale: '5' date\_modified: '2026-08-09' parent\_category: name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t" url: https://www.g2.com/categories/devsecops ---

# Checkmarx Reviews & Product Details

Visit Website

Checkmarx is a type of application security solution designed to help organizations safeguard their software development processes while enhancing efficiency and reducing costs. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. With the increasing reliance on AI technologies and the rapid pace of software development, Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as AI SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

* * *

Product Website
 Checkmarx
Seller
 [Checkmarx](https://www.g2.com/sellers/checkmarx)
Discussions
 [Checkmarx Community](https://www.g2.com/products/checkmarx/discuss)
Solution Type
 
All-in-One

Show More

## Value at a Glance

Averages based on real user reviews.

### Time to Implement

2 months

[
View More Pricing Information
](https://www.g2.com/products/checkmarx/pricing)

Checkmarx Solutions
(1)

See how Checkmarx products can work together to solve real problems.

[
 ![Solution Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Solution Avatar Image")
 

Build secure code faster

SolutionBy Checkmarx

](/sellers/checkmarx/solutions/build-secure-code-faster)

Show More

## Checkmarx Integrations
(6)

What do users say about integrations?

Verified by Checkmarx

[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

AWS Lambda

](https://www.g2.com/products/aws-lambda/reviews)[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

Azure Pipelines

](https://www.g2.com/products/azure-pipelines/reviews)[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

GitHub

](https://www.g2.com/products/github/reviews)[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

GitLab

](https://www.g2.com/products/gitlab/reviews)[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

Jenkins

](https://www.g2.com/products/jenkins/reviews)[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

TeamCity

](https://www.g2.com/products/teamcity/reviews)

Show More

  

 ![Aman M.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Aman M.")
AM

Aman M.

Senior DevOps Engineer

Information Technology and Services

Enterprise (\> 1000 emp.)

6/19/2026

"Centralized Source Code Security with Seamless CI/CD Integration"

5/5

What do you like best about Checkmarx?

Checkmarx is a centralized security tool that provides end-to-end insights into source code security and vulnerabilities. It also helps improve the efficiency of the source code by highlighting the associated risks and suggesting ways to remediate the vulnerabilities. In addition, it shows vulnerabilities in the open-source libraries and packages we use in our source code through SCA scans.

One thing I like the most is how well it integrates with our CI/CD tooling. We can plug it into our DevSecOps CI/CD flow, and developers can see scan insights directly from the pipeline itself, without needing to log in to the Checkmarx UI separately. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

It should better cope with modern software development lifecycles and provide end-to-end support for scanning any valid file extensions. For example, we are migrating from Node JS to TypeScript, and as part of that change we updated our .js files to use the .mjs extension. However, Checkmarx still does not support scanning .mjs files. We reported this issue to them about a year ago, but even now it remains unsupported. The current suggestion is to rename .mjs files to .js when uploading code for Checkmarx scans, which is not a practical workaround for us. Review collected by and hosted on G2.com.

What problems is Checkmarx solving and how is that benefiting you?

End-to-end security scanning for source code, including SAST and SCA scanning. It also supports API security scanning, IaC file scanning, and secret detection. Seamless integration with native CI/CD tools makes it easy to integrate Checkmarx into DevSecOps pipelines.

This reduces the Source Codes attack surface and by that we have achieved over 70%-80% of improvement in overall Code Security and our feature releases is now bullet proof from Security attacks Review collected by and hosted on G2.com.

Show More

Response from Shane McLaughlin of Checkmarx

[Editedit](https://www.g2.com/survey_responses/checkmarx-review-12980590/official_response/edit)

Aman, thank you for the feedback. We understand the challenges that can arise when development teams adopt new languages, frameworks, and file types.

Checkmarx has recently expanded its language-agnostic scanning capabilities through a new hybrid scanning engine that combines deterministic analysis with AI-powered detection, enabling broader coverage across modern and emerging technologies, including AI-generated code and polyglot environments. This approach is designed to reduce gaps created by evolving development practices while maintaining high-fidelity results.

We appreciate you highlighting the .mjs support issue, and feedback like this helps us continue improving coverage and compatibility for modern software development workflows. Please reach out to us if you would like to discuss more, and again thank you for the feedback!

[See how Checkmarx improved](https://checkmarx.com/press-releases/checkmarx-one-achieves-industrys-highest-scanning-fidelity-outperforming-both-legacy-tools-and-ai-models/)

7/13/2026
Current UserValidated ReviewerSource: G2 invite

  

 ![Nitesh A.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Nitesh A.")
NA

Nitesh A.

Module Lead - Stellantis (formerly PSA Group) - Automotive

Enterprise (\> 1000 emp.)

6/20/2026

"Automated Checkmarx Scans Keep Us Ahead of Key Vulnerabilities"

4.5/5

What do you like best about Checkmarx?

Provision to automate scan runs is now available. Scan results are well structured and comments are well documented. Easy for developers to understand and fix. Can be integrated with stakeholder reports. Good UI and support Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Scan results on Salesforce security portal are different from checkmarx portal which cause issues during package submission to Salesforce. Review collected by and hosted on G2.com.

What problems is Checkmarx solving and how is that benefiting you?

Checkmarx helps us to automate repo scans, provides good insights into vulnerabilities or major issues in code and segregates them in terms of severity. It also provides option to upload results as false positive So these do not get reported again n again. The exports are good to submit for security review. The UI design is good and intuitive. We found the scans run pretty fast and hence better in performance. We good good response and support from checkmark team for any issues or new features. Overall good experience. Review collected by and hosted on G2.com.

Show More

Response from Shane McLaughlin of Checkmarx

[Editedit](https://www.g2.com/survey_responses/checkmarx-review-12983770/official_response/edit)

Thank you for the feedback Nitesh! We understand that differences between scan results from Salesforce Security Portal scans and Checkmarx scans can be challenging when comparing findings across tools. To address this, Checkmarx has recently introduced a new hybrid scanning engine and Finding Analysis Engine designed to improve scan fidelity and consistency by validating findings, reducing noise, and surfacing the vulnerabilities that matter most.

The result is an industry-leading F1 score and a 60% reduction in false positives, helping teams gain greater confidence in their scan results and prioritize remediation more effectively.

We're also glad to hear that Checkmarx is delivering fast scans, actionable vulnerability insights, intuitive workflows, and strong support for your team.

Let us know how we can continue to support your team, reach out any time and again, thank you for your review!

[See how Checkmarx improved](https://checkmarx.com/press-releases/checkmarx-one-achieves-industrys-highest-scanning-fidelity-outperforming-both-legacy-tools-and-ai-models/)

8/7/2026
Validated ReviewerSource: G2 invite

  

 ![Arya S.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Arya S.")
AS

Arya S.

Cybersecurity Lead

Computer & Network Security

Enterprise (\> 1000 emp.)

6/17/2026

"Comprehensive Application Security with Checkmarx"

4.5/5

What do you like best about Checkmarx?

I like Checkmarx because it provides comprehensive application security, with accurate vulnerability detection, risk-based prioritization, and clear remediation recommendations. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

One area that could be improved is the number of false positives generated during scans, as this can add extra time to validation and triage. In addition, scans may take longer when running against large codebases. Review collected by and hosted on G2.com.

What problems is Checkmarx solving and how is that benefiting you?

Checkmarx helps us address the challenge of identifying security vulnerabilities early in the software development lifecycle, before they reach production. It scans source code, open-source dependencies, APIs, and other application components to detect security risks and provide remediation guidance. For us, this reduces the likelihood of security incidents, supports compliance efforts, reinforces secure development practices, and helps development teams fix vulnerabilities faster without significantly slowing delivery timelines. Review collected by and hosted on G2.com.

Show More

Response from Shane McLaughlin of Checkmarx

[Editedit](https://www.g2.com/survey_responses/checkmarx-review-12972848/official_response/edit)

Arya, thank you for the thoughtful feedback! We’re glad Checkmarx is helping you find risk earlier across source code, open source, APIs, and other application components. We also understand that false positives and scan time can add friction for developers.

That’s why Checkmarx One is investing heavily in higher-fidelity scanning, not just more findings. Our new hybrid SAST engine combines deterministic analysis, purpose-tuned AI, and a Finding Analysis Engine to confirm true positives and suppress false ones before results reach developers.

In head-to-head testing across seven production codebases, it achieved a 0.64 F1 score, more than 3x the evaluated average, while reducing false positives by 60%. The goal is to help teams cut through noise, prioritize genuinely exploitable risk, and remediate faster without slowing delivery.

[See how Checkmarx improved](https://checkmarx.com/press-releases/checkmarx-one-achieves-industrys-highest-scanning-fidelity-outperforming-both-legacy-tools-and-ai-models/)

Validated ReviewerSource: G2 invite

  

 ![Verified User in Information Technology and Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Information Technology and Services")
UI

Verified User in Information Technology and Services

Mid-Market (51-1000 emp.)

7/29/2026

"Powerful Application Security Testing That Helps Developers Spot Issues Fast"

4.5/5

What do you like best about Checkmarx?

The best about Checkmarx is its application security testing capabilities that helps developers to identify the issues Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

The dislike about Checkmarx is Large codebases may require significant scan time. Review collected by and hosted on G2.com.

What problems is Checkmarx solving and how is that benefiting you?

The problems that Checkmarx solving for me is scanning my codebase and identify the security vulnerabilities and help me in fixing those things efficiently. Review collected by and hosted on G2.com.

Show More

Response from Shane McLaughlin of Checkmarx

[Editedit](https://www.g2.com/survey_responses/checkmarx-review-13182941/official_response/edit)

Thanks for the review! Scanning large code bases just got easier with the rollout of Checkmarx Fusion this week, which merges deterministic precision and frontier AI models together into a single platform that is getting a .741 F1 score, nearly four times the category average. I invite you to reach out for a demo or additional questions.

[See how Checkmarx improved](https://checkmarx.com/platform/checkmarx-fusion/?utm_source=httpscheckmarx.comblog&utm_medium=httpscheckmarx.comblog&utm_campaign=checkmarx_fusion)

Our network of Icons are G2 members who are recognized for their outstanding contributions and commitment to helping others through their expertise. G2 IconCurrent UserValidated ReviewerSource: G2 invite

  

 ![uday n.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "uday n.")
UN

uday n.

System Engineer

Mid-Market (51-1000 emp.)

6/24/2026

"Seamlessly Integrates Security Into the Development Lifecycle"

5/5

What do you like best about Checkmarx?

its ability to integrate security directly into software development life cycle Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

deeper security analysis can sometimes increase scan duration Review collected by and hosted on G2.com.

What problems is Checkmarx solving and how is that benefiting you?

helps catch security issues early in development Review collected by and hosted on G2.com.

Show More

Response from Shane McLaughlin of Checkmarx

[Editedit](https://www.g2.com/survey_responses/checkmarx-review-13002744/official_response/edit)

Thanks Uday, in addition to the SDLC we recently announced general availability of Checkmarx AI Inventory, a new capability that gives continuous visibility into the AI components running in applications, (like models, agents, MCP servers, AI libraries, and SDKs.) From that inventory, it generates an AI-BOM (AI Bill of Materials): the policy controls and audit-ready documentation for every AI component it discovers. Thanks for your review!

[See how Checkmarx improved](https://checkmarx.com/press-releases/checkmarx-delivers-complete-ai-asset-visibility-governance-software-supply-chain-closing-shadow-ai-gap/)

Validated ReviewerIncentivizedSource: G2 invite

  

 ![Verified User in Retail](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Retail")
AR

Verified User in Retail

Enterprise (\> 1000 emp.)

12/16/2024

"Brilliant Code to Cloud Application"

4.5/5

What do you like best about Checkmarx?

Is so user friendly and it is very easy to become familiar with all the numerous features. Although I wasn't around for the implementation, I've found that it is relatively straightforward to integrate further functionality. The Scanning tools (IaC, SAST, SCA, API etc.) are all excellent and provide us with all the staus and visibility that we require. If we ever have issues that can't be resolved the Customer Support team at Checkmarx always are there to help us out. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

The dahsboards layour and display could be improved. Review collected by and hosted on G2.com.

What problems is Checkmarx solving and how is that benefiting you?

Checkmarx is being used mainly for the scanning and checking of code before it makes the journey to the Cloud (AWS). We are using it to look at all the languages and frameworks that we have in our Tech/Data Stack that are incorporated into our IT Landscape. One of the main benefits is that it allows our developers to identify, detect and remediate vulnerabilities at source. It also allows them to edit queries easily and quickly. Review collected by and hosted on G2.com.

Show More

Our network of Icons are G2 members who are recognized for their outstanding contributions and commitment to helping others through their expertise. G2 IconCurrent UserValidated ReviewerIncentivizedSource: G2 Gives Campaign

  

 ![Abhineet S.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Abhineet S.")
AS

Abhineet S.

DevSecOps Engineer II

Mid-Market (51-1000 emp.)

1/12/2024

"Best in class SAST solution in the market"

5/5

What do you like best about Checkmarx?

I like the SAST-ification thing in overall, it is having all offering varies from source code scans to sca, to license scanning and does a great job finding vulnerabilities. It is easy to use and visually easy to look around for the bugs. Similarly very optimized so that we can integrate with the CI/CD pipelines Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

The cost acquiring in all of the modules is pretty high. Review collected by and hosted on G2.com.

What problems is Checkmarx solving and how is that benefiting you?

Solving major bugs right from the code by applying shift left approach in an easier way. Review collected by and hosted on G2.com.

Show More

Our network of Icons are G2 members who are recognized for their outstanding contributions and commitment to helping others through their expertise. G2 Icon
9/10/2024
Validated ReviewerIncentivizedSource: G2 invite

  

 ![Verified User in Computer & Network Security](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Computer & Network Security")
UC

Verified User in Computer & Network Security

Mid-Market (51-1000 emp.)

11/2/2023

"A good alternative in a fierceful market"

4.5/5

What do you like best about Checkmarx?

Integration with CI/CD is pretty fetatureful. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

High number of false positives unless you carefully tailor it to each project. Review collected by and hosted on G2.com.

What problems is Checkmarx solving and how is that benefiting you?

Automatic CI/CD SAST testing before each new feature or release. Review collected by and hosted on G2.com.

Show More

Validated ReviewerSource: Organic

  

 ![Pankaj W.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Pankaj W.")
PW

Pankaj W.

Specialist - Information Security

Enterprise (\> 1000 emp.)

4/19/2022

"Best tool for Source code scanning"

5/5

What do you like best about Checkmarx?

The most valuable features are the easy to understand interface, and it 's very user-friendly. Reduce the code using cxsast plugin. It will scan code line by line and find most of vulnerabilities. Very easy to use. Vulnerability report is awesome. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

UI should update. Reduce the false positive. Please upgrade rules set to avoid the false positive. Review collected by and hosted on G2.com.

What problems is Checkmarx solving and how is that benefiting you?

It will find the vulnerabilities like SQL injection, cross site scripting, command injection, Xxe etc vulnerabilities. Scan speed is very good. We can review the issue easily. Review collected by and hosted on G2.com.

Show More

9/12/2023
Validated ReviewerIncentivizedSource: G2 invite

  

 ![Sujeet S.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Sujeet S.")
SS

Sujeet S.

Technology Lead

Mid-Market (51-1000 emp.)

6/25/2021

"Impressed with the Codebashing platform and AppSec awareness"

4.5/5

What do you like best about Checkmarx?

Checkmarx has an impressive Codebashing feature that has the edge over SonarQube. The application tracking-reporting feature is good too. I like the "delta-scan" feature as it is really good for cases when there are very frequent scans needed (e.g. with every major code commit, we don't want the entire source code scan to happen again). Having used both tools extensively (SonarQube and Checkmarx), I prefer Checkmarx overall. Checkmarx also fares better compared to peers when it comes to finding any vulnerabilities within the database. Since ours is a user-information driven applicaiton, it becomes even more imminent to identify the data-specfic vulnerabilities at the earliest. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Dashboarding could be better. The UI to show the current issue and the descriptive/suggestive text for the potential fix could be more "obvious" to the end-users. SonarQube scores over checkmarx in this regard.

Also, dashboarding could provide a little more flexibility towards the creation of new widgets.

One ore thing that I disliked about Checkmarx is that I could not find a free version in the market. Even for making an initial comparison, I had to contact the sales rep (the sales rep were pretty quick to respond, though). Review collected by and hosted on G2.com.

Recommendations to others considering Checkmarx:

Check your organization's needs. Checkmarx is comparitively expensive, and there is no free edition to try out first, as far as I know. Review collected by and hosted on G2.com.

What problems is Checkmarx solving and how is that benefiting you?

Static code analysis helps identify AppSec related issues at the earliest. Also, integration with the CICD pipeline ensures quality gating.

Ours is new product development in the earlier stages, and checkmarx is truly helping us by providing the developers and early insight into what could be done "right" from the beginning and instill a culture of finding issues at the earlier stage of development. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite

## Questions about Checkmarx? Ask real users or explore answers from the community

Get practical answers, real workflows, and honest pros and cons from the G2 community or share your insights.

[
Ask about Checkmarx
](https://www.g2.com/products/checkmarx/discussions/new)

GU

Guest User
•
Last activity about 2 years ago

What is Checkmarx used for?

1 Upvote

1

[
Join the conversation
](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for)

GU

Guest User
•
Last activity over 3 years ago

Which testing method does Checkmarx support?

0 Upvotes

1

[
Join the conversation
](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support)

[
View all Discussions
](https://www.g2.com/products/checkmarx/discuss)

## Pricing Insights

Averages based on real user reviews.

### Time to Implement

2 months

### Return on Investment

11 months

### Perceived Cost

$$$$$

[
View More Pricing Information
](https://www.g2.com/products/checkmarx/pricing)

## How much does Checkmarx cost?

Data powered by [BetterCloud](https://www.bettercloud.com).

Estimated Price

### $$k - $$k

Per Year

Based on data from 5 purchases.

Get Price Estimate

Checkmarx Comparisons

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_a4dc620644f85fd7e4f00b0a2267d09c/sonarqube.png "Product Avatar Image")

SonarQube

4.4/5(155)

[
Compare Now
](https://www.g2.com/compare/checkmarx-vs-sonarqube)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_eba7b910de9a9aac0b4f1b82545d0832/black-duck-coverity-static.jpg "Product Avatar Image")

Black Duck Coverity Static

4.3/5(65)

[
Compare Now
](https://www.g2.com/compare/black-duck-coverity-static-vs-checkmarx)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_1690e90d3b34e5682247349555a8ab59/opentext-core-application-security.jpeg "Product Avatar Image")

OpenText Core Application...

4.1/5(34)

[
Compare Now
](https://www.g2.com/compare/checkmarx-vs-opentext-core-application-security)

##### ##### Checkmarx Features

Analysis

Static Code Analysis

[
View More Features
](https://www.g2.com/products/checkmarx/features)

## Top-Rated Alternatives

[

 ![Veracode Application Security Platform](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Veracode Application Security Platform")

Veracode Application Security Platform

3.8/5(26)

](https://www.g2.com/products/veracode-application-security-platform/reviews)

[

 ![SonarQube](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "SonarQube")

SonarQube

4.4/5(155)

](https://www.g2.com/products/sonarqube/reviews)

[

 ![GitLab](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "GitLab")

GitLab

4.5/5(901)

](https://www.g2.com/products/gitlab/reviews)

[
View All Alternatives
](https://www.g2.com/products/checkmarx/competitors/alternatives)

##### Categories on G2

[Static Application Security Testing (SAST)](https://www.g2.com/categories/static-application-security-testing-sast)[Secure Code Review](https://www.g2.com/categories/secure-code-review)[Dynamic Application Security Testing (DAST)](https://www.g2.com/categories/dynamic-application-security-testing-dast)

[Static Application Security Testing (SAST)](https://www.g2.com/categories/static-application-security-testing-sast)[Secure Code Review](https://www.g2.com/categories/secure-code-review)[Dynamic Application Security Testing (DAST)](https://www.g2.com/categories/dynamic-application-security-testing-dast)[Static Code Analysis](https://www.g2.com/categories/static-code-analysis)[AI AppSec Assistants](https://www.g2.com/categories/ai-appsec-assistants)[Interactive Application Security Testing (IAST)](https://www.g2.com/categories/interactive-application-security-testing-iast)

[Show MoreShow Less](javascript:void(0);)

##### Explore More

[Best online registration tools for workshops](https://www.g2.com/discussions/best-remote-management-software-for-tech-startups)[What are the most trusted field sales software by sales managers at retail based on user reviews?](https://www.g2.com/discussions/what-are-the-most-trusted-field-sales-software-by-sales-managers-at-retail-based-on-user-reviews)[Is ENPS worth it for newsroom management?](https://www.g2.com/discussions/is-enps-worth-it-for-newsroom-management)

[Which enterprise asset leasing solutions have the strongest IFRS 16 and ASC 842 compliance tools for a finance team that cannot afford errors in lease accounting?](https://www.g2.com/discussions/which-enterprise-asset-leasing-solutions-have-the-strongest-ifrs-16-and-asc-842-compliance-tools-for-a-finance-team-that-cannot-afford-errors-in-lease-accounting)[Which cloud workload protection tools give security teams clean dashboards and compliance monitoring in one view rather than forcing them to switch between tools?](https://www.g2.com/discussions/which-cloud-workload-protection-tools-give-security-teams-clean-dashboards-and-compliance-monitoring-in-one-view-rather-than-forcing-them-to-switch-between-tools%20)[Pros and Cons Details](https://www.g2.com/products/checkmarx/reviews?qs=pros-and-cons)

[Show MoreShow Less](javascript:void(0);)