Verified User in Higher Education
UH
Verified User in Higher Education
Enterprise (> 1000 emp.)
"To find any security vulnerabilities, Checkmarx is an awesome tool."
4.5/5
What do you like best about Checkmarx?

Easy to scan any application to find any security threats Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Even after marking false positives, the same issue sometimes still appears as a high or critical security issue. Review collected by and hosted on G2.com.

Verified User in Investment Banking
UI
Verified User in Investment Banking
Enterprise (> 1000 emp.)
"Be a step ahead by identifying vulnerability using checkmarx to"
4/5
What do you like best about Checkmarx?

It identifies all the security vulnerabilities making your code secure than ever before. It also categorises the vulnerability into different categories based on the risk associated. Can be easily integrated with your CI pipeline to have you code scan with every build Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

We can have a more better and user friendly UI to go through the report. Review collected by and hosted on G2.com.

Verified User in Banking
UB
Verified User in Banking
Enterprise (> 1000 emp.)
"Checkmarx : Enable SAST for CI/CD Effortlessly"
4.5/5
What do you like best about Checkmarx?

The best features of Checkmarx are:

1) Open Source vulnerability scanner

2) Integration with multiple Ci/CD orchestration tools

3) Real-time reporting of static code vulnerabilities Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

I feel the Jenkins code snippet of Checkmarx is a bit complex, and it could be a lot simpler. Review collected by and hosted on G2.com.

HG
himanshu g.
Senior software engineer
Mid-Market (51-1000 emp.)
"An efficient application to check vulnerability in the software"
3.5/5
What do you like best about Checkmarx?

CheckMarx has been used an application to scan the applications to rectify vulnerability in the code and to check the security lapses. I have been using checkMarx to check the same in my .NET application and have found checkMarx to be great use. I would like to mention few good things about the same .

1.) It has support to many languages . In my case it can find the lapses in C#, Java script, J query , Typescript .

2.) The description is quite clear about the issues which makes it easier to understand the problem statement behind the security lapse.

3.) The online community present for CheckMarx is quite good which makes it easier to find the resolution Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Even though CheckMarx is quite helpful to check the security threats in the application code there are few things which can be improved by the CheckMarx team to make it more useful and efficient .

1.) There are many false positives which increase a lot of issues which in turn are required to marked as non exploitable

2.) Per user cost of CheckMarx subscription is high which makes it difficult for the small organisation to own it completely. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Enterprise (> 1000 emp.)
"Good and very useful sast tool"
4.5/5
What do you like best about Checkmarx?

The report generated by this tool is comprehensive and easy to understand

It has good charts Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

The report some times have false positives and duplication Review collected by and hosted on G2.com.

Roman P.
RP
Roman P.
Software Security Consultant
Information Technology and Services
Enterprise (> 1000 emp.)
"The lightest and most complete static analysis tool with best place to fix"
5/5
What do you like best about Checkmarx?

ease of deployment. Number of supported languages and best place to fix function. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Too much detail in the report for small security shops. Review collected by and hosted on G2.com.

Verified User in Financial Services
UF
Verified User in Financial Services
Enterprise (> 1000 emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"Great for finding overlooked or unthought of issues"
4/5
What do you like best about Checkmarx?

I like the way that the checkmarx report provides a detailed account of al potential vulnerabilities and then provides examples of how the issue can be fixed. This is very helpful when it comes to trying to resolve all issues. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

As with anything automated, some issues that are found are just non-issues. We use several different security gating products like Checkmarx and I would say that it is less often incorrect than the others. Review collected by and hosted on G2.com.

Verified User in Banking
UB
Verified User in Banking
Enterprise (> 1000 emp.)
"Great application for Software security"
4.5/5
What do you like best about Checkmarx?

Results are pretty good with CheckMarx. This tool is helpful to build secure source code. CheckMarx scan report gives detailed view of each issue and flowchart is given for the variables which might cause security threat. Code scanning is fast. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Sometimes reports generated by the CheckMarx scan contain lot of false positive issues even though code is designed in a way that ensures security. This decreases the readability of the reports. Review collected by and hosted on G2.com.

Hatim B.
HB
Hatim B.
IT Architect & Project manager
Enterprise (> 1000 emp.)
"A useful SAST tool to improve maturity in IT security"
4.5/5
What do you like best about Checkmarx?

Our choice of Checkmarx as a static code audit tool was done after a long reflection. the richness in terms of languages and the customization of the presets were determinents. We were accompanied at first by a very competent editor team. Today, the use of the tool is unavoidable. We use it both as an integrated tool in our IDEs but also when building in our continuous integration platform. He is also at the hand of the security team to audit code delivered by an external service provider.

We also appreciate the possibility of modifying but also creating new rules to eliminate false positives.

The tool is also rich in terms of indicators and charts. it provides a dashboard that makes it easy to track application risk level scores over time and provides management with comprehensive reports. the details of the vulnerabilities detected and the description of the corrections allows the development teams to correct the vulnerabilities but also to learn about the security of the coding. Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

At each audit, the number of false positives is high. but this is a defect specific to SAST tools. knowledge of the business specificities of the application is necessary to personalize the presets to eliminate false positives.

This tool is a step in the security audit process, it must be completed by DAST and IAST audits. Review collected by and hosted on G2.com.

VC
vidya vignan c.
Mid-Market (51-1000 emp.)
"We use it for checking the test cases"
4.5/5
What do you like best about Checkmarx?

Automation has been much more easier with the checkmarx Review collected by and hosted on G2.com.

What do you dislike about Checkmarx?

Even if 1 test fails it shows the everything as failed Review collected by and hosted on G2.com.