---
title: SonarQube Reviews
meta_title: 'SonarQube Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 155 reviews by the users' company size, role or industry
  to find out how SonarQube works for a business like yours.
aggregate_rating:
  rating_value: 4.4
  review_count: 155
  scale: '5'
date_modified: '2026-07-28'
parent_category:
  name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t"
  url: https://www.g2.com/categories/devsecops
---

# SonarQube Reviews
**Vendor:** SonarSource Sàrl  
**Category:** [Static Code Analysis Tools](https://www.g2.com/categories/static-code-analysis)  
**Average Rating:** 4.4/5.0  
**Total Reviews:** 155
## About SonarQube
Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.



## SonarQube Pros & Cons
**What users like:**

- Users value how SonarQube **efficiently flags code quality and security issues** , ensuring a clean and maintainable codebase. (24 reviews)
- Users value the **issue filtering and prioritization features** of SonarQube, enhancing focus on high-priority tasks. (20 reviews)
- Users value the **issue identification and prioritization** features of SonarQube, improving focus on critical tasks. (19 reviews)
- Users find SonarQube&#39;s **ease of use** invaluable for maintaining code quality and integrating seamlessly into development workflows. (18 reviews)
- Users appreciate the **easy integrations** with existing CI/CD tools, enhancing their development workflow seamlessly. (18 reviews)
- Users value the **seamless integration** of SonarQube with CI/CD pipelines, enhancing code quality management effortlessly. (18 reviews)
- Security (15 reviews)
- Vulnerability Detection (15 reviews)
- Code Review (12 reviews)
- Integration Support (12 reviews)

**What users dislike:**

- Users face challenges with **software bugs** as SonarQube can consume excessive RAM and occasionally reports false positives. (12 reviews)
- Users find SonarQube&#39;s configuration **complex** , especially for beginners, leading to difficulties and overwhelming warnings to manage. (10 reviews)
- Users encounter **false positives** that complicate evaluations, though mitigation options exist through detailed analysis and rule customization. (10 reviews)
- Users find that SonarQube&#39;s **complexity in configuration** and excessive warnings can hinder effective usage and efficiency. (8 reviews)
- Users find the **complex setup** of SonarQube challenging, especially for beginners unfamiliar with the configuration process. (8 reviews)
- Users often face **integration issues** with SonarQube, particularly in connecting to GitLab and navigating its complexities. (8 reviews)
- Users find SonarQube&#39;s **limited features** frustrating, particularly with restrictions on scanning and analysis capabilities. (8 reviews)
- Users note that the **expensive nature** of SonarQube limits access to advanced features and complicates setup. (7 reviews)
- Difficult Setup (6 reviews)
- Setup Difficulty (6 reviews)

## SonarQube Reviews
  ### 1. Sonarqube is a great tool for monitoring codebases.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Ethan B. | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 18, 2024

**What do you like best about SonarQube?**

Quick, easy way to see major issues with code, duplications, security issues, etc. Easy to setup and maintain. Support has been very quick and helpful when I have needed them.

**What do you dislike about SonarQube?**

While it supports a decent ammount of prgoramming languages, it definitely doesn't support all of them. Specifically Dart projects in Flutter which we use for mobile app developement (though apparently there are plans to add it in the future).

**What problems is SonarQube solving and how is that benefiting you?**

It helps us to make sure we are not duplicating code, using depricated libraries and methodes, and helps to identify any security issues.

  ### 2. SonarQube has Improved our Tech Debt!

**Rating:** 5.0/5.0 stars

**Reviewed by:** Kelli K. | Senior Software Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

We have implemented it across our org, and it has been awesome. Code coverage everywhere has gone up, more bugs are being fixed, and there is more visibility into team's tech debt.

**What do you dislike about SonarQube?**

The one downside to the new versions is lack of support for older node versions. Our monolith is still using some old versions (which of course we need to work on upgrading!), keeping us from upgrading sonarqube.

**What problems is SonarQube solving and how is that benefiting you?**

It is helping us increase code coverage across our whole organization, which is making for better code all around.

  ### 3. Good but I would like to have training courses

**Rating:** 4.5/5.0 stars

**Reviewed by:** josue d. | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 25, 2024

**What do you like best about SonarQube?**

I like how complete the tool is, I like that I can have many users with different permissions

**What do you dislike about SonarQube?**

I don't like the complexity of integrations
I don't like that there is no error documentation
I don't like that there are no training courses.
I would like a certification

**What problems is SonarQube solving and how is that benefiting you?**

in ease of use, because it is easier to make demos that way

  ### 4. Must for high quality development

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** May 03, 2024

**What do you like best about SonarQube?**

SonarQube helps to evaluate your code during the development itself. It provides a great amount of reviews/suggestions to improve your code. It also supports a variety of programming languages. The tool is easy to use.

**What do you dislike about SonarQube?**

Nothing as such, but some of the static analysis could be improved for certain languages like C++.

**What problems is SonarQube solving and how is that benefiting you?**

We were facing quite a few challenges in manual code reviews and  standardizing the coding formats. Sonarqube came to our rescue during our development to have a good quality code with integrated chcks into Developer IDE as well as the build pipeline.

  ### 5. Good tool, mixed experience with SonarSource

**Rating:** 1.5/5.0 stars

**Reviewed by:** Verified User in Medical Devices | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 28, 2024

**What do you like best about SonarQube?**

Good integration with CI tools. Supports many programming languages. Modern web UI.

**What do you dislike about SonarQube?**

My experience as a SonarSource customer shows that they manifest little interest in small customers. In addition, their quality policy is poor when it comes to fixing major bugs in their code. For instance, this ticket has now been open for 1 year without any time frame for fix:
https://sonarsource.atlassian.net/browse/CPP-4175
This is unsatifying and quite ironical actually, for a company writing software for code quality.

**What problems is SonarQube solving and how is that benefiting you?**

Static code analysis, discover potential bugs in code.

  ### 6. Game Changer for Shifting Left

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Manufacturing | Enterprise (> 1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

SonarQube has been an invaluable tool for our development team that helps us catch issue earlier on in the SDLC.  We like the wide range of static code analysis rules, easy to use UI, and the large number of supported programming languages.

**What do you dislike about SonarQube?**

Occasionally, when analyzing large codebases or running complex rules, SonarQube can be resource-intensive and slow down the analysis process.  Also, there are more languages we would like to see supported as the product matures.

**What problems is SonarQube solving and how is that benefiting you?**

The ability to shift left on code quality and application security by using SonarQube in our SDLC.

  ### 7. A powerful tool for more powerful teams

**Rating:** 4.0/5.0 stars

**Reviewed by:** Franco R. | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

This easy-to-configure tool increases code quality in no time

**What do you dislike about SonarQube?**

It takes a bit to achieve the cultural change of the team necessary to take advantage of the insights reported by the tool

**What problems is SonarQube solving and how is that benefiting you?**

We were able to resolve code errors and improve quality. We also increased test coverage by reducing the number of functional errors

  ### 8. A Tool to Improve Code Quality!

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ankshuk R. | Specialist Programmer, Enterprise (> 1000 emp.)

**Reviewed Date:** July 20, 2022

**What do you like best about SonarQube?**

SonarLint is the most customizable and Free Open Source tool that can be integrated with multiple IDEs and coding platforms like Spring tools suite, IntelliJ Idea etc.
The fact that it is this customizable and user friendly, is what I like about it the most.

**What do you dislike about SonarQube?**

Although it is very customizable and user-friendly, SonalLint can be very vague at times, there are times when it throws errors in the code like some auto wiring errors for spring-boot projects that are ignorable.
Also, it does not have a way to understand and improve code complexity.

**What problems is SonarQube solving and how is that benefiting you?**

SonarLint reduces the overall time to review code quality and helps in making the code readable. It has helped our codes to be more production friendly and less bulky. It also resolves potential errors areas of code and warns the developer while coding itself.

  ### 9. Simple to set up, use, and provides useful feedback on code quality

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 18, 2024

**What do you like best about SonarQube?**

- The basic setup (automated analysis) is as simple as it gets to integrate with GitHub and supported languages
- The language-specific rules are of good quality and we rarely encounter false positives
- The overview it provides of the code quality trends is particularly nice

**What do you dislike about SonarQube?**

- Manual setup could be documented better (it is not always fully clear which properties you need to define and why)
- There is no way to manually trigger an analysis with an automated analysis setup, which is sometimes necessary as the GitHub application "bugs out" and doesn't provide an analysis

**What problems is SonarQube solving and how is that benefiting you?**

It is generally difficult to track code quality across different projects, and SonarQube offers a simple way with not much additional overhead to track and analyse code quality for each project.

  ### 10. Wonderful tool to learn from your mistakes

**Rating:** 4.5/5.0 stars

**Reviewed by:** Soufiane M. | System Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

* Comprehensive Code Analysis
* Very easy to use
* Very easy to integrate with existing CI/CD tools

**What do you dislike about SonarQube?**

* Difficult to implement in a rigid environment

**What problems is SonarQube solving and how is that benefiting you?**

Issues related to code quality
Recurrent mistakes that need to be taught to all new comers can be added as rules
Code Legacy

  ### 11. Deeper insights into code quality

**Rating:** 5.0/5.0 stars

**Reviewed by:** Frederik E. | Intern konsulent, Small-Business (50 or fewer emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

Automated Pullrequest decoration for quick insights into new code.

**What do you dislike about SonarQube?**

Onboarding of new GitHub Actions was difficult - I believe however, that this flow has been vastly improved since then.

**What problems is SonarQube solving and how is that benefiting you?**

Automated validating of simple errors, that are caught in static analysis, to ease load off other developers.

  ### 12. SonarQube: Help Developers to accelerate their productivity

**Rating:** 4.0/5.0 stars

**Reviewed by:** Damien G. | Enterprise (> 1000 emp.)

**Reviewed Date:** April 18, 2024

**What do you like best about SonarQube?**

Using SonarQube transformed our development process by providing comprehensive code analysis. it identified and flagged code smells, bugs and security vulnerabilities enabling our team to address them early in the development cycle

**What do you dislike about SonarQube?**

Difficult to integrate with. Low integration with other ecosystem especialy with Kubernetes/Openshift.

**What problems is SonarQube solving and how is that benefiting you?**

code analysis

  ### 13. Sast tooling experience

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Manufacturing | Enterprise (> 1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

SonarQubes ability to analyze the code at local build as well in CI/CD build add an important steps in improving the quality of the code. The recently added security analsyis of the code is very helpful for us for discovering any vulnerabily of the written code.

**What do you dislike about SonarQube?**

Reporting can be further improved with slice and dice featues

**What problems is SonarQube solving and how is that benefiting you?**

SonarQube is helping improve the code quality interms of security and as well as overall quality of the code

  ### 14. SonarQube Review

**Rating:** 5.0/5.0 stars

**Reviewed by:** murthy g. | DevOps Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 18, 2024

**What do you like best about SonarQube?**

It's very easy to use and the customer support is fantastic. Very easy to integrate with other tools like TeamCity.

**What do you dislike about SonarQube?**

Nothing in special we dislike about the product.

**What problems is SonarQube solving and how is that benefiting you?**

We have been using sonar for Statis code analysis.

  ### 15. Must have static code analysis tool in every developer's tool box

**Rating:** 5.0/5.0 stars

**Reviewed by:** Suman P. | Principal Software Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** August 27, 2023

**What do you like best about SonarQube?**

SonarLint is an extremely powerful static code analysis tool. It is available as a plugin for all popular integrated development environments. This enables running the tool as soon as the new code is written so that any violations can be rectified immediately preventing technical debt and to ensure it meets the organization's quality standards.

**What do you dislike about SonarQube?**

SonarLint is an extremely powerful tool. It allows customization as per the organizations quality and coding standards. One thing it needs to improve is that local run of sonarlint does not report all the violations that the server version reports. This area needs to be fixed as 100% of the violations can be caught in the developer workstation itself.

**What problems is SonarQube solving and how is that benefiting you?**

SonarLint is a static analysis tool that scans the code to ensure the code meets the organizations quality standards. My organization is very stringent about the code quality. SonarLint is helping me everyday to quickly scan the code in my workstation itself to identify any violations that needs to be rectified. Along with the violations it shoulds suggests the possible fixes.

  ### 16. QA with SonarQube

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Biotechnology | Enterprise (> 1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

The ease of use of SonarQube (in house we call it sqube) is vital to our teams in increasing the velocity of development

**What do you dislike about SonarQube?**

The admin interface could be simplified. Also it does't automatically provide pull requests with fixes.

**What problems is SonarQube solving and how is that benefiting you?**

In BioTech, safety is paramount. We use Sqube as a tool to show that we follow the latest trends to provide GxP methods found in the industry.

  ### 17. SonarQube as part of SDLC

**Rating:** 5.0/5.0 stars

**Reviewed by:** Dimitar K. | InfoSec, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 24, 2024

**What do you like best about SonarQube?**

The tool is really good for Static Code Analysis - detecting bugs, vulnerabilities and code smells.  CI/CD pipeline integrations are really usesfull and cruical as part of the SDLC. Another great feature is the custom rules - for the advanced users. Apart from theese things -  combination with SonarLint is great!

Last but not least eveyone can start with the free version and check if it will match their way of working - which is not available for many other tools!

**What do you dislike about SonarQube?**

It would be great if there is better dependencies report!

**What problems is SonarQube solving and how is that benefiting you?**

It's part of our Secure code review!

  ### 18. Exceptional

**Rating:** 5.0/5.0 stars

**Reviewed by:** Sheldon R. | Senior Software Engineer | Technical Lead, Small-Business (50 or fewer emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

Great way to measure quality and ensure all new dev meets expected quality standards.

**What do you dislike about SonarQube?**

Pricing is a little too expensive - we need local pricing tiers.

**What problems is SonarQube solving and how is that benefiting you?**

We know exactly what standard code is at when it merges into our main branch. 
Shift testing left into the IDE with SonarLint

  ### 19. really Bad i have issues to implement on a repo sonaqube free edition

**Rating:** 0.0/5.0 stars

**Reviewed by:** theo g. | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

they sell that is good , i don't have a change to fully test

**What do you dislike about SonarQube?**

complicated to implement , lack of documentation for diff version .
all points to developer edition of sonaclone that is expensive

**What problems is SonarQube solving and how is that benefiting you?**

unable to make work , java errors for every where

  ### 20. Best tool to inspect code quality and detect bugs and very easy to use.

**Rating:** 4.5/5.0 stars

**Reviewed by:** Mohit S. | Mid-Market (51-1000 emp.)

**Reviewed Date:** September 07, 2023

**What do you like best about SonarQube?**

I like everything about SonarQube, It is best tool to make your code bug free and optimised. It analysis your code very fast and provide proper path of the issue in your code and also provide best suggestion to how to solve it.

**What do you dislike about SonarQube?**

SonarQube is not snychronze with the IDE, from where I am solving the issues. Whenever I solve an issue I have to re-run the sonarQube to check whether the issue is solved or not. It is little time consuming.

**What problems is SonarQube solving and how is that benefiting you?**

SonarQube is helping me to improve my code performance and make it bug free, It also suggest best coding practices which helps to increase my knowledge and learn standard coding.

  ### 21. SonarQube delivers on Code Quality and Code Security

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Human Resources | Enterprise (> 1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

SonarQube support an extensive number of code languages and provides flexibility to introduce quality rules and quality gates, lastly shifting left for Code Quality with SonarLint. The solution is easy to implement and use. Customer support provides timely responses. We have incorporate SonarQube within our CI/CD SDLC workflow.

**What do you dislike about SonarQube?**

No support for Elixir, SonarQube Enterprise not offered as a native SaaS Cloud option.

**What problems is SonarQube solving and how is that benefiting you?**

Improving Code Quality, Code Security and shifting left with SonarLint

  ### 22. Enhance our progress

**Rating:** 5.0/5.0 stars

**Reviewed by:** Marco B. | Enterprise (> 1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

- Easy to install and use in our pipelines.
- Integrates with GitHub and Jira.
- Great support and community for help.

**What do you dislike about SonarQube?**

Some documentation can be a bit confusing.

**What problems is SonarQube solving and how is that benefiting you?**

We'll keep releasing quality code.

  ### 23. Best Tool for Code Quality

**Rating:** 5.0/5.0 stars

**Reviewed by:** Recep C. | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

Especially Issues about security, and code smells are great to be better developer

**What do you dislike about SonarQube?**

To develop new ext or rules for sonarqube

**What problems is SonarQube solving and how is that benefiting you?**

For huge applications, you can manage code quality easily, best sync for teams

  ### 24. SonarQube for Static code analysis

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

Its pretty effortless to integrate this with DevSecoOps pipeline

**What do you dislike about SonarQube?**

It would be good if they provide support for more legacy code languages.

**What problems is SonarQube solving and how is that benefiting you?**

Code quality improvement, early vulnerability findings and resolution.

  ### 25. No way to escape from writing the quality code.

**Rating:** 4.5/5.0 stars

**Reviewed by:** sumit k. | Software Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 07, 2023

**What do you like best about SonarQube?**

Automated quality code check analysis. The code smells, and major issues can easily be tracked mostly, which can cause production failure. We can integrate it with our applications and can perform the sonar checks with a single command.

**What do you dislike about SonarQube?**

Though most of the time, it works well but sometimes creates problems without any significant issues in the code. Very strict in terms of code coverage part. Integrating and performing pre-flight jobs with sonar is a difficult process if you are a beginner, which means it requires complete knowledge of it.

**What problems is SonarQube solving and how is that benefiting you?**

In my organization, we have integrated the sonarQube with GitHub pre-flight checks and CI-CD pipeline to perform the quality checks. We have set up a code coverage threshold of 90%, which restricts merging the code if the coverage is below the threshold. So in this way, we always ensure that the code developers write is up to the mark and easily readable.

  ### 26. Great tool but getting developers to adopt in large enterprise is very difficult

**Rating:** 2.5/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Enterprise (> 1000 emp.)

**Reviewed Date:** April 24, 2024

**What do you like best about SonarQube?**

It has great features and is very transparent. It relies on open source community and is overall a good product

**What do you dislike about SonarQube?**

Ease of use is not that great. The datacenter prouct is not relaiable. Customer support for enterprise product is also that that great. Lot of time they point you to KB article which doesnt always help.

**What problems is SonarQube solving and how is that benefiting you?**

Reducing code smells and improving overall code quality and security

  ### 27. SonarLint Review

**Rating:** 4.5/5.0 stars

**Reviewed by:** Shubham . | Software Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** August 24, 2023

**What do you like best about SonarQube?**

SonarLint is a free IDE extension that connects to the Sonar Cloud. It is good tool to use. As, you type the code it highlights the issue it found and also suggests how to resolve them. This saves time as issues can be resolved at the time of writing the code.

**What do you dislike about SonarQube?**

The thing I disliked about SonarLint based on my experience is at times it does n't gives correct solutions to the issues highlighted. Also, you can't use it to run checks only for a specific piece of code or find code coverage of the specific piece of new code written.

**What problems is SonarQube solving and how is that benefiting you?**

SonarLint is a extension available for free for IDE that can be use to identify the issues or bug in the code while writing. It highlights the issues thus making easy for developers to resolve the issues at the time of writing the code itself.

  ### 28. Best Code Quality Analysis tool : SonarQube

**Rating:** 5.0/5.0 stars

**Reviewed by:** Kaviraj R. | System Administrator, Small-Business (50 or fewer emp.)

**Reviewed Date:** October 07, 2023

**What do you like best about SonarQube?**

SonarQube is its ability to identify and highlight code quality issues. It can detect coding errors, code smells, and potential bugs, enabling developers to fix them before they become more significant problems

**What do you dislike about SonarQube?**

SonarQube can be complex and difficult to configure
community version can only be integrated with one branch, and the enterprise version is expensive

**What problems is SonarQube solving and how is that benefiting you?**

SonarQube helps identify issues like: Bugs, Code smells, Security hotspots, Other vulnerabilities.
Maintains code quality
Improves coding structure

  ### 29. Quality Code Scans on the cloud

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** September 15, 2023

**What do you like best about SonarQube?**

Cloud based and hence no need to install on any server.
Integrates into various version control systems using CI/CD pipelines.
Has a huge database of various rules per coding platform. 
Helps in scanning large quantities of code efficiently. Also, provides insights into possible security misconfigurations.

**What do you dislike about SonarQube?**

Initial setup is a little difficult, but manageable.
Can give a lot of false positives.
If the number of lines cross a particular threshold the overall scan is taking a very long time.

**What problems is SonarQube solving and how is that benefiting you?**

There are a few code issues that can escape even the most experienced reviewer. The static code scan from Sonar Cloud helps to detect code smells. 
Also, we were able to see unreachable code and some security misconfigurations which is not easily visible to a manual review.

  ### 30. Awesome tool for integrated static code analysis along with code smells

**Rating:** 4.5/5.0 stars

**Reviewed by:** NItin  K. | Enterprise (> 1000 emp.)

**Reviewed Date:** October 27, 2023

**What do you like best about SonarQube?**

Amazing user interface, fast learning curve, faster installation and deployment, good customer support, security scanning features and code smells

**What do you dislike about SonarQube?**

lacks in good graphs and reports generations, not very easy to customize the reports and export them, webAPI is not value for money

**What problems is SonarQube solving and how is that benefiting you?**

Helps in fiding the vulnerabilities in our products and give early detection,. Its able to intergrate well with all our build chain.

  ### 31. Org Wide Static Code Analyzer for Code Quality

**Rating:** 5.0/5.0 stars

**Reviewed by:** Rahul S. | Technical Architect, Small-Business (50 or fewer emp.)

**Reviewed Date:** May 09, 2023

**What do you like best about SonarQube?**

SonarQube is an excellent tool for maintaining code quality and enforcing code quality rules organization-wide. It has a free and open-source version which can be self-hosted. 
Badges can also be created, which can be embedded in repos. It can be integrated with the CICD process

**What do you dislike about SonarQube?**

The free and open source version can be pretty limited and restrictive (it does not allow per-branch scanning, and only one branch can be analyzed at once) 
The Enterprise version / Cloud version is quite expensive for a small startup

**What problems is SonarQube solving and how is that benefiting you?**

SonarQube is an excellent tool for maintaining code quality. It helps track tech debt and common code smells. Keeping SonarQube score high generally indicates a higher quality of code repo. 
Rules can be enforced on an organization-wide basis or a per-repository basis. It also works with a lot of different languages and is continuously updated

  ### 32. Sonar qube

**Rating:** 3.0/5.0 stars

**Reviewed by:** Sundarrajan G. | Senior Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** November 27, 2023

**What do you like best about SonarQube?**

If you don't have much budget to go for sast products, it's good to go for this product, it's good and provides most of the best practices.

**What do you dislike about SonarQube?**

It's not easy to integrate with cicd pipeline also you might not get very frequent or recent security recommendation like the commercial products.

**What problems is SonarQube solving and how is that benefiting you?**

If you don't have much budget to go for sast products, it's good to go for this product, it's good and provides most of the best practices.

  ### 33. Excellent tool to check a code quality

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** August 25, 2023

**What do you like best about SonarQube?**

Most of the times the bug detection feature is very quick & sharp even while writing the code.
Excellent in the categorization of the severity (blocker to info) of issues.
Most of the time gives accurate suggestions to fix the issues.
Saves time in issue detection and fixing the issue. Also, helps in improving the efficiency of the code.
Easy to configure & set rules as per organization policies.
Good for new coders to learn coding & fix mistakes immediately.

**What do you dislike about SonarQube?**

It gets slower in visual studios.
Sometimes it doesn't give correct suggestions on the issues.

**What problems is SonarQube solving and how is that benefiting you?**

Helps a lot in improving code quality and performance.
Saves a lot of time in bug detection & fixing the bugs.
Before unit testing, developers can easily identiy & fix the bugs.

  ### 34. SonarLint - Awesome extension for Sonar

**Rating:** 5.0/5.0 stars

**Reviewed by:** Deepak K. | Programming Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** August 26, 2023

**What do you like best about SonarQube?**

SonarLint is very helpfull IDE extension for Sonar Analysis. I helps me in writing bug free code by highlighting the bugs or defects in the code. Also, it suggest fixes of the highlighted bugs

**What do you dislike about SonarQube?**

Do not find anything to dislike, overall good experience so far and it helps a lot during the code development.

**What problems is SonarQube solving and how is that benefiting you?**

SonarLint is extension for IDE. I use it in intellij and helps in identifying the bugs at the time of writing the code by highlighting. It helps me a lot, many times highlighted the bugs that had serious security related issues.

  ### 35. Sonarqube review

**Rating:** 5.0/5.0 stars

**Reviewed by:** Prakash E. | Sr. Software Engineer (DevOps), Small-Business (50 or fewer emp.)

**Reviewed Date:** July 07, 2023

**What do you like best about SonarQube?**

Its a efficient tool using performing code review.easy to implement and getting reports very easily and we can integrate on serverless also on eks. It showing wonderfull results

**What do you dislike about SonarQube?**

Actyally no dislikes. But one thing it has default h2 database better we have postgress

**What problems is SonarQube solving and how is that benefiting you?**

Its generating code quality reports in efficient way. Its benifiting you very usefully

  ### 36. A great analysis tool based on cloud platform.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Achyut S. | Cloud Architect , Enterprise (> 1000 emp.)

**Reviewed Date:** April 30, 2023

**What do you like best about SonarQube?**

SonarCloud is a cloud-based code analysis service that helps in detecting and fixing bugs, vulnerabilities, code issues, and other quality issues in your code.
One of the best feature i like about it is its integration with various CI/CD tools like GitLab, GitHub etc.

**What do you dislike about SonarQube?**

As sonar cloud is used on-the-go cloud analysis tool for the code. So, just like any other tool in the market in this particular category, it increases the complexity of the programming for the first-time, and later on some minor maintenance is needed which is fine.

**What problems is SonarQube solving and how is that benefiting you?**

SonarCloud is benefits me by making my coding experience more enjoyable, productive, and rewarding. For example:
1. Improved code quality
2. Enhanced collaboration
3. Reduced risks and associated costs.

  ### 37. Since I have found SonarCloud our Code Quality increased 10X

**Rating:** 5.0/5.0 stars

**Reviewed by:** Paulo A. | CTO, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 12, 2022

**What do you like best about SonarQube?**

The Pull Request Analysis is our best option to keep your code clean of bugs and reduce manual work, increase test coverage and in the overall align the code quality across all your repositories in the most automated way possible by entirely using Github Actions, in our days it has become an indispensable tool for all software engineer team.

**What do you dislike about SonarQube?**

The software fully does what it says it does; there is nothing to complain about. Fair price, has awesome features, 100% availability. the only added feature I believe it can be added is the ability to produce reports using multiple repos.

**What problems is SonarQube solving and how is that benefiting you?**

Sona Cloud automates the process of validation on code coverage, bug detection and pattern usage, as well to identify possible security risks, and all of this is done on a Pull Request base making the CI/CD pipelines 10X faster

  ### 38. My Experience with Sonar Cloud and SonarLint

**Rating:** 4.5/5.0 stars

**Reviewed by:** Narayan S. | Sr. Technical Architect, Enterprise (> 1000 emp.)

**Reviewed Date:** April 11, 2023

**What do you like best about SonarQube?**

Supports major Cloud Providers/Cloud Platforms and Many popular Programming Languages. We are in the age of the Security left shift. The integration of SonarLint with IDE brings security even when code is pushed to source control.

**What do you dislike about SonarQube?**

Data Privacy, Data Sovereignty(Some countries/organizations don't allow your data to go outside your network even if it's an analysis result data). Cost is another factor. Sometimes it produces a large number of false positives.

**What problems is SonarQube solving and how is that benefiting you?**

It helps in remediating the following
1. Vulnerabilities 
2. Bugs
3. Security Hotspots 
4. Code Smells

There is a difference between traditional and cloud-native security; SonarCloud or SonarQube greatly helps here.
With many developments being cloud-native, there is a need for Clean Code in cloud-native.

  ### 39. Good tool to detect issues within code

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Sports | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 20, 2023

**What do you like best about SonarQube?**

- Provides a wide range of code analysis tools that help developers identify and fix code quality issues, security vulnerabilities, and bugs.

- Offers support for a wide range of programming languages, including Java, C/C++, C#, Python, and many more.

- Integrates with a variety of popular build systems, CI/CD pipelines, and code repositories, including Jenkins, Azure DevOps, GitHub, and GitLab, making it easy to incorporate SonarQube into existing workflows.

**What do you dislike about SonarQube?**

- Sometimes it may produce false positives or miss certain types of code quality issues, requiring developers to perform additional manual code review.

- The documentation can be overwhelming, and some of users with which I have worked with have face difficulties in finding the information they need.

**What problems is SonarQube solving and how is that benefiting you?**

It majorly solves our probelm by integrating into our DevOsp tool chains such as Jenkins, Azure DevOps, GitHub, and GitLab, making it easy to incorporate SonarQube into existing workflows.

  ### 40. SonarCloud -the new generation code security tool

**Rating:** 4.0/5.0 stars

**Reviewed by:** Somnath N. | Senior Consultant, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 08, 2023

**What do you like best about SonarQube?**

SonarCloud is one of the top most vulnerabilitie and security tool which inspect bug in code which is used to build pipeline.its has ability to identify error in code.

**What do you dislike about SonarQube?**

although it's has many advantages but some big advantage about it price so as it it the product of Microsoft. so while you run with private devops with external tools you have to purchase its license extra.

**What problems is SonarQube solving and how is that benefiting you?**

before SonarCloud launched commercially tester ase testing code one by one brunch and it's take lot of time to deliver in production. but after SonarCloud launch it's make tester life easy and bug free

  ### 41. Want to improve your code quality? Sonarlint is the tool for you.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Joy M. | Full stack developer, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 20, 2023

**What do you like best about SonarQube?**

It provides one of the best extensions for VS Code to improve code quality and maintain standards throughout. With its excellent inbuilt rules, I improved my coding skills. It can help you while you code; for example, if a written statement doesn't need a null check, it notifies the developer.

**What do you dislike about SonarQube?**

So far never had any problems with the rules which were predefined. One thing is that it slows down development, but it's better to be cautious than to solve the mess later.

**What problems is SonarQube solving and how is that benefiting you?**

We had five teammates in one project, and our coding standards differed. To make it almost unanimous, we enforced to the installation of Sonarlint in our VS Code to maintain coding standards.

  ### 42. Code review at coding time

**Rating:** 5.0/5.0 stars

**Reviewed by:** Brallan G. | SRE &amp; DevOps Engineer, Program Development, Mid-Market (51-1000 emp.)

**Reviewed Date:** March 09, 2023

**What do you like best about SonarQube?**

SonarCloud is one of the indispensable tools to improve the quality of the code and in our continuous integration model gives us that peace of mind in each release to production, also SonarCloud is one of the tools that help us with compliance in some items of our SOC2 certification.

**What do you dislike about SonarQube?**

Scanning at coding time with the help of the agent is a bit slow in very large projects.  And I think a way to globally configure the Long-lived branches pattern should be enabled.

**What problems is SonarQube solving and how is that benefiting you?**

Improve the code quality in each new release, meet the points related to security and vulnerabilities in the code for our SOC2 certification, developers to be more attentive to details when coding.

  ### 43. One stop solution for analysing code and ensure quality

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** August 15, 2023

**What do you like best about SonarQube?**

It provides all varieties of the code scans and enterprise provides branch-based analysis

**What do you dislike about SonarQube?**

Opensource doesn't allow branch analysis

**What problems is SonarQube solving and how is that benefiting you?**

SonarQube helps development teams build successful and secure applications as part of their CI pipeline.

  ### 44. My Code Quality Thanks SonarCloud

**Rating:** 4.5/5.0 stars

**Reviewed by:** Jenna P. | Senior Product Management Specialist, Enterprise (> 1000 emp.)

**Reviewed Date:** March 02, 2023

**What do you like best about SonarQube?**

SonarCloud makes it easy to set your own rules when doing a code scan and to notify you so you can stop pushing a product if any of those rules aren't satisfied. It integrates well with other products as well.

**What do you dislike about SonarQube?**

It integrates well but takes quite a bit of work to get set up. Overall it's not the quickest tool and there are definitely more robust options for scanning out there.

**What problems is SonarQube solving and how is that benefiting you?**

We have been able to improve the quality of our code with the analysis checks specifically. We have also become more aware of how to improve based on the analytics.

  ### 45. Lightweight statis code analysis tool

**Rating:** 4.0/5.0 stars

**Reviewed by:** Benoît F. | Specialist, Security Operations Center, Enterprise (> 1000 emp.)

**Reviewed Date:** March 17, 2023

**What do you like best about SonarQube?**

Is very responsible and light. Quickly report issues in code

**What do you dislike about SonarQube?**

Requires a certain level of knowledge (ex: CI-CD / pipeline). Cannot be implemented by security teams without assistance from the developer teams.

**What problems is SonarQube solving and how is that benefiting you?**

Helps applying best practices in coding. Is a complement to our dynamic app scanning tools.

  ### 46. Great plugin for Code Analysis

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** June 22, 2023

**What do you like best about SonarQube?**

It's good to analyze code. It improves code practice.

**What do you dislike about SonarQube?**

Sometimes it shows code smell that are not genuine

**What problems is SonarQube solving and how is that benefiting you?**

Sonar cube is easy to use  and solving code review effort as shows best practices for code

  ### 47. Regarding SonarLint Review

**Rating:** 4.5/5.0 stars

**Reviewed by:** Anirudh J. | Software Engineer 2, Enterprise (> 1000 emp.)

**Reviewed Date:** April 11, 2023

**What do you like best about SonarQube?**

I have integrated SonarLint in VS code it helps me to modularize my code.

**What do you dislike about SonarQube?**

Sometimes I get warning lines based on cache memory.

**What problems is SonarQube solving and how is that benefiting you?**

It helps me to track bugs and maintaining code modularity

  ### 48. IDE for all language developers

**Rating:** 4.5/5.0 stars

**Reviewed by:** MANOJ GOWDA T. | Data Scientist, Enterprise (> 1000 emp.)

**Reviewed Date:** November 08, 2022

**What do you like best about SonarQube?**

Sonarlint is an IDE that supprts all the major programming languages like Java, Python, C, C++, C#, JavaScript, etc. There are other IDEs made only for specific languages. But sonarlint  is a one stop you can code and develop in any language you prefer.

**What do you dislike about SonarQube?**

There is no such thing which I dislike. The only thing I can add is that It should work on frontend to make the IDE looks more user friendly and easy to use. And add many themes so that the user can select based on their preference.

**What problems is SonarQube solving and how is that benefiting you?**

Sonarlint helps to write code easily. Its real time syntax error detection helps not to make error. Easy to find bugs and fix bugs. Formatting is so good that its easy to find the blocks of code. It provides good platform for developer to develop and maintain product easily.

  ### 49. Review of SonarCloud

**Rating:** 3.5/5.0 stars

**Reviewed by:** Aashish H. | Software Developer, Enterprise (> 1000 emp.)

**Reviewed Date:** May 02, 2023

**What do you like best about SonarQube?**

Easy code quality and security checks at real time with the usage of plugins is one of the best features that sonarcloud offers.

**What do you dislike about SonarQube?**

Inability to detect runtime code flaws is something that can be improved.

**What problems is SonarQube solving and how is that benefiting you?**

Making the code much more efficient by allowing the users to refine their code and remove any bugs

  ### 50. Stati code analysis tool part of the SonarQube platform

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** August 22, 2023

**What do you like best about SonarQube?**

Integration with various code editors and IDEs

**What do you dislike about SonarQube?**

Limited to code level, dependancy on language rules and false positives

**What problems is SonarQube solving and how is that benefiting you?**

Identifying and fixing code quality issues early in the development process


## SonarQube Discussions
  - [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
  - [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
  - [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)
  - [What is the best way to integrate a plugin for the code coverage?](https://www.g2.com/discussions/what-is-the-best-way-to-integrate-a-plugin-for-the-code-coverage) - 1 upvote
  - [test coverage](https://www.g2.com/discussions/31154-test-coverage) - 1 upvote

- [View SonarQube pricing details and edition comparison](https://www.g2.com/products/sonarqube/reviews?page=2&section=pricing&secure%5Bexpires_at%5D=2026-07-28+22%3A49%3A00+-0500&secure%5Bsession_id%5D=e1f005a8-a4b5-4bdb-886f-9aec5e23e362&secure%5Btoken%5D=8e28c1368b2c24b6b63d5462fb23184320b31c381e5cf4ddc6d46e389f71fc4d&format=llm_user)
## SonarQube Integrations
  - [Android Studio](https://www.g2.com/products/android-studio/reviews)
  - [Apache Maven](https://www.g2.com/products/apache-maven/reviews)
  - [Atlassian](https://www.g2.com/products/atlassian-2025-01-31/reviews)
  - [AWS CodeBuild](https://www.g2.com/products/aws-codebuild/reviews)
  - [AWS CodePipeline](https://www.g2.com/products/aws-codepipeline/reviews)
  - [AWS CodePipeline for CI/CD Automation](https://www.g2.com/products/aws-codepipeline-for-ci-cd-automation/reviews)
  - [Azure DevOps Server](https://www.g2.com/products/azure-devops-server/reviews)
  - [Azure Pipelines](https://www.g2.com/products/azure-pipelines/reviews)
  - [Backstage](https://www.g2.com/products/backstage/reviews)
  - [Bitbucket](https://www.g2.com/products/bitbucket/reviews)
  - [CircleCI](https://www.g2.com/products/circleci/reviews)
  - [Claude](https://www.g2.com/products/claude-2025-12-11/reviews)
  - [CloudBees](https://www.g2.com/products/cloudbees/reviews)
  - [Codemagic](https://www.g2.com/products/codemagic/reviews)
  - [Copado DevOps](https://www.g2.com/products/copado-devops/reviews)
  - [Cortex](https://www.g2.com/products/cortex-automation-inc-cortex/reviews)
  - [Cursor](https://www.g2.com/products/cursor/reviews)
  - [Datadog](https://www.g2.com/products/datadog/reviews)
  - [Devin AI](https://www.g2.com/products/devin-ai/reviews)
  - [Docker](https://www.g2.com/products/docker-inc-docker/reviews)
  - [Drata](https://www.g2.com/products/drata/reviews)
  - [DX](https://www.g2.com/products/dx-platform/reviews)
  - [Dynatrace](https://www.g2.com/products/dynatrace/reviews)
  - [Eclipse](https://www.g2.com/products/tph-global-eclipse/reviews)
  - [Gemini](https://www.g2.com/products/gemini-2021-11-09/reviews)
  - [GitHub](https://www.g2.com/products/github/reviews)
  - [GitLab](https://www.g2.com/products/gitlab/reviews)
  - [Google Cloud Console](https://www.g2.com/products/google-cloud-console/reviews)
  - [Google Cloud Tekton](https://www.g2.com/products/google-cloud-tekton/reviews)
  - [Gradle Build Tool](https://www.g2.com/products/gradle-build-tool/reviews)
  - [Harness](https://www.g2.com/products/harness-wealth-harness/reviews)
  - [IntelliJ IDEA](https://www.g2.com/products/intellij-idea/reviews)
  - [Jellyfish](https://www.g2.com/products/jellyfish-2018-10-15/reviews)
  - [Jenkins](https://www.g2.com/products/jenkins/reviews)
  - [JFrog](https://www.g2.com/products/jfrog-2024-03-28/reviews)
  - [Jira](https://www.g2.com/products/jira/reviews)
  - [LinearB](https://www.g2.com/products/linearb/reviews)
  - [Microsoft Visual Studio App Center](https://www.g2.com/products/microsoft-microsoft-visual-studio-app-center/reviews)
  - [MuleSoft Anypoint Platform](https://www.g2.com/products/mulesoft-anypoint-platform/reviews)
  - [npm](https://www.g2.com/products/npm/reviews)
  - [Oobeya](https://www.g2.com/products/oobeya/reviews)
  - [Port](https://www.g2.com/products/port-port/reviews)
  - [PyCharm](https://www.g2.com/products/pycharm/reviews)
  - [Python](https://www.g2.com/products/python/reviews)
  - [ServiceNow DevOps](https://www.g2.com/products/servicenow-devops/reviews)
  - [Slack](https://www.g2.com/products/slack/reviews)
  - [Travis CI](https://www.g2.com/products/travis-ci/reviews)
  - [Visual Studio](https://www.g2.com/products/visual-studio/reviews)
  - [Visual Studio Code](https://www.g2.com/products/visual-studio-code/reviews)
  - [Zed](https://www.g2.com/products/zed-zed/reviews)

## SonarQube Features
**Administration**
- API / Integrations
- Extensibility

**Functionality**
- Repository Integration
- Analytics and Trends
- Productivity Updates

**Bug Reporting**
- User Reports & Feedback
- Tester Reports & Feedback
- Team Reports & Comments

**Functionality - Software Composition Analysis **
- Language Support
- Integration
- Transparency

**Documentation**
- Feedback
- Prioritization
- Remediation Suggestions

**Risk management - Application Security Posture Management (ASPM)**
- Vulnerability Management
- Compliance Management
- Policy Enforcement

**Functionality - Software Bill of Materials (SBOM)**
- Format Support
- Annotations
- Attestation

**AI Compliance**
- Regulatory Reporting
- Automated Compliance

**Agentic AI - Static Code Analysis**
- Adaptive Learning
- Natural Language Interaction
- Proactive Assistance

**Performance - AI AppSec Assistants**
- Remediation
- Real-time Vulnerability Detection
- Accuracy

**Analysis**
- Reporting and Analytics
- Issue Tracking
- Static Code Analysis
- Code Analysis

**Management**
- Data Context
- Testing Integration

**Bug Monitoring**
- Analytics
- Bug History
- Data Retention

**Effectiveness - Software Composition Analysis**
- Remediation Suggestions
- Continuous Monitoring
- Thorough Detection

**Security**
- False Positives
- Custom Compliance
- Agility

**Integration and efficiency - Application Security Posture Management (ASPM)**
- Integration with Development Tools

**Management - Software Bill of Materials (SBOM)**
- Monitoring
- Dashboards
- User Provisioning

**Risk Management & Monitoring**
- Real-time Monitoring

**Integration - AI AppSec Assistants**
- Stack Integration
- Workflow Integration
- Codebase Contextual Awareness

**Security**
- Data Security
- Data loss Prevention
- Security Auditing

**Testing**
- Command-Line Tools
- Manual Testing
- Test Automation
- Compliance Testing
- Black-Box Scanning
- Detection Rate
- False Positives

**Reporting and Analytics - Application Security Posture Management (ASPM)**
- Trend Analysis
- Risk Scoring
- Customizable Dashboards

**Agentic AI - Bug Tracking**
- Adaptive Learning
- Natural Language Interaction
- Proactive Assistance

**Identity**
- SSO
- Governance
- User Analytics

**Access Control and Security**
- Pole-based Access Control (RBAC)

**Agentic AI - Static Application Security Testing (SAST)**
- Autonomous Task Execution

**Agentic AI  - Application Security Posture Management (ASPM)**
- Autonomous Task Execution
- Multi-step Planning

**Agentic AI - AI Governance Tools**
- Autonomous Task Execution
- Multi-step Planning
- Cross-system Integration
- Adaptive Learning
- Natural Language Interaction
- Decision Making

## Top SonarQube Alternatives
  - [GitHub](https://www.g2.com/products/github/reviews) - 4.7/5.0 (2,323 reviews)
  - [GitLab](https://www.g2.com/products/gitlab/reviews) - 4.5/5.0 (884 reviews)
  - [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews) - 3.8/5.0 (25 reviews)

