--- title: SonarQube Reviews meta_title: 'SonarQube Reviews 2026: Details, Pricing, & Features | G2' meta_description: Filter 155 reviews by the users' company size, role or industry to find out how SonarQube works for a business like yours. aggregate_rating: rating_value: 4.4 review_count: 155 scale: '5' date_modified: '2026-10-08' parent_category: name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t" url: https://www.g2.com/categories/devsecops ---

SonarQube Pros and Cons: Top 5 Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users value SonarQube for its ability to quickly flag code quality and security issues, ensuring a reliable codebase. (24 mentions)
Users value the flexible issue filtering and prioritization features of SonarQube, enhancing team productivity and focus. (20 mentions)
Users appreciate how SonarQube quickly flags code quality and security issues, ensuring a clean and reliable codebase. (19 mentions)
Users appreciate the ease of use of SonarQube, finding integration and actionable feedback simple and effective. (18 mentions)
Users appreciate the easy integrations with CI/CD tools, enhancing their workflow and improving code quality effectively. (18 mentions)
Users face software bugs that lead to false positives, complicating the experience and requiring significant knowledge to manage. (12 mentions)
Users find the complex configuration of SonarQube challenging, especially for beginners needing extensive knowledge. (10 mentions)
Users encounter false positives that complicate usage, despite helpful tools for review and customization of analysis. (10 mentions)
Users find SonarQube's complexity in configuration and excessive warnings can make it cumbersome to use. (8 mentions)
Users find the complex setup of SonarQube time-consuming, requiring significant effort to configure and tune effectively. (8 mentions)

5 Pros or Advantages of SonarQube

5 Cons or Disadvantages of SonarQube

Murtadha Bazli T.
MT
Murtadha Bazli T.
Senior Embedded System Engineer
Small-Business (50 or fewer emp.)
"Easy to use, modular and helpful in improving software quality."
5/5
What do you like best about SonarQube?

I use SonarQube mainly for analyzing C, C++ and Python programming languages, and that's why I need a SonarQube developer license. The $160 I spent for a year is really worth it. Think of SonarQube as your peer review, friend and supervisor for your software development.

Analyzing C/C++ is really easy and not tied to an IDE. I simply host SonarQube in Docker, build my software with build-wrapper and analyze it with Sonar-scanner. The analysis results then appear in the SonarQube dashboard.

I use SonarQube both at work and at home for my personal project. Due to the affordable price and ease of use, I have been loyal to SonarQube for 3 years now.

Sonar also has responsive customer support, and I mainly contact them to get a new license due to an issue with my Docker image. The response consistently within 1-2 days, and I always communicate via email. No website to report or form to fill out, which for me is convenience. Review collected by and hosted on G2.com.

What do you dislike about SonarQube?

I develop embedded software that adheres to MISRA C/C++, and SonarQube does have some MISRA rules, but not all of them are implemented. I really love to see SonarQube being able to adopt all these rules.

A few times I have found alternatives to SonarQube for this reason, but since other tools are expensive, tied to an IDE and the learning curve is unknown (unlike SonarQube, we only need 3 steps to analyze the code), I keep coming back to SonarQube. Review collected by and hosted on G2.com.

Alan R.
AR
Alan R.
R&D Manager
Mid-Market (51-1000 emp.)
"Sonarqube is a great tool to help devs raise the quality of legacy code and new greenfield code"
5/5
What do you like best about SonarQube?

Identification of coding issues across whole codebases, while providing a manageable way to gradually improve the code quality over time by enforcing that new code is of good quality. Developers can be gently guided to better practices without having to solve thousands of code smells all at once. We can refactor code as we work in different areas without introducing new risk of regressions. Easy to setup and manage and pretty hands off. It integrates well with Azure DevOps and our pull request and CI workflows. Review collected by and hosted on G2.com.

What do you dislike about SonarQube?

Some churn recently in how Sonarqube manages quality gates and what the bar is. We have a number of limitations in our analysis, particularly in collecting code coverage information. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Verified User in Computer Software
Mid-Market (51-1000 emp.)
"Effective static analysis for bugs and vulnerabilities"
4.5/5
What do you like best about SonarQube?

Being able to filter issues and assign them to different team members allows each developer to focus on high-priority issues. SonarQube allows you to enable to disable specific rules, and to set the severity of each rule. This further helps to prioritize the issues needing attention.

When a developer determines that a particular issue should NOT result in a code change, they can mark that issue as "won't fix" and enter an explanation. This helps provide detailed reports.

SonarQube also provides clear, high-level overviews of the status of your software projects (for managers), along with reports (for customers). This helps take much of the communication burden off of the development team. Review collected by and hosted on G2.com.

What do you dislike about SonarQube?

Like any static analysis tool, there are occasional false-positives. And depending on your code, there may be issues flagged as "problems" which are really just stylistic differences or deviations from best practices.

But it is fairly easy to mitigate these issues. False-positives need to be reviewed, but the detailed analysis provided by SonarQube (including traces through earlier statements showing how the issue was identified) help with the review. As for issues that are merely stylistic differences, these can be given a lower severity rating or even eliminated by customizing the underlying rules. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
AH
Verified User in Hospital & Health Care
Mid-Market (51-1000 emp.)
"Best performance/cost SAST tooling"
4.5/5
What do you like best about SonarQube?

- We are using a self hosted SonarQube server - hosting and upgrading our instance is a relatively painless process. The online documentation is clear and easy to follow

- The SonarQube scanner integrated easily into our existing Bitbucket and Cloud Build CI/CDs

- When comparing the findings with other SAST tooling, out-of-the-box SonarQube analysis had a low false positive rate, yet found extensive legitimate security/code quality issues

- Very happy with the speed of analysis, completes in only a few minutes on large repos (an order of magnitude faster than certain other SAST services)

- Surprised that language support is actually slightly better than documented - we were able to sucessfully analyze projects with older versions of .NET framework (4.5 and 4.0) than indicated in the documenation

- The triage and review process is easy for individual teams to execute on a regular basis

- The WEB API is well documented and enabled automating steps around user maintenance

- Bitbucket OAuth worked seamlesses to onboard users

- Installing additional plugins is also easy - we use Dependency-Check to add SCA to projects

- Bug fixes and features added to each new release are well documented, I appreciate being able to review all changes on the sonarsource atlassian page (and not just rely on the high-level marketing notes) Review collected by and hosted on G2.com.

What do you dislike about SonarQube?

- While SonarQube is a SAST tool, better support for SCA would be beneficial. The Dependency-Check plugn does not integrate well into the existing triage/remediation process.

- Other tooling does a better job of proving a high level overview of users and their productivity, ie. # of assigned open issues by engineer, # of fixed issues by engineer, etc. Review collected by and hosted on G2.com.

Mukesh K. R.
MR
Mukesh K. R.
Cyber Security Analyst and Senior Developer
Information Technology and Services
Small-Business (50 or fewer emp.)
"Essential for clean code"
4.5/5
What do you like best about SonarQube?

Simple deployment. Very easy installing is practiced particularly on Kubernetes using YAML formats. Moreover, integration with GitHub by means of GitHub actions is fluent because it enables developers to conduct their scans, therefore, receiving their notifications once they complete them. On the other side when it comes to flexibility, SonarQube is unmatched. It offers so much when you want to configure it letting you even prevent vulnerability detection until pull request merges are halted for example while at the same time providing a good way of looking at detected exploitation points - such as their exact location that has been pointed out about them. Review collected by and hosted on G2.com.

What do you dislike about SonarQube?

This tool is exclusively for Static Application Security Testing, other tools provide integrating Dynamic (DAST) and Static (SAST). Review collected by and hosted on G2.com.

Ethan B.
EB
Ethan B.
Small-Business (50 or fewer emp.)
"Sonarqube is a great tool for monitoring codebases."
4/5
What do you like best about SonarQube?

Quick, easy way to see major issues with code, duplications, security issues, etc. Easy to setup and maintain. Support has been very quick and helpful when I have needed them. Review collected by and hosted on G2.com.

What do you dislike about SonarQube?

While it supports a decent amount of programming languages, it definitely doesn't support all of them. Specifically Dart projects in Flutter which we use for mobile app development (though apparently there are plans to add it in the future). Review collected by and hosted on G2.com.

Kelli K.
KK
Kelli K.
Senior Software Engineer
Enterprise (> 1000 emp.)
"SonarQube has Improved our Tech Debt!"
5/5
What do you like best about SonarQube?

We have implemented it across our org, and it has been awesome. Code coverage everywhere has gone up, more bugs are being fixed, and there is more visibility into team's tech debt. Review collected by and hosted on G2.com.

What do you dislike about SonarQube?

The one downside to the new versions is lack of support for older node versions. Our monolith is still using some old versions (which of course we need to work on upgrading!), keeping us from upgrading sonarqube. Review collected by and hosted on G2.com.

JD
josue d.
Small-Business (50 or fewer emp.)
"Good but I would like to have training courses"
4.5/5
What do you like best about SonarQube?

I like how complete the tool is, I like that I can have many users with different permissions Review collected by and hosted on G2.com.

What do you dislike about SonarQube?

I don't like the complexity of integrations

I don't like that there is no error documentation

I don't like that there are no training courses.

I would like a certification Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Enterprise (> 1000 emp.)
"Must for high quality development"
4.5/5
What do you like best about SonarQube?

SonarQube helps to evaluate your code during the development itself. It provides a great amount of reviews/suggestions to improve your code. It also supports a variety of programming languages. The tool is easy to use. Review collected by and hosted on G2.com.

What do you dislike about SonarQube?

Nothing as such, but some of the static analysis could be improved for certain languages like C++. Review collected by and hosted on G2.com.

Verified User in Medical Devices
AM
Verified User in Medical Devices
Mid-Market (51-1000 emp.)
"Good tool, mixed experience with SonarSource"
1.5/5
What do you like best about SonarQube?

Good integration with CI tools. Supports many programming languages. Modern web UI. Review collected by and hosted on G2.com.

What do you dislike about SonarQube?

My experience as a SonarSource customer shows that they manifest little interest in small customers. In addition, their quality policy is poor when it comes to fixing major bugs in their code. For instance, this ticket has now been open for 1 year without any time frame for fix:

https://sonarsource.atlassian.net/browse/CPP-4175

This is unsatifying and quite ironical actually, for a company writing software for code quality. Review collected by and hosted on G2.com.