
Checkmarx is a centralized security tool that provides end-to-end insights into source code security and vulnerabilities. It also helps improve the efficiency of the source code by highlighting the associated risks and suggesting ways to remediate the vulnerabilities. In addition, it shows vulnerabilities in the open-source libraries and packages we use in our source code through SCA scans.
One thing I like the most is how well it integrates with our CI/CD tooling. We can plug it into our DevSecOps CI/CD flow, and developers can see scan insights directly from the pipeline itself, without needing to log in to the Checkmarx UI separately. Review collected by and hosted on G2.com.
It should better cope with modern software development lifecycles and provide end-to-end support for scanning any valid file extensions. For example, we are migrating from Node JS to TypeScript, and as part of that change we updated our .js files to use the .mjs extension. However, Checkmarx still does not support scanning .mjs files. We reported this issue to them about a year ago, but even now it remains unsupported. The current suggestion is to rename .mjs files to .js when uploading code for Checkmarx scans, which is not a practical workaround for us. Review collected by and hosted on G2.com.
Aman, thank you for the feedback. We understand the challenges that can arise when development teams adopt new languages, frameworks, and file types.
Checkmarx has recently expanded its language-agnostic scanning capabilities through a new hybrid scanning engine that combines deterministic analysis with AI-powered detection, enabling broader coverage across modern and emerging technologies, including AI-generated code and polyglot environments. This approach is designed to reduce gaps created by evolving development practices while maintaining high-fidelity results.
We appreciate you highlighting the .mjs support issue, and feedback like this helps us continue improving coverage and compatibility for modern software development workflows. Please reach out to us if you would like to discuss more, and again thank you for the feedback!
See how Checkmarx improved