
I use Checkmarx for SAST code review, and it helps me identify security vulnerabilities early in the software development lifecycle, saving a lot of money by catching them in the code for each commit. I really like how it identifies security vulnerabilities, especially getting rid of common OWASP top 10 vulnerabilities like SQL injection and Cross-Site Scripting. I'm impressed that it can also detect business logic vulnerabilities, such as unauthorized access control, earlier in the development process. I also appreciate that it reports IDOR vulnerabilities from the OWASP top 10. The initial setup was easy, and I switched to Checkmarx from Fortify mainly because it provides less noise from false positives and offers deeper coverage of the OWASP top 10. Review collected by and hosted on G2.com.
Some of false positive seems painful sometimes Review collected by and hosted on G2.com.