CAST Highlight vs Checkmarx One comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

CAST Highlight
Average Rating
7.8
Number of Reviews
5
Ranking in other categories
Software Composition Analysis (SCA) (13th)
Checkmarx One
Average Rating
7.6
Number of Reviews
67
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (11th), Static Code Analysis (2nd), API Security (4th), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
 

Market share comparison

As of June 2024, in the Software Composition Analysis (SCA) category, the market share of CAST Highlight is 0.5% and it decreased by 35.9% compared to the previous year. The market share of Checkmarx One is 3.3% and it decreased by 68.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Composition Analysis (SCA)
Unique Categories:
No other categories found
Application Security Tools
13.2%
Static Application Security Testing (SAST)
10.2%
 

Featured Reviews

VG
Nov 15, 2022
Excellent support, works seamlessly with most languages, and useful for knowing about the readiness of the codebase for cloud migration
Its price should be better. It is a pretty costly tool. They have two products: CAST Highlight and CAST AIP. Both are licensed separately. As per CAST, Highlight is for RAPID prototyping and AIP is for in depth detailed analysis. But then there are areas which Highlights covers (Cloud Adoption) which AIP does not. Our experience in using AIP is that it also does not look at entire tech stack and does not provide the list of all technologies present in your application and then flag what is supported and what is not so that customer has clear view. Highlight probably does that. They need to simplify it for customers. I would expect CAST Highlight to have lighter version of the Health dashboard and the Engineering dashboards . These dashboards are currently a part of CAST AIP, and if these are made available in CAST Highlight, customers won't have to use two different products all the time.
PG
Sep 10, 2022
A good compliance solution that is best suited to small scale applications, and suffers from stability issues
Our main uses of this solution are to ensure our required compliance policies are met, and that we are applying best practice This solution helps to remediate the compliance requirements we have.  The product also increases the quality of the code the developers are able to implement.  The main…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features of the CAST Highlight are the interface and there are three notations that are very simple to understand and communicate with."
"CAST Highlight is easy to use and has a good dashboard."
"The way it tells you which codebase is more ready for the cloud and which codebase is less ready is very valuable. It works seamlessly with most languages."
"The most valuable features of CAST Highlight are automation and speed."
"It offers good performance."
"The user interface is excellent. It's very user friendly."
"The solution improved the efficiency of our code security reviews. It helps tremendously because it finds hundreds of potential problems sometimes."
"The value you can get out of the speedy production may be worth the price tag."
"The administration in Checkmarx is very good."
"The solution allows us to create custom rules for code checks."
"The SAST component was absolutely 100% stable."
"The most valuable features of Checkmarx are the Best Fix Location and the Payments option because you can save a lot of time trying to mitigate the configuration. Using these tools can save you a lot of time."
"The main thing we find valuable about Checkmarx is the ease of use. It's easy to initiate scans and triage defects."
 

Cons

"CAST Highlight could improve to allow us to comment and do a deep analysis by ourselves."
"The reports that describe the issues of concern are rather abstract and the issues should be more clearly described to the user."
"Its price should be better. It is a pretty costly tool. They have two products: CAST Highlight and CAST AIP. I would expect CAST Highlight to have the Help dashboard and the Engineering dashboard. These dashboards are currently a part of CAST AIP, and if these are made available in CAST Highlight, customers won't have to use two different products all the time."
"There's a bit of a learning curve at the outset."
"The ease of configuration and customization could be improved in CAST Highlight."
"It is an expensive solution."
"Checkmarx has a slightly difficult compilation with the CI/CD pipeline."
"Integration into the SDLC (i.e. support for last version of SonarQube) could be added."
"The reports are good, but they still need to be improved considering what the UI offers."
"I would like to see the DAST solution in the future."
"Checkmarx could improve by reducing the price."
"The tool is currently quite static in terms of finding security vulnerabilities. It would be great if it was more dynamic and we had even more tools at our disposal to keep us safe. It would help if there was more scanning or if the process was more automated."
"The cost per user is high and should be reduced."
 

Pricing and Cost Advice

"Basic support is included with the standard licensing feed but it can be upgraded for an additional cost."
"It is a pretty costly tool. A lot of customers are resistant to using it."
"CAST Highlight is an expensive solution. However, CAST Highlight is less expensive than the CAST AIP, but it remains too expensive and the professional services from CAST are also too expensive. The high price is part of the problem with the CAST solutions."
"CAST Highlight is an expensive solution."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"The number of users and coverage for languages will have an impact on the cost of the license."
"The average deal size was usually anywhere between $120K to $175K on an annual basis, which could be divided across 12 months."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"We got a special offer for a 30% reduction for three years, after our first year. I think for a real source-code scanning tool, you have to add a lot of money for Open Source Analysis, and AppSec Coach (160 Euro per user per year)."
"It is an expensive solution."
"Before implementing the product I would evaluate if it is really necessary to scan so many different languages and frameworks. If not, I think there must be a cheaper solution for scanning Java-only applications (which are 90% of our applications)."
"I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone."
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
16%
Insurance Company
10%
Manufacturing Company
9%
Financial Services Firm
21%
Computer Software Company
15%
Manufacturing Company
9%
Insurance Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about CAST Highlight?
The most valuable features of CAST Highlight are automation and speed.
What is your experience regarding pricing and costs for CAST Highlight?
CAST Highlight is an expensive solution. On a scale from one to ten, where one is cheap, and ten is expensive, I rate the solution's pricing an eight or nine out of ten.
What needs improvement with CAST Highlight?
The ease of configuration and customization could be improved in CAST Highlight.
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The solution's price is high and you pay based on the number of users.
 

Comparisons

 

Learn More

 

Overview

 

Sample Customers

Wells Fargo, Bank of NY Mellon, Northern Trust, Microsoft, Amazon, IBM, BMW, AT&T, US Army, US Air Force, US Navy, John Hancock, Marsh & McLennan, Ernst & Young, PwC, Volkswagen, Boston Consulting Group, London Stock Exchange, Telefonica, Saur France, Total Energies France, SNCF
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Find out what your peers are saying about CAST Highlight vs. Checkmarx One and other solutions. Updated: September 2022.
787,061 professionals have used our research since 2012.