We use the solution for dynamic application testing.
Cyber Security Engineer at Defa3 cyber security
A stable solution that helps with dynamic application testing
Pros and Cons
- "We use the solution for dynamic application testing."
- "I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side."
What is our primary use case?
What needs improvement?
I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side.
For how long have I used the solution?
I have been working with the product for seven months.
What do I think about the stability of the solution?
I would rate the product's stability a ten out of ten.
Buyer's Guide
Checkmarx One
January 2025
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
What do I think about the scalability of the solution?
I would rate the product's scalability a ten out of ten. My company has 15 users for the produc.
How are customer service and support?
The solution's technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The tool's setup is very straightforward and I would rate it a ten out of ten. The product's deployment took one to two months to complete. We required the technical and development team which consisted of four to five people to handle the deployment.
What's my experience with pricing, setup cost, and licensing?
The solution's price is high and you pay based on the number of users.
What other advice do I have?
I would rate the product a ten out of ten. The solution is the best tool for developers and organizations.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director at a tech services company with 11-50 employees
Good features, good support, fair price, and good ability to deliver what customers require
Pros and Cons
- "The features and technologies are very good. The flexibility and the roadmap have also been very good. They're at the forefront of delivering the additional capabilities that are required with cloud delivery, etc. Their ability to deliver what customers require and when they require is very important."
- "There is nothing particular that I don't like in this solution. It can have more integrations, but the integrations that we would like are in the roadmap anyway, and they just need to deliver the roadmap. What I like about the roadmap is that it is going where it needs to go. If I were to look at the roadmap, there is nothing that is jumping out there that says to me, "Yeah. I'd like something else on the roadmap." What they're looking to deliver is what I would expect and forecast them to deliver."
What is our primary use case?
We're selling their licenses and their technologies. We have on-premises and cloud deployments. Its deployment depends on the customer requirements.
It is used for a range of requirements for DevSecOps. It has been deployed to ensure that the development cycle delivers clean and secure code that is vulnerability-free. It is there as a part of the whole compliance and security process.
What is most valuable?
The features and technologies are very good. The flexibility and the roadmap have also been very good. They're at the forefront of delivering the additional capabilities that are required with cloud delivery, etc. Their ability to deliver what customers require and when they require is very important.
What needs improvement?
There is nothing particular that I don't like in this solution. It can have more integrations, but the integrations that we would like are in the roadmap anyway, and they just need to deliver the roadmap. What I like about the roadmap is that it is going where it needs to go. If I were to look at the roadmap, there is nothing that is jumping out there that says to me, "Yeah. I'd like something else on the roadmap." What they're looking to deliver is what I would expect and forecast them to deliver.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the scalability of the solution?
Our customers are completely comfortable with the scalability of the technologies. They can deploy them initially in a relatively straightforward manner and then grow them into their organization quite successfully. We primarily have large customers.
How are customer service and technical support?
Our team works with them. Their sales engineering team as well as their pre-sales capabilities are very good. They're clear. They work, and they're available, which is good. It is somewhat unusual in this business.
How was the initial setup?
It depends on different technologies, but it is reasonably quite straightforward.
What's my experience with pricing, setup cost, and licensing?
Its price is fair. It is in or around the right spot. Ultimately, if the price is wrong, customers won't commit, but they do tend to commit. It is neither too cheap nor too expensive.
What other advice do I have?
They're a very good company to work with, and that's a very important aspect of any technology these days. You could find very nice technologies, but if the company is not good to work with, it could be of no use. You'll not be able to get it deployed, and you'll not get assistance. You will get bad value for good technology. Checkmarx is a nice, pleasant, and relatively easy company to work with. You will get a good return, and you will get a good partnership and relationship working with them.
I would rate Checkmarx an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Checkmarx One
January 2025
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Cyber Security Consultant at a computer software company with 5,001-10,000 employees
Stable with an easy setup and good visibility
Pros and Cons
- "The setup is fairly easy. We didn't struggle with the process at all."
- "They could work to improve the user interface. Right now, it really is lacking."
What is our primary use case?
We primarily use the solution for static analysis.
What is most valuable?
The visibility the solution gives you is great. It really gives you the ability to see what the root issues in the code actually are.
The setup is fairly easy. We didn't struggle with the process at all.
What needs improvement?
The solution isn't exactly user-friendly. They could make the user experience a bit better in future builds.
They could work to improve the user interface. Right now, it really is lacking.
For how long have I used the solution?
We've been using this solution for six months. It's been less than a year and not very long just yet.
What do I think about the stability of the solution?
The solution is very stable. There aren't bugs or glitches. The solution doesn't freeze and it's not likely to crash. We find it very reliable.
What do I think about the scalability of the solution?
It's my understanding that the solution is scalable. A company that needs to expand can do so.
We have about 100 people that use it in the company.
How are customer service and technical support?
The technical support is fine. We've always had good experiences. We're satisfied with the level of service we are provided.
Which solution did I use previously and why did I switch?
We didn't previously use a different solution. We've only ever used this product.
How was the initial setup?
The initial setup is easy and straightforward. It's not complex.
We don't have to handle any maintenance. It's my understanding that Checkmarx handles it.
What's my experience with pricing, setup cost, and licensing?
The pricing is rather reasonable. It's not the most expensive on the market.
What other advice do I have?
We're a customer. We use the solution in our organization.
I'm not sure of which version of the solution we're using.
Overall, I'd rate the solution eight out of ten. We've had a pretty positive experience overall.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Vice President at Arisglobal Software Pvt Ltd
Very good technical support, good vulnerability protection upgrades, and rich in features
Pros and Cons
- "The solution is always updating to continuously add items that create a level of safety from vulnerabilities. It's one of the key features they provide that's an excellent selling point. They're always ahead of the game when it comes to finding any vulnerabilities within the database."
- "In terms of dashboarding, the solution could provide a little more flexibility in terms of creating more dashboards. It has some of its own dashboards that come out of the box. However, if I have to implement my own dashboards that are aligned to my organization's requirements, that dashboarding feature has limited capability right now."
What is our primary use case?
We are using it for static security scanning and static security testing. We also use it for code dependency analysis. We use two of the solution's tools for each variable.
What is most valuable?
The support the solution offers is very good. When we were evaluating tools, they were extremely helpful. They're always available and they always respond back to any queries.
The solution is always updating to continuously add items that create a level of safety from vulnerabilities. It's one of the key features they provide that's an excellent selling point. They're always ahead of the game when it comes to finding any vulnerabilities within the database. I am able to be assured that when I am scanning my product those vulnerabilities are identified at very initial stages. It gives my development team more time to react.
What needs improvement?
The particular way the tool works for the scanning at the IDE level, is very expensive. It makes it very expensive to deploy this tool on to multiple different developers' machines. Right now, the way it scans, the request is raised to the IDE of the developer but then the actual scanning gets done in the centralized scan server. This increases the load on the scanning server and that will make it difficult to use Checkmarx at the developer end. That forces me to look for another solution for implementing at the developer IDE level. I would strongly recommend Checkmarx relook into their approach.
From a technical point of view, it's better to integrate with other systems within my ecosystem. For example, when I'm connecting Checkmarx with my DevSecOps pipeline and then wiring Checkmarx with other security systems as well as the pipeline (and my defect management system), it provides the connectivity to some of the tools, but there are tools which are excluded. It would be nice if they were added to the solution itself, otherwise, it requires us to do custom development.
In terms of dashboarding, the solution could provide a little more flexibility in terms of creating more dashboards. It has some of its own dashboards that come out of the box. However, if I have to implement my own dashboards that are aligned to my organization's requirements, that dashboarding feature has limited capability right now. I would recommend much more flexibility in terms of dashboarding to help us customize more effectively.
Their licensing model is rigid and difficult to navigate.
For how long have I used the solution?
I haven't been dealing with the solution for that long. We've only used it for one quarter - about three months.
What do I think about the scalability of the solution?
Their licensing fees are rigid and this causes two main issues. One is a restriction in terms of scaling the product at an enterprise level. The number of licenses required for a sizable business is just too large. The solution forces a user to apply for the licenses not directly to the software and the software products are defined in a curious way. For that reason, I wouldn't say it's great at scaling.
How are customer service and support?
So far, technical support at the initial level has been decent. We paid for their protection services, and, the protection tool is definitely very expensive. However, with the price tag comes more support and service.
We'll have to see in the coming quarters once the protection services end if the support will continue to be at such a high level of attention.
Which solution did I use previously and why did I switch?
We were using AppScan. Checkmarx is much better than that particular tool. It has more functionality and offers much more support to its users.
How was the initial setup?
It took about two to three days to deploy a basic portion of the solution. However, it takes more time in terms of configuring and fine-tuning the product so that it's useable. I would say it took us about two to three weeks of configuring before we could start our initial scans.
What about the implementation team?
We bought that separate service from Checkmarx to help us out in terms of deploying and configuring the products.
What's my experience with pricing, setup cost, and licensing?
This solution is definitely one of the more expensive tools. However, if I'm able to get value out of using it, I don't mind paying.
They have protection services costs that are separate from the main license.
There are multiple components that are part of the product suite and there are different license costs for each of those components. Sometimes it can be a little difficult to understand. There are a lot of components an individual will need to buy to cover an organization's needs. It really should be more transparent and flexible. Their licensing model as of today is quite rigid.
What other advice do I have?
We're just a customer. We don't have a special relationship with the company.
I would definitely recommend Checkmarx, I find them much more feature-rich than other tools I've used in the past.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Security Engineer at a pharma/biotech company with 501-1,000 employees
Detailed reporting assists in repairing problems, but there are a lot of false positives
Pros and Cons
- "The reports are very good because they include details on the code level, and make suggestions about how to fix the problems."
- "You can't use it in the continuous delivery pipeline because the scanning takes too much time."
What is our primary use case?
When I had an issue that was causing trouble in my code, I would upload it to Checkmarx to perform static code analysis. I would then study the reports.
How has it helped my organization?
Using this product improved the stability of my code that went into production.
What is most valuable?
The most valuable feature is the scanning.
The reports are very good because they include details on the code level, and make suggestions about how to fix the problems.
What needs improvement?
You can't use it in the continuous delivery pipeline because the scanning takes too much time. Better integration with the CD pipeline would be helpful.
It reports a lot of false positives so you have to discriminate and take ones that are rated at either a one or a two. The lower-rated problems need to be discarded.
For how long have I used the solution?
I used Checkmarx for about six months at my previous place of employment. I stopped using it about six months ago.
What do I think about the scalability of the solution?
We had perhaps 100 users at my previous job.
How are customer service and technical support?
I was not in contact with technical support.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
SAP FIORI / HCP Consultant at Silveo
Helps us check vulnerabilities in our applications. I would like to integrate it as a service along with the cloud platform.
Pros and Cons
- "Helps us check vulnerabilities in our SAP Fiori application."
- "I really would like to integrate it as a service along with the SAP HANA Cloud Platform. It will then be easy to use it directly as a service."
How has it helped my organization?
This product helps us to deliver good quality software.
What is most valuable?
- Performs security checks for SAP Fiori applications
- Helps us check vulnerabilities in our SAP Fiori application
- Easy to use and master
- One of the most important tools in our building process
What needs improvement?
I really would like to integrate it as a service along with the SAP HANA Cloud Platform. It will then be easy to use it directly as a service.
This improvement is needed in order to follow up the growth and of SAP cloud platform, it is a Platform as a service created by SAP, many services have been added to SAP HANA Cloud Platform, like GIT repository, Jenkins, Translation etc.
So, if it is possible to add the Checkmarx as a service in this platform, it will be easy to perform security check directly without using a dedicated server.
What do I think about the stability of the solution?
Maybe this issue is related to our configuration. When we have many applications to check, I need to wait a long time in the queue.
What do I think about the scalability of the solution?
We did encounter scalability issues. Maybe this is related to the stability issue mentioned above.
Which solution did I use previously and why did I switch?
We haven't used anything else. This is our first solution.
How was the initial setup?
I don’t know how to set up the product.
Which other solutions did I evaluate?
We did not look at any other options.
What other advice do I have?
It is a good tool. I recommend it in order to ensure software quality.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
AVP, aPaaS Engineer at a financial services firm with 10,001+ employees
Reasonably price, high performance, and simple installation
Pros and Cons
- "The solution has good performance, it is able to compute in 10 to 15 minutes."
- "Checkmarx could improve the REST APIs by including automation."
What is our primary use case?
We are using Checkmarx for application code scanning, such as scanning for different leverages in the application code.
What is most valuable?
The solution has good performance, it is able to compute in 10 to 15 minutes.
What needs improvement?
Checkmarx could improve the REST APIs by including automation.
For how long have I used the solution?
I have been using Checkmarx for approximately one year.
What do I think about the stability of the solution?
Checkmarx is stable.
What do I think about the scalability of the solution?
The scalability of Checkmarx is good, we can onboard easily.
We have approximately 200 people in my organization using this solution.
How are customer service and support?
I have not contacted technical support. We have not required it.
Which solution did I use previously and why did I switch?
I have used SonarQube previously.
How was the initial setup?
The installation is straightforward and takes approximately 40 minutes.
What about the implementation team?
I am able to do the implementation myself.
We have administrators and engineers that support and maintain the solution.
What's my experience with pricing, setup cost, and licensing?
We have purchased an annual license to use this solution. The price is reasonable.
What other advice do I have?
I rate Checkmarx a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director and Co-Founder at Ushiro-tec
The Best Fix Location & Payments Features Can Save Time Mitigating Network Configurations
Pros and Cons
- "The most valuable features of Checkmarx are the Best Fix Location and the Payments option because you can save a lot of time trying to mitigate the configuration. Using these tools can save you a lot of time."
- "With Checkmarx, normally you need to use one tool for quality and you need to use another tool for security. I understand that Checkmarx is not in the parity space because it's totally different, but they could include some free features or recommendations too."
What is our primary use case?
We use Checkmarx to review the source code for the external applications that we expose to the cloud or other servers on the internet.
How has it helped my organization?
We received two main benefits from Checkmarx:
- Better Security
- Saving Time
I recommend Checkmarx to be sure that your development has robust security. For your team management, Checkmarx has a very nice feature to check out manual staff in the process.
What is most valuable?
The most valuable features of Checkmarx are the Best Fix Location and the Payments option because you can save a lot of time trying to mitigate the configuration. Using these tools can save you a lot of time.
What needs improvement?
Checkmarx could probably do something to improve their license model. If you have a small company, or if you have a small team with just one or two applications, the entry-level price is too high for such a company.
You can find all the solutions offered by Checkmarx through other solutions providers. That is why this type of company needs to be more flexible.
In this space, you have a security code and also you have a quality code. It is totally different in terms of investment. In terms of functionality, there are a lot of differences between the various competing products.
With Checkmarx, normally you need to use one tool for quality and you need to use another tool for security. I understand that Checkmarx is not in the parity space because it's totally different, but they could include some free features or recommendations too.
The problem with Checkmarx lies with the pricing and licensing, not the product itself. The product is very good.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
Checkmarx is a good product, certainly stable.
What do I think about the scalability of the solution?
The scalability is good. We haven't had any problems with it.
How are customer service and technical support?
Our experience with technical support is good. They have a lot of expert staff on their customer service lines. We have had no problems with their technical support services.
Which solution did I use previously and why did I switch?
We used Veracode for some time and it's also a good solution. Veracode fits better for small companies. It's more automatic.
Checkmarx is more complete and they have more features to support our development team and security team requirements.
In general, Checkmarx is a better solution, but it's more complicated, especially in terms of the price for a small company.
How was the initial setup?
Our deployment of Checkmarx took a couple of days, at max, a week.
What about the implementation team?
The setup was a long time back, but I know that we did not use a reseller or consultant for the deployment.
Which other solutions did I evaluate?
We evaluated some products from a company in Spain. Checkmarx provided better functionality and options for us.
What other advice do I have?
We have a small team. It is about four people in total. We do not require that many staff for the deployment and maintenance of Checkmarx.
We are testing the solution in a small local company. Our idea is to expand the use of it to our clients in the West.
In this space, you can have different points of view and if only you are looking for a solution to do a check in your auditory report, then you can choose anyone.
If you really are worried about your business, i.e. about your development sites or development environments, Checkmarx is a great solution.
I would rate Checkmarx a nine out of ten because of the price, but technically for me, it is a 10.
I would rate Checkmarx with a nine because it would be perfect at a more functional level, and could be better at providing these features for parity.
If you research what Checkmarx is offering in their package distribution, you get exactly what they promise up front, so they are not lying.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Vulnerability Management Static Code Analysis API Security DevSecOps Risk-Based Vulnerability ManagementPopular Comparisons
SonarQube Server (formerly SonarQube)
GitLab
Veracode
Mend.io
Fortify on Demand
Sonatype Lifecycle
CrowdStrike Falcon Cloud Security
Acunetix
GitHub Advanced Security
PortSwigger Burp Suite Professional
HCL AppScan
Qualys Web Application Scanning
GitHub
Klocwork
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Checkmarx or Veracode. Which should we choose?
- What is the Biggest Difference Between Checkmarx and Fortify?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which application security solutions include both vulnerability scans and quality checks?