Try our new research platform with insights from 80,000+ expert users
it_user598917 - PeerSpot reviewer
Senior Manager at a financial services firm
Vendor
We felt like we were the extended quality organization as they frequently released poor quality patches that broke the existing functionality.
Pros and Cons
  • "Scan reviews can occur during the development lifecycle."
  • "C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported."

How has it helped my organization?

It moved our organization towards being agile vs. waterfall.

What is most valuable?

Scan reviews can occur during the development lifecycle.

What needs improvement?

The areas in which this product needs to improve are:

  • C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported.
  • There were issues in regards to the JSP parsing.
  • Defect report generation takes multiple hours for large projects.
  • The Jenkins plugin does not work for projects that are larger than 4 million lines of code.
  • The Eclipse plugin does not work.
  • The hardware requirements for the tool add to the substantial cost of the solution and thus, increase the total cost of ownership.
  • There seems to be a decline in the support team's responsiveness as our contract nears its end.

  • We felt like we were the extended quality organization for Checkmarx as they frequently released poor quality patches that broke the existing functionality. A lot of the organizational hours, almost 1 FTE per year since Checkmarx was implemented, were spent to allow regression testing of the product. The Checkmarx SME team at my company had to do this testing to ensure that we do not expose product flaws to our user community.

What do I think about the stability of the solution?

We did encounter stability issues. The different versions of this product provide inconsistent results when the same piece of code is scanned.

Buyer's Guide
Checkmarx One
February 2025
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.

What do I think about the scalability of the solution?

We did not encounter any scalability issues.

How are customer service and support?

The support team is knowledgeable. However, we still have tickets open from 2014. There is a lot of follow up required to get closure on issues.

Which solution did I use previously and why did I switch?

Previously, we were using a different solution. We were leveraging multiple tools since we have code in multiple languages. Checkmarx advertised that they provide support for C, C+++, Java, etc. It turned out that they aren’t able to scan C and C++ for us. Our reason to switch to Checkmarx didn’t work out for us.

How was the initial setup?

The initial setup was straightforward.

What's my experience with pricing, setup cost, and licensing?

The license has a vague language around P1 issues and the associated support. Make sure to review these in order to align them with your organizational policies.

I suggest using a trial term to run a gamut of scenarios that need to be leveraged before settling in with the Checkmarx solution.

Which other solutions did I evaluate?

We evaluated the Veracode option.

What other advice do I have?

The product is not mature and ready for the enterprise usage yet. It is okay to use it when the support expectations are low and the code is in languages that require support only in Java and .NET.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1398084 - PeerSpot reviewer
Procurement Analyst at a pharma/biotech company with 10,001+ employees
Real User
Flexible features, stable, but more supported languages needed
Pros and Cons
  • "One of the most valuable features is it is flexible."
  • "The integration could improve by including, for example, DevSecOps."

What is our primary use case?

We use the solution for scanning the code for security.

What is most valuable?

One of the most valuable features is it is flexible. 

What needs improvement?

The integration could improve by including, for example, DevSecOps.

In an upcoming release, they could improve by adding support for more languages.

For how long have I used the solution?

I have been using the solution for two years.

What do I think about the stability of the solution?

I have found the solution to be stable.

What do I think about the scalability of the solution?

The scalability of the solution is good. We have approximately 4000 using the solution in my organization and they are mostly engineers.

How are customer service and technical support?

The technical support we have experience was good but they could be faster.

What other advice do I have?

I would recommend this solution to others.

I rate Checkmarx a six out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Checkmarx One
February 2025
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.
Cyber Security Analyst at a tech vendor with 1,001-5,000 employees
Vendor
The static operation security has been able to identify more security issues since implementing this solution
Pros and Cons
  • "Our static operation security has been able to identify more security issues since implementing this solution."
  • "It would be really helpful if the level of confidence was included, with respect to identified issues."

What is our primary use case?

Our primary use case for this solution is SAST, Static Application Security Testing.

How has it helped my organization?

Our static operation security has been able to identify more security issues since implementing this solution.

What is most valuable?

There are many good features like site integration, but the most valuable feature for us is the XL scan of source code. 

What needs improvement?

It would be really helpful if the level of confidence was included, with respect to identified issues. Some competitors have this feature, and it helps a lot to concentrate on the real findings.

For how long have I used the solution?

One year.

What do I think about the stability of the solution?

In general, stability is good, although sometimes it crashes. We use this product daily, and I would rate the stability a four out of five.

What do I think about the scalability of the solution?

The scalability is very good.

How are customer service and technical support?

Technical support for this solution is very effective. Each time we have had questions, the answers they provided have been very clear and comprehensive.

Which solution did I use previously and why did I switch?

Prior to this solution, we were using IBM Security AppScan. We had many, many issues with the application, along with complaints about the deployment time. The main reason we switched is that it was not updated, and it did not support certain technologies. For example, it did not support Visual Studio 2017, so we had to switch to a new solution.

How was the initial setup?

The initial setup for this solution is straightforward.

It took less that one day to deploy.

What about the implementation team?

We handled the implementation in-house.

What was our ROI?

We have not yet seen ROI.

Which other solutions did I evaluate?

We did evaluate other options.

What other advice do I have?

If people are in need of static application security, then I would recommend this product.

I would rate this solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user607392 - PeerSpot reviewer
Security test engineer at a tech vendor with 10,001+ employees
Real User
Communicates where to fix the issue for less iterations. Resolutions should be provided for installation issues due to internal security policies.
Pros and Cons
  • "The solution communicates where to fix the issue for the purpose of less iterations."
  • "The resolutions should also be provided. For example, if the user faces any problem regarding an installation due to the internal security policies of their company, there should be a resolution offered."

How has it helped my organization?

Now we have information about which specific sections have to be fixed. We can now remove the issue from most of the sections.

What is most valuable?

The solution communicates where to fix the issue for the purpose of less iterations.

What needs improvement?

The resolutions should also be provided. For example, if the user faces any problem regarding an installation due to the internal security policies of their company, there should be a resolution offered.

What do I think about the stability of the solution?

There were no stability issues.

What do I think about the scalability of the solution?

There were no scalability issues.

How are customer service and technical support?

I would give technical support a rating of 8/10.

Which solution did I use previously and why did I switch?

We switched solutions due to the client's requirements.

What's my experience with pricing, setup cost, and licensing?

I faced a few issues in the installation due to my local policies. The customer support was very helpful.

Which other solutions did I evaluate?

We looked at other tools, such as HPE Security and ZAP solutions.

What other advice do I have?

Go for it, if you want testing on the code level.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1415661 - PeerSpot reviewer
General Manager at a consultancy with 51-200 employees
Real User
Intuitive interface, easy to set up, and saves us money by finding problems at an early stage
Pros and Cons
  • "The UI is very intuitive and simple to use."
  • "Creating and editing custom rules in Checkmarx is difficult because the license for the editor comes at an additional cost, and there is a steep learning curve."

What is our primary use case?

We use Checkmarx for static analysis as part of our software development lifecycle. It is very important because it helps us identify the security flaws in the code at a very early stage. Ultimately, this helps in reducing costs.

What is most valuable?

The UI is very intuitive and simple to use. You don't need to know anything about the product before you being working with it.

The interface used to audit issues is also simple to use.

Compared to similar products, the code scanning time is fast.

What needs improvement?

Most the the static analysers come with pre-loaded rulesets. However, many times developers have to write their own custom rules. Writing custom rules in Checkmark is difficult because you need a different editor which is licensed separately. Besides not much training material is available on how to write the rules. 

For how long have I used the solution?

We have been using Checkmarx for almost four years.

What do I think about the stability of the solution?

It is pretty stable and we have not had any issues. We have a monitoring team that monitors the health of our infrastructure and we are alerted to any problems.

What do I think about the scalability of the solution?

We were able to scale easily and did not have any issues in doing so. At this team, we have between 70 and 80 applications that we are scanning with it.

How are customer service and technical support?

We have contacted technical support a couple of times and the issues were addressed in a timely manner.

Which solution did I use previously and why did I switch?

We have used other products and found that you have to spend considerable time fine-tuning the scanning engine. With Checkmarx, it is a lot less and I would say that this is one of the significant differences with this solution.

The maintenance in terms of running the scans and fine-tuning the scans is very low.

On the other hand, we have used other tools where writing custom rules is not so difficult to do.

How was the initial setup?

Checkmarx is pretty straightforward and very easy to set up.

What about the implementation team?

Our in-house team deployed and manages this product. I have one person who handles all of it, and the deployment can be completed within a day or two. As long as the infrastructure is ready, it can be done within a day.

What was our ROI?

Checkmarx helps us to find problems with source code at an early stage in the development, which saves us in terms of troubleshooting costs.

What's my experience with pricing, setup cost, and licensing?

The interface used to create custom rules comes at an additional cost.

What other advice do I have?

Checkmarx is probably one of the best static code analyzers available in the market at this point. It is very easy to deploy, use, and maintain. The amount of maintenance required is pretty low. It is absolutely a good tool that I can recommend.

Checkmarx has added a lot of functionality since we began using it. This includes OSA, the open-source scan, a training module, and run-time protection.

For static code analysis, we are only using Checkmarx and we plan to continue. 

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Business Analyst at a tech services company with 201-500 employees
Real User
It made our organization more efficient with our whole code scan/deployment process for our software applications.
Pros and Cons
  • "It is a stable product."
  • "Most valuable features include: ease of use, dashboard. interface and the ability to report."
  • "It is an expensive solution."

What is our primary use case?

Our primary use case solution is for code scanning.

How has it helped my organization?

It has made our organization more efficient with our whole code scan/deployment process for our software applications.

What is most valuable?

The most valuable features are:

  • Ease of use
  • Dashboard
  • Interface
  • Report

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

I have not had an issue with stability of the product.

What do I think about the scalability of the solution?

There have been no issues with scalability that I am aware of.

How are customer service and technical support?

I have not needed the use of technical support.

Which solution did I use previously and why did I switch?

Previously, we considered: Veracode, SonarQube, Fortify and IBM Security AppScan.

How was the initial setup?

I was not involved in the initial setup of the solution.

What was our ROI?

One should consider:

  • Visual studio
  • Report generation
  • If the solution can be on-prem
  • Pricing

What's my experience with pricing, setup cost, and licensing?

It is an expensive solution.

What other advice do I have?

Be cautious of the one-year subscription date. Once it expires, your price will go up.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Technical Architect at Photon Interactive
MSP
It gives the proper code flow of vulnerabilities and the number of occurrences
Pros and Cons
  • "It shows in-depth code of where actual vulnerabilities are."
  • "It gives the proper code flow of vulnerabilities and the number of occurrences."
  • "It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."

What is our primary use case?

I have used it for source code scanning of security vulnerabilities. It seems to be a good tool. It gives the proper code flow of vulnerabilities and the number of occurrences.

How has it helped my organization?

We have scanned various applications with it. It works fine, although we need to check manually for false positive issues. 

What is most valuable?

After scanning, it shows in-depth code of where actual vulnerabilities are, which helps us to analyze them.

What needs improvement?

It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use.

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1672218 - PeerSpot reviewer
Director and Co-Founder at a tech services company with 1-10 employees
Real User
Fits our requirements, scales easily, and is easy to use
Pros and Cons
  • "It is very useful because it fits our requirements. It is also easy to use. It is not complex, and we are satisfied with the results."
  • "Its pricing model can be improved. Sometimes, it is a little complex to understand its pricing model."

What is most valuable?

It is very useful because it fits our requirements. It is also easy to use. It is not complex, and we are satisfied with the results.

What needs improvement?

Its pricing model can be improved. Sometimes, it is a little complex to understand its pricing model.

For how long have I used the solution?

I have been using this solution for a couple of years.

What do I think about the stability of the solution?

It is pretty stable.

What do I think about the scalability of the solution?

It has the capability to scale very easily. It is not a problem.

How are customer service and technical support?

Their support is good. It has a good webpage with a lot of details.

How was the initial setup?

It is very easy to set up. It takes a couple of days. It is not an issue.

What's my experience with pricing, setup cost, and licensing?

It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing. 

What other advice do I have?

I would absolutely recommend this solution. I would rate Checkmarx a nine out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros sharing their opinions.