Checkmarx Software Composition Analysis is used for detecting vulnerabilities in the open source software component of a project.
What's most valuable in Checkmarx Software Composition Analysis is that it provides security from the start. In the traditional approach, an enterprise or company validates the solution before launching to a production environment, but in the modern approach, security must be checked and provided from the beginning and from the design, and this is where Checkmarx Software Composition Analysis comes in. The solution helps you make sure that every open-source application that you use is secure, and that there's no vulnerability inside that open-source application.
In terms of areas for improvement, what could be improved in Checkmarx Software Composition Analysis is pricing because customers always compare the pricing among secure DevOps solutions in the market. Checkmarx Software Composition Analysis has a lot of competitors yet its features aren't much different. Pricing is the first thing customers consider, and from a partner perspective, if you can offer affordable pricing to your customers, it's more likely you'll have a winning deal.
The performance of Checkmarx Software Composition Analysis also needs improvement because sometimes, it's slow, and in particular, scanning could take several hours.
I've been working with Checkmarx Software Composition Analysis since August, last year.
In terms of the stability of Checkmarx Software Composition Analysis, I've experienced a performance bottleneck, for example, it's been slow. My company has two clouds in Europe and the United States, and when I use the cloud that's based in Europe, sometimes its performance isn't good. When I perform a scan, it takes a long time. It particularly takes several hours for the scan to be completed.
At the moment, customers can use Checkmarx Software Composition Analysis for unlimited projects, so in terms of internal capacity and scalability, those areas are good.
Checkmarx Software Composition Analysis has very good technical support.
The initial setup for Checkmarx Software Composition Analysis was straightforward. On a scale of one to five, I'm rating the setup a five.
Pricing for Checkmarx Software Composition Analysis needs to be competitive.
My company is a Checkmarx Software Composition Analysis partner.
The solution is cloud-based, so it doesn't have a specific version. When Checkmarx markets a product, the product version isn't mentioned.
Checkmarx Software Composition Analysis is SaaS, so the customer just gets the account then he can log onto the platform and use it online.
My advice to anyone looking into implementing the solution is that you need to know about open-source security, particularly open-source software fundamentals. It's knowing not just open-source vulnerabilities which Checkmarx Software Composition Analysis scans, but legal information as well. The solution doesn't just detect vulnerabilities. It also detects legal risks, for example, if you're using a copyrighted open-source license or a permissive license, etc.
I'm rating Checkmarx Software Composition Analysis ten out of ten.