Try our new research platform with insights from 80,000+ expert users

Amazon Inspector vs Checkmarx One comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Customer Service

Sentiment score
8.5
Amazon Inspector offers reliable customer service, with varying response times based on subscription tier, ensuring user satisfaction.
Sentiment score
7.4
Checkmarx One's support is generally rated positively for knowledgeability and quick responses, despite occasional delays and unresolved issues.
I have not needed to use AWS support for Inspector, which indicates that the service is almost perfect.
 

Room For Improvement

Sentiment score
5.6
Amazon Inspector needs better integration, expanded vulnerability coverage, real-time protection, automation, and improved guidance for comprehensive security.
Sentiment score
4.7
Checkmarx One needs better accuracy, language support, integration, flexibility, UI customization, documentation, dynamic testing, and API security features.
Automation for scheduling 'turn on' and 'turn off' operations and better integration with CloudWatch for alarms could enhance the service's functionality.
 

Scalability Issues

Sentiment score
7.6
Amazon Inspector offers scalable vulnerability monitoring with ECR integration, popular among security teams but sometimes limited for developers.
Sentiment score
7.3
Checkmarx One is favored for its scalability and efficiency, though licensing and resource challenges are sometimes noted.
Scalability is not an issue with Amazon Inspector as it is scalable to the maximum, covering any business scale effectively.
 

Setup Cost

No sentiment score available
Amazon Inspector offers a cost-effective, tiered pricing model with transparent, low-cost scans suitable for diverse organizational needs.
Sentiment score
6.4
Checkmarx One is costly but valued for its robust security, despite complexity in setup and licensing options.
The pricing for Amazon Inspector is very fair, and I would rate it as two out of ten, with ten being the most expensive.
 

Stability Issues

Sentiment score
9.5
Amazon Inspector is highly stable and reliable, receiving excellent user support and impacting business security positively.
Sentiment score
7.2
Checkmarx One is stable for most, but large codebase handling can cause crashes, memory issues, and configuration dependence.
Amazon Inspector is highly stable, rated ten out of ten, and this stability impacts business security and administration positively.
 

Valuable Features

Sentiment score
8.2
Amazon Inspector offers automated vulnerability detection, categorization, and Security Hub integration for enhanced AWS security assessment across resources.
Sentiment score
8.4
Checkmarx One enhances secure coding with user-friendly interface, automation, and multi-language support, making it ideal for developers.
The most valuable feature of Amazon Inspector is the categorization of findings, which filters vulnerabilities by instance, container image, container repository, and Lambda function.
 

Categories and Ranking

Amazon Inspector
Ranking in Vulnerability Management
24th
Average Rating
8.0
Reviews Sentiment
8.0
Number of Reviews
5
Ranking in other categories
IT Vendor Risk Management (9th)
Checkmarx One
Ranking in Vulnerability Management
16th
Average Rating
7.6
Reviews Sentiment
7.1
Number of Reviews
70
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Static Code Analysis (2nd), API Security (2nd), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
 

Featured Reviews

Nikhil Sehgal - PeerSpot reviewer
Primarily focuses on security of EC2 instances, provides point-in-time assessments rather than real time protection but provides automated vulnerability detection
It has a limited scope. So, AWS Inspector primarily focuses on the security of the EC2 instance. So, if your architecture includes other AWS services, then you may need to use additional tools for your comprehensive security assessment. So that is one con. Another is, like, we have a dependency on agents. So other is dependency on agents, like, Inspector relies on agents installed on instances for deeper assessment. So managing these agents can be additional overhead. So these kinds of things. It does not even provide real-time protection. So, Inspector provides point-in-time assessment rather than continuous monitoring. So these are all cons. When it comes to false positives, it is there for most security tools as of now. I would not consider false positives a major concern. So, these are the major concerns that I found: dependency on agents, limited scope, and no real-time protection.
Rohit Kesharwani - PeerSpot reviewer
Provides good security analysis and security identification within the source code
We integrate Checkmarx into our software development cycle using GitLab's CI/CD pipeline. Checkmark has been the most helpful for us in the development stage. The solution's incremental scanning feature has impacted our development speed. The solution's vulnerability detection is around 80% to 90% accurate. I would recommend Checkmarx to other users because it is one of the good tools for doing security analysis and security identification within the source code. Overall, I rate Checkmarx a nine out of ten.
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
816,660 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Financial Services Firm
12%
Government
7%
Manufacturing Company
7%
Financial Services Firm
22%
Computer Software Company
15%
Manufacturing Company
10%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Amazon Inspector?
The integration of Amazon Inspector with other AWS services has enhanced our security. Security Hub is a major asset because it allows us to centralize data from various AWS services. We can integ...
What is your experience regarding pricing and costs for Amazon Inspector?
The pricing is very transparent and clear, so I don't have any challenges with it. It's good.
What needs improvement with Amazon Inspector?
There is room for improvement in the scanning capabilities. I'd like to see broader coverage in terms of the vulnerabilities detected. Right now, it's not as comprehensive as some of the third-part...
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
 

Overview

 

Sample Customers

betterment, caplinked, flatiron, university of nutri dame
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Find out what your peers are saying about Amazon Inspector vs. Checkmarx One and other solutions. Updated: October 2024.
816,660 professionals have used our research since 2012.