We performed a comparison between Black Duck and Checkmarx Software Composition Analysis based on real PeerSpot user reviews.
Find out in this report how the two Software Composition Analysis (SCA) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The UI is the solution's most valuable feature since it allows for easy pipeline integration."
"The solution works well on Mac products."
"I like the fact that the product auto analyzes components."
"The knowledge base and the management system are the most valuable features of Black Duck Hub. It has a very helpful management environment. They offer an editor where we can check the discovered license, which is retrieved from their knowledge base. They have a huge knowledge base build over the years. It gives you some possibilities, such as this license with possibility A could cause a vulnerability issue or a potential breach."
"The most valuable feature is the vulnerability scanning, and that it's easy to use."
"The cloud option of the product is always available and a positive aspect of the solution."
"The solution is stable."
"The product enables other applications to be secure."
"The customer service and support were good."
"What's most valuable in Checkmarx Software Composition Analysis is its ability to identify vulnerabilities in open-source components, especially if some critical issues exist."
"The tool's visual scan analysis shows me all the libraries' vulnerabilities and license types. It helps identify the most complex issues with licenses. It provides good visibility. SCA shows me all libraries that are vulnerable and the extent of their vulnerability."
"Checkmarx unifies all the features in its service."
"It is a stable solution...It is a scalable solution."
"The product is stable and scalable."
"The integration part is easy...It's a stable solution right now."
"The most valuable feature of Checkmarx Software Composition Analysis is the comprehensive security scan."
"The initial setup could be simplified. It was somewhat complex."
"The tool's documentation and support are areas of concern where improvements are required."
"Black Duck can improve the time it takes for a scan. Most of the time it's not ideal when integrated with the live DevSecOps pipeline. We have to create a separate job to scan the library because it takes a couple of hours to scan all those libraries. The scanning could be faster."
"I would like to see more integration with other solutions, such as IntelliJ IDEA."
"It's still a bit inconsistent. For example, if I scan today, it might not show the same results tomorrow."
"It is a cloud-only solution. In many cases, companies like to evaluate the software, but they're very reluctant to give you the software. It would be great if they could offer an on-prem component that could be used to scan the code and then upload the discovery results to the cloud and get all the information from there, but there is no such possibility. You have to upload the code to the Black Duck cloud system. Of course, they have a strong legal department, and they offer some configuration, but it is never enough. You have to give the code, which is a drawback. In modern designs like Snyk or FOSSA, you don't need to give the code. It requires more native integration with Coverity because they go together technically. You need both Coverity and Black Duck Hub. It would be really helpful for companies working in this space to get a combined offer from the same company. They should provide an option to buy Coverity for an additional fee. Coverity combined with Black Duck Hub will provide a one-step analysis to get everything you need and a unified report. It would be really great to be able to connect Black Duck Hub with Coverity unified reports."
"The tool needs to improve its pricing. Its configuration is complex and can be improved."
"The product's pricing is higher compared to other competitor products."
"Parts of the implementation process could improve by making it more user-friendly."
"In terms of areas for improvement, what could be improved in Checkmarx Software Composition Analysis is pricing because customers always compare the pricing among secure DevOps solutions in the market. Checkmarx Software Composition Analysis has a lot of competitors yet its features aren't much different. Pricing is the first thing customers consider, and from a partner perspective, if you can offer affordable pricing to your customers, it's more likely you'll have a winning deal. The performance of Checkmarx Software Composition Analysis also needs improvement because sometimes, it's slow, and in particular, scanning could take several hours."
"I have received complaints from my customers that the pricing could be improved."
"Checkmarx Software Composition Analysis should improve dynamic analysis."
"It can have better licensing models."
"The quality of technical support has decreased over time, and it is not as good as it used to be."
"Personally, I currently use it as a standalone tool without integrating it with other systems, and it meets my needs adequately. As a suggestion, I request on considering to add a "what if" feature to the application. Currently, when the tool identifies issues and suggests updates, if I want to explore different scenarios, I need to prepare another file, turn it into a ZIP, and run the analysis again. It would be more convenient if there was a "what if" option in the GUI. This feature could simulate a run, allowing me to quickly check the impact of changing one or more files or versions without the need for a full rerun."
"I would rate the scalability a seven out of ten."
More Checkmarx Software Composition Analysis Pricing and Cost Advice →
Black Duck is ranked 1st in Software Composition Analysis (SCA) with 19 reviews while Checkmarx Software Composition Analysis is ranked 8th in Software Composition Analysis (SCA) with 12 reviews. Black Duck is rated 7.8, while Checkmarx Software Composition Analysis is rated 9.2. The top reviewer of Black Duck writes "Enables applications to be secure, but it must provide more open APIs". On the other hand, the top reviewer of Checkmarx Software Composition Analysis writes "Comprehensive security scan, helpful support, and high availability". Black Duck is most compared with Snyk, Fortify Static Code Analyzer, JFrog Xray, Mend.io and Veracode, whereas Checkmarx Software Composition Analysis is most compared with JFrog Xray, Semgrep Supply Chain, Fortify Static Code Analyzer, Mend.io and FOSSA. See our Black Duck vs. Checkmarx Software Composition Analysis report.
See our list of best Software Composition Analysis (SCA) vendors.
We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.