Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard WAF vs SonarQube Server (formerly SonarQube) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 30, 2024
 

Categories and Ranking

Check Point CloudGuard WAF
Ranking in Application Security Tools
10th
Average Rating
8.8
Reviews Sentiment
8.0
Number of Reviews
33
Ranking in other categories
Web Application Firewall (WAF) (14th)
SonarQube Server (formerly ...
Ranking in Application Security Tools
1st
Average Rating
8.0
Reviews Sentiment
7.5
Number of Reviews
113
Ranking in other categories
Static Application Security Testing (SAST) (1st), Software Development Analytics (1st)
 

Mindshare comparison

As of December 2024, in the Application Security Tools category, the mindshare of Check Point CloudGuard WAF is 0.1%, up from 0.1% compared to the previous year. The mindshare of SonarQube Server (formerly SonarQube) is 26.7%, down from 27.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
 

Featured Reviews

Ashish Upadhyay - PeerSpot reviewer
Automation capabilities also help streamline security processes and smooths down API integration processes and detects API availability
There is room for improvement in the pricing strategy. By reducing their cost and extending the trial period, Check Point can attract more partnerships and customers, keeping up with other vendors in the field. It has a trial period, but they can extend it so we can better evaluate how it's working in our environment and how well it is suited. It should be converted to activate some discounts on buying standard versions. This will attract more of us, and we'll get more time to check the application and how it works. Additionally, their effort to involve IT teams would mean continuous adaptation to meet business requirements. This can help with the price picture and increasing the trial period so we can better evaluate the cost-effectiveness. Also, Check Point need to continue developing new features and arrangements in line with changing business requirements. The analysis time while it analyzes itself is very time-consuming. They need to improve the latency and minimize the steps involved. Also, the documentation needs to be updated, more improved, and simplified... so that even a beginner can start with this application. It can make things more beginner-friendly. Also, Check Point can bring some updates to the integration features with other security solutions, making it easier to integrate. For instance, it needs to integrate with solutions someone might have various firewall solutions from IBM and others, depending on which ones the business wants to integrate with.
Wang Dayong - PeerSpot reviewer
Easy to integrate and has a plug-in that supports both C and C++ languages
The product provides false reports sometimes. It also fails to understand the context of the code. It reports that a line of code has issues without considering its relation with the previous line. The product should improve the report quality. While it asks us to improve the code quality, it would be good if it also suggests how to improve the quality.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution offers continuous security monitoring and alerting, which can help organizations detect and respond to security incidents in real time."
"User attitude reviews help us keep all online users compliant with company regulations and policies."
"They offer free trials, which is quite appreciative and grabs more attention from new users and businesses."
"It offers good functionality of the application that is currently running."
"On the endpoint side, the most valuable feature is undoubtedly the cloud-based management capability, along with the ransomware protection, despite not encountering any instances so far."
"With the solution, we managed to obtain complete comprehensive visibility of the entire environment in the cloud, thus having better control of each of the resources."
"After integrating AppSec with other applications, team members can easily work without fear of confidential information exposure."
"The most valuable features are its ease of use and multiple functionalities."
"Code Convention: Using the tool to implement some sort of coding convention is really useful and ensures that the code is consistent no matter how many contributors."
"The most valuable features are the wide array of languages, multiple languages per project, the breakdown of bugs, and the description of vulnerabilities and code smells (best practices)."
"We are using the Community edition. So, we don't have to incur any licensing costs. This is the best part."
"We advise all of our developers to have this solution in place."
"The stability is good."
"The overall quality of the indicator is good."
"We have worked with the support from SonarQube and we have had good experiences."
"The reporting and the results are quick. It gets integrated within the pipeline well."
 

Cons

"Deeper and more transparent integration between Cloud Application Security and analysis monitoring tools could be very valuable - although the solution currently offers integrations with third-party security tools."
"Cost reduction and trial period extension should be considered with some lucrative discount offerings in buying standard versions."
"You need to know exactly the system. You cannot have someone running the system if they don't have the knowledge to do so."
"They need improved latency in the main window."
"We would like to have a solution of this type for the administration of applications from mobile devices."
"One of the big problems we found in Check Point, in general, is the support."
"I do not know if it is already there, but I would like to have complete visibility between the posture management and firewall as a service."
"Improving the process for handling licensing renewals would be a welcome enhancement."
"A better design of the interface and add some new rules."
"The reporting is good, but I am not able to download a specific report as a PDF, so downloading reports is something that should be looked at."
"I am not very pleased with the technical debt computation."
"I would also like SonarQube to be able to write custom scanning rules. More documentation would be helpful as well because some of our guys were struggling with the customization script."
"I would like to see dynamic code analysis in the next version of the software."
"The product's pricing could be lower."
"Code security could be better. They are already focusing on it, but I see a lot of improvement opportunities over there. I can see a lot of false positives in terms of security. They need to make the tests more accurate so that the false positives are not detected so frequently. It would also help if they provided us with an installer."
"Although it has Sonar built into it, it is still lacking. Customization features of identifying a particular attack still need to be worked on. To give you an example: if we want to scan and do a false positive analysis, those types of features are missing. If we want to rescan something from a particular point that is a feature that is also missing. It’s in our queue. That will hopefully save a lot of time."
 

Pricing and Cost Advice

"Check Point CloudGuard Application Security's pricing is comparable to other products in the market."
"Considering all the benefits we've observed, we find the price to be satisfactory."
"The pricing is not that expensive considering what it offers."
"If the pricing for the Infinity platform covers everything, it would be more straightforward. I had a hard time selling it to our CEO as a former CFO because of the differentials. There are different deltas year to year over a five-year period. It is very difficult to explain. It would be easier to digest for our executives if there was a flatter scale"
"The tool's licensing costs are yearly and competitive."
"Check Point CloudGuard Application Security's pricing is not friendly."
"I work for an Indian banking client. In India, companies are on a budget. The company liked Check Point very much, but it was a little bit costly compared to FortiWeb. However, it had more features compared to FortiWeb."
"I find the pricing to be reasonable."
"It's a bit expensive for us. The currency rate of the dollar is a problem but it may be fine for other countries."
"We use the free version; there are no hidden costs or licensing required."
"I am satisfied with the pricing."
"Get the paid version which allows the customized dashboard and provides technical support."
"This product is open source and very convenient."
"As a user and a consumer of this solution, it can be pricey for my company to support and use, even though there are many benefits. For this reason, we use the free version. In the future, as our product cycles develop and evolve at a more steady pace, we hope to invest in the licensing for this tool."
"SonarQube enterprise, I am not sure of the price but from what I understand they are charging a fee. It's is not clear if it is an annual fee or a one-off."
"The development license cost is reasonable, and we've had no concerns about SonarQube when it comes to cost."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Computer Software Company
11%
Security Firm
9%
Manufacturing Company
7%
Financial Services Firm
17%
Computer Software Company
15%
Manufacturing Company
13%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about CloudGuard for Application Security?
We have not had any incidents. We could realize its benefits immediately. We watched and monitored the traffic, and it was amazing to see the results.
What is your experience regarding pricing and costs for CloudGuard for Application Security?
Pricing is average—not too expensive, yet not cheap either. CloudGuard offers bundled packages, which may reduce costs compared to paying for individual features as opposed to other providers.
What needs improvement with CloudGuard for Application Security?
Support could be improved, particularly in terms of availability. Although they provide 24/7 support, there are sometimes delays in delivering solutions. Advanced bot protection has recently been i...
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
 

Also Known As

Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec
Sonar
 

Learn More

 

Interactive Demo

 

Overview

 

Sample Customers

Orange España, Paschoalotto
Information Not Available
Find out what your peers are saying about Check Point CloudGuard WAF vs. SonarQube Server (formerly SonarQube) and other solutions. Updated: December 2024.
824,053 professionals have used our research since 2012.