Checkmarx One and Coverity are contenders in the software security field, each with distinct advantages. Checkmarx One appears to have the upper hand in pricing and support satisfaction, indicating cost-effectiveness and customer care.
Features: Checkmarx One's effective integration capabilities, broad language support, and pricing are highlighted as key features. Coverity stands out with its advanced static analysis, precise defect detection, and comprehensive feature set.
Room for Improvement: Checkmarx One could enhance performance speed, reporting, and specific integration features. Coverity may benefit from improved customizability, interface enhancements, and specific integration improvements.
Ease of Deployment and Customer Service: Checkmarx One is recognized for flexible deployment options and responsive support. Coverity offers strong on-premise solutions but faces complexity in setup, though with professional customer service.
Pricing and ROI: Checkmarx One's competitive pricing and high ROI make it attractive for budget-conscious users. Coverity presents higher initial costs but justifies them with significant ROI from advanced features.
The Coverity license fee is very high, making it tricky for individual developers.
Understanding the reporting in the beginning was challenging, especially when figuring out which mode to run on and the different arguments to use.
Understanding the flow and pipeline helps in scaling effectively.
Coverity is considered expensive compared to other tools like SonarQube, which is much cheaper.
The most valuable feature of Coverity is its interprocedural analysis.
The solution offers good scalability and is straightforward to deploy.
Checkmarx One is an enterprise cloud-native application security platform focused on providing cross-tool, correlated results to help AppSec and developer teams prioritize where to focus time and resources.
Checkmarx One offers comprehensive application scanning across the SDLC:
Checkmarx One provides everything you need to secure application development from the first line of code through deployment and runtime in the cloud. With an ever-evolving set of AppSec engines, correlation and prioritization features, and AI capabilities, Checkmarx One helps consolidate expanding lists of AppSec tools and make better sense of results. Its capabilities are designed to provide an improved developer experience to build trust with development teams and ensure the success of your AppSec program investment.
Coverity gives you the speed, ease of use, accuracy, industry standards compliance, and scalability that you need to develop high-quality, secure applications. Coverity identifies critical software quality defects and security vulnerabilities in code as it’s written, early in the development process, when it’s least costly and easiest to fix. With the Code Sight integrated development environment (IDE) plugin, developers get accurate analysis in seconds in their IDE as they code. Precise actionable remediation advice and context-specific eLearning help your developers understand how to fix their prioritized issues quickly, without having to become security experts.
Coverity seamlessly integrates automated security testing into your CI/CD pipelines and supports your existing development tools and workflows. Choose where and how to do your development: on-premises or in the cloud with the Polaris Software Integrity Platform (SaaS), a highly scalable, cloud-based application security platform. Coverity supports more than 20 languages and 200 frameworks and templates.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.