We performed a comparison between Checkmarx One and Fortify Application Defender based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The UI is very intuitive and simple to use."
"What I like best about Checkmarx is that it has fewer false positives than other products, giving you better results."
"The most valuable features of Checkmarx are the Best Fix Location and the Payments option because you can save a lot of time trying to mitigate the configuration. Using these tools can save you a lot of time."
"The most valuable features of Checkmarx are the automation and information that it provides in the reports."
"The process of remediating software security vulnerabilities can now be performed (ongoing) as portions of the application are being built in advance of being compiled."
"Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%."
"The ability to track the vulnerabilities inside the code (origin and destination of weak variables or functions)."
"Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
"Fortify Application Defender's most valuable features are machine learning algorithms, real-time remediation, and automatic vulnerability notifications."
"Its ability to find security defects is valuable."
"I find the configuration of rules in Fortify Application Defender useful. Its integration is also easy."
"The most valuable feature is that it analyzes data in real-time."
"The tool's most valuable feature is software composition analysis. This feature works well with my .NET applications, providing a better understanding of library vulnerabilities."
"We are able to provide out customers with a secure application after development. They are no longer left wondering if they are vulnerable to different threats within the market following deployment."
"The solution helped us to improve the code quality of our organization."
"The product saves us cost and time."
"Micro-services need to be included in the next release."
"The validation process needs to be sped up."
"The tool is currently quite static in terms of finding security vulnerabilities. It would be great if it was more dynamic and we had even more tools at our disposal to keep us safe. It would help if there was more scanning or if the process was more automated."
"We can run only one project at a time."
"It would be really helpful if the level of confidence was included, with respect to identified issues."
"You can't use it in the continuous delivery pipeline because the scanning takes too much time."
"Checkmarx could improve the speed of the scans."
"The statistics module has a function that allows you to show some statistics, but I think it's limited. Maybe it needs more information."
"Fortify Application Defender could improve by supporting more code languages, such as GRAAS and Groovy."
"The biggest complaint that I have heard concerns additional platform support because right now, it only supports applications that are written in .NET and Java."
"The workbench is a little bit complex when you first start using it."
"The licensing can be a little complex."
"The solution could improve the time it takes to scan. When comparing it to SonarQube it does it in minutes while in Fortify Application Defender it can take hours."
"The false positive rate should be lower."
"Support for older compilers/IDEs is lacking."
"Fortify Application Defender gives a lot of false positives."
Checkmarx One is ranked 3rd in Application Security Tools with 67 reviews while Fortify Application Defender is ranked 30th in Application Security Tools with 11 reviews. Checkmarx One is rated 7.6, while Fortify Application Defender is rated 7.8. The top reviewer of Checkmarx One writes "The report function is a great, configurable asset but sometimes yields false positives". On the other hand, the top reviewer of Fortify Application Defender writes "Useful for fast code review in devOps pipelines ". Checkmarx One is most compared with SonarQube, Veracode, Fortify on Demand, Snyk and SonarCloud, whereas Fortify Application Defender is most compared with Coverity, CAST Application Intelligence Platform, SonarQube, Qualys Web Application Scanning and Fortify on Demand. See our Checkmarx One vs. Fortify Application Defender report.
See our list of best Application Security Tools vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.
Fewer false positives with CX than Fortify. More integrated.
Looking at the Gartner report I would say that Checkmarx is way easier to set up (initial setup) compared to Micro Focus Fortify.
Also, the financial strength of the Micro Focus Fortify spin/merger is a concern so investments could be at risk.
The major difference is that Checkmarx scans the code without compiling the code. This has a great advantage as code building issues are eliminated,
scan time is very less and false positive is less to some extent. One more major this is Checkmarx learns as you eliminate false positives and does not show the same issue again. We can perform incremental scans on the codebase where the old issue is nicely marked as "Recurring" and new ones in Red as NEW. Checkmarx has a highly customizable filter creation where you can create a filter that can eliminate the common recurring issues in
scans. This feature is very flexible and you can write your own filters and also, write specific patterns that are found in manual review which is a
great help as coding styles differ form teams to teams.
Thanks a lot. Thank you for the information.