Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs GitHub comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 5, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Application Security Tools
3rd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
70
Ranking in other categories
Static Application Security Testing (SAST) (3rd), Vulnerability Management (21st), Static Code Analysis (2nd), API Security (2nd), DevSecOps (2nd), Risk-Based Vulnerability Management (7th)
GitHub
Ranking in Application Security Tools
7th
Average Rating
8.8
Reviews Sentiment
7.5
Number of Reviews
92
Ranking in other categories
Version Control (3rd)
 

Mindshare comparison

As of February 2025, in the Application Security Tools category, the mindshare of Checkmarx One is 11.5%, down from 15.2% compared to the previous year. The mindshare of GitHub is 0.8%, down from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
 

Featured Reviews

Rohit Kesharwani - PeerSpot reviewer
Provides good security analysis and security identification within the source code
We integrate Checkmarx into our software development cycle using GitLab's CI/CD pipeline. Checkmark has been the most helpful for us in the development stage. The solution's incremental scanning feature has impacted our development speed. The solution's vulnerability detection is around 80% to 90% accurate. I would recommend Checkmarx to other users because it is one of the good tools for doing security analysis and security identification within the source code. Overall, I rate Checkmarx a nine out of ten.
Pervez Roy - PeerSpot reviewer
Very good for collaboration on software projects
We use GitHub for code repository alongside Bitbucket GitHub is very good for collaboration on software projects. We prefer Bitbucket for commercial use, while GitHub is used for open source. You can get the differences, history of changes, and version control for various pull requests. You can…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The best thing about Checkmarx is the amount of vulnerabilities that it can find compared to other free tools."
"We use the solution to validate the source code and do SAST and security analysis."
"The process of remediating software security vulnerabilities can now be performed (ongoing) as portions of the application are being built in advance of being compiled."
"The most valuable feature is that it actually identifies the different criteria you can set to meet whatever standards you're trying to get your system accredited for."
"It gives the proper code flow of vulnerabilities and the number of occurrences."
"The solution improved the efficiency of our code security reviews. It helps tremendously because it finds hundreds of potential problems sometimes."
"The most valuable features of Checkmarx are the automation and information that it provides in the reports."
"Most valuable features include: ease of use, dashboard. interface and the ability to report."
"You can get the differences, history of changes, and version control for various pull requests."
"The technical support of the solution is good, and our company has used it for GitHub upgrades."
"I use this solution to store my code in a repository so we can manage version control which is useful."
"The most valuable feature is the source code management. It's very helpful and it's a great product."
"It has a lot of features from the code development perspective. You get a lot of features such as repo, commit, merge, and branch. You can play around and do things on the fly. It is easy and simple to deploy. It is also easier to use when working from home."
"GitHub is a fundamental tool in the software industry."
"Any complex banking can be handled very easily in GitHub. It allows us to integrate with tools like Grid, where we can merge and resolve conflicts without any hassle."
"The most valuable aspects of GitHub are version control and parallel development. I also appreciate the forking part, which allows us to release a specific set of features to the environment."
 

Cons

"Checkmarx is not good because it has too many false positive issues."
"The integration could improve by including, for example, DevSecOps."
"The validation process needs to be sped up."
"The plugins for the development environment have room for improvements such as for Android Studio and X code."
"C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported."
"We have received some feedback from our customers who are receiving a large number of false positives."
"You can't use it in the continuous delivery pipeline because the scanning takes too much time."
"Checkmarx being Windows only is a hindrance. Another problem is: why can't I choose PostgreSQL?"
"We want to incorporate management comments within GitHub, making it more like a product management tool. We haven't done that yet. Another change we're considering is migrating from GitHub to Azure DevOps, especially now that Microsoft has introduced it."
"The documentation needs to be more concise and easier for developers to understand."
"When solving merge conflicts, it would be helpful to have tooltips within the actions to know what changes could happen next when resolving a conflict."
"GitHub's issue management could be improved a little from an organization standpoint. It would be helpful to have the ability to organize a work board or a backlog more comprehensively. For organizations migrating to GitHub from arbitrary systems, it's a little bit of a headache to move on to that system."
"There is nothing that I find that needs improvement in GitHub."
"I faced one or two breakdowns. That said, they lasted only for a few seconds or a minute."
"In complex cases, we have to use the terminal for conflict resolution. If those conflicts could be resolved visually in the editor, that would be much better."
"The ticketing system is not working."
 

Pricing and Cost Advice

"It is an expensive solution."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"The price of Checkmarx could be reduced to match their competitors, it is expensive."
"We have purchased an annual license to use this solution. The price is reasonable."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"I believe pricing is better compared to other commercial tools."
"The tool's pricing is fine."
"The price of this solution is reasonable."
"GitHub is an open-source application. It's free to use."
"We are currently paying nothing for GitHub."
"My company purchased it. Before, we used to receive the free version, but then they purchased some of the features."
"You don't have to pay for a license if you are using the free version."
"The private repositories are free, which is very good."
"There are no licensing fees for the features that we use."
"I haven't had to pay anything for GitHub, I use the free version."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
838,640 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
14%
Manufacturing Company
10%
Government
5%
Manufacturing Company
13%
Financial Services Firm
12%
Computer Software Company
12%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about GitHub?
The control is the most valuable feature as developers can work on a single code.
What is your experience regarding pricing and costs for GitHub?
I'm not aware of the costs associated with GitHub. I simply appreciate its efficiency in managing code and collaborating with team members.
What needs improvement with GitHub?
I would like to see some AI functionality included in GitHub, similar to the features seen in GitLab, to enhance productivity. Additionally, offering limited free access to features like Copilot co...
 

Comparisons

 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Dominion Enterprises, NASA, Braintree, SAP, CyberAgent
Find out what your peers are saying about Checkmarx One vs. GitHub and other solutions. Updated: January 2025.
838,640 professionals have used our research since 2012.