Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs GitHub comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Application Security Tools
3rd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
70
Ranking in other categories
Static Application Security Testing (SAST) (3rd), Vulnerability Management (21st), Static Code Analysis (2nd), API Security (3rd), DevSecOps (2nd), Risk-Based Vulnerability Management (8th)
GitHub
Ranking in Application Security Tools
6th
Average Rating
8.8
Reviews Sentiment
7.5
Number of Reviews
93
Ranking in other categories
Version Control (3rd)
 

Mindshare comparison

As of April 2025, in the Application Security Tools category, the mindshare of Checkmarx One is 10.7%, down from 15.1% compared to the previous year. The mindshare of GitHub is 0.8%, down from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
 

Featured Reviews

Rohit Kesharwani - PeerSpot reviewer
Provides good security analysis and security identification within the source code
We integrate Checkmarx into our software development cycle using GitLab's CI/CD pipeline. Checkmark has been the most helpful for us in the development stage. The solution's incremental scanning feature has impacted our development speed. The solution's vulnerability detection is around 80% to 90% accurate. I would recommend Checkmarx to other users because it is one of the good tools for doing security analysis and security identification within the source code. Overall, I rate Checkmarx a nine out of ten.
Pervez Roy - PeerSpot reviewer
Very good for collaboration on software projects
We use GitHub for code repository alongside Bitbucket GitHub is very good for collaboration on software projects. We prefer Bitbucket for commercial use, while GitHub is used for open source. You can get the differences, history of changes, and version control for various pull requests. You can…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The main advantage of this solution is its centralized reporting functionality, which lets us track issues, then see and report on the priorities via a web portal."
"What I like best about Checkmarx is that it has fewer false positives than other products, giving you better results."
"The most valuable feature of Checkmarx is the user interface, it is very easy to use. We do not need to configure anything, we only have to scan to see the results."
"The most valuable feature is that it actually identifies the different criteria you can set to meet whatever standards you're trying to get your system accredited for."
"Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
"The user interface is excellent. It's very user friendly."
"Most valuable features include: ease of use, dashboard. interface and the ability to report."
"It gives the proper code flow of vulnerabilities and the number of occurrences."
"The most valuable features are GitHub are the standard features, they are very useful."
"We are finding GitHub is very stable."
"You can write the code with AI. But when it comes to implementation, you must upgrade the bits of code that will support this and generate solutions based on that architecture. Then, you need comparable code bits. Therefore, AI can propose how much a specific function can be better optimized. So, AI can help stakeholders reach tasks quicker."
"I did not have any issues with the stability of Github. It worked seamlessly."
"During our use of GitHub, we have not encountered any problems and GitHub adds new features frequently."
"GitHub is convenient and easy to use."
"The tool also helps organize collaboration by allowing users to share a repository with other developers."
"The deployment is fast since we just have to run the script, and once it's done, it takes a few minutes."
 

Cons

"It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."
"The validation process needs to be sped up."
"We have received some feedback from our customers who are receiving a large number of false positives."
"The interactive application security testing, or IAST, the interactive part where you're looking at an application that lives in a runtime environment on a server or virtual machine, needs improvement."
"Micro-services need to be included in the next release."
"Checkmarx could improve by reducing the price."
"I would like to see the rate of false positives reduced."
"Meta data is always needed."
"Our firewall was blocking cloning and downloading with SSH."
"I cannot recall coming across any shortcomings of the product."
"The solution's cost is high and should be reduced."
"The onboarding process could be simplified."
"There are still areas for improvement with GitHub Actions and their deployment workflows, as they have made significant progress but are not yet polished."
"I would want to see some form of code security scanning implemented."
"The ticketing system is not working."
"The solution could have better support for the Markdown language."
 

Pricing and Cost Advice

"The tool's pricing is fine."
"The number of users and coverage for languages will have an impact on the cost of the license."
"I believe pricing is better compared to other commercial tools."
"For around 250 users or committers, the cost is approximately $500,000."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"Its price is fair. It is in or around the right spot. Ultimately, if the price is wrong, customers won't commit, but they do tend to commit. It is neither too cheap nor too expensive."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"My company purchased it. Before, we used to receive the free version, but then they purchased some of the features."
"If I consider the market standards, the product's price is pocket-friendly."
"I haven't had to pay anything for GitHub, I use the free version."
"GitHub is a cost-effective solution."
"The private repositories are free, which is very good."
"You don't have to pay for a license if you are using the free version."
"I use the free version of GitHub."
"It is open-source. There is no license for GitHub."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
848,716 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
14%
Manufacturing Company
10%
Government
5%
Financial Services Firm
13%
Manufacturing Company
13%
Computer Software Company
12%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about GitHub?
The control is the most valuable feature as developers can work on a single code.
What is your experience regarding pricing and costs for GitHub?
The pricing of GitHub depends on the choice of solutions, such as building one's own GitHub Runners to save money or using GitHub's Runners with extra costs. The pricing is considered reasonable an...
What needs improvement with GitHub?
There are still areas for improvement with GitHub Actions and their deployment workflows, as they have made significant progress but are not yet polished. Occasionally, stability can be an issue, t...
 

Comparisons

 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Dominion Enterprises, NASA, Braintree, SAP, CyberAgent
Find out what your peers are saying about Checkmarx One vs. GitHub and other solutions. Updated: April 2025.
848,716 professionals have used our research since 2012.