Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs OWASP Zap comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Static Application Security Testing (SAST)
4th
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Vulnerability Management (24th), Static Code Analysis (3rd), API Security (5th), DevSecOps (5th), Risk-Based Vulnerability Management (9th)
OWASP Zap
Ranking in Static Application Security Testing (SAST)
11th
Average Rating
7.6
Reviews Sentiment
7.3
Number of Reviews
41
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2025, in the Static Application Security Testing (SAST) category, the mindshare of Checkmarx One is 9.5%, down from 12.7% compared to the previous year. The mindshare of OWASP Zap is 4.7%, down from 4.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Amit Beniwal - PeerSpot reviewer
Simplifies vulnerability discovery and has high quality support
There are areas for improvement with OWASP Zap, particularly in the alignment of vulnerabilities concerning CVSS scores. Sometimes, a vulnerability initially categorized as high severity may be reduced to medium or low over time after security patches are applied. This alignment with the present severity score and CVSS score could be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Checkmarx is the user interface, it is very easy to use. We do not need to configure anything, we only have to scan to see the results."
"Less false positive errors as compared to any other solution."
"The user interface is modern and nice to use."
"It has all the features we need."
"The most valuable features of Checkmarx are the SCA module and the code-checking module. Additionally, the solutions are explanatory and helpful."
"Most valuable features include: ease of use, dashboard. interface and the ability to report."
"The best thing about Checkmarx is the amount of vulnerabilities that it can find compared to other free tools."
"The reports are very good because they include details on the code level, and make suggestions about how to fix the problems."
"OWASP is quite matured in identifying the vulnerabilities."
"Simple and easy to learn and master."
"One valuable feature of OWASP Zap is that it is simple to use."
"The ZAP scan and code crawler are valuable features."
"It has evolved over the years and recently in the last year they have added, HUD (Heads Up Display)."
"OWASP Zap is a good tool, one of my favorites for a long time, and I would recommend it."
"Automatic scanning is a valuable feature and very easy to use."
"​It has improved my organization with faster security tests.​"
 

Cons

"I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side."
"The product's reporting feature could be better. The feature works well for developers, but reports generated to be shared with external parties are poor, it lacks the details one gets when viewing the results directly from the Checkmarx One platform."
"Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
"It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."
"Checkmarx is not good because it has too many false positive issues."
"Integration into the SDLC (i.e. support for last version of SonarQube) could be added."
"Licensing models and Swift language support are the aspects in which this product needs to improve. Swift is a new language, in which major customers require support for lower prices."
"Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”."
"The forced browse has been incorporated into the program and it is resource-intensive."
"OWASP Zap needs to extend to mobile application testing."
"It would be beneficial to enhance the algorithm to provide better summaries of automatic scanning results."
"For scalability, I would rate OWASP Zap between four to five out of ten."
"The solution is unable to customize reports."
"The product reporting could be improved."
"There's very little documentation that comes with OWASP Zap."
"Sometimes, we get some false positives."
 

Pricing and Cost Advice

"The average deal size was usually anywhere between $120K to $175K on an annual basis, which could be divided across 12 months."
"I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone."
"Checkmarx is comparatively costlier than other products, which is why some of the customers feel reluctant to go for it, though performance-wise, Checkmarx can compete with other products."
"It is the right price for quality delivery."
"The solution's price is high and you pay based on the number of users."
"We have purchased an annual license to use this solution. The price is reasonable."
"For around 250 users or committers, the cost is approximately $500,000."
"The solution is costly."
"This app is completely free and open source. So there is no question about any pricing."
"OWASP ZAP is a free tool provided by OWASP’s engineers and experts. There is an option to donate."
"It is open source, and we can scan freely."
"OWASP Zap is free to use."
"It is highly recommended as it is an open source tool."
"This solution is open source and free."
"We have used the freeware version. I believe Zap only has freeware."
"It's free and open, currently under the Apache 2 license. If ZAP does what you need it to do, selling a free solution is a very easy."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
863,679 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
Computer Software Company
17%
Financial Services Firm
11%
Manufacturing Company
8%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What do you like most about OWASP Zap?
The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan websites with automatic scanning, and the website has a web application firewall, i...
What is your experience regarding pricing and costs for OWASP Zap?
OWASP might be cost-effective, however, people prefer to use the free edition available as open source.
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Find out what your peers are saying about Checkmarx One vs. OWASP Zap and other solutions. Updated: July 2025.
863,679 professionals have used our research since 2012.