Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs OWASP Zap comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Static Application Security Testing (SAST)
3rd
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
80
Ranking in other categories
Application Security Tools (3rd), Vulnerability Management (16th), Container Security (15th), Static Code Analysis (2nd), API Security (3rd), Dynamic Application Security Testing (DAST) (2nd), DevSecOps (3rd), Risk-Based Vulnerability Management (8th), Application Security Posture Management (ASPM) (3rd), AI Security (1st)
OWASP Zap
Ranking in Static Application Security Testing (SAST)
10th
Average Rating
7.6
Reviews Sentiment
7.3
Number of Reviews
41
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2026, in the Static Application Security Testing (SAST) category, the mindshare of Checkmarx One is 10.4%, down from 12.0% compared to the previous year. The mindshare of OWASP Zap is 3.9%, down from 4.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Market Share Distribution
ProductMarket Share (%)
Checkmarx One10.4%
OWASP Zap3.9%
Other85.7%
Static Application Security Testing (SAST)
 

Featured Reviews

Shahzad Shahzad - PeerSpot reviewer
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Enable secure development workflows while identifying opportunities for faster scans and improved AI guidance
Checkmarx One is a very strong platform, but there are several areas where it can improve to support modern DevSecOps workflows even better. For example, better real-time developer guidance is needed. The IDE plugin should offer richer AI-powered auto-fixes similar to SNYK Code or GitHub Copilot Security, as current guidance is good but not deeply contextual for large-scale enterprise codebases. This matters because it reduces developer friction and accelerates shift-left adoption. More transparency control over the correlation engines is another need. The correlation engine is powerful but not fully transparent. Users want to understand why vulnerabilities were correlated or de-prioritized, which helps AppSec teams trust the prioritization logic. Faster SAST scan and more language coverage is needed since SAST scan can still be slow for very large mono-repos and there is limited deep support for new language frameworks like Rust and Go, along with advanced coverage for serverless-specific frameworks. This matters because large organizations want sub-minute scans in CI/CD as cloud-native ecosystems evolve fast. A strong API security module is another area for enhancement. API security scanning could be improved with active testing, API discovery, full Swagger, OpenAPI, drift detection, and schema-based fuzzing. This is important as API attacks are one of the biggest AppSec risks in 2025. Checkmarx One is strong, but I see a few areas for improvement including faster SAST scanning for large mono-repos, deeper language framework support, more transparent correlation logic, and stronger API security that includes discovery and runtime context. The IDE plugin could offer more AI-assisted fixes, and the SBOM lifecycle tracking can evolve further. Enhancing integration with SIEM and SOAR would also make enterprise adoption smoother, and these improvements would help developers and AppSec teams move faster with more accuracy.
Prasant Pokarnaa - PeerSpot reviewer
Delivery Head - DevOps at Datamato Technologies
Effective vulnerability identification enhances security scans but AI-driven enhancements are needed
OWASP is only meant for two or three different types of scans. It is a tool which will scan the code for security for vulnerabilities We were able to convince the customers to really remove those rules when GitLab was able to show the results. Customers should be aware that GitLab is not just a…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I have seen a return on investment from Checkmarx One."
"Checkmarx One has definitely helped us to save time and reduce the need for additional security resources, meaning employees."
"The main advantage of this solution is its centralized reporting functionality, which lets us track issues, then see and report on the priorities via a web portal."
"Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
"Helps us check vulnerabilities in our SAP Fiori application."
"The solution has good performance, it is able to compute in 10 to 15 minutes."
"Overall, the ability to find vulnerabilities in the code is better than the tool that we were using before."
"What I like best about Checkmarx is that it has fewer false positives than other products, giving you better results."
"The solution is good at reporting the vulnerabilities of the application."
"Fuzzer and Java APIs help a lot with our custom needs."
"They offer free access to some other tools."
"It scans while you navigate, then you can save the requests performed and work with them later."
"The product discovers more vulnerabilities compared to other tools."
"OWASP Zap is a good tool, one of my favorites for a long time, and I would recommend it."
"The API is exceptional."
"The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan websites with automatic scanning, and the website has a web application firewall, it's very difficult."
 

Cons

"There is nothing particular that I don't like in this solution. It can have more integrations, but the integrations that we would like are in the roadmap anyway, and they just need to deliver the roadmap. What I like about the roadmap is that it is going where it needs to go. If I were to look at the roadmap, there is nothing that is jumping out there that says to me, "Yeah. I'd like something else on the roadmap." What they're looking to deliver is what I would expect and forecast them to deliver."
"The Dynamic Application Security Testing (DAST) feature should be better."
"Checkmarx could improve by reducing the price."
"Some were valid and some were not applicable for us based on the scenario."
"Checkmarx needs to be more scalable for large enterprise companies."
"Checkmarx could improve the REST APIs by including automation."
"This product requires you to create your own rulesets. You have to do a lot of customization."
"For Checkmarx One, I think that adding repositories and scanning impromptu code could improve it."
"The reporting feature could be more descriptive."
"Deployment is somewhat complicated."
"Too many false positives; test reports could be improved."
"As security evolves, we would like DevOps built into it. As of now, Zap does not provide this."
"It doesn't run on absolutely every operating system."
"Reporting format has no output, is cluttered and very long."
"I'd like to see a kind of feature where we can just track what our last vulnerability was and how it has improved or not. More reports that can have some kind of base-lining, I think that would be a good feature too. I'm not sure whether it can be achieved and implement but I think that would really help."
"The ability to search the internet for other use cases and to use the solution to make applications more secure should be addressed."
 

Pricing and Cost Advice

"It is an expensive solution."
"I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone."
"The number of users and coverage for languages will have an impact on the cost of the license."
"It is a good product but a little overpriced."
"It's relatively expensive."
"It is the right price for quality delivery."
"We got a special offer for a 30% reduction for three years, after our first year. I think for a real source-code scanning tool, you have to add a lot of money for Open Source Analysis, and AppSec Coach (160 Euro per user per year)."
"The average deal size was usually anywhere between $120K to $175K on an annual basis, which could be divided across 12 months."
"The tool is open-source."
"We have used the freeware version. I believe Zap only has freeware."
"As Zap is free and open-source, with tons of features similar to those of commercial solutions, I would definitely recommend trying it out."
"This is an open-source solution and can be used free of charge."
"The solution’s pricing is high."
"The tool is open source."
"It's free. It's good for us because we don't know what the extent of our use will be yet. It's good to start with something free and easy to use."
"This solution is open source and free."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
879,927 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
11%
Manufacturing Company
10%
Government
5%
Computer Software Company
13%
Financial Services Firm
9%
University
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise9
Large Enterprise45
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise11
Large Enterprise21
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
Checkmarx One is a premium solution, so budget accordingly. Make sure you understand how licensing scales with additional applications and users. I advise negotiating multi-year contracts or bundle...
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What do you like most about OWASP Zap?
The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan websites with automatic scanning, and the website has a web application firewall, i...
What is your experience regarding pricing and costs for OWASP Zap?
OWASP might be cost-effective, however, people prefer to use the free edition available as open source.
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Find out what your peers are saying about Checkmarx One vs. OWASP Zap and other solutions. Updated: December 2025.
879,927 professionals have used our research since 2012.