Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs Parasoft SOAtest comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.5
Checkmarx One enhances security, speeds delivery, reduces costs, and returns ROI within six months for some users.
Sentiment score
7.8
Parasoft SOAtest improved testing efficiency, reduced manual effort, automated testing, and enhanced software quality, making it essential for users.
 

Customer Service

Sentiment score
7.1
Checkmarx One provides generally positive support, but response delays and unresolved tickets challenge some users, despite skilled assistance.
Sentiment score
7.8
Parasoft SOAtest's service is generally satisfactory and responsive, but some report delays and communication issues in certain regions.
 

Scalability Issues

Sentiment score
7.1
Checkmarx One offers strong scalability, supports automation, and manages scan engines, though may face processing time and licensing cost constraints.
Sentiment score
7.2
Parasoft SOAtest is scalable, well-integrated with CI/CD pipelines, and suits teams of various sizes, scoring 7-8 in ratings.
 

Stability Issues

Sentiment score
7.1
Checkmarx One is generally stable, but users report occasional crashes and performance issues, varying stability ratings from 4-10.
Sentiment score
7.5
Parasoft SOAtest is rated 8/10 for stability, praised for being reliable, stable, and free from bugs or crashes.
 

Room For Improvement

Checkmarx One requires enhancements in false positive reduction, language support, pricing, role management, UI, and support response time.
Users want Parasoft SOAtest to be more user-friendly with improved reporting, guidance, optimization, UI testing, and code coverage.
 

Setup Cost

Checkmarx One's pricing is costly but justified by its flexibility, competitive pricing, and enhanced security for enterprises.
<p>Parasoft SOAtest pricing is customizable starting from $5,000 annually, including support, training, and updates, based on enterprise needs.</p>
 

Valuable Features

Checkmarx One offers advanced code analysis, seamless repository integration, and user-friendly features for efficient security testing and vulnerability management.
Parasoft SOAtest offers comprehensive testing, efficient automation, versatile data handling, scalability, and user-friendly features, including Service Virtualization.
 

Categories and Ranking

Checkmarx One
Ranking in Static Application Security Testing (SAST)
3rd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
70
Ranking in other categories
Application Security Tools (3rd), Vulnerability Management (22nd), Static Code Analysis (2nd), API Security (2nd), DevSecOps (2nd), Risk-Based Vulnerability Management (8th)
Parasoft SOAtest
Ranking in Static Application Security Testing (SAST)
31st
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
30
Ranking in other categories
Functional Testing Tools (19th), API Testing Tools (9th), Test Automation Tools (22nd)
 

Mindshare comparison

As of March 2025, in the Static Application Security Testing (SAST) category, the mindshare of Checkmarx One is 11.0%, down from 13.9% compared to the previous year. The mindshare of Parasoft SOAtest is 0.5%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
 

Featured Reviews

ScottDenton - PeerSpot reviewer
Supports different languages, has excellent support, and easily expands
The interactive application security testing, or IAST, where code scans are being ran on an application that lives in a runtime environment on a server or virtual machine, needs improvement. There was limited support from different languages. It didn't support everything under the sun, so you would lose revenue since you didn't have support for Scala or some other language that your developer was fluent in. They needed to improve on language support. That is about it, really. The dev team did everything that they said they were going to do. If they said they were going to hit a mark, they'd hit a mark. That release would come out. Typically, they would do four major releases a year, quarterly, with two-point releases in between, or based on any additional hotfixes that may be needed. In most cases, however, IAST was the part of the product that needed to be improved the most. Codebashing is a really cool product from the aspect of teaching developers how to write secure code. However, it would be even cooler if you could not only point out and teach someone how to do it while also making the appropriate recommendation on how to rewrite the code itself, using machine learning or AI. Instead of you, the developer learning how to do it and then writing the code yourself, it'd be cooler if you could push a button, have it analyzed, scans the code, find the code, find the issue within the line of code, and then go ahead and automatically rewrite that code for you. Then, by repetition, it just teaches you through muscle memory how to do that as opposed to, "Hey, you've found this problem. This is where the problem's located, within this particular line of code." Right now, do you know how to rewrite Java? Well, if you're not familiar with how to do that, then go push on this button. Now, take this test and go through this exercise.” It doesn't make a recommendation. It's not like providing a script that fixes the problem. It's just teaching you on how to write the code in that form in that manner.
Ujjwal Gupta - PeerSpot reviewer
Easy to use and understand with multiple types of testing on offer
It is very easy to understand. We can do a lot with it. Since this is a commercial tool, we can have more functionality in place. It covers more things like ADI and APIs, et cetera. Everything is in one place, right there, so you don't need to go anywhere. With one single tool, you have everything you need. You can even test the UI as well. The initial setup is very easy. There is nice functionality under the Service Virtualization feature. The solution is stable. Technical support is helpful. This product easily scales. Parasoft actually provides very extensive coverage. For example, in SAP applications, we have various EDIs, and integrated development. That also is supported by Parasoft. In the market, we don't have many of the tools there to test those things. It's nice to be able to with this product.
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
841,004 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
22%
Computer Software Company
15%
Manufacturing Company
10%
Government
5%
Financial Services Firm
24%
Manufacturing Company
18%
Computer Software Company
11%
University
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about Parasoft SOAtest?
Since the solution has both command line and automation options, it generates good reports.
What needs improvement with Parasoft SOAtest?
Tuning the tool takes time because it gives quite a long list of warnings. Going through that is a challenge. It only happens in the initial stage when we are setting up the tool, but it can be imp...
 

Also Known As

No data available
SOAtest
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Charter Communications, Sabre, Caesars Entertainment, Charles Schwab, ING, Intel, Northbridge Financial, Capital Services, WoodmenLife
Find out what your peers are saying about Checkmarx One vs. Parasoft SOAtest and other solutions. Updated: March 2025.
841,004 professionals have used our research since 2012.