Try our new research platform with insights from 80,000+ expert users

Checkmarx Software Composition Analysis vs Semgrep comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Checkmarx Software Composit...
Ranking in Software Composition Analysis (SCA)
8th
Average Rating
9.2
Number of Reviews
12
Ranking in other categories
No ranking in other categories
Semgrep
Ranking in Software Composition Analysis (SCA)
16th
Average Rating
0.0
Number of Reviews
0
Ranking in other categories
Static Application Security Testing (SAST) (34th), Supply Chain Management Software (27th), Static Code Analysis (10th)
 

Featured Reviews

DS
Sep 1, 2023
Identified and fixed security vulnerabilities in our code, such as a SQL injection vulnerability.
To make the list of the vulnerabilities more clear and exposed to the users in order to see. Sometimes, we see issues high-level issues vulnerabilities that are not really issues, the interpretation of scanning. Meaning, like, outside, it's not really the issue. But it surfaces as an issue, so we probably may have a database of the errors of the vulnerabilities to expose and maybe even provide some feedback on how valuable the vulnerability is. I'm doing that. So, basically, one area that could be improved is the way that false positives are handled. In future releases, if we could create a clear RESTful API to just extract the scanning data on user-added applications and presentations.
Use Semgrep?
Share your opinion

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pricing and Cost Advice

"My customers need to pay for the licensing part, and they need to opt for an annual subscription."
"It is a little bit high priced. It would be better if it was a little less expensive."
"Pricing for Checkmarx Software Composition Analysis needs to be competitive."
"We don't have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage."
"The license model is somewhat perplexing as it comprises multiple aspects that can be confusing for customers. The model is determined by the number of registered users and the number of projects being scanned, along with a third component that adds to the complexity."
Information not available
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
801,394 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
37%
Manufacturing Company
15%
Computer Software Company
11%
Healthcare Company
4%
Financial Services Firm
23%
Computer Software Company
16%
Manufacturing Company
8%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Checkmarx Software Composition Analysis?
The tool's visual scan analysis shows me all the libraries' vulnerabilities and license types. It helps identify the most complex issues with licenses. It provides good visibility. SCA shows me all...
What is your experience regarding pricing and costs for Checkmarx Software Composition Analysis?
We have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage.
What needs improvement with Checkmarx Software Composition Analysis?
Checkmarx Software Composition Analysis should improve dynamic analysis.
Ask a question
Earn 20 points
 

Also Known As

CxSCA
Semgrep Code, Semgrep Supply Chain, Semgrep AppSec Platform
 

Learn More

 

Overview

 

Sample Customers

AXA, Liveperson, Aaron's, Playtech, Morningstar
Policygenius, Tide, Lyft, Thinkific, FloQast, Vanta, and Fareportal
Find out what your peers are saying about Synopsys, Veracode, Snyk and others in Software Composition Analysis (SCA). Updated: August 2024.
801,394 professionals have used our research since 2012.