

CodeSonar and OpenText Static Application Security Testing compete in static code analysis. OpenText SAST appears superior due to its robust features.
Features: CodeSonar is recognized for deep code analysis, vulnerability identification, and quick deployment. OpenText SAST has strong integration capabilities, extensive language support, and efficient risk mapping.
Room for Improvement: CodeSonar could enhance its cloud deployment options, integration with more tools, and language support. OpenText SAST may benefit from simplified configuration, reduced initial setup costs, and clearer documentation on feature updates.
Ease of Deployment and Customer Service: OpenText SAST offers flexible cloud and on-premise deployment with proactive customer service, making it adaptable for various infrastructures. CodeSonar primarily focuses on on-premise solutions with satisfactory support but less deployment versatility.
Pricing and ROI: CodeSonar offers a cost-effective setup leading to strong ROI by minimizing long-term vulnerabilities. OpenText SAST's higher initial costs are justified by comprehensive features that provide consistent returns, enhancing application security.
| Product | Mindshare (%) |
|---|---|
| OpenText Static Application Security Testing | 5.5% |
| CodeSonar | 3.8% |
| Other | 90.7% |

| Company Size | Count |
|---|---|
| Small Business | 5 |
| Midsize Enterprise | 1 |
| Large Enterprise | 2 |
| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 3 |
| Large Enterprise | 11 |
CodeSonar offers a potent tool for static code analysis, adept in detecting runtime errors and security vulnerabilities, with a fast deployment process and scalable capabilities. Its quick analysis and efficient web interface provide a strong basis for code quality validation.
CodeSonar specializes in identifying runtime errors, dead code, and security threats while providing features like code surfing and browsing. It offers a highly efficient web interface, though users find initial setup complex and highlight the need for better static analysis, broader language support beyond C and C++, and an improved licensing model. Despite these challenges, its integration with Jenkins and technical guidance support makes it a reliable choice for teams in defense and software quality assessment. Deployment is quick and easy, yet initial costs are a common concern among users.
What are the key features of CodeSonar?CodeSonar is primarily implemented in industries like defense and companies prioritizing code quality. Teams utilize its static code analysis and threat detection capabilities, integrating with Jenkins for continuous integration workflows. Security checks post-builds and technical support are common, aiding in effective defect management.
OpenText Static Application Security Testing empowers teams with efficient vulnerability detection and streamlined secure coding practices, offering comprehensive language support and seamless integration with development tools.
OpenText Static Application Security Testing enhances software security during development by accurately identifying vulnerabilities with minimal false positives. It integrates seamlessly with IDEs and CI/CD pipelines, making it highly efficient for early detection of security issues. Users benefit from its easy setup, clear documentation, and centralized portal for managing security findings. Despite facing challenges like high costs and complex configurations for certain languages, its role in facilitating compliance and streamlining secure coding processes is indispensable. Improvements are needed in areas such as outdated design, language support, and integration capabilities to meet evolving user expectations.
What features does OpenText Static Application Security Testing offer?Organizations across diverse sectors implement OpenText Static Application Security Testing primarily to secure applications during development phases. Its integration with tools like GitLab, Jenkins, and Azure DevOps ensures a robust security pipeline. By combining with Sonatype Nexus, secure code, and library management is achieved effectively.
We monitor all Static Code Analysis reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.