No more typing reviews! Try our Samantha, our new voice AI agent.

Contrast Security Assess vs Veracode comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.8
Contrast Security Assess improves code quality, reduces costs, and streamlines workflows by detecting vulnerabilities early, enhancing efficiency.
Sentiment score
6.5
Veracode boosts ROI by reducing security breaches and costs, enhancing compliance, and integrating effective vulnerability detection and automation.
Contrast has probably saved us a couple hundred hours over the past six years.
Threat & Vulnerability Management Senior Analyst at a tech vendor with 10,001+ employees
The speed of fixing issues is significantly improved due to the vast amount of information provided by Contrast Security Assess, making it quite essential for finding the root cause of problems in the source code.
Management Of Quality Managers at a tech vendor with 1,001-5,000 employees
The scanners of Veracode bring status of the weaknesses in the current infrastructure. It scans and provides reports regarding the servers, the network, and the applications running on those servers.
Senior Solutions Architect at IDS Comercial
Regarding price, the evaluation should focus on how efficiently they will recover their investment, considering the time saved through the use of Veracode Fix, for example, and the ability to fix code at dev time compared to the problems faced when fixing after the product is already deployed.
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
We did see a return on investment with Veracode, as we segregated our remediation efforts, which reduced our time to delivery as well as the number of engineers needed to help us in delivering a secure solution.
DevSecOps Engineer at a tech services company with 11-50 employees
 

Customer Service

Sentiment score
8.4
Contrast Security Assess support is responsive and knowledgeable, with efficient issue resolution and high user satisfaction despite customization challenges.
Sentiment score
7.2
Veracode's support is praised for expertise and responsiveness, though some report delays, improvements noted with dedicated managers.
They go out of their way to respond quickly and very knowledgeably.
Threat & Vulnerability Management Senior Analyst at a tech vendor with 10,001+ employees
Customer support is one of the strongest points of Contrast Security Assess, as they are really responsive and answer tickets in less than one hour.
Management Of Quality Managers at a tech vendor with 1,001-5,000 employees
Access to the engineering team is crucial for faster feedback on the product fix process.
Principal Architect at a consultancy with 11-50 employees
I have communicated with the technical support of Veracode a couple of times, and this was a really great experience because these professionals know their material.
Application Security Specialist at Herrenknecht
They share detailed information via email, including screenshots or further clarification about the issue.
DevSecOps Engineer at a tech services company with 1,001-5,000 employees
 

Scalability Issues

Sentiment score
8.0
Contrast Security Assess offers scalability across platforms but faces challenges with change management and limited technology support.
Sentiment score
7.4
Veracode is praised for effective scalability across diverse needs, though costs and complexity can increase with scaling.
It is fairly simple to install the agents for Contrast Security Assess and keep them updated.
Threat & Vulnerability Management Senior Analyst at a tech vendor with 10,001+ employees
Contrast Security Assess's scalability is not an issue at all.
Management Of Quality Managers at a tech vendor with 1,001-5,000 employees
Cloud solutions are easier to scale than on-premise solutions.
Senior Solutions Architect at IDS Comercial
It has a good capacity to scale effectively.
Lead Automation Quality Engineer in Leading UK Bank at a consultancy with 10,001+ employees
Implementing these features into our normal CI/CD was good, so I can say that scalability is really good.
Application Security Specialist at Herrenknecht
 

Stability Issues

Sentiment score
7.9
Contrast Security Assess is highly stable and reliable, with occasional environment-related issues and limited ColdFusion support.
Sentiment score
7.8
Veracode is generally stable with minor glitches, but could improve speed and communication for enhanced reliability.
We opened a ticket to customer support and experienced four weeks of disruption due to the extension malfunctioning in some of the .NET servers running Contrast Security Assess.
Management Of Quality Managers at a tech vendor with 1,001-5,000 employees
If the Veracode server is down, we experience many issues during the scan.
Lead Automation Quality Engineer in Leading UK Bank at a consultancy with 10,001+ employees
I have observed that it is not that reliable in terms of security because Veracode was not able to find some security threats in our application that existed since the product was developed.
Software Development Engineer II at Rocket Software
It's not that easy to onboard, but once they have been onboarded on the platform, and the pipeline configured alongside the product configured, it works effectively.
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
 

Room For Improvement

Contrast Security Assess offers effective automation but requires better documentation, integration, reporting, support, pricing flexibility, and AI enhancements.
Veracode is criticized for high costs, licensing rigidity, false positives, slow UI, and limited integration and language support.
Regarding Contrast Security Assess's AI capabilities, I think they are missing a huge opportunity because they could lead the way in automatic testing and AI security testing.
Management Of Quality Managers at a tech vendor with 1,001-5,000 employees
Contrast support has been great in fixing any issues or getting back to us with questions.
Threat & Vulnerability Management Senior Analyst at a tech vendor with 10,001+ employees
Contrast Security Assess can be improved as it checks the code and asks to fix the code that is vulnerable, and in that way, we can prevent potential hacking or attempts for people to inject malicious code.
Postdoctoral Research Fellow at a program development consultancy with 1-10 employees
If it could be integrated directly with code repositories such as Bitbucket or GitHub, without the need to create a pipeline to upload and decode code, it would simplify the code scan process significantly.
We had issues with scanning large applications. Scanning took a lot of time, so we kept it outside the DevOps pipeline to avoid delaying deployments.
Lead Automation Quality Engineer in Leading UK Bank at a consultancy with 10,001+ employees
A nice addition would be if it could be extended for scenarios with custom cleansers.
IT App Security Senior Analyst at a transportation company with 10,001+ employees
 

Setup Cost

Contrast Security Assess offers scalable pricing based on application size and environment, ranging from $20,000 to $100,000 annually.
Veracode's pricing is high and complex, valued by enterprises but expensive for smaller businesses with flexible options.
Licensing costs are fairly high compared to other DAST and SAST tools, but it seems to be worth the money.
Threat & Vulnerability Management Senior Analyst at a tech vendor with 10,001+ employees
It's not the most expensive solution.
Senior Solutions Architect at IDS Comercial
Overall, Veracode's pricing is lower and more scalable than many alternatives in the market.
DevSecOps Engineer at a tech services company with 1,001-5,000 employees
If there's a security gap, you'll never know the cost or effect.
 

Valuable Features

Contrast Security Assess offers real-time vulnerability detection with minimal false positives, enhancing security through CI/CD integration and proactive measures.
Veracode offers effective security analysis, CI/CD integration, multi-language support, and detailed reports for secure, compliant software development.
The ability to see what is going on and what has been going on in a given application and basically get to see what is coming across it in real time is helpful in finding vulnerabilities to remediate before production deployments.
Threat & Vulnerability Management Senior Analyst at a tech vendor with 10,001+ employees
Instead of fixing each vulnerability reported independently, you can group them and fix them in a single point in the source code, resolving several vulnerabilities at once.
Management Of Quality Managers at a tech vendor with 1,001-5,000 employees
Contrast Security Assess has positively impacted my organization by improving the security features of our application.
Postdoctoral Research Fellow at a program development consultancy with 1-10 employees
It offers confidence by preventing exposure to vulnerabilities and helps ensure that we are not deploying vulnerable code into production.
Site Leader (India) at Industrial Scientific
The best features in Veracode include static analysis and the early detection of vulnerable libraries; it integrates with tools such as Jenkins.
It fixes issues directly in the IDE while you're doing it.
IT App Security Senior Analyst at a transportation company with 10,001+ employees
 

Categories and Ranking

Contrast Security Assess
Ranking in Application Security Tools
17th
Ranking in Static Application Security Testing (SAST)
12th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
15
Ranking in other categories
No ranking in other categories
Veracode
Ranking in Application Security Tools
3rd
Ranking in Static Application Security Testing (SAST)
3rd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Container Security (13th), Software Composition Analysis (SCA) (2nd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (3rd)
 

Mindshare comparison

As of October 2026, in the Application Security Tools category, the mindshare of Contrast Security Assess is 1.7%, up from 0.8% compared to the previous year. The mindshare of Veracode is 4.2%, down from 7.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools Mindshare Distribution
ProductMindshare (%)
Veracode4.2%
Contrast Security Assess1.7%
Other94.1%
Application Security Tools
 

Featured Reviews

Ryan Flake - PeerSpot reviewer
Threat & Vulnerability Management Senior Analyst at a tech vendor with 10,001+ employees
Real-time assessments have improved remediation speed and reduced time spent on authentication issues
I do find that here and there with Contrast Security Assess there are user interface issues, particularly with how they work with libraries. The way that it works is people have access to library data for all applications, not just the applications that they should have access to. However, they are trying to fix that. The way the libraries are handled with Contrast Security Assess could use some work. I know that there is an additional service tier that allows for more in-depth library data. These are small things. Contrast support has been great in fixing any issues or getting back to us with questions. They seem to really be dedicated to the product.
YS
Software Development Engineer II at Rocket Software
Monthly scans have provided baseline security but still miss critical vulnerabilities
Veracode can improve to stand in this market. They do not have to do much; they just need to improve their UI experience and add more documentation within the application rather than just creating documentation pages on different websites. They need to ensure their web application guides whoever uses it. Since whoever uses Veracode must be a technical person, they just need to guide them to the actual points. They can also improve their security capabilities by adding more filters to identify what vulnerabilities their application has. They need to improve their scanning engine to scan for more critical defects. Also, the integration part can be enhanced by adding features to integrate with a CLI, such as introducing a CLI version or a Jenkins plugin. If such features exist, they should show it as a pop-up, signaling that they have a new feature. Currently, it feels Veracode from two years ago is still the same, so that is something Veracode needs to improve. They can improve the security part. Some of the severe security issues were never caught by Veracode in the reports. In fact, I have never seen any high or critical severity issues pop up in my Veracode report. That is one thing they can improve on their scanning ability to catch high severity issues. Next is integration; Veracode does not provide any tools to integrate with Jenkins or CLI. I do not even know if there is any CLI for Veracode that I can use to automate in my pipeline. The last thing is the UI interface that they have, as it is a bit confusing. I remember we did not have the capability to handle authentications of our internal application. We had to write Selenium code using a Selenium IDE. To write a Selenium script for a Veracode scan, you have to download a Selenium IDE, record it, and then paste that file into Veracode. I can see that Selenium IDE is already decommissioned, so it is no longer used by anyone. Still, we have to use it because Veracode only supports that kind of file for Selenium to automate. They can add more ways to authenticate our application using normal JavaScript or Python or Shell script. I feel these are the four main points. They can document it more by adding tooltips into the application that explain why a parameter is required and what other options are available. For the same example with the Selenium script, they can add a link to their documentation that explains what other kinds of scripts can be written for authentication. I feel they can also make the UI more intuitive so that whoever uses it can guide themselves, as whoever uses Veracode is already a technical person.
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
915,287 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
13%
Financial Services Firm
13%
Comms Service Provider
10%
Construction Company
7%
Financial Services Firm
14%
Manufacturing Company
12%
Outsourcing Company
9%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise3
Large Enterprise11
By reviewers
Company SizeCount
Small Business70
Midsize Enterprise46
Large Enterprise114
 

Questions from the Community

What is your experience regarding pricing and costs for Contrast Security Assess?
I was not involved in the negotiation of pricing for Contrast Security Assess, but I am somewhat familiar with setup cost and licensing. Licensing costs are fairly high compared to other DAST and S...
What needs improvement with Contrast Security Assess?
I do find that here and there with Contrast Security Assess there are user interface issues, particularly with how they work with libraries. The way that it works is people have access to library d...
What advice do you have for others considering Contrast Security Assess?
I would give Contrast Security Assess a score of 8 out of 10. That is a small little issue, but it is a great product and I would recommend it to others. There are a couple things that could be imp...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed AppSec platform with strong focus on ease of use, it is SaaS delivery, and provide...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

Contrast Assess
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

Williams-Sonoma, Autodesk, HUAWEI, Chromeriver, RingCentral, Demandware.
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about Contrast Security Assess vs. Veracode and other solutions. Updated: September 2026.
915,287 professionals have used our research since 2012.