Try our new research platform with insights from 80,000+ expert users

Coverity vs OWASP Zap comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024
 

Categories and Ranking

Coverity
Ranking in Static Application Security Testing (SAST)
4th
Average Rating
7.8
Number of Reviews
41
Ranking in other categories
No ranking in other categories
OWASP Zap
Ranking in Static Application Security Testing (SAST)
7th
Average Rating
7.6
Number of Reviews
37
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of November 2024, in the Static Application Security Testing (SAST) category, the mindshare of Coverity is 8.4%, up from 7.2% compared to the previous year. The mindshare of OWASP Zap is 5.1%, down from 6.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
 

Featured Reviews

Md. Shahriar Hussain - PeerSpot reviewer
May 3, 2024
Offers impressive reporting features with user-friendliness and high scalability
The solution can be easily setup but requires heavy integration due to the multiple types of port and programming languages involved. Comparing the resource requirements of the solution I would say it can be installed effortlessly. I would rate the initial setup an eight out of ten. A professional needs some pre-acquired knowledge to manage Coverity's deployment process, but the local solution partners provide support well enough for trouble-free deployment. The overall deployment process of Coverity took around two and a half hours in our organization. The deployment duration depends upon the operating system and resources including high-end RAM and CPU processors.
AnkithKumar - PeerSpot reviewer
Jun 22, 2022
Great for automating and testing and has tightened our security
I use this solution to test applications; web applications, web APIs, and infrastructure. For the web APIs and applications, I use OWASP Zap for interpreting requests and responses, and to see how the application behaves to resist payloads. This is one of the basic applications for us to automate…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution has improved our code quality and security very well."
"The product has been beneficial in logging functionality, allowing me to categorize vulnerabilities based on severity. This aids in providing updated reports on subsequent scans."
"We were very comfortable with the initial setup."
"The solution effectively identifies bugs in code."
"The tool as it is can be used for code quality improvement."
"It is a scalable solution."
"The most valuable feature is the integration with Jenkins."
"The most valuable feature of Coverity is its interprocedural analysis, which is advantageous because it compares favorably with other tools in terms of security and code analysis."
"ZAP is easy to use. The automated scan is a powerful feature. You can simulate attacks with various parameters. ZAP integrates well with SonarQube."
"The product helps users to scan and fix vulnerabilities in the pipeline."
"The solution is good at reporting the vulnerabilities of the application."
"It's great that we can use it with Portswigger Burp."
"They offer free access to some other tools."
"The stability of the solution is very good."
"The reporting is quite intuitive, which gives you a clear indication of what kind of vulnerability you have that you can drill down on to gather more information."
"The application scanning feature is the most valuable feature."
 

Cons

"The reporting tool integration process is sometimes slow."
"Sometimes, vulnerabilities remain unidentified even after setting up the rules."
"Right now, the Coverity executable is around 1.2GB to download. If they can reduce it to approximately 600 or 700MB, that would be great. If they decrease the executable, it will be much easier to work in an environment like Docker."
"Coverity is far from perfection, and I'm not 100 percent sure it's helping me find what I need to find in my role. We need exactly what we are looking for, i.e. security errors and vulnerabilities. It doesn't seem to be reporting while we are changing our code."
"The solution's user interface and quality gate could be improved."
"It would be great if we could customize the rules to focus on critical issues."
"Zero-day vulnerability identification can be an add-on feature that Coverity can provide."
"Coverity takes a lot of time to dereference null pointers."
"The port scanner is a little too slow.​"
"Sometimes, we get some false positives."
"Deployment is somewhat complicated."
"I prefer Burp Suite to SWASP Zap because of the extensive coverage it offers."
"They stopped their support for a short period. They've recently started to come back again. In the early days, support was much better."
"As security evolves, we would like DevOps built into it. As of now, Zap does not provide this."
"It doesn't run on absolutely every operating system."
"It needs more robust reporting tools."
 

Pricing and Cost Advice

"This is a pretty expensive solution. The overall value of the solution could be improved if the price was reduced. Licensing is done on an annual basis."
"The price is competitive with other solutions."
"Coverity is very expensive."
"I would rate Coverity's pricing as a nine out of ten. It's already very expensive, and it's a problem for us to get more licenses due to the price. The pricing model has some good aspects - for example, a personal license gives access to all languages without code limitations, which is better than some competitors. However, it's still a lot of money for us to spend."
"The pricing is on the expensive side, and we are paying for a couple of items."
"I would rate the tool's pricing a one out of ten."
"The pricing is very reasonable compared to other platforms. It is based on a three year license."
"I would rate the pricing a six out of ten, where one is low, and ten is high price."
"This is an open-source solution and can be used free of charge."
"It's free. It's good for us because we don't know what the extent of our use will be yet. It's good to start with something free and easy to use."
"The solution’s pricing is high."
"This app is completely free and open source. So there is no question about any pricing."
"We have used the freeware version. I believe Zap only has freeware."
"This solution is open source and free."
"As Zap is free and open-source, with tons of features similar to those of commercial solutions, I would definitely recommend trying it out."
"OWASP Zap is free to use."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
32%
Computer Software Company
15%
Financial Services Firm
8%
Government
4%
Computer Software Company
19%
Financial Services Firm
11%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What do you like most about Coverity?
The solution has improved our code quality and security very well.
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What do you like most about OWASP Zap?
The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan websites with automatic scanning, and the website has a web application firewall, i...
 

Comparisons

 

Also Known As

Synopsys Static Analysis
No data available
 

Learn More

 

Overview

 

Sample Customers

SAP, Mega International, Thales Alenia Space
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Find out what your peers are saying about Coverity vs. OWASP Zap and other solutions. Updated: October 2024.
814,649 professionals have used our research since 2012.