Try our new research platform with insights from 80,000+ expert users

Klocwork vs OpenText Static Application Security Testing comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 28, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.2
Klocwork enhances code quality and compliance, improving efficiency in defect resolution, especially in automotive sectors, despite ROI measurement challenges.
Sentiment score
6.8
OpenText Static Application Security Testing received mixed reviews, praising cost savings and partnerships, but highlighting challenges in quantifying ROI.
The main ROI factors include efficiency and how we meet compliance standards for various automotive requirements.
Manager, Quality, Functional Safety, Cybersecurity Embedded Processing at a manufacturing company with 10,001+ employees
 

Customer Service

Sentiment score
6.8
Klocwork's support is praised for responsiveness, effective problem-solving, and reducing user contact via comprehensive documentation, despite prioritization issues.
Sentiment score
6.7
Generally positive with dedicated teams, though some seek improvements in ticket system and responsiveness for OpenText support.
The issue is not about the knowledge of the support but about the prioritization of the tickets they handle.
Manager, Quality, Functional Safety, Cybersecurity Embedded Processing at a manufacturing company with 10,001+ employees
The customer support team is very responsive, proactive, and engages in conversations to ensure our needs are met.
Application Development Team Lead at Miura Pay
During the initial phase when I did interact with the vendor, the support was satisfactory.
Director - Quality Excellence at a manufacturing company with 501-1,000 employees
The technical support has been good because we always received answers to our questions.
Manager at DTEK
The customer service and support for Fortify Static Code Analyzer are better than those for LoadRunner.
CTO at Marco Technology
 

Scalability Issues

Sentiment score
6.7
Klocwork is scalable, efficient, and integrates well with SAST tools, suitable for teams of all sizes without scalability issues.
Sentiment score
7.8
OpenText SAST is scalable for various project sizes but needs improvement in speed and infrastructure management.
Klocwork supports our scalability needs without issues, even as project volumes increase.
Application Development Team Lead at Miura Pay
The program-to-program enablement is scalable.
Director - Quality Excellence at a manufacturing company with 501-1,000 employees
Fortify Static Code Analyzer integrates well and is scalable.
CTO at Marco Technology
 

Stability Issues

Sentiment score
6.8
Klocwork is reliable and stable, effectively handling large codebases but requires significant computing power and faster updates.
Sentiment score
7.5
OpenText Static Application Security Testing is reliable and stable, with improvements since version 19.10, and benefits from proper training.
Installation is easy, and the solution is stable.
Integration Supervisor Lead at Visteon Corporation
The stability of Fortify Static Code Analyzer is generally good.
CTO at Marco Technology
I would rate the product stability as an eight.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
 

Room For Improvement

Klocwork needs improved language support, flexible reporting, better integration with Agile DevOps, and enhanced static and dynamic analysis.
OpenText SAST faces high costs, complex use, false positives, and needs better integration, language support, and feature enhancements.
We would like Klocwork to connect to Git and notify developers of issues tied to specific commits.
Application Development Team Lead at Miura Pay
Klocwork sometimes provides too many additional warnings which require expertise to manage.
Director - Quality Excellence at a manufacturing company with 501-1,000 employees
There are too many warnings, and it requires expertise to determine the correct category for them.
Integration Supervisor Lead at Visteon Corporation
We are not ready to transfer our code without control to AI instruments.
Manager at DTEK
It would be really helpful to include trending vulnerabilities and how to manage them.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers.
CTO at Marco Technology
 

Setup Cost

Klocwork's flexible pricing models are valued, though opinions vary on cost-effectiveness, catering to diverse organizational needs.
Enterprise users find OpenText Static Application Security Testing's pricing high but consider it economical compared to other major solutions.
It is less expensive than Coverity.
Director - Quality Excellence at a manufacturing company with 501-1,000 employees
Klocwork was competitively priced, making it a cost-effective solution for us.
Application Development Team Lead at Miura Pay
Klocwork's pricing seems attractive, as it uses a per-user license model that does not have a lot of overhead.
Manager, Quality, Functional Safety, Cybersecurity Embedded Processing at a manufacturing company with 10,001+ employees
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs.
CTO at Marco Technology
My experience with the pricing, setup costs, and licensing has been good.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
 

Valuable Features

Klocwork provides efficient static code analysis with strong IDE integration, supporting multiple languages and enhancing code quality and collaboration.
OpenText SAST enhances security by automating vulnerability detection, integrating across tools, and providing detailed remediation and compliance guidance.
The most valuable feature of Klocwork is the static analysis tools, which help identify potential security threats and errors.
Application Development Team Lead at Miura Pay
Its integration with the CI/CD pipeline has helped streamline the software development process.
Manager, Quality, Functional Safety, Cybersecurity Embedded Processing at a manufacturing company with 10,001+ employees
It takes just half a day to set up.
Integration Supervisor Lead at Visteon Corporation
Fortify Static Code Analyzer has the capability of giving fewer false positives compared to other tools.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
The most impactful feature of Fortify Static Code Analyzer in identifying vulnerabilities is the ratio of total number of vulnerabilities to false positives.
Manager at DTEK
The most valuable feature of Fortify Static Code Analyzer is its extensive language support, covering many languages from legacy ones to the newest.
CTO at Marco Technology
 

Categories and Ranking

Klocwork
Ranking in Static Code Analysis
4th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
25
Ranking in other categories
Application Security Tools (17th), Static Application Security Testing (SAST) (16th)
OpenText Static Application...
Ranking in Static Code Analysis
3rd
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
19
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2026, in the Static Code Analysis category, the mindshare of Klocwork is 5.5%, up from 3.4% compared to the previous year. The mindshare of OpenText Static Application Security Testing is 7.4%, down from 10.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Code Analysis Market Share Distribution
ProductMarket Share (%)
Klocwork5.5%
OpenText Static Application Security Testing7.4%
Other87.1%
Static Code Analysis
 

Featured Reviews

KG
Manager, Quality, Functional Safety, Cybersecurity Embedded Processing at a manufacturing company with 10,001+ employees
Experience with compliance improvements and efficiency boosts but static analysis engine shows a need for enhancement
One area for improvement is that when customers use different static analysis tools, they report more issues compared to Klocwork. The static analysis engine of Klocwork has areas that need improvement. Customers using different static analysis tools report more issues than with Klocwork, indicating that Klocwork's engine is not as superior. Klocwork should be able to analyze large codebases efficiently, supporting a desktop version for periodic small delta changes before pushing to the server.
DK
Lead Information Security Analyst at a financial services firm with 10,001+ employees
Focuses on detailed scans to find critical vulnerabilities while ensuring minimal false positives
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less than the current latest version. It would be really helpful to include trending vulnerabilities and how to manage them. While it includes all the OWASP top factors, AI has come into the picture, so those updates should also be considered. I haven't thought much about additional features for improvement since I am using it daily. Most of our work revolves around scanning and providing the results, which sometimes feels like a crunch. However, I believe rule pack updates should be implemented. It feels easy to upgrade to the latest version as well.
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
879,371 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
24%
Computer Software Company
10%
Transportation Company
8%
Comms Service Provider
7%
Financial Services Firm
28%
Computer Software Company
11%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise2
Large Enterprise12
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise3
Large Enterprise11
 

Questions from the Community

What is your experience regarding pricing and costs for Klocwork?
Klocwork's pricing seems attractive, as it uses a per-user license model that does not have a lot of overhead.
What needs improvement with Klocwork?
One area for improvement is that when customers use different static analysis tools, they report more issues compared to Klocwork. The static analysis engine of Klocwork has areas that need improve...
What is your primary use case for Klocwork?
I work on tools such as Klocwork, LDRA, as well as Jira and Confluence, focusing more on the software quality assurance aspect. We use Klocwork for coding and aggregate checks. We use it for static...
What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
My experience with the pricing, setup costs, and licensing has been good. We have the scan machines, and we are planning to request more from Micro Focus now. We have calls every month or every oth...
What needs improvement with Fortify Static Code Analyzer?
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less ...
 

Also Known As

No data available
Fortify Static Code Analysis SAST
 

Overview

 

Sample Customers

ACCESS Co Ltd, Risk-AI, Winbond Electronics, Bristol-Myers Squibb Pharmaceutical Research Institute, University of Southern California, Alebra Technologies, SIMULIA, Risk Management Solutions, Brigham Young University, SRD, HRL
Information Not Available
Find out what your peers are saying about Klocwork vs. OpenText Static Application Security Testing and other solutions. Updated: December 2025.
879,371 professionals have used our research since 2012.