Try our new research platform with insights from 80,000+ expert users

Parasoft SOAtest vs SonarQube Server (formerly SonarQube) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 30, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Parasoft SOAtest
Ranking in Static Application Security Testing (SAST)
31st
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
30
Ranking in other categories
Functional Testing Tools (21st), API Testing Tools (9th), Test Automation Tools (23rd)
SonarQube Server (formerly ...
Ranking in Static Application Security Testing (SAST)
1st
Average Rating
8.0
Reviews Sentiment
7.5
Number of Reviews
113
Ranking in other categories
Application Security Tools (1st), Software Development Analytics (1st)
 

Mindshare comparison

As of January 2025, in the Static Application Security Testing (SAST) category, the mindshare of Parasoft SOAtest is 0.5%, down from 0.5% compared to the previous year. The mindshare of SonarQube Server (formerly SonarQube) is 28.4%, down from 28.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
 

Featured Reviews

Ujjwal Gupta - PeerSpot reviewer
Easy to use and understand with multiple types of testing on offer
It is very easy to understand. We can do a lot with it. Since this is a commercial tool, we can have more functionality in place. It covers more things like ADI and APIs, et cetera. Everything is in one place, right there, so you don't need to go anywhere. With one single tool, you have everything you need. You can even test the UI as well. The initial setup is very easy. There is nice functionality under the Service Virtualization feature. The solution is stable. Technical support is helpful. This product easily scales. Parasoft actually provides very extensive coverage. For example, in SAP applications, we have various EDIs, and integrated development. That also is supported by Parasoft. In the market, we don't have many of the tools there to test those things. It's nice to be able to with this product.
Wang Dayong - PeerSpot reviewer
Easy to integrate and has a plug-in that supports both C and C++ languages
The product provides false reports sometimes. It also fails to understand the context of the code. It reports that a line of code has issues without considering its relation with the previous line. The product should improve the report quality. While it asks us to improve the code quality, it would be good if it also suggests how to improve the quality.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"If you want something that’s not provided out of the box, then you can write it yourself and integrate it with SOAtest."
"We do a lot of web services testing and REST services testing. That is the focus of this product."
"Since the solution has both command line and automation options, it generates good reports."
"Technical support is helpful."
"Parasoft SOAtest has improved the quality of our automated web services, which can be easily implemented through service chaining and service virtualization."
"The solution is scalable."
"The testing time is shortened because we generate test data automatically with SOAtest."
"Good write and read files which save execution inputs and outputs and can be stored locally."
"It is an easy tool that you can deploy and configure. After that you can measure the history of your obligation and integrate it with other tools like GitLab or GitHub or Azure DevOps to do quality code analysis."
"SonarQube is designed well making it easy to use, simple to identify issues and find solutions to problems."
"It provides the security that is required from a solution for financial businesses."
"The stability is good."
"I like the by-default policies that are they, as they seem to cover most of what I need."
"We use this solution for qualitative coding. We make use of the SonarLint plugin as well as the dashboard."
"One of the most valuable features of SonarQube is its ability to detect code quality during development. There are rules that define various technologies—Java, C#, Python, everything—and these rules declare the coding standards and code quality. With SonarQube, everything is detectable during the time of development and continuous integration, which is an advantage. SonarQube also has a Quality Gate, where the code should reach 85%. Below that, the code cannot be promoted to a further environment, it should be in a development environment only. So the checks are there, and SonarQube will provide that increase. It also provides suggestions on how the code can be fixed and methods of going about this, without allowing hackers to exploit the code. Another valuable feature is that it is tightly integrated with third-party tools. For example, we can see the SonarQube metrics in Bitbucket, the code repository. Once I raise the full request, the developer, team lead, or even the delivery lead can see the code quality metrics of the deliverable so that they can make a decision. SonarQube will also cover all of the top OWASP vulnerabilities, however it doesn't have penetration testing or hacker testing. We use other tools, like Checkmarx, to do penetration testing from the outside."
"The SonarQube dashboard looks great."
 

Cons

"The product is very slow to start up, and that is a bit of a problem, actually."
"Tuning the tool takes time because it gives quite a long list of warnings."
"The summary reports could be improved."
"The performance could be a bit better."
"From an automation point of view, it should have better clarity and be more user friendly."
"Reporting facilities can be better."
"The feedback that we received from the DevOps of our organization was that the tool was a little heavy from the transformation perspective."
"UI testing should be more in-depth."
"I don't believe you can have metrics of code quality based upon code analysis. I don't think it's possible for a computer to do it."
"We called support and complained but have not received any information as we use the free version. We had to fix it on our own and could not escalate it to the tool's developer."
"We have tens of millions of code to be analyzed and processed. There can be some performance degradation if we are applying Sonar Link to large code or code that is complex. When the code had to be analyzed is when we ran into the main issues. There were several routines involved to solve those performance issues but this process should be improved."
"I would like to see SonarQube implement a good amount of improvements to the product's security features. Another aspect of SonarQube that could be improved is the search functionality."
"For improvement, this solution could be offered on Docker and the cloud and the support for this solution could be improved. Customizing rules could also be made simpler."
"The product's pricing could be lower."
"It should be user-friendly."
"SonarQube could improve by adding automatic creation of tasks after scanning and more support for the Czech language."
 

Pricing and Cost Advice

"The cost of Parasoft seems to have gotten higher with a projection that wasn't really stipulated for our company. They've done a tremendous job at negotiating those deals."
"The license price is a little expensive, but it provides a better outcome in terms of the end-to-end automation process."
"It is an expensive product, so think carefully about whether it fits your purposes and is the right tool for you."
"I think it would be a great step to decrease the price of the licenses."
"They do have a confusing licensing structure."
"The price is around $5,000 USD."
"We are completed satisfied with Parasoft SOAtest. The ROI is more than 95%."
"From what I understand, Parasoft SOAtest isn't the cheapest option. But it has a lot to offer."
"The development license cost is reasonable, and we've had no concerns about SonarQube when it comes to cost."
"We're using an older version because it is the open-source flavor of it and we can continue using it at no cost. We're not paying any licensing at all, which was another factor in choosing this route so that we can learn and grow with it and not be committed to licenses and other similar things. If we choose to get something else, we have to relearn, but we don't have to relicense. Basically, we're paying no license costs."
"It's an open-source product."
"There are many different packages with different pricing options available. We are able to try what we have and if we need extra features we can upgrade the license."
"The price of the solution could be reduced."
"On the pricing side, it's 3,000 Euros for 1 million lines of code."
"The product’s price is lower than Veracode’s price."
"The costs for this application, for the kind of job it does, are pretty decent."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
24%
Manufacturing Company
17%
Computer Software Company
13%
Government
4%
Financial Services Firm
17%
Computer Software Company
15%
Manufacturing Company
13%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Parasoft SOAtest?
Since the solution has both command line and automation options, it generates good reports.
What needs improvement with Parasoft SOAtest?
Tuning the tool takes time because it gives quite a long list of warnings. Going through that is a challenge. It only happens in the initial stage when we are setting up the tool, but it can be imp...
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
 

Also Known As

SOAtest
Sonar
 

Learn More

 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Charter Communications, Sabre, Caesars Entertainment, Charles Schwab, ING, Intel, Northbridge Financial, Capital Services, WoodmenLife
Information Not Available
Find out what your peers are saying about Parasoft SOAtest vs. SonarQube Server (formerly SonarQube) and other solutions. Updated: January 2025.
831,158 professionals have used our research since 2012.