Try our new research platform with insights from 80,000+ expert users
SonarQube Cloud (formerly SonarCloud) Logo

SonarQube Cloud (formerly SonarCloud) pros and cons

Vendor: Sonar
4.1 out of 5

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

SonarQube Cloud (formerly SonarCloud) effectively discovers vulnerabilities, security weak points, and security hotspots, allowing developers to address issues before production.
It offers continuous code analysis, improving code quality by raising alarms on vulnerabilities with immediate dashboard reports.
The dashboard provides a unified view of code quality metrics such as code duplication, unit test coverage, and security hotspots.
Recently introduced support for mono reports and microservices offers a more detailed view of each service.
SonarQube Cloud is beneficial for easy integration into YAML pipelines for scanning.

CONS

Developers find SonarQube Cloud to be limited in container testing.
There are issues with the scanner and false positives require manual intervention.
More customization and flexibility in reports and notifications are needed.
Improvements are needed in vulnerability detection and reporting features.
Enhancing the configuration process and build time optimization documentation would be beneficial.
 

SonarQube Cloud (formerly SonarCloud) Pros review quotes

reviewer1992327 - PeerSpot reviewer
Dec 11, 2023
SonarCloud is overall a good tool for identifying code smells, bugs, and code duplication, but we've found that using Android Lint is more effective for our needs.
Huzaifa Asif - PeerSpot reviewer
Dec 12, 2023
Recently, they introduced support for mono reports and microservices, which is a noteworthy development as it provides a more detailed view of each service.
reviewer1871532 - PeerSpot reviewer
May 29, 2022
I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is.
Learn what your peers think about SonarQube Cloud (formerly SonarCloud). Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
847,862 professionals have used our research since 2012.
SenthuranPooranananthan - PeerSpot reviewer
Apr 25, 2022
The most valuable features of SonarCloud are the ability to discover vulnerabilities, security weak points, security hotspots, and all the feedback that comes into the feature branch. You can deploy the code with the security, you can eliminate the problem at the developer level rather than identifying the problem in the productions.
Diego Moreo - PeerSpot reviewer
Oct 7, 2024
The SaaS solution for checking code without execution and dealing with security issues is valuable.
Archana Verma - PeerSpot reviewer
Feb 24, 2025
I find SonarQube Cloud to be very user-friendly with an easy-to-use interface.
HT
Jun 24, 2021
For what it is meant to do, it works pretty well.
RG
Apr 9, 2025
It is the best product we use for easy integration into YAML pipelines for scanning.
reviewer2356089 - PeerSpot reviewer
Feb 18, 2025
I find SonarQube Cloud very easy to use and simple to integrate initially.
Rashedul Khan - PeerSpot reviewer
Mar 10, 2023
The most valuable feature of SonarCloud is its overall performance.
 

SonarQube Cloud (formerly SonarCloud) Cons review quotes

reviewer1992327 - PeerSpot reviewer
Dec 11, 2023
The documentation needs improvement on optimizing build time for seamless CI/CD integration with our Android apps.
Huzaifa Asif - PeerSpot reviewer
Dec 12, 2023
There's room for improvement in the configuration process, particularly during the initial setup phase.
reviewer1871532 - PeerSpot reviewer
May 29, 2022
CI/CD pipeline is part of a whole chain of design, development, and production, and it's becoming increasingly crucial to optimize the various tools across different stages. However, it's still a silo approach because the full integration is missing. This isn't just an issue with SonarCloud. It's a general problem with tooling.
Learn what your peers think about SonarQube Cloud (formerly SonarCloud). Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
847,862 professionals have used our research since 2012.
SenthuranPooranananthan - PeerSpot reviewer
Apr 25, 2022
SonarCloud can improve the false positives. Sometimes the gates sometimes act a little weird. We then need to manually go and mark the false positive.
Diego Moreo - PeerSpot reviewer
Oct 7, 2024
Reporting features are missing in SonarCloud.
Archana Verma - PeerSpot reviewer
Feb 24, 2025
The UI can be improved.
HT
Jun 24, 2021
I've been told by the developers that the solution is too limited. It's not testing enough within the containers.
RG
Apr 9, 2025
I need a solution that can bring together three key areas: vulnerabilities, static scanning, and misarchitecture. Currently, to achieve our expectations, we have to use more than one product, as some products excel at scanning for vulnerabilities but are poor at checking code quality.
reviewer2356089 - PeerSpot reviewer
Feb 18, 2025
SonarQube Cloud could improve its vulnerability detection compared to Veracode.
Rashedul Khan - PeerSpot reviewer
Mar 10, 2023
The reports could improve by providing more information. We are not able to use the reports in our operation until they are improved. Additionally, if the vendor provided more customization capabilities it would be a benefit.