Try our new research platform with insights from 80,000+ expert users
Uzma Noreen - PeerSpot reviewer
Head of Infrastructure & Compliance & Cloud at TEO
Real User
Top 20
Offers continuous code analysis which can improve the code quality
Pros and Cons
  • "The solution provides continuous code analysis which has improved the quality of our code. It can raise alarms on vulnerabilities with immediate reports on the dashboard. Few things are false positives and we can customize the rules."
  • "The solution needs to improve its customization and flexibility."

What is most valuable?

The solution provides continuous code analysis which has improved the quality of our code. It can raise alarms on vulnerabilities with immediate reports on the dashboard. Few things are false positives and we can customize the rules. 

What needs improvement?

The solution needs to improve its customization and flexibility. 

For how long have I used the solution?

I have been using the solution for ten days. 

What do I think about the stability of the solution?

I would rate the product's stability an eight out of ten. 

Buyer's Guide
SonarQube Cloud (formerly SonarCloud)
January 2025
Learn what your peers think about SonarQube Cloud (formerly SonarCloud). Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
838,713 professionals have used our research since 2012.

How are customer service and support?

We have received instant replies from the support but not actual answers. We contacted support regarding upgrading the edition.  

How was the initial setup?

The tool's setup is not complex. Our engineers were not experienced and they took time to implement the product. 

What other advice do I have?

The tool is simple and I would rate it an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
GHASSAN ODETALLAH - PeerSpot reviewer
Head of Quality Engineers/Automation Architect at a tech company with 201-500 employees
Real User
Quick deployment, scales well, and accurate reports
Pros and Cons
  • "The reports from SonarCloud are very good."
  • "We had some issues with the scanner."

What is our primary use case?

We use SonarCloud tools for all our 20 repositories and we are connecting the SonarCloud, from the Bitbucket pipeline.

What is most valuable?

The reports from SonarCloud are very good.

What needs improvement?

We had some issues with the scanner.

For how long have I used the solution?

I have been using SonarCloud for approximately three weeks.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

SonarCloud is scalable.

We plan to increase our package to the enterprise edition and decrease the lines of code in the future.

How are customer service and support?

We have not needed the support at this time.

Which solution did I use previously and why did I switch?

We previously used Codacy. We switch to SonarCloud because of their good reputation and we compared reports from both of them. SonarCloud seems to be more accurate. However, Codacy has a simpler installation. SonarCloud has more steps involved.

How was the initial setup?

The solution is straightforward to implement. Some of the implementations can be quick.

The installation of the framwork was a bit difficult, it could be improved.

What's my experience with pricing, setup cost, and licensing?

The price of SonarCloud could be less expensive. We are using the community version and the price should be more reasonable.

We have purchased a license for 2 million lines of code. However, we have 10 million lines of code but it would be too costly for us to have a license for all the amount.

What other advice do I have?

I would recommend SonarCloud to others.

I rate SonarCloud a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
SonarQube Cloud (formerly SonarCloud)
January 2025
Learn what your peers think about SonarQube Cloud (formerly SonarCloud). Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
838,713 professionals have used our research since 2012.
Senior Security Consultant at Tafhar IT Services
Consultant
Well priced, good for basic needs, but is too limited
Pros and Cons
  • "For what it is meant to do, it works pretty well."
  • "I've been told by the developers that the solution is too limited. It's not testing enough within the containers."

What is our primary use case?

The solution is a static code analysis tool. That's basically what we use it for in our organization.

What is most valuable?

We bought the solution due to the fact that it was the lowest price. 

For what it is meant to do, it works pretty well. 

It's good for analysis.

What needs improvement?

I've been told by the developers that the solution is too limited. It's not testing enough within the containers. For instance, it only checks for obvious code errors. They should work to improve this.

At that moment we needed to scan the codes that the developers are producing, we found out that we needed more features.

For how long have I used the solution?

I've been using the solution for six months or so now. It's been less than a year.

Which solution did I use previously and why did I switch?

The former product we used was Twistlock.

How was the initial setup?

I haven't had much experience with the initial setup. I can't speak to what the deployment or setup was like.

What's my experience with pricing, setup cost, and licensing?

The pricing is very good.

Which other solutions did I evaluate?

We're currently looking into other options.

We're either looking for an integrated product for the whole CICB pipeline, such as StackRox, or we're looking at Fishman from Palo Alto. We're also looking at individual products for the whole CICB pipeline. In fact, this afternoon we are having a meeting to further discuss what tools we will use, or what can we use for dependency decks in the whole CICB pipeline, and for us to get a container image.

What other advice do I have?

We're a customer and an end-user of the product. We don't have a business relationship with them. 

I'm not sure which version of the solution we're using.

I'd advise potential users to first check all the features to see if what they need is there and then check them off to ensure that SonarCloud fills all your needs.

It's a good product for its purpose.

I'd rate the solution at a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2356089 - PeerSpot reviewer
CEO at a computer software company with 1-10 employees
Real User
Integration is simple and effective, but detection capabilities need enhancement
Pros and Cons
  • "I find SonarQube Cloud very easy to use and simple to integrate initially."
  • "I find SonarQube Cloud very easy to use and simple to integrate initially."
  • "SonarQube Cloud could improve its vulnerability detection compared to Veracode."
  • "SonarQube Cloud could improve its vulnerability detection compared to Veracode. Additionally, it has fewer capabilities, which prompted us to use Veracode."

What is our primary use case?

We mainly use SonarQube Cloud for code analysis, specifically static code analysis.

What is most valuable?

I find SonarQube Cloud very easy to use and simple to integrate initially. Our development teams find it very easy to integrate into their workflow. New team members immediately know how to use it. 

What needs improvement?

SonarQube Cloud could improve its vulnerability detection compared to Veracode. Additionally, it has fewer capabilities, which prompted us to use Veracode.

For how long have I used the solution?

We have been using SonarQube Cloud for about two to three years.

What do I think about the stability of the solution?

I find SonarQube Cloud to be relatively stable. From my team's feedback, it is almost an eight out of ten.

What do I think about the scalability of the solution?

I am uncertain about SonarQube Cloud's scalability. There are limitations, and it seems to have fewer capabilities than Veracode, which is why we also use Veracode.

How are customer service and support?

I did not have much interaction with customer support. When I did contact them, the experience was very good, however, I didn't have any technical questions.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I am mainly focusing on Veracode, and we also use SonarQube Cloud. In contrast, I find Veracode to be more complex. Veracode is considered to have better detection capabilities than SonarQube Cloud.

How was the initial setup?

SonarQube Cloud was much easier to install compared to Veracode. One person is enough to handle the installation.

What was our ROI?

I have not done any ROI calculations on SonarQube Cloud.

What's my experience with pricing, setup cost, and licensing?

From what I understand, SonarQube Cloud is roughly equivalent in cost to Veracode, maybe a little cheaper.

What other advice do I have?

I rate SonarQube Cloud as a whole solution about seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free SonarQube Cloud (formerly SonarCloud) Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free SonarQube Cloud (formerly SonarCloud) Report and get advice and tips from experienced pros sharing their opinions.