No more typing reviews! Try our Samantha, our new voice AI agent.

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

SonarQube provides extensive support for multiple programming languages, improving code quality across diverse tech stacks.
SonarQube excels in detecting and addressing security vulnerabilities and code smells within the development process.
The seamless integration of SonarQube into CI/CD pipelines significantly enhances the software delivery process.
SonarQube helps reduce technical debt and ensures that software is more secure and of higher quality before reaching production.
SonarQube's ability to provide comprehensive static code analysis makes it a valuable tool in maintaining high coding standards and practices.

CONS

SonarQube's support for additional languages and the ease of adding new detection rules need enhancement.
SonarQube retains some vulnerabilities and security issues, requiring improvement in identifying and addressing these problems.
SonarQube's documentation and customization support need significant updates, with users facing challenges related to these areas.
SonarQube's pricing is considered high, making its affordability an area of concern for users.
SonarQube struggles with performance issues, especially when analyzing large code bases, indicating a need for better optimization.
 

SonarQube Pros review quotes

Vitthal Gole - PeerSpot reviewer
Devops Engineer at AIQOD
Jul 14, 2026
A specific outcome I can share is that after integrating SonarQube into our CI/CD pipeline, we reduced production bugs by 30 to 40 percent and improved code coverage from 65 to 85 percent by enforcing the Quality Gate, along with a 25 percent reduction in technical debt over the last six to seven months post-implementation.
Sathyamurthi Natarajan - PeerSpot reviewer
IT Officer (Solution Architect) at World Bank
Sep 8, 2025
The ability to tailor metrics tracking with SonarQube Server (formerly SonarQube) has been beneficial to my team and stakeholders as we are able to get portfolio reports and project-wise reports, though there are areas for improvement.
AG
Sales Finance at Hero FinCorp Limited
Jul 10, 2026
The strong side of SonarQube is that it has both CLI-based channels and is user-friendly for testers, allowing them to scan code locally, and now they have the capability of software composition analysis, which is a win-win situation and a great advantage because under one umbrella, you can get multiple scanning capabilities.
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
906,829 professionals have used our research since 2012.
KH
Sr Software Engineering Supervisor at Mozarc Medical
May 27, 2025
Overall, I would rate SonarQube Server (formerly SonarQube) as a 9 out of 10.
Sthembiso Zondi - PeerSpot reviewer
Head of Software Engineering at ronaldmariah@gmail.com
May 27, 2025
SonarQube Server (formerly SonarQube) is very stable.
Archana Verma - PeerSpot reviewer
Security Analyst at Dover Corporation
Feb 24, 2025
I find SonarQube Cloud to be very user-friendly with an easy-to-use interface.
SK
DevOps Lead at CODVO
Aug 14, 2025
When we push our code to the repo, while in continuous integration, it will run a few tests and based on the vulnerability data set it has, it can track the vulnerabilities, indicate the code line where the issue exists, and show how much code is covered by all the unit tests, integration tests, and those sorts of things.
Angelo Quaglia - PeerSpot reviewer
Independent Professional at Studio Dott. Ing. Angelo Quaglia
Mar 27, 2026
The integration with Atlassian Jira is very useful and it works very well.
RG
Architect at sigpsc inc
Apr 9, 2025
It is the best product we use for easy integration into YAML pipelines for scanning.
reviewer2356089 - PeerSpot reviewer
CEO at a computer software company with 1-10 employees
Feb 18, 2025
I find SonarQube Cloud very easy to use and simple to integrate initially.
 

SonarQube Cons review quotes

Vitthal Gole - PeerSpot reviewer
Devops Engineer at AIQOD
Jul 14, 2026
SonarQube could improve by reducing false positives in its static code analysis; while its detection capabilities are strong, some findings require manual verification, increasing developers' workload.
Sathyamurthi Natarajan - PeerSpot reviewer
IT Officer (Solution Architect) at World Bank
Sep 8, 2025
SonarQube Server (formerly SonarQube) could be improved on the reporting front. Instead of grouping, I would prefer to scan the code as part of development and then generate a report on a daily basis among different units or projects, which is currently complicated.
AG
Sales Finance at Hero FinCorp Limited
Jul 10, 2026
SonarQube does not have robust or strong rules because I have seen some other products able to identify specific vulnerabilities in the code base that SonarQube is unable to identify.
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
906,829 professionals have used our research since 2012.
KH
Sr Software Engineering Supervisor at Mozarc Medical
May 27, 2025
I see a problem with SonarQube Server (formerly SonarQube) because the vulnerability assessment is continuous; if I fix some vulnerabilities today, they reappear in the next scan, and there will be completely different issues that need to be fixed.
Sthembiso Zondi - PeerSpot reviewer
Head of Software Engineering at ronaldmariah@gmail.com
May 27, 2025
I think SonarQube Server (formerly SonarQube) should improve by integrating a new feature that includes AI. As soon as I see that they've got a new feature that integrates AI that is not as generative as other GenAI platforms that actually generate the code and help developers develop faster, I believe that capability is lacking.
Archana Verma - PeerSpot reviewer
Security Analyst at Dover Corporation
Feb 24, 2025
The UI can be improved.
SK
DevOps Lead at CODVO
Aug 14, 2025
Since most of our projects are open source, there are multiple features which can be improved.
Angelo Quaglia - PeerSpot reviewer
Independent Professional at Studio Dott. Ing. Angelo Quaglia
Mar 27, 2026
However, there could be an improvement in providing additional training resources.
RG
Architect at sigpsc inc
Apr 9, 2025
I need a solution that can bring together three key areas: vulnerabilities, static scanning, and misarchitecture. Currently, to achieve our expectations, we have to use more than one product, as some products excel at scanning for vulnerabilities but are poor at checking code quality.
reviewer2356089 - PeerSpot reviewer
CEO at a computer software company with 1-10 employees
Feb 18, 2025
SonarQube Cloud could improve its vulnerability detection compared to Veracode. Additionally, it has fewer capabilities, which prompted us to use Veracode.