No more typing reviews! Try our Samantha, our new voice AI agent.

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

SonarQube aids in the detection and resolution of security vulnerabilities during the development process, ensuring high-quality code before deployment.
It offers extensive support for multiple programming languages, which benefits diverse developer communities.
The integration with continuous integration and development pipelines enhances workflow efficiency and maintains coding standards.
SonarQube is known for its ability to analyze technical debt and improve code quality, leading to fewer bugs and higher efficiency.
Its comprehensive code scanning capabilities allow for the early detection of code smells, vulnerabilities, and hotspots.

CONS

SonarQube needs to improve its security scanning features, including more advanced options and a robust credential scanner.
SonarQube requires better support and documentation, especially for users of the community version.
There are issues with false positives and effective vulnerability detection in SonarQube.
Integration with other tools and platforms, including better support for additional languages, should be enhanced in SonarQube.
Pricing for SonarQube could be more competitive, making it more accessible to organizations of different sizes.
 

SonarQube Pros review quotes

Sathyamurthi Natarajan - PeerSpot reviewer
IT Officer (Solution Architect) at World Bank
Sep 8, 2025
The ability to tailor metrics tracking with SonarQube Server (formerly SonarQube) has been beneficial to my team and stakeholders as we are able to get portfolio reports and project-wise reports, though there are areas for improvement.
KH
Sr Software Engineering Supervisor at Mozarc Medical
May 27, 2025
Overall, I would rate SonarQube Server (formerly SonarQube) as a 9 out of 10.
Sthembiso Zondi - PeerSpot reviewer
Head of Software Engineering at ronaldmariah@gmail.com
May 27, 2025
SonarQube Server (formerly SonarQube) is very stable.
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
899,258 professionals have used our research since 2012.
Archana Verma - PeerSpot reviewer
Security Analyst at Dover Corporation
Feb 24, 2025
I find SonarQube Cloud to be very user-friendly with an easy-to-use interface.
Angelo Quaglia - PeerSpot reviewer
Independent Professional at Studio Dott. Ing. Angelo Quaglia
Mar 27, 2026
The integration with Atlassian Jira is very useful and it works very well.
RG
Architect at sigpsc inc
Apr 9, 2025
It is the best product we use for easy integration into YAML pipelines for scanning.
reviewer2356089 - PeerSpot reviewer
CEO at a computer software company with 1-10 employees
Feb 18, 2025
I find SonarQube Cloud very easy to use and simple to integrate initially.
Diego Moreo - PeerSpot reviewer
Software Quality Coordinator at a retailer with 10,001+ employees
Oct 7, 2024
The SaaS solution for checking code without execution and dealing with security issues is valuable.
MB
Senior Manager Product Engineering at GlobalLogic
Sep 2, 2024
SonarQube's unit test coverage and exhaustive information at the module, project, and overall code repo levels are quite good.
DB
Distinguish Engineer at Gtmhub
Feb 14, 2025
Some of the static code analysis capabilities are the most beneficial.
 

SonarQube Cons review quotes

Sathyamurthi Natarajan - PeerSpot reviewer
IT Officer (Solution Architect) at World Bank
Sep 8, 2025
SonarQube Server (formerly SonarQube) could be improved on the reporting front. Instead of grouping, I would prefer to scan the code as part of development and then generate a report on a daily basis among different units or projects, which is currently complicated.
KH
Sr Software Engineering Supervisor at Mozarc Medical
May 27, 2025
I see a problem with SonarQube Server (formerly SonarQube) because the vulnerability assessment is continuous; if I fix some vulnerabilities today, they reappear in the next scan, and there will be completely different issues that need to be fixed.
Sthembiso Zondi - PeerSpot reviewer
Head of Software Engineering at ronaldmariah@gmail.com
May 27, 2025
I think SonarQube Server (formerly SonarQube) should improve by integrating a new feature that includes AI. As soon as I see that they've got a new feature that integrates AI that is not as generative as other GenAI platforms that actually generate the code and help developers develop faster, I believe that capability is lacking.
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
899,258 professionals have used our research since 2012.
Archana Verma - PeerSpot reviewer
Security Analyst at Dover Corporation
Feb 24, 2025
The UI can be improved.
Angelo Quaglia - PeerSpot reviewer
Independent Professional at Studio Dott. Ing. Angelo Quaglia
Mar 27, 2026
However, there could be an improvement in providing additional training resources.
RG
Architect at sigpsc inc
Apr 9, 2025
I need a solution that can bring together three key areas: vulnerabilities, static scanning, and misarchitecture. Currently, to achieve our expectations, we have to use more than one product, as some products excel at scanning for vulnerabilities but are poor at checking code quality.
reviewer2356089 - PeerSpot reviewer
CEO at a computer software company with 1-10 employees
Feb 18, 2025
SonarQube Cloud could improve its vulnerability detection compared to Veracode. Additionally, it has fewer capabilities, which prompted us to use Veracode.
Diego Moreo - PeerSpot reviewer
Software Quality Coordinator at a retailer with 10,001+ employees
Oct 7, 2024
Reporting features are missing in SonarCloud.
MB
Senior Manager Product Engineering at GlobalLogic
Sep 2, 2024
Depending on the tool's configuration, sometimes you get false alarms that are unimportant to you.
DB
Distinguish Engineer at Gtmhub
Feb 14, 2025
Any suggestions for potential improvements may include bill of materials functionality.