Try our new research platform with insights from 80,000+ expert users
Veracode Logo

Veracode pros and cons

Vendor: Veracode
4.1 out of 5
Badge Ranked 1
4,429 followers
Post review

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Veracode efficiently identifies and manages software vulnerabilities, enhancing security in development phases.
Integrates seamlessly with developer tools and IDEs like Eclipse, Visual Studio, and Jenkins to embed security in the development process.
Offers automated and comprehensive static and dynamic code analysis, enabling continuous security assessment.
Provides valuable e-learning resources, enabling developers to improve secure coding practices.
Supports a broad range of programming languages and frameworks, facilitating comprehensive application security coverage.

CONS

A high number of false positives are reported and this should be reduced.
The cost of Veracode is a little bit expensive and there was a hundred percent increase in cost from last year to this year, which is certainly not justified.
There were some additional manual steps or work involved that should not have been needed.
The documentation is poor and the technical support isn't helpful.
It needs better controls to include/exclude specific sections when creating a report that can be shared externally with customers and prospects.
 

Veracode Pros review quotes

SP
Oct 14, 2021
The static scan is the feature that we use the most, as it gives us insight into our source code. We have it integrated with our continuous integration, continuous delivery system, so we can get insight quickly.
reviewer1705929 - PeerSpot reviewer
Oct 28, 2021
There is a single area on the dashboard where you can get a full view of all of the tests and the results from everything. There is a nice, very simple graphic that shows you the types of vulnerabilities that were found, their severity, the scoring, and in what part of the code they were found. All the details are together in one place.
Robert Hood - PeerSpot reviewer
Jul 31, 2023
The most valuable feature is the SAST capability and its integration into the Veracode pipelines.
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: October 2024.
816,406 professionals have used our research since 2012.
Evan Gertis - PeerSpot reviewer
Sep 14, 2021
The solution's ability to help create secure software is very valuable. We're a zero-trust networking company so we want to have the ability to say that we're practicing security seriously. Having something like Veracode allows us to have confidence when we're speaking to people about our product that we can back up what we're doing with a certification, with a reputable platform, and say, "This is what we're using to scan an application. Here's the number of vulnerabilities that are on an application. And here's the risk that we're accepting."
OK
Oct 18, 2021
Considering that in my project, we are mostly using Software Composition Analysis as a part of Static Code Analysis, for me, the main part is reporting and highlighting necessary vulnerabilities. Veracode platform has a rather good database of different vulnerabilities in different libraries and different sources. So, finding vulnerabilities in third-party libraries is the main feature of Software Composition Analysis that we use. It is the most important feature for us.
Saket Pandey - PeerSpot reviewer
Jun 21, 2023
The recommendations and frequent updates are the most valuable features of Veracode.
MT
Nov 4, 2020
The solution's ability to prevent vulnerable code from going into production is perfectly fine. It delivers, at least for the reports that we have been checking on Java and JavaScript. It has reported things that were helpful.
AB
Dec 20, 2020
Within SCA, there is an extremely valuable feature called vulnerable methods. It is able to determine within a vulnerable library which methods are vulnerable. That is very valuable, because in the vast majority of cases where a library is vulnerable, none of the vulnerable methods are actually used by the code. So, if we want to prioritize the way open source libraries are updated when a library is found vulnerable, then we want to prioritize the libraries which have vulnerable methods used within the code.
SumalyaGuha - PeerSpot reviewer
Jan 9, 2023
In pipeline scanning, there is a configuration that can be set with respect to the security level of the flaw. If there is a high or a critical issue, there's a way the build can be failed and blocked before going into production.
KM
Nov 8, 2020
In terms of secure development, the SAST scan is very useful because we are able to identify security flaws in the code base itself, for the application.
 

Veracode Cons review quotes

SP
Oct 14, 2021
The ideal situation in terms of putting the results in front of the developers would be with Veracode integration into the developer environment (IDE). They do have a plugin, which we've used in the past, but we were not as positive about it.
reviewer1705929 - PeerSpot reviewer
Oct 28, 2021
I would ask Veracode to be a lot more engaged with the customer and set up live sessions where they force the customer to engage with Veracode's technical team. Veracode could show them a repo, how they should do things, this is what these results mean, here is a dashboard, here's the interpretation, here's where you find the results.
Robert Hood - PeerSpot reviewer
Jul 31, 2023
From what we have seen of Veracode's SCA offering, it is just average.
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: October 2024.
816,406 professionals have used our research since 2012.
Evan Gertis - PeerSpot reviewer
Sep 14, 2021
The JIRA integration automation aspect of it could be improved significantly. We want to have a way to create tickets that are going to allow people to work through those flaws that we're finding. We don't want people to feel like they're missing out on something or that they're not following directions in the right way.
OK
Oct 18, 2021
The results of agent-based software composition analysis are not connected to policy scanning. So, for me, the only thing that Veracode can improve in Software Composition Analysis is to connect it with the policy scan because, at present, it is a bit inconvenient for those in our organization who use agent-based Software Composition Analysis. In the end, they need to make a static scan with all those libraries in order to receive that report. If Veracode implemented a connection between agent-based static scan and static scanning itself, it would be great because it would lead to fewer operations in order to prepare release documentation and release reporting from Veracode. We recently had a conversation with Veracode about it.
Saket Pandey - PeerSpot reviewer
Jun 21, 2023
The false positive rates were quite high in our case.
MT
Nov 4, 2020
Veracode has plenty of data. The problem is the information on the dashboards of Veracode, as the user interface is not great. It's not immediately usable. Most of the time, the best way to use it is to just create issues and put them in JIRA... But if I were a startup, and only had products with a good user interface, I wouldn't use Veracode because the UI is very dated.
AB
Dec 20, 2020
Veracode has a few shortcomings in terms of how they handle certain components of the UI. For example, in the case of the false positive, it would be highly desirable if the false positive don't show up again on the UI, instead still showing up for any subsequent scan as a false positive. There is a little bit of cluttering that could be avoided.
SumalyaGuha - PeerSpot reviewer
Jan 9, 2023
Veracode's SAST, DAST, and SCA are pretty good with respect to industry standards, but with regard to container security, they are in either beta or alpha testing. They need to get that particular feature up and running so that they take care of the container security part.
KM
Nov 8, 2020
The feature that allows me to read which mitigation answer was submitted, and to approve it, requires me to use do so in different screens. That makes it a little bit more complicated because I have to read and then I have to go back and make sure it falls under the same number ID number. That part is a little bit complicated from my perspective, because that's what I use the most.