Scanning for code security vulnerabilities within our company's products.
DevOps Release Engineer at a tech services company with 51-200 employees
Makes us aware of any potential code security vulnerabilities in our products
Pros and Cons
- "Informs me of code security vulnerabilities. Bamboo build automation with Veracode API calls are used."
- "The user interface could be more sleek. Some scanning requirements aren't flexible. Some features take some time for new users to understand (like what exactly "modules" are)."
What is our primary use case?
How has it helped my organization?
Made our company aware of any potential code security vulnerabilities. Also, customers can use our products knowing they are verified by top organizations as safe.
What is most valuable?
Informing me of application security vulnerabilities. Bamboo build-automation with Veracode API calls are used.
What needs improvement?
- The user interface could be more sleek.
- Some scanning requirements aren't flexible.
- Some features take some time for new users to understand (like what exactly "modules" are).
Buyer's Guide
Veracode
January 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,340 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No issues with stability.
What do I think about the scalability of the solution?
No issues with scalability.
How are customer service and support?
Great.
How was the initial setup?
Somewhat straightforward. There was a little confusion about "missing modules" that are third-party files that we couldn't upload because we don't actually have them. That really confused us, but the technical support resolved the confusion.
What was our ROI?
I can't report on any cost savings relating to code fixes since implementing Veracode in our development process, but it makes us feel more confident about our code, which is awesome.
What's my experience with pricing, setup cost, and licensing?
We are satisfied.
Which other solutions did I evaluate?
None. We might look into Checkmarx.
What other advice do I have?
I am very likely to recommend Veracode to colleagues. Veracode is great.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
General Manager - Application Security at a tech consulting company with 51-200 employees
Needs to improve service levels and capabilities versus competitors. Provides a wide range of platforms and technology assessments.
Pros and Cons
- "Wide range of platforms and technology assessments."
- "It needs to reach the level of Checkmarx's and Fortify Software's capabilities and service levels, or may further loosen the market share."
How has it helped my organization?
PoC is in progress.
What is most valuable?
- Application testing
- False positives challenges
- Wide range of platforms and technology assessments
What needs improvement?
It needs to reach the level of Checkmarx's and Fortify Software's capabilities and service levels, or may further loosen the market share.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
Customer Service:
A three out of 10.
Technical Support:
A two out of 10.
Which solution did I use previously and why did I switch?
Quality levels, service offerings, pricing, and mainly the features and abundance of technologies provided by others made us switch to a different solution.
What about the implementation team?
In-house.
What's my experience with pricing, setup cost, and licensing?
The pricing is pretty high.
Which other solutions did I evaluate?
Yes. Checkmarx, SonarQube and Fortify Software.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Container Security Software Composition Analysis (SCA) Penetration Testing Services Static Code Analysis Application Security Posture Management (ASPM)Popular Comparisons
SonarQube Server (formerly SonarQube)
GitLab
Snyk
Checkmarx One
Mend.io
Fortify on Demand
CrowdStrike Falcon Cloud Security
Sonatype Lifecycle
Acunetix
GitHub Advanced Security
PortSwigger Burp Suite Professional
HCL AppScan
Qualys Web Application Scanning
GitHub
Klocwork
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Which gives you more for your money - SonarQube or Veracode?
- Checkmarx or Veracode. Which should we choose?
- Would you recommend Veracode? What are some of your use cases?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- What do I scan when changing code in Veracode?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?