No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1310136 - PeerSpot reviewer
Founder & CEO at a healthcare company with 1-10 employees
Real User
Leaderboard
Feb 22, 2021
Valuable wide-spread features, stable, scalable, easy to install and deploy, with amazing technical support
Pros and Cons
  • "The features are so extensive, which is why they are ahead of the game, and the reason I continue to use this solution."
  • "They put together a complete solution that has a number of components."
  • "The only area of this solution that needs improvement is the pricing for startups."
  • "The only area of this solution that needs improvement is the pricing for startups."

What is our primary use case?

We use Veracode Security Labs along with Veracode Developer Training and other Veracode components in our company for Digitial Health, and security testing.

How has it helped my organization?

Veracode and all of its components have helped us in developing a secure product.

What is most valuable?

All of the features offered in this solution are valuable.

The features are extensive, which is why they are ahead of the game, and the reason I continue to use this solution.

What needs improvement?

The only area of this solution that needs improvement is the pricing for startups.

Buyer's Guide
Veracode Security Labs
March 2026
Learn what your peers think about Veracode Security Labs. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
886,932 professionals have used our research since 2012.

For how long have I used the solution?

I have been working with Veracode for several years.

What do I think about the stability of the solution?

It's a stable solution. We have no issues with stability.

What do I think about the scalability of the solution?

It's a scalable product.

How are customer service and support?

The technical support is amazing! They are very responsive.

Which solution did I use previously and why did I switch?

We also use Veracode Developer Training, Manual Penetration Testing, Static Analysis for the same use case.

How was the initial setup?

The initial setup is straightforward and extremely easy to install.

Deployment only took a few hours.

What about the implementation team?

We have a team in-house.

What's my experience with pricing, setup cost, and licensing?

The pricing for qualified startups should only charge for Veracode Developer Training.

The licensing cost should be fair, and the use cost when the company or the clients release their product to the market should also be fair.

What other advice do I have?

They put together a complete solution that has a number of components. My advice is to take it all. Don't just take just Developer Training or Security Labs or Static Analysis. Rather, take the whole solution and run with it.

Veracode cannot be taught about security. I would rate Veracode Security Labs a ten out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
CristobalRodriguez - PeerSpot reviewer
Principal Information Security Engineer at Sabre
Real User
Jan 20, 2021
Good coding challenges, but it needs better auto-completion in the IDE
Pros and Cons
  • "The coding challenges were well put together and I was happy to see some of the challenges even had a built-in web browser."
  • "The coding challenges were well put together and I was happy to see some of the challenges even had a built-in web browser."
  • "I would have liked to see a bit better auto-completion in the IDE, and there was a typo in one of the questions where the code you were supposed to copy was missing a pair of parentheses."
  • "I would have liked to see a bit better auto-completion in the IDE, and there was a typo in one of the questions where the code you were supposed to copy was missing a pair of parentheses."

What is our primary use case?

We use this eLearning product for our developers. We are working on adding it to our enterprise eLearning solution to help get developers to take it.

How has it helped my organization?

We use Veracode Security Labs as our primary security learning platform. It was pretty cool to use for the first time.

What is most valuable?

The coding challenges were well put together and I was happy to see some of the challenges even had a built-in web browser. That made them very convenient.

What needs improvement?

I would have liked to see a bit better auto-completion in the IDE, and there was a typo in one of the questions where the code you were supposed to copy was missing a pair of parentheses. I'm sure the typo messed up a lot of people. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Fletcher - PeerSpot reviewer
FletcherDirector, Developer Enablement at a computer software company with 501-1,000 employees
Vendor

Hi there, PM for Security Labs here. If you haven't already, please reach out to support@veracode.com about the IDE autocompletion and lab typo, so that we can gather some more details and follow up to make sure those are fixed + improved. Thank you for the review!

Buyer's Guide
Veracode Security Labs
March 2026
Learn what your peers think about Veracode Security Labs. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
886,932 professionals have used our research since 2012.
reviewer1345386 - PeerSpot reviewer
Senior Software Developer at a pharma/biotech company with 201-500 employees
Real User
Dec 9, 2020
Produces reliable software scans but overall database scanning needs to be improved
Pros and Cons
  • "The deployment didn't take that long."
  • "Mainly it's just quality, the level of comfort that we have now just from using the product, just knowing, having another set of eyes, gives you a comfort level."
  • "Its ability to handle more types of files and making it work better with databasing and other API could be improved."
  • "The database portion of it where it's loading and analyzing seemed to be a little more laborious compared to the Java stuff which was easier to use and more streamlined."

What is our primary use case?

I have used it and looked at it from the perspective of its analysis, if you will, of database files, SQL, MCL SQL. I also looked at other components, Java and such, but not as in-depth. Personally, I think it was a little difficult trying to get it to profile those particular files to get them loaded in; however, it was honestly probably user error — just my misunderstanding of how to use the software more than anything else which is why it took a little longer. The Java stuff was a lot more streamlined. The database stuff was not as robust.

We used this solution to identify vulnerabilities. Essentially, load stuff up, find out what it finds. The next step is (assuming we have enough people to fix the higher priority ones) to look at some of the tips or remediation. Generally, just to find out what's wrong.

We're a smaller company, we had roughly 10 people or less using this solution. I don't think anyone is actively using it as much now because of project work, etc.

I am not familiar with how many other people are using it currently. Probably not many because the project work is different. Previously, there were more business needs for us to build more software but things have changed a little bit in the company. That requirement is different now from a corporate perspective.

How has it helped my organization?

Mainly it's just quality. The level of comfort that we have now just from using the product. Again, there may be some other people at the company that had used it a lot more than me but just knowing, having another set of eyes, gives you a comfort level. 

What needs improvement?

The database portion of it where it's loading and analyzing. That seemed to be a little more laborious compared to the Java stuff which was easier to use and more streamlined.

Its ability to handle more types of files and making it work better with databasing and other API could be improved. That would be really nice.

What do I think about the stability of the solution?

It seemed generally stable. The database stuff didn't seem to be working as well, as fast. It wasn't as responsive. In other words, we'd load something up and then we find out that it loaded everything but there were zero results that it found when it did the analysis. We tried it again and we got the same thing.

What do I think about the scalability of the solution?

It seemed like it could handle volumes. It was pretty fast, too.

How are customer service and technical support?

When the person I referenced earlier needed help, it seemed like he was able to get the help he needed — they were pretty responsive. He didn't mention that there were any issues with technical support.

Which solution did I use previously and why did I switch?

No, I don't think we did. We had looked at the reviews and started using Veracode.

How was the initial setup?

I wasn't that involved in the initial setup of it — the bootstrapping and getting it all ready on the cloud. That being said, setting up a profile for it to do its thing was pretty easy to do. That was pretty straightforward.

The deployment didn't take that long. I don't think it took the guy very long to do it. There was probably some stuff that was done before I started using it. I'm not familiar with what was done but I don't think it was much more than just getting a trial account and such. 

What about the implementation team?

I don't recall who deployed it, but one person can look after deployment and maintenance. The CIO looked after it — he was a "Jack of all trades" type.

What other advice do I have?

If you're interested in using this solution, you should take advantage of the trial and throw some real-life example code at it and try to figure out how you're going to deal with that. Once you get the results back, just do a trial.

On a scale from one to ten, I would give this solution a rating of seven.

It's hard to really put a number on it but it's just mainly because of my experience with the databasing analysis. Databasing is so prevalent and so important, the security of that, it shouldn't be as hard as it seemed to be when we were trying to analyze SQL code as it was, compared to the Java stuff.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Veracode Security Labs Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Veracode Security Labs Report and get advice and tips from experienced pros sharing their opinions.