Checkmarx聽vs聽SonarQube

Get Advice Icon

Need advice about which tool to choose?Ask the StackShare community!

Checkmarx
Checkmarx

6
6
+ 1
0
SonarQube
SonarQube

531
258
+ 1
14
Add tool
- No public GitHub repository available -

What is Checkmarx?

It is a provider of state-of-the-art application security solution: static code analysis software, seamlessly integrated into development process.

What is SonarQube?

SonarQube provides an overview of the overall health of your source code and even more importantly, it highlights issues found on new code. With a Quality Gate set on your project, you will simply fix the Leak and start mechanically improving.
Get Advice Icon

Need advice about which tool to choose?Ask the StackShare community!

Why do developers choose Checkmarx?
Why do developers choose SonarQube?
    Be the first to leave a pro
      Be the first to leave a con
        Be the first to leave a con
        Jobs that mention Checkmarx and SonarQube as a desired skillset
        What companies use Checkmarx?
        What companies use SonarQube?

        Sign up to get full access to all the companiesMake informed product decisions

        What tools integrate with Checkmarx?
        What tools integrate with SonarQube?

        Sign up to get full access to all the tool integrationsMake informed product decisions

        What are some alternatives to Checkmarx and SonarQube?
        Veracode
        It seamlessly integrates application security into the software lifecycle, effectively eliminating vulnerabilities during the lowest-cost point in the development/deployment chain, and blocking threats while in production.
        Black Duck
        It is a solution that helps development teams manage risks that come with the use of open source. It gives you complete visibility into open source management, combining sophisticated, multi-factor open source detection capabilities with the Black Duck KnowledgeBase.
        OpenSSL
        It is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols. It is also a general-purpose cryptography library.
        Let's Encrypt
        Let鈥檚聽Encrypt is a free, automated, and open certificate authority brought to you by the non-profit Internet Security Research Group (ISRG).
        Ensighten
        The leading cybersecurity solution providing client-side protection against data loss, journey hijacking and intrusion while enhancing website performance. Assess and monitor privacy risk to protect against malicious JavaScript attacks.
        See all alternatives
        Decisions about Checkmarx and SonarQube
        Ganesa Vijayakumar
        Ganesa Vijayakumar
        Full Stack Coder | Module Lead | 15 upvotes 397.2K views
        SonarQube
        SonarQube
        Codacy
        Codacy
        Docker
        Docker
        Git
        Git
        Apache Maven
        Apache Maven
        Amazon EC2 Container Service
        Amazon EC2 Container Service
        Microsoft Azure
        Microsoft Azure
        Amazon Route 53
        Amazon Route 53
        Elasticsearch
        Elasticsearch
        Solr
        Solr
        Amazon RDS
        Amazon RDS
        Amazon S3
        Amazon S3
        Heroku
        Heroku
        Hibernate
        Hibernate
        MySQL
        MySQL
        Node.js
        Node.js
        Java
        Java
        Bootstrap
        Bootstrap
        jQuery Mobile
        jQuery Mobile
        jQuery UI
        jQuery UI
        jQuery
        jQuery
        JavaScript
        JavaScript
        React Native
        React Native
        React Router
        React Router
        React
        React

        I'm planning to create a web application and also a mobile application to provide a very good shopping experience to the end customers. Shortly, my application will be aggregate the product details from difference sources and giving a clear picture to the user that when and where to buy that product with best in Quality and cost.

        I have planned to develop this in many milestones for adding N number of features and I have picked my first part to complete the core part (aggregate the product details from different sources).

        As per my work experience and knowledge, I have chosen the followings stacks to this mission.

        UI: I would like to develop this application using React, React Router and React Native since I'm a little bit familiar on this and also most importantly these will help on developing both web and mobile apps. In addition, I'm gonna use the stacks JavaScript, jQuery, jQuery UI, jQuery Mobile, Bootstrap wherever required.

        Service: I have planned to use Java as the main business layer language as I have 7+ years of experience on this I believe I can do better work using Java than other languages. In addition, I'm thinking to use the stacks Node.js.

        Database and ORM: I'm gonna pick MySQL as DB and Hibernate as ORM since I have a piece of good knowledge and also work experience on this combination.

        Search Engine: I need to deal with a large amount of product data and it's in-detailed info to provide enough details to end user at the same time I need to focus on the performance area too. so I have decided to use Solr as a search engine for product search and suggestions. In addition, I'm thinking to replace Solr by Elasticsearch once explored/reviewed enough about Elasticsearch.

        Host: As of now, my plan to complete the application with decent features first and deploy it in a free hosting environment like Docker and Heroku and then once it is stable then I have planned to use the AWS products Amazon S3, EC2, Amazon RDS and Amazon Route 53. I'm not sure about Microsoft Azure that what is the specialty in it than Heroku and Amazon EC2 Container Service. Anyhow, I will do explore these once again and pick the best suite one for my requirement once I reached this level.

        Build and Repositories: I have decided to choose Apache Maven and Git as these are my favorites and also so popular on respectively build and repositories.

        Additional Utilities :) - I would like to choose Codacy for code review as their Startup plan will be very helpful to this application. I'm already experienced with Google CheckStyle and SonarQube even I'm looking something on Codacy.

        Happy Coding! Suggestions are welcome! :)

        Thanks, Ganesa

        See more
        Codacy
        Codacy
        codebeat
        codebeat
        SonarQube
        SonarQube

        It is very important to have clean code. To be sure that the code quality is not really bad I use a few tools. I love SonarQube with many relevant hints and deep analysis of code. codebeat isn't so detailed, but it can find complexity issues and duplications. Codacy cannot find more bugs then your IDE. The winner for me is SonarQube that shows me really relevant bugs in my code.

        See more
        Interest over time
        Reviews of Checkmarx and SonarQube
        No reviews found
        How developers use Checkmarx and SonarQube
        Avatar of Trusted Shops GmbH
        Trusted Shops GmbH uses SonarQubeSonarQube

        To increase our code quality and make vulnerabilities visible, we added SonarQube to our Git(lab) workflow, so every commit is analyzed and code flaws are shown directly at the Mergerequest.

        Avatar of Sodep
        Sodep uses SonarQubeSonarQube

        Static code analysis for Java and Javascript projects.

        How much does Checkmarx cost?
        How much does SonarQube cost?
        Pricing unavailable
        Pricing unavailable
        News about Checkmarx
        More news
        News about SonarQube
        More news