Compare HCL AppScan and SonarQube Server (formerly SonarQube)

Save
    Log in to your account
    to save comparisons,
    products and more.
At a Glance
HCL AppScan
HCL AppScan
Star Rating
(76)4.1 out of 5
Market Segments
Enterprise (53.4% of reviews)
Information
Entry-Level Pricing
Free
Browse all 3 pricing plans
SonarQube Server (formerly SonarQube)
SonarQube Server (formerly SonarQube)
Star Rating
(90)4.4 out of 5
Market Segments
Enterprise (43.8% of reviews)
Information
Entry-Level Pricing
Free
Browse all 4 pricing plans
AI Generated Summary
AI-generated. Powered by real user reviews.
  • Users report that SonarQube Server excels in Static Code Analysis with a score of 9.0, highlighting its ability to provide detailed insights into code quality, while HCL AppScan, with a score of 8.3, is noted for its comprehensive security testing but lacks the same depth in code quality metrics.
  • Reviewers mention that HCL AppScan shines in Test Automation, scoring 8.4, which allows for seamless integration into CI/CD pipelines, whereas SonarQube Server's score of 6.3 indicates it may not be as robust in automating testing processes.
  • G2 users highlight that SonarQube Server's Repository Integration score of 7.8 is beneficial for developers looking to maintain code quality across various repositories, while HCL AppScan's integration capabilities are rated higher at 8.2, making it more versatile for different development environments.
  • Users on G2 report that HCL AppScan provides better Compliance Testing with a score of 7.9, which is crucial for organizations needing to adhere to regulatory standards, compared to SonarQube Server's score of 7.1, which may not meet all compliance needs.
  • Reviewers say that SonarQube Server's Documentation is often praised for its clarity and comprehensiveness, aiding users in navigating the software effectively, while HCL AppScan's documentation is perceived as less user-friendly, impacting the ease of onboarding.
  • Users report that HCL AppScan's False Positives score of 7.5 is better than SonarQube Server's 6.8, indicating that AppScan may provide more accurate vulnerability assessments, which is critical for security-focused teams.
Featured Products
Pricing
Entry-Level Pricing
HCL AppScan
HCL AppScan CodeSweep
Free
Browse all 3 pricing plans
SonarQube Server (formerly SonarQube)
Community Edition
Free
Browse all 4 pricing plans
Free Trial
HCL AppScan
Free Trial is available
SonarQube Server (formerly SonarQube)
Free Trial is available
Ratings
Meets Requirements
8.8
59
8.7
77
Ease of Use
8.5
62
8.3
79
Ease of Setup
8.5
31
7.8
50
Ease of Admin
8.7
31
8.3
46
Quality of Support
8.5
60
8.0
62
Has the product been a good partner in doing business?
8.8
30
8.3
40
Product Direction (% positive)
8.4
58
8.0
74
Features by Category
Static Application Security Testing (SAST)Hide 13 FeaturesShow 13 Features
8.1
275
7.5
194
Administration
8.2
21
7.7
14
8.5
21
6.3
15
Analysis
8.6
22
7.6
16
7.8
22
8.2
15
8.3
22
9.0
17
8.0
22
9.1
17
Testing
7.6
21
7.2
13
7.8
21
6.3
14
8.4
20
6.3
16
7.9
21
7.1
13
8.3
20
7.6
12
8.3
21
8.5
16
7.5
21
6.6
16
Dynamic Application Security Testing (DAST)Hide 13 FeaturesShow 13 Features
8.1
357
Not enough data
Administration
8.1
26
Not enough data
8.2
28
Not enough data
Analysis
8.5
29
Not enough data
8.0
27
Not enough data
8.2
28
Not enough data
8.5
27
Not enough data
8.3
27
Not enough data
Testing
7.7
28
Not enough data
7.9
24
Not enough data
8.4
26
Not enough data
8.2
29
Not enough data
8.2
29
Not enough data
7.1
29
Not enough data
Software Development Analytics ToolsHide 6 FeaturesShow 6 Features
Not enough data
7.9
127
Functionality
Not enough data
7.8
24
Not enough data
8.3
23
Not enough data
8.3
22
Management
Not enough data
7.5
20
Not enough data
7.6
18
Not enough data
7.8
20
Software Composition AnalysisHide 6 FeaturesShow 6 Features
Not enough data
Not enough data
Functionality - Software Composition Analysis
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Effectiveness - Software Composition Analysis
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
7.6
150
Documentation
Not enough data
7.7
26
Not enough data
7.4
26
Not enough data
8.2
27
Security
Not enough data
6.8
24
Not enough data
7.5
23
Not enough data
8.0
24
Application Security Posture Management (ASPM)Hide 9 FeaturesShow 9 Features
Not enough data
Not enough data
Risk management - Application Security Posture Management (ASPM)
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Integration and efficiency - Application Security Posture Management (ASPM)
Not enough data
Not enough data
Not enough data
Not enough data
Reporting and Analytics - Application Security Posture Management (ASPM)
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Cloud Visibility
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Security
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Identity
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Not enough data
Categories
Categories
Shared Categories
HCL AppScan
HCL AppScan
SonarQube Server (formerly SonarQube)
SonarQube Server (formerly SonarQube)
HCL AppScan and SonarQube Server (formerly SonarQube) are categorized as Static Application Security Testing (SAST)
Reviews
Reviewers' Company Size
HCL AppScan
HCL AppScan
Small-Business(50 or fewer emp.)
27.4%
Mid-Market(51-1000 emp.)
19.2%
Enterprise(> 1000 emp.)
53.4%
SonarQube Server (formerly SonarQube)
SonarQube Server (formerly SonarQube)
Small-Business(50 or fewer emp.)
20.2%
Mid-Market(51-1000 emp.)
36.0%
Enterprise(> 1000 emp.)
43.8%
Reviewers' Industry
HCL AppScan
HCL AppScan
Information Technology and Services
24.3%
Computer & Network Security
13.5%
Computer Software
9.5%
Automotive
8.1%
Banking
6.8%
Other
37.8%
SonarQube Server (formerly SonarQube)
SonarQube Server (formerly SonarQube)
Computer Software
23.6%
Information Technology and Services
22.5%
Financial Services
7.9%
Hospital & Health Care
4.5%
Computer & Network Security
4.5%
Other
37.1%
Most Helpful Reviews
HCL AppScan
HCL AppScan
Most Helpful Favorable Review
Verified User
G
Verified User in Information Technology and Services

AppScan's thorough scanning capabilities and CI/CD integration streamline security testing. Detailed reporting aids in prioritizing vulnerabilities effectively.

Most Helpful Critical Review
Verified User
G
Verified User in Information Technology and Services

We can't relay solely on scanner results ,have to depend on manual testing as well

SonarQube Server (formerly SonarQube)
SonarQube Server (formerly SonarQube)
Most Helpful Favorable Review
KB
Kevin B.
Verified User in Computer Software

What I love about SonarQube is how it digs deep into my code and finds hidden issues which are not as obvious when writing the code, especially bugs and security problems, across different programming languages. It hooks up smoothly with my CI/CD pipelines,...

Most Helpful Critical Review
Verified User
G
Verified User in Medical Devices

My experience as a SonarSource customer shows that they manifest little interest in small customers. In addition, their quality policy is poor when it comes to fixing major bugs in their code. For instance, this ticket has now been open for 1 year without...

Alternatives
HCL AppScan
HCL AppScan Alternatives
Veracode Application Security Platform
Veracode Application Security Platform
Add Veracode Application Security Platform
Invicti (formerly Netsparker)
Invicti (formerly Netsparker)
Add Invicti (formerly Netsparker)
Checkmarx
Checkmarx
Add Checkmarx
GitLab
GitLab
Add GitLab
SonarQube Server (formerly SonarQube)
SonarQube Server (formerly SonarQube) Alternatives
Embold
Embold
Add Embold
GitHub
GitHub
Add GitHub
GitLab
GitLab
Add GitLab
Coverity
Coverity
Add Coverity
Discussions
HCL AppScan
HCL AppScan Discussions
Is AppScan free?
1 comment
Arnaud B.
AB
APPSCAN CodeSweep is free as a plugin in Visual Studio.Read more
Who owns AppScan?
1 comment
Official Response from HCL AppScan
HCL AppScan is owned by HCL Software.Read more
Monty the Mongoose crying
HCL AppScan has no more discussions with answers
SonarQube Server (formerly SonarQube)
SonarQube Server (formerly SonarQube) Discussions
Monty the Mongoose crying
SonarQube Server (formerly SonarQube) has no discussions with answers