Top Rated Checkmarx Alternatives
35 Checkmarx Reviews
Overall Review Sentiment for Checkmarx
Log in to view review sentiment.
Is so user friendly and it is very easy to become familiar with all the numerous features. Although I wasn't around for the implementation, I've found that it is relatively straightforward to integrate further functionality. The Scanning tools (IaC, SAST, SCA, API etc.) are all excellent and provide us with all the staus and visibility that we require. If we ever have issues that can't be resolved the Customer Support team at Checkmarx always are there to help us out. Review collected by and hosted on G2.com.
The dahsboards layour and display could be improved. Review collected by and hosted on G2.com.

I like the SAST-ification thing in overall, it is having all offering varies from source code scans to sca, to license scanning and does a great job finding vulnerabilities. It is easy to use and visually easy to look around for the bugs. Similarly very optimized so that we can integrate with the CI/CD pipelines Review collected by and hosted on G2.com.
The cost acquiring in all of the modules is pretty high. Review collected by and hosted on G2.com.
UI implementations are really good (Data Flow Matrixes)
suggestions are provided for the most suitable place to fix a set of vulnerabilities.
Most of the integrations are working seamlessly Review collected by and hosted on G2.com.
Support service is getting delayed sometimes
Some of the findings tend to be false positives
Scanning time is slow when compared with other tools.
Some of the IDE integrations aren't working as intended. Review collected by and hosted on G2.com.

Checkmarx Tool Scans the code pretty well. Gives accurate results in-depth analysis can be done because checkmarx provides Flow of code from source till the values getting executed Review collected by and hosted on G2.com.
Checkmarx reports false positives issues a lot. If it's a big application code base it's tough to control the number of false positive issues to analyse.Reporting can also be improved Review collected by and hosted on G2.com.

The most valuable features are the easy to understand interface, and it 's very user-friendly. Reduce the code using cxsast plugin. It will scan code line by line and find most of vulnerabilities. Very easy to use. Vulnerability report is awesome. Review collected by and hosted on G2.com.
UI should update. Reduce the false positive. Please upgrade rules set to avoid the false positive. Review collected by and hosted on G2.com.

Checkmarx has an impressive Codebashing feature that has the edge over SonarQube. The application tracking-reporting feature is good too. I like the "delta-scan" feature as it is really good for cases when there are very frequent scans needed (e.g. with every major code commit, we don't want the entire source code scan to happen again). Having used both tools extensively (SonarQube and Checkmarx), I prefer Checkmarx overall. Checkmarx also fares better compared to peers when it comes to finding any vulnerabilities within the database. Since ours is a user-information driven applicaiton, it becomes even more imminent to identify the data-specfic vulnerabilities at the earliest. Review collected by and hosted on G2.com.
Dashboarding could be better. The UI to show the current issue and the descriptive/suggestive text for the potential fix could be more "obvious" to the end-users. SonarQube scores over checkmarx in this regard.
Also, dashboarding could provide a little more flexibility towards the creation of new widgets.
One ore thing that I disliked about Checkmarx is that I could not find a free version in the market. Even for making an initial comparison, I had to contact the sales rep (the sales rep were pretty quick to respond, though). Review collected by and hosted on G2.com.
Easy to scan any application to find any security threats Review collected by and hosted on G2.com.
After marking false positives still, sometimes it shows the same issue as a security issue as high or critical. Review collected by and hosted on G2.com.
It identifies all the security vulnerabilities making your code secure than ever before. It also categorises the vulnerability into different categories based on the risk associated. Can be easily integrated with your CI pipeline to have you code scan with every build Review collected by and hosted on G2.com.
We can have a more better and user friendly UI to go through the report. Review collected by and hosted on G2.com.
The best features of Checkmarx are:
1) Open Source vulnerability scanner
2) Integration with multiple Ci/CD orchestration tools
3) Real-time reporting of static code vulnerabilities Review collected by and hosted on G2.com.
I feel the Jenkins code snippet of Checkmarx is a bit complex, and it could be a lot simpler. Review collected by and hosted on G2.com.