Show rating breakdown
Save to My Lists
Claimed
Claimed

Top Rated CodeSonar Alternatives

CodeSonar Reviews & Product Details

Verified User in Medical Devices
UM
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about CodeSonar?

The flexibility of the static analysis profile that can be used to assess the code. Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

The initial effort to hook up the Codesonar hub and connect that to a node that was running codesonar in our build pipeline was a little complex. Review collected by and hosted on G2.com.

Recommendations to others considering CodeSonar:

Look at the ease of integration into Jenkins build pipeline. Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

We have a regulatory requirement that our code base must have a static code analysis performed. Codesonar is helping us to meet that objective. Review collected by and hosted on G2.com.

CodeSonar Overview

What is CodeSonar?

As a leading provider of static application security testing (SAST) solutions, CodeSecure helps software developers solve challenging issues throughout the software development life cycle (SDLC) to protect mission-critical software and devices from failure and cyberattack. By enabling developers to shift security testing left, CodeSecure CodeSonar seamlessly integrates into CI/CD and DevSecOps tools to assist developers in designing, developing, and deploying trusted software applications – meeting standards, minimizing risk and accelerating projects to gain a competitive advantage. CodeSecure CodeSonar is a multi-language static application security testing (SAST) solution supporting C, C++, C# and Java. CodeSonar provides deep static analysis to quickly find and fix defects impacting code quality, safety and security. With seamless integrations into developer tools such as GitHub, GitLab, Jenkins, Visual Studio and others, CodeSonar is easily adopted into developer workflows to efficiently and continuously test code to create higher quality, safer and more secure software.  

CodeSonar Details
Show LessShow More
Product Description

CodeSonar, GrammaTech's flagship static analysis SAST tool, identifies bugs that can result in system crashes, unexpected behavior, and security breaches.

How do you position yourself against your competitors?

When safety and security matter most, organizations developing mission-critical software and devices turn to GrammaTech CodeSonar for static application security testing. CodeSonar's static analysis engine is extraordinarily deep, finding 3-5 times more defects on average than other static analysis tools. This deep analysis combined with extensive features around code navigation and understanding enables developers to find and fix more defects to meet critical safety and security standard requirements and coding guidelines.


Seller Details
Year Founded
1988
HQ Location
Ithaca, NY
Twitter
@GrammaTech
699 Twitter followers
LinkedIn® Page
www.linkedin.com
54 employees on LinkedIn®

Alison N.
AN
Overview Provided by:
Marketer, Board Director + lifelong learner. Inspired by humble leadership, teamwork and a well-told story.

Recent CodeSonar Reviews

kanchan s.
KS
kanchan s.Small-Business (50 or fewer emp.)
4.0 out of 5
"Help developers identify and address software defects"
CodeSonar is a static analysis tool designed to help developers identify and address software defects and vulnerabilities. It analyzes source code ...
Verified User
C
Verified UserEnterprise (> 1000 emp.)
5.0 out of 5
"Grammatech feedback from a field support engineer perspective"
Having deep analysis engine outputting the results in several formats for most convenient interpretation; straight-forward support and maintenance;...
Tushar J.
TJ
Tushar J.Small-Business (50 or fewer emp.)
4.0 out of 5
"CodeSonar : Life saver"
CodeSonar is the best tool in market for static code analysis for C/C++ and other languages. It can be easily integrate with other tools like Jenki...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

CodeSonar Media

Answer a few questions to help the CodeSonar community
Have you used CodeSonar before?
Yes

12 out of 13 Total Reviews for CodeSonar

4.3 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
12 out of 13 Total Reviews for CodeSonar
4.3 out of 5
12 out of 13 Total Reviews for CodeSonar
4.3 out of 5
G2 reviews are authentic and verified.
kanchan s.
KS
Search Engine Optimization Specialist
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: Organic Review from User Profile
(Original )Information
What do you like best about CodeSonar?

CodeSonar is a static analysis tool designed to help developers identify and address software defects and vulnerabilities. It analyzes source code to detect potential issues and provides insights to improve code quality. Here's a review of CodeSonar, including its pros and cons:

Pros:

Powerful bug detection: CodeSonar is known for its robust bug detection capabilities. It uses advanced static analysis techniques to identify a wide range of defects, including memory leaks, null pointer dereferences, buffer overflows, and concurrency issues. Its deep analysis helps developers uncover subtle bugs that may be challenging to detect through manual code review or testing.

Precise and accurate results: CodeSonar is praised for its accuracy in detecting bugs. It employs a combination of data flow analysis, control flow analysis, and symbolic execution to provide precise results. This reduces false positives and helps developers focus on genuine issues, saving time and effort during the debugging process.

Scalability: CodeSonar is designed to handle large and complex codebases. It can analyze projects with millions of lines of code efficiently, making it suitable for enterprise-level software development. Its scalability ensures that developers can apply static analysis to projects of varying sizes without sacrificing performance. Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

Complexity and learning curve: CodeSonar is a powerful tool, but it can be complex to set up and configure, especially for developers who are new to static analysis. The learning curve can be steep, and users may require some time and training to fully understand and utilize its features effectively.

False negatives: While CodeSonar strives for accurate bug detection, there is still a possibility of false negatives—bugs that go undetected by the tool. Some types of bugs or code patterns may be more challenging for static analysis to identify, and developers should not rely solely on CodeSonar but also supplement it with other testing and code review practices.

Cost: CodeSonar is a commercial tool, and its licensing costs may be a deterrent for small or independent developers or organizations with limited budgets. The pricing structure may not be feasible for all development teams, particularly those working on open-source or non-commercial projects. Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

Helping developers identify and address software defects and vulnerabilities. Review collected by and hosted on G2.com.

Tushar J.
TJ
System Engineer
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about CodeSonar?

CodeSonar is the best tool in market for static code analysis for C/C++ and other languages. It can be easily integrate with other tools like Jenkins. It's GUI is impressive. The accuracy of problems detected in code is quite high in CodeSonar. Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

Sometimes it seems it's performance speed gets low and the keyword which was searched doesn't produce useful results. Else there's nothing much to dislike CodeSonar. Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

CodeSonar helps me to analyse the quality and enhance the performance of the code written. To make the code complaint with the guidelines provided by client, CodeSonar helps to provide perfect solution to the respective warnings. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
CI
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: In-app
What do you like best about CodeSonar?

Having deep analysis engine outputting the results in several formats for most convenient interpretation; straight-forward support and maintenance; improved log and database management from 6.2p2; support and development organization that takes bugs and improvements seriously and fixes them as soon as possible in alignment with the CodeSonar development roadmap Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

Fanatical leadership, product owners and technical support that are interested in having long-term good terms with customers; actively listening back and taking input. Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

Solving serious hidden programming errors that cost my client quite a budget; improving the code quality and educating developers to write better code that is secure Review collected by and hosted on G2.com.

MP
Software engineer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about CodeSonar?

Very simple to launch an analysis from the command line on the Linux software. Results were sent when all analyzed is finished which can contains several compilations or code analysis. Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

The CodeSonar hub interface is not ergonomic and practical for dealing with errors. Bad integration in the CI/CD process like Jenkins. The configuration process from the configuration is a little longer to set up (but great doc does deal with it so small negative point). Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

Static and dynamic source code analysing with MISRA rules coverage. Review collected by and hosted on G2.com.

Verified User in Aviation & Aerospace
AA
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about CodeSonar?

Customer support has been excellent, some are always there to respond to technical questions. The Help manual is also really good, and the response time for new licenses or training licenses etc. is very fast! Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

There isn't anything I dislike, the team I work with takes a long time to decide on upgrades etc. so that is the most frustrating thing. Also, I wish I had more time to work with support on implementing the disaster recovery mechanism... Review collected by and hosted on G2.com.

Recommendations to others considering CodeSonar:

na Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

Codesonar provides whatever static analysis is required for the flight software team to meat the compliance requirements for their projects. Also, when there are security issues from the DoD etc. then Grammatech is very quick to resolve those issues and provide updates/fixes. Review collected by and hosted on G2.com.

Verified User in Electrical/Electronic Manufacturing
UE
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about CodeSonar?

The way to check the result in browser, and no need to search the result it's intuitive. Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

The configuration if there is no support. Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

Some potential bugs or errors before the code increase.Avoid spending time. Review collected by and hosted on G2.com.

Verified User in Computer Hardware
AC
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about CodeSonar?

All the features that are available to me. Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

I do not like the UI. It could be made easier to use. Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

Improving code quality and security through static analysis. It works on code built in Green Hill's MULTI, which is something that is not offered by one of your copetitors (sonarQube) Review collected by and hosted on G2.com.

Mika V.
MV
Senior Manager
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about CodeSonar?

The GUI is intuitive. I like the support Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

There are still some issues what it didn't detct. Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

Finds issues, which are difficult to find by peer-review and thus identify issues earlier than in released product Review collected by and hosted on G2.com.

Verified User in Government Relations
UG
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about CodeSonar?

Quick respones when putting in a ticket. Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

I have not found anything I don't like yet. Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

The software identifies potential flaws in code. Gives generic examples on how to fix the problem. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
(Original )Information
What do you like best about CodeSonar?

CodeSonar is easy to use offers rich experience in finding security vulnerabilities in source code Review collected by and hosted on G2.com.

What do you dislike about CodeSonar?

Nothing to be disliked about this product Review collected by and hosted on G2.com.

What problems is CodeSonar solving and how is that benefiting you?

Finding security vulnerabilities in our organisations source code. This offers better security testing Review collected by and hosted on G2.com.