Best Software for 2025 is now live!
Save to My Lists
Claimed
Claimed

Top Rated Coverity Alternatives

Coverity Reviews & Product Details

Coverity Overview

What is Coverity?

Coverity® is a fast, accurate, and highly scalable static analysis (SAST) solution that helps development and security teams address security and quality defects early in the software development life cycle (SDLC), track and manage risks across the application portfolio, and ensure compliance with security and coding standards.

Coverity Details
Show LessShow More
Product Description

Coverity static analysis by Synopsys helps development and security teams find and fix defects and security flaws in code as it’s being written. Coverity is highly accurate, supports thousands of developers, and quickly analyzes large projects exceeding 100 million lines of code, helping your teams build secure, high-quality software faster.


Seller Details
Seller
Synopsys
Year Founded
1986
HQ Location
Mountain View, CA
Twitter
@synopsys
22,849 Twitter followers
LinkedIn® Page
www.linkedin.com
19,499 employees on LinkedIn®
Ownership
NASDAQ:SNPS
Total Revenue (USD mm)
$3,685
Description

Synopsys helps customers innovate from Silicon to Software, so they can deliver Smart, Secure Everything


JE
Overview Provided by:

Recent Coverity Reviews

Flash S.
FS
Flash S.Mid-Market (51-1000 emp.)
2.0 out of 5
"Used to be wonderful for finding C++ bugs"
Sometimes finds breathtaking C++ out of bounds memory writes.
Deepti S.
DS
Deepti S.Enterprise (> 1000 emp.)
5.0 out of 5
"Optimized code with Coverity tool"
I love the feature how coverity tool by synopsys can detect issues in the code and thus provides a way to make your code way more optimized.
Verified User
U
Verified UserMid-Market (51-1000 emp.)
4.5 out of 5
"Tool which is the best for the static analysis"
It has very capable and promising features which provides an user to debug and analysis the code for the faster run times. I have used this tool wh...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

Coverity Media

Coverity Demo - Coverity
Coverity (Code Sight) customer view
Answer a few questions to help the Coverity community
Have you used Coverity before?
Yes

56 Coverity Reviews

4.2 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
56 Coverity Reviews
4.2 out of 5
56 Coverity Reviews
4.2 out of 5

Coverity Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for CoverityQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Flash S.
FS
Senior Compiler Test Engineer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: Organic Review from User Profile
What do you like best about Coverity?

Sometimes finds breathtaking C++ out of bounds memory writes. Review collected by and hosted on G2.com.

What do you dislike about Coverity?

Little progress since 2010’s; languages other than C/C++ extremely weak. Useless support since takeover by Synopsys. Review collected by and hosted on G2.com.

What problems is Coverity solving and how is that benefiting you?

Bugs Review collected by and hosted on G2.com.

Mushegh D.
MD
DevOps Architect
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
(Original )Information
Business partner of the seller or seller's competitor, not included in G2 scores.
What do you like best about Coverity?

A good text editor does more than just inspect and verify one programming language. A text editor that doesn’t have much in the way of language support can be the greatest app the world has ever seen and still be wrong for your needs if you don’t code in one of the languages it understands. Your dream editor should be able to work with many languages without reduced functionality. An easy-to-use, fully customizable editor. Some of its customizations include debugging and compiling features through extensions and plug-ins. Best of all. In general, it's great when you have the time to set it upright, and not as good when you want to get moving quickly without a lot of configuration. Review collected by and hosted on G2.com.

What do you dislike about Coverity?

Everything is ok, But the project is not famous yet, but I think it will be resolved soon. Also, some plugins crash randomly. Sometimes it becomes slow when working on multiple files and the syntax highlighting for some languages is missing. Depending on your previous workspace, it can open with two panes and a welcome tab in each, requiring you to close lots of cruft on startup. Review collected by and hosted on G2.com.

Recommendations to others considering Coverity:

Coverity has a lot of nice documentation that provides you all the information that you might need when writing code on code. What is more, if you can any questions in the specific code that you are currently using or the Coverity m document is not covered you can always check it online. Coverity is being used across the entire organization and most of the data scientists in my company are currently using it in the local environment. Even though Coverity is just an option and not required to be used, most of my colleagues including myself prefer to use it due to its interface. Review collected by and hosted on G2.com.

What problems is Coverity solving and how is that benefiting you?

Coverity is widely known as a great text editor as it’s fast, capable, and well-suited for editing large projects. However, Sublime lacks updates and is a closed source, thus limiting its opportunities for growth. Meanwhile, Coverity boasts flexibility, an open-source code, many contributors, and easy-to-install packages. Coverity is on track to be the next leader of the industry and is worth investing time into. Coverity has a simple UI that makes users use it without any issues. I have been using this product since my college days when I had a very low system configuration PC. It's a very good application but sometimes the mixed plugin's back-end gives unnecessary errors. All features like multiple programming language support, extensions, etc. are personally good. Sometimes we face performance effects when using it for the last many hours. Review collected by and hosted on G2.com.

Deepti S.
DS
5G Software Developer 2
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about Coverity?

I love the feature how coverity tool by synopsys can detect issues in the code and thus provides a way to make your code way more optimized. Review collected by and hosted on G2.com.

What do you dislike about Coverity?

I dislike that sometimes there are false positive issues for which there is no perfect fix, but coverity indicate it as a bug. But there is always a way to declare that false positive and its good enough. Review collected by and hosted on G2.com.

Recommendations to others considering Coverity:

Its a great tool to further improve your code Review collected by and hosted on G2.com.

What problems is Coverity solving and how is that benefiting you?

I am working on a project and coverity tool is really helpful in pin pointing the minor or major issues which one can ignore in there day to day work life. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Coverity?

It has very capable and promising features which provides an user to debug and analysis the code for the faster run times. I have used this tool while doing in my project.

The quality of producy support is awe some, they actually helped me alot which reduces time and effort, and makes my code best. Review collected by and hosted on G2.com.

What do you dislike about Coverity?

It has some bugs to fix but can find the solutions for it because of their product support. Review collected by and hosted on G2.com.

Recommendations to others considering Coverity:

Its the best tool to have in industry which releaves you a head of time by reporting all the major issues a head of time, which probably makes ur code best at time release. Review collected by and hosted on G2.com.

What problems is Coverity solving and how is that benefiting you?

The debuging skills of the code is vey good while using this tool which saves a lot of time and the code can be in better way which possibly solves much issues with out any major defects in the release. Review collected by and hosted on G2.com.

Verified User in Computer Software
IC
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Coverity?

We use the Coverity Static Analysis tool for security scans of C/C++ server code.

Coverity is having a higher detection rate as we highly rely on this code scan for our application code.

We had seamlessly integrated this SAST tool (Coverity) to our CI/CD Pipeline and the vulnerabilities were being notified to the respective developer via mail.

It provides a mechanism to audit the findings and mark false positives in an effecient way.

Support for several languages is one another factor that stands out well when compared to other tools.

Time it takes to scan huge code lines is significantky faster compared to other tools. Review collected by and hosted on G2.com.

What do you dislike about Coverity?

However there are some improvements points which I thought I should highlight to make this tool even more better for the end users.

strzcpy vs. NULL_STRING

Coverity does not recognize that strzcpy adds a terminating x00.

ab_pfetch*

On Windows we currently have many OVERRUN false positives.

bsearch on fixed width table vs. Literal

Coverity’s model for bsearch assumes that bsearch access the key on the full width of the key. If bsearch is given a fixed (max) size table, and say strcmp as compare function, then in reality when bsearch is called with a small literal as key, then all is good. Alas Coverity thinks that bsearch will read beyond the end of the literal, even though strcmp will not.

NO_EFFECT on var_arg

On Windows we currently have a NO_EFFECT warning on all uses of va_args

TAINTED_SCALAR

Coverity to warn for uses of tainted data, data that might be controlled by an attacker. This may lead to data corruption, code injection,...

When possible Coverity reports additional defects describing the dangerous use of the tainted data INTEGER_OVERFLOW.

RW.LITERAL_OPERATOR_NOT_FOUND on printf with TEL_Format

When using TEL defined format such as TEL_Flpu, TEL_Fsu, TEL_Fpid ,... Coverity sometimes requires a space before the 'T' from TEL_Fxxx.

TAINTED_STRING

Coverity to warn for uses of tainted data, data that might be controlled by an attacker. This may lead to data corruption, code injection, SQL injection, directory traversal,

PW.PRINTF_ARG_MISMATCH - * precision or * size vs. size_t or ptrdiff_t parameters

64 bits builds or scans - The C-Standard states that the * precision or size are of type int. This is generally 4 bytes. On 64 bits builds size_t and ptrdiff_t are 8 bytes.

If I had submitted a fix yesterday, today’s Coverity Connect continue to report the defect. Review collected by and hosted on G2.com.

What problems is Coverity solving and how is that benefiting you?

We use Coverity to solve both Quality and Security issues.

Outpf bound access

Uninitialized pointer reads

Calling risky functions

Resource leak and lot more Review collected by and hosted on G2.com.

Viraj P.
VP
Associate Lead - Application Security Engineer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Coverity?

Assigning issues to users is simply easy and less false positives. Review collected by and hosted on G2.com.

What do you dislike about Coverity?

Reporting portion and for results it take more time than other solutions. Review collected by and hosted on G2.com.

Recommendations to others considering Coverity:

A good SAST solution if you are considering multi-platforms and fewer false positives. Review collected by and hosted on G2.com.

What problems is Coverity solving and how is that benefiting you?

It helps to identify bugs related to security during our application lifecycle. Review collected by and hosted on G2.com.

Verified User in Computer Software
CC
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Coverity?

helps development and security teams address security and quality defects early in the software development life cycle (SDLC),

Best thing about Coverity is highly accurate, supports thousands of developers, and quickly analyzes large projects exceeding 100 million lines of code. Review collected by and hosted on G2.com.

What do you dislike about Coverity?

Few pointers definitely needs improvement would be resources leaks. dereferences of NULL pointers. incorrect usage of APIs. Review collected by and hosted on G2.com.

What problems is Coverity solving and how is that benefiting you?

Have used Coverity Quality Advisor and solved issues like:

resources leaks.

dereferences of NULL pointers.

incorrect usage of APIs.

use of uninitialized data.

memory corruptions.

buffer overruns.

control flow issues.

error handling issues. Review collected by and hosted on G2.com.

Nikhil D.
ND
Software Engineer
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Coverity?

Its user friendly UI. It easy to browse code using Coverity and it also briefly describes about the issue. Review collected by and hosted on G2.com.

What do you dislike about Coverity?

I was facing issue in categorising the Coverity issues. Review collected by and hosted on G2.com.

What problems is Coverity solving and how is that benefiting you?

I have mainly used for solving Coverity fixes.

It catches the basic issues which can be easily fixed and helps in improving the code base. Review collected by and hosted on G2.com.

Sumit K.
SK
Software Engineer
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Coverity?

It is easy to use the tool. And helps to find any issue that is overlooked in manual review. Review collected by and hosted on G2.com.

What do you dislike about Coverity?

The tool is pretty good. It is easy to set up with proper guidelines. Review collected by and hosted on G2.com.

What problems is Coverity solving and how is that benefiting you?

Secured code review. Review collected by and hosted on G2.com.

Swarup A.
SA
Project Manager
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Coverity?

Excellent User Interface and server-side features. The Coverity support team is also very responsive Review collected by and hosted on G2.com.

What do you dislike about Coverity?

I did not find any such attribute during my experience Review collected by and hosted on G2.com.

What problems is Coverity solving and how is that benefiting you?

Static analysis integration with CI-CD DevOps pipeline and improvement of code quality Review collected by and hosted on G2.com.