--- title: OpenText Static Application Security Testing Reviews meta\_title: 'OpenText Static Application Security Testing Reviews 2026: Details, Pricing, & Features | G2' meta\_description: Filter 24 reviews by the users' company size, role or industry to find out how OpenText Static Application Security Testing works for a business like yours. aggregate\_rating: rating\_value: 4.5 review\_count: 24 scale: '5' date\_modified: '2026-08-17' parent\_category: name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t" url: https://www.g2.com/categories/devsecops ---

### OpenText Static Application Security Testing Pros and Cons: Top Advantages and Disadvantages

#### Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users value the **easy integrations** of OpenText Static Application Security Testing, enhancing their workflow with multiple tools. [(1 mentions)](https://www.g2.com/products/opentext-static-application-security-testing/reviews?filters%5Bsentiment_snippet%5D=1997535&qs=pros-and-cons#reviews)

Users value the **extensive integration capabilities** of OpenText Static Application Security Testing with various third-party tools. [(1 mentions)](https://www.g2.com/products/opentext-static-application-security-testing/reviews?filters%5Bsentiment_snippet%5D=1997526&qs=pros-and-cons#reviews)

Users value the **extensive integration support** for various technologies and third-party tools offered by OpenText Static Application Security Testing. [(1 mentions)](https://www.g2.com/products/opentext-static-application-security-testing/reviews?filters%5Bsentiment_snippet%5D=1997522&qs=pros-and-cons#reviews)

Users are disappointed by the **false positives** , but appreciate the ability to ignore issues in future scans. [(1 mentions)](https://www.g2.com/products/opentext-static-application-security-testing/reviews?filters%5Bsentiment_snippet%5D=1997517&qs=pros-and-cons#reviews)

### Top Pros or Advantages of OpenText Static Application Security Testing

##### 1. Easy Integrations

Users value the **easy integrations** of OpenText Static Application Security Testing, enhancing their workflow with multiple tools.
[
See 1 mentions
](https://www.g2.com/products/opentext-static-application-security-testing/reviews?filters%5Bsentiment_snippet%5D=1997535&qs=pros-and-cons#reviews)

See Related User Reviews

LT

Lokesh T.

Mid-Market (51-1000 emp.)

4.0/5

"Fortify Static Code Analyzer (SCA)"

What do you like about OpenText Static Application Security Testing?

Fortify SCA is having large Technologies Stack support, It supports more then 34+ Languages for Static Analysis. And also he is having huge integratio

##### 2. Integrations

Users value the **extensive integration capabilities** of OpenText Static Application Security Testing with various third-party tools.
[
See 1 mentions
](https://www.g2.com/products/opentext-static-application-security-testing/reviews?filters%5Bsentiment_snippet%5D=1997526&qs=pros-and-cons#reviews)

See Related User Reviews

LT

Lokesh T.

Mid-Market (51-1000 emp.)

4.0/5

"Fortify Static Code Analyzer (SCA)"

What do you like about OpenText Static Application Security Testing?

Fortify SCA is having large Technologies Stack support, It supports more then 34+ Languages for Static Analysis. And also he is having huge integratio

##### 3. Integration Support

Users value the **extensive integration support** for various technologies and third-party tools offered by OpenText Static Application Security Testing.
[
See 1 mentions
](https://www.g2.com/products/opentext-static-application-security-testing/reviews?filters%5Bsentiment_snippet%5D=1997522&qs=pros-and-cons#reviews)

See Related User Reviews

LT

Lokesh T.

Mid-Market (51-1000 emp.)

4.0/5

"Fortify Static Code Analyzer (SCA)"

What do you like about OpenText Static Application Security Testing?

Fortify SCA is having large Technologies Stack support, It supports more then 34+ Languages for Static Analysis. And also he is having huge integratio

### Top Cons or Disadvantages of OpenText Static Application Security Testing

##### 1. False Positives

Users are disappointed by the **false positives** , but appreciate the ability to ignore issues in future scans.
[
See 1 mentions
](https://www.g2.com/products/opentext-static-application-security-testing/reviews?filters%5Bsentiment_snippet%5D=1997517&qs=pros-and-cons#reviews)

See Related User Reviews

LT

Lokesh T.

Mid-Market (51-1000 emp.)

4.0/5

"Fortify Static Code Analyzer (SCA)"

What do you dislike about OpenText Static Application Security Testing?

It gives few False Positive, which i didnt liked, But to manage false positive, we can make use of feature called, ignore teh issues, where once it is

## Top-Rated Alternatives

[

 ![SonarQube](https://images.g2crowd.com/uploads/product/hd_favicon/2d6b80be24e9f51c144f780f2aa41cb3/sonarqube.svg "SonarQube")

SonarQube

4.4/5(154)

](https://www.g2.com/products/sonarqube/reviews)

[

 ![Checkmarx](https://images.g2crowd.com/uploads/product/hd_favicon/ee46b61b130757d24b7633fe98e00fb6/checkmarx.svg "Checkmarx")

Checkmarx

4.2/5(49)

](https://www.g2.com/products/checkmarx/reviews)

[

 ![GitHub](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_8ec3c17e3fb1df25b6a8bd7cc69cf2d1/github.png "GitHub")

GitHub

4.7/5(2,401)

](https://www.g2.com/products/github/reviews)

[
View All Alternatives
](https://www.g2.com/products/opentext-static-application-security-testing/competitors/alternatives)

  

LT

Lokesh T.

Sr. Security Engineer

Mid-Market (51-1000 emp.)

1/27/2025

"Fortify Static Code Analyzer (SCA)"

4/5

What do you like best about OpenText Static Application Security Testing?

Fortify SCA is having large Technologies Stack support, It supports more then 34+ Languages for Static Analysis. And also he is having huge integration capabalities with other third party tools. Review collected by and hosted on G2.com.

What do you dislike about OpenText Static Application Security Testing?

It gives few False Positive, which i didnt liked, But to manage false positive, we can make use of feature called, ignore teh issues, where once it is ignored, then it wont be availabe in furthr scans. Review collected by and hosted on G2.com.

What problems is OpenText Static Application Security Testing solving and how is that benefiting you?

It is a powerfull Static Analysis tool. where it helps in identifying vulnerabilities in 1st part code. And also for me it helped in building DevSecOps Pipeline Review collected by and hosted on G2.com.

Show More

Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (Validated through a business email account)Source: Organic (Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.)

 (Copy Review URL)

  

NN

Nav N.

IT Consultant

Small-Business (50 or fewer emp.)

10/27/2022

"Efficient and easy to use Code Analyzer"

4.5/5

What do you like best about OpenText Static Application Security Testing?

Fortify is an excellent code analyzer. Its plugins are handy as compared to other solutions. It can quickly and accurately identify errors. We can efficiently address critical errors and warnings. It can scan the code in real time. Fortify Static Code Analyzer is handy for CI/CD programs. We can resolve the issues quickly at the development level. It is efficient and time-saving also. It can be easily integrated with Android Studio, Visual Studio, IntelliJ, etc. Fortify Static Code Analyzer notifies us on time if there are any security leaks. All the features are very beneficial once you know their proper functionalities, Review collected by and hosted on G2.com.

What do you dislike about OpenText Static Application Security Testing?

The price of Fortify Static Code Analyzer is a bit high. Also, sometimes we can face troubleshooting issues. Other functionalities can also be improved to make it more handy and easy to use. Review collected by and hosted on G2.com.

What problems is OpenText Static Application Security Testing solving and how is that benefiting you?

It helps to fix coding errors in real-time. The dashboard is easy to use to keep track of all mistakes and security risks. Development and Deployment have become much simple and easier. It also saves a lot of time. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through a business email account)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Varun J.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Varun J.")
VJ

Varun J.

Principal Consultant

Enterprise (\> 1000 emp.)

9/21/2022

"Veteran & Powerful SCA tool"

4.5/5

What do you like best about OpenText Static Application Security Testing?

Fortify has been the first choice for doing secure (static) code analysis for many years because

1. Languages support - it supports both legacy and modern development languages.

2. Deployment Model - on-prem, cloud, Security as a service (FOD)

3. Technical support - Fortify not only helps the new onboarded customers with detailed documentation but also provides good trainings Review collected by and hosted on G2.com.

What do you dislike about OpenText Static Application Security Testing?

There is a native issue of false positives with all the SCA tools. Which somehow decreases the value and increases the turn around time for finding the exact true positives Review collected by and hosted on G2.com.

What problems is OpenText Static Application Security Testing solving and how is that benefiting you?

Fortify integrates with CICD pipeline which helps to write secure code and it's plugin for various IDEs gives the developers early feedback , so that the application being deployed in production is vulnerability free and more secure Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Mohsin K.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Mohsin K.")
MK

Mohsin K.

Information Security Manager

Small-Business (50 or fewer emp.)

9/7/2022

"Absolute Stunner! Efficient IDE support in a SAST!"

4.5/5

What do you like best about OpenText Static Application Security Testing?

Friendly and Efficient Integrations - IntelliJ, VS, Android Studio, etc. Organized Dashboard and their absolutely wonderful reporting platform. It really helped us achieve our compliance goals! Review collected by and hosted on G2.com.

What do you dislike about OpenText Static Application Security Testing?

Fortify should develop a DAST setup as well, this would really marginalize our input and time efficiency. Review collected by and hosted on G2.com.

What problems is OpenText Static Application Security Testing solving and how is that benefiting you?

Compliance

Risk Management

Development Efficiency

Fortify provides us with absolute defense. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Tejas P.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Tejas P.")
TP

Tejas P.

Sr. DevOps Engineer

Enterprise (\> 1000 emp.)

9/15/2022

"efficient scanning tool"

3.5/5

What do you like best about OpenText Static Application Security Testing?

Exact pinpointing of issues in code and suggestions to fix them. Review collected by and hosted on G2.com.

What do you dislike about OpenText Static Application Security Testing?

bit costly, also bit difficult to set up at intial. Review collected by and hosted on G2.com.

What problems is OpenText Static Application Security Testing solving and how is that benefiting you?

Source code analysis, finding a vulnerability.

Used it for security as well. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Mohammed Imran A.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Mohammed Imran A.")
MA

Mohammed Imran A.

DevOps Specialist

Mid-Market (51-1000 emp.)

9/7/2022

"This is a code scanning tool which does it job perfectly. it show the vulnerabilities in a code."

4/5

What do you like best about OpenText Static Application Security Testing?

It shows how to fix the vulnerable code. Review collected by and hosted on G2.com.

What do you dislike about OpenText Static Application Security Testing?

i did not find the automatic way to create the projects. Review collected by and hosted on G2.com.

What problems is OpenText Static Application Security Testing solving and how is that benefiting you?

It helped me and my team to clean the code and upgrade the erroneous plugins in the code. Helped the code quality. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Abhishikt V.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Abhishikt V.")
AV

Abhishikt V.

Security Engineer 2

Enterprise (\> 1000 emp.)

9/27/2022

"Experienced Security Test Engineer in the cloud security, Supplychain security, health care."

5/5

What do you like best about OpenText Static Application Security Testing?

Ease of using, deployment in CI/CD & the custom ruleset/report creation. Review collected by and hosted on G2.com.

What do you dislike about OpenText Static Application Security Testing?

Heavily depends on JRE configs, which makes compiling & running slower. Review collected by and hosted on G2.com.

What problems is OpenText Static Application Security Testing solving and how is that benefiting you?

Static Security code analysis Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through a business email account)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Vis C.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Vis C.")
VC

Vis C.

Software Security Technical Director

Enterprise (\> 1000 emp.)

5/18/2022

"A worthy SAST product for any software's source code security"

4.5/5

What do you like best about OpenText Static Application Security Testing?

Wide range of programming language support, Ability to generate FPR files from CICD pipelines, Externalization of scans into another server for performance reasons. Review collected by and hosted on G2.com.

What do you dislike about OpenText Static Application Security Testing?

Slow at times to complete at large number of files in a heavy software. Review collected by and hosted on G2.com.

What problems is OpenText Static Application Security Testing solving and how is that benefiting you?

Security of software source code. SAST! Review collected by and hosted on G2.com.

Show More

6/2/2025 (At G2, we prefer fresh reviews and we like to follow up with reviewers. They may not have updated their review text, but have updated their review.)
Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Verified User in Computer Software](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Computer Software")
CC

Verified User in Computer Software
 (This reviewer's identity has been verified by our review moderation team. They have asked not to show their name, job title, or picture.)

Enterprise (\> 1000 emp.)

4/19/2022

"Fortify is best tool to scan source code"

5/5

What do you like best about OpenText Static Application Security Testing?

I like fortify to scan source code in deply. It will compile the code and find the vulnerabilities. No others tools compile the code scan. Most important thing is result. It will find all critical issues. Review collected by and hosted on G2.com.

What do you dislike about OpenText Static Application Security Testing?

Sometimes it will show more duplicate issue. Developer should work on this and resolved it. Review collected by and hosted on G2.com.

What problems is OpenText Static Application Security Testing solving and how is that benefiting you?

Fortify find all the low to critical risk issue and make the application secure. As well as it will provide the very simple report to developer should understand the remediation and fix it. Review collected by and hosted on G2.com.

Show More

9/12/2023 (At G2, we prefer fresh reviews and we like to follow up with reviewers. They may not have updated their review text, but have updated their review.)
Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Mohit G.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Mohit G.")
MG

Mohit G.

Asst. Vice President - Information Security 

Enterprise (\> 1000 emp.)

9/14/2021

"Value for Money"

4/5

What do you like best about OpenText Static Application Security Testing?

It is an on-prem solution and is compatible with most of the commonly used languages. It can get the scan results verified by an audit assistant that will further reduce the false positives. Very easy to install and can be deployed over windows or Linux machines. SSC module can be utilized for better reporting and tracking. Furthermore, it can be integrated with CI/CD pipelines for automated assessments. Review collected by and hosted on G2.com.

What do you dislike about OpenText Static Application Security Testing?

Reporting can be me more intelligent, and false positives are little on the higher side. Review collected by and hosted on G2.com.

What problems is OpenText Static Application Security Testing solving and how is that benefiting you?

Primarily used for Application source code assessments by integrating it with DevSecOps pipeline. That helps us to automate the assessment process and remediate the vulnerabilities in the early stages of the development. That enables the developers to release new features timely. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

##### Categories on G2

[Static Application Security Testing (SAST)](https://www.g2.com/categories/static-application-security-testing-sast)[Static Code Analysis](https://www.g2.com/categories/static-code-analysis)

##### Explore More

[What is the best-rated time tracking solution for startups?](https://www.g2.com/discussions/what-is-the-best-rated-time-tracking-solution-for-startups)[Which feature management tools reduce production risk through instant rollback capabilities when issues arise?](https://www.g2.com/discussions/which-feature-management-tools-reduce-production-risk-through-instant-rollback-capabilities-when-issues-arise)[What are the highest rated managed mobility services platforms for organisations transitioning from legacy systems and infrastructure?](https://www.g2.com/discussions/what-are-the-highest-rated-managed-mobility-services-platforms-for-organisations-transitioning-from-legacy-systems-and-infrastructure%20)

[Best software for terminology management in translation](https://www.g2.com/discussions/best-software-for-terminology-management-in-translation)[Top platforms for managing employee vacation and sick leave](https://www.g2.com/discussions/top-platforms-for-managing-employee-vacation-and-sick-leave)[Pros and Cons Details](https://www.g2.com/products/opentext-static-application-security-testing/reviews?qs=pros-and-cons)

[Show MoreShow Less](javascript:void(0);)