Best Software for 2025 is now live!
Save to My Lists
Paid
Claimed

SonarQube Cloud (formerly SonarCloud) Reviews & Product Details

Verified User in Financial Services
AF
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
(Original )Information
What do you like best about SonarQube Cloud (formerly SonarCloud)?

Cloud based and hence no need to install on any server.

Integrates into various version control systems using CI/CD pipelines.

Has a huge database of various rules per coding platform.

Helps in scanning large quantities of code efficiently. Also, provides insights into possible security misconfigurations. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Cloud (formerly SonarCloud)?

Initial setup is a little difficult, but manageable.

Can give a lot of false positives.

If the number of lines cross a particular threshold the overall scan is taking a very long time. Review collected by and hosted on G2.com.

What problems is SonarQube Cloud (formerly SonarCloud) solving and how is that benefiting you?

There are a few code issues that can escape even the most experienced reviewer. The static code scan from Sonar Cloud helps to detect code smells.

Also, we were able to see unreachable code and some security misconfigurations which is not easily visible to a manual review. Review collected by and hosted on G2.com.

SonarQube Cloud (formerly SonarCloud) Overview

What is SonarQube Cloud (formerly SonarCloud)?

SonarQube Cloud (formerly SonarCloud) is a SaaS code analysis tool, designed to detect coding issues in 30+ languages, frameworks, and IaC platforms. The solution also provides fix recommendations leveraging AI with Sonar’s AI CodeFix capability. By integrating directly with your CI pipeline or one of the supported DevOps platforms, your code is checked against an extensive set of rules that cover many attributes of code, such as maintainability, reliability, and security issues, on each merge/pull request.

SonarQube Cloud (formerly SonarCloud) Details
Product Website
Languages Supported
English
Show LessShow More
Product Description

SonarCloud is a fully managed SaaS solution, improving human-developed and AI-assisted code at scale that can be used by dev teams to ensure code quality and security. It heps produce software that is secure, reliable, and maintainable. SonarCloud is free for open-source projects, and is offered as a paid subscription for private projects, priced per line of code.

How do you position yourself against your competitors?

Sonar helps prevent code quality and security issues from reaching production, amplifies developers' productivity in concert with AI assistants, and improves the developer experience with streamlined workflows. Sonar analyzes all code, regardless of who writes it—your internal team or genAI—resulting in more secure, reliable, and maintainable software.


Seller Details
Company Website
Year Founded
2008
HQ Location
Geneva, Switzerland
Twitter
@SonarSource
10,279 Twitter followers
LinkedIn® Page
www.linkedin.com
653 employees on LinkedIn®
Description

Sonar helps prevent code quality and security issues from reaching production, amplifies developers' productivity in concert with AI assistants, and improves the developer experience with streamlined workflows. Sonar analyzes all code, regardless of who writes it—your internal team or genAI—resulting in more secure, reliable, and maintainable software. Rooted in the open source community, Sonar’s solutions support over 30 programming languages, frameworks, and infrastructure technologies. Today, Sonar is used by 7M+ developers and 400K organizations worldwide, including the DoD, Microsoft, NASA, MasterCard, Siemens, and T-Mobile.


London S.
LS
Overview Provided by:

Recent SonarQube Cloud (formerly SonarCloud) Reviews

Verified User
U
Verified UserMid-Market (51-1000 emp.)
5.0 out of 5
"Easy but powerful enough"
SonarCloud is easy to use and integrates seamlessly into existing projects and nearly all CI/CD pipelines. We integrated almost all of our codebase...
Verified User
A
Verified UserSmall-Business (50 or fewer emp.)
5.0 out of 5
"Quality Code Scans on the cloud"
Cloud based and hence no need to install on any server. Integrates into various version control systems using CI/CD pipelines. Has a huge databas...
Somnath N.
SN
Somnath N.Mid-Market (51-1000 emp.)
4.0 out of 5
"SonarCloud -the new generation code security tool"
SonarCloud is one of the top most vulnerabilitie and security tool which inspect bug in code which is used to build pipeline.its has ability to ide...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

SonarQube Cloud (formerly SonarCloud) Media

SonarQube Cloud (formerly SonarCloud) Demo - Overall Projects Summary View
Learn more: https://www.sonarsource.com/products/sonarcloud/
SonarQube Cloud (formerly SonarCloud) Demo - Overview of a Project Analysis
Learn more: https://www.sonarsource.com/products/sonarcloud/
SonarQube Cloud (formerly SonarCloud) Demo - Issues discovered in a project
Learn more: https://www.sonarsource.com/products/sonarcloud/
SonarQube Cloud (formerly SonarCloud) Demo - Detailed view of an issue showing where is the issue and why it is an issue.
Learn more: https://www.sonarsource.com/products/sonarcloud/
Watch this 60-second video to learn more about SonarCloud today!
Play SonarQube Cloud (formerly SonarCloud) Video
Watch this 60-second video to learn more about SonarCloud today!
Get started with SonarCloud in 3 easy steps!
Play SonarQube Cloud (formerly SonarCloud) Video
Get started with SonarCloud in 3 easy steps!
How to do Code Analysis in Minutes with SonarCloud | Automatic Code Analyzer
Play SonarQube Cloud (formerly SonarCloud) Video
How to do Code Analysis in Minutes with SonarCloud | Automatic Code Analyzer
Instant Pull Request Analysis with SonarCloud | Detect Security Vulnerabilities, Bugs & Code Smells
Play SonarQube Cloud (formerly SonarCloud) Video
Instant Pull Request Analysis with SonarCloud | Detect Security Vulnerabilities, Bugs & Code Smells

Official Interactive Demo

SonarQube Cloud (formerly SonarCloud) demo available

Try an interactive demo created by the software seller (right here on G2).

Official Downloads

Answer a few questions to help the SonarQube Cloud (formerly SonarCloud) community
Have you used SonarQube Cloud (formerly SonarCloud) before?
Yes

Video Reviews

14 out of 15 Total Reviews for SonarQube Cloud (formerly SonarCloud)

4.5 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.

SonarQube Cloud (formerly SonarCloud) Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for SonarQube Cloud (formerly SonarCloud)Question

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Verified User in Computer Software
UC
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about SonarQube Cloud (formerly SonarCloud)?

SonarCloud is easy to use and integrates seamlessly into existing projects and nearly all CI/CD pipelines. We integrated almost all of our codebases and used it along with the Sonar cloud extension, which made it more powerful. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Cloud (formerly SonarCloud)?

The downside with sonar is that it requires us to make at least one change in a file to get it scanned. Because of this, sometimes, issues slip into production. Review collected by and hosted on G2.com.

What problems is SonarQube Cloud (formerly SonarCloud) solving and how is that benefiting you?

Linting issues in the code

Security vulnerabilities in the code

It helped us in identifying the issues while development itself and if anything misses Sonar's CICD Integration will take care of this. Review collected by and hosted on G2.com.

Achyut S.
AS
Cloud Architect
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
(Original )Information
What do you like best about SonarQube Cloud (formerly SonarCloud)?

SonarCloud is a cloud-based code analysis service that helps in detecting and fixing bugs, vulnerabilities, code issues, and other quality issues in your code.

One of the best feature i like about it is its integration with various CI/CD tools like GitLab, GitHub etc. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Cloud (formerly SonarCloud)?

As sonar cloud is used on-the-go cloud analysis tool for the code. So, just like any other tool in the market in this particular category, it increases the complexity of the programming for the first-time, and later on some minor maintenance is needed which is fine. Review collected by and hosted on G2.com.

What problems is SonarQube Cloud (formerly SonarCloud) solving and how is that benefiting you?

SonarCloud is benefits me by making my coding experience more enjoyable, productive, and rewarding. For example:

1. Improved code quality

2. Enhanced collaboration

3. Reduced risks and associated costs. Review collected by and hosted on G2.com.

Paulo A.
PA
CTO
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about SonarQube Cloud (formerly SonarCloud)?

The Pull Request Analysis is our best option to keep your code clean of bugs and reduce manual work, increase test coverage and in the overall align the code quality across all your repositories in the most automated way possible by entirely using Github Actions, in our days it has become an indispensable tool for all software engineer team. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Cloud (formerly SonarCloud)?

The software fully does what it says it does; there is nothing to complain about. Fair price, has awesome features, 100% availability. the only added feature I believe it can be added is the ability to produce reports using multiple repos. Review collected by and hosted on G2.com.

What problems is SonarQube Cloud (formerly SonarCloud) solving and how is that benefiting you?

Sona Cloud automates the process of validation on code coverage, bug detection and pattern usage, as well to identify possible security risks, and all of this is done on a Pull Request base making the CI/CD pipelines 10X faster Review collected by and hosted on G2.com.

NS
Sr. Technical Architect
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about SonarQube Cloud (formerly SonarCloud)?

Supports major Cloud Providers/Cloud Platforms and Many popular Programming Languages. We are in the age of the Security left shift. The integration of SonarLint with IDE brings security even when code is pushed to source control. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Cloud (formerly SonarCloud)?

Data Privacy, Data Sovereignty(Some countries/organizations don't allow your data to go outside your network even if it's an analysis result data). Cost is another factor. Sometimes it produces a large number of false positives. Review collected by and hosted on G2.com.

What problems is SonarQube Cloud (formerly SonarCloud) solving and how is that benefiting you?

It helps in remediating the following

1. Vulnerabilities

2. Bugs

3. Security Hotspots

4. Code Smells

There is a difference between traditional and cloud-native security; SonarCloud or SonarQube greatly helps here.

With many developments being cloud-native, there is a need for Clean Code in cloud-native. Review collected by and hosted on G2.com.

Somnath N.
SN
Senior Consultant
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: Organic Review from User Profile
Incentivized Review
What do you like best about SonarQube Cloud (formerly SonarCloud)?

SonarCloud is one of the top most vulnerabilitie and security tool which inspect bug in code which is used to build pipeline.its has ability to identify error in code. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Cloud (formerly SonarCloud)?

although it's has many advantages but some big advantage about it price so as it it the product of Microsoft. so while you run with private devops with external tools you have to purchase its license extra. Review collected by and hosted on G2.com.

What problems is SonarQube Cloud (formerly SonarCloud) solving and how is that benefiting you?

before SonarCloud launched commercially tester ase testing code one by one brunch and it's take lot of time to deliver in production. but after SonarCloud launch it's make tester life easy and bug free Review collected by and hosted on G2.com.

Brallan G.
BG
SRE & DevOps Engineer
Program Development
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about SonarQube Cloud (formerly SonarCloud)?

SonarCloud is one of the indispensable tools to improve the quality of the code and in our continuous integration model gives us that peace of mind in each release to production, also SonarCloud is one of the tools that help us with compliance in some items of our SOC2 certification. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Cloud (formerly SonarCloud)?

Scanning at coding time with the help of the agent is a bit slow in very large projects. And I think a way to globally configure the Long-lived branches pattern should be enabled. Review collected by and hosted on G2.com.

What problems is SonarQube Cloud (formerly SonarCloud) solving and how is that benefiting you?

Improve the code quality in each new release, meet the points related to security and vulnerabilities in the code for our SOC2 certification, developers to be more attentive to details when coding. Review collected by and hosted on G2.com.

Jenna P.
JP
Senior Product Management Specialist
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about SonarQube Cloud (formerly SonarCloud)?

SonarCloud makes it easy to set your own rules when doing a code scan and to notify you so you can stop pushing a product if any of those rules aren't satisfied. It integrates well with other products as well. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Cloud (formerly SonarCloud)?

It integrates well but takes quite a bit of work to get set up. Overall it's not the quickest tool and there are definitely more robust options for scanning out there. Review collected by and hosted on G2.com.

What problems is SonarQube Cloud (formerly SonarCloud) solving and how is that benefiting you?

We have been able to improve the quality of our code with the analysis checks specifically. We have also become more aware of how to improve based on the analytics. Review collected by and hosted on G2.com.

Komal Ashokkumar J.
KJ
Senior SET
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
Aashish H.
AH
Software Developer
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about SonarQube Cloud (formerly SonarCloud)?

Easy code quality and security checks at real time with the usage of plugins is one of the best features that sonarcloud offers. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Cloud (formerly SonarCloud)?

Inability to detect runtime code flaws is something that can be improved. Review collected by and hosted on G2.com.

What problems is SonarQube Cloud (formerly SonarCloud) solving and how is that benefiting you?

Making the code much more efficient by allowing the users to refine their code and remove any bugs Review collected by and hosted on G2.com.

JP
Small-Business(50 or fewer emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about SonarQube Cloud (formerly SonarCloud)?

Integration is easy in CI/CD pipelines

Helped a lot at the time of code push!

UI interface is really good and easy to go!

It helped a lot in code duplicate! Review collected by and hosted on G2.com.

What do you dislike about SonarQube Cloud (formerly SonarCloud)?

It took too long to setup and move forward! Review collected by and hosted on G2.com.

What problems is SonarQube Cloud (formerly SonarCloud) solving and how is that benefiting you?

It helped with static code analysis. Review collected by and hosted on G2.com.