Best Software for 2025 is now live!
Save to My Lists
Paid
Claimed

SonarQube Server (formerly SonarQube) Reviews & Product Details

Mohit S.
MS
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about SonarQube Server (formerly SonarQube)?

I like everything about SonarQube, It is best tool to make your code bug free and optimised. It analysis your code very fast and provide proper path of the issue in your code and also provide best suggestion to how to solve it. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

SonarQube is not snychronze with the IDE, from where I am solving the issues. Whenever I solve an issue I have to re-run the sonarQube to check whether the issue is solved or not. It is little time consuming. Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

SonarQube is helping me to improve my code performance and make it bug free, It also suggest best coding practices which helps to increase my knowledge and learn standard coding. Review collected by and hosted on G2.com.

SonarQube Server (formerly SonarQube) Overview

What is SonarQube Server (formerly SonarQube)?

SonarQube Server (formerly SonarQube) is a self-managed open-source platform that helps developers create code devoid of quality and vulnerability issues. By integrating seamlessly with the top DevOps platforms in the Continuous Integration (CI) pipeline, SonarQube Server continuously inspects projects across multiple programming languages, providing immediate status feedback while coding. SonarQube Server’s quality gates become part of your release pipeline, displaying pass/fail results for new code based on quality profiles you customize to your company standards. Following Sonar’s Clean as You Code methodology guarantees that only software of the highest quality makes it to production. At its core, SonarQube Server includes a static code analyzer that identifies bugs, security vulnerabilities, hidden secrets, and code smells. The platform guides you through issue resolution, fostering a culture of continuous improvement. SonarQube Server's comprehensive reporting is a valuable tool for dev teams to monitor their codebase's overall health and quality across multiple projects in their portfolio. With SonarQube Server, you can achieve a state of Clean Code, leading to secure, reliable, and maintainable software. Sonar is the only solution combining the power of industry-leading software quality analysis with static application security testing (SAST) and real-time coding guidance in the IDE (with SonarQube for IDE; formerly SonarLint) to meet the DevOps and DevSecOps demand of putting agility, automation, and security in the hands of developers. Further accelerate DevOps continuous integration by helping developers find and fix issues in code before the software testing stage, reducing the churn of finding, fixing, rebuilding, and retesting your app. With over 5,000 Clean Code rules, SonarQube Server analyzes 30+ of the most popular programming languages, including dozens of frameworks, the top DevOps platforms (GitLab, GitHub, Azure DevOps, and Bitbucket, and more), and the leading infrastructure as code (IaC) platforms. SonarQube Server is the most trusted static code analyzer used by over 7 million developers and 400,000 organizations globally to clean over half a trillion lines of code.

SonarQube Server (formerly SonarQube) Details
Product Website
Languages Supported
English
Show LessShow More
Product Description

SonarQube is a code quality and vulnerability solution for development teams that integrates with CI/CD pipelines to ensure the software you produce is secure, reliable, and maintainable.

How do you position yourself against your competitors?

Sonar helps prevent code quality and security issues from reaching production, amplifies developers' productivity in concert with AI assistants, and improves the developer experience with streamlined workflows. Sonar analyzes all code, regardless of who writes it—your internal team or genAI—resulting in more secure, reliable, and maintainable software.


Seller Details
Company Website
Year Founded
2008
HQ Location
Geneva, Switzerland
Twitter
@SonarSource
10,279 Twitter followers
LinkedIn® Page
www.linkedin.com
653 employees on LinkedIn®
Description

Sonar helps prevent code quality and security issues from reaching production, amplifies developers' productivity in concert with AI assistants, and improves the developer experience with streamlined workflows. Sonar analyzes all code, regardless of who writes it—your internal team or genAI—resulting in more secure, reliable, and maintainable software. Rooted in the open source community, Sonar’s solutions support over 30 programming languages, frameworks, and infrastructure technologies. Today, Sonar is used by 7M+ developers and 400K organizations worldwide, including the DoD, Microsoft, NASA, MasterCard, Siemens, and T-Mobile.


London S.
LS
Overview Provided by:

Recent SonarQube Server (formerly SonarQube) Reviews

KB
Kevin B.Mid-Market (51-1000 emp.)
4.0 out of 5
"Effective Code Quality Management with SonarQube"
What I love about SonarQube is how it digs deep into my code and finds hidden issues which are not as obvious when writing the code, especially bug...
RS
Rekha S.Mid-Market (51-1000 emp.)
4.0 out of 5
"Comprehensive Code Quality Tool"
SonarQube has a great way of examining code quality as a whole. It has the capability of discovering mistakes, threats, as well as unfavorable prac...
Mukesh Kumar R.
MR
Mukesh Kumar R.Small-Business (50 or fewer emp.)
4.5 out of 5
"Essential for clean code"
Simple deployment. Very easy installing is practiced particularly on Kubernetes using YAML formats. Moreover, integration with GitHub by means of G...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

SonarQube Server (formerly SonarQube) Media

SonarQube Server (formerly SonarQube) Demo - Screenshot of Application Status
.
SonarQube Server (formerly SonarQube) Demo - Screenshot of Security Report
.
SonarQube Server (formerly SonarQube) Demo - Screenshot of Portfolio Overview
.
SonarQube Enterprise Solution Demo
Play SonarQube Server (formerly SonarQube) Video
SonarQube Enterprise Solution Demo

Official Interactive Demo

SonarQube Server (formerly SonarQube) demo available

Try an interactive demo created by the software seller (right here on G2).

Official Downloads

Answer a few questions to help the SonarQube Server (formerly SonarQube) community
Have you used SonarQube Server (formerly SonarQube) before?
Yes

89 out of 90 Total Reviews for SonarQube Server (formerly SonarQube)

4.4 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.

SonarQube Server (formerly SonarQube) Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for SonarQube Server (formerly SonarQube)Question

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
KB
Senior DevOps Engineer
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about SonarQube Server (formerly SonarQube)?

What I love about SonarQube is how it digs deep into my code and finds hidden issues which are not as obvious when writing the code, especially bugs and security problems, across different programming languages. It hooks up smoothly with my CI/CD pipelines, which means I can keep an eye on code quality at every step. The reports it generates are super detailed and really help the team see where we can improve. Plus, you can customize the rules and use tons of plugins to make it work just how you need it. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

The one thing that I dislike is how much it can slow things down when you're working with big projects. The scans can take a while, which sometimes messes with our workflow, and we cannot use parallel analysis as we are on the Developer license since the Enterprise is too costly for us. Also, setting it up and getting everything configured right can be a bit of a headache and takes some time. Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

SonarQube is a lifesaver for keeping our code clean, secure, and easy to maintain. It’s always on the lookout, catching bugs, code smells, and security issues early in the game. This means our codebase stays solid and we don’t end up with a pile of technical debt.

For me and the team, it’s been a game-changer. We get automatic code reviews and detailed feedback that helps us catch issues before they cause any real trouble. The insights we get from the quality metrics push us to keep improving our code. Integrating SonarQube into our CI/CD pipelines has really smoothed out our quality checks, making sure we keep high standards from start to finish. All in all, it’s made our software better and we feel way more confident in what we deliver. Review collected by and hosted on G2.com.

Stanley S.
SS
Embedded Engineer
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about SonarQube Server (formerly SonarQube)?

Our development process is helped alot by SonarQube as it will detect some bugs such as running out of memory, or simple error that we might not see at the first time. Our team is happy to use the product. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

Getting it to start is a long process. We are having some trouble trying to understand how sonarqube judges our code. As our team is using it for the embedded environment, some suggestions (such as atomic implementations etc) are not really applicable to us. At first we were frustated as it always suggested that our code is wrong, but now we can find a way to silence it. Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

It can be integrated easily (after we understand) to our Gitlab server. We can have the analysis out of the box immediately when we are pushing the commits. Review collected by and hosted on G2.com.

RS
Software Developer
Computer Software
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: Seller invite
Incentivized Review
What do you like best about SonarQube Server (formerly SonarQube)?

SonarQube has a great way of examining code quality as a whole. It has the capability of discovering mistakes, threats, as well as unfavorable practices found in different programming languages to maintain superior coding norms. It generates detailed dashboards and reports which give specific views allowing for developing incrementally in addition to keeping code clean and gracious throughout its life span. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

SonarQube's complicated setup and configuration process remains trail and discouraging being time consuming for newbies. In addition one may also suffer from performance degradation caused by big code bases as well as when they discover that some extra skills need payment before using them; hence would be so costly particularly among little groups or small enterprises. Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

SonarQube focuses on addressing the critical issue of keeping code desirable and secure thereby automating code reviews, identifying potential issues earlier on and ensuring conformity to coding standards. Instead of taking a reactive approach, it helps reduce technical debts, fosters software reliability, simplifies development as it eventually saves on time and resources. Review collected by and hosted on G2.com.

Murtadha Bazli T.
MT
Senior Embedded System Engineer
Small-Business(50 or fewer emp.)
Validated Reviewer
Review source: Seller invite
Incentivized Review
What do you like best about SonarQube Server (formerly SonarQube)?

I use SonarQube mainly for analyzing C, C++ and Python programming languages, and that's why I need a SonarQube developer license. The $160 I spent for a year is really worth it. Think of SonarQube as your peer review, friend and supervisor for your software development.

Analyzing C/C++ is really easy and not tied to an IDE. I simply host SonarQube in Docker, build my software with build-wrapper and analyze it with Sonar-scanner. The analysis results then appear in the SonarQube dashboard.

I use SonarQube both at work and at home for my personal project. Due to the affordable price and ease of use, I have been loyal to SonarQube for 3 years now.

Sonar also has responsive customer support, and I mainly contact them to get a new license due to an issue with my Docker image. The response consistently within 1-2 days, and I always communicate via email. No website to report or form to fill out, which for me is convenience. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

I develop embedded software that adheres to MISRA C/C++, and SonarQube does have some MISRA rules, but not all of them are implemented. I really love to see SonarQube being able to adopt all these rules.

A few times I have found alternatives to SonarQube for this reason, but since other tools are expensive, tied to an IDE and the learning curve is unknown (unlike SonarQube, we only need 3 steps to analyze the code), I keep coming back to SonarQube. Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

SonarQube became my main platform for consolidating unit test results, code coverage and static code analysis. SonarQube Dashboard becomes my benchmark for software development maturity.

Other static code analyzers can also report errors, but unlike SonarQube, it shows very nice examples of compliant and non-compliant code. This has helped me a lot throughout my software development career. Review collected by and hosted on G2.com.

Alan R.
AR
R&D Manager
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: Seller invite
Incentivized Review
What do you like best about SonarQube Server (formerly SonarQube)?

Identification of coding issues across whole codebases, while providing a manageable way to gradually improve the code quality over time by enforcing that new code is of good quality. Developers can be gently guided to better practices without having to solve thousands of code smells all at once. We can refactor code as we work in different areas without introducing new risk of regressions.

Easy to setup and manage and pretty hands off. It integrates well with Azure DevOps and our pull request and CI workflows. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

Some churn recently in how Sonarqube manages quality gates and what the bar is.

We have a number of limitations in our analysis, particularly in collecting code coverage information. Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

Sonarqube provides a level of security review to our code changes.

Sonarqube helps developers maintain a high quality bar in the code they write, provides neutral guidance and learning without code reviewers having to nitpick every commit. Developers are guided to improve the code they touch, gradually helping improve the quality of older legacy codebases without making large changes and introducing regression risk. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about SonarQube Server (formerly SonarQube)?

Being able to filter issues and assign them to different team members allows each developer to focus on high-priority issues. SonarQube allows you to enable to disable specific rules, and to set the severity of each rule. This further help to prioritize the issues needing attention.

When a developer determines that a particular issue should NOT result in a code change, they can mark that issue as "won't fix" and enter an explanation. This helps provide detailed reports.

SonarQube also provides clear, high-level overviews of the status of your software projects (for managers), along with reports (for customers). This helps take much of the communication burden off of the development team. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

Like any static analysis tool, there are occasional false-positives. And depending on your code, there may be issues flagged as "problems" which are really just stylistic differences or deviations from best practices.

But it is fairly easy to mitigate these issues. False-positives need to be reviewed, but the detailed analysis provided by SonarQube (including traces through earlier statements showing how the issue was identified) help with the review. As for issues that are merely stylistic differences, these can be given a lower severity rating or even eliminated by customizing the underlying rules. Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

Identifies code quality issues. Helps us improve the reliability of our applications and reduce our technical support burden. Also helps us mature the code base, which makes subsequent development faster and easier.

Identifies code security issues. Helps us head off vulnerability crises and the need to develop hotfixes.

Reports the status of unresolved issues and unit test code coverage per project. Helps us track technical debt.

Reports the status of each project or application (set of projects) for consumption by customers. Meets requirements imposed by some customers, allowing certain sales to go through that would otherwise be blocked. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
AH
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about SonarQube Server (formerly SonarQube)?

- We are using a self hosted SonarQube server - hosting and upgrading our instance is a relatively painless process. The online documentation is clear and easy to follow

- The SonarQube scanner integrated easily into our existing Bitbucket and Cloud Build CI/CDs

- When comparing the findings with other SAST tooling, out-of-the-box SonarQube analysis had a low false positive rate, yet found extensive legitimate security/code quality issues

- Very happy with the speed of analysis, completes in only a few minutes on large repos (an order of magnitude faster than certain other SAST services)

- Surprised that language support is actually slightly better than documented - we were able to sucessfully analyze projects with older versions of .NET framework (4.5 and 4.0) than indicated in the documenation

- The triage and review process is easy for individual teams to execute on a regular basis

- The WEB API is well documented and enabled automating steps around user maintenance

- Bitbucket OAuth worked seamlesses to onboard users

- Installing additional plugins is also easy - we use Dependency-Check to add SCA to projects

- Bug fixes and features added to each new release are well documented, I appreciate being able to review all changes on the sonarsource atlassian page (and not just rely on the high-level marketing notes) Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

- While SonarQube is a SAST tool, better support for SCA would be beneficial. The Dependency-Check plugn does not integrate well into the existing triage/remediation process.

- Other tooling does a better job of proving a high level overview of users and their productivity, ie. # of assigned open issues by engineer, # of fixed issues by engineer, etc. Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

SonarQube enables us to perform code and security analysis and comply with our internal security procedures, with clear visibilty into the process via it's clean dashboards. SonarQube's bug and code smell detection has also reduced our technical debt and improved overall codebae quality. Review collected by and hosted on G2.com.

Mukesh Kumar R.
MR
Cyber Security Researcher
Small-Business(50 or fewer emp.)
Validated Reviewer
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about SonarQube Server (formerly SonarQube)?

Simple deployment. Very easy installing is practiced particularly on Kubernetes using YAML formats. Moreover, integration with GitHub by means of GitHub actions is fluent because it enables developers to conduct their scans, therefore, receiving their notifications once they complete them. On the other side when it comes to flexibility, SonarQube is unmatched. It offers so much when you want to configure it letting you even prevent vulnerability detection until pull request merges are halted for example while at the same time providing a good way of looking at detected exploitation points - such as their exact location that has been pointed out about them. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

This tool is exclusively for Static Application Security Testing , other tools provides integrating Dynamic (DAST) and Static (SAST). Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

Improve compliance and risk management, reduce the cost of management while enhancing the business process results. Review collected by and hosted on G2.com.

Ethan B.
EB
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about SonarQube Server (formerly SonarQube)?

Quick, easy way to see major issues with code, duplications, security issues, etc. Easy to setup and maintain. Support has been very quick and helpful when I have needed them. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

While it supports a decent ammount of prgoramming languages, it definitely doesn't support all of them. Specifically Dart projects in Flutter which we use for mobile app developement (though apparently there are plans to add it in the future). Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

It helps us to make sure we are not duplicating code, using depricated libraries and methodes, and helps to identify any security issues. Review collected by and hosted on G2.com.

Kelli K.
KK
Senior Software Engineer
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about SonarQube Server (formerly SonarQube)?

We have implemented it across our org, and it has been awesome. Code coverage everywhere has gone up, more bugs are being fixed, and there is more visibility into team's tech debt. Review collected by and hosted on G2.com.

What do you dislike about SonarQube Server (formerly SonarQube)?

The one downside to the new versions is lack of support for older node versions. Our monolith is still using some old versions (which of course we need to work on upgrading!), keeping us from upgrading sonarqube. Review collected by and hosted on G2.com.

What problems is SonarQube Server (formerly SonarQube) solving and how is that benefiting you?

It is helping us increase code coverage across our whole organization, which is making for better code all around. Review collected by and hosted on G2.com.