
Was required by some of our customers, allowed us to scan code and develop higher confidence in security robustness Review collected by and hosted on G2.com.
Huge number of false positives that needed to be explained away, did not deal well with 3rd party libraries Review collected by and hosted on G2.com.
The world needs something like Veracode. Cyberthreats are too complex and are changing too fast for average software developers to keep up with all the necessary expertise and techniques. Separating cybersecurity testing into a standalone, purpose-built service simply makes sense. I appreciate that Veracode is, at least in theory, attempting to be that platform. Review collected by and hosted on G2.com.
Unfortunately, Veracode hasn't actually found the formula for success yet. The interface is clunky and disjointed, the documentation is confusing, and customer support takes literally weeks or months to respond to requests. It's a classic case of an excellent idea with lackluster execution. Review collected by and hosted on G2.com.
Veracode combines human and automated scanning to offer a really robust report. Reports are actionable, remediation is automated, and executive summaries are available on demand. Review collected by and hosted on G2.com.
Veracode today is robust for static scans, but limited to specific mobile builds and Firefox for dynamic scans. This makes analyzing Saas apps that do not support Firefox particularly challenging. Review collected by and hosted on G2.com.
The idea. I'm a big evangelist of clean code and standards. Review collected by and hosted on G2.com.
Everything:
- Scans inaccurate
- Slow
- Outdated UI
- Not user friendly
- Terrible HTTP API for automation
- Bad customer support
- One of our applications, only 1 out of hundreds issues turns out to be true. Review collected by and hosted on G2.com.