Product Avatar Image

Checkmarx

Show rating breakdown
73 reviews
  • 3 profiles
  • 8 categories
Average star rating
4.3
#1 in 1 categories
Grid® leader
Serving customers since
2006

Checkmarx Solutions

Discover ready-made solutions that bring related products, reviews, and resources together in one place.

Profile Filters

All Products & Services

Product Avatar Image
Checkmarx

49 reviews

Identify software security vulnerabilities & fix them

Product Avatar Image
ZAP by Checkmarx

14 reviews

ZAP by Checkmarx, formerly known as Zed Attack Proxy , is a leading open-source web application security scanner designed to help developers, testers, and security professionals identify vulnerabilities in web applications. Actively maintained by a global community, ZAP offers both automated and manual testing capabilities, making it suitable for users with varying levels of security expertise. Key Features and Functionality: - Automated Security Scanning: ZAP provides simple, single-click automated scanning, enabling users to identify security flaws with ease. - Active and Passive Scanning: Utilizes both passive and active scanning techniques to uncover a wide range of security vulnerabilities. - Advanced User Controls: Offers tools like manual interception, fuzzing, and forced browsing for thorough penetration testing. - CI/CD Integration: Seamlessly integrates with Continuous Integration/Continuous Deployment pipelines, automating security testing within development workflows. - Cross-Platform Support: Compatible with Linux, Windows, and macOS operating systems. Primary Value and Problem Solved: ZAP by Checkmarx addresses the critical need for accessible and effective web application security testing. By offering a free, open-source solution with both automated and manual testing capabilities, ZAP empowers organizations to identify and remediate vulnerabilities early in the development lifecycle. Its integration with CI/CD pipelines ensures that security becomes an integral part of the development process, reducing the risk of security breaches and enhancing overall application security.

Product Avatar Image
Checkmarx Codebashing

10 reviews

Raising AppSec awareness simply cannot be thought of as a distinct step in the SDLC. It's all about inserting awareness into every step of the SDLC in a manner that actually fuels faster releases. Codebashing does exactly that - Through the use of just-in-time training, ongoing communication, and fun engagement, security managers cultivate a culture of software security that empowers developers to think and act securely in their day-to-day work.

Profile Name

Star Rating

42
28
2
1
0

Checkmarx Reviews

Review Filters
Profile Name
Star Rating
42
28
2
1
0
Roushan J.
RJ
Roushan J.
Senior Application Security Engineer | AI-Assisted Penetration Testing | API & LLM Security | Threat Modeling | DevSecOps
09/01/2026
Validated Reviewer
Review source: Organic

Effective SAST with Minimal false Positives

I use Checkmarx for SAST code review, and it helps me identify security vulnerabilities early in the software development lifecycle, saving a lot of money by catching them in the code for each commit. I really like how it identifies security vulnerabilities, especially getting rid of common OWASP top 10 vulnerabilities like SQL injection and Cross-Site Scripting. I'm impressed that it can also detect business logic vulnerabilities, such as unauthorized access control, earlier in the development process. I also appreciate that it reports IDOR vulnerabilities from the OWASP top 10. The initial setup was easy, and I switched to Checkmarx from Fortify mainly because it provides less noise from false positives and offers deeper coverage of the OWASP top 10.
Poorna Srinivasa Rao T.
PT
Poorna Srinivasa Rao T.
Sr. Consultant
08/30/2026
Validated Reviewer
Review source: G2 invite
Incentivized Review

Poorna's Checkmarx Review

Checkmarx is a solid application security tool that helps identify security vulnerabilities throughout the software development lifecycle, including with its AI features. Its ability to alert developers to application flaws even before the code moves to production is especially appreciable. The UI is easy to navigate and delivers fast performance, and its ability to integrate with multiple repos and CI/CD pipelines is great. Although the pricing is a bit higher, it still feels worth it. Support is fair enough.
Nitesh A.
NA
Nitesh A.
Senior Consultant at Capgemini | 7x Salesforce Certified | Application Architect | CRM Technical/Functional Consultant
08/07/2026
Validated Reviewer
Review source: G2 invite

Automated Checkmarx Scans Keep Us Ahead of Key Vulnerabilities

Provision to automate scan runs is now available. Scan results are well structured and comments are well documented. Easy for developers to understand and fix. Can be integrated with stakeholder reports. Good UI and support

About

Contact

HQ Location:
Paramus, NJ

Social

@Checkmarx

What is Checkmarx?

Checkmarx is the leader in agentic application security, delivering enterprise-grade protection while helping organizations lower engineering costs and accelerate development velocity. The Checkmarx One platform scans trillions of lines of code each year, enabling companies to cut vulnerability density by more than half. Autonomous security agents continuously detect and counter AI-driven threats across the software development lifecycle, delivering prevention-first protection for legacy, modern, and AI-generated code at enterprise scale.

Details

Year Founded
2006