SonarQube Server vs. VMware AppDefense (discontinued)

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
SonarQube Server
Score 9.5 out of 10
N/A
SonarQube is a code quality and vulnerability solution for development teams that integrates with CI/CD pipelines to ensure the software you produce is secure, reliable, and maintainable.
$720
per year per installation
VMware AppDefense (discontinued)
Score 4.0 out of 10
N/A
VMware AppDefense was a hypervisor-native workload protection platform for enterprise virtualization and security teams, used to deliver a secure virtual infrastructure and simplify micro-segmentation planning by providing application visibility, reputation scoring, and security. The product is discontinued, and no longer available.N/A
Pricing
SonarQube ServerVMware AppDefense (discontinued)
Editions & Modules
Community
Free
Developer EDITION
starting at $720
per year per installation
Enterprise EDITION
Contact sales for pricing
per year per installation
Data Center EDITION
Contact sales for pricing
per year per installation
No answers on this topic
Offerings
Pricing Offerings
SonarQube ServerVMware AppDefense (discontinued)
Free Trial
YesYes
Free/Freemium Version
YesNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeOptional
Additional Details
More Pricing Information
Community Pulse
SonarQube ServerVMware AppDefense (discontinued)
Best Alternatives
SonarQube ServerVMware AppDefense (discontinued)
Small Businesses
GitLab
GitLab
Score 8.7 out of 10
GitLab
GitLab
Score 8.7 out of 10
Medium-sized Companies
Veracode
Veracode
Score 8.7 out of 10
Veracode
Veracode
Score 8.7 out of 10
Enterprises
Veracode
Veracode
Score 8.7 out of 10
Veracode
Veracode
Score 8.7 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
SonarQube ServerVMware AppDefense (discontinued)
Likelihood to Recommend
8.9
(0 ratings)
8.4
(0 ratings)
Usability
9.1
(0 ratings)
-
(0 ratings)
Support Rating
9.0
(0 ratings)
8.5
(0 ratings)
User Testimonials
SonarQube ServerVMware AppDefense (discontinued)
Likelihood to Recommend
Scenarios where SonarQube is well suited:
  1. Large codebase: The tool's static analysis capabilities can help teams quickly identify and fix bugs, vulnerabilities, and code smells in large codebases.
  2. Compliance and security: The tool can check the code against industry standards or regulations, such as OWASP and CWE, and identify any issues that need to be addressed.
  3. Agile development: SonarQube can be integrated with CI/CD pipelines allowing teams to continuously monitor and improve code quality throughout the development process.
  4. Teams using multiple languages: Teams that use multiple programming languages can benefit from using SonarQube, as the tool supports a wide range of languages and can be integrated with a variety of development tools.
Scenarios where SonarQube may be less appropriate:
  1. Small codebase: Organizations with a small codebase may not see the full benefits of using SonarQube, as the tool's static analysis capabilities may be overkill for a smaller codebase.
  2. Limited resources: Organizations with limited resources may find it difficult to set up and configure SonarQube, as the tool can be complex and may require specialized expertise.
  3. Limited integration: Organizations that use development tools or IDEs that are not supported by SonarQube may find it difficult to integrate the tool into their existing development workflow.
  4. Limited scalability: Large organizations with millions of lines of code may find SonarQube's performance and scalability to be an issue. It may take longer for the analysis to finish and the results may not be as accurate.
Read full review
I believe that the product is priced well enough that a small business that is concerned with data center security can justify using the product. My environment hasn't scaled up very far yet, but I am a little concerned that when we get to a certain point, the management console will get full and be more difficult to track. An enterprise customer might see that as a problem.
Read full review
Pros
  • Generating code quality report
  • Calculates junit coverage of the codebase very efficiently and precisely
  • Highlights the bugs and vulnerabilities in our codebase
  • Informs the user of the improvements which can be done to the code to make it cleaner
  • SonarQube also suggests remediation and resolution of the problems it highlights
Read full review
  • Provides detailed process and command-line information.
  • Provides visibility into what connections are being made to/from a specific server/service.
  • Ability to group multiple VMs into service groups for proper correlation.
Read full review
Cons
  • It doesn't provide automatic pull request with fixes
  • It doesn't provide insights about the libraries of the projects
  • The administration management user interface could be simplified
  • It doesn't provide an order to fix issues, like archives with more and frequent commits have top priority
Read full review
  • Steep learning and a lot of moving pieces
  • Very new product and Carbon Black is the only 3rd party vendor that can integrate
  • Limited information and training. We've never been to VMworld but it was barely mentioned at the VMUG UserCons we've attended
Read full review
Usability
It can improve in some user experience and usability parts, like the code view and the way we assign issues it's a bit hidden and not highlighted
Read full review
No answers on this topic
Support Rating
We we easily able to integrate the SonarQube steps into our TFS process via the Microsoft Marektplace, we didn't have the need to call SonarQube support. We've used their online documentation and community forum if we ran into any issues.
Read full review
Their support chat system is very responsive, and if they don't resolve it quickly with that method, then they will remote in and help that way.
Read full review
Alternatives Considered
SonarQube identifies significant more thing compared to the built-in suggestions in IntelliJ IDEA. The suggestions how to correct issues are also a lot better with SonarQube. IntelliJ IDEA provides great refactoring support to make it easy to refactor the code to solve issues. We use these tools together and they really complement each other.
Read full review
We were advised that vShield will be retired and its functionality was being integrated with App Defense. Carbon Black is or was the only AV vendor that integrated with it. A priority for us was to use a VMware supported solution. Sophos Intercept X was creating their own module. Trend Micro Deep Security didn't have any plans in place to move from vShield.
Read full review
Return on Investment
  • Positive ROI from the standpoint of flagging several issues that would have otherwise likely been unaddressed and caused more time to be spent closer to launch
  • Slightly positive ROI from time-saving perspective (it's an automated check which is nice, but depending on the issues it finds, can take developers time to investigate and resolve)
Read full review
  • For the cost of the upgrade to vSphere Platinum compared to the costs we were already paying for vSphere Enterprise Plus with Operations Management was comparable. It made sense to upgrade and with that, we received the added features of AppDefense.
Read full review
ScreenShots

SonarQube Server Screenshots

Screenshot of Application Status.Screenshot of Portfolio Overview.Screenshot of Taint Analysis.