TrustRadius: an HG Insights company

Checkmarx vs. Coverity Static Analysis (SAST)

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Checkmarx

    Score9.1 out of 10
    N/ACheckmarx, an Israeli headquartered company with US offices, provides a suite of application security software delivered via the Checkmarx Software Security Platform. Individual modules and capabilities include Checkmarx Static Application Security Testing, Checkmarx Software Composition Analysis, Checkmarx Interactive Application Security Testing (CxIAST)N/A

    Synopsys Coverity

    Score8.3 out of 10
    N/ASynopsys offers the Coverity static application security testing (SAST) solution, to help users build software that’s more secure, higher-quality, and compliant with standards.N/A
    Pricing
    CheckmarxSynopsys Coverity
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    CheckmarxSynopsys Coverity
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoYes
    Entry-level Setup FeeNo setup feeOptional
    Additional DetailsContact the Synopsys Software Integrity Group (SIG) Sales team at https://www.synopsys.com/software-integrity/contact-sales.html for more detailed pricing information.
    More Pricing Information
    User Ratings
    CheckmarxSynopsys Coverity
    Likelihood to Recommend
    9.0
    (4 ratings)
    9.0
    (1 ratings)
    Usability
    7.0
    (1 ratings)
    -
    (0 ratings)
    User Testimonials
    CheckmarxSynopsys Coverity
    Likelihood to Recommend
    Checkmarx
    If you are going with SAST process or want to improve overall security posture then go for it like integrating it with post deployment steps. If you are more concerned about proactive controls better choose other options such as pee-commit hooks and CI security. Also choose other tools for DAST and API scans.
    Incentivized
    Read full review
    Synopsys
    Best suits for large scale and dynamic development environment. It may be best tool if you want to release your apps with less TAT. However if you have a CRM tool which is COTS product it can offer little help. Even then you should be familiar with what features of Coverity Static Analysis (SAST) are helpful for your development environment
    Incentivized
    Read full review
    Pros
    Checkmarx
    • Detects security vulnerabilities in source code with accuracy and detail.
    • Integrates seamlessly with CI/CD pipelines, IDEs, and repositories.
    • Provides clear reports and actionable fix recommendations for developers.
    Incentivized
    Read full review
    Synopsys
    • It can provide security scanning dashboard
    • Help detect vulnerabilities and recommend remediation
    • Integration of devsecops helps speed up release cycles
    Incentivized
    Read full review
    Cons
    Checkmarx
    • Scan duration
    • False positives
    • Integration with other tools like Jenkins comes with some inconveniences.
    Incentivized
    Read full review
    Synopsys
    • Coverage of integration with other security tools can be improved
    • Customisation of dashboard to enable customer choice of tracking
    • Showcase devsecops progressive tasks from SLA and violation from code scanner perspective
    Incentivized
    Read full review
    Usability
    Checkmarx
    Their API based customizations which I leveraged to create an ASPM package, which is developer friendly and can extend above the dashboard features, other ones are UI which is great and feels clutter free. Menu and navigation is also good so as support. Only drawback is sometimes scan takes longer which I feel so can be reduced
    Incentivized
    Read full review
    Synopsys
    No answers on this topic
    Alternatives Considered
    Checkmarx
    Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into our development process, offering faster scans and more useful suggestions for fixing problems
    Incentivized
    Read full review
    Synopsys
    Coverity Static Analysis (SAST) has wide coverage in terms of Owasp Top 10 vulnerabilities, various types of languages, backward integration. While other tools offer similar experience of code scanning, coverity helps in pointed recommendations for quick closure of vulnerabilities. The historical analysis of vulnerabilities is a good value add in understanding which type of code and which language is better in improving cyber security maturity.
    Incentivized
    Read full review
    Return on Investment
    Checkmarx
    • Improved ability to provide high level of IA confidence
    • Improved confidence in application-level security
    Incentivized
    Read full review
    Synopsys
    • Helped reduce efforts of development team avoiding rework
    • Increased security maturity
    • Increased efficiency of the teams
    Incentivized
    Read full review
    ScreenShots

    Synopsys Coverity Screenshots

    Screenshot of Coverity works with the Code Sight™ IDE plugin, enabling developers to find and fix security and quality defects as they write code.Screenshot of Coverity provides broad security and quality checker support for 21 languages and over 70 frameworks.