Apache JMeter vs. Veracode

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
JMeter
Score 8.5 out of 10
N/A
JMeter, from Apache, is a load and performance testing tool.N/A
Veracode
Score 8.5 out of 10
Mid-Size Companies (51-1,000 employees)
Veracode is an application security platform that performs five types of analysis; static analysis, dynamic analysis, software composition analysis, interactive application security testing, and penetration testing. Veracode offers on-demand expertise and aims to help companies fix security defects.N/A
Pricing
Apache JMeterVeracode
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
JMeterVeracode
Free Trial
NoYes
Free/Freemium Version
YesYes
Premium Consulting/Integration Services
NoYes
Entry-level Setup FeeNo setup feeNo setup fee
Additional DetailsDeveloper pricing options available
More Pricing Information
Community Pulse
Apache JMeterVeracode
Considered Both Products
JMeter

No answer on this topic

Veracode
Chose Veracode
One Stop solution for security evaluation. Others were not so accurate and covering all the scenarios we were looking to plug.
Top Pros
Top Cons
Features
Apache JMeterVeracode
Load Testing
Comparison of Load Testing features of Product A and Product B
Apache JMeter
7.6
24 Ratings
10% below category average
Veracode
-
Ratings
End to end performance management9.021 Ratings00 Ratings
Integrated performance data8.722 Ratings00 Ratings
Deployment model flexibility6.721 Ratings00 Ratings
Real time monitoring8.821 Ratings00 Ratings
Automated anomaly detection4.818 Ratings00 Ratings
Best Alternatives
Apache JMeterVeracode
Small Businesses

No answers on this topic

GitLab
GitLab
Score 8.9 out of 10
Medium-sized Companies
ReadyAPI
ReadyAPI
Score 8.1 out of 10
GitLab
GitLab
Score 8.9 out of 10
Enterprises
ReadyAPI
ReadyAPI
Score 8.1 out of 10
GitLab
GitLab
Score 8.9 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Apache JMeterVeracode
Likelihood to Recommend
8.2
(39 ratings)
9.4
(127 ratings)
Likelihood to Renew
8.6
(12 ratings)
8.1
(7 ratings)
Usability
9.0
(1 ratings)
7.3
(27 ratings)
Availability
1.0
(1 ratings)
9.1
(1 ratings)
Performance
8.0
(1 ratings)
6.4
(1 ratings)
Support Rating
10.0
(1 ratings)
8.0
(66 ratings)
Online Training
1.0
(1 ratings)
-
(0 ratings)
Implementation Rating
-
(0 ratings)
7.3
(2 ratings)
Configurability
-
(0 ratings)
6.4
(1 ratings)
Ease of integration
-
(0 ratings)
5.5
(1 ratings)
Product Scalability
-
(0 ratings)
7.3
(1 ratings)
Vendor post-sale
-
(0 ratings)
8.9
(2 ratings)
Vendor pre-sale
-
(0 ratings)
8.2
(1 ratings)
User Testimonials
Apache JMeterVeracode
Likelihood to Recommend
Apache
JMeter is well suited for Java applications where the user can script the scenario once and make changes to accommodate for as many numbers of users for load test execution. The image and selection of any files or exporting files scenario is handled well.
It is less appropriate to test Ajax applications where it is required to script click per use.
Read full review
Veracode
Within our organization it is clear that when a codebase is available, and in a language that Veracode supports, the use of Veracode (with a particular focus to the static scanning platform) is a great suggestion. The depth of information it can provide with respect to security flaws is valuable, with very little setup required from the developers. When a codebase is unavailable, say in the instance of third-party applications for which you are creating extensions or some form of module, then static code scanning is not an option but even then dynamic scanning (DAST) may prove to be helpful, though potentially less so.
Read full review
Pros
Apache
  • Easy of use - in generate load like HTTP requests, and processing/analyzing the responses. No coding is necessary at the basic level, just need to understand load testing and the infrastructure being tested.
  • Automatic management of things like cookies to help with session state support - so you don't specifically have to worry about it or handle it
  • Lots of testing/configuration options to suit your needs in making the right load generation (sampling requests), and analyzing the results, including any pre and post processing of the results first. Things like the Beanshell/BSF pre/post processors, response assertion, regular expression extractor, XPath extractor, CSV data set config
  • There is a JMeter cloud service called BlazeMeter that I think would be useful for those that need to scale up high load without provisioning their own systems. I've not personally tried it though, but I recently attended a meetup presentation that highlighted nice useful features that BlazeMeter provides. One should evaluate the service if they are considering JMeter and need to expand beyond existing hardware resources.
Read full review
Veracode
  • The pipeline scan is a very fast way to scan code and inform developers if a new flaw is introduced by their pull requests.
  • Upload & Scan provides an in-depth analysis of the codebase, which features like reporting being made easy.
  • SCA Scans help us not only identify the vulnerabilities but also in helping fix them and in identifying if our application is using that part of the vulnerable library or not.
  • Veracode is very easy to integrate into the CI/CD pipelines (especially Jenkins)
Read full review
Cons
Apache
  • Jmeter requires many tweaks with respect to its configuration file and thread properties. users need to edit theses files themselves. There could be some interface where we can edit this fields.
  • Jmeter cannot handle more threads and hangs up when we increase the number of threads. This causes lot of inconvenience. In these situations, user can be notified that such change would be lead to slow performance so that user can do as required. The same appears when we try to view huge files on graph listener.
  • Jmeter should optimize the read and write access to output csv since it acts as overhead to the I/O performance. This affects our test results for the application which we are testing.
Read full review
Veracode
  • MPT Results should be segmented from DAST/SAST results.
  • MPT Reports should include more information on scoping and testing dates as generally provided by accounting firms conducting similar tests.
  • Vulnerability readouts should not be so hidden in the platform (It shouldn't take as many clicks to get to and view).
Read full review
Likelihood to Renew
Apache
Price, Wiki and user sharing. Having access to the information provided by the developers and other open source providers is key for me. The ability to share information and get answers directly is very important to success in software testing. And the price of this product currently is amazing. Too many companies charge way too much money for products that are far behind in their value and pertinence
Read full review
Veracode
At this time, and we just renewed a month ago, I dont see any products out there overall that can offer what Veracode does. Yes, its not cheap by any means, but for the money its the best application security scanning tool out there.
Read full review
Usability
Apache
I can jump right into a new test plan and start building from scratch. The natural progression from test plan to thread group and then designing the basic format of the process is very streamlined and smooth. With only slight modifications I can build out a very complex model from a very basic beginning.
Read full review
Veracode
- Almost no setup required and easy to configure - Very easy to use, intuitive UI with integrated analytics and learning portals. - Seamless to review the results, triage them, generate reports. - Security progression of the product/application is tracked via successive scans. - Privileges/Roles nicely fine grained and tightly controlled to let teams "view" only their products.
Read full review
Reliability and Availability
Apache
No answers on this topic
Veracode
Veracode has always been up and available to us.
Read full review
Performance
Apache
No answers on this topic
Veracode
At this point, it runs well and mostly in a timely fashion. Dynamic scans take days but this may be a config issue still to be resolved.
Read full review
Support Rating
Apache
I have been using JMeter for the last year. By using this tool, you can make sure the system will work under varied loads. It helps us to simulate real time scenarios by creating required virtual users and make sure the application will work under load. Perform load, stress, and stability testing using JMeter.
Read full review
Veracode
Overall, Veracode support is helpful, community support is great, and documentation is available for self-service. Our Customer Success Manager is very helpful and reaches out regularly to see if we need assistance. We have not utilized many of the other resources offered by Veracode, however, in the future we would like to leverage secure coding training for our Development teams.
Read full review
Implementation Rating
Apache
No answers on this topic
Veracode
We use it as a SAS service, so really just getting our teams to mold the use of Veracode into their SDLC has been a process of years in the making. It comes down to what your teams are ready and willing to accept and change. Management is key in getting their groups on board with using it regularly. If it doesnt have management backing, your security teams have little to no influence in getting this process off the ground fully.
Read full review
Alternatives Considered
Apache
I have used LoadRunner and Silkperformer, and so far Jmeter turns out be the easiest to use of all these. While each of them have their own ROI, Jmeter can be picked by anyone in hours and start testing within a day. While with other tools, we need to get license, install them (takes a while) and setup tests and firewalls, etc.
Read full review
Veracode
Mend.IO formerly WhiteSource software is a product we used prior to Vericode. It did not have all of the capabilities or depth of Vericode. Additionally, Whitesource did not offer automatic scanning as part of their product and there was no Certification program to speak of.
Read full review
Scalability
Apache
No answers on this topic
Veracode
It meets our needs.
Read full review
Return on Investment
Apache
  • Good ROI on improving the performance of the application.
  • Finding issues in the performance.
  • Benchmark the performance results.
  • CON: Need skillset to create and maintain the scripts in Java.
  • Scripts are reusable and it is executed by any user.
  • Need Client and Server setup to execute the scripts.
Read full review
Veracode
  • Developers are now realizing that security is there to help them, not just the people saying NO.
  • When setting up Veracode integrations we found that Devs really like their IDEs and Repos. It's like a personal choice. However, as a company, it was unwieldy without devoting people to Veracode integrations to have so many so we had to slime the available IDEs to 3 and Repos to 3, just to be able to set up and maintain the integrations.
  • Veracode is paying for itself (though through a different cost category). Our Development costs are going down and releases are getting quicker and more agile.
Read full review
ScreenShots

Veracode Screenshots

Screenshot of The Veracode Platform HomepageScreenshot of Static Analysis ScansScreenshot of Findings Status and History DashboardScreenshot of The Veracode Platform