Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Checkmarx
Score 8.5 out of 10
N/A
Checkmarx, an Israeli headquartered company with US offices, provides a suite of application security software delivered via the Checkmarx Software Security Platform. Individual modules and capabilities include Checkmarx Static Application Security Testing, Checkmarx Software Composition Analysis, Checkmarx Interactive Application Security Testing (CxIAST)N/A
Cloudflare Access
Score 9.2 out of 10
N/A
Cloudflare Access is a Zero Trust Network Access (ZTNA) solution that secures internal applications by verifying identity, device posture, and context for every request. It replaces legacy VPNs with a faster, more secure alternative that lives at the network edge.N/A
SonarQube for IDE
Score 8.2 out of 10
N/A
SonarQube for IDE is a free IDE plugin that helps developers by detecting and highlighting issues in their code in real time. Like a spell checker, SonarLint detects Bugs, code smells, and Security Vulnerabilities as code is written, and offers guidance.N/A
Pricing
CheckmarxCloudflare AccessSonarQube for IDE
Editions & Modules
No answers on this topic
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
CheckmarxCloudflare AccessSonarQube for IDE
Free Trial
NoNoYes
Free/Freemium Version
NoYesYes
Premium Consulting/Integration Services
NoNoNo
Entry-level Setup FeeNo setup feeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
CheckmarxCloudflare AccessSonarQube for IDE
Considered Multiple Products
Checkmarx
Chose Checkmarx
Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into …
Chose Checkmarx
We actually use Checkmarx along with the other tools. However, the reason we chose Checkmarx is its wide support for languages and useful fix recommendations. The flowcharts help better understand the data flow and give a clear picture of what needs to be fixed and how. Also, …
Cloudflare Access
Chose Cloudflare Access
As long as all Cloudflare products and services rely on anycast technology, in a complex approach Cloudflare is faster and more relevant for cloud applications. The balance between security and performance is fully established. Also, Cloudflare has quite a good stack for API …
Chose Cloudflare Access
Cloudflare Gateway does not require local resources and hardware to implement, is very simple and efficient, easy to use, and has clear analytics. It is backed by a very fast DNS resolver in the market.
Chose Cloudflare Access
Cloudflare was both the most feature-rich and cost-effective of comparisons. Presales engagement understood our challenges and was keen to solve them.
SonarQube for IDE
Features
CheckmarxCloudflare AccessSonarQube for IDE
Identity Management
Comparison of Identity Management features of Product A and Product B
Checkmarx
-
Ratings
Cloudflare Access
10.0
Ratings
12% above category average
SonarQube for IDE
-
Ratings
Multi-Factor Authentication00 Ratings10.00 Ratings00 Ratings
Endpoint Security
Comparison of Endpoint Security features of Product A and Product B
Checkmarx
-
Ratings
Cloudflare Access
10.0
Ratings
11% above category average
SonarQube for IDE
-
Ratings
Endpoint Detection and Response (EDR)00 Ratings10.00 Ratings00 Ratings
Threat Intelligence
Comparison of Threat Intelligence features of Product A and Product B
Checkmarx
-
Ratings
Cloudflare Access
8.9
Ratings
15% above category average
SonarQube for IDE
-
Ratings
Network Analytics00 Ratings5.40 Ratings00 Ratings
Threat Recognition00 Ratings10.00 Ratings00 Ratings
Vulnerability Classification00 Ratings10.00 Ratings00 Ratings
Automated Alerts and Reporting00 Ratings6.70 Ratings00 Ratings
Threat Analysis00 Ratings10.00 Ratings00 Ratings
Threat Intelligence Reporting00 Ratings10.00 Ratings00 Ratings
Automated Threat Identification00 Ratings10.00 Ratings00 Ratings
Zero Trust Security
Comparison of Zero Trust Security features of Product A and Product B
Checkmarx
-
Ratings
Cloudflare Access
9.3
Ratings
9% above category average
SonarQube for IDE
-
Ratings
Continuous Verification00 Ratings10.00 Ratings00 Ratings
Secure Web Gateways00 Ratings10.00 Ratings00 Ratings
Network Flow Control00 Ratings10.00 Ratings00 Ratings
Network Traffic Analysis00 Ratings6.70 Ratings00 Ratings
Segmentation Leveraging00 Ratings10.00 Ratings00 Ratings
Admin Access Control00 Ratings8.00 Ratings00 Ratings
Network Data Encryption00 Ratings9.30 Ratings00 Ratings
Network Topology Mapping00 Ratings10.00 Ratings00 Ratings
Best Alternatives
CheckmarxCloudflare AccessSonarQube for IDE
Small Businesses
GitLab
GitLab
Score 8.8 out of 10
ThreatLocker
ThreatLocker
Score 9.1 out of 10

No answers on this topic

Medium-sized Companies
Veracode
Veracode
Score 8.6 out of 10
Palo Alto Networks Prisma Access
Palo Alto Networks Prisma Access
Score 8.6 out of 10
Redgate SQL Toolbelt Essentials
Redgate SQL Toolbelt Essentials
Score 9.6 out of 10
Enterprises
Veracode
Veracode
Score 8.6 out of 10
Palo Alto Networks Prisma Access
Palo Alto Networks Prisma Access
Score 8.6 out of 10
Redgate SQL Toolbelt Essentials
Redgate SQL Toolbelt Essentials
Score 9.6 out of 10
All AlternativesView all alternativesView all alternativesView all alternatives
User Ratings
CheckmarxCloudflare AccessSonarQube for IDE
Likelihood to Recommend
8.4
(0 ratings)
10.0
(0 ratings)
8.0
(0 ratings)
Usability
7.6
(0 ratings)
10.0
(0 ratings)
-
(0 ratings)
Support Rating
-
(0 ratings)
9.1
(0 ratings)
-
(0 ratings)
User Testimonials
CheckmarxCloudflare AccessSonarQube for IDE
Likelihood to Recommend
If you are going with SAST process or want to improve overall security posture then go for it like integrating it with post deployment steps. If you are more concerned about proactive controls better choose other options such as pee-commit hooks and CI security. Also choose other tools for DAST and API scans.
Read full review
I wanted to securely connect to my servers without getting tracked by malicious attackers, even though I was on public Wi-Fi. Security was my top priority, and I also wanted a setup that was easy and quick to start and provided great network performance. Cloudflare's Zero trust matches my criteria for becoming my first choice.
Read full review
No answers on this topic
Pros
  • Supports a large number of languages
  • Finds a large variety of potential risks
Read full review
  • Block access to known bad, risky, or unwanted destinations at the DNS or HTTP level.
  • Excellent protection for remote users.
  • Best in class browser isolation techniques.
Read full review
  • SonarLint highlights all the issues in our codes and also displays the severity of each issue.
  • SonarLint also provides suggestions for how to fix those code issues which are highlighted.
  • SonarLint starts the processing of the file as soon as it is opened and highlights all the issues which it found.
  • When we fix the issue, we don't even need to create a new build or generate fresh code quality report, as soon as we save the file with the changes, it does the processing again and shows the result if the issue is fixed or not.
  • SonarLint saves a lot of time and effort by saving us from doing fresh build every time and generating new code quality report every time, thus increasing the efficiency and output which is in return beneficial for the client.
Read full review
Cons
  • DAST capability can be the one where it does not support native use case of using OTP based arch
  • API Scanning is something that lacks a bit due to not much customizations
  • Branch wise reports for SAST is not available
Read full review
  • Cloudflare picks the nearest device location to route the traffic, but It would be great if we could select any particular location.
  • Cloudflare enables monitoring for all the connected clients; it would be great if we could monitor any individual client device while keeping some client devices private.
  • Sometimes, its DNS is not able to resolve a few project websites; we have to manually purge the cache and even disable the Security to get the work done. So, it would be better if we could manually provide a DNS list or whitelist some websites.
Read full review
  • Sometimes, SonarLint does not highlight the issues in the code correctly.
  • The severity of the issues highlighted is according to the default rules set, we should also be given authority to set the severity of the issues.
  • The default fixes which SonarLint provides should be more enhanced and there should be more fixes available.
  • Sometimes it takes a lot of time for processing of the file when any new file is loaded or changes are saved in a file.
Read full review
Usability
Checkmarx's usability is generally good, but it can be a bit complex for new users. The interface may take some time to get used to, especially for those unfamiliar with security tools. Once you become familiar with it, it’s effective and integrates well into development workflows.
Read full review
Within a few hours, new engineers are trained in basic tasks and are quite happy they are able to resolve issues independently. After SSO is configured, onboarding is as simple as signing into m365 via a web browser popup.
Read full review
No answers on this topic
Support Rating
No answers on this topic
Good chat support from the portal for basic questions and minor issues. The enterprise support line is provided as well.
Read full review
No answers on this topic
Alternatives Considered
Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into our development process, offering faster scans and more useful suggestions for fixing problems
Read full review
As long as all Cloudflare products and services rely on anycast technology, in a complex approach Cloudflare is faster and more relevant for cloud applications. The balance between security and performance is fully established. Also, Cloudflare has quite a good stack for API connection protection, like the API Shield example, which makes it more effective compared to F5 for example. Warp as a ZTNA agent gives better visibility and device posture information than FortiClient does.
Read full review
SonarLint works along with SonarQube
Read full review
Return on Investment
  • Great diversity of vulnerabilities covered.
  • Quicker scans
  • They are feature rich compared to other tools I used in the past.
  • Dashboards are not customizable enough.
  • High number of false positives take up time and sometimes make our report look bad.
Read full review
  • Cloudflare has provided us with 100% uptime even during planned maintenance
  • Cloudflare has reduced time for engineering fixes from hours (or days) to minutes in some cases (primarily through Workers)
Read full review
  • SonarLint helps in achieving all the business requirements in a more efficient way.
  • It reduces the manual and redundant work which we would have to do else every time if we did not use SonarLint.
  • SonarLint helps in maintaining code quality, and thus also highlights the loopholes for the cyber attacks and phishing attacks.
  • SonarLint makes work easy and helps the developer to invest less time in manual work thereby increasing their capacity to deliver the maximum output to the client.
Read full review
ScreenShots

SonarQube for IDE Screenshots

Screenshot of where SonarQube for IDE identifies and highlights issues in a Java project within VS Code. It also explains why this is an issue, how to fix it, and offers more educational content to help developers grow. SonarLint uncovers issues in over 30 languages, frameworks and IaC platforms. SonarLint is available for VS Code, Visual Studio, Eclipse and JetBrains IDEs.Screenshot of how when connected to either SonarCloud or SonarQube the developer can leverage  SonarQube for IDE to identify complex bugs, share code quality expectations with their team, perform deeper issue analysis, enjoy smart notifications, and unlock additional language analysis opportunities. Connecting is easy and guided for a rapid setup, as seen here in the image.