TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Checkmarx

    Score7.6 out of 10
    N/ACheckmarx, an Israeli headquartered company with US offices, provides a suite of application security software delivered via the Checkmarx Software Security Platform. Individual modules and capabilities include Checkmarx Static Application Security Testing, Checkmarx Software Composition Analysis, Checkmarx Interactive Application Security Testing (CxIAST)N/A

    Git

    Score10 out of 10
    N/AN/AN/A
    Pricing
    CheckmarxGit
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    CheckmarxGit
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional Details——
    More Pricing Information
    Community Pulse
    CheckmarxGit
    Considered Both Products
    Checkmarx
    No answer on this topic
    Open Source
    No answer on this topic
    Key User Insights
    Would buy again
    No answers on this topic
    100%
    Would buy again
    12 Answers
    Delivers good value for the price
    No answers on this topic
    100%
    Delivers good value for the price
    11 Answers
    Happy with the feature set
    No answers on this topic
    100%
    Happy with the feature set
    12 Answers
    Lived up to sales and marketing promises
    No answers on this topic
    100%
    Lived up to sales and marketing promises
    9 Answers
    Implementation went as expected
    No answers on this topic
    100%
    Implementation went as expected
    9 Answers
    Best Alternatives
    CheckmarxGit
    Small Businesses
    Rencore Code (SPCAF)
    Score8.8 out of 10
    GitHub
    Score9.2 out of 10
    Medium-sized Companies
    Trend Vision One Email and Collaboration Security
    Score9.9 out of 10
    GitHub
    Score9.2 out of 10
    Enterprises
    Trend Vision One Email and Collaboration Security
    Score9.9 out of 10
    Perforce P4
    Score7.5 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    CheckmarxGit
    Likelihood to Recommend
    8.3
    (5 ratings)
    10.0
    (36 ratings)
    Likelihood to Renew
    -
    (0 ratings)
    10.0
    (1 ratings)
    Usability
    7.7
    (2 ratings)
    9.0
    (1 ratings)
    Support Rating
    -
    (0 ratings)
    8.5
    (11 ratings)
    Implementation Rating
    -
    (0 ratings)
    9.0
    (1 ratings)
    User Testimonials
    CheckmarxGit
    Likelihood to Recommend
    Checkmarx
    If you are going with SAST process or want to improve overall security posture then go for it like integrating it with post deployment steps. If you are more concerned about proactive controls better choose other options such as pee-commit hooks and CI security. Also choose other tools for DAST and API scans.
    Incentivized
    Read full review
    Open Source
    GIT is good to be used for faster and high availability operations during code release cycle. Git provides a complete replica of the repository on the developer's local system which is why every developer will have complete repository available for quick access on his system and they can merge the specific branches that they have worked on back to the centralized repository. The limitations with GIT are seen when checking in large files.
    Incentivized
    Read full review
    Pros
    Checkmarx
    • Detects security vulnerabilities in source code with accuracy and detail.
    • Integrates seamlessly with CI/CD pipelines, IDEs, and repositories.
    • Provides clear reports and actionable fix recommendations for developers.
    Incentivized
    Read full review
    Open Source
    • Ability to create branches off current releases to modify code that can be tested in a separate environment.
    • Each developer had their own local copy of branches so it minimizes mistakes being made.
    • Has a user-friendly UI called Git Gui that users can use if they do not like using the command line.
    • Conflicts are displayed nicely so that developers can resolve with ease.
    Incentivized
    Read full review
    Cons
    Checkmarx
    • Scan duration
    • False positives
    • Integration with other tools like Jenkins comes with some inconveniences.
    Incentivized
    Read full review
    Open Source
    • There can be quite a number of commands once you get to the advanced features and functionality of Git. Takes time to master.
    • Doesn't handle static assets (ie: videos, images, etc.) well. Although in the recent years, new functionality has been introduced to address this.
    • Many different GUIs, many people (including myself) opt to just use the command-line.
    Incentivized
    Read full review
    Likelihood to Renew
    Checkmarx
    No answers on this topic
    Open Source
    Git has met all standards for a source control tool and even exceeded those standards. Git is so integrated with our work that I can't imagine a day without it.
    Incentivized
    Read full review
    Usability
    Checkmarx
    Their API based customizations which I leveraged to create an ASPM package, which is developer friendly and can extend above the dashboard features, other ones are UI which is great and feels clutter free. Menu and navigation is also good so as support. Only drawback is sometimes scan takes longer which I feel so can be reduced
    Incentivized
    Read full review
    Open Source
    Git is easy to use most of the time. You mostly use a few commands like commiting, fetch/pull, and push which will get you by for most of time.
    Incentivized
    Read full review
    Support Rating
    Checkmarx
    No answers on this topic
    Open Source
    I am not sure what the official Git support channels are like as I have never needed to use any official support. Because Git is so popular among all developers now, it is pretty easy to find the answer to almost any Git question with a quick Google search. I've never had trouble finding what I'm looking for.
    Incentivized
    Read full review
    Implementation Rating
    Checkmarx
    No answers on this topic
    Open Source
    It's easy to set up and get going.
    Incentivized
    Read full review
    Alternatives Considered
    Checkmarx
    Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into our development process, offering faster scans and more useful suggestions for fixing problems
    Incentivized
    Read full review
    Open Source
    I've used both Apache Subversion & Git over the years and have maintained my allegiance to Git. Git is not objectively better than Subversion. It's different.
    The key difference is that it is decentralized. With Subversion, you have a problem here: The SVN Repository may be in a location you can't reach (behind a VPN, intranet - etc), you cannot commit. If you want to make a copy of your code, you have to literally copy/paste it. With Git, you do not have this problem. Your local copy is a repository, and you can commit to it and get all benefits of source control. When you regain connectivity to the main repository, you can commit against it. Another thing for consideration is that Git tracks content rather than files. Branches are lightweight and merging is easy, and I mean really easy.
    It's distributed, basically every repository is a branch. It's much easier to develop concurrently and collaboratively than with Subversion, in my opinion. It also makes offline development possible. It doesn't impose any workflow, as seen on the above linked website, there are many workflows possible with Git. A Subversion-style workflow is easily mimicked.
    Incentivized
    Read full review
    Return on Investment
    Checkmarx
    • Improved ability to provide high level of IA confidence
    • Improved confidence in application-level security
    Incentivized
    Read full review
    Open Source
    • Git has saved our organization countless hours having to manually trace code to a breaking change or manage conflicting changes. It has no equal when it comes to scalability or manageability.
    • Git has allowed our engineering team to build code reviews into its workflow by preventing a developer from approving or merging in their own code; instead, all proposed changes are reviewed by another engineer to assess the impact of the code and whether or not it should be merged in first. This greatly reduces the likelihood of breaking changes getting into production.
    • Git has at times created some confusion among developers about what to do if they accidentally commit a change they decide later they want to roll back. There are multiple ways to address this problem and the best available option may not be obvious in all cases.
    Incentivized
    Read full review
    ScreenShots