Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Checkmarx
Score 8.5 out of 10
N/A
Checkmarx, an Israeli headquartered company with US offices, provides a suite of application security software delivered via the Checkmarx Software Security Platform. Individual modules and capabilities include Checkmarx Static Application Security Testing, Checkmarx Software Composition Analysis, Checkmarx Interactive Application Security Testing (CxIAST)N/A
SonarQube
Score 8.6 out of 10
N/A
SonarQube is an automated code review solution, serving as the verification layer for code quality and SDLC security. SonarQube is used to ensure that code is secure, reliable, and maintainable. It is available through SaaS or self-managed deployment.
$0
(open source)
Trellix Enterprise Security Manager
Score 8.6 out of 10
N/A
Trellix Enterprise Security Manager (formerly McAfee Enterprise Security Manager) is security information and event management (SIEM) software.N/A
Pricing
CheckmarxSonarQubeTrellix Enterprise Security Manager
Editions & Modules
No answers on this topic
SonarQube Community Build
$0
(open source)
Self-managed: Developer
Starting at $720 annually
per year per installation
Self-managed: Enterprise
Contact sales for pricing
per year per installation
Cloud-based: Enterprise
Contact sales for pricing
per year per installation
Cloud-based: Teams
Starting at $34 per month
per month per installation
Self-managed: Data Center
Contact sales for pricing
per year per installation
No answers on this topic
Offerings
Pricing Offerings
CheckmarxSonarQubeTrellix Enterprise Security Manager
Free Trial
NoYesNo
Free/Freemium Version
NoYesNo
Premium Consulting/Integration Services
NoNoNo
Entry-level Setup FeeNo setup feeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
CheckmarxSonarQubeTrellix Enterprise Security Manager
Considered Multiple Products
Checkmarx
Chose Checkmarx
Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into …
Chose Checkmarx
We actually use Checkmarx along with the other tools. However, the reason we chose Checkmarx is its wide support for languages and useful fix recommendations. The flowcharts help better understand the data flow and give a clear picture of what needs to be fixed and how. Also, …
SonarQube
Chose SonarQube
Some are still under consideration. Pricing is a big component. Some FOSS products have been considered is at par (at least for our needs) or catching up. Although the amazing support in the community weighs hard on the value. So, if it went away...so would some arguments …
Chose SonarQube
SonarQube is more focused on code quality, whereas Veracode does a better job of finding security vulnerabilities. We lean towards SonarQube because we are looking for quality.
Chose SonarQube
Jenkins and Gitlab are not exact alternatives for SonarQube, however, they do provide functionality for running and executing build pipelines for various languages and generating reports. However, they are not extensible, have no integration with IDEs and not suitable for …
Chose SonarQube
SonarQube deployment worked well with our pipeline and had the right integrations with our IDE as well as it worked well with analyzing .NET frameworks when compared to GitHub and GitLab which has some of the functionality and can do some checks, but SonarQube made more sense …
Chose SonarQube
SonarQube is a SAST, SOOS focuses on SCA and DAST - both of which we felt were out of scope for our immediate needs. Plus, through plugins SonarQube is able to accomplish some SCA.
Chose SonarQube
SonarQube identifies significant more thing compared to the built-in suggestions in IntelliJ IDEA. The suggestions how to correct issues are also a lot better with SonarQube. IntelliJ IDEA provides great refactoring support to make it easy to refactor the code to solve issues. …
Chose SonarQube
Getting SonarQube instead of the other tools we tested was an easy choice. Snyk was way too much limited to only Docker images and dependency analysis at that time. And Checkmarx was very hard to adapt to our needs : configuring custom quality gates was way too much of a …
Chose SonarQube
SonarQube is much improved version as compared to SonarLint and Findbugs or any other software we found in similar category. It's open source and can be easily integrated with code pipeline.
Chose SonarQube
We decided to use SonarQube for the following reasons:
  1. Multi-language support: SonarQube supported all the languages used in our codebase while some of the other tools did not.
  2. Customizable quality profiles: SonarQube allowed teams to create custom quality profiles that aligned …
Chose SonarQube
I have used GitHub more that fortify so I am more familiar with GitHub for checking for vulnerabilities. I have noticed GitHub is good for checking different packages within your project but as far as checking code Quality and coverage Sonar is the better one in my opinion. …
Chose SonarQube
Visual Studio has some nice code analysis tools, most which can be activated at development time.
But they have some shortcomings and using an external tool allows catching issues that were not seen during development.
Using this dual approach makes for a more robust application …
Chose SonarQube
I have used other tools like SoapUI and Postman, but their working and use case are totally different from the SonarQube, so basically cannot compare SonarQube with them. We use SonarQube in our project to basically calculate the code quality report mostly. In that report, we …
Chose SonarQube
I personally evaluated klocwork in a previous company and it worked well for Static Code Analysis for C++ applications but the Java support was not as good as SonarQube.

Also the overall tooling and integrations provided by SonarQube is stellar and very other competitors can …
Chose SonarQube
Setting up with Azure devops is easier.
Scans results and depth of tweaking/whitelisting code snippets is easier with SonarQube.
Chose SonarQube
SonarQube is an open-source. It's a scalable product. The costs for this application, for the kind of job it does, are pretty descent. Pipeline scan is more secured in SonarQube. Its a very good tool and its support multiple languages. Its main core competency is of static code …
Chose SonarQube
SonarQube contains all of their features. Findbugs has very limited capabilities. It is just a static code analyser and does not check for a continous code quality and also not possible to integrate its plugin azure devops .net pipelines and more importantly SonarQube ui is …
Chose SonarQube
Sonar Qube doesn't do as good of a job of finding security vulnerabilities as dedicated SAST software, but it does more for code quality that the developers want to see. A comparison of Sonar Qube to something like Veracode or Fortify isn't apples to apples since they're not …
Chose SonarQube
We found SonarQube right at the beginning of our research process and found that it met most of our needs. SonarQube fit very nicely into our TFS continuous integration process. We seamlessly integrated the SonarQube steps into our TFS process via the Microsoft Marketplace. …
Chose SonarQube
Gitlab, if you have the right license, ships with a static analysis tool. It integrates better with Gitlab, but didn't seem to have the same quality output that Sonarqube did. Sonarqube's community version is plenty suitable for day to day analysis operations.
Trellix Enterprise Security Manager
Chose Trellix Enterprise Security Manager
McAfee Enterprise Security Manager is a better option than other security software because it's both inexpensive and extremely effective. Norton and other security software boast a high price tag but don't always back it up when it comes to performance. With McAfee Enterprise …
Chose Trellix Enterprise Security Manager
Other evaluated products: Microsoft Defender and Symantec
- McAffee has more comprehensive integrated tools that better serve our infrastructure
- Analysts found the use of the tool more intuitive
Chose Trellix Enterprise Security Manager
McAfee is not the easiest tool to use. The user interface (specially the admin part) is fairly confusing.
At first, McAfee is very overwhelming and not so easy to understand. However, once you get used to the tool, you get used to the interface and you're able to do pretty much …
Chose Trellix Enterprise Security Manager
We had used McAfee Enterprise Security Manager for a long time, and it served us well. It is great since it can serve as an all-in security tool. Also, it was a great deal for our organization, since it came bundled with our manager network security.
Chose Trellix Enterprise Security Manager
We selected McAfee Enterprise Security Manager because the pricing is competitive in the industry. It is very reliable. The vendor offers good support in real time. Offers the results that we have been looking for. The ability to get the logs may be of last 2 years in a matter …
Chose Trellix Enterprise Security Manager
We selected and implemented McAfee Enterprise Security Manager because is the best SIEM solution from the market. With a very good support from the vendor. Easy implementation and easy management. A lot of threats addressed. High level of security assured. Very good resilience. …
Chose Trellix Enterprise Security Manager
Splunk tends to be the top dog in the space. Everything is compatible and it's capable of anything. You just have to have the time and money to do the work. And if you have a large volume of logs (and who doesn't?), it's not cheap. McAfee Enterprise Security Manager's advantage …
Chose Trellix Enterprise Security Manager

We looked at a few products, these were AlienVault, ESM, LogRhythm and Alert Logic.

ESM at the time had more functionality and a friendlier and cleaner user interface than LogRhythm

ESM had an ability to integrate easily into Intel's endpoint solution versus AlienVault where a …

Features
CheckmarxSonarQubeTrellix Enterprise Security Manager
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
Checkmarx
-
Ratings
SonarQube
-
Ratings
Trellix Enterprise Security Manager
8.4
Ratings
6% above category average
Centralized event and log data collection00 Ratings00 Ratings8.60 Ratings
Correlation00 Ratings00 Ratings7.00 Ratings
Event and log normalization/management00 Ratings00 Ratings8.00 Ratings
Deployment flexibility00 Ratings00 Ratings8.30 Ratings
Integration with Identity and Access Management Tools00 Ratings00 Ratings9.30 Ratings
Custom dashboards and workspaces00 Ratings00 Ratings9.30 Ratings
Host and network-based intrusion detection00 Ratings00 Ratings8.30 Ratings
Data integration/API management00 Ratings00 Ratings9.30 Ratings
Behavioral analytics and baselining00 Ratings00 Ratings8.60 Ratings
Rules-based and algorithmic detection thresholds00 Ratings00 Ratings8.60 Ratings
Response orchestration and automation00 Ratings00 Ratings8.00 Ratings
Reporting and compliance management00 Ratings00 Ratings8.60 Ratings
Incident indexing/searching00 Ratings00 Ratings7.60 Ratings
Best Alternatives
CheckmarxSonarQubeTrellix Enterprise Security Manager
Small Businesses
GitLab
GitLab
Score 8.8 out of 10
GitLab
GitLab
Score 8.8 out of 10
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 8.0 out of 10
Medium-sized Companies
Veracode
Veracode
Score 8.6 out of 10
Veracode
Veracode
Score 8.6 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Enterprises
Veracode
Veracode
Score 8.6 out of 10
Veracode
Veracode
Score 8.6 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
All AlternativesView all alternativesView all alternativesView all alternatives
User Ratings
CheckmarxSonarQubeTrellix Enterprise Security Manager
Likelihood to Recommend
8.4
(0 ratings)
8.8
(0 ratings)
9.0
(0 ratings)
Usability
7.6
(0 ratings)
9.1
(0 ratings)
-
(0 ratings)
Support Rating
-
(0 ratings)
9.0
(0 ratings)
6.5
(0 ratings)
User Testimonials
CheckmarxSonarQubeTrellix Enterprise Security Manager
Likelihood to Recommend
If you are going with SAST process or want to improve overall security posture then go for it like integrating it with post deployment steps. If you are more concerned about proactive controls better choose other options such as pee-commit hooks and CI security. Also choose other tools for DAST and API scans.
Read full review
Scenarios where SonarQube is well suited:
  1. Large codebase: The tool's static analysis capabilities can help teams quickly identify and fix bugs, vulnerabilities, and code smells in large codebases.
  2. Compliance and security: The tool can check the code against industry standards or regulations, such as OWASP and CWE, and identify any issues that need to be addressed.
  3. Agile development: SonarQube can be integrated with CI/CD pipelines allowing teams to continuously monitor and improve code quality throughout the development process.
  4. Teams using multiple languages: Teams that use multiple programming languages can benefit from using SonarQube, as the tool supports a wide range of languages and can be integrated with a variety of development tools.
Scenarios where SonarQube may be less appropriate:
  1. Small codebase: Organizations with a small codebase may not see the full benefits of using SonarQube, as the tool's static analysis capabilities may be overkill for a smaller codebase.
  2. Limited resources: Organizations with limited resources may find it difficult to set up and configure SonarQube, as the tool can be complex and may require specialized expertise.
  3. Limited integration: Organizations that use development tools or IDEs that are not supported by SonarQube may find it difficult to integrate the tool into their existing development workflow.
  4. Limited scalability: Large organizations with millions of lines of code may find SonarQube's performance and scalability to be an issue. It may take longer for the analysis to finish and the results may not be as accurate.
Read full review
McAfee is a good solution if you're in a medium/large company and if you're looking for a solution that can be customized and expanded. I also recommend if you have the most common log sources on your environment, since McAfee supports the major log sources (but lack a lot of small vendors). In my opinion, I wouldn't recommend McAfee for small companies, since it's not that easy to manage and maintain.
Read full review
Pros
  • Supports a large number of languages
  • Finds a large variety of potential risks
Read full review
  • Generating code quality report
  • Calculates junit coverage of the codebase very efficiently and precisely
  • Highlights the bugs and vulnerabilities in our codebase
  • Informs the user of the improvements which can be done to the code to make it cleaner
  • SonarQube also suggests remediation and resolution of the problems it highlights
Read full review
  • McAfee Enterprise Security Manager has a large library of pre-made correlations that reduces the amount of work needed to make it functional.
  • This is a core McAfee product that is still getting support.
  • It has a substantial amount of compatibility and integration with other products.
Read full review
Cons
  • DAST capability can be the one where it does not support native use case of using OTP based arch
  • API Scanning is something that lacks a bit due to not much customizations
  • Branch wise reports for SAST is not available
Read full review
  • It doesn't provide automatic pull request with fixes
  • It doesn't provide insights about the libraries of the projects
  • The administration management user interface could be simplified
  • It doesn't provide an order to fix issues, like archives with more and frequent commits have top priority
Read full review
  • If there is a requirement to integrate into other vendor products i.e. (log sharing) then this was very cumbersome.
  • Integration of vulnerability scanning that is available in other vendor products would be a good addition.
  • When integrating all of Intel's products a third party consultancy is usually required, where other vendor products can be configured without this additional cost.
Read full review
Usability
Checkmarx's usability is generally good, but it can be a bit complex for new users. The interface may take some time to get used to, especially for those unfamiliar with security tools. Once you become familiar with it, it’s effective and integrates well into development workflows.
Read full review
It can improve in some user experience and usability parts, like the code view and the way we assign issues it's a bit hidden and not highlighted
Read full review
No answers on this topic
Support Rating
No answers on this topic
We we easily able to integrate the SonarQube steps into our TFS process via the Microsoft Marektplace, we didn't have the need to call SonarQube support. We've used their online documentation and community forum if we ran into any issues.
Read full review
Dealing with the McAfee support is a lottery. Sometimes you reach them and it's a really experienced engineer, but sometimes it's a person with no clue on the tool. We had few cases where our internal engineers knew more about the tool than the McAfee support. However, sometimes we get hold of some really good engineers that know the tool from inside out
Read full review
Alternatives Considered
Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into our development process, offering faster scans and more useful suggestions for fixing problems
Read full review
SonarQube identifies significant more thing compared to the built-in suggestions in IntelliJ IDEA. The suggestions how to correct issues are also a lot better with SonarQube. IntelliJ IDEA provides great refactoring support to make it easy to refactor the code to solve issues. We use these tools together and they really complement each other.
Read full review
McAfee Enterprise Security Manager is a better option than other security software because it's both inexpensive and extremely effective. Norton and other security software boast a high price tag but don't always back it up when it comes to performance. With McAfee Enterprise Security Manager, I know I'm getting a quality product for a fair price.
Read full review
Return on Investment
  • Great diversity of vulnerabilities covered.
  • Quicker scans
  • They are feature rich compared to other tools I used in the past.
  • Dashboards are not customizable enough.
  • High number of false positives take up time and sometimes make our report look bad.
Read full review
  • Positive ROI from the standpoint of flagging several issues that would have otherwise likely been unaddressed and caused more time to be spent closer to launch
  • Slightly positive ROI from time-saving perspective (it's an automated check which is nice, but depending on the issues it finds, can take developers time to investigate and resolve)
Read full review
  • It effectively blocks potential attacks from outside.
  • It aids us in doing more effective root-cause analysis whenever an incident occurs, since it gives us enough details to understand what went wrong.
Read full review
ScreenShots

SonarQube Screenshots

Screenshot of Projects.Screenshot of Static Application Security Testing.Screenshot of Software Composition Analysis.