TrustRadius: an HG Insights company

Findbugs vs. Sonatype Vulnerability Scanner

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Findbugs

    Score7 out of 10
    N/AFindBugs is an open source program which uses static analysis to look for bugs in Java code. It is free software, distributed under the terms of the Lesser GNU Public License, and was developed (and its brand is trademarked by) the University of Maryland.N/A

    Sonatype Vulnerability Scanner

    Score9.1 out of 10
    N/ASonatype Vulnerability Scanner (formerly DepShield) discovers vulnerability among open source components and code in an application. It is available free and open source.

    $0

    Pricing
    FindbugsSonatype Vulnerability Scanner
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    FindbugsSonatype Vulnerability Scanner
    Free Trial
    NoYes
    Free/Freemium Version
    NoYes
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional Details——
    More Pricing Information
    User Ratings
    FindbugsSonatype Vulnerability Scanner
    Likelihood to Recommend
    7.0
    (1 ratings)
    9.1
    (1 ratings)
    User Testimonials
    FindbugsSonatype Vulnerability Scanner
    Likelihood to Recommend
    Open Source
    Findbugs is best suited even when you want to adapt to certain coding conventions and discover possible bugs beforehand and it's best suited for the java open source. whether you are a developer or a DevOps engineer you can even use it as a plugin in your Jenkins pipeline or any other build automation server and your developer tool such as visual studio as well.
    Incentivized
    Read full review
    Sonatype
    Well suited for organizations with small application security team as the solution scales and is easy for devs to use. The only choice if you develop in Java as their data is the most accurate.
    Incentivized
    Read full review
    Pros
    Open Source
    • Scan the code for existing bugs present
    • It can detect an vulnerabilities and also show possible bad warnings
    • Can help identify errors in advance to avoid code crash post deployment
    Incentivized
    Read full review
    Sonatype
    No answers on this topic
    Cons
    Open Source
    • It’s documentation is not always up to date
    • Difficulty in finding a prper solution when an issue arises during its configuration
    • has limited features
    Incentivized
    Read full review
    Sonatype
    No answers on this topic
    Alternatives Considered
    Open Source
    Sonar cloud has its own cloud where all the code vulnerabilities are collected and stored as a whole whereas its a plugin that is used in a code itself but the cons is that SonarCloud needs a license if you want to use it privately and also requires personal access token authentication if used with an external service
    Incentivized
    Read full review
    Sonatype
    No answers on this topic
    Return on Investment
    Open Source
    • Its being used overall by most of the teams
    • Some of the teams migrating to another testing tool as it has limited features
    • Still recommend as its open source and beginners friendly
    Incentivized
    Read full review
    Sonatype
    No answers on this topic
    ScreenShots