Overview
ProductRatingMost Used ByProduct SummaryStarting Price
ManageEngine Application Control Plus
Score 9.1 out of 10
N/A
Application Control Plus is an enterprise security software that brings together privilege management and application control capabilities. It helps enterprises again a holistic view of their network by aiding in the instant discovery and categorization of authorized and unauthorized applications. With application-level privilege management and rule-based whitelisting and blacklisting, Application Control Plus aims to ensure only authorized access occurs, minimizing an enterprise’s attack…N/A
Snyk
Score 8.7 out of 10
N/A
Snyk’s Developer Security Platform automatically integrates with a developer’s workflow and helps security teams to collaborate with their development teams. It boasts a developer-first approach that ensures organizations can secure all of the critical components of their applications from code to cloud, driving developer productivity, revenue growth, customer satisfaction, cost savings and an improved security posture. The vendor states Snyk is used by 1,200 customers worldwide today, including…
$0
SonarQube
Score 8.0 out of 10
N/A
SonarQube is an automated code review solution, serving as the verification layer for code quality and SDLC security. SonarQube is used to ensure that code is secure, reliable, and maintainable. It is available through SaaS or self-managed deployment.
$0
Pricing
ManageEngine Application Control PlusSnykSonarQube
Editions & Modules
No answers on this topic
Free
$0
Team (Snyk Open Source or Snyk Container or Snyk Infrastructure as Code)
$23
per month per user
Business (Snyk Open Source or Snyk Container or Snyk Infrastructure as Code)
$42
per month per user
Team (Snyk Open Source + Snyk Container + Snyk Code + Snyk Infrastructure as Code)
$98
per month per user
Business (Snyk Open Source + Snyk Container + Snyk Code + Snyk Infrastructure as Code)
$178
per month per user
Enterprise
Contact Sales
Cloud-based: Free
$0
Self-managed: Developer
Starting at $720 annually
per year per installation
Self-managed: Enterprise
Contact sales for pricing
per year per installation
Cloud-based: Enterprise
Contact sales for pricing
per year per installation
Cloud-based: Teams
Starting at $32 per month
per month per installation
Self-managed: Data Center
Contact sales for pricing
per year per installation
Offerings
Pricing Offerings
ManageEngine Application Control PlusSnykSonarQube
Free Trial
YesYesYes
Free/Freemium Version
YesYesYes
Premium Consulting/Integration Services
NoNoNo
Entry-level Setup FeeOptionalNo setup feeNo setup fee
Additional DetailsPricing is dependent on the number of developers selected, the number of products selected, and the payment term selected. Please visit the Snyk plans page for an interactive pricing calculator.
More Pricing Information
Community Pulse
ManageEngine Application Control PlusSnykSonarQube
Considered Multiple Products
ManageEngine Application Control Plus

No answer on this topic

Snyk
SonarQube
Chose SonarQube
Getting SonarQube instead of the other tools we tested was an easy choice. Snyk was way too much limited to only Docker images and dependency analysis at that time. And Checkmarx was very hard to adapt to our needs : configuring custom quality gates was way too much of a …
Chose SonarQube
Some are still under consideration. Pricing is a big component. Some FOSS products have been considered is at par (at least for our needs) or catching up. Although the amazing support in the community weighs hard on the value. So, if it went away...so would some arguments …
Best Alternatives
ManageEngine Application Control PlusSnykSonarQube
Small Businesses

No answers on this topic

No answers on this topic

GitLab
GitLab
Score 8.8 out of 10
Medium-sized Companies
BeyondTrust Privileged Remote Access
BeyondTrust Privileged Remote Access
Score 9.2 out of 10
Veracode
Veracode
Score 8.7 out of 10
Veracode
Veracode
Score 8.7 out of 10
Enterprises
BeyondTrust Endpoint Privilege Management
BeyondTrust Endpoint Privilege Management
Score 10.0 out of 10
Veracode
Veracode
Score 8.7 out of 10
Veracode
Veracode
Score 8.7 out of 10
All AlternativesView all alternativesView all alternativesView all alternatives
User Ratings
ManageEngine Application Control PlusSnykSonarQube
Likelihood to Recommend
-
(0 ratings)
8.5
(6 ratings)
8.8
(35 ratings)
Usability
-
(0 ratings)
9.0
(2 ratings)
9.1
(2 ratings)
Support Rating
-
(0 ratings)
-
(0 ratings)
9.0
(1 ratings)
User Testimonials
ManageEngine Application Control PlusSnykSonarQube
Likelihood to Recommend
ManageEngine A Div of Zoho Corporation Pvt Ltd
It works great if you want to run an application as an admin. We did find out that it will not work, or at least we cannot get it to work for users that need to change the IP address on their endpoint to connect to a traffic light. So far those users are still admins until we can figure it out
Read full review
Snyk
Scenarios Where Snyk Is Well-Suited CI/CD Pipeline Integration (Node.js, Python, etc.) Container Security Open Source License Compliance Infrastructure as Code (IaC) SecurityScenarios Where Snyk May Be Less Appropriate Scanning Proprietary or Custom Code for Unknown Vulnerabilities Complex Monorepos with Custom Build Tools Organizations Requiring Custom Security Rules Advanced Security Teams Needing Correlation and Deep Triage.
Read full review
SonarSource Sarl
SonarQube is excellent if you start using it at the beginning when developing a new system, in this situation you will be able to fix things before they become spread and expensive to correct. It’s a bit less suitable to use on existing code with bad design as it’s usually too expensive to fix everything and only allows you to ensure the situation doesn’t get worse.
Read full review
Pros
ManageEngine A Div of Zoho Corporation Pvt Ltd
  • Console built well and easy to understand
  • Support is awesome
  • Pulls in the exe information so that it is easy to allow the application to be ran as an admin
Read full review
Snyk
  • Helps in dependency management
  • SAST - Static Application Security Testing
  • Infra Code Scan ( Terraform , Cloud Formation , Docker image scan)
  • OSSG
Read full review
SonarSource Sarl
  • Detecting bugs and vulnerabilities: SonarQube can identify a wide range of bugs and vulnerabilities in code, such as null pointer exceptions, SQL injection, and cross-site scripting (XSS) attacks. It uses static analysis to analyze the code and identify potential issues, and it can also integrate with dynamic analysis tools to provide even more detailed analysis.
  • Measuring code quality: SonarQube can measure a wide range of code quality metrics, such as cyclomatic complexity, duplicated code, and code coverage. This can help teams understand the quality of their code and identify areas that need improvement.
  • Providing actionable insights: SonarQube provides detailed information about issues in the code, including the file and line number where the issue occurs and the severity of the issue. This makes it easy for developers to understand and address issues in the code.
  • Integrating with other tools: SonarQube can be integrated with a wide range of development tools and programming languages, such as Git, Maven, and Java. This allows teams to use SonarQube in their existing development workflow and take advantage of its powerful code analysis capabilities.
  • Managing technical debt: SonarQube provides metrics and insights on the technical debt on the codebase, enabling teams to better prioritize issues to improve the quality of the code.
  • Compliance with coding standards: SonarQube can check the code against industry standards like OWASP, CWE and more, making sure the code is compliant with security and coding standards.
Read full review
Cons
ManageEngine A Div of Zoho Corporation Pvt Ltd
  • The agent on the endpoint will sometimes fail to install or it will get corrupted. Nothing in the console that we can find tells us that there is an issue
  • Create an agent that also works with the other products that you sell. If we have more than one product there is a chance that it may not work
  • I really do not have a 3rd. This is a really good product
Read full review
Snyk
  • The tool itself has many capabilities but using them operationally within the platform on a day to day basis for managing vulnerabilities is not a good experience.
  • Our company was in desparate need of a tool to help us manage vulnerabilities so we could achieve a SOC 2 assurance report without findings.
Read full review
SonarSource Sarl
  • Importing a new custom quality profile on SonarQube is a bit tricky, it can be made easier
  • Every second time when we want to rerun the server, we have to restart the whole system, otherwise, the server stops and closes automatically
  • When we generate a new report a second time and try to access the report, it shows details of the old report only and takes a lot of time to get updated with the details of the new and fresh report generated
Read full review
Usability
ManageEngine A Div of Zoho Corporation Pvt Ltd
Extremely easy to use. Once we had a good idea of how it worked we had it up and running in about 2 weeks. It did take us nearly 9 months to get it installed and fully operational on all users endpoints that needed it. My admin on the team that runs the software loves it.
Read full review
Snyk
Developer-Centric Design - Snyk integrates directly into IDEs (like VS Code and IntelliJ), CI/CD pipelines, GitHub/GitLab, and container registries. Clear, Actionable Vulnerability report issues are categorized by severity.


Reports include fix recommendations, pull request suggestions, and links to remediation advice.
Read full review
SonarSource Sarl
It can improve in some user experience and usability parts, like the code view and the way we assign issues it's a bit hidden and not highlighted
Read full review
Support Rating
ManageEngine A Div of Zoho Corporation Pvt Ltd
No answers on this topic
Snyk
No answers on this topic
SonarSource Sarl
We we easily able to integrate the SonarQube steps into our TFS process via the Microsoft Marektplace, we didn't have the need to call SonarQube support. We've used their online documentation and community forum if we ran into any issues.
Read full review
Alternatives Considered
ManageEngine A Div of Zoho Corporation Pvt Ltd
ME has many more applications that are in the database that will work. The cost was also much cheaper that is until we confronted the other vendor about us finding another product. At that point it was too late. We own other ME products and have found success in all of them
Read full review
Snyk
Unfortunately, neither cover all of the use cases that we would like so we need to use both but they are both excellent tools as part of our vulnerability management. We find that Snyk helps us better with improving our MTTR of identified vulnerabilities when compared to inspector but that may be more based on how we have implemented both tools
Read full review
SonarSource Sarl
SonarQube is an open-source. It's a scalable product. The costs for this application, for the kind of job it does, are pretty descent. Pipeline scan is more secured in SonarQube. Its a very good tool and its support multiple languages. Its main core competency is of static code analysis and that is why SonarQube exists and it does it exceedingly well. The quality of scan on code convention, best practices, coding standards, unit test coverage etc makes them one of the best competent tool in the market
Read full review
Return on Investment
ManageEngine A Div of Zoho Corporation Pvt Ltd
  • This product will help us better secure our environment. That alone is a huge cost savings
  • We have allowed users that were admins to still be able to install some software on their endpoints without having admin rights on the whole endpoint
  • This product has woke up some in the department to look for applications that do not require admin rights.
Read full review
Snyk
  • Increased developer experience
  • Better productivity due to shift left as Vulnerabilities are caught earlier in the SDLC process
  • Improved Vulnerability Management
  • Common dashboard for various stages in CI/CD
Read full review
SonarSource Sarl
  • Positive ROI from the standpoint of flagging several issues that would have otherwise likely been unaddressed and caused more time to be spent closer to launch
  • Slightly positive ROI from time-saving perspective (it's an automated check which is nice, but depending on the issues it finds, can take developers time to investigate and resolve)
Read full review
ScreenShots

ManageEngine Application Control Plus Screenshots

Screenshot of Product DashboardScreenshot of Application GroupScreenshot of Endpoint Privilege ManagementScreenshot of Application Greylist

SonarQube Screenshots

Screenshot of Projects.Screenshot of Static Application Security Testing.Screenshot of Software Composition Analysis.