TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Nmap

    Score8.7 out of 10
    N/ANmap is a free, open source network discovery, mapper, and security auditing software. Its core features include port scanning identifying unknown devices, testing for security vulnerabilities, and identifying network issues.

    $49,980

    one-time fee

    SonarQube

    Score8.7 out of 10
    N/ASonarQube is an automated code review solution, serving as the verification layer for code quality and SDLC security. SonarQube is used to ensure that code is secure, reliable, and maintainable. It is available through SaaS or self-managed deployment.

    $34

    per month Recommended for teams <50 developers

    Pricing
    NmapSonarQube
    Editions & Modules
    Nmap OEM Small/Startup Company Redistribution License - Quarterly Term Maintenance Fee
    $7,980
    Every Three Months per license
    Nmap OEM Mid-Sized Company Redistribution License - Quarterly Term Maintenance Fee
    $11,980
    Every Three Months per license
    Nmap OEM Enterprise Redistribution License - Quarterly Term Maintenance Fee
    $13,980
    Every Three Months per license
    Nmap OEM Small/Startup Company Redistribution License - Annual Maintenance Fee
    $14,980
    per year per license
    Nmap OEM Mid-Sized Company Redistribution License - Annual Maintenance Fee
    $19,980
    per year per license
    Nmap OEM Enterprise Redistribution License - Annual Maintenance Fee
    $23,980
    per year per license
    Nmap OEM Small/Startup Company Redistribution License - Perpetual License
    $49,980
    one-time fee per license
    Nmap OEM Small/Startup Company Redistribution License - 5 year prepay Maintenance Fee
    $59,920
    Every Five Years per license
    Nmap OEM Mid-Sized Company Redistribution License - 5 year prepay Maintenance Fee
    $79,920
    Every Five Years per license
    Nmap OEM Mid-Sized Company Redistribution License - Perpetual License
    $79,980
    one-time fee per license
    Nmap OEM Enterprise Redistribution License - 5 year prepay Maintenance Fee
    $95,920
    Every Five Years per license
    Nmap OEM Enterprise Redistribution License - Perpetual License
    $98,980
    one-time fee per license
    SonarQube Community Build
    $0
    (open source)
    Self-managed: Developer
    Starting at $720 annually
    per year per installation
    Self-managed: Enterprise
    Contact sales for pricing
    per year per installation
    Cloud-based: Enterprise
    Contact sales for pricing
    per year per installation
    Cloud-based: Teams
    Starting at $34 per month
    per month per installation
    Self-managed: Data Center
    Contact sales for pricing
    per year per installation
    Offerings
    Pricing Offerings
    NmapSonarQube
    Free Trial
    NoYes
    Free/Freemium Version
    NoYes
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional DetailsAll perpetual licenses include a six-month trial period during which you can cancel for any reason and receive a full refund of all money paid (including maintenance). The term license is only a 3-month commitment and cal also be terminated with full refund during the first 30 days of the initial quarter.—
    More Pricing Information
    Community Pulse
    NmapSonarQube
    Considered Both Products
    Open Source
    No answer on this topic
    SonarSource Sarl
    No answer on this topic
    Key User Insights
    Would buy again
    100%
    Would buy again
    14 Answers
    100%
    Would buy again
    32 Answers
    Delivers good value for the price
    100%
    Delivers good value for the price
    14 Answers
    100%
    Delivers good value for the price
    29 Answers
    Happy with the feature set
    100%
    Happy with the feature set
    14 Answers
    100%
    Happy with the feature set
    32 Answers
    Lived up to sales and marketing promises
    100%
    Lived up to sales and marketing promises
    11 Answers
    95%
    Lived up to sales and marketing promises
    18 Answers
    Implementation went as expected
    100%
    Implementation went as expected
    13 Answers
    100%
    Implementation went as expected
    27 Answers
    Features
    NmapSonarQube
    Network Performance Monitoring
    Comparison of Network Performance Monitoring features of Nmap and SonarQube
    Feature
    Nmap
    5.3
    17 Ratings
    40% below category average
    SonarQube
    -
    Ratings
    Automated network device discovery5.011 Ratings00 Ratings
    Network monitoring10.012 Ratings00 Ratings
    Baseline threshold calculation9.06 Ratings00 Ratings
    Alerts3.04 Ratings00 Ratings
    Network capacity planning6.07 Ratings00 Ratings
    Packet capture analysis2.07 Ratings00 Ratings
    Network mapping10.016 Ratings00 Ratings
    Customizable reports1.010 Ratings00 Ratings
    Wireless infrastructure monitoring2.08 Ratings00 Ratings
    Hardware health monitoring5.06 Ratings00 Ratings
    Best Alternatives
    NmapSonarQube
    Small Businesses
    Auvik
    Score8.8 out of 10
    No answers on this topic
    Medium-sized Companies
    PingPlotter
    Score9 out of 10
    No answers on this topic
    Enterprises
    PingPlotter
    Score9 out of 10
    No answers on this topic
    All AlternativesView all alternativesView all alternatives
    User Ratings
    NmapSonarQube
    Likelihood to Recommend
    10.0
    (18 ratings)
    8.9
    (35 ratings)
    Usability
    10.0
    (1 ratings)
    9.1
    (2 ratings)
    Support Rating
    8.4
    (7 ratings)
    9.0
    (1 ratings)
    User Testimonials
    NmapSonarQube
    Likelihood to Recommend
    Open Source
    If you're a sysadmin, or anyone who's had to deploy network services, you've almost certainly had to use Nmap at some point or other. Need to see what devices are on your LAN? Nmap can tell you that. Want to check which ports your web server has open to the internet? Nmap is your friend.
    Nmap is a powerful command-line tool and has many options that require some reading of documentation to get the best out of (although generally straightforward). If the thought of working at the command-line scares you (presumably not if you're reading this review), then you may want a much simpler tool, or at least check out Zenmap GUI.
    Incentivized
    Read full review
    SonarSource Sarl
    SonarQube is excellent if you start using it at the beginning when developing a new system, in this situation you will be able to fix things before they become spread and expensive to correct. It’s a bit less suitable to use on existing code with bad design as it’s usually too expensive to fix everything and only allows you to ensure the situation doesn’t get worse.
    Incentivized
    Read full review
    Pros
    Open Source
    • NMap provides a very fast and a very thorough network "sweep" that allows you to quickly map out exactly what's on your network.
    • NMap is highly configurable. The "canned" choices are very good in most instances, but using various switches and options, you can create a very specific scan and get exactly the results you're looking for.
    • NMap is easy to use. Even a new administrator will be able to use the graphical version (Zenmap) with efficiency right away.
    Incentivized
    Read full review
    SonarSource Sarl
    • Detecting bugs and vulnerabilities: SonarQube can identify a wide range of bugs and vulnerabilities in code, such as null pointer exceptions, SQL injection, and cross-site scripting (XSS) attacks. It uses static analysis to analyze the code and identify potential issues, and it can also integrate with dynamic analysis tools to provide even more detailed analysis.
    • Measuring code quality: SonarQube can measure a wide range of code quality metrics, such as cyclomatic complexity, duplicated code, and code coverage. This can help teams understand the quality of their code and identify areas that need improvement.
    • Providing actionable insights: SonarQube provides detailed information about issues in the code, including the file and line number where the issue occurs and the severity of the issue. This makes it easy for developers to understand and address issues in the code.
    • Integrating with other tools: SonarQube can be integrated with a wide range of development tools and programming languages, such as Git, Maven, and Java. This allows teams to use SonarQube in their existing development workflow and take advantage of its powerful code analysis capabilities.
    • Managing technical debt: SonarQube provides metrics and insights on the technical debt on the codebase, enabling teams to better prioritize issues to improve the quality of the code.
    • Compliance with coding standards: SonarQube can check the code against industry standards like OWASP, CWE and more, making sure the code is compliant with security and coding standards.
    Incentivized
    Read full review
    Cons
    Open Source
    • The GUI version on Nmap could use some improvement with the options that are available to do scans. For example, they could make it easier to select options for the different types of scanning for people who are beginners
    • There are no abilities to schedule a scan in the Nmap tool.
    • An intensive scan sometimes takes too much time to complete.
    Incentivized
    Read full review
    SonarSource Sarl
    • Importing a new custom quality profile on SonarQube is a bit tricky, it can be made easier
    • Every second time when we want to rerun the server, we have to restart the whole system, otherwise, the server stops and closes automatically
    • When we generate a new report a second time and try to access the report, it shows details of the old report only and takes a lot of time to get updated with the details of the new and fresh report generated
    Incentivized
    Read full review
    Usability
    Open Source
    Nmap uses are very practical and I don't think there is a better tools for what Nmap does. It is open-sources that therefore there is no cost to use it. It offers a number of benefits, including but not limited to network mapping, port scanning and more. It is very reliable as a network scanning tool.
    Incentivized
    Read full review
    SonarSource Sarl
    It can improve in some user experience and usability parts, like the code view and the way we assign issues it's a bit hidden and not highlighted
    Incentivized
    Read full review
    Support Rating
    Open Source
    There is a very large support community and a robust selection of add-ons and scripts. Once you get the use down this is one of the most powerful tools and you can find anything you are looking for as far as examples on the web. While not having official support its not lacking by any means.
    Incentivized
    Read full review
    SonarSource Sarl
    We we easily able to integrate the SonarQube steps into our TFS process via the Microsoft Marektplace, we didn't have the need to call SonarQube support. We've used their online documentation and community forum if we ran into any issues.
    Incentivized
    Read full review
    Alternatives Considered
    Open Source
    Alternatives to Nmap (other IP scanners) are often much more limited in what they can do; They often only allow you to scan a specific subset of ports or a limited number of IP addresses in one command. Nmap is unrestricted in that regard. What makes Nmap stand out above the rest, is the complete network analysis package you get with it. It allows IP scanner, network deep-dives, hardware analysis, vulnerability analysis, encryption detailing, and so much more, in one free application
    Incentivized
    Read full review
    SonarSource Sarl
    SonarQube is an open-source. It's a scalable product. The costs for this application, for the kind of job it does, are pretty descent. Pipeline scan is more secured in SonarQube. Its a very good tool and its support multiple languages. Its main core competency is of static code analysis and that is why SonarQube exists and it does it exceedingly well. The quality of scan on code convention, best practices, coding standards, unit test coverage etc makes them one of the best competent tool in the market
    Incentivized
    Read full review
    Return on Investment
    Open Source
    • Nmap with Wireshark is free, so it's been a great combo team to gather info and test.
    • It's allowed us to avoid fines from false positives and to fix actual issues ourselves.
    • Great for finding hosts, helps keep the network secure.
    Incentivized
    Read full review
    SonarSource Sarl
    • Positive ROI from the standpoint of flagging several issues that would have otherwise likely been unaddressed and caused more time to be spent closer to launch
    • Slightly positive ROI from time-saving perspective (it's an automated check which is nice, but depending on the issues it finds, can take developers time to investigate and resolve)
    Read full review
    ScreenShots

    SonarQube Screenshots

    Screenshot of Projects.Screenshot of Static Application Security Testing.Screenshot of Software Composition Analysis.