Rencore Code (SPCAF) vs. Sonatype Platform

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Rencore Code (SPCAF)
Score 8.8 out of 10
Enterprise companies (1,001+ employees)
Many organizations that use Office 365 are exposed to security risks that they are unaware of. As they extend SharePoint to meet their business needs, they build applications using technologies that range from end-user Microsoft Flow to developer-focused SharePoint Framework. Unfortunately, all of these custom applications are capable of circumventing the security measures organizations have in place exposing the organization and its data to security…N/A
Sonatype Platform
Score 8.7 out of 10
Enterprise companies (1,001+ employees)
Sonatype secures the software supply chain and protects organizations' vital software development lifecycle(SDLC). The platform unites security teams and developers to accelerate digital innovation without sacrificing security or quality across the SDLC. With users among more than 2,000 organizations and 15 million software developers, Sonatype tools and guidance help users to deliver and maintain exceptional and secure software.
$165
Per user per month, billed annually per user
Pricing
Rencore Code (SPCAF)Sonatype Platform
Editions & Modules
No answers on this topic
Sonatype Nexus Repository
$145
per year per user
Sonatype Air-Gapped Environment Nexus Repository
$175
per year per user
Sonatype Repository Firewall
$224
per year per user
Sonatype Repository Firewall for Artifactory
$224
per year per user
Sonatype Air-Gapped Environment Repository Firewall
$230
per year per user
Sonatype Repository Firewall Cloud
$265
per year per user
Sonatype Lifecycle
$690
per year per user
Sonatype Lifecycle Cloud
$810
per year per user
Sonatype Air-Gapped Environment Lifecycle
$825
per year per user
Offerings
Pricing Offerings
Rencore Code (SPCAF)Sonatype Platform
Free Trial
YesYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
YesNo
Entry-level Setup FeeOptionalRequired
Additional Details
More Pricing Information
Community Pulse
Rencore Code (SPCAF)Sonatype Platform
Top Pros
Top Cons
Best Alternatives
Rencore Code (SPCAF)Sonatype Platform
Small Businesses
GitLab
GitLab
Score 8.9 out of 10

No answers on this topic

Medium-sized Companies
GitLab
GitLab
Score 8.9 out of 10
Veracode
Veracode
Score 8.6 out of 10
Enterprises
GitLab
GitLab
Score 8.9 out of 10
Veracode
Veracode
Score 8.6 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Rencore Code (SPCAF)Sonatype Platform
Likelihood to Recommend
8.8
(11 ratings)
8.5
(12 ratings)
Support Rating
9.1
(2 ratings)
10.0
(1 ratings)
User Testimonials
Rencore Code (SPCAF)Sonatype Platform
Likelihood to Recommend
Rencore
For Microsoft shops that are doing custom development on the Microsoft cloud platform in Office 365 and Azure, the Rencore toolset is an absolute must, especially if you are involved in converting farm solutions to cloud, or just moving into cloud development for the first time.
Read full review
Sonatype
For a medium to large size organization with the possibility to setup a central support team to support the governance, maintenance and implementation of the Sonatype Platform, the product suite from Sonatype is very well suited. Setting up detailed configurations requires quite some effort and deep understanding of the Sonatype Platform. Whenever needed the support teams from Sonatype are available for technical and functional support. As well the Innovate platform of Sonatype offers customers to interact on specific topics and set up customer reference calls.
Read full review
Pros
Rencore
  • Unique expert knowledge of their target platforms. Not many companies have such a unique position in their target market. Their employees have a deep understanding of SharePoint, Office 365 and Azure and also regularly advise Microsoft on these matters.
  • Community involvement and contribution to open source projects. Key employees at Rencore are considered thought leaders in their area of expertise and contribute to high profile Microsoft open source initiatives.
  • Rencore's unique position when it comes to code quality analysis in the SharePoint space sets it apart. There's really no alternative.
  • Platform governance is another Rencore strength. No other product provides the insights into your SharePoint Online environment with full auditing of not only configuration changes but also who changed which code where and when. Again no alternatives exist.
Read full review
Sonatype
  • Nexus firewall is a great feature enabled for all our proxy repositories which are used to download the third-party opensource packages.
  • Nexus IQ is integrated with build stage to analyze the component against evaluation policy. This helps to figure out the application security standards.
  • Nexus IQ is also having a feature to scan container images before it uploads to our private repository. This is great feature for container platforms.
Read full review
Cons
Rencore
  • Rencore's product line is of course still a bit of a niche: SharePoint code quality is not something every organization on the planet is concerned with - although Rencore does much more than that.
  • We feel Rencore's marketing efforts are mainly targeted at technologists. There's a lot of other potential, especially for their platform governance product.
Read full review
Sonatype
  • Recommendations for best Energy Consumption options based on existing BOM - e.g. replace component X with component Y to reduce CPU cycles.
  • More specific recommendations regarding Open Source Licensing - not just saying "Copyleft" but the next level of analysis (it's difficult - but would save a lot of time)
  • Provide specific component replacement options where no "next version" resolves a high severity vulnerability.
Read full review
Support Rating
Rencore
Rencore support is unbeatable
Read full review
Sonatype
Monthly touchpoints with Sinisa has been very valuable.
Read full review
Alternatives Considered
Rencore
I don't know of any products that compete in the space and if there were any, they would not stand a chance against Rencore. Behind any good product is a team of highly skilled individuals, who all have the same goal, who are passionate what they do and lastly, are in it for the betterment of where they started; As Developers themselves. You can't buy that
Read full review
Sonatype
Out of other products we evaluated before choosing Sonatype, the later looked far more user friendly, easy to understand and work with. This was key for us, as the tool needs to be used by many engineers that don't have security as their main focus. Having a tool that is easy to understand and work with, makes the process of evaluating open source dependencies much easier and appealing for developers.
Read full review
Return on Investment
Rencore
  • The clear impact was the amount of time saved code reviewing or going through lines of code marked off by other tools that are not relevant. We cannot put a number on it since the project started off with the tool in place but based on the rules applied it could be as high as 20% of the project time.
Read full review
Sonatype
  • Sonatype Nexus has a positive ROI my organization. It has saved cost of hardware and network bandwidth by acting as repository manager
  • It has eliminated vulnerability threats by checking the components for security risk and vulnerabilities
  • It has allowed the management of the artifacts thus saving on the disk space on servers
Read full review
ScreenShots

Rencore Code (SPCAF) Screenshots

Screenshot of Using third party libraries allows you to build your SharePoint and Office 365 applications faster and focus on functionality specific for your organization. But regularly, security vulnerabilities are discovered in these external dependencies. If left unpatched, they become a security risk for your organization and its data. Rencore automatically warns you when any of the third-party libraries used in your applications has known vulnerabilities that could be exploited to hack your environment.Screenshot of Third-party libraries are regularly updated to improve performance and stability. Many organizations however don’t know when a new version of the library they use in their SharePoint and Office 365 applications is released and they keep using the old versions which exposes them not only to bugs but also to security risks. Rencore automatically warns you when a new version of a library that you use is available allowing you to verify the contents and the impact of the upgrade.Screenshot of Without proper tooling, it’s impossible to successfully enforce an application governance plan in SharePoint and Office 365. The number of ways in which users could possibly extend SharePoint combined with the thousands of pages and hundreds of settings that can be configured, make it impossible to continuously monitor for alignment with the organizational policies. 

Rencore helps you understand the configuration of your tenant as well as discover the different SharePoint and Office 365 applications used in your organization. With Rencore you will easily understand how these applications are built, which dependencies they have and which possible risks they expose your organization to.Screenshot of Your organization tailors SharePoint and Office 365 to its specific needs to get more value of its investment in the platform. But each organization has different needs and is subject to different laws and regulations. 

Rencore allows you to configure what policies you want to enforce in your tenant. Each violation gets reported so that you can take corrective action and successfully enforce your organization’s application governance plan.Screenshot of As you start discovering issues in your SharePoint and Office 365 environment, you will be taking corrective actions to mitigate the risks. Rencore helps you track these issues and the related tasks so that you can easily follow up on the status of each issue and control that your organization is improving over time.Screenshot of It’s not enough to have your SharePoint and Office 365 applications verified for compliancy with your organization’s policies before using them in production. As your applications evolve, they will require changes and each change exposes you to a number of risks. Rencore helps you track how your applications change over time, even if these applications don’t follow centralized deployment and are managed by power-users. Each change is assessed for potential risks that it could expose your organization to.

Sonatype Platform Screenshots

Screenshot of Sonatype LifecycleScreenshot of Sonatype Lifecycle - Chrome extensionScreenshot of Sonatype Advanced Legal PackScreenshot of Sonatype Nexus RepositoryScreenshot of Sonatype Nexus Repository ManagerScreenshot of Remediation of vulnerabilities