Skip to main content
TrustRadius
Veracode

Veracode

Overview

What is Veracode?

Veracode is an application security platform that performs five types of analysis; static analysis, dynamic analysis, software composition analysis, interactive application security testing, and penetration testing. Veracode offers on-demand expertise and aims to help companies fix security defects.

Read more
Recent Reviews

Best in Security

10 out of 10
March 03, 2024
Incentivized
It's being used across whole organization, multiple engineering teams are using it for third-party libraries scan i.e. software …
Continue reading

Veracode to the Rescue!

10 out of 10
February 27, 2024
Veracode DAST is used on app applications in the portfolio. SAST/SCA scans and DAST scans are run monthly for all Critical application in …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Reviewer Pros & Cons

View all pros & cons

Video Reviews

1 video

Veracode Review: Provides Helpful Support When Troubleshooting Security Needs
02:38
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Veracode?

Veracode is an application security platform that performs five types of analysis; static analysis, dynamic analysis, software composition analysis, interactive application security testing, and penetration testing. Veracode offers on-demand expertise and aims to help companies fix security defects.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

940 people also want pricing

Alternatives Pricing

What is SonarQube?

SonarQube is a code quality and vulnerability solution for development teams that integrates with CI/CD pipelines to ensure the software you produce is secure, reliable, and maintainable.

What is Indusface WAS?

Indusface Web Application Scanner provides an application security audit to detect a range of high-risk Vulnerabilities, Malware, and Critical CVEs.

Return to navigation

Product Details

What is Veracode?

The Veracode platform is a software security solution that aims to be pervasive but not invasive, embedded into the environments that developers work in, with recommended fix and in-context learning. Security teams can use Veracode to manage policy, gain a comprehensive view of an organization's security posture though analytics and reporting, mitigate risks, and produce the evidence necessary to meet regulatory requirements.

It is presented as an always-on, continuous orchestration of secure development that gives organizations the confidence that the software being built is secure and meets compliance requirements.

Veracode Features

  • Supported: Continuous Scanning to reduce risks at every phase of development - Veracode Static Analysis, Dynamic Analysis, Software Composition Analysis, and Manual Penetration Test throughout SDLC.
  • Supported: Developer Experience - Finds and fixes laws in line with security integration into where developers work, automated remediation guidance, and in-context learning.
  • Supported: Comprehensive Platform Experience - Streamlined governance, risk and compliance processes through flexible policy management, unified reporting and analytics, and peer benchmarking to mitigate risks fast and deliver a successful DevSecOpsprogram.
  • Supported: Market Expansion - To meet data residency needs in EU with cloud-native instance built in Frankfurt, Germany on AWS.
  • Supported: Contextual Platform Data - Fine-tuned with nearly 2 decades of scanning and customer learning. Predicts future vulnerabilities with self-healing capabilities through applying machine learning and artificial intelligence to the data.
  • Supported: Cloud-native SaaS Architecture - Provides elastic scalability, high performance, and lower costs with cloud-native SaaS architecture.

Veracode Screenshots

Screenshot of The Veracode Platform HomepageScreenshot of Static Analysis ScansScreenshot of Findings Status and History DashboardScreenshot of The Veracode Platform

Veracode Videos

Veracode Static Analysis Demo
Veracode Software Composition Analysis Demo
Veracode Dynamic Analysis Demo

Watch The Veracode Platform

Veracode Technical Details

Deployment TypesSoftware as a Service (SaaS), Cloud, or Web-Based
Operating SystemsUnspecified
Mobile ApplicationNo
Supported CountriesNorth America, EMEA, APAC, LATAM
Supported LanguagesJava, .NET, PHP, Android, iOS, JavaScript, Python

Frequently Asked Questions

Veracode is an application security platform that performs five types of analysis; static analysis, dynamic analysis, software composition analysis, interactive application security testing, and penetration testing. Veracode offers on-demand expertise and aims to help companies fix security defects.

Checkmarx, Snyk, and SonarQube are common alternatives for Veracode.

Reviewers rate Support Rating highest, with a score of 8.

The most common users of Veracode are from Enterprises (1,001+ employees).

Veracode Customer Size Distribution

Consumers0%
Small Businesses (1-50 employees)18%
Mid-Size Companies (51-500 employees)65%
Enterprises (more than 500 employees)17%
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(197)

Attribute Ratings

Reviews

(1-25 of 27)
Companies can't remove reviews or game the system. Here's why
Score 7 out of 10
Vetted Review
Verified User
Incentivized
The interface is easy to figure out, the information is well presented, and the reporting features are easy to consume, however, the interface is slow, and integrating with CI/CD could be better. Occasionally scans fail and need to be manually cleared using the web interface, and instead of Veracode automatically re-scanning every once in a while (when the Veracode engine updates), we have to schedule re-scans on our side, which adds some CI/CD setup burden to the process.
Teresa Kosinski | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Once you become accustomed to using Veracode, you will more thoroughly understand the many ways in which you can use their tools. My only complaint is that it can be a bit daunting for new users of the platform. Perhaps some "Introduction to Veracode Tools" would be helpful for new users.
February 27, 2024

Veracode to the Rescue!

Score 10 out of 10
Vetted Review
Verified User
It takes a bit of time to get developers up to speed on setups, triage, working with defects, etc. For developers who have a backgound in scanners and computer science, they can more rapidly understand concepts like taint analysis and that makes it simpler for them to gain the best uses from the product(s). Since all scanning is tied to an application, it's easy to find everything one needs to know about the app's security and lifecycle in one place.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
I believe this platform to be one of the most user friendly out there. After evaluating some other competitor platforms, I've seen one other that comes close to ease of use and others not so much. That is one of the main reasons we continue to renew with Veracode. Areas for improvement continue to be the analytics section and a very quick to annoy idle timer.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
For people who don't use the Veracode platform all the time it can be a little challenging, so when I need developers to check on a vulnerability I may need to hop on a call to walk them through the UI. Otherwise the integrations with pipelines, IDEs, reporting tools is pretty easy.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Overall Veracode's static scanning tool works well and is pretty intuitive. I do find myself trying to remember how to find certain features or screens from time to time, but I eventually stumble upon them. To be fair, I am only in the tool once every three months. I do find their dynamic scanning tool a bit confusing regarding the setup and configuration of a target URL. I do eventually find things but I do believe this process could be improved upon.
February 23, 2021

It's decent

Score 1 out of 10
Vetted Review
Verified User
Incentivized
You can do the upload process manually or automated the upload via CICD as well. It takes a long long time to upload it to the servers (from SEA region at least) and the UI is kinda confusing to me. There was some kind of refresh on the UI last year, but UX can be improved.
Śrinivāsa Rao Kuruba | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
- Almost no setup required and easy to configure
- Very easy to use, intuitive UI with integrated analytics and learning portals.
- Seamless to review the results, triage them, generate reports.
- Security progression of the product/application is tracked via successive scans.
- Privileges/Roles nicely fine grained and tightly controlled to let teams "view" only their products.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Setting up the scans isn't too difficult and there is documentation on them. Navigating the portal and understanding the report is not as easy as we would've liked. The end to end process was quite confusing and we did not see or receive any documentation on it.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
It offer versatile interface for kicking off code security scanning. We can submit for code scanning from Visual Studio on application we are still working on. We can manually upload our application files for scanning using the web interface. We can also install Veracode extension to our TFS instance to kick off automatic code scanning in our building/release definitions.
October 16, 2020

Veracode Review

Score 10 out of 10
Vetted Review
Verified User
Incentivized
Veracode provides scanning results and, especially on SAST and DAST, is very fast and easy to use and has updated plugins.
David Nelson-Gal | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
This used to be terrible. Had a difficult time figuring out where information was. Partly this was due to duplicative features, jargon labels, and user navigation. However, in the seven years I've been using the product, it has gotten better.

Some of my issues were associated with trying to get scans to work unassisted. Now that scans, once set up, just run periodically, I don't have to deal with that as much. Part of this might also be that I've learned what I need to know about getting around. And still part of this assessment is in comparison to other tools out there that are even worse.

Still, they could benefit from an investment in a full useability redesign from someone with an outside perspective, modernizing the UX but also studying and working through the bigger usability concerns. I would love to see better diagnostic tools around getting scans to work so I wouldn't need their tech support people to get scans to work. However, as long as the scheduler keeps going, my needs on this get ever rarer.
October 12, 2020

My Veracode Review

Score 1 out of 10
Vetted Review
Verified User
Incentivized
The UI is dated, messy, unresponsive, a real nightmare. SourceClear before it was integrated was better, now it's a mess that only support can explain.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
The platform has many features that were not relevant to use, retrieving the different reports was not always straightforward and sometimes required special assistance. Overall I think the platform could use a UX refresh. I did not have considerable issues using the platform, however I think some less technical users would require significant training in order to effective use the product to meet their various needs.
October 02, 2020

Veracode review

Score 8 out of 10
Vetted Review
Verified User
Incentivized
The analysis just takes longer. I think all other aspects from scan time, to reporting, to compliance checking are all great. But when I go to do analysis of the findings, I have to dig through my project to find each file with findings and drag it into the browser. Just takes a lot longer sadly.
October 01, 2020

My Veracode Review

Yaniv Toplian | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
It's a new tool so there is a learning curve to adopt, learn, and use it. Overall, it was okay. Still, there are some UX improvements to consider, to navigate more easily to find your project and its related sub-project libraries.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Now that we know how Veracode wants us to prepare and submit our code for scanning, it's pretty straightforward. Still, I would like for Veracode to have a module that would connect with Xcode so that creating and submitting the archives for scanning is more baked-in.
Return to navigation