Checkmarx One vs Parasoft SOAtest comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Checkmarx One
Ranking in Static Application Security Testing (SAST)
3rd
Average Rating
7.6
Number of Reviews
67
Ranking in other categories
Application Security Tools (3rd), Vulnerability Management (11th), Static Code Analysis (2nd), API Security (4th), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
Parasoft SOAtest
Ranking in Static Application Security Testing (SAST)
29th
Average Rating
8.2
Number of Reviews
30
Ranking in other categories
Functional Testing Tools (24th), API Testing Tools (9th), Test Automation Tools (21st)
 

Market share comparison

As of June 2024, in the Static Application Security Testing (SAST) category, the market share of Checkmarx One is 10.2% and it decreased by 20.5% compared to the previous year. The market share of Parasoft SOAtest is 0.4% and it increased by 12.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
Unique Categories:
Application Security Tools
13.2%
Vulnerability Management
1.3%
Functional Testing Tools
0.5%
API Testing Tools
2.4%
 

Featured Reviews

RB
Jul 11, 2022
Useful automation , detailed reports, but scalability could improve
We use Checkmarx as a code analysis tool We have always used some kind of code analysis tool and Checkmarx has been working for us at this time. We like the tool. The most valuable feature of Checkmarx are the automation and information that it provides in the reports. I am using Checkmarx for…
Milind Parab - PeerSpot reviewer
Jan 3, 2023
Useful for automated SQA, certifications, but the summary reports could improve
The summary reports could be improved because sometimes it is not very concise. The waiver process can also be improved because Parasoft SQAtest doesn't have a method to waive off one rule. Additionally, adding some guidance on providing standard templates could be helpful for new engineers or in complexity reduction. It could be sustained in a better way because it currently just gives the number that is a level of looping or callings. Hence, if something can be improved to refactor the code, then it should be code restructuring and all the information that can be provided to look at the complexity of the code.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The SAST component was absolutely 100% stable."
"The setup is fairly easy. We didn't struggle with the process at all."
"The most valuable feature is the simple user interface."
"We use the solution to validate the source code and do SAST and security analysis."
"It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc)."
"The administration in Checkmarx is very good."
"The value you can get out of the speedy production may be worth the price tag."
"The UI is user-friendly."
"The testing time is shortened because we generate test data automatically with SOAtest."
"Technical support is helpful."
"They have a feature where they can record traffic and create tests on the report traffic."
"If you want something that’s not provided out of the box, then you can write it yourself and integrate it with SOAtest."
"Every imaginable source in the entire world of information technology can be accessed and used."
"Automatic testing is the most valuable feature."
"Generating new messages, based on the existing .EDN and .XML messages, is a crucial part or the testing project that I’m currently in."
"Since the solution has both command line and automation options, it generates good reports."
 

Cons

"I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side."
"The integration could improve by including, for example, DevSecOps."
"Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”."
"The plugins for the development environment have room for improvements such as for Android Studio and X code."
"Checkmarx could improve the speed of the scans."
"We are trying to find out if there is a way to identify the run-time null values. I am analyzing different tools to check if there is any tool that supports run-time null value identification, but I don't think any of the tools in the market currently supports this feature. It would be helpful if Checkmarx can identify and throw an exception for a null value at the run time. It would make things a lot easier if there is a way for Checkmarx to identify nullable fields or hard-coded values in the code. The accessibility for customized Checkmarx rules is currently limited and should be improved. In addition, it would be great if Checkmarx can do static code and dynamic code validation. It does a lot of security-related scanning, and it should also do static code and dynamic code validation. Currently, for security-related validation, we are using Checkmarx, and for static code and dynamic code validation, we are using some other tools. We are spending money on different tools. We can pay a little extra money and use Checkmarx for everything."
"I would like to see the DAST solution in the future."
"C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported."
"Parasoft SOAtest has an internal refresh function where you can refresh the software to show the changes you’ve made in your projects. Unfortunately this function does not work properly, because it often does not show the changes after you’ve hit te refresh button a few times."
"Reporting facilities can be better."
"The performance could be a bit better."
"From an automation point of view, it should have better clarity and be more user friendly."
"During the process of working with SOAtest and building test cases, the .TST files will grow. A negative side effect is that saving your changes takes more time."
"Reports could be customized and more descriptive according to the user's or company's requirements."
"The summary reports could be improved."
"UI testing should be more in-depth."
 

Pricing and Cost Advice

"The average deal size was usually anywhere between $120K to $175K on an annual basis, which could be divided across 12 months."
"We have purchased an annual license to use this solution. The price is reasonable."
"​Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products."
"The solution's price is high and you pay based on the number of users."
"The number of users and coverage for languages will have an impact on the cost of the license."
"It is the right price for quality delivery."
"It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"From what I understand, Parasoft SOAtest isn't the cheapest option. But it has a lot to offer."
"The cost of Parasoft seems to have gotten higher with a projection that wasn't really stipulated for our company. They've done a tremendous job at negotiating those deals."
"They do have a confusing licensing structure."
"The license price is a little expensive, but it provides a better outcome in terms of the end-to-end automation process."
"It is an expensive product, so think carefully about whether it fits your purposes and is the right tool for you."
"We are completed satisfied with Parasoft SOAtest. The ROI is more than 95%."
"The price is around $5,000 USD."
"I think it would be a great step to decrease the price of the licenses."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
15%
Manufacturing Company
9%
Insurance Company
5%
Financial Services Firm
30%
Manufacturing Company
16%
Computer Software Company
13%
Government
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The solution's price is high and you pay based on the number of users.
What do you like most about Parasoft SOAtest?
Since the solution has both command line and automation options, it generates good reports.
What needs improvement with Parasoft SOAtest?
Tuning the tool takes time because it gives quite a long list of warnings. Going through that is a challenge. It only happens in the initial stage when we are setting up the tool, but it can be imp...
 

Comparisons

 

Also Known As

No data available
SOAtest
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Charter Communications, Sabre, Caesars Entertainment, Charles Schwab, ING, Intel, Northbridge Financial, Capital Services, WoodmenLife
Find out what your peers are saying about Checkmarx One vs. Parasoft SOAtest and other solutions. Updated: May 2024.
787,061 professionals have used our research since 2012.