We performed a comparison between Checkmarx One and Qualys Web Application Scanning based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."We were using HPE Security Fortify to scan code for security vulnerabilities, but it can scan only after a successful compile. If the code has dependencies or build errors, the scan fails. With Checkmarx, pre-compile scanning is seamless. This allows us to scan more code."
"The reports are very good because they include details on the code level, and make suggestions about how to fix the problems."
"The user interface is modern and nice to use."
"I like that you don't have to compile the code in order to execute static code analysis. So, it's very handy."
"The solution allows us to create custom rules for code checks."
"We use the solution for dynamic application testing."
"The report function is the solution's greatest asset."
"It is very useful because it fits our requirements. It is also easy to use. It is not complex, and we are satisfied with the results."
"It combines both web application vulnerability management and internal vulnerability management on one platform and dashboard. Usually, you have to purchase separate tools."
"It is a good product for website penetration testing to detect vulnerabilities."
"You can integrate your Burp Suite results and create an integrated report. Also, the way it shows the results - threats and exploit details - makes remediation very easy."
"We have experienced quick customer support. They have a complete list of our previous issues along with our history, which makes it faster for them to solve issues."
"The interface is user-friendly and easy to understand."
"With our vulnerabilities under control, it's putting our services in compliance and minimizing our risk for exposure."
"The most valuable feature is that we are able to scan the services and put credentials like a user ID password. We can verify the vulnerability level."
"Its most valuable features are patch management, vulnerability management, and PCI compliance."
"You can't use it in the continuous delivery pipeline because the scanning takes too much time."
"The plugins for the development environment have room for improvements such as for Android Studio and X code."
"Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
"I would like to see the tool’s pricing improved."
"We would like to be able to run scans from our local system, rather than having to always connect to the product server, which is a longer process."
"The reports are good, but they still need to be improved considering what the UI offers."
"Checkmarx could be improved with more integration with third-party software."
"We have received some feedback from our customers who are receiving a large number of false positives."
"The scanner reports a lot of false positives, which is something that needs to be improved."
"The virus code updates are not frequent enough."
"There should be better visibility into the application."
"Sometimes the response time is low because the handshake fails, and then you have to re-login and start again."
"Qualys Web Application Scanning is very complex to use, and its graphical interface is not very user-friendly."
"We receive false positives sometimes when using a solution that could be improved. However, the technical team provides us with the exact explanation why it was giving us that kind of error."
"Deployment can be complicated."
"The software’s pricing could be improved."
More Qualys Web Application Scanning Pricing and Cost Advice →
Checkmarx One is ranked 3rd in Application Security Tools with 67 reviews while Qualys Web Application Scanning is ranked 18th in Application Security Tools with 31 reviews. Checkmarx One is rated 7.6, while Qualys Web Application Scanning is rated 7.8. The top reviewer of Checkmarx One writes "The report function is a great, configurable asset but sometimes yields false positives". On the other hand, the top reviewer of Qualys Web Application Scanning writes "A stable solution that can be used for infrastructure vulnerability scanning and web application scanning". Checkmarx One is most compared with SonarQube, Veracode, Fortify on Demand, Snyk and Coverity, whereas Qualys Web Application Scanning is most compared with OWASP Zap, Veracode, SonarQube, PortSwigger Burp Suite Professional and Invicti. See our Checkmarx One vs. Qualys Web Application Scanning report.
See our list of best Application Security Tools vendors and best Static Application Security Testing (SAST) vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.