What is SonarQube?
SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.
Company Details
Need Assistance?
We're here to help you with understanding our reports and the data inside to help you make decisions.
Get AssistanceSonarQube Ratings
Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard
to access more information on SonarQube.
90 Likeliness to Recommend
100 Plan to Renew
83 Satisfaction of Cost Relative to Value
Emotional Footprint Overview
+89 Net Emotional Footprint
The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.
How much do users love SonarQube?
Pros
- Performance Enhancing
- Respectful
- Altruistic
- Transparent
Emotional Footprint
How to Read
Positive
Neutral
Negative
The Net Emotional Footprint measures high-level user sentiment towards particular product offerings. It aggregates emotional response ratings for various dimensions of the vendor-client relationship and product effectiveness, creating a powerful indicator of overall user feeling toward the vendor and product.
While purchasing decisions shouldn't be based on emotion, it's valuable to know what kind of emotional response the vendor you're considering elicits from their users.
Footprint
Feature Ratings
Software Composition Analysis (SCA)
Automated Workflow
Dynamic Application Security Testing (DAST)
Vulnerability Scanning
Static Application Security Testing (SAST)
Interactive Application Security Testing (IAST)
Container Security Testing
False Positive Remediation
Risk Scoring
Mobile Application Security Testing
Policy Engine and Enforcements
Vendor Capability Ratings
Ease of Data Integration
Business Value Created
Breadth of Features
Ease of Implementation
Ease of IT Administration
Ease of Customization
Availability and Quality of Training
Vendor Support
Quality of Features
Usability and Intuitiveness
Product Strategy and Rate of Improvement
SonarQube Reviews
Govind S.
- Role: Consultant
- Industry: Telecommunications
- Involvement: IT Development, Integration, and Administration
Submitted Apr 2024
SonarQube: Streamlining Code Quality
Likeliness to Recommend
What differentiates SonarQube from other similar products?
1. Comprehensive Code Analysis: SonarQube offers a comprehensive set of code analysis tools that cover a wide range of programming languages and frameworks. 2. Scalability: SonarQube is highly scalable, capable of analyzing codebases of any size, from small projects to large enterprise applications. 3. Customizable Quality Profiles: SonarQube allows users to create custom quality profiles tailored to their specific project requirements. 4. ntegration Ecosystem: SonarQube integrates seamlessly with various development tools and CI/CD pipelines, including Jenkins, GitLab CI, and Azure DevOps.
What is your favorite aspect of this product?
One of the standout features of SonarQube that I find particularly impressive is its comprehensive code analysis capabilities. SonarQube offers an extensive array of static code analysis tools that provide deep insights into code quality, security vulnerabilities, and potential bugs. This level of analysis empowers development teams to proactively identify and address issues early in the development lifecycle, leading to higher-quality code and more robust software applications.
What do you dislike most about this product?
One aspect that some users may find challenging with SonarQube is its initial setup and configuration complexity. Setting up SonarQube to integrate seamlessly with existing development workflows, configuring quality profiles, defining rulesets, and establishing appropriate quality gates can require a significant investment of time and effort.
What recommendations would you give to someone considering this product?
1. Understand Your Requirements: Clearly define your organization's code quality and security requirements, as well as the specific challenges you aim to address with SonarQube. 2. Customize for Your Environment: Take advantage of SonarQube's customization options to tailor the platform to your organization's specific needs and coding standards. 3, Integrate with CI/CD Pipelines: Integrate SonarQube seamlessly into your continuous integration and continuous deployment (CI/CD) pipelines to automate code analysis and quality checks as part of your development workflow.
Pros
- Altruistic
- Helps Innovate
- Continually Improving Product
- Performance Enhancing
Amit C.
- Role: Industry Specific Role
- Industry: Healthcare
- Involvement: End User of Application
Submitted Mar 2024
SonarQube is amazing and Swift!
Likeliness to Recommend
What differentiates SonarQube from other similar products?
We can integrate SonarQube seamlessly with build tools, such as Gradle and ant
What is your favorite aspect of this product?
SonarQube reports duplicate code, code coverage, unit testing, code complexity historical.
What do you dislike most about this product?
It lacks advanced code security features.
What recommendations would you give to someone considering this product?
It's a open source and supports various languages such as C# and Java.
Pros
- Helps Innovate
- Continually Improving Product
- Reliable
- Performance Enhancing
Rajat S.
- Role: Information Technology
- Industry: Engineering
- Involvement: IT Development, Integration, and Administration
Submitted Mar 2024
Open-source with a free community edition
Likeliness to Recommend
What differentiates SonarQube from other similar products?
SonarQube promotes a philosophy of "Clean Code," guiding development towards well-structured, maintainable, and secure code. SonarQube goes beyond basic code analysis, offering robust security vulnerability detection capabilities.
What is your favorite aspect of this product?
Catching issues early in development saves time and resources compared to fixing them later in the cycle. By identifying code smells and complexities, SonarQube encourages developers to write code that's easier to understand and modify in the future.
What do you dislike most about this product?
Setting up and configuring SonarQube can be challenging for those unfamiliar with static code analysis tools. SonarQube can generate a large number of warnings, requiring developers to filter and prioritize effectively.
What recommendations would you give to someone considering this product?
Consider the size and complexity of your codebase, as well as your team's experience with static analysis tools. Begin with a pilot project using the free community edition to get comfortable with SonarQube's functionalities.
Pros
- Helps Innovate
- Continually Improving Product
- Reliable
- Performance Enhancing