SonarQube Logo Award Winner Product Badge
SonarQube Logo Award Winner Product Badge
SonarSource SA

SonarQube

Composite Score
8.4 /10
CX Score
8.7 /10
Category
SonarQube
8.4 /10

What is SonarQube?

SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.

Company Details


Need Assistance?

We're here to help you with understanding our reports and the data inside to help you make decisions.

Get Assistance

Awards & Recognition

SonarQube won the following awards in the Application Security Testing category

Filter By

SonarQube Ratings

Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard to access more information on SonarQube.

Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.

90 Likeliness to Recommend

100 Plan to Renew

82 Satisfaction of Cost Relative to Value

1
Since last award


{y}
{name}

Emotional Footprint Overview

Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.

+94 Net Emotional Footprint

The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.

How much do users love SonarQube?

0% Negative
0% Neutral
100% Positive

Pros

  • Transparent
  • Caring
  • Over Delivered
  • Appreciates Incumbent Status

Feature Ratings

Average 80

Vulnerability Scanning

83

Policy Engine and Enforcements

82

Static Application Security Testing (SAST)

82

Mobile Application Security Testing

81

SDLC Integration

80

Dynamic Application Security Testing (DAST)

80

Interactive Application Security Testing (IAST)

79

Risk Scoring

79

Container Security Testing

78

Integrated Development Environment (IDE) plug-in

78

False Positive Remediation

76

Vendor Capability Ratings

Average 82

Ease of Data Integration

87

Business Value Created

84

Ease of Implementation

84

Breadth of Features

82

Vendor Support

81

Ease of Customization

81

Quality of Features

80

Availability and Quality of Training

80

Product Strategy and Rate of Improvement

80

Usability and Intuitiveness

80

Ease of IT Administration

79

SonarQube Reviews

Chiesa B.

  • Role: Information Technology
  • Industry: Insurance
  • Involvement: End User of Application
Validated Review
Verified Reviewer

Submitted Mar 2025

My preferred tool for code quality analysis .

Likeliness to Recommend

8 /10

What differentiates SonarQube from other similar products?

I love and appreciate that Sonarqube integrates with the CI/CD ( continuous integration and continuous deployment ) infrastructure on Gitlab. This comes with a whole lot of benefit when developing software , including helping to comply with best coding standards and practices, it also helps with facilitating collaboration between developers and reviewers in the process of developing software. Of importance is the early detection of security risks within the development process, even before code is passed into the repository.

What is your favorite aspect of this product?

Among the main strength of Sonarqube is its support for different programming languages. This makes Sonarqube the unified tool to use for the purpose of analyzing code quality, regardless of the programming language in which the code was written.

What do you dislike most about this product?

In situations where we have tried to reuse legacy codebases, we have noticed that Sonarqube easily gets overwhelmed by the inherent technical debt and problems which are common on legacy codebases. Of importance, is its tendency to generate a lot of false positives when working on Legacy codes.

What recommendations would you give to someone considering this product?

As far as enterprise level code management is concerned , I think Sonarqube is the tool I recommend because of its rule based analysis and its support for a variety of programming languages. It is important though, that it is setup and customized properly.

Pros

  • Reliable
  • Performance Enhancing
  • Enables Productivity
  • Security Protects

Jeemish M.

  • Role: Information Technology
  • Industry: Technology
  • Involvement: IT Leader or Manager
Validated Review
Verified Reviewer

Submitted Jul 2023

Enterprise scale SAST scans at zero cost !!

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

Ease of implementation and support for most common technology stacks like java, Js, .net, python, groovy, etc for SAST scans

What is your favorite aspect of this product?

Minimalistic UI and multiple technology stack support

What do you dislike most about this product?

Requires a lot of manual setup and configuration for maintenance

What recommendations would you give to someone considering this product?

Must have for implementing automated SAST scans at enterprise scale

Pros

  • Helps Innovate
  • Reliable
  • Performance Enhancing
  • Respectful

Mayank A.

  • Role: Information Technology
  • Industry: Technology
  • Involvement: End User of Application
Validated Review
Verified Reviewer

Submitted Aug 2026

Smarter code quality, better development

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

I enjoy SonarQube because I get a clear image of code quality when I am developing. It brings together the flaws, vulnerabilities and code smells so I don’t have to rely solely on manual code reviews. Plus it integrates with CI/CD so it is handy for spotting bugs before they go to production.

What is your favorite aspect of this product?

I like the code analysis. It gives me good input on how I can improve, and spot problems earlier in the development process. I think the quality gate approach also useful to keep the projects consistent.

What do you dislike most about this product?

Some of the results may require further study to discover their true significance. It can also take some effort to learn and tune the rules, especially for a big code base.

What recommendations would you give to someone considering this product?

I would advocate to include SonarQube into the development and CI/CD workflow from the beginning. Start with a small number of quality rules you can cope with and then tune them up or down as needed to fit the needs of your project. This makes it easy for developers to solve concerns, rather than getting buried with findings.

Pros

  • Helps Innovate
  • Continually Improving Product
  • Reliable
  • Performance Enhancing

Most Popular SonarQube Comparisons