SonarQube Logo
SonarQube Logo
SonarSource SA

SonarQube

Composite Score
8.4 /10
CX Score
8.7 /10
Category
SonarQube
8.4 /10

What is SonarQube?

SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.

Company Details


Need Assistance?

We're here to help you with understanding our reports and the data inside to help you make decisions.

Get Assistance

Awards & Recognition

SonarQube won the following awards in the Application Security Testing category

SonarQube Ratings

Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard to access more information on SonarQube.

Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.

90 Likeliness to Recommend

2
Since last award

100 Plan to Renew

83 Satisfaction of Cost Relative to Value

1
Since last award


{y}
{name}

Emotional Footprint Overview

Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.

+94 Net Emotional Footprint

The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.

How much do users love SonarQube?

0% Negative
0% Neutral
100% Positive

Pros

  • Respectful
  • Transparent
  • Appreciates Incumbent Status
  • Performance Enhancing

Feature Ratings

Average 80

Vulnerability Scanning

84

SDLC Integration

82

Policy Engine and Enforcements

82

Static Application Security Testing (SAST)

81

Mobile Application Security Testing

80

Interactive Application Security Testing (IAST)

80

Dynamic Application Security Testing (DAST)

80

Risk Scoring

78

Integrated Development Environment (IDE) plug-in

78

Container Security Testing

77

False Positive Remediation

76

Vendor Capability Ratings

Average 82

Ease of Data Integration

87

Business Value Created

85

Ease of Implementation

83

Breadth of Features

83

Quality of Features

82

Ease of Customization

81

Usability and Intuitiveness

81

Vendor Support

80

Ease of IT Administration

80

Availability and Quality of Training

79

Product Strategy and Rate of Improvement

78

SonarQube Reviews

Mayank J.

  • Role: Information Technology
  • Industry: Other
  • Involvement: End User of Application
Validated Review
Verified Reviewer

Submitted Apr 2026

Keep Code Healthy with SonarQube

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

It's is handles technical debt and historical trends. It's doesn't just flag problem even it's show my codebase is evolving over time and also I can see weather things like I m improving or slowly even getting worse and which is something most tools don't really surface in s meaningful way.

What is your favorite aspect of this product?

I like about how it's stands for me in intergation into the workflow without being intrusive. Once it's part of my CI/CD pipeline than it's just keep an eye on things in the background and flags issues consistently.

What do you dislike most about this product?

I dislike one thing it can feel sometimes a bit rigid especially when I am working in s fast paced environment.

What recommendations would you give to someone considering this product?

My recommendation for my personal experience it's start small especially it you are introducing it into an existing Codebase. Another thing that helps is intergation it properly into your CI/CD pipeline and making it part of your normal development flow and also when feedback shows up early during pull requests or bulid it become much easier to act on. That's specific reason why I am using it.

Pros

  • Reliable
  • Performance Enhancing
  • Efficient Service
  • Respectful

Ananya P.

  • Role: Information Technology
  • Industry: Other
  • Involvement: End User of Application
Validated Review
Verified Reviewer

Submitted Mar 2026

Automate code quality checks early.

Likeliness to Recommend

10 /10

What differentiates SonarQube from other similar products?

It focuses on code quality and maintainability not just basic bug detection. It analyzes code continuously and highlights issues like bugs, vulnerabilities and code smells before they reach production.

What is your favorite aspect of this product?

I like most is that the issues are explained in a very practical way. It not only flags the problem but also shows why it mattera and often suggests how to fux it. This makes it easier to learn better coding practices over time.

What do you dislike most about this product?

The downside is that large codebase scans can take significant time and system resources. If the server is not properly configured, analysis can become slow and may affects the development workflow.

What recommendations would you give to someone considering this product?

Start by focusing on improving new code instead of fixing the entire old codebase, customize the rules to match your project and regularly review the reports to maintain better code quality over time.

Pros

  • Helps Innovate
  • Reliable
  • Performance Enhancing
  • Unique Features

Cons

  • Charges for Enhancements

Mujbur R.

  • Role: Information Technology
  • Industry: Technology
  • Involvement: Business Leader or Manager
Validated Review
Verified Reviewer

Submitted Jan 2026

Strong security features with a learning curve

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

SonarQube stands out because it focuses heavily on code quality and maintainability, not just security. It integrates easily into CI/CD pipelines and supports many languages, making it practical for everyday development.

What is your favorite aspect of this product?

My favorite aspect is how it gives quick, clear feedback on code quality and helps catch issues early during development.

What do you dislike most about this product?

dislike the amount of tuning needed to reduce false positives, especially in larger or older codebases.

What recommendations would you give to someone considering this product?

Start with a small project first, spend time tuning the rules, and integrate it early into your CI/CD pipeline to get the most value.

Pros

  • Enables Productivity
  • Efficient Service
  • Effective Service
  • Saves Time

Most Popular SonarQube Comparisons