SonarQube Logo
SonarQube Logo
SonarSource SA

SonarQube

Composite Score
8.2 /10
CX Score
8.5 /10
Category
SonarQube
8.2 /10

What is SonarQube?

SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.

Company Details


Need Assistance?

We're here to help you with understanding our reports and the data inside to help you make decisions.

Get Assistance

Awards & Recognition

SonarQube won the following awards in the Application Security Testing category

SonarQube Ratings

Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard to access more information on SonarQube.

Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.

91 Likeliness to Recommend

1
Since last award

100 Plan to Renew

87 Satisfaction of Cost Relative to Value

3
Since last award


{y}
{name}

Emotional Footprint Overview

Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.

+93 Net Emotional Footprint

The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.

How much do users love SonarQube?

0% Negative
0% Neutral
100% Positive

Pros

  • Respectful
  • Altruistic
  • Transparent
  • Caring

Feature Ratings

Average 82

SDLC Integration

86

Vulnerability Scanning

83

Policy Engine and Enforcements

82

Static Application Security Testing (SAST)

81

Risk Scoring

81

Dynamic Application Security Testing (DAST)

81

Mobile Application Security Testing

80

Interactive Application Security Testing (IAST)

80

Container Security Testing

79

Software Composition Analysis (SCA)

78

False Positive Remediation

78

Vendor Capability Ratings

Average 83

Ease of Data Integration

90

Business Value Created

89

Breadth of Features

85

Ease of IT Administration

84

Ease of Implementation

84

Ease of Customization

82

Product Strategy and Rate of Improvement

81

Usability and Intuitiveness

81

Quality of Features

81

Availability and Quality of Training

80

Vendor Support

79

SonarQube Reviews

Jeemish M.

  • Role: Information Technology
  • Industry: Technology
  • Involvement: IT Leader or Manager
Validated Review
Verified Reviewer

Submitted Jul 2023

Enterprise scale SAST scans at zero cost !!

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

Ease of implementation and support for most common technology stacks like java, Js, .net, python, groovy, etc for SAST scans

What is your favorite aspect of this product?

Minimalistic UI and multiple technology stack support

What do you dislike most about this product?

Requires a lot of manual setup and configuration for maintenance

What recommendations would you give to someone considering this product?

Must have for implementing automated SAST scans at enterprise scale

Pros

  • Helps Innovate
  • Reliable
  • Performance Enhancing
  • Respectful

Anurag S.

  • Role: Information Technology
  • Industry: Other
  • Involvement: End User of Application
Validated Review
Verified Reviewer

Submitted Apr 2026

Keep Your Code Clean with SonarQube

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

SonarQube is holistic and continuous it is you don't just run it once or rely on spotty manual reviews because it's intergation with my bulid pipeline or CI/CD,so issues are flagged early and automatically that's means you catch messy patterned or problems ins production which helps me like life saver when I working on large web apps with multiple teams.

What is your favorite aspect of this product?

My favorite that's how it's quietly keeps my codebase honest without getting in the way. I alsor appreciate how it's gives a big picture view of my code quality over time and I can actuallu see whether my codebase id improving, which areas are accumulating technical debt and where the team might need to focus that's why the reasons why I like to work with SonarQube.

What do you dislike most about this product?

When I working on larger web project I feel a bit heavy and slow and it's fast moving features or prototyping, running a full analysis can take longer than and it can interrupt my flow. One more issue that can be frustrating in setup and configuration.

What recommendations would you give to someone considering this product?

My recommendation is to be realistic about what it is and what is it isn't because it's not magic wand that instantly fixed your code or replace human reviews it's just a tool that give you insight don't expect too much and it's help maintain long term code quality than you will get the most value from it if ou treat as part of your workflows rather than extra task. I also advise you to spend time customizing it to our codebase.

Pros

  • Helps Innovate
  • Performance Enhancing
  • Trustworthy
  • Effective Service

Cons

  • Less Friendly Negotiation

Mayank J.

  • Role: Information Technology
  • Industry: Other
  • Involvement: End User of Application
Validated Review
Verified Reviewer

Submitted Apr 2026

Keep Code Healthy with SonarQube

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

It's is handles technical debt and historical trends. It's doesn't just flag problem even it's show my codebase is evolving over time and also I can see weather things like I m improving or slowly even getting worse and which is something most tools don't really surface in s meaningful way.

What is your favorite aspect of this product?

I like about how it's stands for me in intergation into the workflow without being intrusive. Once it's part of my CI/CD pipeline than it's just keep an eye on things in the background and flags issues consistently.

What do you dislike most about this product?

I dislike one thing it can feel sometimes a bit rigid especially when I am working in s fast paced environment.

What recommendations would you give to someone considering this product?

My recommendation for my personal experience it's start small especially it you are introducing it into an existing Codebase. Another thing that helps is intergation it properly into your CI/CD pipeline and making it part of your normal development flow and also when feedback shows up early during pull requests or bulid it become much easier to act on. That's specific reason why I am using it.

Pros

  • Reliable
  • Performance Enhancing
  • Efficient Service
  • Respectful

Most Popular SonarQube Comparisons