SonarQube Logo
SonarQube Logo
SonarSource SA

SonarQube

7.9 /10
Category
SonarQube
7.9 /10

What is SonarQube?

SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.

Company Details


Need Assistance?

We're here to help you with understanding our reports and the data inside to help you make decisions.

Get Assistance

SonarQube Ratings

Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard to access more information on SonarQube.

90 Likeliness to Recommend

100 Plan to Renew

83 Satisfaction of Cost Relative to Value


{y}
{name}

Emotional Footprint Overview

+89 Net Emotional Footprint

The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.

How much do users love SonarQube?

0% Negative
0% Neutral
100% Positive

Pros

  • Performance Enhancing
  • Respectful
  • Altruistic
  • Transparent

Feature Ratings

Average 83

Software Composition Analysis (SCA)

89

Automated Workflow

88

Dynamic Application Security Testing (DAST)

86

Vulnerability Scanning

84

Static Application Security Testing (SAST)

84

Interactive Application Security Testing (IAST)

83

Container Security Testing

82

False Positive Remediation

82

Risk Scoring

81

Mobile Application Security Testing

79

Policy Engine and Enforcements

79

Vendor Capability Ratings

Average 80

Ease of Data Integration

90

Business Value Created

87

Breadth of Features

85

Ease of Implementation

84

Ease of IT Administration

80

Ease of Customization

78

Availability and Quality of Training

78

Vendor Support

77

Quality of Features

77

Usability and Intuitiveness

75

Product Strategy and Rate of Improvement

72

SonarQube Reviews

Chintan G.

  • Role: Information Technology
  • Industry: Entertainment
  • Involvement: IT Leader or Manager
Validated Review
Verified Reviewer

Submitted Nov 2022

Fine product for detecting code vulnerabilities

Likeliness to Recommend

8 /10

What differentiates SonarQube from other similar products?

SonarQube has large library of various programming language code vulnerabilities and defects.

What is your favorite aspect of this product?

SonarQube provides multi-language static analysis. Their publicly available ruleset includes thousands of rules covering various issue categories and language standards.

What do you dislike most about this product?

Nothing specifically as of now.

What recommendations would you give to someone considering this product?

Try to integrate this at every stage of project development within your CI/CD pipeline. This way you will utilize the real value of the product as it can then detect majority of the vulnerabilities.

Pros

  • Helps Innovate
  • Inspires Innovation
  • Generous Negotitation
  • Performance Enhancing

Cons

  • Commodity Features
  • Vendor Friendly Policies
  • Less Fair

Mary V.

  • Role: Information Technology
  • Industry: Technology
  • Involvement: IT Leader or Manager
Validated Review
Verified Reviewer

Submitted Jun 2022

My experience with SonarQube.

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

Code analysis, minimizing coding violations, ensuring that code complexity is resolved and complies with industry standards, running a health report for every check-in to the repository, removing duplicate methods or code, empty methods, and making sure we have a plan in place for the required.Our staff may visit the cloud-based server where SonarQube is running to assess the caliber of their code.

What is your favorite aspect of this product?

One of the main advantages is the connection with Jenkins. It's an excellent feature for enterprise apps since it makes the entire process easier and allows you to incorporate the tollgate idea. also SonarQube provides strong capabilities to maintain the quality of your code by eliminating bugs, which also increases the code's security.

What do you dislike most about this product?

It takes some time to integrate Sonarqube into CI/CD pipelines, and if the developer is less experienced, it can take even longer. The offered help guide also needs to be more recent. Finally, it would be great if there was a way to download the report and provide it to the teams.

What recommendations would you give to someone considering this product?

When using this tool, it is crucial to note that not all IDE codes can be used in SonarQube, so be careful when choosing them. Static scans are easy to incorporate into your DevOps lifecycle and have several benefits. We recommend companies to use this technology to guarantee the expected performance.

Pros

  • Performance Enhancing
  • Trustworthy
  • Unique Features
  • Efficient Service

Alexis P.

  • Role: Sales Marketing
  • Industry: Technology
  • Involvement: IT Development, Integration, and Administration
Validated Review
Verified Reviewer

Submitted Jan 2022

Great product, easy implementation

Likeliness to Recommend

10 /10

What differentiates SonarQube from other similar products?

Works best for the company I am with.

What is your favorite aspect of this product?

Easy implementation and use.

What do you dislike most about this product?

Nothing. Service is great and easy to use

What recommendations would you give to someone considering this product?

Look at your options and see what's the best fit for your company

Pros

  • Helps Innovate
  • Continually Improving Product
  • Reliable
  • Performance Enhancing