Veracode Static Analysis Logo
Veracode Static Analysis Logo
Veracode

Veracode Static Analysis

Composite Score
7.8 /10
CX Score
8.2 /10
Category
Veracode Static Analysis
7.8 /10

What is Veracode Static Analysis?

Veracode Static Analysis provides fast, automated security feedback in the IDE and the pipeline, and conducts a full policy scan before deployment. It then provides clear guidance on what issues to focus on and how to fix them faster.

Company Details


Need Assistance?

We're here to help you with understanding our reports and the data inside to help you make decisions.

Get Assistance

Awards & Recognition

Veracode Static Analysis won the following awards in the Application Security Testing category

Veracode Static Analysis Ratings

Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard to access more information on Veracode Static Analysis.

Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.

87 Likeliness to Recommend

1
Since last award

100 Plan to Renew

79 Satisfaction of Cost Relative to Value

7
Since last award


{y}
{name}

Emotional Footprint Overview

Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.

+95 Net Emotional Footprint

The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.

How much do users love Veracode Static Analysis?

0% Negative
8% Neutral
92% Positive

Pros

  • Helps Innovate
  • Continually Improving Product
  • Enables Productivity
  • Trustworthy

Feature Ratings

Average 75

Interactive Application Security Testing (IAST)

83

Vulnerability Scanning

83

Software Composition Analysis (SCA)

81

Static Application Security Testing (SAST)

80

Container Security Testing

79

Risk Scoring

74

Mobile Application Security Testing

74

Dynamic Application Security Testing (DAST)

73

Policy Engine and Enforcements

73

SDLC Integration

73

False Positive Remediation

73

Vendor Capability Ratings

Average 77

Ease of Data Integration

81

Ease of Implementation

81

Ease of IT Administration

79

Ease of Customization

78

Usability and Intuitiveness

78

Quality of Features

76

Vendor Support

76

Availability and Quality of Training

75

Business Value Created

75

Breadth of Features

73

Product Strategy and Rate of Improvement

73

Veracode Static Analysis Reviews

Rajat S.

  • Role: Information Technology
  • Industry: Engineering
  • Involvement: IT Development, Integration, and Administration
Validated Review
Verified Reviewer

Submitted Mar 2024

Veracode boasts a powerful scanning engine

Likeliness to Recommend

9 /10

What differentiates Veracode Static Analysis from other similar products?

Unlike most SAST tools that require source code, Veracode can analyze compiled binaries. This is crucial for applications where source code isn't readily available, expanding its reach

What is your favorite aspect of this product?

Each vulnerability has a detailed explanation, helping developers understand the root cause and potential impact. Veracode prioritizes vulnerabilities based on severity and exploitability, allowing developers to focus on the most critical issues first.

What do you dislike most about this product?

Veracode is a commercial product with tiered pricing plans, which can be expensive for smaller teams or those with limited budgets. Setting up and configuring Veracode can be challenging for beginners, especially for teams unfamiliar with SAST tools. The comprehensive nature requires some learning curve.

What recommendations would you give to someone considering this product?

Consider your team's experience with SAST tools. If your team is new to these tools, the initial learning curve for Veracode might be steeper.

Pros

  • Helps Innovate
  • Continually Improving Product
  • Reliable
  • Performance Enhancing

Saurabh G.

  • Role: Information Technology
  • Industry: Engineering
  • Involvement: Initial Implementation
Validated Review
Verified Reviewer

Submitted Mar 2024

"Great tool to find security flaws"

Likeliness to Recommend

10 /10

What differentiates Veracode Static Analysis from other similar products?

My company is using Veracode as the first item to be run before a Application Security Review. It shows the items that are the possible problems before running a dynamic vulnerability scan.

What is your favorite aspect of this product?

Veracode is good static analysis tool to find security flaws. I use this tool to scan my java microservices jar files. it's easy to configure. It does not require source code and accepts binary files and scans them. We can either manually scan files or integrate with jenkin so jars are auto scanned on every build.

What do you dislike most about this product?

Can take some time. It could be better if scanning time is improved.

What recommendations would you give to someone considering this product?

Just give it a try and see how much better you will operate!

Pros

  • Helps Innovate
  • Continually Improving Product
  • Reliable
  • Performance Enhancing

Mohamed F.

  • Role: Information Technology
  • Industry: Technology
  • Involvement: IT Development, Integration, and Administration
Validated Review
Verified Reviewer

Submitted Feb 2024

Likeliness to Recommend

9 /10

Pros

  • Performance Enhancing
  • Enables Productivity
  • Unique Features
  • Efficient Service

Most Popular Veracode Static Analysis Comparisons