Comparison

Checkmarx vs GitGuardian

On the evidence we track, GitGuardian leads this comparison with a composite score of 75/100. Scores are only directly comparable because these tools share a category; the full breakdown and every source is below.

Machine formatsJSONMarkdownGraphQLor send Accept: application/json
Checkmarx54
GitGuardian75
Score
Vioscale score
Checkmarx54 / 100low · 46%updating
GitGuardian75 / 100medium · 71%updating
Pricing
Free tier
Checkmarx
GitGuardian
Model
Checkmarxcommercial
GitGuardianfreemium
Price level
Checkmarxunknown
GitGuardianlow
Transparent
Checkmarx
GitGuardian
Integrations
Count
Checkmarx1
GitGuardian15
Security
Disclosure policy
Checkmarx
GitGuardian
Fedramp
Checkmarx
GitGuardian
Gdpr
Checkmarx
GitGuardian
Iso27001
Checkmarx
GitGuardian
Pci
Checkmarx
GitGuardian
Soc2
Checkmarx
GitGuardian
Reliability
Status page
Checkmarx
GitGuardian

Capabilities

Feature-by-feature on the axes that matter for devsecops tools. “-” means undocumented, not absent.

Scan types
SAST (static analysis)
Checkmarx
GitGuardian
DAST (dynamic analysis)
Checkmarx
GitGuardian-
SCA / dependency scanning
Checkmarx
GitGuardian-
Secret scanning
Checkmarx-
GitGuardian
Container / image scanning
Checkmarx-
GitGuardian
IaC misconfiguration scanning
Checkmarx-
GitGuardian-
Governance
OSS licence compliance
Checkmarx-
GitGuardian-
SBOM generation (SPDX/CycloneDX)
Checkmarx
GitGuardian-
Remediation
Automated fix / upgrade PRs
Checkmarx-
GitGuardian
Prioritisation
Reachability / exploitability prioritisation
Checkmarx
GitGuardian
Deployment
Hosting
CheckmarxCloud only
GitGuardianCloud + self-hosted
Integration
First-class CI / pipeline integration
Checkmarx
GitGuardian
In-editor / IDE scanning
Checkmarx
GitGuardian
Licensing
OSS engine available
Checkmarx-
GitGuardian

What each one is

The product in its own terms, so the numbers below have context.

Checkmarx

An integrated platform combining static analysis, dynamic testing, dependency scanning, and AI-powered agents to identify and prioritize vulnerabilities across the entire software development lifecycle, from code to cloud deployment.

Independently observed

GitGuardian

Leader

A platform that detects hardcoded secrets and leaked credentials in source code, CI/CD pipelines, container images, developer machines, and public repositories, then automates remediation through context-aware prioritization and integration with existing security workflows.

Independently observed

Pricing

List pricing as published by each vendor, with the date we read it. Always verify at the source before you buy.

Checkmarx

Quote-based

All three tiers require custom quote. No published per-seat or usage-based pricing.

  • EssentialsContact sales
    • SAST
    • SCA
    • API Security
    • ASPM visibility
    • Core reporting
  • ProfessionalContact sales
    • Everything in Essentials
    • DAST
    • IaC Security
    • AI Security
    • Advanced ASPM
    • +1 more
  • EnterpriseContact sales
    • Everything in Professional
    • Supply Chain Security
    • Container Security
    • Runtime Protection
    • Custom Policies
    • +1 more
as of verify ↗

GitGuardian

Leader
SubscriptionFree tier

Free Starter tier for up to 25 developers. Paid plans start with Growth tier; Enterprise and Business require custom quote.

  • StarterFree
    • Internal secrets monitoring
    • Unlimited real-time scanning
    • Multi-VCS support (GitHub, GitLab, Bitbucket, Azure Repos)
    • Developer workstations scan via Git hooks
    • Remediation tracking and guidelines
    • +2 more
  • GrowthFree trial available
    • Everything in Starter, plus:
    • Internal secrets monitoring (code, CI/CD, containers, custom sources)
    • Public secrets monitoring (limited)
    • Endpoint protection for developer machines
    • Remediation playbooks with automated routing
    • +4 more
  • BusinessContact sales
    • Internal secrets monitoring
    • Remediation playbooks
    • Up to 20 teams
    • Large repository scanning
  • EnterpriseContact sales
    • Everything in Growth, plus:
    • Unlimited public secrets monitoring
    • NHI governance (vault management, identity mapping, policy enforcement)
    • Endpoint protection (developer and standard endpoints)
    • Corporate and enterprise data sources (Jira, Slack, Confluence, file storage)
    • +5 more
as of verify ↗

Platform & deployment

Where each product runs and how it can be hosted. A dash means undocumented, not unsupported.

Platforms
Web
Checkmarx
GitGuardian
CLI
Checkmarx
GitGuardian
Deployment
Cloud / SaaS
Checkmarx
GitGuardian
Self-hosted
Checkmarx
GitGuardian
Hybrid
Checkmarx
GitGuardian

Integrations

What each product connects to. Counts come from the vendor's own integration directory where one exists.

Checkmarx

1 total
  • Wiz
Independently observed

GitGuardian

Leader
15 total
  • GitHub
  • GitHub Enterprise Server
  • GitLab
  • Bitbucket
  • Azure Repos
  • Azure DevOps
  • Jira
  • Slack
  • ServiceNow
  • Confluence
  • Docker
  • Container registries
  • HashiCorp Vault
  • CyberArk
  • AWS Secrets Manager
Independently observed

Comparison generated from independently-sourced facts. Every value links to its source and retrieval date. See the method.