Comparison

SonarQube vs Veracode

On the evidence we track, SonarQube leads this comparison with a composite score of 71/100. Scores are only directly comparable because these tools share a category; the full breakdown and every source is below.

Machine formatsJSONMarkdownGraphQLor send Accept: application/json
SonarQube71
Veracode59
Score
Vioscale score
SonarQube71 / 100high · 75%
Veracode59 / 100low · 11%
Pricing
Free tier
SonarQube
Veracode
Model
SonarQubefreemium
Veracodecommercial
Price level
SonarQubemid
Veracode
Transparent
SonarQube
Veracode
Integrations
Count
SonarQube20
Veracode
Security
Gdpr
SonarQube
Veracode
Iso27001
SonarQube
Veracode
Scorecard
SonarQube4.9
Veracode
Soc2
SonarQube
Veracode
Reliability
Sla pct
SonarQube99.9
Veracode
Status page
SonarQube
Veracode
Adoption
Dependent repos
SonarQube497
Veracode
Github stars
SonarQube10,928
Veracode
Activity
Commits last 30d
SonarQube100
Veracode
Release
Cadence days
SonarQube28
Veracode
History
SonarQube20 items
Veracode
License
Spdx
SonarQubeLGPL-3.0
Veracode
Language
Primary
SonarQubeJava
Veracode
Market

Capabilities

Feature-by-feature on the axes that matter for devsecops tools. “-” means undocumented, not absent.

Scan types
SAST (static analysis)
SonarQube
Veracode
DAST (dynamic analysis)
SonarQube
Veracode
SCA / dependency scanning
SonarQube
Veracode
Secret scanning
SonarQube
Veracode-
Container / image scanning
SonarQube
Veracode
IaC misconfiguration scanning
SonarQube
Veracode-
Governance
OSS licence compliance
SonarQube
Veracode-
SBOM generation (SPDX/CycloneDX)
SonarQube
Veracode-
Remediation
Automated fix / upgrade PRs
SonarQube
Veracode
Prioritisation
Reachability / exploitability prioritisation
SonarQube
Veracode-
Deployment
Hosting
SonarQubeCloud + self-hosted
VeracodeCloud only
Integration
First-class CI / pipeline integration
SonarQube
Veracode-
In-editor / IDE scanning
SonarQube
Veracode-
Licensing
OSS engine available
SonarQube
Veracode-

What each one is

The product in its own terms, so the numbers below have context.

SonarQube

Leader

A code verification system that scans source code repositories for bugs, security flaws, and quality problems, supporting both human-written and AI-generated code. It integrates directly into development workflows and CI/CD pipelines to provide real-time feedback and automated fix suggestions.

Independently observed

Veracode

Veracode provides unified application security posture management with tools for detecting, analyzing, and remediating application vulnerabilities across the software development lifecycle.

Independently observed

Pricing

List pricing as published by each vendor, with the date we read it. Always verify at the source before you buy.

SonarQube

Leader
from $34/moSubscriptionFree tier14-day trial

From $34/month. Free tier for open source projects. 14-day free trial.

  • Team$34/month
    • 30+ languages
    • code quality standards
    • bug and vulnerability detection
    • secret scanning
    • AI-powered code fixes
    • +2 more
  • EnterpriseContact sales
    • 40+ languages including ABAP, COBOL, Apex
    • all Team features plus
    • advanced security reports and audit logs
    • OWASP, CWE, PCI DSS, MISRA C++:2023 compliance
    • unlimited users and projects
    • +5 more
as of verify ↗

Veracode

Pricing not documented yet.

Platform & deployment

Where each product runs and how it can be hosted. A dash means undocumented, not unsupported.

Platforms
Web
SonarQube
Veracode
CLI
SonarQube
Veracode
Deployment
Cloud / SaaS
SonarQube
Veracode
Self-hosted
SonarQube
Veracode
On-premise
SonarQube
Veracode
Air-gapped
SonarQube
Veracode

Integrations

What each product connects to. Counts come from the vendor's own integration directory where one exists.

SonarQube

Leader
19 total
  • GitHub
  • GitLab
  • Bitbucket
  • Azure DevOps
  • CodeCatalyst
  • CircleCI
  • TravisCI
  • GitHub Actions
  • Jenkins
  • Codemagic
  • Slack
  • Jira
  • Linear
  • GitHub Advanced Security
  • Backstage
  • Compass
  • Cortex
  • Harness
  • Port
Independently observed

Veracode

Not documented yet.

Comparison generated from independently-sourced facts. Every value links to its source and retrieval date. See the method.