# Checkmarx vs SonarQube

**Leader by vioscaleAI score:** SonarQube

| Attribute | Checkmarx | SonarQube |
|---|---|---|
| **vioscaleAI score** | 53.6 (46% (low)) | 70.9 (76% (high)) |
| activity.commits_last_30d | - | 100 |
| adoption.dependent_repos | - | 497 |
| adoption.github_stars | - | 10,969 |
| content.faq | `[{"answer":"Checkmarx integrates static analysis (SAST), dynamic analysis (DAST), dependency scanning (SCA), and specialized AI-based analysis to detect vulnerabilities across code, dependencies, and AI components. It prioritizes findings by exploitability and reachability while embedding directly into development tools and CI/CD pipelines. It is indexed under DevSecOps Tools.","source":"https://checkmarx.com","question":"What is Checkmarx?","confidence":0.6},{"answer":"Checkmarx does not publish its prices. Pricing is quoted on request, across 3 plans (Essentials, Professional and Enterprise), so the figure depends on your seat count and requirements. We record this as a pricing-transparency signal rather than guessing a number. Pricing changes often, so verify at source before relying on it.","source":"https://checkmarx.com","question":"How much does Checkmarx cost?","confidence":0.6},{"answer":"We have confirmed browser-based access to Checkmarx. That is the extent of what we could verify from public sources, so it may well offer desktop or mobile clients we have not indexed.","source":"https://checkmarx.com","question":"What platforms does Checkmarx support?","confidence":0.6},{"answer":"We have only confirmed a cloud / SaaS deployment for Checkmarx, so it appears to be vendor-hosted. If a self-hosted option exists we have not found it documented publicly.","source":"https://checkmarx.com","question":"Can Checkmarx be self-hosted?","confidence":0.6},{"answer":"We have independently confirmed SOC 2, ISO 27001 and GDPR for Checkmarx. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Checkmarx not holding them. Always confirm compliance directly before you rely on it.","source":"https://checkmarx.com/blog/security-in-vibe-coding/","question":"What security certifications does Checkmarx have?","confidence":0.7},{"answer":"Checkmarx is available in Australia, Germany, France, the United Kingdom, Israel, India, Portugal and Singapore. The vendor is headquartered in Israel.","source":"https://checkmarx.com","question":"Where is Checkmarx available?","confidence":0.75}]` | `[{"answer":"A code verification system that scans source code repositories for bugs, security flaws, and quality problems, supporting both human-written and AI-generated code. It integrates directly into development workflows and CI/CD pipelines to provide real-time feedback and automated fix suggestions. It is indexed under DevSecOps Tools.","source":"https://www.sonarsource.com/jp/plans-and-pricing/","question":"What is SonarQube?","confidence":0.6},{"answer":"SonarQube offers a free tier, so you can start without paying. Paid plans start at $34 per month. Prices are published openly on the vendor's own pricing page. Pricing changes often, so verify at source before relying on it.","source":"https://www.sonarsource.com/jp/plans-and-pricing/","question":"Is SonarQube free?","confidence":0.6},{"answer":"SonarQube supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.","source":"https://www.sonarsource.com/jp/plans-and-pricing/","question":"What platforms does SonarQube support?","confidence":0.6},{"answer":"Yes. SonarQube can be deployed cloud / SaaS, on-premise, air-gapped and self-hosted, so it does not have to run on the vendor's infrastructure.","source":"https://www.sonarsource.com/jp/plans-and-pricing/","question":"Can SonarQube be self-hosted?","confidence":0.6},{"answer":"We have confirmed 17 integrations for SonarQube, including GitHub, GitLab, Bitbucket, Azure DevOps, CodeCatalyst, CircleCI, TravisCI and Jenkins, plus 9 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.","source":"https://www.sonarsource.com/jp/plans-and-pricing/","question":"What does SonarQube integrate with?","confidence":0.6},{"answer":"We have independently confirmed SOC 2, ISO 27001 and GDPR for SonarQube. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as SonarQube not holding them. Always confirm compliance directly before you rely on it.","source":"https://www.sonarsource.com/products/sonarqube/","question":"What security certifications does SonarQube have?","confidence":0.48},{"answer":"Yes. SonarQube is published under the LGPL-3.0 licence, a copyleft licence, so check its terms before embedding it in a closed-source product. Licence terms can change between releases, so verify against the repository for the version you intend to use.","source":"https://github.com/SonarSource/sonarqube","question":"Is SonarQube open source?","confidence":0.95},{"answer":"SonarQube is available worldwide. Its primary markets are the United States and the EU. The vendor is headquartered in Switzerland.","source":"https://www.sonarsource.com/jp/plans-and-pricing/","question":"Where is SonarQube available?","confidence":0.75}]` |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"self_hosted":true}` |
| description.long | Checkmarx integrates static analysis (SAST), dynamic analysis (DAST), dependency scanning (SCA), and specialized AI-based analysis to detect vulnerabilities across code, dependencies, and AI components. It prioritizes findings by exploitability and reachability while embedding directly into development tools and CI/CD pipelines. | A code verification system that scans source code repositories for bugs, security flaws, and quality problems, supporting both human-written and AI-generated code. It integrates directly into development workflows and CI/CD pipelines to provide real-time feedback and automated fix suggestions. |
| features.capabilities | `{"sca":true,"dast":true,"sast":true,"sbom":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"iac_scanning":true,"reachability":true,"secret_scanning":true}` | `{"sca":true,"dast":false,"sast":true,"sbom":true,"hosting":"both","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":true,"iac_scanning":true,"reachability":true,"secret_scanning":true,"container_scanning":true,"license_compliance":true}` |
| integrations.count | 1 | 20 |
| integrations.list | `[{"name":"Wiz"}]` | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"Bitbucket"},{"name":"Azure DevOps"},{"name":"CodeCatalyst"},{"name":"CircleCI"},{"name":"TravisCI"},{"name":"GitHub Actions"},{"name":"Jenkins"},{"name":"Codemagic"},{"name":"Slack"},{"name":"Jira"},{"name":"Linear"},{"name":"GitHub Advanced Security"},{"name":"Backstage"},{"name":"Compass"},{"name":"Cortex"},{"name":"Harness"},{"name":"Port"},{"name":"Bitbucket Pipelines","native":true,"category":"ci_cd"},{"name":"GitLab CI","native":true,"category":"ci_cd"},{"name":"Bamboo","native":true,"category":"ci_cd"}]` |
| language.primary | - | Java |
| license.spdx | - | LGPL-3.0 |
| market.availability | `{"hqCountry":"IL","primaryMarkets":[],"availabilityScope":"global","availableCountries":["AU","DE","FR","GB","IL","IN","PT","SG","US"],"notAvailableCountries":[]}` | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"quote","plans":[{"free":false,"name":"Essentials","summary":"Custom quote required","features":["SAST","SCA","API Security","ASPM visibility","Core reporting"],"description":"Core application security coverage. Establish a unified foundation for identifying, managing, and reporting application risk.","contactSales":true},{"free":false,"name":"Professional","summary":"Custom quote required","features":["Everything in Essentials","DAST","IaC Security","AI Security","Advanced ASPM","PR Decorations"],"description":"Advanced protection and AI-powered security. Scale your AppSec program with AI-assisted remediation and deeper multi-layer coverage.","contactSales":true},{"free":false,"name":"Enterprise","summary":"Custom quote required","features":["Everything in Professional","Supply Chain Security","Container Security","Runtime Protection","Custom Policies","Executive Reporting"],"description":"Complete coverage and full compliance. Maximum coverage and control for organizations with the most demanding security requirements.","contactSales":true}],"summary":"All three tiers require custom quote. No published per-seat or usage-based pricing.","freeTier":false,"sourceUrl":"https://checkmarx.com","retrievedAt":"2026-08-05T14:23:25.473Z"}` | `{"type":"hybrid","plans":[{"free":true,"name":"Free","summary":"Free, up to 50k lines of code","description":"Free tier for exploring SonarQube with private projects","contactSales":false,"includedLimits":{"lines_of_code":"50k"}},{"free":false,"name":"Team","summary":"$32/month, billed monthly or annually, Team plan","features":["Auto-approve & merge blocking","3rd-party integrations (Slack, Linear, Jira)"],"commitment":"monthly","components":[{"kind":"fixed","amount":32,"period":"month","currency":"USD"}],"contactSales":false,"includedLimits":{"lines_of_code":"100k"}},{"free":false,"name":"Enterprise","summary":"Contact sales for custom pricing","commitment":"annual","contactSales":true},{"free":true,"name":"Community Build","summary":"Free and open source","description":"Free and open source, self-managed edition","contactSales":false,"includedLimits":{"languages":"20+"}}],"summary":"From $32/month (Team plan). Free tier available with 14-day trial. Community Build is free and open source.","currency":"USD","freeTier":true,"sourceUrl":"https://www.sonarsource.com/plans-and-pricing/","retrievedAt":"2026-09-10T21:09:05.076Z","freeTrialDays":14,"startingPrice":{"amount":32,"period":"month","currency":"USD"},"billingPeriods":["month","year"]}` |
| pricing.free_tier | no | yes |
| pricing.model | commercial | freemium |
| pricing.price_level | unknown | mid |
| pricing.starting_price | - | `{"amount":32,"currency":"USD"}` |
| pricing.transparent | no | yes |
| release.cadence_days | - | 28 |
| release.history | - | `[{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.9.0.129388","date":"2026-09-02T10:29:07Z","type":"stable","version":"26.9.0.129388"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.8.0.126808","date":"2026-08-05T07:17:56Z","type":"stable","version":"26.8.0.126808"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.7.0.124771","date":"2026-07-08T13:48:56Z","type":"stable","version":"26.7.0.124771"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.6.0.123539","date":"2026-06-03T09:56:25Z","type":"stable","version":"26.6.0.123539"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.5.0.122743b","date":"2026-05-19T12:59:25Z","type":"stable","version":"26.5.0.122743b"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.4.0.121862","date":"2026-04-10T13:17:33Z","type":"stable","version":"26.4.0.121862"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.3.0.120487","date":"2026-03-03T09:53:50Z","type":"stable","version":"26.3.0.120487"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.2.0.119303","date":"2026-02-04T10:07:42Z","type":"stable","version":"26.2.0.119303"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.1.0.118079","date":"2026-01-06T14:46:07Z","type":"stable","version":"26.1.0.118079"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.12.0.117093","date":"2025-12-23T15:00:10Z","type":"stable","version":"25.12.0.117093"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.11.0.114957","date":"2025-11-05T10:26:59Z","type":"stable","version":"25.11.0.114957"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.10.0.114319","date":"2025-10-03T13:33:44Z","type":"stable","version":"25.10.0.114319"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.9.0.112764","date":"2025-09-01T15:33:36Z","type":"stable","version":"25.9.0.112764"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.8.0.112029","date":"2025-08-06T13:33:07Z","type":"stable","version":"25.8.0.112029"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.7.0.110598","date":"2025-07-07T09:39:23Z","type":"stable","version":"25.7.0.110598"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.6.0.109173","date":"2025-06-02T14:19:56Z","type":"stable","version":"25.6.0.109173"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.5.0.107428","date":"2025-05-06T08:12:43Z","type":"stable","version":"25.5.0.107428"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.4.0.105899","date":"2025-04-07T13:22:08Z","type":"stable","version":"25.4.0.105899"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.3.0.104237","date":"2025-03-04T14:08:50Z","type":"stable","version":"25.3.0.104237"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.2.0.102705","date":"2025-02-03T16:06:10Z","type":"stable","version":"25.2.0.102705"}]` |
| reliability.sla_pct | - | 99.9 |
| reliability.status_page | - | yes |
| security.certifications | `[{"name":"SOC 2 Type II","status":"active"},{"name":"ISO 27001","status":"active"}]` | `[{"name":"SOC 2 Type II","level":"Type II","status":"active"}]` |
| security.fedramp | yes | - |
| security.gdpr | yes | yes |
| security.iso27001 | yes | yes |
| security.scorecard | - | 4.9 |
| security.soc2 | yes | yes |
| security.trust_center | https://checkmarx.com/blog/security-in-vibe-coding/ | - |
| security.vulnerabilities | - | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.sonarsource.sonarqube%3Asonar-plugin-api&per_page=100","last_12m":0,"max_severity":"MODERATE"}` |

## Capabilities (DevSecOps Tools)

| Capability | Checkmarx | SonarQube |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | ✓ | ✓ |
| DAST (dynamic analysis) | ✓ | ✗ |
| SCA / dependency scanning | ✓ | ✓ |
| Secret scanning | ✓ | ✓ |
| Container / image scanning | - | ✓ |
| IaC misconfiguration scanning | ✓ | ✓ |
| **Governance** |  |  |
| OSS licence compliance | - | ✓ |
| SBOM generation (SPDX/CycloneDX) | ✓ | ✓ |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | - | ✓ |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | ✓ | ✓ |
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | ✓ | ✓ |
| **Licensing** |  |  |
| OSS engine available | - | ✓ |

*Source: vioscaleAI. Generated 2026-09-21T02:32:18.083Z. "-" = undocumented, not absent.*
