Available worldwide · Popular in: US, GB
What is Checkmarx?
Agentic application security testing software platform providing comprehensive code scanning, supply chain security, and runtime protection across development and production environments.
Checkmarx pricing
Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.
All three tiers require custom quote. No published per-seat or usage-based pricing.
Essentials
Contact salesCore application security coverage. Establish a unified foundation for identifying, managing, and reporting application risk.
- SAST
- SCA
- API Security
- ASPM visibility
- Core reporting
Professional
Contact salesAdvanced protection and AI-powered security. Scale your AppSec program with AI-assisted remediation and deeper multi-layer coverage.
- Everything in Essentials
- DAST
- IaC Security
- AI Security
- Advanced ASPM
- PR Decorations
Enterprise
Contact salesComplete coverage and full compliance. Maximum coverage and control for organizations with the most demanding security requirements.
- Everything in Professional
- Supply Chain Security
- Container Security
- Runtime Protection
- Custom Policies
- Executive Reporting
What Checkmarx does
The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- SAST (static analysis)
- ✓
- DAST (dynamic analysis)
- ✓
- SCA / dependency scanning
- ✓
- Secret scanning
- ✓
- Container / image scanning
- ✓
- IaC misconfiguration scanning
- ✓
- OSS licence compliance
- ✓
- SBOM generation (SPDX/CycloneDX)
- ✓
- Automated fix / upgrade PRs
- ✓
- Reachability / exploitability prioritisation
- ✓
- Hosting
- Cloud only
- First-class CI / pipeline integration
- ✓
- In-editor / IDE scanning
- ✓
- OSS engine available
- ✗
Platform & deployment
Independently observed- CLI
- Web
- Cloud / SaaS
Checkmarx alternatives
Other devsecops tools we track, ranked by the same independent score.
- Endor LabsSpeed or security. The best teams code without compromise.low · 36%
- SemgrepAI-assisted SAST, SCA and Secrets Detectionmedium · 51%
- SnykAI Security Fabricmedium · 60%
- OWASP ZAPThe world's most widely used web app scanner. Free and open source.low · 13%
- MendSecure code, AI, and every interaction between themmedium · 53%
- GitGuardianFind every credential. Stop the next breach.medium · 60%
The Vioscale score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Checkmarx, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Security Posture | 65 | 0.23 | 15.2 | ✓ |
| Capabilities | 100 | 0.07 | 7.0 | ✓ |
| Price Level | 0 | 0.05 | 0.0 | - |
| Reliability | 0 | 0.10 | 0.0 | - |
| Integrations | 0 | 0.07 | 0.0 | - |
| Pricing Transparency | 0 | 0.06 | 0.0 | ✓ |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | {"sca":true,"dast":true,"sast":true,"sbom":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":false,"iac_scanning":true,"reachability":true,"secret_scanning":true,"container_scanning":true,"license_compliance":true} | mediumsource · 2026-08-05 · 60% |
Market
| Attribute | Value | Evidence |
|---|---|---|
| Availability | {"hqCountry":"IL","primaryMarkets":["US","GB"],"availabilityScope":"global","availableCountries":["US","GB","PT","FR","AU","IN","SG","DE"],"notAvailableCountries":[]} | highsource · 2026-08-05 · 75% |