Checkmarx One
CheckmarxExternal reviews
51 reviews
from
and
External reviews are not included in the AWS star rating for the product.
Great scanning tool for code
What do you like best about the product?
We use this tool to scan our code for vulnerabilities. It is a great tool because it can be run against our code base and it lists our the vulnerabilities. This has reduced our time for manual code reviews by quite some time. Also, it helps us set code quality standard. We have implemented this as part of our software development cycle. The new developers that come on board can look at previous scans and learn our coding standards and follow that as part of our coding policy.
What do you dislike about the product?
There can be many false positives. Since the tool is automated it doesn't understand some of the code logic and why it was written in a certain way.
What problems is the product solving and how is that benefiting you?
It helps us automate the code review process and catches code vulnerabilities. We have saved time on code reviews by running the code against this tool first.
Recommendations to others considering the product:
Be aware of false positives. Other than it's a great tool to scan your code base.
Good App
What do you like best about the product?
Highly recommend Check mark in this current trend.
What do you dislike about the product?
Not having an option to choose personal email.
What problems is the product solving and how is that benefiting you?
Analytics
Innovative
What do you like best about the product?
This is a very innovative company. The product is safe.
What do you dislike about the product?
Customer service is not so great. It takes a while for them to return your call.
What problems is the product solving and how is that benefiting you?
It is good for network security.
Recommendations to others considering the product:
Consider it. Nothing to lose. If you do not like it, switch to something else.
A useful SAST tool to improve maturity in IT security
What do you like best about the product?
Our choice of Checkmarx as a static code audit tool was done after a long reflection. the richness in terms of languages and the customization of the presets were determinents. We were accompanied at first by a very competent editor team. Today, the use of the tool is unavoidable. We use it both as an integrated tool in our IDEs but also when building in our continuous integration platform. He is also at the hand of the security team to audit code delivered by an external service provider.
We also appreciate the possibility of modifying but also creating new rules to eliminate false positives.
The tool is also rich in terms of indicators and charts. it provides a dashboard that makes it easy to track application risk level scores over time and provides management with comprehensive reports. the details of the vulnerabilities detected and the description of the corrections allows the development teams to correct the vulnerabilities but also to learn about the security of the coding.
We also appreciate the possibility of modifying but also creating new rules to eliminate false positives.
The tool is also rich in terms of indicators and charts. it provides a dashboard that makes it easy to track application risk level scores over time and provides management with comprehensive reports. the details of the vulnerabilities detected and the description of the corrections allows the development teams to correct the vulnerabilities but also to learn about the security of the coding.
What do you dislike about the product?
At each audit, the number of false positives is high. but this is a defect specific to SAST tools. knowledge of the business specificities of the application is necessary to personalize the presets to eliminate false positives.
This tool is a step in the security audit process, it must be completed by DAST and IAST audits.
This tool is a step in the security audit process, it must be completed by DAST and IAST audits.
What problems is the product solving and how is that benefiting you?
we use this tool in a bank-insurance information system. Business requirements are high. Checkmarx has helped us improve the maturity of our IT security in order to gain the confidence of our business.
Recommendations to others considering the product:
we highly recommend this tool. We have already recommended the tool at our group level. The cost-effectiveness ratio is interesting.
Checkmarx for security scan of code base
What do you like best about the product?
Recommendations provided are easy to understand and actionable insights
What do you dislike about the product?
too many false positive results while scanning code
What problems is the product solving and how is that benefiting you?
Code best practices
Recommendations to others considering the product:
Good tool to use for code scanning for beginners
Great security software
What do you like best about the product?
Application Security testing and the testing UI
What do you dislike about the product?
Still needs the break even analysis for the cases
What problems is the product solving and how is that benefiting you?
Application software vulnerablities and workflow needed
Great for Code REviews
What do you like best about the product?
Reviews APEX code and most security/code scanners do not
What do you dislike about the product?
Results take a few minutes to return, not a huge issue but if you are in a time crunch you never know when they will arrive :)
What problems is the product solving and how is that benefiting you?
Providing reassurance to our customers
Good and practical
What do you like best about the product?
Checkmarx has a lot of pros, easy to deploy and integrates well in the SDLC, board overage of language support.
What do you dislike about the product?
Very high number of false positives takes longer time to triage.
What problems is the product solving and how is that benefiting you?
Securing SDLC.
Spying on Salesforce inhouse Source
What do you like best about the product?
Static analysis & Apex Overview of unpackaged code
What do you dislike about the product?
Cost is a big concern and frequent analysis could be better if cost is not a concern.
What problems is the product solving and how is that benefiting you?
Threat identification in our custom code.
Security requirements review.
Security requirements review.
A really great way to run security tests
What do you like best about the product?
I was working on a project for Salesforce and needed to test my code and running CheckMarx against the code helped me get my development done faster and done right.
What do you dislike about the product?
The specific documentation for APEX is a little hard to parse but it helps point out where you need to look.
What problems is the product solving and how is that benefiting you?
We needed to test our APEX code and needed to make sure it was as secure as possible.
showing 31 - 40