SonarQube Server

SonarQube Server

SonarSource
+
+

Related Products

  • Aikido Security
    239 Ratings
    Visit Website
  • Feroot
    32 Ratings
    Visit Website
  • Canditech
    110 Ratings
    Visit Website
  • Jscrambler
    40 Ratings
    Visit Website
  • Astra Pentest
    295 Ratings
    Visit Website
  • Nexcess Digital Cloud
    205 Ratings
    Visit Website
  • ToogleBox
    85 Ratings
    Visit Website
  • Parasoft
    148 Ratings
    Visit Website
  • Bitrise
    401 Ratings
    Visit Website
  • SurveyJS
    63 Ratings
    Visit Website

About

OpenText Dynamic Application Security Testing (DAST) is an automated solution that simulates real-world attacks on live applications, APIs, and services to identify exploitable vulnerabilities. It operates on running production environments, requiring no source code or staging setup. Designed for modern DevSecOps teams, the platform prioritizes vulnerabilities for root cause analysis and integrates seamlessly through REST APIs and an intuitive user interface. OpenText DAST supports automation in CI/CD pipelines, reducing manual efforts while accelerating security feedback. It covers modern web technologies like HTML5, JSON, AJAX, JavaScript, and HTTP2 to ensure comprehensive testing. Flexible deployment options allow organizations to run the solution on public cloud, private cloud, or on-premises environments.

About

SonarQube Server is a self-managed solution for continuous code quality inspection that helps development teams identify and fix bugs, vulnerabilities, and code smells in real-time. It provides automated static code analysis for a variety of programming languages, ensuring the highest quality and security standards are maintained throughout the development lifecycle. SonarQube Server integrates seamlessly with existing CI/CD pipelines, offering flexibility for on-premise or cloud-based deployment. With advanced reporting features, it helps teams manage technical debt, track improvements, and enforce coding standards. SonarQube Server is ideal for organizations seeking full control over their code quality and security without compromising on performance.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

DevSecOps and security teams looking for automated, scalable, real-time vulnerability testing on live applications and APIs integrated into CI/CD workflows

Audience

Companies searching for a solution to manage and empower their dev teams

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

No information available.
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 5.0 / 5
ease 5.0 / 5
features 5.0 / 5
design 5.0 / 5
support 5.0 / 5

Pros & Cons from Real Users

Pros

  • Great User Interface / Dashboard. Different tiers of bugs - helps identify and fix only the critical issues. Suggestions to fix the issue. Jenkins integration. Also available as SaaS offering. Also shows security defects.
  • - Accurate results and no bullshit findings - Very fast analysis - Handy configuration features for analysis customization - Nice interface - Plenty integration options

Cons

  • The only con i can think of is expensive license which is not optimal for personal projects (unless open source). There is a free trial though.
  • - It has its price but its worth every penny. Similar vendors are more expensive with significantly less value.

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

OpenText
Founded: 1991
Canada
www.opentext.com/products/dynamic-application-security-testing

Company Information

SonarSource
Founded: 2008
Switzerland
www.sonarsource.com/products/sonarqube/

Alternatives

OWASP ZAP

OWASP ZAP

OWASP

Alternatives

Burp Suite

Burp Suite

PortSwigger
Invicti

Invicti

Invicti Security
AppScan

AppScan

HCLSoftware
SonarQube for IDE

SonarQube for IDE

SonarSource
SonarQube Cloud

SonarQube Cloud

SonarSource

Categories

Categories

Application Security Features

Analytics / Reporting
Open Source Component Monitoring
Source Code Analysis
Third-Party Tools Integration
Training Resources
Vulnerability Detection
Vulnerability Remediation

Static Code Analysis Features

Analytics / Reporting
Code Standardization / Validation
Multiple Programming Language Support
Provides Recommendations
Standard Security/Industry Libraries
Vulnerability Management

Integrations

ArmorCode
Bizzy
Kondukto
Seeker
ThreadFix
Clarive
Digital.ai Release
Fianu
IBM DevOps Velocity
JavaScript
Jtest
JupiterOne
Merico
OpenAI Codex
OpsLevel
Propelo
SonarQube for IDE
XML
configure8

Integrations

ArmorCode
Bizzy
Kondukto
Seeker
ThreadFix
Clarive
Digital.ai Release
Fianu
IBM DevOps Velocity
JavaScript
Jtest
JupiterOne
Merico
OpenAI Codex
OpsLevel
Propelo
SonarQube for IDE
XML
configure8
Claim OpenText Dynamic Application Security Testing and update features and information
Claim OpenText Dynamic Application Security Testing and update features and information
Claim SonarQube Server and update features and information
Claim SonarQube Server and update features and information