SonarQube Server

SonarQube Server

SonarSource
+
+

Related Products

  • Aikido Security
    239 Ratings
    Visit Website
  • Parasoft
    152 Ratings
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • Gearset
    305 Ratings
    Visit Website
  • Innoslate
    93 Ratings
    Visit Website
  • Cloudflare
    2,042 Ratings
    Visit Website
  • New Relic
    2,938 Ratings
    Visit Website
  • Keeper Security
    1,810 Ratings
    Visit Website
  • Jama Connect
    387 Ratings
    Visit Website
  • Feroot
    32 Ratings
    Visit Website

About

With triggers in your CI/CD pipeline, SecureStack can check for common security issues and stop those issues from getting into your applications. SecureStack embeds security automatically with every git push. We built our technology to test every facet of your application security looking for things like missing security controls, are you using encryption correctly; we test the efficacy of your WAF and are your cloud-native components secure and more than 250 other data points. All of that was delivered in less than 60 seconds. See what a hacker can see when they view your applications. Test and compare your development, staging and production environments to quickly find critical differences and understand ways to fix high-priority defects. We help you decompose your web application so you are aware of all the resources your app is using behind the scenes.

About

SonarQube Server is a self-managed solution for continuous code quality inspection that helps development teams identify and fix bugs, vulnerabilities, and code smells in real-time. It provides automated static code analysis for a variety of programming languages, ensuring the highest quality and security standards are maintained throughout the development lifecycle. SonarQube Server integrates seamlessly with existing CI/CD pipelines, offering flexibility for on-premise or cloud-based deployment. With advanced reporting features, it helps teams manage technical debt, track improvements, and enforce coding standards. SonarQube Server is ideal for organizations seeking full control over their code quality and security without compromising on performance.

Platforms Supported

Windows Supported
Mac Supported
Linux Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Not Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

Developers and anyone searching for a security platform to find vulnerabilities in their code

Audience

Companies searching for a solution to manage and empower their dev teams

Support

Phone Support Supported
24/7 Live Support Not Supported
Online Supported

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Not Supported

API

Offers API Supported

API

Offers API Not Supported

Screenshots and Videos

Screenshots and Videos

Pricing

$500/mo
500 analyses per month cost $500, which is typically enough for a growing startup.
Free Version Not Supported
Free Trial Supported

Pricing

No information available.
Free Version Not Supported
Free Trial Not Supported

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 5.0 / 5
ease 5.0 / 5
features 5.0 / 5
design 5.0 / 5
support 5.0 / 5

Pros & Cons from Real Users

Pros

  • Great User Interface / Dashboard. Different tiers of bugs - helps identify and fix only the critical issues. Suggestions to fix the issue. Jenkins integration. Also available as SaaS offering. Also shows security defects.
  • - Accurate results and no bullshit findings - Very fast analysis - Handy configuration features for analysis customization - Nice interface - Plenty integration options

Cons

  • The only con i can think of is expensive license which is not optimal for personal projects (unless open source). There is a free trial though.
  • - It has its price but its worth every penny. Similar vendors are more expensive with significantly less value.

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Not Supported

Training

Documentation Supported
Webinars Not Supported
Live Online Not Supported
In Person Not Supported

Company Information

SecureStack
Founded: 2017
Australia
securestack.com

Company Information

SonarSource
Founded: 2008
Switzerland
www.sonarsource.com/products/sonarqube/

Alternatives

Alternatives

Seeker

Seeker

Black Duck
SonarQube for IDE

SonarQube for IDE

SonarSource
SonarQube Cloud

SonarQube Cloud

SonarSource

Categories

Categories

Application Security Features

Analytics / Reporting Supported
Open Source Component Monitoring Supported
Source Code Analysis Supported
Third-Party Tools Integration Supported
Training Resources Not Supported
Vulnerability Detection Supported
Vulnerability Remediation Supported

Static Application Security Testing (SAST) Features

Application Security Supported
Dashboard Supported
Debugging Not Supported
Deployment Management Supported
IDE Not Supported
Multi-Language Scanning Not Supported
Real-Time Analytics Supported
Source Code Scanning Supported
Vulnerability Scanning Supported

Application Development Features

Access Controls/Permissions Supported
Code Assistance Not Supported
Code Refactoring Not Supported
Collaboration Tools Supported
Compatibility Testing Not Supported
Data Modeling Not Supported
Debugging Not Supported
Deployment Management Not Supported
Graphical User Interface Not Supported
Mobile Development Not Supported
No-Code Not Supported
Reporting/Analytics Not Supported
Software Development Not Supported
Source Control Supported
Testing Management Supported
Version Control Supported
Web App Development Not Supported

Application Lifecycle Management Features

Administrator Level Control Supported
Defect Tracking Supported
Iteration Planning Not Supported
Project Management Not Supported
Release Management Not Supported
Requirements Review Not Supported
Task Management Not Supported
Test Case Tracking Not Supported
User Level Management Not Supported
Version Control Supported

Cybersecurity Features

AI / Machine Learning Not Supported
Behavioral Analytics Not Supported
Endpoint Management Not Supported
Incident Management Supported
IOC Verification Not Supported
Tokenization Not Supported
Vulnerability Scanning Supported
Whitelisting / Blacklisting Not Supported

DevOps Features

Approval Workflow Not Supported
Dashboard Not Supported
KPIs Not Supported
Policy Management Supported
Portfolio Management Not Supported
Prioritization Not Supported
Release Management Supported
Timeline Management Not Supported
Troubleshooting Reports Not Supported

Application Security Features

Analytics / Reporting Not Supported
Open Source Component Monitoring Supported
Source Code Analysis Supported
Third-Party Tools Integration Not Supported
Training Resources Supported
Vulnerability Detection Supported
Vulnerability Remediation Not Supported

Static Code Analysis Features

Analytics / Reporting Supported
Code Standardization / Validation Supported
Multiple Programming Language Support Supported
Provides Recommendations Supported
Standard Security/Industry Libraries Supported
Vulnerability Management Supported

Integrations

JavaScript Supported
Python Supported
Azure DevOps Supported
Azure Marketplace Not Supported
Betterscan.io Not Supported
COBOL Not Supported
Claude Code Not Supported
CodeScene Not Supported
HTML Not Supported
HivePro Uni5 Not Supported
IBM DevOps Velocity Not Supported
Jira Supported
JupiterOne Not Supported
Maverix Not Supported
Oobeya Not Supported
OpsMx Enterprise for Spinnaker Not Supported
TypeScript Not Supported
configure8 Not Supported

Integrations

JavaScript Supported
Python Supported
Azure DevOps Not Supported
Azure Marketplace Supported
Betterscan.io Supported
COBOL Supported
Claude Code Supported
CodeScene Supported
HTML Supported
HivePro Uni5 Supported
IBM DevOps Velocity Supported
Jira Not Supported
JupiterOne Supported
Maverix Supported
Oobeya Supported
OpsMx Enterprise for Spinnaker Supported
TypeScript Supported
configure8 Supported
Claim SecureStack and update features and information
Claim SecureStack and update features and information
Claim SonarQube Server and update features and information
Claim SonarQube Server and update features and information