SonarQube Logo
SonarQube Logo
SonarSource SA

SonarQube

Composite Score
8.1 /10
CX Score
8.5 /10
Category
SonarQube
8.1 /10

What is SonarQube?

SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.

Company Details


Need Assistance?

We're here to help you with understanding our reports and the data inside to help you make decisions.

Get Assistance

SonarQube Ratings

Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard to access more information on SonarQube.

Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.

91 Likeliness to Recommend

100 Plan to Renew

84 Satisfaction of Cost Relative to Value


Emotional Footprint Overview

Chart with 5 data points.
The chart has 1 X axis displaying categories.
The chart has 1 Y axis displaying values. Range: 0 to 100.
End of interactive chart.
{y}
{name}

Emotional Footprint Overview

Product Experience:
93%
Negotiation and Contract:
93%
Conflict Resolution:
92%
Strategy & Innovation:
93%
Service Experience:
94%

Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.

+93 Net Emotional Footprint

The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.

How much do users love SonarQube?

Chart

Bar chart with 10 data series.
The chart has 1 X axis displaying values. Range: -0.5 to 0.5.
The chart has 1 Y axis displaying values. Range: 0 to 100.
End of interactive chart.
0% Negative
0% Neutral
100% Positive

Pros

  • Performance Enhancing
  • Respectful
  • Altruistic
  • Transparent

Feature Ratings

Average 82

Automated Workflow

87

Vulnerability Scanning

85

Mobile Application Security Testing

85

Static Application Security Testing (SAST)

84

Software Composition Analysis (SCA)

84

Policy Engine and Enforcements

83

Dynamic Application Security Testing (DAST)

82

Container Security Testing

80

Risk Scoring

77

Integrated Development Environment (IDE) plug-in

77

False Positive Remediation

77

Vendor Capability Ratings

Average 82

Ease of Data Integration

90

Business Value Created

89

Breadth of Features

85

Ease of Implementation

83

Ease of IT Administration

82

Usability and Intuitiveness

80

Quality of Features

79

Availability and Quality of Training

79

Vendor Support

79

Product Strategy and Rate of Improvement

78

Ease of Customization

77

SonarQube Reviews

KIRAN KUMAR V.

  • Role: Information Technology
  • Industry: Energy
  • Involvement: IT Development, Integration, and Administration
Validated Review
Verified Reviewer

Submitted Jan 2024

Nice application

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

Code quality and venerability

What is your favorite aspect of this product?

Suggested correction

What do you dislike most about this product?

Also showing some unwanted changes

What recommendations would you give to someone considering this product?

To creat user based rules

Pros

  • Helps Innovate
  • Continually Improving Product
  • Trustworthy
  • Performance Enhancing

Sourabh G.

  • Role: Information Technology
  • Industry: Finance
  • Involvement: IT Leader or Manager
Validated Review
Verified Reviewer

Submitted Oct 2023

Sonar - Defacto code static analysis tool

Likeliness to Recommend

10 /10

What differentiates SonarQube from other similar products?

It provides multiple options to track code vulnerability, static code analysis. It has easy integrations with all CI servers and allow easy integrations with devops cycle for analysis. It enables easy refactoring and maintain standard code styles across projects. When combined with other plugins like check-style, PMD etc code quality can be improved a lot.

What is your favorite aspect of this product?

Ability to create custom quality profiles Ability to create custom quality gates at project/business level based on projects. Easy integration with devops pipeline.

What do you dislike most about this product?

There are multiple new nextgen SAST tools in market, Sonar seems to be little out dated. Sonar is not pushing hard on shift left mindset. Plugins and integrations are still an headache. No AI capability , and no compile time suggestions in IDE for analysis.

What recommendations would you give to someone considering this product?

Sonar has been a proven tool and works seamlessly with pipelines. We should have static analysis as part of pipeline as well as developer IDE to keep standards.

Pros

  • Reliable
  • Performance Enhancing
  • Security Protects
  • Enables Productivity

Cons

  • Slower Product Innovation

Jeemish M.

  • Role: Information Technology
  • Industry: Technology
  • Involvement: IT Leader or Manager
Validated Review
Verified Reviewer

Submitted Jul 2023

Enterprise scale SAST scans at zero cost !!

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

Ease of implementation and support for most common technology stacks like java, Js, .net, python, groovy, etc for SAST scans

What is your favorite aspect of this product?

Minimalistic UI and multiple technology stack support

What do you dislike most about this product?

Requires a lot of manual setup and configuration for maintenance

What recommendations would you give to someone considering this product?

Must have for implementing automated SAST scans at enterprise scale

Pros

  • Helps Innovate
  • Reliable
  • Performance Enhancing
  • Respectful