What is SonarQube?
SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.
Company Details
Need Assistance?
We're here to help you with understanding our reports and the data inside to help you make decisions.
Get AssistanceSonarQube Ratings
Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard
to access more information on SonarQube.
90 Likeliness to Recommend
100 Plan to Renew
83 Satisfaction of Cost Relative to Value
Emotional Footprint Overview
+89 Net Emotional Footprint
The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.
How much do users love SonarQube?
Pros
- Performance Enhancing
- Respectful
- Altruistic
- Transparent
Emotional Footprint
How to Read
Positive
Neutral
Negative
The Net Emotional Footprint measures high-level user sentiment towards particular product offerings. It aggregates emotional response ratings for various dimensions of the vendor-client relationship and product effectiveness, creating a powerful indicator of overall user feeling toward the vendor and product.
While purchasing decisions shouldn't be based on emotion, it's valuable to know what kind of emotional response the vendor you're considering elicits from their users.
Footprint
Feature Ratings
Software Composition Analysis (SCA)
Automated Workflow
Dynamic Application Security Testing (DAST)
Vulnerability Scanning
Static Application Security Testing (SAST)
Interactive Application Security Testing (IAST)
Container Security Testing
False Positive Remediation
Risk Scoring
Mobile Application Security Testing
Policy Engine and Enforcements
Vendor Capability Ratings
Ease of Data Integration
Business Value Created
Breadth of Features
Ease of Implementation
Ease of IT Administration
Ease of Customization
Availability and Quality of Training
Vendor Support
Quality of Features
Usability and Intuitiveness
Product Strategy and Rate of Improvement
SonarQube Reviews
Sourabh G.
- Role: Information Technology
- Industry: Finance
- Involvement: IT Leader or Manager
Submitted Oct 2023
Sonar - Defacto code static analysis tool
Likeliness to Recommend
What differentiates SonarQube from other similar products?
It provides multiple options to track code vulnerability, static code analysis. It has easy integrations with all CI servers and allow easy integrations with devops cycle for analysis. It enables easy refactoring and maintain standard code styles across projects. When combined with other plugins like check-style, PMD etc code quality can be improved a lot.
What is your favorite aspect of this product?
Ability to create custom quality profiles Ability to create custom quality gates at project/business level based on projects. Easy integration with devops pipeline.
What do you dislike most about this product?
There are multiple new nextgen SAST tools in market, Sonar seems to be little out dated. Sonar is not pushing hard on shift left mindset. Plugins and integrations are still an headache. No AI capability , and no compile time suggestions in IDE for analysis.
What recommendations would you give to someone considering this product?
Sonar has been a proven tool and works seamlessly with pipelines. We should have static analysis as part of pipeline as well as developer IDE to keep standards.
Pros
- Reliable
- Performance Enhancing
- Security Protects
- Enables Productivity
Cons
- Slower Product Innovation
Jeemish M.
- Role: Information Technology
- Industry: Technology
- Involvement: IT Leader or Manager
Submitted Jul 2023
Enterprise scale SAST scans at zero cost !!
Likeliness to Recommend
What differentiates SonarQube from other similar products?
Ease of implementation and support for most common technology stacks like java, Js, .net, python, groovy, etc for SAST scans
What is your favorite aspect of this product?
Minimalistic UI and multiple technology stack support
What do you dislike most about this product?
Requires a lot of manual setup and configuration for maintenance
What recommendations would you give to someone considering this product?
Must have for implementing automated SAST scans at enterprise scale
Pros
- Helps Innovate
- Reliable
- Performance Enhancing
- Respectful
Oferi G.
- Role: Information Technology
- Industry: Construction
- Involvement: End User of Application
Submitted Jan 2023
Securing Applications Made Easy
Likeliness to Recommend
What differentiates SonarQube from other similar products?
Using SonarQube is easy an it comes with amazing application security testing criterion
What is your favorite aspect of this product?
I like the many security features of SonarQube The software makes testing applications for security threshold easy
What do you dislike most about this product?
No dislikes in the way SonarQube works
What recommendations would you give to someone considering this product?
SonarQube has met our needs and has been our go to software when it comes to testing application security and for this reason I recommend it.
Pros
- Continually Improving Product
- Unique Features
- Efficient Service
- Inspires Innovation