Checkmarx vs. Codacy

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Checkmarx
Score 9.1 out of 10
N/A
Checkmarx, an Israeli headquartered company with US offices, provides a suite of application security software delivered via the Checkmarx Software Security Platform. Individual modules and capabilities include Checkmarx Static Application Security Testing, Checkmarx Software Composition Analysis, Checkmarx Interactive Application Security Testing (CxIAST)N/A
Codacy
Score 8.9 out of 10
N/A
Codacy automates code reviews and monitors code quality on every commit and pull request reporting back the impact of every commit or pull request, issues concerning code style, best practices, security, and many others. It monitors changes in code coverage, code duplication and code complexity. Saving developers time in code reviews thus efficiently tackling technical debt. JavaScript, Java, Ruby, Scala, PHP, Python, CoffeeScript and CSS are currently supported. Codacy is static analysis…
$0
Pricing
CheckmarxCodacy
Editions & Modules
No answers on this topic
Open Source
$0.00
Startup
$0.00
Pro
$15.00
user/mo
Enterprise
$40.00
user/mo
Offerings
Pricing Offerings
CheckmarxCodacy
Free Trial
NoYes
Free/Freemium Version
NoYes
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeOptional
Additional Details
More Pricing Information
Community Pulse
CheckmarxCodacy
Considered Both Products
Checkmarx
Chose Checkmarx
Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into …
Chose Checkmarx
We actually use Checkmarx along with the other tools. However, the reason we chose Checkmarx is its wide support for languages and useful fix recommendations. The flowcharts help better understand the data flow and give a clear picture of what needs to be fixed and how. Also, …
Codacy
Chose Codacy
Even though it is paid while SonarQube is free, we chose Codacy because it is simpler to configure and maintain the implemented rules. In addition, it offers support for the main programming languages ​​on the market, ensuring that we can continue to use it if we want to use …
Chose Codacy
Codacy is an amazing and fantastic tool I really like the UI/UX with great amount of customizations around rules for code review. It supports multiple languages like Java, PHP and Python hence making it the best, fast, and easy to get real-time quality codes. The support is …
Chose Codacy
Codacy provides a good support mechanism and has very intuitive UI. Even a newbie can understand the details of a code base. The best part is you don't have to manually update everything. Once you have connected the git repository, it will automatically rate the code and …
Best Alternatives
CheckmarxCodacy
Small Businesses
GitLab
GitLab
Score 8.7 out of 10
GitHub
GitHub
Score 9.0 out of 10
Medium-sized Companies
Veracode
Veracode
Score 8.7 out of 10
Veracode
Veracode
Score 8.7 out of 10
Enterprises
Veracode
Veracode
Score 8.7 out of 10
Perforce P4
Perforce P4
Score 7.7 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
CheckmarxCodacy
Likelihood to Recommend
9.0
(0 ratings)
9.2
(0 ratings)
Usability
7.0
(0 ratings)
-
(0 ratings)
Support Rating
-
(0 ratings)
10.0
(0 ratings)
User Testimonials
CheckmarxCodacy
Likelihood to Recommend
If you are going with SAST process or want to improve overall security posture then go for it like integrating it with post deployment steps. If you are more concerned about proactive controls better choose other options such as pee-commit hooks and CI security. Also choose other tools for DAST and API scans.
Read full review
It's a great tool that has greatly improved our code and I'd recommend it to anyone. With the ability to check duplicated codes. And automated systems to ensure quality and standards when opening a pull requests. The support team is one of the best team I have worked along with because they are very user-friendly and responsive in case of any challenge.
Read full review
Pros
  • Supports a large number of languages
  • Finds a large variety of potential risks
Read full review
  • Code standardization across teams and projects.
  • Integration with our in-house workflow processes.
  • Perfect for identifying potential security vulnerabilities within our code.
Read full review
Cons
  • DAST capability can be the one where it does not support native use case of using OTP based arch
  • API Scanning is something that lacks a bit due to not much customizations
  • Branch wise reports for SAST is not available
Read full review
  • There should be customization to get code quality for your own projects if standards are provided.
  • Offline or a standalone application is much needed from Codacy to get local support.
  • Spots a lot of errors and small ones that don't affect much about quality and are de-facto standards.
Read full review
Usability
Checkmarx's usability is generally good, but it can be a bit complex for new users. The interface may take some time to get used to, especially for those unfamiliar with security tools. Once you become familiar with it, it’s effective and integrates well into development workflows.
Read full review
No answers on this topic
Support Rating
No answers on this topic
Great company and support team!
Read full review
Alternatives Considered
Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into our development process, offering faster scans and more useful suggestions for fixing problems
Read full review
Even though it is paid while SonarQube is free, we chose Codacy because it is simpler to configure and maintain the implemented rules. In addition, it offers support for the main programming languages ​​on the market, ensuring that we can continue to use it if we want to use other languages ​​in new products.
Read full review
Return on Investment
  • Great diversity of vulnerabilities covered.
  • Quicker scans
  • They are feature rich compared to other tools I used in the past.
  • Dashboards are not customizable enough.
  • High number of false positives take up time and sometimes make our report look bad.
Read full review
  • I would say the ROI is not financial but we have the peace of mind of pushing production code that is well structured.
Read full review
ScreenShots

Codacy Screenshots

Screenshot of Screenshot of Screenshot of Screenshot of Screenshot of Screenshot of