
Veracode
Coverity Scan
SonarQube
Appknox
Acunetix Vulnerability Scanner
Netsparker
GitLab
The industry’s most comprehensive AppSec platform, Checkmarx One is fast, accurate, and accelerates your business.

OpenGrok
GitHub
Etsy Hound
Atlassian Fisheye
Tabnine
GitHub Copilot
Cody AI
Sourcegraph is a free, self-hosted code search and intelligence server that helps developers find, review, understand, and debug code. Use it with any Git code host for teams from 1 to 10,000+.

Which is more popular?
Based on our record, Sourcegraph should be more popular than Checkmarx. It has been mentioned 37 times since March 2021.
Website, pricing, platforms and company facts side by side.
|
|
|
|
|---|---|---|
| Website | checkmarx.com | sourcegraph.com |
| Pricing | — | |
| Listed in |
What each product offers, as listed by its team.


Possible disadvantages
Possible disadvantages
An editorial look at what each product does well and who it suits.


Overall verdict
Why this product is good
Recommended for
Overall verdict
Why this product is good
Recommended for
Walkthroughs and reviews on video.
Viewing results and understanding security issues via Checkmarx online scanner
More videos
Code review with IDE powers: Sourcegraph Chrome extension
More videos
How often each product is chosen within a category, 0–100% relative to the other.


Share your experience with using Checkmarx and Sourcegraph. For example, how are they different and which one is better?
External articles and on-site reviews we used to compare the two products.


Why We Picked Checkmarx SAST: We like Checkmarx SAST for its early detection of vulnerabilities, which enables faster and safer code development. Its AI-assisted prioritization of vulnerabilities according to severity...
Checkmarx is a developer-centric security tool that specializes in secure coding practices and compliance. It helps developers identify and fix security vulnerabilities in their code, ensuring that their applications...
While SonarQube offers some security features, Checkmarx provides a more holistic approach to application security, covering a more comprehensive range of security aspects throughout the SDLC. Checkmarx One's...
We have no reviews of Sourcegraph yet. Be the first one to post
Recommendations tracked on public social media and blogs since March 2021.


Tools like OWASP ZAP are excellent for dynamic application security testing, while SonarQube and Checkmarx specialize in static security testing. These tools integrate seamlessly into your pipeline, automating checks and enabling you to... - Source: dev.to / about 1 year ago
Tools like SonarQube, Checkmarx, or Snyk can automate parts of this process by scanning for known vulnerability patterns. While white box testing may not reflect real-world attack scenarios (as attackers rarely access source code), it... - Source: dev.to / over 1 year ago
Automate security testing: Use tools such as OWASP ZAP, SonarQube, or Checkmarx to automate security testing. This will help you identify security issues early in the development process and reduce the risk of vulnerabilities being... - Source: dev.to / over 3 years ago
The setup is one prompt long. You tell the agent to install Sourcegraph for semantic code search or xerj.org for patch and impact analysis. From that point it runs unattended:. - Source: dev.to / 26 days ago
Sourcegraph | Remote | Full-Time | SWE, Tech Lead, Agent Engineer, Product Manager, Product Marketing Manager | https://sourcegraph.com Sourcegraph is building the context layer for AI-powered software development. As AI accelerates code... - Source: Hacker News / about 2 months ago
Sourcegraph | San Francisco | Full-Time | SWE, Design Engineer, Forward Deployed Eng, Head of Design, Solutions Eng, Dev Advocate (all roles write code) | https://sourcegraph.com Sourcegraph is hiring SWEs and FDEs for Amp... - Source: Hacker News / about 1 year ago
When comparing Checkmarx and Sourcegraph, you can also consider the following products.

Veracode's application security software products are simpler and more scalable to increase the resiliency of your application infrastructure.
Compare Veracode to Checkmarx or Sourcegraph:

OpenGrok is a fast and usable source code search and cross reference engine.
Compare OpenGrok to Checkmarx or Sourcegraph:

Find and fix defects in your Java, C/C++ or C# open source project for free
Compare Coverity Scan to Checkmarx or Sourcegraph:

Originally founded as a project to simplify sharing code, GitHub has grown into an application used by over a million people to store over two million code repositories, making GitHub the largest code host in the world.
Compare GitHub to Checkmarx or Sourcegraph:

SonarQube, a core component of the Sonar solution, is an open source, self-managed tool that systematically helps developers and organizations deliver Clean Code.
Compare SonarQube to Checkmarx or Sourcegraph:

Hound is an extremely fast source code search engine.
Compare Etsy Hound to Checkmarx or Sourcegraph: