Software Alternatives, Accelerators & Startups

lgtm.com VS DefenseCode ThunderScan®

Compare lgtm.com VS DefenseCode ThunderScan® and see what are their differences

lgtm.com logo lgtm.com

lgtm.com is a platform for code analytics.

DefenseCode ThunderScan® logo DefenseCode ThunderScan®

DefenseCode ThunderScan® is a SAST (Static Application Security Testing, WhiteBox Testing) solution for performing deep and extensive security analysis of application source code.
  • lgtm.com Landing page
    Landing page //
    2023-03-14
  • DefenseCode ThunderScan® Landing page
    Landing page //
    2021-07-16

lgtm.com features and specs

  • Automated Code Review
    LGTM.com provides automated code reviews, offering deep semantic analysis of code which helps in identifying bugs, vulnerabilities, and other issues early in the development process.
  • Multi-language Support
    LGTM.com supports multiple programming languages, including Java, JavaScript, Python, C++, and C#, allowing teams with diverse codebases to use one tool for all their projects.
  • Integrations
    It integrates with popular platforms like GitHub and Bitbucket, allowing seamless operation within existing workflows and continuous integration pipelines.
  • Database of Queries
    Users have access to a large database of customizable queries written in QL, which helps in tailoring the analysis to fit specific needs and discovering new patterns and issues.
  • Free for Open Source
    LGTM.com is free for open-source projects, making it an attractive option for many open-source communities looking to enhance their code quality without incurring costs.

Possible disadvantages of lgtm.com

  • Learning Curve for QL
    The use of QL for customizing analyses can have a steep learning curve for users unfamiliar with this language, potentially requiring additional time and effort to master.
  • Performance Overhead
    The analysis can be resource-intensive, potentially slowing down builds or consuming significant computational resources, especially for large codebases.
  • Limited Offline Support
    LGTM.com primarily operates as a cloud-based service, limiting offline use or self-hosted scenarios, which may be a consideration for teams with specific privacy or compliance requirements.
  • Dependency on Internet Connection
    Its reliance on internet connectivity may pose an issue for developers in regions with unstable internet access, affecting productivity.
  • Platform-specific Limitations
    Some functionalities might be optimized or limited based on the particular platform integration, potentially requiring different configurations for distinct environments.

DefenseCode ThunderScan® features and specs

  • Comprehensive Analysis
    ThunderScan® provides thorough static application security testing (SAST), allowing for detailed analysis of source code and detection of vulnerabilities.
  • Language Support
    The tool supports a wide range of programming languages, making it versatile and adaptable for different development environments.
  • Integration
    It integrates well with various CI/CD pipelines, enhancing continuous development workflows by providing automated security checks.
  • User Interface
    ThunderScan® features an intuitive and user-friendly interface, making it accessible for users with varying levels of technical expertise.
  • Comprehensive Reporting
    The tool offers detailed reports with insights into identified vulnerabilities, including potential impacts and remediation advice.

Possible disadvantages of DefenseCode ThunderScan®

  • Resource Intensive
    The scanning process can be resource-heavy, potentially affecting the performance of other applications running on the same system.
  • Initial Setup
    The initial setup and configuration of ThunderScan® can be time-consuming, requiring a significant investment of time and expertise.
  • False Positives
    Like many SAST tools, ThunderScan® may generate false positives, requiring manual review to distinguish genuine issues from non-issues.
  • License Cost
    The licensing cost for ThunderScan® can be high, which might be prohibitive for smaller organizations or projects with limited budgets.
  • Dependency Limitations
    The tool may have limitations in scanning certain complex dependencies or legacy systems, potentially missing vulnerabilities in those areas.

Analysis of DefenseCode ThunderScan®

Overall verdict

  • DefenseCode ThunderScan is a solid, mature Static Application Security Testing (SAST) solution well-regarded for its accuracy and broad language support, making it a good choice for organizations focused on securing their source code.

Why this product is good

  • Comprehensive Static Application Security Testing (SAST) that analyzes source code without needing to execute it
  • Supports a wide range of programming languages including Java, C/C++, C#, PHP, JavaScript, Python, Ruby, and more
  • Detects common and complex vulnerabilities aligned with standards like OWASP Top 10, SANS Top 25, PCI DSS, and HIPAA
  • Integrates into the software development lifecycle (SDLC) and CI/CD pipelines for early detection of security flaws
  • Provides detailed reports with vulnerability descriptions, severity levels, and remediation guidance
  • Established vendor with a focus on application security and reasonable pricing compared to some larger competitors

Recommended for

  • Development teams wanting to integrate security testing into their CI/CD pipelines
  • Organizations that need to scan large codebases across multiple programming languages
  • Companies needing to meet compliance requirements such as PCI DSS, HIPAA, or OWASP standards
  • Security teams and DevSecOps practitioners seeking early detection of code-level vulnerabilities
  • Enterprises and mid-sized businesses building or maintaining custom software applications

Category Popularity

0-100% (relative to lgtm.com and DefenseCode ThunderScan®)
Code Analysis
79 79%
21% 21
Tool
100 100%
0% 0
Code Coverage
60 60%
40% 40
Development
100 100%
0% 0

User comments

Share your experience with using lgtm.com and DefenseCode ThunderScan®. For example, how are they different and which one is better?
Log in or Post with

Social recommendations and mentions

Based on our record, lgtm.com seems to be more popular. It has been mentiond 3 times since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.

lgtm.com mentions (3)

DefenseCode ThunderScan® mentions (0)

We have not tracked any mentions of DefenseCode ThunderScan® yet. Tracking of DefenseCode ThunderScan® recommendations started around Jul 2021.

What are some alternatives?

When comparing lgtm.com and DefenseCode ThunderScan®, you can also consider the following products

Cppcheck - Cppcheck is an analysis tool for C/C++ code. It detects the types of bugs that the compilers normally fail to detect. The goal is no false positives. CppCheckDownload cppcheck for free.

SonarQube - SonarQube, a core component of the Sonar solution, is an open source, self-managed tool that systematically helps developers and organizations deliver Clean Code.

Clang Static Analyzer - The Clang Static Analyzer is a source code analysis tool that finds bugs in C, C++, and Objective-C...

Kiuwan Application Security - Kiuwan Application Security is an end-to-end Appsec platform.

VisualCodeGrepper - VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL.

Codacy - Automatically reviews code style, security, duplication, complexity, and coverage on every change while tracking code quality throughout your sprints.