Latest Research


This content is currently locked.

Your current Info-Tech Research Group subscription does not include access to this content. Contact your account representative to gain access to Premium SoftwareReviews.

Contact Your Representative
Or Call Us:
1-888-670-8889 (US/CAN) or
+1-519-432-3550 (International)
SonarQube Logo
SonarQube Logo
SonarSource SA

SonarQube

8.0 /10
Category
SonarQube
8.0 /10

What is SonarQube?

SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.

Company Details


Need Assistance?

We're here to help you with understanding our reports and the data inside to help you make decisions.

Get Assistance

SonarQube Ratings

Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard to access more information on SonarQube.

91 Likeliness to Recommend

100 Plan to Renew

84 Satisfaction of Cost Relative to Value


{y}
{name}

Emotional Footprint Overview

+90 Net Emotional Footprint

The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.

How much do users love SonarQube?

0% Negative
0% Neutral
100% Positive

Pros

  • Performance Enhancing
  • Respectful
  • Altruistic
  • Transparent

Feature Ratings

Average 84

Software Composition Analysis (SCA)

91

Dynamic Application Security Testing (DAST)

88

Automated Workflow

87

Interactive Application Security Testing (IAST)

86

Vulnerability Scanning

85

False Positive Remediation

83

Static Application Security Testing (SAST)

83

Risk Scoring

82

Mobile Application Security Testing

82

Container Security Testing

82

Policy Engine and Enforcements

80

Vendor Capability Ratings

Average 81

Ease of Data Integration

90

Business Value Created

87

Breadth of Features

86

Ease of Implementation

85

Ease of IT Administration

82

Ease of Customization

80

Availability and Quality of Training

79

Vendor Support

79

Quality of Features

76

Usability and Intuitiveness

76

Product Strategy and Rate of Improvement

72

SonarQube Reviews

Ramaseshan N.

  • Role: Information Technology
  • Industry: Engineering
  • Involvement: Business Leader or Manager
Validated Review
Verified Reviewer

Submitted May 2024

Great Product in the Market

Likeliness to Recommend

10 /10

What differentiates SonarQube from other similar products?

Comprehensive Code Analysis: SonarQube offers a comprehensive set of static code analysis rules covering a wide range of programming languages, frameworks, and technologies. This extensive coverage ensures that developers can identify and address code quality issues, security vulnerabilities, and technical debt across their entire codebase. Customizable Quality Profiles: SonarQube allows users to define customizable quality profiles tailored to their specific project requirements, coding standards, and performance benchmarks.

What is your favorite aspect of this product?

One of my favorite aspects of SonarQube is its comprehensive and customizable code analysis capabilities. SonarQube offers a wide range of static code analysis rules covering various programming languages, frameworks, and technologies, allowing developers to identify and address code quality issues, security vulnerabilities, and technical debt effectively. I appreciate how SonarQube provides customizable quality profiles, enabling organizations to tailor code analysis rules to their specific project requirements and coding standards.

What do you dislike most about this product?

Complexity of Setup: Setting up SonarQube for the first time can be complex, especially for users who are new to the platform or lack experience with static code analysis tools. The process involves installing and configuring the SonarQube server, setting up analysis projects, configuring quality profiles, and integrating with CI/CD pipelines. Resource Requirements: SonarQube can be resource-intensive, particularly for large codebases or organizations with extensive project portfolios. Users may need to allocate sufficient hardware resources, such as CPU, memory, and storage, to ensure optimal performance and scalability.

What recommendations would you give to someone considering this product?

Assess Your Needs: Before implementing SonarQube, assess your organization's specific requirements and objectives for code quality management and static code analysis. Consider factors such as the size and complexity of your codebase, the programming languages and frameworks used, and the desired level of integration with CI/CD pipelines. Plan Your Implementation: Develop a clear plan for implementing SonarQube within your organization. Define your goals, scope, and timeline for deployment, and identify key stakeholders and team members who will be involved in the implementation process.

Pros

  • Helps Innovate
  • Continually Improving Product
  • Reliable
  • Performance Enhancing

Govind S.

  • Role: Consultant
  • Industry: Telecommunications
  • Involvement: IT Development, Integration, and Administration
Validated Review
Verified Reviewer

Submitted Apr 2024

SonarQube: Streamlining Code Quality

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

1. Comprehensive Code Analysis: SonarQube offers a comprehensive set of code analysis tools that cover a wide range of programming languages and frameworks. 2. Scalability: SonarQube is highly scalable, capable of analyzing codebases of any size, from small projects to large enterprise applications. 3. Customizable Quality Profiles: SonarQube allows users to create custom quality profiles tailored to their specific project requirements. 4. ntegration Ecosystem: SonarQube integrates seamlessly with various development tools and CI/CD pipelines, including Jenkins, GitLab CI, and Azure DevOps.

What is your favorite aspect of this product?

One of the standout features of SonarQube that I find particularly impressive is its comprehensive code analysis capabilities. SonarQube offers an extensive array of static code analysis tools that provide deep insights into code quality, security vulnerabilities, and potential bugs. This level of analysis empowers development teams to proactively identify and address issues early in the development lifecycle, leading to higher-quality code and more robust software applications.

What do you dislike most about this product?

One aspect that some users may find challenging with SonarQube is its initial setup and configuration complexity. Setting up SonarQube to integrate seamlessly with existing development workflows, configuring quality profiles, defining rulesets, and establishing appropriate quality gates can require a significant investment of time and effort.

What recommendations would you give to someone considering this product?

1. Understand Your Requirements: Clearly define your organization's code quality and security requirements, as well as the specific challenges you aim to address with SonarQube. 2. Customize for Your Environment: Take advantage of SonarQube's customization options to tailor the platform to your organization's specific needs and coding standards. 3, Integrate with CI/CD Pipelines: Integrate SonarQube seamlessly into your continuous integration and continuous deployment (CI/CD) pipelines to automate code analysis and quality checks as part of your development workflow.

Pros

  • Altruistic
  • Helps Innovate
  • Continually Improving Product
  • Performance Enhancing

Amit C.

  • Role: Industry Specific Role
  • Industry: Healthcare
  • Involvement: End User of Application
Validated Review
Verified Reviewer

Submitted Mar 2024

SonarQube is amazing and Swift!

Likeliness to Recommend

10 /10

What differentiates SonarQube from other similar products?

We can integrate SonarQube seamlessly with build tools, such as Gradle and ant

What is your favorite aspect of this product?

SonarQube reports duplicate code, code coverage, unit testing, code complexity historical.

What do you dislike most about this product?

It lacks advanced code security features.

What recommendations would you give to someone considering this product?

It's a open source and supports various languages such as C# and Java.

Pros

  • Helps Innovate
  • Continually Improving Product
  • Reliable
  • Performance Enhancing
Visit our Exponential IT Research Center
Over 100 analysts waiting to take your call right now: 1-519-432-3550 x2019