Latest Research


This content is currently locked.

Your current Info-Tech Research Group subscription does not include access to this content. Contact your account representative to gain access to Premium SoftwareReviews.

Contact Your Representative
Or Call Us:
1-888-670-8889 (US/CAN) or
+1-519-432-3550 (International)
SonarQube Logo
SonarQube Logo
SonarSource SA

SonarQube

7.9 /10
Category
SonarQube
7.9 /10

What is SonarQube?

SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.

Company Details


Need Assistance?

We're here to help you with understanding our reports and the data inside to help you make decisions.

Get Assistance

SonarQube Ratings

Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard to access more information on SonarQube.

90 Likeliness to Recommend

100 Plan to Renew

83 Satisfaction of Cost Relative to Value


{y}
{name}

Emotional Footprint Overview

+89 Net Emotional Footprint

The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.

How much do users love SonarQube?

0% Negative
0% Neutral
100% Positive

Pros

  • Performance Enhancing
  • Respectful
  • Altruistic
  • Transparent

Feature Ratings

Average 83

Software Composition Analysis (SCA)

89

Automated Workflow

88

Dynamic Application Security Testing (DAST)

86

Vulnerability Scanning

84

Static Application Security Testing (SAST)

84

Interactive Application Security Testing (IAST)

83

Container Security Testing

82

False Positive Remediation

82

Risk Scoring

81

Mobile Application Security Testing

79

Policy Engine and Enforcements

79

Vendor Capability Ratings

Average 80

Ease of Data Integration

90

Business Value Created

87

Breadth of Features

85

Ease of Implementation

84

Ease of IT Administration

80

Ease of Customization

78

Availability and Quality of Training

78

Vendor Support

77

Quality of Features

77

Usability and Intuitiveness

75

Product Strategy and Rate of Improvement

72

SonarQube Reviews

DANIEL A.

  • Role: Information Technology
  • Industry: Technology
  • Involvement: IT Development, Integration, and Administration
Validated Review
Verified Reviewer

Submitted Mar 2024

Likeliness to Recommend

10 /10

What differentiates SonarQube from other similar products?

Quality customer service Open source and community

What is your favorite aspect of this product?

Early detection of issues

Pros

  • Helps Innovate
  • Performance Enhancing
  • Enables Productivity
  • Trustworthy

KIRAN KUMAR V.

  • Role: Information Technology
  • Industry: Energy
  • Involvement: IT Development, Integration, and Administration
Validated Review
Verified Reviewer

Submitted Jan 2024

Nice application

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

Code quality and venerability

What is your favorite aspect of this product?

Suggested correction

What do you dislike most about this product?

Also showing some unwanted changes

What recommendations would you give to someone considering this product?

To creat user based rules

Pros

  • Helps Innovate
  • Continually Improving Product
  • Trustworthy
  • Performance Enhancing

Nikhil K.

  • Role: Information Technology
  • Industry: Technology
  • Involvement: IT Development, Integration, and Administration
Validated Review
Verified Reviewer

Submitted Dec 2023

SonarQube is a versatile static code analysis tool

Likeliness to Recommend

9 /10

What differentiates SonarQube from other similar products?

Language Support: SonarQube supports a wide array of programming languages, making it versatile for multi-language projects. This includes popular languages such as Java, JavaScript, C#, Python, and more. Extensive Rule Sets: SonarQube provides a comprehensive set of predefined coding rules for each supported language, helping developers identify and address code quality issues. Users can also customize or create their own rules to align with specific coding standards. Integration with CI/CD Pipelines: SonarQube seamlessly integrates with continuous integration and continuous deployment (CI/CD) pipelines.

What is your favorite aspect of this product?

Comprehensive Analysis:SonarQube provides a broad range of static code analysis rules, covering both security-related issues and general code quality concerns. This comprehensive analysis allows SAST engineers to address multiple aspects of software development in a single tool. Integration of Security and Quality Metrics:The tool integrates security metrics seamlessly with code quality metrics. Early Detection of Issues: SonarQube's integration with CI/CD pipelines facilitates early detection of security vulnerabilities and code quality issues.

What do you dislike most about this product?

Resource Intensiveness:Some users have reported that running extensive static code analysis with SonarQube can be resource-intensive, especially for large codebases. This might include increased memory and processing requirements during the analysis. Learning Curve for Customization:While SonarQube is known for its flexibility, some users, especially newcomers, may find the learning curve steep when it comes to customizing rules or configurations to meet specific project requirements.

What recommendations would you give to someone considering this product?

1. Understand Your Project Requirements 2. Evaluate Integration with Your Development Workflow 3. Consider the Learning Curve 4. Start with a Pilot Project 5. Customization and Rules Configuration 6. Assess Community Support 7. Consider Enterprise Edition Features 8. Evaluate Resource Requirements 9. Check for Regular Updates 10. Address False Positives and Negatives

Pros

  • Reliable
  • Effective Service
  • Saves Time
  • Client's Interest First
Visit our Exponential IT Research Center
Over 100 analysts waiting to take your call right now: 1-519-432-3550 x2019