What is SonarQube?
SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.
Company Details
Need Assistance?
We're here to help you with understanding our reports and the data inside to help you make decisions.
Get AssistanceSonarQube Ratings
Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard
to access more information on SonarQube.
Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.
91 Likeliness to Recommend
100 Plan to Renew
84 Satisfaction of Cost Relative to Value
Emotional Footprint Overview
Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.
+93 Net Emotional Footprint
The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.
How much do users love SonarQube?
Pros
- Performance Enhancing
- Respectful
- Altruistic
- Transparent
How to read the Emotional Footprint
The Net Emotional Footprint measures high-level user sentiment towards particular product offerings. It aggregates emotional response ratings for various dimensions of the vendor-client relationship and product effectiveness, creating a powerful indicator of overall user feeling toward the vendor and product.
While purchasing decisions shouldn't be based on emotion, it's valuable to know what kind of emotional response the vendor you're considering elicits from their users.
Footprint
Negative
Neutral
Positive
Feature Ratings
Automated Workflow
Vulnerability Scanning
Static Application Security Testing (SAST)
Mobile Application Security Testing
Container Security Testing
Policy Engine and Enforcements
Software Composition Analysis (SCA)
Dynamic Application Security Testing (DAST)
Risk Scoring
False Positive Remediation
Interactive Application Security Testing (IAST)
Vendor Capability Ratings
Ease of Data Integration
Business Value Created
Breadth of Features
Ease of Implementation
Ease of IT Administration
Availability and Quality of Training
Vendor Support
Ease of Customization
Usability and Intuitiveness
Quality of Features
Product Strategy and Rate of Improvement
SonarQube Reviews
Mary V.
- Role: Information Technology
- Industry: Technology
- Involvement: IT Leader or Manager
Submitted Jun 2022
My experience with SonarQube.
Likeliness to Recommend
What differentiates SonarQube from other similar products?
Code analysis, minimizing coding violations, ensuring that code complexity is resolved and complies with industry standards, running a health report for every check-in to the repository, removing duplicate methods or code, empty methods, and making sure we have a plan in place for the required.Our staff may visit the cloud-based server where SonarQube is running to assess the caliber of their code.
What is your favorite aspect of this product?
One of the main advantages is the connection with Jenkins. It's an excellent feature for enterprise apps since it makes the entire process easier and allows you to incorporate the tollgate idea. also SonarQube provides strong capabilities to maintain the quality of your code by eliminating bugs, which also increases the code's security.
What do you dislike most about this product?
It takes some time to integrate Sonarqube into CI/CD pipelines, and if the developer is less experienced, it can take even longer. The offered help guide also needs to be more recent. Finally, it would be great if there was a way to download the report and provide it to the teams.
What recommendations would you give to someone considering this product?
When using this tool, it is crucial to note that not all IDE codes can be used in SonarQube, so be careful when choosing them. Static scans are easy to incorporate into your DevOps lifecycle and have several benefits. We recommend companies to use this technology to guarantee the expected performance.
Pros
- Performance Enhancing
- Trustworthy
- Unique Features
- Efficient Service
Alexis P.
- Role: Sales Marketing
- Industry: Technology
- Involvement: IT Development, Integration, and Administration
Submitted Jan 2022
Great product, easy implementation
Likeliness to Recommend
What differentiates SonarQube from other similar products?
Works best for the company I am with.
What is your favorite aspect of this product?
Easy implementation and use.
What do you dislike most about this product?
Nothing. Service is great and easy to use
What recommendations would you give to someone considering this product?
Look at your options and see what's the best fit for your company
Pros
- Helps Innovate
- Continually Improving Product
- Reliable
- Performance Enhancing
Lindator K.
- Role: Information Technology
- Industry: Healthcare
- Involvement: End User of Application
Submitted Aug 2021
Sufficient Application Safety Tool
Likeliness to Recommend
What differentiates SonarQube from other similar products?
SonarQube ensures anything that is malicious or suspicious is thoroughly scanned and reports or notifications given to the IT department. SonarQube has automated features and work flow, where actions or activities runs systematically without anyone's supervision.
What is your favorite aspect of this product?
The inappropriate and false remediation that some people issues are identified by SonarQube. After a comprehensive security analysis, there is the risk score that SonarQube issues to the company.
What do you dislike most about this product?
SonarQube vendor ignored the feature for system or software hardening, which is vital in trying to identify the efficiency of the program. The challenge of instability in a software leads to operations failure.
What recommendations would you give to someone considering this product?
That the safety of every software should be measured, and SonarQube is a program with incomparable powers. After the vulnerability scan, reports in terms of risk score is shared.
Pros
- Helps Innovate
- Continually Improving Product
- Reliable
- Enables Productivity