Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

1 AWS reviews
  • 5 star
    0
  • 4 star
    0
  • 1
  • 2 star
    0
  • 1 star
    0

External reviews

12 reviews
from and

External reviews are not included in the AWS star rating for the product.


3-star reviews ( Show all reviews )

    Tharindu Malwenna

Developers have improved vulnerability awareness but require more customizable training options

  • October 17, 2025
  • Review from a verified AWS customer

What is our primary use case?

I have used SonarQube as a community product for static application security testing as well as quality gate checking for the organization. Now I have retired the community edition of SonarQube and I am currently working with Checkmarx for a proper solution.

In my current license configuration, I have Codebashing, secret scanning, and SAST.

Codebashing is solely purposed for training our developers regarding the vulnerabilities we have, and it has seamless integration within Checkmarx. I am running a security champions program which leverages Codebashing platform itself.

How has it helped my organization?

Codebashing serves as a baseline for developers, though not many advanced techniques are available. In the tournament phases, it mostly resembles a Kahoot tournament, so having more CTF capabilities within the platform would be beneficial.

The statistics are really good for the developers after we deployed Codebashing. When people do not know anything regarding a vulnerability, they can gain a basic idea of what that vulnerability is and how they can mitigate things. There are some lacking vulnerabilities in Codebashing platform itself, making it both advantageous and disadvantageous.

What is most valuable?

The best features of Codebashing are the skill trees and the way I can impose trainings for the developers, which is highly effective.

What needs improvement?

It would be beneficial for Codebashing platform if we were able to quickly customize the questionnaires. Currently, we have to work with predefined questionnaires or utilize another language to create quizzes. I would prefer having a GUI for that aspect so I can provide tailor-made questionnaires for the developers, allowing me to utilize Codebashing platform entirely instead of depending on other solutions.

For how long have I used the solution?

I have two years of experience with Checkmarx.

How are customer service and support?

With Codebashing solution, we had a couple of complications, such as account configuration issues. Because we are currently in the initial stages, the support is really good, but we have to wait and see.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Initially, we had Contrast Security, and comparing with that, the coverage against the cost shows that Checkmarx is doing a good job.

How was the initial setup?

Codebashing and Checkmarx SAST are really easy to set up; it is a matter of figuring out the SSO configuration from our end. The rest of the things are currently using the SaaS solution provided by Checkmarx, so the initial setup phase is straightforward.

Scanning the entire organization takes time, which was one of the challenges we faced during the initial phase. To overcome such issues, we had to write scripts as workarounds.

What was our ROI?

With Codebashing we can see a clear difference; the vulnerability fixing ratio became 160% per month, and the density counts started reducing after implementation.

Which other solutions did I evaluate?

Based on the coverage we receive when comparing it with the IAS tool and the options we receive, such as ID integrations and direct impact on pull push requests, the pricing is much lower than IAS.

What other advice do I have?

I am not familiar with Codebashing updates frequency. We bought it through an agent. On a scale of 1-10, I rate this solution a 7.


    Frank B.

Pioneer in Application Security Training

  • June 27, 2023
  • Review provided by G2

What do you like best about the product?
Gyan Chawdhary created the first AppSec Training for developers. At the time it was the only tool and very useful
What do you dislike about the product?
Tool is getting old. Colors used for developers are not clear. Exercises take too much time.
What problems is the product solving and how is that benefiting you?
It helps me spot the main weaknesses in the code writing and is a daily training that help me be more productive.


showing 1 - 2