Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
The leader in application vulnerability scanning
What do you like best about the product?
Single solution for both static and dynamic scans.
What do you dislike about the product?
There's a little bit of a learning curve.
What problems is the product solving and how is that benefiting you?
Developing secure software.
- Leave a Comment |
- Mark review as helpful
Comprehensive code Security Reporting
What do you like best about the product?
It is easy to integrate with code build tools and produces comprehensive reports about the code quality and security vulnerabilities.
What do you dislike about the product?
Nothing much to consider but it needs little bit of tweaks in order to tailor to your needs and to suit multiple technologies.
What problems is the product solving and how is that benefiting you?
It serves multiple purposes like static code analysis and security vulnerabilities at one shot and produces good reports.
Great tool to find security flaws
What do you like best about the product?
Veracode is good static analysis tool to find security flaws. I use this tool to scan my java microservices jar files. it's easy to configure. It does not require source code and accepts binary files and scans them.
We can either manually scan files or integrate with jenkin so jars are auto scanned on every build.
We can either manually scan files or integrate with jenkin so jars are auto scanned on every build.
What do you dislike about the product?
can takes some time . It could be better if scanning time is improved.
What problems is the product solving and how is that benefiting you?
We use veracode to identify flaws and malicious code in applications before they are bought or deployed. It helps to build more secure application.
Great, In Depth Scanned with Limited Experience Support
What do you like best about the product?
Veracode combines human and automated scanning to offer a really robust report. Reports are actionable, remediation is automated, and executive summaries are available on demand.
What do you dislike about the product?
Veracode today is robust for static scans, but limited to specific mobile builds and Firefox for dynamic scans. This makes analyzing Saas apps that do not support Firefox particularly challenging.
What problems is the product solving and how is that benefiting you?
Application security, vulnerability assessment.
Recommendations to others considering the product:
If your app supports Firefox, this is the best tool on the market!
Good concept, terrible implementation
What do you like best about the product?
The idea. I'm a big evangelist of clean code and standards.
What do you dislike about the product?
Everything:
- Scans inaccurate
- Slow
- Outdated UI
- Not user friendly
- Terrible HTTP API for automation
- Bad customer support
- One of our applications, only 1 out of hundreds issues turns out to be true.
- Scans inaccurate
- Slow
- Outdated UI
- Not user friendly
- Terrible HTTP API for automation
- Bad customer support
- One of our applications, only 1 out of hundreds issues turns out to be true.
What problems is the product solving and how is that benefiting you?
No benefits. I only use Veracode because it is enforced by company policies
Recommendations to others considering the product:
If you want your developers frustrated, go ahead and impose veracode. SonarQube together with Findbugs provides more useful feedback.
showing 11 - 15