Checkmarx One logo

    Checkmarx One

    Sold by
    Checkmarx One helps you deliver secure software faster with an integrated Application Security Testing platform deployed as a service. A single event, like a code commit or build stage, can trigger scans of your source code, dependencies, and IaC templates, with results aggregated in one place.

    Ratings and reviews

    4.2
    71 ratings
    47%
    51%
    1%
    1%
    0%
    4 AWS reviews
    |
    67 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (71)
    Roushan J.

    Effective SAST with Minimal false Positives

    Reviewed on Sep 01, 2026
    Review provided by G2
    What do you like best about the product?
    I use Checkmarx for SAST code review, and it helps me identify security vulnerabilities early in the software development lifecycle, saving a lot of money by catching them in the code for each commit. I really like how it identifies security vulnerabilities, especially getting rid of common OWASP top 10 vulnerabilities like SQL injection and Cross-Site Scripting. I'm impressed that it can also detect business logic vulnerabilities, such as unauthorized access control, earlier in the development process. I also appreciate that it reports IDOR vulnerabilities from the OWASP top 10. The initial setup was easy, and I switched to Checkmarx from Fortify mainly because it provides less noise from false positives and offers deeper coverage of the OWASP top 10.
    What do you dislike about the product?
    Some of false positive seems painful sometimes
    What problems is the product solving and how is that benefiting you?
    I use Checkmarx to identify security vulnerabilities early in the development process, saving money by catching issues with every commit. It helps eliminate OWASP top 10 vulnerabilities, like SQL injection, Cross-Site Scripting, and unauthorized access control, even catching IDOR vulnerabilities.
    Poorna Srinivasa Rao T.

    Poorna's Checkmarx Review

    Reviewed on Aug 30, 2026
    Review provided by G2
    What do you like best about the product?
    Checkmarx is a solid application security tool that helps identify security vulnerabilities throughout the software development lifecycle, including with its AI features. Its ability to alert developers to application flaws even before the code moves to production is especially appreciable. The UI is easy to navigate and delivers fast performance, and its ability to integrate with multiple repos and CI/CD pipelines is great. Although the pricing is a bit higher, it still feels worth it. Support is fair enough.
    What do you dislike about the product?
    It tends to generate more noise, and even items that are negligible still get flagged. The scan speed is a bit slow compared to other tools in the market, but it does deliver on results. Pricing also feels a bit on the higher side.
    What problems is the product solving and how is that benefiting you?
    Checkmarx helps throughout the software development lifecycle by flagging bugs and vulnerabilities. It supports Static Application Security Testing, API security, Software Composition Analysis, and Dynamic Application Security Testing.
    Naushad T.

    Checkmarx: Reliable SAST Solution for Strengthening Application Security

    Reviewed on Jul 09, 2026
    Review provided by G2
    What do you like best about the product?
    I had a positive experience using Checkmarx as part of our application security process. What I appreciated most was how it helped us identify security vulnerabilities early in the development lifecycle, so teams could address issues before they reached production. The interface is fairly friendly once you're familiar with it, and the scan reports provide enough detail for developers and security teams to understand the root cause and recommended remediation.
    What do you dislike about the product?
    The initial setup and policy configuration come with a learning phase, especially for teams that are new to application security testing. In addition, full scans can take a while on large or complex projects, which can slow down development pipelines.
    What problems is the product solving and how is that benefiting you?
    Checkmarx has helped us standardize our secure code review process by delivering consistent vulnerability analysis across multiple projects. Its integration with our CI/CD pipeline lets us run automated security scans as part of the build process, so developers get timely feedback without interrupting their day-to-day workflow. Overall, Checkmarx has strengthened our security posture and continues to support our DevSecOps initiatives.
    Computer Software

    Strong Integrations and Support, but Pricing Is a Challenge for LatAm Startups

    Reviewed on Jul 09, 2026
    Review provided by G2
    What do you like best about the product?
    For us the most importante is the number of integrations that it has, sometimes de price is a little bit hi because we are startup that is based in Latam. The support also is good, and the performance UI and UX algo good.
    What do you dislike about the product?
    During the pilot test of this technology it works correct, we are evaluating due pricing because our geography
    What problems is the product solving and how is that benefiting you?
    Right now we are using a lot of agenting development, so it works for us correctly making some integrations with agentic coding. The AI that use is really good for this evaluation and integration
    uday n.

    Seamlessly Integrates Security Into the Development Lifecycle

    Reviewed on Jun 24, 2026
    Review provided by G2
    What do you like best about the product?
    its ability to integrate security directly into software development life cycle
    What do you dislike about the product?
    deeper security analysis can sometimes increase scan duration
    What problems is the product solving and how is that benefiting you?
    helps catch security issues early in development
    Nitesh A.

    Automated Checkmarx Scans Keep Us Ahead of Key Vulnerabilities

    Reviewed on Jun 20, 2026
    Review provided by G2
    What do you like best about the product?
    Provision to automate scan runs is now available. Scan results are well structured and comments are well documented. Easy for developers to understand and fix. Can be integrated with stakeholder reports. Good UI and support
    What do you dislike about the product?
    Scan results on Salesforce security portal are different from checkmarx portal which cause issues during package submission to Salesforce.
    What problems is the product solving and how is that benefiting you?
    Checkmarx helps us to automate repo scans, provides good insights into vulnerabilities or major issues in code and segregates them in terms of severity. It also provides option to upload results as false positive So these do not get reported again n again. The exports are good to submit for security review. The UI design is good and intuitive. We found the scans run pretty fast and hence better in performance. We good good response and support from checkmark team for any issues or new features. Overall good experience.
    Aman M.

    Centralized Source Code Security with Seamless CI/CD Integration

    Reviewed on Jun 19, 2026
    Review provided by G2
    What do you like best about the product?
    Checkmarx is a centralized security tool that provides end-to-end insights into source code security and vulnerabilities. It also helps improve the efficiency of the source code by highlighting the associated risks and suggesting ways to remediate the vulnerabilities. In addition, it shows vulnerabilities in the open-source libraries and packages we use in our source code through SCA scans.

    One thing I like the most is how well it integrates with our CI/CD tooling. We can plug it into our DevSecOps CI/CD flow, and developers can see scan insights directly from the pipeline itself, without needing to log in to the Checkmarx UI separately.
    What do you dislike about the product?
    It should better cope with modern software development lifecycles and provide end-to-end support for scanning any valid file extensions. For example, we are migrating from Node JS to TypeScript, and as part of that change we updated our .js files to use the .mjs extension. However, Checkmarx still does not support scanning .mjs files. We reported this issue to them about a year ago, but even now it remains unsupported. The current suggestion is to rename .mjs files to .js when uploading code for Checkmarx scans, which is not a practical workaround for us.
    What problems is the product solving and how is that benefiting you?
    End-to-end security scanning for source code, including SAST and SCA scanning. It also supports API security scanning, IaC file scanning, and secret detection. Seamless integration with native CI/CD tools makes it easy to integrate Checkmarx into DevSecOps pipelines.

    This reduces the Source Codes attack surface and by that we have achieved over 70%-80% of improvement in overall Code Security and our feature releases is now bullet proof from Security attacks
    Arya S.

    Comprehensive Application Security with Checkmarx

    Reviewed on Jun 17, 2026
    Review provided by G2
    What do you like best about the product?
    I like Checkmarx because it provides comprehensive application security, with accurate vulnerability detection, risk-based prioritization, and clear remediation recommendations.
    What do you dislike about the product?
    One area that could be improved is the number of false positives generated during scans, as this can add extra time to validation and triage. In addition, scans may take longer when running against large codebases.
    What problems is the product solving and how is that benefiting you?
    Checkmarx helps us address the challenge of identifying security vulnerabilities early in the software development lifecycle, before they reach production. It scans source code, open-source dependencies, APIs, and other application components to detect security risks and provide remediation guidance. For us, this reduces the likelihood of security incidents, supports compliance efforts, reinforces secure development practices, and helps development teams fix vulnerabilities faster without significantly slowing delivery timelines.
    Program Development

    Seamless Developer Workflow Integration for Real-Time Vulnerability Fixes

    Reviewed on May 31, 2026
    Review provided by G2
    What do you like best about the product?
    Checkmarx integrates directly into the developer workflow. By providing plugins for popular IDEs, CI/CD pipelines, and source code management (SCM) platforms, it allows developers to catch and fix vulnerabilities in real time without context-switching
    What do you dislike about the product?
    Running the application can strain local servers, and I note that the system requires substantial RAM and processing power to perform efficiently.
    What problems is the product solving and how is that benefiting you?
    Checkmarx solves the critical problem of vulnerabilities slipping into production code, which directly benefits me by reducing security risks and saving development time.
    Information Technology and Services

    Proactive Security and Smooth Cross-Team Collaboration

    Reviewed on May 30, 2026
    Review provided by G2
    What do you like best about the product?
    Its proactive approach to security.. I like how it enables you to collaborate with other teams.
    What do you dislike about the product?
    the only concern I had initially was the complexity the platform has a steep learning curve. and the Cost
    What problems is the product solving and how is that benefiting you?
    Protects customers data, and lowered remediation cost.