Sold by
Checkmarx One
Checkmarx One helps you deliver secure software faster with an integrated Application Security Testing platform deployed as a service. A single event, like a code commit or build stage, can trigger scans of your source code, dependencies, and IaC templates, with results aggregated in one place.
Reviews (69)
Naushad T.
Checkmarx: Reliable SAST Solution for Strengthening Application Security
Reviewed on Jul 09, 2026
Review provided by G2
What do you like best about the product?
I had a positive experience using Checkmarx as part of our application security process. What I appreciated most was how it helped us identify security vulnerabilities early in the development lifecycle, so teams could address issues before they reached production. The interface is fairly friendly once you're familiar with it, and the scan reports provide enough detail for developers and security teams to understand the root cause and recommended remediation.
What do you dislike about the product?
The initial setup and policy configuration come with a learning phase, especially for teams that are new to application security testing. In addition, full scans can take a while on large or complex projects, which can slow down development pipelines.
What problems is the product solving and how is that benefiting you?
Checkmarx has helped us standardize our secure code review process by delivering consistent vulnerability analysis across multiple projects. Its integration with our CI/CD pipeline lets us run automated security scans as part of the build process, so developers get timely feedback without interrupting their day-to-day workflow. Overall, Checkmarx has strengthened our security posture and continues to support our DevSecOps initiatives.
Computer Software
Strong Integrations and Support, but Pricing Is a Challenge for LatAm Startups
Reviewed on Jul 09, 2026
Review provided by G2
What do you like best about the product?
For us the most importante is the number of integrations that it has, sometimes de price is a little bit hi because we are startup that is based in Latam. The support also is good, and the performance UI and UX algo good.
What do you dislike about the product?
During the pilot test of this technology it works correct, we are evaluating due pricing because our geography
What problems is the product solving and how is that benefiting you?
Right now we are using a lot of agenting development, so it works for us correctly making some integrations with agentic coding. The AI that use is really good for this evaluation and integration
uday n.
Seamlessly Integrates Security Into the Development Lifecycle
Reviewed on Jun 24, 2026
Review provided by G2
What do you like best about the product?
its ability to integrate security directly into software development life cycle
What do you dislike about the product?
deeper security analysis can sometimes increase scan duration
What problems is the product solving and how is that benefiting you?
helps catch security issues early in development
Nitesh A.
Automated Checkmarx Scans Keep Us Ahead of Key Vulnerabilities
Reviewed on Jun 20, 2026
Review provided by G2
What do you like best about the product?
we use checkmark to scan Salesforce code base in GitHub. we have automated the checkmarx run of scans so we are aware of key vulnerabilities so we can fix them before time. The scans are showing good results, export options are good. overall a good product
What do you dislike about the product?
What we found was the scan results derived from repo scan using Salesforce Security portal scans are different from the results of checkmark scans.
What problems is the product solving and how is that benefiting you?
Checkmarx helps us to automate repo scans, provides good insights into vulnerabilities or major issues in code and segregates them in terms of severity. It also provides option to upload results as false positive So these do not get reported again n again. The exports are good to submit for security review. The UI design is good and intuitive. We found the scans run pretty fast and hence better in performance. We good good response and support from checkmark team for any issues or new features. Overall good experience.
Aman M.
Centralized Source Code Security with Seamless CI/CD Integration
Reviewed on Jun 19, 2026
Review provided by G2
What do you like best about the product?
Checkmarx is a centralized security tool that provides end-to-end insights into source code security and vulnerabilities. It also helps improve the efficiency of the source code by highlighting the associated risks and suggesting ways to remediate the vulnerabilities. In addition, it shows vulnerabilities in the open-source libraries and packages we use in our source code through SCA scans.
One thing I like the most is how well it integrates with our CI/CD tooling. We can plug it into our DevSecOps CI/CD flow, and developers can see scan insights directly from the pipeline itself, without needing to log in to the Checkmarx UI separately.
One thing I like the most is how well it integrates with our CI/CD tooling. We can plug it into our DevSecOps CI/CD flow, and developers can see scan insights directly from the pipeline itself, without needing to log in to the Checkmarx UI separately.
What do you dislike about the product?
It should better cope with modern software development lifecycles and provide end-to-end support for scanning any valid file extensions. For example, we are migrating from Node JS to TypeScript, and as part of that change we updated our .js files to use the .mjs extension. However, Checkmarx still does not support scanning .mjs files. We reported this issue to them about a year ago, but even now it remains unsupported. The current suggestion is to rename .mjs files to .js when uploading code for Checkmarx scans, which is not a practical workaround for us.
What problems is the product solving and how is that benefiting you?
End-to-end security scanning for source code, including SAST and SCA scanning. It also supports API security scanning, IaC file scanning, and secret detection. Seamless integration with native CI/CD tools makes it easy to integrate Checkmarx into DevSecOps pipelines.
This reduces the Source Codes attack surface and by that we have achieved over 70%-80% of improvement in overall Code Security and our feature releases is now bullet proof from Security attacks
This reduces the Source Codes attack surface and by that we have achieved over 70%-80% of improvement in overall Code Security and our feature releases is now bullet proof from Security attacks
Arya S.
Comprehensive Application Security with Checkmarx
Reviewed on Jun 17, 2026
Review provided by G2
What do you like best about the product?
I like Checkmarx because it provides comprehensive application security, with accurate vulnerability detection, risk-based prioritization, and clear remediation recommendations.
What do you dislike about the product?
One area that could be improved is the number of false positives generated during scans, as this can add extra time to validation and triage. In addition, scans may take longer when running against large codebases.
What problems is the product solving and how is that benefiting you?
Checkmarx helps us address the challenge of identifying security vulnerabilities early in the software development lifecycle, before they reach production. It scans source code, open-source dependencies, APIs, and other application components to detect security risks and provide remediation guidance. For us, this reduces the likelihood of security incidents, supports compliance efforts, reinforces secure development practices, and helps development teams fix vulnerabilities faster without significantly slowing delivery timelines.
Program Development
Seamless Developer Workflow Integration for Real-Time Vulnerability Fixes
Reviewed on May 31, 2026
Review provided by G2
What do you like best about the product?
Checkmarx integrates directly into the developer workflow. By providing plugins for popular IDEs, CI/CD pipelines, and source code management (SCM) platforms, it allows developers to catch and fix vulnerabilities in real time without context-switching
What do you dislike about the product?
Running the application can strain local servers, and I note that the system requires substantial RAM and processing power to perform efficiently.
What problems is the product solving and how is that benefiting you?
Checkmarx solves the critical problem of vulnerabilities slipping into production code, which directly benefits me by reducing security risks and saving development time.
Information Technology and Services
Proactive Security and Smooth Cross-Team Collaboration
Reviewed on May 30, 2026
Review provided by G2
What do you like best about the product?
Its proactive approach to security.. I like how it enables you to collaborate with other teams.
What do you dislike about the product?
the only concern I had initially was the complexity the platform has a steep learning curve. and the Cost
What problems is the product solving and how is that benefiting you?
Protects customers data, and lowered remediation cost.
Amshu P.
Powerful for Security, But Needs UI Improvements
Reviewed on May 27, 2026
Review provided by G2
What do you like best about the product?
I like Checkmarx for its security testing at the application level. It's practical even though it wasn't really easy to use at first. I appreciate its security capabilities, easy navigation, and the reporting which works pretty well.
What do you dislike about the product?
It was really tough for me to use initially, felt kinda confusing but got used to it as I started working with it. UI could be better. Scans take a lot of time and I used to get false positives, which required so much energy ugh. I stopped using it because the cost was too high for my boss and he stopped paying for it. Tough, it took like, days for the team to properly set it up.
What problems is the product solving and how is that benefiting you?
Checkmarx helps with scanning code and addressing security issues, offering good security testing capabilities with easy navigation and solid reporting for our team.
Tadele L.
Essential for Secure Development, Accurate and Efficient
Reviewed on May 26, 2026
Review provided by G2
What do you like best about the product?
I like Checkmarx for its accurate vulnerability detection, easy CI/CD integration, and detailed remediation guidance that helps developers fix security issues quickly.
What do you dislike about the product?
Checkmarx could improve scan performance for large projects, reduce false positives, and provide a more user-friendly interface for easier navigation and reporting.
What problems is the product solving and how is that benefiting you?
Checkmarx helps us identify and fix application security vulnerabilities early in the development lifecycle, improve secure coding practices, and automate security testing within CI/CD pipelines.