CxSAST
About CxSAST

Most Helpful Reviews for CxSAST
7 Reviews
Daniel
Verified reviewer
Hospital & Health Care, 10,000+ employees
Used daily for more than 2 years
OVERALL RATING:
5
EASE OF USE
5
FUNCTIONALITY
5
Reviewed January 2023
Gives a full 360 degree view of vulnerabilities in static code
My personal overall experience with SAST is positive. I like that I can tweak queries myself and if there is something I can't do, support is just a phone call/ticket away. They respond to all inquiries very quickly.
PROSThe ability to use CI/CD pipelines so when the build task kicks off, scanning for static code and open source libraries is done at build time.
CONSThe only thing I do not like is we have some languages that the product does not support like ColdFusion and R-Code.
Tiennot
Computer & Network Security, 11-50 employees
Used daily for more than 2 years
OVERALL RATING:
5
EASE OF USE
4
VALUE FOR MONEY
4
CUSTOMER SUPPORT
5
FUNCTIONALITY
5
Reviewed January 2021
CxSAST - A great static software analyzer
CXSast has several very important advantages. The first is that the code is scanned before it is even compiled, this means that de developers can scan and fix while they are still in the coding process. Second CXSAST fully integrates in any devops proces. Scanning and reporting will be doen from within the screens developers work in, so no unneccesary switching between screens. (see extention CXflow) Nex to that the rules (or queries) are open, every one can see them or a organisation can tailor them to their own need. If needed a FP free setup can be created! V9.3 now enable installation of the engines on Linux, you can dockarize the stuff Last but not least CXSast can be setup with additions such as CX-SCA (opensource analysis) and CX-IAST (passive IAST scanning)
CONSThe installation can sometimes be difficult. However Checkmarx counters this by offering free installation services for their costumers.
Donovan
Financial Services, 51-200 employees
Used daily for less than 12 months
OVERALL RATING:
1
EASE OF USE
1
VALUE FOR MONEY
1
CUSTOMER SUPPORT
2
FUNCTIONALITY
4
Reviewed March 2022
Super expensive but also feels outdated
Overall I did not enjoy using it.
PROSIt certainly covers all the vulnerability rules you would ever need.
CONSIt is SUPER expensive, very slow and the reporting is too messy. It would have been better if it can take a more integrated into the code approach like Sonar.
Juan
Banking, 1,001-5,000 employees
Used daily for more than 2 years
OVERALL RATING:
4
EASE OF USE
4
VALUE FOR MONEY
4
CUSTOMER SUPPORT
5
FUNCTIONALITY
4
Reviewed November 2021
Checkmarx a strong and reliable competitor
It has been a good experience, the support is fast and reliable. The tool work as expected and you can use the api integration to go even further.
PROSEasy of use, the 0 complexity it adds to configure a new project, it feels to work in a collaborative way even in an on premise environment.
CONSThe implementation requires Windows and SQL, i would prefer that it runs on linux with postgresql. The reporting could be improved.
Reason for choosing CxSAST
We needed an on premise solution (veracode is 100% Cloud), and an easy y quick way to configure projects Fortify is a little bit complex, and depend on the language to be scanned
Reasons for switching to CxSAST
AppScan didn't have that native integration to SecDevOps environments
Shreyans
Verified reviewer
Banking, 10,000+ employees
Used weekly for more than 2 years
OVERALL RATING:
4
EASE OF USE
4
FUNCTIONALITY
4
Reviewed November 2022
Preferred Vulnerability Management Tool
Can be used to analyse application, source code, byte code, and binaries for coding and design conditions.Key elements of the checkmarx dashboard can be split into two sections, namely scan, statistics and scan trends.
CONSUnavailable or downtime of application causes delay in deploying the code through pipeline which is integrated with Checkmarx.
Sarai
Verified reviewer
Publishing, 1,001-5,000 employees
Used daily for less than 6 months
OVERALL RATING:
5
EASE OF USE
5
FUNCTIONALITY
5
Reviewed April 2021
Intuitive software
Finding code vulnerabilities is hard. CxSAST makes it easy. Not only does it point out the vulnerability, it explains why the code is vulnerable, which is very valuable for future proofing code.
CONSCan sometimes include false positives. However this is mitigated by selecting “proposed not exploitable” if necessary.
Jayesh
Leisure, Travel & Tourism, 501-1,000 employees
Used monthly for less than 12 months
OVERALL RATING:
3
EASE OF USE
3
VALUE FOR MONEY
3
FUNCTIONALITY
3
Reviewed August 2019
Its on OK Product
We use this tool to check security vulnerabilities Option to configure multiple projects Compare the results between two scans Download the report results
CONSNot very User-Friendly. Takes time to run the scan Difficult to configure with development studios.