Skip to content
SocialAtoZ

Checkmarx

Verified

Application security testing across the whole software supply chain

Not yet rated. Be the first to review Checkmarx.

Checkmarx screenshot See all screenshots
  • Deployment Cloud Based, On Premise
  • Starting price Not published
  • Free trial Available
  • Best for Medium Business, Large Enterprise

What is Checkmarx?

Checkmarx provides application security testing spanning static analysis, software composition analysis, infrastructure as code and API security. It is one of the established enterprise names in this field and sells primarily to organisations with a dedicated application security function.

Breadth is the position rather than any single capability. A large organisation running four separate security tools has four sets of findings in four formats with four sets of false positives, and nobody able to say whether a given application is acceptable overall, which is the question an executive actually asks.

Consolidating those into one view is worth real money to a security team even where individual scanners are no better than specialised alternatives. Correlating a code vulnerability with a vulnerable dependency reaching the same function tells you which findings genuinely matter, which no single scanner can determine alone.

False positive rates are the metric that decides whether any tool in this category survives contact with developers. A scanner reporting problems that are not real trains engineers to ignore it within weeks, and once that habit forms the genuine findings are ignored alongside the noise, so accuracy matters more than coverage.

No pricing is published, which is standard at this end of the market where deployments are scoped by application count, scan volume and the modules taken.

Key Features of Checkmarx

  • Static application security testing
  • Software composition analysis
  • Infrastructure as code scanning
  • API security testing
  • Container scanning
  • Correlated findings across scanners
  • Developer remediation guidance
  • CI pipeline integration
  • Policy and compliance reporting
  • Application risk scoring

Checkmarx Pricing

Not published

Not published

No pricing is published. Scoped by application count, scan volume and modules taken.

Checkmarx Specifications

Deployment
  • Cloud Based
  • On Premise
Desktop
  • Web App
Built for
  • Medium Business
  • Large Enterprise
Support
  • Email
  • Knowledge Base
  • Phone
Public API
Yes
Free trial
Yes
Free plan
No
Runs in browser
No
Customisable
No
Website
checkmarx.com

Checkmarx Screenshots

Checkmarx Reviews

No reviews yet

Used Checkmarx? Share your experience and help other buyers decide.

Checkmarx FAQs

No pricing is published. Enterprise application security is scoped by application count, scan volume and the modules taken.

Four separate tools produce four sets of findings in four formats, and nobody can say whether an application is acceptable overall, which is the real question.

Knowing a code vulnerability and a vulnerable dependency reach the same function identifies which findings matter, which no single scanner can determine.

A scanner reporting unreal problems trains developers to ignore it within weeks, and the genuine findings are then ignored alongside the noise.

Organisations with a dedicated application security function, rather than teams looking for a tool individual developers adopt themselves.