
Calificación general
Filtrar
Tamaño de la empresa
Tiempo usado
52 opiniones
- Sector: Software informático
- Tamaño de la empresa: 5.001-10.000 empleados
- Software usado Semanalmente durante Más de un año
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 7.0 /10
Manten código de calidad gracias a SonarQube
Revisado el 9/8/2023
Puntos a favor
Me gusta mucho la integración con el servicio de devops de azure, gracias a ello puedo integrar las tareas de revisión de código de SonartiQube en la integración continua. Los reportes que genera son de gran utilidad para detectar malas prácticas o brechas de seguridad en el código.
Desventajas
Me gustaría que el panel de administración de la herramienta fuera más configurable, para poder hacer que el análisis de código sea más efectivo.

- Sector: Software informático
- Tamaño de la empresa: 10.000+ empleados
- Software usado A diario durante 6-12 meses
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 9.0 /10
Code Analysis and ensuing security against threats
Revisado el 23/5/2022
Overall experience with Sonarqube is pretty wholesome integration came handy with my CI/CD tools...
Overall experience with Sonarqube is pretty wholesome integration came handy with my CI/CD tools such as Azure Devops and Jenkins. Provides insights against vulnerabilities and common threats so that necessary actions can be taken by developers to ensure the security and good coding practices to follow. Features like PR decoration allows to get results in CI/CD tools itself if passed then only commit happens to master branch.
Puntos a favor
Feature like Code Analysis and publishing those analysis report to end user. You can use default Quality Gates and Quality Profiles for scanning of your code. In case you want to modify these you can do that and define your own rule. Whenever there's commit in repo you just need to configure the task in your continuous integration pipeline if it passed the parameter only then commit will happens the master/main branch otherwise it will not. With these features you can eliminate the security threats and ensure that developers are following good practices while developing their code. I have integrated it with Azure DevOps.
Desventajas
Only thing which I can think can be improved is logging of events. Sometime it becomes hard to debug the issues. Other then that, I think over all this fulfills all the requirements.
- Sector: Tecnología y servicios de la información
- Tamaño de la empresa: 501-1.000 empleados
- Software usado A diario durante Más de un año
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 9.0 /10
Best Code Quality check Tool
Revisado el 25/8/2022
We are really taking help of SonarQUbe in maintaining code quality. Doing code scanning on each ...
We are really taking help of SonarQUbe in maintaining code quality. Doing code scanning on each JIRA story completion. It also helps our developers to improve their code quality. Coding standards are better now. Reports are very useful.
Puntos a favor
1. Calculate the quality of code and also helps to improve the quality by providing the solution
2. Highlight the vulnerabilities , repetitive line of code
3. Developer Friendly tool as it provides recommendations on the line of code which needs an improvement.
4. Create Scan reports on demand
5. Option to add exception in code
Desventajas
1. Report Generation sometime take long time.
2. User Interface should be enhanced.
3. Lack custom rule set
4. As per cost, it is little bit expensive.
Alternativas consideradas
CodeScanRazones para elegir SonarQube
SOnarQube is better in terms of quality percentage, provide more insights.- Sector: Software informático
- Tamaño de la empresa: 1.001-5.000 empleados
- Software usado Semanalmente durante Más de un año
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 10.0 /10
Popular tool for code smell search in the organisation's repositories
Revisado el 8/8/2023
Puntos a favor
Easy-to-administer tool, with good functionality to monitor security part of your code (using SAST methodology), with ability to integrate with Jenkins, GitHub and other tools. You are able to fail the build if the code doesn't meet percentage score.
Desventajas
When new repository is added - there should be pop-up suggestion to create SonarQube project for it, coming from SonarQube. At the moment the user/administrator must watch out for new repositories in the organisation, without a note from the system itself that there is a new repository which you might want to add for scanning.
- Sector: Hospital y atención sanitaria
- Tamaño de la empresa: 501-1.000 empleados
- Software usado A diario durante 6-12 meses
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 7.0 /10
Great tool to drive Coding Quality standards
Revisado el 12/8/2021
PR analysis and Integration with Bitbucket are most in avoiding the new issues.
The tool needs a...
PR analysis and Integration with Bitbucket are most in avoiding the new issues.
The tool needs a lot of improvements
1. Number of rules should be increased.
2. Few rules should have custom exclusions. Ex: Naming conventions => Organisation-specific words will be there which should be in Capital.
3. Generating a lot of false positives
4. Executive reports should generate based on scheduled triggers. We have 20 projects which are assigned to a Portfolio. if you are going to generate a report and send an email for the first portfolio calculation then the rest of the 19 projects info for that day will be missed. Higher management will think that the generated report is the latest but it is not.
5. PR analysis reports should be generated Quickly
Puntos a favor
PR analysis and Integration with Bitbucket are most helpful.
Desventajas
1. Number of rules should be increased.
2. Few rules should have custom exclusions. Ex: Naming conventions => Organisation-specific words will be there which should be in Capital.
3. Generating a lot of false positives
4. Executive reports should generate based on scheduled triggers. We have 20 projects which are assigned to a Portfolio. if you are going to generate a report and send an email for the first portfolio calculation then the rest of the 19 projects info for that day will be missed. Higher management will think that the generated report is the latest but it is not.
5. PR analysis reports should be generated Quickly
Respuesta de SonarSource
Thank you for your review, Chandramouli. We appreciate your feedback, and invite you to join the SonarSource Community Forum.
SonarSource Community Forum: https://community.sonarsource.com/
Posting to the Forum will allow there to be transparency to the community, and allow our product managers & users to understand any issues you are facing.
To better assist you, please indicate what language(s), and how long the PR analysis is actually taking; as well as, examples of the false positives.
Thanks!
- Sector: Aerolíneas/aviación
- Tamaño de la empresa: 201-500 empleados
- Software usado A diario durante 6-12 meses
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 8.0 /10
Great product!
Revisado el 11/7/2023
Puntos a favor
This product has actually improved productivity within my team by making sure there’s no duplicate code and by making code easily understandable.
Desventajas
Code maintenance is actually a difficult part.
- Sector: Educación superior
- Tamaño de la empresa: 1.001-5.000 empleados
- Software usado Mensualmente durante 6-12 meses
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 8.0 /10
SonarQube is Great for Developers!
Revisado el 23/12/2022
We could identify many code related issues that are presented in our code and improve the quality...
We could identify many code related issues that are presented in our code and improve the quality of the application that we are developing. As a overall, SonarQube tool is able to add a value to our applications.
Puntos a favor
It is simple for developers to recognize their code smells, unused lines of code, errors, problems with the third-party libraries they are using, etc. information and the precise location of the issue. It also offers answers to those problems. As a result, figuring out the problems and fixing them is simple. This will be a terrific tool for developers. Except that, we can introduce our own rules for checking the code quality. It could identify the code issues that are vulnerable to cyber attacks such as XSS, SQL Injection, etc.
Desventajas
It was difficult to use the SonarQube on-premise application. Once we pushed a new code section, the server needed to restart in order for the application to work.
Alternativas consideradas
GitGuardianRazones para cambiar a SonarQube
Higher number of facilities are available in SonarQube and suggesting the options for fixing the issues.- Sector: Tecnología y servicios de la información
- Tamaño de la empresa: Trabajador autónomo
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Probabilidad de recomendación 10.0 /10
Measure the quality of your software
Revisado el 24/12/2022
Puntos a favor
I like sonarqube dashboard and the flexibility that quality gates provide to measure your software quality. You can set up you own thresholds for maintenance, reliability, security, code coverage and many other metrics, and allow only versions passing this quality gate to be deployed.
Desventajas
Unfortunately it lacks an easy way to see trends and go deep into which developers are the best/the worst. Also, it is paid if you need to analyse software in some languages, available only on the cloud.
Software anterior
CAST Highlight- Sector: Banca
- Tamaño de la empresa: 51-200 empleados
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Facilidad de uso
- Probabilidad de recomendación 8.0 /10
Sonarqube essential code quality analysis tool
Revisado el 12/3/2023
In short, it is an indispensable tool and should be mandatory in all software development companies.
In short, it is an indispensable tool and should be mandatory in all software development companies.
Puntos a favor
The ability to analyze the quality of the code in each deployment or integration, together with the possibility of modifying the rules to allow deployment or not (quantity or criticality of errors or defects), as well as vulnerability analysis allows for better software, always keeping in mind of the developers the quality and security of the code.
Desventajas
Like everything, the time it takes to leave it well configured and integrated with the rest of the systems, as well as the maintenance and updating of the standards, rules and vulnerabilities depending on the programming language and the news that are published at the level of security.

- Sector: Servicios jurídicos
- Tamaño de la empresa: 501-1.000 empleados
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 10.0 /10
Developer friendly SAST
Revisado el 7/12/2022
Puntos a favor
We really like the IDE tool called SonarLint which makes it easy for developers to integrate with most IDEs and lint their code even before committing it to the repos. Another advantage was that we were able to self host our own instance on our Kubernetes cluster and keep the versions based on the containers we specify to pull.
Desventajas
Other engines tend to scan the same code base faster. Not too much of a con since this is all automated.
Alternativas consideradas
Snyk- Sector: Software informático
- Tamaño de la empresa: 11-50 empleados
- Software usado A diario durante Más de un año
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 10.0 /10
A free tool for source code analysis
Revisado el 10/4/2023
It helped me to be able to do my job in improving the code, giving me possible solutions and saving...
It helped me to be able to do my job in improving the code, giving me possible solutions and saving me time.
Puntos a favor
What I find most useful in this software is the code analysis, which gives detailed reports of the errors found and then suggests possible solutions. This saves time in software development.In addition, their large community helps solve problems that arise along the way.
Desventajas
Sometimes the reports can give false positives, which requires that the personnel in charge of handling the software carefully review the results to avoid false positives.
- Sector: Software informático
- Tamaño de la empresa: 201-500 empleados
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 10.0 /10
SonarQube l'outil a avoir
Revisado el 18/2/2023
J'ai utilisé Sonarqube que ce soit avec l'invite de commande de faire une analyse du code avant de...
J'ai utilisé Sonarqube que ce soit avec l'invite de commande de faire une analyse du code avant de le pousser. et aussi la création du pipeline de compilation.
Puntos a favor
il s'intègre dans le pipeline de compilation
Desventajas
L'analyse du code prend du temps et parfois, il y a des recommandations qu'on ne peut pas corriger
- Sector: Tecnología y servicios de la información
- Tamaño de la empresa: 1.001-5.000 empleados
- Software usado Semanalmente durante Más de dos años
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Probabilidad de recomendación 10.0 /10
The least you can do for software quality
Revisado el 30/11/2022
Puntos a favor
Sonarqube allows anyone to run a scan for code smells, bugs or vulnerabilities. There is no reason not to use it or integrate it into your CI/CD pipelines. Even if you do not enforce passing the quality gate, it helps a lot in tracking and highlighting where are your weaknesses. Code duplication and Code coverage are very useful tools to understand the overall quality of your development.
Desventajas
It is hard to view historic data, and once you run a new analysis you cannot see the previous ones anymore from the same unified dashboard, you have to enter into each metric and check the history link. Please bring back the history dashboard from sonar 5!
- Sector: Software informático
- Tamaño de la empresa: 10.000+ empleados
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Facilidad de uso
- Probabilidad de recomendación 9.0 /10
Excellent code assurance tool
Revisado el 15/1/2023
It's a great tool and be understood by experienced people more easily.
It's a great tool and be understood by experienced people more easily.
Puntos a favor
Sonarqube helps me find out if there are any repetitive lines in my code. Since the code sometimes get lengthy or at times missed by me to recheck. It is added in continuous integration in jenkins which when runs code smells, coverage and quality will be detected.
Desventajas
At times we need to precisely set all the settings for the issues to be detected. If any small mistake happens then no result can be seen. We use traditional sonarqube where we install and integrate rather then plugin in jenkins. So the traditional method needs to be more careful in installing and running it.
- Sector: Propiedad inmobiliaria
- Tamaño de la empresa: 201-500 empleados
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 6.0 /10
Review
Revisado el 16/8/2021
It have been a mixed ride overall. The actualy code analysis is really great, the rest is so so.
It have been a mixed ride overall. The actualy code analysis is really great, the rest is so so.
Puntos a favor
The amount of errors it catches and that developers code look somewhat similar in mindset after using it for some time.
Desventajas
The setup with CodeCoverage is a nightmare and it seems is not working equallty well all the time. We also have a solution where it doesn't even work.
Respuesta de SonarSource
Hi Daniel. Thank you for your review of SonarQube. We appreciate your feedback! Regarding your code coverage issues, have you checked out our Community Forum? There may be a solution/fix already identified and if not, you can easily start a new thread and provide us with the details around your workflow, language(s), etc. Thanks!
Community Forum: https://community.sonarsource.com/
- Sector: Tecnología y servicios de la información
- Tamaño de la empresa: 10.000+ empleados
- Software usado A diario durante 6-12 meses
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 7.0 /10
Staple in the CI/CD pipelined quality gate solutions
Revisado el 11/12/2022
It allows our dev teams to keep consistent level of code quality and known issues proof in code and...
It allows our dev teams to keep consistent level of code quality and known issues proof in code and used target platforms so as to provide to end users/customers highest quality products delivered in CI/CD methodology.
Puntos a favor
Easily add source code analysis for potential bugs and pitfalls to warrant against developers' errors or just not efficient coding by novices, projects dependencies on vulnerable platforms and potential long-term support issues due to how your code is structured. Simple deployment of binaries needed for scans for major target build environments OSes, plus easy to use APIs, all for the benefit of easy integration into CI/CD pipelines.
Desventajas
Caps and limits on key server instance component required when obtaining config for project and preset rules, when sending analysis results or getting quality gate results may make the pipelines seem to fail without easier discerning real reasons.
- Sector: Automoción
- Tamaño de la empresa: 10.000+ empleados
- Software usado A diario durante 6-12 meses
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 8.0 /10
Sonarqube a static code analysis for quality and security of the code
Revisado el 17/7/2022
We have been using sonarqube in our cicd pipeline for static code analysis and its been very...
We have been using sonarqube in our cicd pipeline for static code analysis and its been very helpful identifying the bugs early in the stages. This tool is best in the market but still missing on some functionalities, mainly in dashboards.
Puntos a favor
1. Ensures that only quality, bugfree and vulnerabilities free code goes into production and improves developer’s skills.
2. Supports 24+ languages.
3. Open source version.
4. Developer workflow integration
5. Detect the bugs early in development and send alerts to developers to have a look into suspicious code snippets.
6. The results are faster and can get integrated within pipeline.
Desventajas
1. Integration with the third party apps could be improved.
2. Dashboards could be better and code security features can be added more.
3. Sometimes false positive results
- Sector: Tecnología y servicios de la información
- Tamaño de la empresa: 5.001-10.000 empleados
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 8.0 /10
SonarQube Usage review
Revisado el 8/4/2021
Cheap and good for Code Vulnerability scans.
Cheap and good for Code Vulnerability scans.
Puntos a favor
The vulnerability scans that it uses encompasses a lot of languages. It also has ability where user can define custom profiles and rules. Dashboards created are easy to use and decipher.
Desventajas
Technical support is very expensive and need to use their community forums to get support.
Respuesta de SonarSource
Thank you for your review, kiruthiga!
- Sector: Tecnología y servicios de la información
- Tamaño de la empresa: 51-200 empleados
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 8.0 /10
Keeps ur code intact with less grammar mistake
Revisado el 24/1/2022
Puntos a favor
it allows us to correct the grammatically wrong code , unused imports ,variables etc. It Helps us to optimize the code with the rules specified for that project. Allows us to remove the duplicate code as well.
Desventajas
Integration with visual studio code and binding with project is tad difficult . Duplicate code block appears only after the build , so we have to wait till the build is completed to view whether any duplicate is present in our code.
- Sector: Tecnología y servicios de la información
- Tamaño de la empresa: 10.000+ empleados
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 10.0 /10
Great tool to drive Coding Quality standards
Revisado el 11/7/2021
Driving code quality standards across enterprise and inducing code quality gates in the continuous...
Driving code quality standards across enterprise and inducing code quality gates in the continuous integration workflow
Puntos a favor
Static code analysis, support for Java, .Net, JavaScript, typescript, html, CSS, etc. Helps you set custom quality gates and rules as well
Desventajas
Community version does not support high availability. You need to pay for this feature, would have preferred it to be free. Tools upgrade process can be improved as we have to take down the tool instance.
Respuesta de SonarSource
Thank you for your review!

- Sector: Software informático
- Tamaño de la empresa: 201-500 empleados
- Software usado Semanalmente durante 6-12 meses
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 10.0 /10
Loved using SonarQube!!!
Revisado el 27/4/2022
We primarily need to perform some static analyses. Everyone sends a pool request while they're...
We primarily need to perform some static analyses. Everyone sends a pool request while they're coding. We must guarantee that the code is up to date before committing it to the main branch. That's basically how we work to make sure that whatever rules we've set up, whatever gates we've set up, are followed before we commit the code to the main branch. I had a lot of fun with the powerful tool.
Puntos a favor
The way it evaluates all of the code generated and reports on any violations of standard coding help us optimize the written code, ensuring that the smallest number of lines are created to properly cover the functionality. It offers a lovely user interface with distinct groups of infractions ranging from small to large, and it involves fixing the code's needless complexity. It also aids in the removal of duplicate code that has been used several times and the upkeep of method standards.
Desventajas
Integrating Sonarqube into CI/CD Pipelines takes time, and it may take even longer if the developer is newer. More real-time solutions could be included in the available guide, making it easier to handle issues and complete the integration.
- Sector: Telecomunicaciones
- Tamaño de la empresa: 10.000+ empleados
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Relación calidad-precio
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 8.0 /10
A great tool to improve Code Quality
Revisado el 28/4/2022
Tool really fulfills our needs on code quality improvements and security perspectives.
Tool really fulfills our needs on code quality improvements and security perspectives.
Puntos a favor
First of all, The tool has a great user interface highlighting all of the errors and bugs. It also shows how much effort is needed to fix those as well. We integrated it with our CI/CD pipelines in GitLab.
Desventajas
Enterprise licensing cost is a bit expensive. We faced rarely memory issues running the CI/CD pipelines.
- Sector: Software informático
- Tamaño de la empresa: 51-200 empleados
- Software usado A diario durante 6-12 meses
-
Fuente de la reseña
Calificación general
- Facilidad de uso
- Probabilidad de recomendación 9.0 /10
powerful code quality tool
Revisado el 23/2/2023
Puntos a favor
SonarQube can integrate with CI/CD tools such as Jenkins, GitLab, and Travis CI, making it easy to automate code analysis as part of the development process. SonarQube allows developers to customize the rules and profiles used for code analysis.SonarQube provides a dashboard and reporting features that allow developers to track the progress of code quality metrics and identify areas that require attention. This feature can help developers stay on top of code quality issues and make data-driven decisions about where to focus their efforts.
Desventajas
Improving documentation could help users better understand how to use the tool effectively.
- Sector: Software informático
- Tamaño de la empresa: 1.001-5.000 empleados
- Software usado A diario durante Más de un año
-
Fuente de la reseña
Calificación general
- Facilidad de uso
- Probabilidad de recomendación 8.0 /10
Check your developers code quality
Revisado el 4/8/2022
Great experience I loved it. It will track all the lines in code and gives us the quality report...
Great experience I loved it. It will track all the lines in code and gives us the quality report according to rule set.
Puntos a favor
Great tool to check the code quality like unit test cases, number of repetitive lines and other checks for coments and other. This helps us to set the rules which should be followed by the developer which maintains the consistency of the software for customers.
Desventajas
I don't have any much cons on this. But we need little good knowledge to handle this. It is little tricky to manage the application.

- Sector: Telecomunicaciones
- Tamaño de la empresa: 10.000+ empleados
- Software usado A diario durante Más de dos años
-
Fuente de la reseña
Calificación general
- Facilidad de uso
- Asistencia al cliente
- Probabilidad de recomendación 10.0 /10
The best bugs exterminator
Revisado el 29/5/2022
We can't live anymore without Sonarqube. When we started using it 5 years ago, the teams adoption...
We can't live anymore without Sonarqube. When we started using it 5 years ago, the teams adoption was very fast.
Puntos a favor
Code review could be more focused on the new features implementation than trying to identify silly basic faults.
Desventajas
The Eclipse Sonarqube plugin was not easy to make it work in the same manner was it was setup in the CI/CD machines.