
What is SonarQube?
SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.
Company Details
Need Assistance?
We're here to help you with understanding our reports and the data inside to help you make decisions.
Get AssistanceSonarQube Ratings
Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard
to access more information on SonarQube.
Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.
91 Likeliness to Recommend
100 Plan to Renew
84 Satisfaction of Cost Relative to Value
Emotional Footprint Overview
Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.
+93 Net Emotional Footprint
The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.
How much do users love SonarQube?
Pros
- Performance Enhancing
- Respectful
- Altruistic
- Transparent
How to read the Emotional Footprint
The Net Emotional Footprint measures high-level user sentiment towards particular product offerings. It aggregates emotional response ratings for various dimensions of the vendor-client relationship and product effectiveness, creating a powerful indicator of overall user feeling toward the vendor and product.
While purchasing decisions shouldn't be based on emotion, it's valuable to know what kind of emotional response the vendor you're considering elicits from their users.
Footprint
Negative
Neutral
Positive
Feature Ratings
Automated Workflow
Vulnerability Scanning
Mobile Application Security Testing
Software Composition Analysis (SCA)
Static Application Security Testing (SAST)
Policy Engine and Enforcements
Dynamic Application Security Testing (DAST)
Container Security Testing
Risk Scoring
False Positive Remediation
Integrated Development Environment (IDE) plug-in
Vendor Capability Ratings
Ease of Data Integration
Business Value Created
Breadth of Features
Ease of Implementation
Ease of IT Administration
Usability and Intuitiveness
Quality of Features
Availability and Quality of Training
Vendor Support
Product Strategy and Rate of Improvement
Ease of Customization
SonarQube Reviews

Chiesa B.
- Role: Information Technology
- Industry: Insurance
- Involvement: End User of Application
Submitted Mar 2025
My preferred tool for code quality analysis .
Likeliness to Recommend
What differentiates SonarQube from other similar products?
I love and appreciate that Sonarqube integrates with the CI/CD ( continuous integration and continuous deployment ) infrastructure on Gitlab. This comes with a whole lot of benefit when developing software , including helping to comply with best coding standards and practices, it also helps with facilitating collaboration between developers and reviewers in the process of developing software. Of importance is the early detection of security risks within the development process, even before code is passed into the repository.
What is your favorite aspect of this product?
Among the main strength of Sonarqube is its support for different programming languages. This makes Sonarqube the unified tool to use for the purpose of analyzing code quality, regardless of the programming language in which the code was written.
What do you dislike most about this product?
In situations where we have tried to reuse legacy codebases, we have noticed that Sonarqube easily gets overwhelmed by the inherent technical debt and problems which are common on legacy codebases. Of importance, is its tendency to generate a lot of false positives when working on Legacy codes.
What recommendations would you give to someone considering this product?
As far as enterprise level code management is concerned , I think Sonarqube is the tool I recommend because of its rule based analysis and its support for a variety of programming languages. It is important though, that it is setup and customized properly.
Pros
- Reliable
- Performance Enhancing
- Enables Productivity
- Security Protects
Please tell us why you think this review should be flagged.

Bharat L.
- Role: Operations
- Industry: Banking
- Involvement: IT Development, Integration, and Administration
Submitted Jun 2024
Ease your source code review work with SonarQube
Likeliness to Recommend
What differentiates SonarQube from other similar products?
the efficiency and the time taken by the product to give the results out, makes it unique and different from others
What is your favorite aspect of this product?
I love the CLI version, gives a good feeling while testing the source code
What do you dislike most about this product?
the process, first set it up offline and then with CLI and then results on the UI
What recommendations would you give to someone considering this product?
It is a good product, good for the developers, so that they can develop a good secured product
Pros
- Helps Innovate
- Continually Improving Product
- Trustworthy
- Unique Features
Please tell us why you think this review should be flagged.

Ramaseshan N.
- Role: Information Technology
- Industry: Engineering
- Involvement: Business Leader or Manager
Submitted May 2024
Great Product in the Market
Likeliness to Recommend
What differentiates SonarQube from other similar products?
Comprehensive Code Analysis: SonarQube offers a comprehensive set of static code analysis rules covering a wide range of programming languages, frameworks, and technologies. This extensive coverage ensures that developers can identify and address code quality issues, security vulnerabilities, and technical debt across their entire codebase. Customizable Quality Profiles: SonarQube allows users to define customizable quality profiles tailored to their specific project requirements, coding standards, and performance benchmarks.
What is your favorite aspect of this product?
One of my favorite aspects of SonarQube is its comprehensive and customizable code analysis capabilities. SonarQube offers a wide range of static code analysis rules covering various programming languages, frameworks, and technologies, allowing developers to identify and address code quality issues, security vulnerabilities, and technical debt effectively. I appreciate how SonarQube provides customizable quality profiles, enabling organizations to tailor code analysis rules to their specific project requirements and coding standards.
What do you dislike most about this product?
Complexity of Setup: Setting up SonarQube for the first time can be complex, especially for users who are new to the platform or lack experience with static code analysis tools. The process involves installing and configuring the SonarQube server, setting up analysis projects, configuring quality profiles, and integrating with CI/CD pipelines. Resource Requirements: SonarQube can be resource-intensive, particularly for large codebases or organizations with extensive project portfolios. Users may need to allocate sufficient hardware resources, such as CPU, memory, and storage, to ensure optimal performance and scalability.
What recommendations would you give to someone considering this product?
Assess Your Needs: Before implementing SonarQube, assess your organization's specific requirements and objectives for code quality management and static code analysis. Consider factors such as the size and complexity of your codebase, the programming languages and frameworks used, and the desired level of integration with CI/CD pipelines. Plan Your Implementation: Develop a clear plan for implementing SonarQube within your organization. Define your goals, scope, and timeline for deployment, and identify key stakeholders and team members who will be involved in the implementation process.
Pros
- Helps Innovate
- Continually Improving Product
- Reliable
- Performance Enhancing
Please tell us why you think this review should be flagged.
Get Instant Access<br>to this Report
Get Instant Access
to this Report
Unlock your first report with just a business email. Register to access our entire library.
© 2025 SoftwareReviews.com. All rights reserved.
