• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Coverity Static Application Security Testing
Logo of Coverity Static Application Security Testing

Coverity Static Application Security Testing

byBlack Duck
in Application Security Testing
4.4

Overview

Product Information on Coverity Static Application Security Testing

Updated 3rd June 2022

What is Coverity Static Application Security Testing?

Coverity® is a fast, accurate, and highly scalable static analysis (SAST) solution that helps development and security teams address security and quality defects in source code early in the software development life cycle (SDLC), track and manage risks across the application portfolio, and ensure compliance with security and coding standards, including: OWASP Top 10, CWE Top 25, PCI DSS, MISRA®, CERT C/C++, CERT Java, DISA STIG, ISO 26262, ISO/IEC TS 17961, and AUTOSAR®. Coverity provides a broad set of security and quality checkers for over 20 languages and 70 frameworks, as well as commonly used infrastructure-as-code (IaC) platforms and file formats. Coverity supports both cloud and on-premises deployment. It supports automated scanning with a wide range of continuous integration (CI) and source code management (SCM) platforms. In addition, static analysis can be performed at the developer desktop when Coverity is used on conjunction with the Code Sight IDE plug-in.

Coverity Static Application Security Testing Pricing

Annual contract based on team size and number of code bases analyzed by the product.

Coverity Static Application Security Testing Product Images

Coverity_Screen_Shot
Coverity_Screen_Shot

Overall experience with Coverity Static Application Security Testing

SECURITY & RISK MANAGEMENT
500M - 1B USD, Telecommunication
FAVORABLE

“Coverity Simplifies Code Security for Industry Standards but UI Presents Challenges”

5.0
Jun 26, 2025
As a well-known source code quality and security detector, Coverity supports individual standards and customized rules. The product supports rapid analysis of source code submissions, which helps the engineer a lot. Coverity's reputation is extremely outstanding, as customers know we pick Coverity as SAST solution, the doubts sharpens down and trust grows up. It also complements with Black Duck, to provide a detailed analysis for end-to-end security detection.
Security Architect
50M - 250M USD, Software
CRITICAL

“Navigating the Limited Market of Firmware Support Tools”

3.0
May 29, 2024
There are only 3 products in the market that support firmware code and this is one of them. I rated it average because it's not truly exceptional or outstanding. This product is similar to other tools. I'm not feeling very generous so 3 stars is still a thumbs-up.

About Company

Company Description

Updated 17th February 2025

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it; development and DevSecOps teams to automate testing within development pipelines without compromising velocity; and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Company Details

Updated 26th February 2025
Year Founded
2002
Head office location
Burlington, United States
Number of employees
1001 - 5000
Website
https://blackduck.com

Do You Manage Peer Insights at Black Duck?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Reviewer Insights for: Coverity Static Application Security Testing
Performance of Coverity Static Application Security Testing Across Market Features

Coverity Static Application Security Testing Likes & Dislikes

Like

The initial set of security rules. When we demonstrate our security capabilities and exercise, especially for customers in specific industries like auto and health, we say weve used Coverity to check if the source code meets MISRA or HIPAA, customers know our effort very quickly, and theres no more negotiation cost. That is what a great product needs, which helps the whole industry to reach an agreement very soon.

Like

Support is good.

Like

Ease of use Low amount of false positives Integration capabilities

Dislike

The user interface, Coverity's UI is not easy to understand, and the users need some time to get to know this platform. It shall ref the popular consumer products, release a modern version to make the tool easy to use, and up to date. Currently the UX does not match the high reputation it grants.

Dislike

UI and False positives. Vendor offers triaging service for extra cost.

Dislike

The interface of coverity looks really old

Top Coverity Static Application Security Testing Alternatives

Logo of Veracode
1. Veracode
4.6
(401 Ratings)
Logo of Checkmarx SAST
2. Checkmarx SAST
4.6
(398 Ratings)
Logo of Appknox
3. Appknox
4.8
(246 Ratings)
View All Alternatives

Peer Discussions

Coverity Static Application Security Testing Reviews and Ratings

4.4

(155 Ratings)

Rating Distribution

5 Star
52%
4 Star
41%
3 Star
5%
2 Star
1%
1 Star
1%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.4

Integration & Deployment

4.3

Service & Support

4.5

Product Capabilities

4.5

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • SECURITY & RISK MANAGEMENT
    50M-1B USD
    Telecommunication
    Review Source

    Coverity Simplifies Code Security for Industry Standards but UI Presents Challenges

    5.0
    Jun 26, 2025
    As a well-known source code quality and security detector, Coverity supports individual standards and customized rules. The product supports rapid analysis of source code submissions, which helps the engineer a lot. Coverity's reputation is extremely outstanding, as customers know we pick Coverity as SAST solution, the doubts sharpens down and trust grows up. It also complements with Black Duck, to provide a detailed analysis for end-to-end security detection.
  • IT SECURITY & RISK MANAGEMENT ASSOCIATE
    50M-1B USD
    Banking
    Review Source

    Ease of Use and Low False Positives: The Highlight of Coverity

    4.0
    Aug 1, 2024
    Low amount of false positives, ease to use and you can integrate it directly with most of CI/CDs
  • Security Architect
    50M-1B USD
    Software
    Review Source

    Navigating the Limited Market of Firmware Support Tools

    3.0
    May 29, 2024
    There are only 3 products in the market that support firmware code and this is one of them. I rated it average because it's not truly exceptional or outstanding. This product is similar to other tools. I'm not feeling very generous so 3 stars is still a thumbs-up.
  • Subject matter expert
    50M-1B USD
    Software
    Review Source

    Could provide more help in terms of risk management and development mitigations.

    2.0
    Dec 11, 2023
    These are the main drawbacks I've seen: 1) The web interface does not allow you to change the default security risk level associated with the vulnerability. It's quite annoying having to write the modified risk level in the description because then you cannot search for them later. 2) It lacks of a proposed solution. I think it needs to provide at least a generic solution or a curated list of references according to the programming language in which the vulnerability was found. 3) It would nice if they improve their search filters. There are a lot of filters/conditions for searching and would be helpful if you could save previously used search filters.
  • Senior Test Specialist
    10B+ USD
    Telecommunication
    Review Source

    Synopsys Coverity Review

    4.0
    Dec 4, 2023
    We have been using Synopsys Coverity for Fuzz testing on various supported interfaces to check for any vulnerabilities and fix them. The GUI interface is easy to navigate with help section documents for support.
...
Showing Result 1-5 of 155

Recommended Gartner Research

  • Critical Capabilities for Application Security Testing
  • Magic Quadrant for Application Security Testing

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.