• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. SonarQube
Logo of SonarQube

SonarQube

bySonarSource
in
4.3
Market Presence: Application Security Testing, Software Supply Chain Security

Overview

Product Information on SonarQube

Updated 6th April 2026

What is SonarQube?

SonarQube is an automated code review platform that checks your code for quality and security issues, available via cloud or on your own server. SonarQube is an independent review and verification layer to ensure all code—whether written by developers or generated by AI or AI agents—is secure, reliable, and maintainable. SonarQube automatically scans every code change, giving developers clear instructions and suggested fixes to resolve problems before they are merged into the main project. The experience starts in your editor with SonarQube for IDE, which works with both traditional and AI-native code editors, to highlight problems and suggest fixes. SonarQube also connects directly to your AI coding tools through an MCP server, giving AI assistants the data they need to understand your code's quality and security rules. Originally built by the open-source community, it is now used by over 7 million developers globally.

SonarQube Pricing

SonarQube Product Images

SonarQube portfolio view
SonarQube portfolio view
SonarQube security reports
SonarQube security reports
SonarQube dashboard
SonarQube dashboard

Overall experience with SonarQube

Chief Architect
30B + USD, Consumer Goods
FAVORABLE

“SonarQube Enables Transparent Software Quality Tracking and Customizable Coding Rules”

5.0
Oct 16, 2025
I set up and used SonarQube for several years in CI/CD pipelines to ensure software quality goals in my teams were clearly defined and met at each commit. The results of the scans were important for handover of software products between teams and different devops partners, as we had a very transparent state of the software quality.
Security Architect
10B - 30B USD, Media
CRITICAL

“SonarQube Integrates Security in Development but Lacks Depth for Complex Needs”

3.0
Mar 30, 2026
SonarQube is a solid foundational asset for our testing capability, making it easy to integrate basic security checks directly into development workflows. However, for organisations with more stringent security requirements or complex attack surfaces, it often serves as a beneficial first layer, rather than a comprehensive, standalone solution when compared to more specialised competitors. Its ease of adoption and developer-centric reporting were key factors in our decision to use it.

About Company

Company Description

Updated 3rd March 2026

Sonar is an automated code review platform serving as the trust and verification layer for AI code. Integrating code quality and code security into a single platform, Sonar delivers deterministic, repeatable, and actionable code verification at scale, analyzing over 750 billion lines of code daily to ensure software is reliable, maintainable, and secure. Originally built by the open-source community, it is now used by over 7 million developers globally.

Company Details

Updated 3rd March 2026
Year Founded
2008
Head office location
Geneva, Switzerland
Number of employees
501 - 1000
Website
https://sonarsource.com/

Do You Manage Peer Insights at SonarSource?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Reviewer Insights for: SonarQube
Deciding Factors: SonarQube Vs. Market Average
Performance of SonarQube Across Market Features

SonarQube Likes & Dislikes

Like

I like the capability to have various rulesets and be able to customize rules that are relevant to my specific domain. I liked the possibility to push these rules as settings for my developers IDE so that they had an early indication when coding rules were violated.

Like

I like its strong focus on developer experience and seamless integration into CI/CD pipelines. It ticks the box of shifting left by making security analysis an integral part of every commit, providing clear, actionable feedback directly to developers.

Like

- SonarQube PyCharm plug-in's code recommendations help to optimize code and make it more clean; - SonarQube server shows test coverage level on the new and overall code; - All found alerts and warnings could be assigned to the team members to remediate

Dislike

I have never achieved good results on C repos, however this may be due to inherent difficulties in analysing C/C code. Maintaining custom coding rules becomes tedious when there are a lot of changes in the underlying rulesets.

Dislike

For more advanced / nuanced security scenarios, its depth of analysis and true security focused findings can sometimes fall short compared to dedicated enterprise-grade SAST solutions. While it's excellent for code quality and many OWASP Top 10 items, we've found it occasionally misses more subtle or complex vulnerabilities, or generates a higher rate of false positives for certain security patterns.

Dislike

- the default settings provide a lot of unnecessary warnings and should be tweaked to have more sense; - it is hard to exclude or partially exclude files and code blocks from scan - it is slower than expected analyzing the large projects

Top SonarQube Alternatives

Logo of Veracode
1. Veracode
4.6
(419 Ratings)
Logo of Checkmarx SAST
2. Checkmarx SAST
4.6
(399 Ratings)
Logo of GitHub
3. GitHub
4.6
(277 Ratings)
View All Alternatives

Peer Discussions

SonarQube Reviews and Ratings

4.3

(113 Ratings)

Rating Distribution

5 Star
37%
4 Star
57%
3 Star
6%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.3

Integration & Deployment

4.6

Service & Support

4.4

Product Capabilities

4.5

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • Security Architect
    10B+ USD
    Media
    Review Source

    SonarQube Integrates Security in Development but Lacks Depth for Complex Needs

    3.0
    Mar 30, 2026
    SonarQube is a solid foundational asset for our testing capability, making it easy to integrate basic security checks directly into development workflows. However, for organisations with more stringent security requirements or complex attack surfaces, it often serves as a beneficial first layer, rather than a comprehensive, standalone solution when compared to more specialised competitors. Its ease of adoption and developer-centric reporting were key factors in our decision to use it.
  • Chief Architect
    10B+ USD
    Consumer Goods
    Review Source

    SonarQube Enables Transparent Software Quality Tracking and Customizable Coding Rules

    5.0
    Oct 16, 2025
    I set up and used SonarQube for several years in CI/CD pipelines to ensure software quality goals in my teams were clearly defined and met at each commit. The results of the scans were important for handover of software products between teams and different devops partners, as we had a very transparent state of the software quality.
  • IT OPS SPECIALIST
    10B+ USD
    Banking
    Review Source

    SonarQube Enhances Python Code Quality With Customizable Checks And Assignable Alerts

    4.0
    Oct 22, 2025
    SonarQube provides an additional layer of checks and optimizations during my Python development. It helps keeping my code clean and properly covered by the tests. Some checks could be annoying though, but they could be commented out in place or turned off at all
  • Director Enterprise Architecture
    50M-1B USD
    Banking
    Review Source

    SonarQube Enables Fast Issue Identification and Seamless Integration in Build Pipelines

    5.0
    Jul 8, 2025
    SonarQube is a true value-add for many organizations. Not only does it help identify various quality issues, it does it at speed in the build pipeline. Additionally, smart engineers will use the IDE extension to get feedback while the code is being written, without waiting on the CI/CD build to complete.
  • IT Manager
    10B+ USD
    IT Services
    Review Source

    Intuitive Dashboard for SAST and Seamless Azure DevOps Integration by SonarQube

    5.0
    Jul 4, 2025
    SonarQube seemed to be a very good tool for code coverage analysis and finding vulnerabilities in code. The dashboard gives a very good view of the analysis results. Pricing seemed to be optimal with respect to other vendors providing similar features. Open API of SonarQube is also very helpful for preparing custom reports.
...
Showing Result 1-5 of 113

Recommended Gartner Insights

  • Critical Capabilities for Application Security Testing
  • Magic Quadrant for Application Security Testing

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.