What is SonarQube?
SonarQube is the leading tool for continuously inspecting the Code Quality & Security of your codebases and guiding development teams during Code Reviews. Covering 27 programming languages, while pairing-up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues and ultimately deliver better and safer software. With over 170k deployments helping small development teams as well as global organizations, SonarQube provides the means for all teams and companies around the world to own and impact their Code Quality.
Company Details
Need Assistance?
We're here to help you with understanding our reports and the data inside to help you make decisions.
Get AssistanceSonarQube Ratings
Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard
to access more information on SonarQube.
Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.
92 Likeliness to Recommend
100 Plan to Renew
84 Satisfaction of Cost Relative to Value
Emotional Footprint Overview
Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.
+94 Net Emotional Footprint
The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.
How much do users love SonarQube?
Pros
- Performance Enhancing
- Respectful
- Altruistic
- Transparent
How to read the Emotional Footprint
The Net Emotional Footprint measures high-level user sentiment towards particular product offerings. It aggregates emotional response ratings for various dimensions of the vendor-client relationship and product effectiveness, creating a powerful indicator of overall user feeling toward the vendor and product.
While purchasing decisions shouldn't be based on emotion, it's valuable to know what kind of emotional response the vendor you're considering elicits from their users.
Footprint
Negative
Neutral
Positive
Feature Ratings
SDLC Integration
Vulnerability Scanning
Policy Engine and Enforcements
Static Application Security Testing (SAST)
Software Composition Analysis (SCA)
Mobile Application Security Testing
Integrated Development Environment (IDE) plug-in
Dynamic Application Security Testing (DAST)
Risk Scoring
False Positive Remediation
Interactive Application Security Testing (IAST)
Vendor Capability Ratings
Business Value Created
Ease of Data Integration
Breadth of Features
Ease of Implementation
Ease of IT Administration
Availability and Quality of Training
Usability and Intuitiveness
Vendor Support
Quality of Features
Product Strategy and Rate of Improvement
Ease of Customization
SonarQube Reviews
Jeemish M.
- Role: Information Technology
- Industry: Technology
- Involvement: IT Leader or Manager
Submitted Jul 2023
Enterprise scale SAST scans at zero cost !!
Likeliness to Recommend
What differentiates SonarQube from other similar products?
Ease of implementation and support for most common technology stacks like java, Js, .net, python, groovy, etc for SAST scans
What is your favorite aspect of this product?
Minimalistic UI and multiple technology stack support
What do you dislike most about this product?
Requires a lot of manual setup and configuration for maintenance
What recommendations would you give to someone considering this product?
Must have for implementing automated SAST scans at enterprise scale
Pros
- Helps Innovate
- Reliable
- Performance Enhancing
- Respectful
Mujbur R.
- Role: Information Technology
- Industry: Technology
- Involvement: Business Leader or Manager
Submitted Jan 2026
Strong security features with a learning curve
Likeliness to Recommend
What differentiates SonarQube from other similar products?
SonarQube stands out because it focuses heavily on code quality and maintainability, not just security. It integrates easily into CI/CD pipelines and supports many languages, making it practical for everyday development.
What is your favorite aspect of this product?
My favorite aspect is how it gives quick, clear feedback on code quality and helps catch issues early during development.
What do you dislike most about this product?
dislike the amount of tuning needed to reduce false positives, especially in larger or older codebases.
What recommendations would you give to someone considering this product?
Start with a small project first, spend time tuning the rules, and integrate it early into your CI/CD pipeline to get the most value.
Pros
- Enables Productivity
- Efficient Service
- Effective Service
- Saves Time
Tammy B.
- Role: Information Technology
- Industry: Technology
- Involvement: End User of Application
Submitted Dec 2025
A reliable guardian for code quality
Likeliness to Recommend
What differentiates SonarQube from other similar products?
SonarQube makes security a shared responsibility instead of an afterthought. It reduces firefighting by preventing issues early. SonarQube stands out from other application security testing tools because it goes beyond basic vulnerability scanning and focuses deeply on overall code quality, maintainability, and long-term health.
What is your favorite aspect of this product?
It catches hidden bugs early, which saves time and reduces stressful last-minute fixes. The security vulnerability detection gives me confidence that our applications meet modern safety expectations. I appreciate how clearly SonarQube explains each issue and suggests practical, actionable fixes. The clean code principles encouraged by SonarQube genuinely improved how I write and review code.
What do you dislike most about this product?
Nothing negative has been seen yet. The platform encourages better developer habits without feeling overly restrictive. I find SonarQube especially valuable for onboarding new developers to our code standards. So I like everything about it.
What recommendations would you give to someone considering this product?
Using SonarQube will significantly reduce the number of security issues found during audits. I recommend spending time customizing quality profiles and rules to match your team’s real coding standards.
Pros
- Helps Innovate
- Continually Improving Product
- Reliable
- Performance Enhancing