SonarQube Reviews

Overall rating
Filter by
Company size
Time used
64 Reviews

- Industry: Music
- Company size: 2–10 Employees
- Used Weekly for Free Trial
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 8.0 /10
Essential tool to guarantee quality and safety
Reviewed on 2023/07/18
As a developer, it has been an invaluable tool in improving the quality and security of my code. It...
As a developer, it has been an invaluable tool in improving the quality and security of my code. It has helped me proactively identify and address issues, allowing me to run cleaner, less bug-prone software.
Pros
I love its ability to provide a clear and concise view of code quality.
Cons
At first, I found it a bit overwhelming to understand all the available features and settings. Although the documentation and support help, I think there could be a better guide for new users.
- Industry: Telecommunications
- Company size: 1,001–5,000 Employees
- Used Daily for 2+ years
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 9.0 /10
Well defined by consistency and high operability
Reviewed on 2024/05/14
Brings quality and professionalism in the final results. It is an impressive tool.
Brings quality and professionalism in the final results. It is an impressive tool.
Pros
One of the outstanding values about SonarQube is the speed of analysis. It makes it easy to collaborate with other features to generate clean codes. I and my team had an easy time during deployment. It was quite easy to relate with our needs. Combining all this benefits leads to a consistent and reliable coding behavior.
Cons
Installation of the tool was troublesome. We were forced to buy a new device with higher processing speed to avoid the numerous rebooting. Later, deployment and use was smooth.
- Industry: Accounting
- Company size: 501–1,000 Employees
- Used Weekly for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 7.0 /10
Perfect for detecting unit test coverage
Reviewed on 2025/02/28
Pros
SonarQube is good at enforcing minimum code coverage on PRs
Cons
It is really difficult to run it locally, however once set up on github it runs well, and provides valuable insights on code coverage.
- Industry: Computer & Network Security
- Company size: 11–50 Employees
- Used Monthly for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 0.0 /10
Never use SonarQube
Reviewed on 2025/02/13
This service is a complete scam. Let's start with how it ended. I canceled my account, only to find...
This service is a complete scam. Let's start with how it ended. I canceled my account, only to find out that it did not actually cancel. So I contacted support. It took them 2 months to resolve my request and they continued billing my card when the account was 100% not in use and I had no access to it. Now they refuse to refund my money. This is after they increased the cost of my plan by 3x without my approval (which is what prompted me to want to leave). In order to try to reduce my cost, our engineering team attempted to discsonnect some unused repos... nope, not possible.
NEVER use this service. You absolutely cannot trust them. It's unbelievable that their system cannot be canceled and yet somehow it's my fault and I continue to get billed while their support team takes weeks to respond.
Pros
There is nothing about this company that I would ever recommend.
Cons
Of all the terrible things about this service and company, it's their customer support that takes the cake!
- Industry: Construction
- Company size: 10,000+ Employees
- Used Weekly for 2+ years
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
SonarQube delivers high code quality standards for every project
Reviewed on 2024/05/22
Vibrant customer service and interactive product demo. Their work is great and commendable.
Vibrant customer service and interactive product demo. Their work is great and commendable.
Pros
For a while, I used the SonarQube product demo which is great and interactive giving the best experience. The dashboard is easy to use since it is designed with a lot of clarity and motivation. While in use, SonarQube can detect and help remove secrets in code but at the same time offering security against any breaches. Dealing with security vulnerabilities in codes is now made possible. Lastly, there are clear security reports in PDF form which helps us to evaluate the risks on our systems.
Cons
It meets our quality and security expectations. No setbacks.
- Industry: Information Technology & Services
- Company size: 201–500 Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Ease of Use
- Likelihood to recommend 9.0 /10
Elevate your code quality to the next level
Reviewed on 2024/03/30
The development process has been a bit slower than usual after SonarQube integration, but the...
The development process has been a bit slower than usual after SonarQube integration, but the quality and readability of the code is much better.
Pros
The main feature of SonarQube is that it detects code complexities within the code so that the developer can optimize it. It also detects accessibility and security issues; code smells and suggests changes.
Cons
It is a bit difficult to integrate with existing services and the quality checks may also conflict with other integrations.
- Industry: Banking
- Company size: 10,000+ Employees
- Used Weekly for 2+ years
-
Review Source
Overall rating
- Ease of Use
- Likelihood to recommend 8.0 /10
Code Quality Assurance
Reviewed on 2024/03/21
Overall, impressed by this tool that supports multiple languages, monitoring code quality, bugs and...
Overall, impressed by this tool that supports multiple languages, monitoring code quality, bugs and vulnerability detection. Also, integrates well with Jenkins, GitHub, etc.
Pros
- It supports almost all commonly used languages like JAVA, Python, Javascript, etc.
- Integrates well with CI/CD pipeline established in tools like Jenkins and GitHub.
- Detects code duplication, bugs and vulnerabilities in code.
Cons
- May be complex to understand the reports for new users.
- May block delivery/deployment if hard gates are enabled by DevOps team which may delay project delivery.
- Industry: Computer Software
- Company size: 51–200 Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Navigating Code Clarity with SonarQube
Reviewed on 2024/05/23
Pros
I love SonarQube's real-time code analysis, providing instant feedback. Recently, while working on a project, it flagged potential code smells, helping me enhance code quality preemptively.
Cons
It is sometimes overwhelming amount of information and alerts, which can make it challenging to prioritize and address issues effectively.
- Industry: Financial Services
- Company size: 501–1,000 Employees
- Used Daily for 2+ years
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 8.0 /10
SonarQube cornerstone of our continuous development lifecycle
Reviewed on 2024/05/03
Pros
Easy to use interface
Rules flexibility
Broad set of rules to activate
Cons
No roadmap for dynamic analysis
Reports API not so flexible
Fixed price approach
- Industry: Information Technology & Services
- Company size: 1,001–5,000 Employees
- Used Daily for 1-5 months
-
Review Source
Overall rating
- Ease of Use
- Likelihood to recommend 10.0 /10
SonarQube reivew
Reviewed on 2024/04/28
Pros
SonarQube provides important metrics such as code smells, bugs, vulnerabilities, and code coverage. Easy integration with CI/CD tools.
Cons
SonarQube may produce false positives, as with any static analysis tool.
- Industry: Insurance
- Company size: 51–200 Employees
- Used Weekly for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Likelihood to recommend 8.0 /10
Code quality matters
Reviewed on 2024/03/01
Very positive as it allows you to improve the writing of your code.
Very positive as it allows you to improve the writing of your code.
Pros
Report both security and code quality vulnerabilities, indicating the reason for the flaw and the possible resolution. It allows you to set thresholds so as not to compromise too much the quality of the code and the coverage of the tests.
Cons
It is necessary to configure it to avoid false positives in terms of code quality that can block the release of the code.
- Industry: Computer Software
- Company size: 1,001–5,000 Employees
- Used Weekly for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Popular tool for code smell search in the organisation's repositories
Reviewed on 2023/08/08
Pros
Easy-to-administer tool, with good functionality to monitor security part of your code (using SAST methodology), with ability to integrate with Jenkins, GitHub and other tools. You are able to fail the build if the code doesn't meet percentage score.
Cons
When new repository is added - there should be pop-up suggestion to create SonarQube project for it, coming from SonarQube. At the moment the user/administrator must watch out for new repositories in the organisation, without a note from the system itself that there is a new repository which you might want to add for scanning.
- Industry: Airlines/Aviation
- Company size: 201–500 Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 8.0 /10
Great product!
Reviewed on 2023/07/11
Pros
This product has actually improved productivity within my team by making sure there’s no duplicate code and by making code easily understandable.
Cons
Code maintenance is actually a difficult part.
- Industry: Computer Software
- Company size: 1,001–5,000 Employees
- Used Weekly for 1+ year
-
Review Source
Overall rating
- Ease of Use
- Likelihood to recommend 8.0 /10
SonarQube Review
Reviewed on 2023/07/20
Overall experience about Sonarqube - Effective tool for improving code quality but demands...
Overall experience about Sonarqube - Effective tool for improving code quality but demands expertise for setup and maintenance.
Pros
Comprehensive code quality analysis. Really good to detect bugs, vulnerabilities and code smells. And integration with popular CI/CD pipelines is really impressive.
Cons
Setup and configuration can be complex for begineers. And limited support for some programming languages is what could be improved.

- Industry: Computer Software
- Company size: 11–50 Employees
- Used Daily for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
A free tool for source code analysis
Reviewed on 2023/04/10
It helped me to be able to do my job in improving the code, giving me possible solutions and saving...
It helped me to be able to do my job in improving the code, giving me possible solutions and saving me time.
Pros
What I find most useful in this software is the code analysis, which gives detailed reports of the errors found and then suggests possible solutions. This saves time in software development.In addition, their large community helps solve problems that arise along the way.
Cons
Sometimes the reports can give false positives, which requires that the personnel in charge of handling the software carefully review the results to avoid false positives.
- Industry: Computer Software
- Company size: Self Employed
- Used Weekly for Free Trial
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 7.0 /10
Free open source
Reviewed on 2023/05/10
Pros
- integrate CI/CD- customizable Quality Profiles- easy to use
Cons
- performance Impact- limited programming language- open-source, some advanced features are only available in the commercial version
- Industry: Banking
- Company size: 51–200 Employees
- Used Daily for 2+ years
-
Review Source
Overall rating
- Ease of Use
- Likelihood to recommend 8.0 /10
Sonarqube essential code quality analysis tool
Reviewed on 2023/03/12
In short, it is an indispensable tool and should be mandatory in all software development companies.
In short, it is an indispensable tool and should be mandatory in all software development companies.
Pros
The ability to analyze the quality of the code in each deployment or integration, together with the possibility of modifying the rules to allow deployment or not (quantity or criticality of errors or defects), as well as vulnerability analysis allows for better software, always keeping in mind of the developers the quality and security of the code.
Cons
Like everything, the time it takes to leave it well configured and integrated with the rest of the systems, as well as the maintenance and updating of the standards, rules and vulnerabilities depending on the programming language and the news that are published at the level of security.

- Industry: Information Technology & Services
- Company size: 201–500 Employees
- Used Daily for 1-5 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Review for Sonar Qube
Reviewed on 2023/04/09
Pros
This is very good and user friendly application.
Cons
As such i didn't found any con for this application.
- Industry: Higher Education
- Company size: 1,001–5,000 Employees
- Used Monthly for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 8.0 /10
SonarQube is Great for Developers!
Reviewed on 2022/12/23
We could identify many code related issues that are presented in our code and improve the quality...
We could identify many code related issues that are presented in our code and improve the quality of the application that we are developing. As a overall, SonarQube tool is able to add a value to our applications.
Pros
It is simple for developers to recognize their code smells, unused lines of code, errors, problems with the third-party libraries they are using, etc. information and the precise location of the issue. It also offers answers to those problems. As a result, figuring out the problems and fixing them is simple. This will be a terrific tool for developers. Except that, we can introduce our own rules for checking the code quality. It could identify the code issues that are vulnerable to cyber attacks such as XSS, SQL Injection, etc.
Cons
It was difficult to use the SonarQube on-premise application. Once we pushed a new code section, the server needed to restart in order for the application to work.
Alternatives Considered
GitGuardianReasons for Switching to SonarQube
Higher number of facilities are available in SonarQube and suggesting the options for fixing the issues.- Industry: Information Technology & Services
- Company size: 10,000+ Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 7.0 /10
Staple in the CI/CD pipelined quality gate solutions
Reviewed on 2022/12/11
It allows our dev teams to keep consistent level of code quality and known issues proof in code and...
It allows our dev teams to keep consistent level of code quality and known issues proof in code and used target platforms so as to provide to end users/customers highest quality products delivered in CI/CD methodology.
Pros
Easily add source code analysis for potential bugs and pitfalls to warrant against developers' errors or just not efficient coding by novices, projects dependencies on vulnerable platforms and potential long-term support issues due to how your code is structured. Simple deployment of binaries needed for scans for major target build environments OSes, plus easy to use APIs, all for the benefit of easy integration into CI/CD pipelines.
Cons
Caps and limits on key server instance component required when obtaining config for project and preset rules, when sending analysis results or getting quality gate results may make the pipelines seem to fail without easier discerning real reasons.
- Industry: Hospital & Health Care
- Company size: 501–1,000 Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 7.0 /10
Great tool to drive Coding Quality standards
Reviewed on 2021/08/12
PR analysis and Integration with Bitbucket are most in avoiding the new issues.
The tool needs a...
PR analysis and Integration with Bitbucket are most in avoiding the new issues.
The tool needs a lot of improvements
1. Number of rules should be increased.
2. Few rules should have custom exclusions. Ex: Naming conventions => Organisation-specific words will be there which should be in Capital.
3. Generating a lot of false positives
4. Executive reports should generate based on scheduled triggers. We have 20 projects which are assigned to a Portfolio. if you are going to generate a report and send an email for the first portfolio calculation then the rest of the 19 projects info for that day will be missed. Higher management will think that the generated report is the latest but it is not.
5. PR analysis reports should be generated Quickly
Pros
PR analysis and Integration with Bitbucket are most helpful.
Cons
1. Number of rules should be increased.
2. Few rules should have custom exclusions. Ex: Naming conventions => Organisation-specific words will be there which should be in Capital.
3. Generating a lot of false positives
4. Executive reports should generate based on scheduled triggers. We have 20 projects which are assigned to a Portfolio. if you are going to generate a report and send an email for the first portfolio calculation then the rest of the 19 projects info for that day will be missed. Higher management will think that the generated report is the latest but it is not.
5. PR analysis reports should be generated Quickly
Response from SonarSource
Thank you for your review, Chandramouli. We appreciate your feedback, and invite you to join the SonarSource Community Forum.
SonarSource Community Forum: https://community.sonarsource.com/
Posting to the Forum will allow there to be transparency to the community, and allow our product managers & users to understand any issues you are facing.
To better assist you, please indicate what language(s), and how long the PR analysis is actually taking; as well as, examples of the false positives.
Thanks!
- Industry: Automotive
- Company size: 10,000+ Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 8.0 /10
Sonarqube a static code analysis for quality and security of the code
Reviewed on 2022/07/17
We have been using sonarqube in our cicd pipeline for static code analysis and its been very...
We have been using sonarqube in our cicd pipeline for static code analysis and its been very helpful identifying the bugs early in the stages. This tool is best in the market but still missing on some functionalities, mainly in dashboards.
Pros
1. Ensures that only quality, bugfree and vulnerabilities free code goes into production and improves developer’s skills.
2. Supports 24+ languages.
3. Open source version.
4. Developer workflow integration
5. Detect the bugs early in development and send alerts to developers to have a look into suspicious code snippets.
6. The results are faster and can get integrated within pipeline.
Cons
1. Integration with the third party apps could be improved.
2. Dashboards could be better and code security features can be added more.
3. Sometimes false positive results
- Industry: Information Technology & Services
- Company size: 501–1,000 Employees
- Used Daily for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 9.0 /10
Best Code Quality check Tool
Reviewed on 2022/08/25
We are really taking help of SonarQUbe in maintaining code quality. Doing code scanning on each ...
We are really taking help of SonarQUbe in maintaining code quality. Doing code scanning on each JIRA story completion. It also helps our developers to improve their code quality. Coding standards are better now. Reports are very useful.
Pros
1. Calculate the quality of code and also helps to improve the quality by providing the solution
2. Highlight the vulnerabilities , repetitive line of code
3. Developer Friendly tool as it provides recommendations on the line of code which needs an improvement.
4. Create Scan reports on demand
5. Option to add exception in code
Cons
1. Report Generation sometime take long time.
2. User Interface should be enhanced.
3. Lack custom rule set
4. As per cost, it is little bit expensive.
Reasons for Choosing SonarQube
SOnarQube is better in terms of quality percentage, provide more insights.Switched From
Coverity- Industry: Computer Software
- Company size: 10,000+ Employees
- Used Daily for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Best code scanning and monitoring tools
Reviewed on 2022/04/26
Used sonarqube in multiple web development project where we used this tool and found very useful...
Used sonarqube in multiple web development project where we used this tool and found very useful and checkpoints
Pros
Reports it generates and grades on vulnerabilities and highlights the scanned code
Cons
Integration with Visual Studio. Net code was not simple and easier.

- Industry: Computer Software
- Company size: 10,000+ Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 9.0 /10
Code Analysis and ensuing security against threats
Reviewed on 2022/05/23
Overall experience with Sonarqube is pretty wholesome integration came handy with my CI/CD tools...
Overall experience with Sonarqube is pretty wholesome integration came handy with my CI/CD tools such as Azure Devops and Jenkins. Provides insights against vulnerabilities and common threats so that necessary actions can be taken by developers to ensure the security and good coding practices to follow. Features like PR decoration allows to get results in CI/CD tools itself if passed then only commit happens to master branch.
Pros
Feature like Code Analysis and publishing those analysis report to end user. You can use default Quality Gates and Quality Profiles for scanning of your code. In case you want to modify these you can do that and define your own rule. Whenever there's commit in repo you just need to configure the task in your continuous integration pipeline if it passed the parameter only then commit will happens the master/main branch otherwise it will not. With these features you can eliminate the security threats and ensure that developers are following good practices while developing their code. I have integrated it with Azure DevOps.
Cons
Only thing which I can think can be improved is logging of events. Sometime it becomes hard to debug the issues. Other then that, I think over all this fulfills all the requirements.