What people actually say about Checkmarx
79 mentions across 6 sources · 33% positive · researched Jul 25, 2026
Hacker News, YouTube, Product Hunt, Bluesky, Stack Overflow, Lemmy
What users praise
- • Highest SAST F1 score with 11% higher true-positive rate than average.
- • Broad scanning coverage: SAST, SCA, IaC, API, secrets, containers, DAST.
- • Agentic AI assistants help developers prevent and fix vulnerabilities in-IDE.
What frustrates them
- • Severe supply chain compromise in 2026 undermines trust in the vendor.
- • High false positive rates produce 'garbage' results without heavy tuning.
- • Setup is complex and error-prone, with ambiguous error messages.
This is a summary. The full report adds every quote we found, a per-source breakdown, recurring themes, hidden costs and the learning curve — run a free scan below, or see the full Checkmarx review.
What comes up again and again about Checkmarx
Recurring themes across everything we collected, with where each one showed up.
Supply chain breach severely damages trust and is the dominant narrative in 2026.
criticised · seen on Hacker News, Bluesky, Lemmy
High false positives frustrate developers, requiring extensive tuning.
criticised · seen on Hacker News, YouTube
Agentic AI and in-IDE remediation assistants are praised as innovative.
praised · seen on Product Hunt, YouTube
Setup and configuration are complex, with poor error messages.
criticised · seen on YouTube
The tool is expensive and pricing is not transparent.
criticised · seen on Hacker News
Irony of a security vendor being hacked is a recurring joke/snark.
criticised · seen on Hacker News, Bluesky
How hard is Checkmarx to learn?
Users describe it as intermediate · typically Days of setup to get going
Where people get stuck
- • Installation fails with unclear engine assignment errors
- • Requires configuration of multiple scanning engines and policies
- • False-positive tuning demands experienced AppSec engineers
Who Checkmarx actually suits
Works well for
- • Large enterprises needing broad, unified AppSec coverage across SAST, SCA, and IaC
- • Teams adopting agentic AI in software development to enforce security at code creation
- • Security-conscious organizations with dedicated AppSec teams to handle tuning
Not the right fit for
- • Small teams or individual developers who cannot afford high licensing and tuning overhead
- • Developers seeking a lightweight, easy-to-setup SAST tool with minimal false positives
What people are discussing right now
Discussion volume is high and trending down
- Supply chain attack on KICS, Jenkins plugin, VS Code extensions
- Bitwarden CLI compromise traced back to Checkmarx breach
- High false positives and tuning difficulty
- AI agent capabilities and in-IDE developer experience
What people really think about Checkmarx
A real-time sweep of the open web — social media, forums, review sites, video reviews and live community discussions — distilled into one honest verdict with the actual mentions behind it.
What's inside your Checkmarx report
Everything you need to decide — distilled from real, current user opinion.
Live mentions
The actual posts, reviews & complaints about Checkmarx — with links and dates.
Honest verdict
A straight answer on whether it lives up to the hype — and who it’s really for.
Praise & gripes
What users genuinely love and the frustrations that keep coming up.
Real quotes
Representative voices from real users, not marketing copy.
Recurring themes
The patterns across hundreds of opinions, surfaced at a glance.
Red flags
Hidden costs and dealbreakers people only discover after signing up.
How it works
Sign up free
Create an account in seconds — get 5 free scans, no card.
We sweep the web
Live social media, forums, reviews & video opinions — in ~30–60s.
Get your report
An honest, downloadable verdict with the real mentions behind it.
Ready to see the real verdict on Checkmarx?
Your scan is ready in under a minute · ₹20 / $1.
Compare Checkmarx head-to-head
See how it stacks up against the tools people weigh it against.
Top alternatives to Checkmarx
Researching options? Explore the closest alternatives.
Snyk DeepCode AI
Hybrid AI code scanner with 85%-accurate autofixes and risk-based prioritization for human and AI-generated code.
Prompt Armor
AI vendor risk intelligence for enterprise TPRM teams
Cycode
Secure and govern AI-generated code from prompt to runtime with agentic development security.
Wiz
Cloud-native security platform (CNAPP) that connects code, cloud, and runtime into a unified graph.
Codacy AI
AI code review, security scans, and governance guardrails for AI-assisted development
Legit Security
AI-native ASPM that secures AI-generated code before it ships
Check sentiment on these too
Run a live scan on the alternatives before you decide.
Checkmarx — questions buyers ask
What do people complain about most with Checkmarx?
The complaints that recur most often are severe supply chain compromise in 2026 undermines trust in the vendor, high false positive rates produce 'garbage' results without heavy tuning and setup is complex and error-prone, with ambiguous error messages. Drawn from 79 mentions across 6 sources.
What do users like about Checkmarx?
Users consistently praise highest SAST F1 score with 11% higher true-positive rate than average, broad scanning coverage: SAST, SCA, IaC, API, secrets, containers, DAST and agentic AI assistants help developers prevent and fix vulnerabilities in-IDE.
Is Checkmarx hard to learn?
Users describe it as intermediate; most people are up and running in days of setup; the usual sticking points are installation fails with unclear engine assignment errors and requires configuration of multiple scanning engines and policies.
Who should not use Checkmarx?
Based on what users report, it is a poor fit for small teams or individual developers who cannot afford high licensing and tuning overhead and developers seeking a lightweight, easy-to-setup SAST tool with minimal false positives.
What are people saying about Checkmarx right now?
Discussion volume is high and trending down. Current topics: supply chain attack on KICS, Jenkins plugin, VS Code extensions, bitwarden CLI compromise traced back to Checkmarx breach and high false positives and tuning difficulty.
How current is this report?
Each scan runs live the moment you click — it reflects what people are saying now, and every report lists the dated mentions behind it.
Can I download it?
Yes — download the full report as a polished, shareable PDF.