About Veracode
Veracode is a commercial application security vendor that provides testing and risk management for the software organizations build. It serves developers, application security leads and executives who need to find and fix flaws across the development lifecycle and show compliance.
Its platform includes static analysis (SAST) for flaws as code is written, dynamic analysis (DAST) for running web applications, software composition analysis for open source vulnerabilities, a package firewall for pipelines, container security and AI-based remediation called Fix. A Risk Manager component brings findings together for application security posture management, and the vendor adds security training through eLearning and hands-on labs.
Services such as penetration testing as a service and application security consulting complement the software. Veracode is proprietary and delivered as a hosted platform; its site frames the products around defending against AI-generated code risk and supply chain threats.
Key features
- Static analysis while code is written
- Dynamic scanning of running web applications
- Software composition analysis for open source
- Package firewall for development pipelines
- AI-assisted code remediation
- Application risk management dashboard
Good fit for
- →Integrating security testing into CI/CD
- →Training developers in secure coding
- Tags
- security
- appsec
- sast
- dast
- sca
- aspm
- devsecops
Veracode: questions and answers
- What is Veracode used for?
- Veracode is an application security platform covering static, dynamic and software composition analysis, with AI-assisted fixing and risk management for development teams. It is a good fit for integrating security testing into CI/CD and training developers in secure coding.
- How much does Veracode cost?
- Veracode doesn't publish fixed prices; pricing is quoted on request.
- Is Veracode open source?
- No. Veracode is proprietary (closed-source) software and can't be self-hosted. Open-source alternatives to Veracode include Semgrep, Horusec and Grype.
- What are some alternatives to Veracode?
- Veracode competes with Checkmarx, Snyk and Aikido Security. For open-source options, see Enlisted's ranked list of open-source Veracode alternatives.
Open-source alternatives to Veracode
See all
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Dependency-Track
Security
Dependency-Track is an intelligent Component Analysis platform that allows organizations t
Apache-2.0vs Snyk★ 4.3k
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
SonarQube
Developer Tools
Continuous Inspection
LGPL-3.0vs Codacy★ 11k
SaaS alternatives to Veracode
See all
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaS
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Socket
Security
Supply chain security that detects risky open source packages before install
SaaS
Mend
Security
Application security platform for software composition analysis and code scanning
SaaS
Black Duck
Security
Software composition analysis and application security testing products
SaaS
