Introducing G2.ai, the future of software buying.Try now
OpenText Fortify Static Code Analyzer
Show rating breakdown
Save to My Lists
Claimed
Claimed

Top Rated OpenText Fortify Static Code Analyzer Alternatives

Coverity
(56)
4.2 out of 5

OpenText Fortify Static Code Analyzer Reviews & Product Details - Page 2

OpenText Fortify Static Code Analyzer Overview

What is OpenText Fortify Static Code Analyzer?

Fortify Static Code Analyzer is designed to identify security vulnerabilities in the user's source code early in the software development lifecycle and provides best practices so developers can code more securely.

OpenText Fortify Static Code Analyzer Details
Show LessShow More
Product Description

Fortify Static Code Analyzer is designed to identify security vulnerabilities in the user's source code early in the software development lifecycle and provides best practices so developers can code more securely.


Seller

OpenText

Description

OpenText software applications manage content or unstructured data for large companies, government agencies, and professional service firms. OpenText aims its products at addressing information management requirements, including management of large volumes of content, compliance with regulatory requirements, and mobile and online experience management.

Overview Provided by:

OpenText Fortify Static Code Analyzer Integrations

(4)
Integration information sourced from real user reviews.

Recent OpenText Fortify Static Code Analyzer Reviews

Vis C.
VC
Vis C.Enterprise (> 1000 emp.)
4.5 out of 5
"A worthy SAST product for any software's source code security"
Wide range of programming language support, Ability to generate FPR files from CICD pipelines, Externalization of scans into another server for per...
LT
Lokesh T.Mid-Market (51-1000 emp.)
4.0 out of 5
"Fortify Static Code Analyzer (SCA)"
Fortify SCA is having large Technologies Stack support, It supports more then 34+ Languages for Static Analysis. And also he is having huge integra...
Verified User
C
Verified UserEnterprise (> 1000 emp.)
5.0 out of 5
"Fortify is best tool to scan source code"
I like fortify to scan source code in deply. It will compile the code and find the vulnerabilities. No others tools compile the code scan. Most imp...

OpenText Fortify Static Code Analyzer Media

Answer a few questions to help the OpenText Fortify Static Code Analyzer community
Have you used OpenText Fortify Static Code Analyzer before?
Yes

24 OpenText Fortify Static Code Analyzer Reviews

4.5 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.

OpenText Fortify Static Code Analyzer Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons
G2 reviews are authentic and verified.
Jobin T.
JT
Software Engineer II
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about OpenText Fortify Static Code Analyzer?

The ease of use and an intuitive UI makes using the Fortify Static Code Analyzer quite easy for people who are new to it. A topic as complex as Security becomes manageable as the tool provides detailed reports on what the vulnerabilities are with their severity level and quite an extensive description of what is causing the vulnerability and recommendations to fix it. This makes life for the developers who might be new to Security. Review collected by and hosted on G2.com.

What do you dislike about OpenText Fortify Static Code Analyzer?

Some newer language syntax of certain languages like Java 8+ might not be understood by Fortify which leads to false positives. Also, certain non-fixeable vulnerabilities for which exceptions were provided would pop back up once in a while, which is a bit annoying. Review collected by and hosted on G2.com.

Recommendations to others considering OpenText Fortify Static Code Analyzer:

It's an amazing tool to start your journey towards making your application secure. Review collected by and hosted on G2.com.

What problems is OpenText Fortify Static Code Analyzer solving and how is that benefiting you?

We majorly solve security vulnerabilities that could be caused due to bad programming on our front and also weed out open source libraries that we use which could introduce vulnerabilities through their transient dependencies. Also as the vulnerability list keeps getting updated regularly we are made aware of any new issue that was recently reported allowing us to keep our application secure proactively. Review collected by and hosted on G2.com.

Touseeq Ali H.
TH
Junior DevOps Engineer
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
Rating Updated ()
What do you like best about OpenText Fortify Static Code Analyzer?

it Supports Nearly all programming languages, the process of testing is very easy, every new update makes it more functional. all the vulnerabilities of all languages are being updated on time. Review collected by and hosted on G2.com.

What do you dislike about OpenText Fortify Static Code Analyzer?

Some times it gives false positives, so we need to recheck it with other tools. please improve the vulnerabilities identification. Review collected by and hosted on G2.com.

Recommendations to others considering OpenText Fortify Static Code Analyzer:

if you want a compact and easy to use tool for code testing the this is the one for you. Review collected by and hosted on G2.com.

What problems is OpenText Fortify Static Code Analyzer solving and how is that benefiting you?

due to this tool, we can say our DevOps becomes Devsecops. our code is secure, pipelines running smoothly. we are increasing our product performance and its functionality. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
AC
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about OpenText Fortify Static Code Analyzer?

Tool is really good. Specially i liked the ai feature.machine learning used is really good. Review collected by and hosted on G2.com.

What do you dislike about OpenText Fortify Static Code Analyzer?

Need to improve on false positive. Some time results give general results for all th Language. For example some vulnerability does not applicable for java but it will show. So need to improve on that part. Review collected by and hosted on G2.com.

What problems is OpenText Fortify Static Code Analyzer solving and how is that benefiting you?

It help me alote in my sast part. I do reviews many scan results. Some time for quick results i can use ai feature. Review collected by and hosted on G2.com.

Verified User in Financial Services
CF
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about OpenText Fortify Static Code Analyzer?

Liked that it support multiple languages, which comes with a less price as compared to other commercial SAST tools. Review collected by and hosted on G2.com.

What do you dislike about OpenText Fortify Static Code Analyzer?

When it comes to the detection, found couple of false positives, for example: found quite of null pointer exceptions which turns out to be incorrect. Review collected by and hosted on G2.com.

Recommendations to others considering OpenText Fortify Static Code Analyzer:

It's obviously better than the open source tools available in the market. However, out need was to go for specific language based assessment. Review collected by and hosted on G2.com.

What problems is OpenText Fortify Static Code Analyzer solving and how is that benefiting you?

Our need of having a commercial SAST tools was satisfied using Fortify.

The reports were neat and easy to understand, plus time duration of the scans where fast compared to the other SAST tools in the market. Review collected by and hosted on G2.com.

Verified User in Telecommunications
UT
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
Business partner of the seller or seller's competitor, not included in G2 scores.
What do you like best about OpenText Fortify Static Code Analyzer?

We like

1. the ease of onboarding

2. the ease of use it in command line

3. How it integrates with Gitlab CI and Jenkins seemlessly

4. The pdf report is useful to present the output to stakeholders and for auditing. Review collected by and hosted on G2.com.

What do you dislike about OpenText Fortify Static Code Analyzer?

We rarely use dashboard. Since there are offshore and onshore restrictions, it is hard to give roles in the site. Review collected by and hosted on G2.com.

What problems is OpenText Fortify Static Code Analyzer solving and how is that benefiting you?

We are trying to be complaint with the company wide security policies. Our organization highly recommend to use Fortify in our CI pipeline.The process of integrating Fortify was rewarding, we fix lot of issues and learnt more from the report and insights. Review collected by and hosted on G2.com.

AB
DevSecOps Engineer
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about OpenText Fortify Static Code Analyzer?

I like the fact that the tool gives a detailed description of the highlighted issues and its very cost effective.

Also better than checkmarx and white hat security. Review collected by and hosted on G2.com.

What do you dislike about OpenText Fortify Static Code Analyzer?

Nothing much until now. Overall its a great tool than what i have reviewed before. Review collected by and hosted on G2.com.

What problems is OpenText Fortify Static Code Analyzer solving and how is that benefiting you?

I am using it for reviewing the in house applications of the company. Review collected by and hosted on G2.com.

ghariza e.
GE
Security Engineer
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about OpenText Fortify Static Code Analyzer?

Code scan duration is quite fast and the result is quite detail. Review collected by and hosted on G2.com.

What do you dislike about OpenText Fortify Static Code Analyzer?

Integration process is very complicated. Review collected by and hosted on G2.com.

Recommendations to others considering OpenText Fortify Static Code Analyzer:

SaaS solution would be more useful and easy to use. Review collected by and hosted on G2.com.

What problems is OpenText Fortify Static Code Analyzer solving and how is that benefiting you?

Security flaws and misconfiguration and vulnerability on the development phase. Review collected by and hosted on G2.com.

Santhosh K.
SK
Member
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about OpenText Fortify Static Code Analyzer?

When it comes to application security you cannot neglect the GAINT Microfocus Fortify. They offer a suite of products such as Fortify SCA, SSC, Audit Workbench, Application Defender, Web Inspect, and their cloud offering Fortify OnDemand to combat security threats for every type of organization. The most striking features of their Fortify are a good number of supported languages, a wide variety of integration capabilities with IDEs, and build servers(Jenkins, Bamboo, Visual Studio, Gradle & Make), Integration with various bug trackers such as Bugzilla, Jira, ALM Octane. Review collected by and hosted on G2.com.

What do you dislike about OpenText Fortify Static Code Analyzer?

Analysis of COTS products will be a challenge with Fortify SCA. But there are other solutions such as Fortify Application Defender to deal with security of COTS product Review collected by and hosted on G2.com.

Recommendations to others considering OpenText Fortify Static Code Analyzer:

Go for Fortify, This is the best solution in the market as per my analysis and it had proved to be the best in the breed so far. I have implemented it in most of the organisation I have worked in. Review collected by and hosted on G2.com.

What problems is OpenText Fortify Static Code Analyzer solving and how is that benefiting you?

Application security vulnerabilities are the major problem we face that cannot be protected by traditional security practices. Review collected by and hosted on G2.com.

Verified User in Higher Education
UH
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about OpenText Fortify Static Code Analyzer?

It always pinpoint the security vulnerabilities! Review collected by and hosted on G2.com.

What do you dislike about OpenText Fortify Static Code Analyzer?

Nothing so far based on my experience . Review collected by and hosted on G2.com.

Recommendations to others considering OpenText Fortify Static Code Analyzer:

Should give it a try! Review collected by and hosted on G2.com.

What problems is OpenText Fortify Static Code Analyzer solving and how is that benefiting you?

It alway provide detailed guidance on how to fix them so we can resolve the issues less time Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
CC
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about OpenText Fortify Static Code Analyzer?

Can be integrated with CI/CD which reduces lots of manual works. Scans are fast and not time consuming Review collected by and hosted on G2.com.

What do you dislike about OpenText Fortify Static Code Analyzer?

Must include docker files scanning mechanism Review collected by and hosted on G2.com.

What problems is OpenText Fortify Static Code Analyzer solving and how is that benefiting you?

Scans are done automatically and timely Review collected by and hosted on G2.com.