Veracode is a security and coding standard tool that offers SAST, DAST, IAST, penetration testing, and application security consultation in one app.
"Common Vulnerabilities and Exposures" reporting is provided by Veracode.
Static scans from Veracode are stated to give unambiguous detection of faults as well as valuable information and thorough triage recommendations. Review collected by and hosted on G2.com.
Veracode can improve UI functionalities as there is a significant learning curve to get started with existing UI.
Currently, the Veracode platform is not capturing the results of the pipeline scan.
Not all instances of the issue are caught when a file is scanned. Review collected by and hosted on G2.com.
Dynamic analysis is not a product its become a framework for application security assessment, the most fascinating feature of this product is automated remediation and dynamic discovery of integrated technologies. I have evaluated other products of application and API security assessment but didn't find such Review collected by and hosted on G2.com.
TWO features, 1st: the policy which has been assigned by the user in Veracodeif the Application doesn't comply with the policy guidelines, it highlighted it as a risk. It won't calculate the residual risk or the compensatory controls implemented in the organization.
2nd: While assessing the cloud-based application, it won't give you visibility until the proper authentication and authorization is not provided. Review collected by and hosted on G2.com.
Veracode reduces the need for iterative manual reviews from security perspectives. You can scan multiple applications within the same scan and can generate historical reports. It keeps proper track of open, closed, in progress issues. It focuses on Issue fixing and hence helps developers by providing remedial actions. It provides the reports in multiple formats, varying from summary to detailed, and also allows you to customize your reports. It also provides the issue severity and their count visually. It's a go-to tool for enterprise applications as well. Review collected by and hosted on G2.com.
It's pretty slow sometimes. You might have to wait for the pages to load, and the scan sometimes takes more than usual. But you can keep them running in the background. Review collected by and hosted on G2.com.
It provide all the details regarding the issue and the way attention to details are provided which makes it easier for a developer to understand the issue in a better way Review collected by and hosted on G2.com.
Again, It's the same as what I mentioned in the like section and details, At times it is not useful to go through each and every detail to address the issue, that is time taking task. Review collected by and hosted on G2.com.
Better than static scan. The idea of having code tested upfront for security flaws is always good.
Static scans can't be through and they are usually through.
Also saves a lot of time as the flaws are deticted before rlease cycles. Review collected by and hosted on G2.com.
The only problem I would like to mention is that flaws are searched on the only part of the code that's being executed. So the code coverage stays in question covered by this. Review collected by and hosted on G2.com.
A step-by-step process for SAST and DAST scans.Excellent Customer Support and a great,responsive Technical Assistance team Review collected by and hosted on G2.com.
User Interface could have been more engaging. Review collected by and hosted on G2.com.
I like the integration that Veracode gives you into your build CI/CD tools and also the integration that you get into your IDE. The tools also covers a number of different and commonly used languages. Review collected by and hosted on G2.com.
I don't feel that the web UI that is provided by Veracode is always intuitive. I wasn't easily able to easily find things like historical scan results or see the improvement/disimprovement over time. Review collected by and hosted on G2.com.
Identification of true vulnerabilities and the way it scans & identifies those Review collected by and hosted on G2.com.
No such as of now, but sometimes it appears to me little bit slowness in analyzing Review collected by and hosted on G2.com.
Code analysis and the reporting feature is awesome and instructions for fixing or metegating issue is real good. I can get the detailed analysis of all my binaries, for volnirability Scan. Review collected by and hosted on G2.com.
Pricing is too high for a start-up where if I want to run the analysis the cost is more than the feature that I am developing. Review collected by and hosted on G2.com.
I like the speed at which Veracode runs through small to medium size apps. I like how easy it is to navigate through the site to find flaws. Review collected by and hosted on G2.com.
Larger apps take quite a bit of time to scan. Having those scan faster or making it easier to scan specific portions of the apps would be helpful. Review collected by and hosted on G2.com.