AppSecNews
SAST Commercial Established

Checkmarx

by Checkmarx

An enterprise SAST engine with broad language coverage that builds a queryable code graph and traces tainted data from source to sink.

Visit checkmarx.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Checkmarx in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
  • Exact current language list and which are generally available versus preview: confirm with vendor

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Checkmarx compiles source into its own intermediate representation and builds a graph of the code: control flow, data flow, call relationships, and the declarations that connect them. Queries written in a proprietary query language traverse that graph to find paths from a source of untrusted input to a dangerous sink, with sanitizers along the path recognized as breaking the flow. The shipped query set covers the usual injection, deserialization, access control and crypto misuse families, and customers can edit those queries or write new ones, which is the main reason large organizations pick it: the engine's behavior is adjustable rather than opaque.

A notable engineering choice is that the core scanner does not require a successful build for many languages. It parses source directly, which removes the classic enterprise problem of needing a working compiler toolchain on the scan host. The trade-off is that resolution of types and third-party symbols is weaker than a compile-based approach, so some flows are inferred rather than proven. Results land in a web console with attack-vector visualization, and the broader product line adds composition analysis, IaC scanning, API discovery and container scanning under one platform.

Where it fits

This is a security-team-owned platform that developers consume through IDE plugins and pipeline gates. It runs in CI on merge or nightly for large repositories, with incremental scans used to keep pull request feedback tolerable. To get value you need someone who owns query tuning and a triage workflow, because the default query set applied to a large legacy codebase produces more findings than any team will fix. Adoption typically involves a months-long tuning phase.

Strengths

  • Very broad language coverage, including languages that are awkward elsewhere such as Apex and mobile native code.
  • Custom query language lets you encode organization-specific sources, sinks and sanitizers, which materially cuts false positives over time.
  • Buildless scanning for many languages removes a large class of pipeline integration problems.
  • Mature result management: audit trails, per-finding state and role separation suited to regulated environments.

Limitations

  • Scan times on large monorepos can be long enough to force incremental scanning, which adds its own configuration burden and blind spots.
  • Out-of-the-box false positive volume is high and the tuning effort is real, not optional.
  • Heavy platform footprint and a proprietary query language create genuine switching costs once your custom rules accumulate.

Who it suits

Large organizations with a dedicated AppSec function, many languages in play, and compliance obligations that expect a named commercial scanner. A small team without someone to own tuning will get more value from a lighter scanner they can actually keep green.

Used Checkmarx? Recommend it under your own name and title.

Recommend this tool