Micro Focus Fortify Static Code Analzyer

Fortify Static Code Analyzer is designed to identify security vulnerabilities in the user's source code early in the software development lifecycle and provides best practices so developers can code more securely.

Languages supported:

9.0/10 (Expert Score) ★★★★★
Product is rated as #10 in category Static Application Security Testing (SAST) Software
Ease of use
9.2
Support
9.0
Ease of Setup
8.6

Fortify Static Code Analyzer is designed to identify security vulnerabilities in the user’s source code early in the software development lifecycle and provides best practices so developers can code more securely.

Micro Focus Fortify Static Code Analzyer
Micro Focus Fortify Static Code Analzyer

Show more categories

Customer Reviews

Micro Focus Fortify Static Code Analzyer Reviews

Jobin T.

Advanced user of Micro Focus Fortify Static Code Analzyer
★★★★★
Must have to secure your Modern Cloud Applications

What do you like best?

The ease of use and an intuitive UI makes using the Fortify Static Code Analyzer quite easy for people who are new to it. A topic as complex as Security becomes manageable as the tool provides detailed reports on what the vulnerabilities are with their severity level and quite an extensive description of what is causing the vulnerability and recommendations to fix it. This makes life for the developers who might be new to Security.

What do you dislike?

Some newer language syntax of certain languages like Java 8+ might not be understood by Fortify which leads to false positives. Also, certain non-fixeable vulnerabilities for which exceptions were provided would pop back up once in a while, which is a bit annoying.

Recommendations to others considering the product:

It's an amazing tool to start your journey towards making your application secure.

What problems are you solving with the product? What benefits have you realized?

We majorly solve security vulnerabilities that could be caused due to bad programming on our front and also weed out open source libraries that we use which could introduce vulnerabilities through their transient dependencies. Also as the vulnerability list keeps getting updated regularly we are made aware of any new issue that was recently reported allowing us to keep our application secure proactively.

Review source: G2.com

Leave a reply

Your total score

B2B Software Guide