Salesforce
Scan and Fix Your APEX Code
Checkmarx is Salesforce’s Official Static Application Security Testing Provider
Why Choose us?
Among the most powerful static source code analysis tools available today, CxSAST and Checkmarx One offers unique features that make them stand out from other enterprise class products
| Feature | Feature | Force.com Scanner | Checkmarx |
|---|---|---|---|
| Price | |||
| Price | Free | Commercial License | |
| Subscription Period | |||
| Subscription Period | Per Scan | minimum 1 year | |
| Max Lines of Code | |||
| Max Lines of Code | Lines of Code per Scan | 30,000 LoC | Unlimited |
| Number of Projects | |||
| Number of Projects | 1 Project | Multiple Projects | |
| Salesforce Languages | |||
| Salesforce Languages | Apex, VisualForce, Javascript, HTML5 | ||
| Technical Support | |||
| Technical Support | |||
| Best Fix Location | |||
| Best Fix Location | Optimal vulnerability remediation can be presented in textual or visual formats. For example, the ability to pinpoint the precise vulnerability which – if fixed – eliminates all vulnerabilities that depend on that particular code flow. | ||
| Salesforce direct support | |||
| Salesforce direct support | for Apex scan queries and scan results | ||
| On-Demand Scanning and Immediate Results | |||
| On-Demand Scanning and Immediate Results | Receive results immediately independent of Salesforce timelines. Full or Incremental project scan options | ||
| Out-of-the-box integration with the most common IDE and Source Repositories. | |||
| Standards Support | |||
| Standards Support | Easily and cost effectively comply with most of the major regulatory requirements and industry standards. e.g. PCI-DSS, HIPAA, etc | ||
| Additional Supported Language Packages | |||
| Additional Supported Language Packages | Java, .Net, ASP, VB, C/C++, PHP, Ruby, JavaScript, VBScript, Perl, Android, iOS, PL/SQL, Python, Groovy and more. Included at additional cost. | ||
| Build Process Integration | |||
| Build Process Integration | Integration into your existing SDLC; Scan automation that supports Continuous Integration Tools, Build Servers, Web Service API, Command Line Interface, Bug Tracking for early-stage scanning and Agile development environments. | ||
| API Access | |||
| API Access |