FOR DEVELOPERS | Get a 1-month free trial of Developer Assist
Platform overview
Checkmarx One
Agentic AI
Checkmarx One Assist
AI-powered Agentic AppSec agents preventing and remediating threats autonomously.
Developer Assist
Developer-first AI agent for instant vulnerability prevention and fix.
Posture
ASPM
Unified visibility, control and prioritization across your entire AppSec posture.
PARTNERSHIPS & INTEGRATIONS
Partner Programs
Building stronger AppSec ecosystems through trusted partnerships.
Find a Partner
Discover certified partners to accelerate your AppSec journey.
SOLUTIONS FOR
Code
Supply Chain
Cloud
Services
Developer-first Al agent preventing and remediating vulnerabilities instantly in IDE.
SAST
Market-leading, developer-friendly static application security testing and analysis
DAST
Developer tailored dynamic application scanning for efficient security issues remediation.
API Security
Enterprise scale API security scanning for early detection of critical vulnerabilities.
SCA
Identify, prioritize, and remediate open-source vulnerabilities, malicious code, and license risks.
Malicious Package Protection
Reveal and eliminate malicious open-source packages using industry’s largest database.
Repository Health
Enhance security with full visibility into code repository health.
Software Supply Chain Security
Protect your entire software supply chain with industry-leading security across legacy, open source, and Al-generated code.
Container Security
Secure containerized applications across SDLC, from code to cloud runtime.
laC Security
Secure cloud infrastructure via advanced scanning and vulnerability detection.
Premium Support
Enhance security outcomes and ROl with proactive, expert technical support.
Premium Services
Accelerate AppSec program success while maintaining seamless developer experience.
Maturity Assessment
Assess your AppSec maturity and unlock actionable improvement steps.
Why Checkmarx
Customer Stories
Awards
Industry Recognition
Integrations
For the Public Sector
COMPARE CHECKMARX
vs. Snyk
vs. GitHub
vs. Veracode
vs. Fortify
vs. Black Duck
vs. Semgrep
RESEARCH
Checkmarx Zero
Research Blog
Disclosed Vulnerabilities
Open-Source Tools
Resources
Analyst Reports
Product Demos
Solution Briefs
Videos
Webinars
Whitepapers
LEARN
Blog
Documentation
Glossary
Knowledge Hub
Customer Enablement
The 2025 Gartner® Magic Quadrant™ for Application Security Testing
Read more
IDC MarketScape for ASPM 2025
The Forrester SAST Wave 2025
Checkmarx One Solution Brief
COMPANY
About Us
Leadership
Press Releases
Newsroom
Events
Careers
PARTNERS
Partner Directory
Become a Partner
GET IN TOUCH
Support Portal
Contact Us
Improve your security posture with full visibility into the security, dependency management, and maintenance health of the code repositories used in your applications.
Without repo health monitoring, repositories are at risk of unauthorized code changes, dangerous or low-quality code, regulatory non-compliance, and other security threats.
Continuous Repo Health Tracking
Monitor the health of all repositories included in your applications based on factors such as security practices, testing practices, dependency management, CI/CD practices, and project maintenance.
Automatic SCM-Triggered Scans
Integration with SCM platforms enables scans to run automatically upon repository updates, ensuring up-to-date repo health assessments with no manual effort.
Flexible On-Demand Scanning Options
In addition to automatic SCM-triggered scans, developers and security teams can manually run repo health scans at any time via API, CLI, or the Checkmarx One UI.
Unified Risk Reporting
Repository health evaluations are included in Checkmarx One reports, providing visibility into – and efficient prioritization of – security vulnerabilities, code quality issues, and repository health risks, all in one place.
Learn how you can use repository health scoring to improve your application security posture.
What’s in it for you
Continuously tracking repository health helps minimize the threat exposure of vulnerable code repos, leading to improved security and enhanced transparency with stakeholders.
Ongoing comprehensive visibility into the security health of all code repositories closes a critical gap in software supply chain security.
Identifying and prioritizing high-risk areas in all aspects of the software supply chain allows developers and security teams to focus their efforts on the most critical security issues.
Having unified assessments of the security posture of code repositories improves transparency, communication, and collaboration among stakeholders.
See why enterprises trust our approach to AppSec to secure their business-critical applications.
“We view Checkmarx as our trusted partner. They’ve elevated our security posture by consolidating our SAST, SCA, and API Security into a unified platform, Checkmarx One, enabling us to achieve vulnerability remediation, reduce noise, and benefit from strong support.”
“Incorporating Checkmarx’s technology has revolutionized our development culture. It’s more than just technology; it serves as the foundation of our security strategy, ensuring that our applications are secure by design.”
“Checkmarx One definitely checks all my boxes from a security standpoint and has a great interface that’s engaging and easy to use. Some of the solutions we considered were more complicated. With Checkmarx One, it’s easy to get right to the problem with little to no learning curve.”
“The success of our AppSec program can be directly attributed to the tooling, processes and support provided by Checkmarx managed services. Our mission revolves around providing secure and compliant lottery and gaming applications and services to our clients around the globe, and with Checkmarx SAST, SCA and associated components enhanced by their stellar service support, we deliver on this promise with confidence and certainty.”
“After nearly nine years of using Checkmarx’s SAST, CGI’s journey has been one of seamless integration and consistent satisfaction. The last three years have been particularly smooth, reflecting the solution’s reliability and our successful partnership.”
“After reviewing the Checkmarx platform, I’m not sure how Veracode is able to exist while being at a similar price point.”
“By Far The Best AppSec Tooling Decision We Have Made!!”
“We were thrilled to find Checkmarx, which helped us improve the SLA for identifying and remediating risk, reduce risk and the number of vulnerabilities, and eliminate high- and medium-risk issues.”
“Checkmarx made security team and developers life easier.”
Modern code repositories store application source code, CI/CD configurations, IaC files and other sensitive data. Software supply chain attacks are rising steeply; poorly managed internal code repos are a weak point in an organization’s software supply chain security posture. Because large enterprises typically maintain thousands of repos, it is impossible to manually track how well each of them is configured, maintained, and secured. An automated solution is needed to continuously determine the security and code-quality health of internal code repos.
Checkmarx’ Repository Health helps you maximize the security posture of your applications by automatically and continuously tracking the security and quality practices applied to your code repositories. Each repo is evaluated on its security policies and best practices, including:
OSSF Scorecard is an open-source project created by the Open-Source Security Foundation (OpenSSF) that assesses code repositories for security risks through a series of automated checks. Checkmarx One incorporates the results of OSSF Scorecard evaluations in its reports so that developers and security teams can improve their visibility into security vulnerabilities, code quality issues, repository maintenance standards, and other repository health risks.
Frequent scans on a regular basis (weekly or monthly) are recommended to continuously monitor repositories for emerging risks. In addition, it is considered a best practice to re-scan a repository any time it is updated, preferably through SCM integration and automation.
A poor repo health evaluation indicates that the repository may have security or operational risks, prompting further investigation and remediation steps. To maximize application security posture, repositories must be protected from the risks of unauthorized code changes, dangerous or low-quality code, regulatory non-compliance, and other security threats.
Everything enterprises need to secure application development from code to cloud on a unified platform.
Application Security Posture Management (ASPM) Consolidated, correlated, prioritized insights to help your team manage risk
Conduct fast and accurate scans to identify risk in your custom code.
Identify vulnerabilities only seen in production and assess their behavior.
Eliminate shadow and zombie APls and mitigate API-specific risks.
Easily identify, prioritize, remediate, and manage open-source security and license risks.
Detect and remediate malicious or suspicious third-party packages that may be endangering your organization.
AI Security
Built to accelerate AppSec teams and help developers secure applications from the first line of code.
Secrets Detection
Minimize risk by quickly identifying and eliminating exposed secrets.
Reduce security risks by health-scoring the code repositories used in your applications.
Scan container images, configurations, and identify open-source packages and vulnerabilities preproduction and runtime.
IaC Security
Automatically scan your laC files for security vulnerabilities, compliance issues, and infrastructure misconfigurations.
Dev Enablement
Codebashing
Secure code training to upskill your developers and reduce risk from the first line of code.
DevSecOps
75+ Languages
100+ Frameworks
75+ Technologies
SDLC Integrations
Maximize ROI with prioritized technical support, metrics monitoring, and operational assistance.
Augment your security team with Checkmarx services to ensure the success of your AppSec program.
Assess the current state of your AppSec program, benchmark against peers, and get actionable next steps for improvement.
Unified Dashboard, Reporting & Risk Management
Application Security Posture Management (ASPM)
Consolidated, correlated, prioritized insights to help your team manage risk
AI Powered
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
See it in action
Learn how automatic repository health tracking strengthens your software supply chain security.
Continuous repo scoring: Track code quality, dependency hygiene, CI/CD practices & maintenance at scale.
Always current: Automatic SCM‑triggered scans + on‑demand via API/CLI/UI.
Unify risk reporting: See repo‑health insights alongside AppSec findings to prioritize efficiently.
Policy guardrails: Use insights to gate merges and reduce blast radius.
Trusted By:
Learn more with these valuable resources.