| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Static application security testing | Developer platform | 22% | 2 of 47 | 10% | 48 | accepted challenger |
| Software composition analysis | Developer platform | 0% | 46 of 49 | 100% | 1 | under 10 labels · led by Trivy at 40% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 2 | 0 | 1 | 0 | 3 |
| GPT-5.4 mini | 0 | 1 | 0 | 0 | 1 |
| Gemini 3.5 Flash | 0 | 2 | 0 | 0 | 2 |
| Perplexity Sonar | 0 | 1 | 1 | 0 | 2 |
| Grok 4.1 Fast | 1 | 4 | 0 | 1 | 6 |
| Mistral Small | 1 | 3 | 1 | 1 | 6 |
| DeepSeek V4 Flash | 0 | 3 | 1 | 1 | 5 |
| Llama 4 Maverick | 1 | 1 | 1 | 0 | 3 |
| Qwen 3.7 Flash | 2 | 2 | 0 | 1 | 5 |
| Kimi K2 | 1 | 3 | 1 | 1 | 6 |
| GLM 4.7 FlashX | 0 | 4 | 0 | 1 | 5 |
| MiniMax M2.5 | 2 | 1 | 2 | 0 | 5 |
Verbatim evidence the judge attached to positive labels.
“Choose SonarQube if you treat security as a subset of quality, need to reduce technical debt, and want better control over costs at scale.” Qwen 3.7 Flash · SAST · direct prompt · first choice
“Widely used, supports multiple languages, integrates well with CI/CD... making it a solid choice for mid-sized teams” Mistral Small · SAST · paraphrase prompt · first choice
“SonarQube or Snyk Code would be the best starting points. SonarQube offers the best overall value” MiniMax M2.5 · SAST · direct prompt · first choice
“A popular choice for mid-sized teams, it offers code analysis, security rules, and continuous monitoring” Llama 4 Maverick · SAST · paraphrase prompt · first choice
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“SonarQube: High false positive rates out-of-the-box (40-82% ...) ... Tune heavily or pair with security-specific tools.” Grok 4.1 Fast · SAST · negative prompt · soft negative
“SonarQube on default settings flags 40‑60 % of findings as non‑issues on typical Java or TypeScript codebases” GLM 4.7 FlashX · SAST · negative prompt · soft negative
“Mature platform, 40+ languages, strong for governance — but noisier out of the box and requires tuning.” DeepSeek V4 Flash · SAST · paraphrase prompt · soft negative
“Developer-first, multi-language coverage, but does not offer reachability analysis.” Mistral Small · SCA · comparative prompt · soft negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 134 of the 152 answers that named SonarQube and are not a share of its labels.
588 of the 588 domain citations in answers naming SonarQube came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when SonarQube's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as SonarQube, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at sonarqube.com is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.