← All website monitoring tools
Veracode
Enterprise AppSec platform — SAST + DAST + SCA + manual pentest. Public minimum ~$15,000/yr.
What it does well
- Combines SAST, DAST, and SCA scanning into a unified cloud platform.
- Provides detailed remediation advice and educational resources for developers.
- Offers manual penetration testing services to supplement automated scans.
Where it falls short
- No free tier or publicly available pricing; requires sales engagement.
- High starting price (~$15,000/yr) makes it inaccessible for small businesses.
- Platform is cloud-only with no self-hosted or on-premise deployment option.
Alternatives to Veracode
Checkmarx One
paidUnified AppSec platform consolidating SAST/SCA/IAST/API/IaC. Quote-based, public minimums ~$30,000/yr.
Detectify
paidEASM + DAST hybrid — vulnerabilities sourced from a private researcher community, $89-$449/mo published tiers.
Acunetix
paidMature commercial DAST scanner from Invicti — quote-based, generally $4,500+/yr per target tier.
Enterprise DAST + IAST with Proof-Based Scanning — annual contracts, quote-only.