Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

Head-to-head · IDE Code Security Plugins

Fortify Static Code Analyzer vs Checkmarx IDE Plugins

  • Updated Sep 2026
  • Both researched from official sources
  • 1 check side by side
Fortify Static Code Analyzer #4 in IDE Code Security Plugins —/10 Pricing on request ✓ 0 of 4 features Visit OpenText
Checkmarx IDE Plugins #5 in IDE Code Security Plugins —/10 Pricing on request ✓ 1 of 4 features Visit Checkmarx

Fortify Static Code Analyzer leads on 0 checks, Checkmarx IDE Plugins on 1, and 0 are even. Who comes out ahead on the 1 yes/no, price and count check where we have data for both products. The editor score weighs everything else too.

Our verdict

  • Most featuresCheckmarx IDE Plugins · 1 of 4

Our editors rank Fortify Static Code Analyzer at #4 and Checkmarx IDE Plugins at #5 for ide code security plugins; Fortify Static Code Analyzer and Checkmarx IDE Plugins have no rubric score yet (facts researched, not yet scored), so the checks below decide.

Checkmarx IDE Plugins offers security analysis; Fortify Static Code Analyzer doesn't publish it.

Fortify Static Code Analyzer is the better fit for mid-market and enterprise security teams. Checkmarx IDE Plugins is the better fit for enterprises already using Checkmarx services.

  • Fortify Static Code Analyzer fits best

    Mid-market and enterprise security teams

  • Checkmarx IDE Plugins fits best

    Enterprises already using Checkmarx services

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. It never changes our verdict. How we rank.

Side by side

Feature Fortify Static Code Analyzer —/10 Visit ↗ Checkmarx IDE Plugins —/10 Visit ↗
At a glance
Editor score — —
Ranking #4 in IDE Code Security Plugins #5 in IDE Code Security Plugins
Best for Mid-market and enterprise security teams Enterprises already using Checkmarx services
Pricing model Paid Paid
Starting price Not published Not published
Free plan Not published Not published
Free trial — —
Deployment Self-hosted Desktop
Built for Mid-market, Enterprise Mid-market, Enterprise
Features Fortify Static Code Analyzer 0/4 · Checkmarx IDE Plugins 1/4
Security analysis Not published ✓ (best)
Taint analysis Not published Not published
Code quality checks Not published Not published
In-IDE fixes Not published Not published
Specs
IDE coverage Not published Broad
Languages supported Not published Not published
Our review
Pros
  • Analyzes source code and compiled artifacts with dataflow and control-flow tracing
  • Supports custom analysis rules, prioritization, and remediation guidance
  • Connects with IDEs and CI/CD or build pipelines
  • Launch Checkmarx security scans from supported IDEs
  • Review findings and their source locations alongside code
  • Bring security checks into developer workflows
Cons
  • Licensing is handled through sales rather than public pricing
  • Requires a self-hosted deployment
  • Listed support channel is documentation
  • Depends on Checkmarx services configured by the organization
  • Not positioned as a standalone code editor or independently priced tool
  • Commercial access and pricing are handled through Checkmarx sales
Our verdict

Fortify Static Code Analyzer is OpenText’s self-hosted static application security testing product. It analyzes source code and compiled artifacts to identify security vulnerabilities, including in Java and other supported languages.…

Read the review →

For development teams whose organizations use Checkmarx application-security services, Checkmarx IDE Plugins bring scan initiation and findings into supported development environments. Developers can start scans from an IDE and review…

Read the review →
  1. Fortify Static Code AnalyzerIDE Code Security Plugins —Pricing on request
  2. Checkmarx IDE PluginsIDE Code Security Plugins —Pricing on request

Strengths and trade-offs

  • Fortify Static Code Analyzer — where it wins

    • Analyzes source code and compiled artifacts with dataflow and control-flow tracing
    • Supports custom analysis rules, prioritization, and remediation guidance
    • Connects with IDEs and CI/CD or build pipelines

    Where it doesn't

    • Licensing is handled through sales rather than public pricing
    • Requires a self-hosted deployment
    • Listed support channel is documentation
  • Checkmarx IDE Plugins — where it wins

    • Launch Checkmarx security scans from supported IDEs
    • Review findings and their source locations alongside code
    • Bring security checks into developer workflows

    Where it doesn't

    • Depends on Checkmarx services configured by the organization
    • Not positioned as a standalone code editor or independently priced tool
    • Commercial access and pricing are handled through Checkmarx sales
  • Fortify Static Code Analyzer—/10 · Pricing on request

    Self-hosted code analysis with custom rules, IDE feedback, and CI/CD integration.

    Visit OpenTextFull verdict →
  • Checkmarx IDE Plugins—/10 · Pricing on request

    A way for Checkmarx customers to launch scans and review findings in supported IDEs.

    Visit CheckmarxFull verdict →

More comparisons

Reviewed by iTechGuides Editors · Editorial team · Updated Sep 2026