Vigilance vs Checkmarx

Checkmarx. Scans the code you write for flaws, and covers open-source parts and more. Vigilance does a different job. It finds the update that gained a hidden power, before you install it.

Updated 5 Oct 2026

Start Free See Pricing

The Catch Checkmarx Cannot Make

Checkmarx scans the code you write for flaws. Vigilance does not read your source for flaws. It does a different job. Vigilance keeps no list. It compares the version you trust with the version you install. It reports any file that can suddenly do more.

A real one: axios, March 2026

axios is one of the most-installed packages on the internet. In release 1.14.1, its package.json gained a hidden install step. That step pulls down a remote-control program. No CVE existed for it, so a list of known bugs had nothing to match. One command sees it:

vigi diff --old ./axios-1.14.0 --new ./axios-1.14.1

HEADS UP. 1 file changed. package.json can now run a hidden helper on install and reach the network.

Run both. Checkmarx scans the code you wrote. Vigilance reads the dependency that just changed underneath it. See them side by side below.

What Checkmarx Does Well

Checkmarx One is a full application security suite. Its site lists static analysis (SAST), software composition analysis (SCA) and dynamic testing (DAST). It also lists API, infrastructure-as-code, container and supply chain security, malicious package protection and application security posture management (ASPM). It presents these as one platform with one view of risk. Source: the Checkmarx site.

SAST is the core of this suite, and it is a different job from Vigilance. A SAST tool reads your own source code and looks for flaws such as injection, unsafe handling of input and weak cryptography. A team that writes software needs this, and Vigilance does not do it.

The suite also helps a security team manage the work. A central view of findings across code, dependencies and cloud setup lets one team set policy for many development teams.

Where It Falls Short

Checkmarx and Vigilance do not do the same job, and the plain answer is that Vigilance is not a replacement. Vigilance does not scan source code for flaws. It does not find an injection bug in your application. If you need SAST, buy a SAST tool.

Where the two meet is the dependencies you pull in. Checkmarx lists malicious package protection and SCA for them. Vigilance reads the update itself, compares it with the version you trust, and reports the file that gained a capability. It does this for any package, installer or container on your machine.

Checkmarx has no list price. It prices per package and tailors the quote to your environment, and it offers no self-serve free trial. A small team that wants to try the product on its own repository first will not find that path.

Checkmarx covers a very wide area. A team that only wants to know whether an update changed what a file can do pays for a large suite. It uses a small part of it.

Feature Comparison

Checkmarx scans the code you write, and Vigilance reads the updates you install. The table shows the split.

Question Checkmarx Vigilance
Finds flaws in the code you write (SAST) Yes No. Vigilance is not a SAST tool.
Finds known bugs in your dependencies Yes No
Lists malicious package protection Yes No. It compares file versions and keeps no list.
Spots a file that can do more than the version before Not described Yes
Covers a vendor file drop, an installer or a zip Not described Yes
Offers DAST, API and infrastructure-as-code checks Yes No
Has a free plan or a self-serve trial No self-serve trial listed Yes, up to 50 machines
Runs on your own machine, not just in the pipeline Some Yes

When Checkmarx Is the Better Fit

Choose Checkmarx if you write software and must find flaws in your own code before release. This is the main reason to buy it, and Vigilance cannot do it.

Choose Checkmarx if an auditor or a customer asks for SAST and DAST evidence. It also fits a company that wants SAST, SCA and API security from one vendor under one policy.

Choose Checkmarx if you have a security team that will tune rules and triage findings every week. The suite gives that team a lot to work with.

Choose Vigilance in addition when the risk is an update to something you did not write. Do not choose Vigilance in place of Checkmarx for source code review.

Checkmarx also fits a company that wants self-hosted deployment. Its pricing page lists SaaS and self-hosted models.

SAST and Update Checks Are Different Jobs

SAST reads source code you control. It asks whether your own logic has a flaw. The input is your repository.

Vigilance reads the files of software that arrives from outside. It asks whether the new version can do something the old version did not do. The input is two versions of one thing, such as an npm package, an installer or a container image.

A flaw in your code and a hidden change in a dependency are two separate risks. A tool for one does not cover the other. The usual answer is to run a SAST tool for the first and Vigilance for the second.

Where the Two Meet

Both touch your dependencies. Checkmarx SCA and malicious package protection look at the packages your project uses. Vigilance looks at what each update changes.

If your team already holds Checkmarx, keep it. Add Vigilance at the step where a dependency update is merged. Compare the old and the new files and read the line it prints. On a normal update it prints nothing.

If you mainly install software, you have little source code to scan. A fleet of machines or a set of vendor tools is an example. Vigilance then covers the risk that matters most to you, which is a trusted file that gains a new power.

What to Ask Before You Choose

Ask whether you write the code you ship. If you do, SAST is a standard need, and a SAST tool is the right buy. If you only install software, SAST has little to scan.

Ask which standards your customers cite. Many ask for static and dynamic testing evidence. Checkmarx supplies that evidence, and Vigilance does not.

Ask who will tune the rules. A SAST suite needs a person to set policy and handle false positives. Make sure that person exists before you sign.

Ask how you check an update to a dependency. SAST does not read the new version for new behaviour. A file-level compare covers that case, and Vigilance does it.

Pricing

Checkmarx has no public list price. Its pricing page says Checkmarx One is priced per package and tailored to your environment. Price depends on the modules you pick, whether you run SaaS or self-hosted, and the size of your team. It offers no self-serve free trial. It offers a personalised demo, and says an expert follows up, typically within one business day. Source: Checkmarx pricing.

Vigilance has a Free plan at $0 with the full scanner for up to 50 machines. Free needs a network and sends a signed report of hashes and capabilities only. A name, an email or a file is sent only if you opt in, and each one needs its own yes. Pro works with no network at all. It is flat for the whole company, starts at $999 CAD a month, and the price steps with company size, not with the machine count.

Which One Do You Need?

Checkmarx finds flaws across your code. Vigilance finds new behaviour in the software that arrives. They do different jobs, and many teams that write code need both.

Read how the two sit among other options in software supply chain security tools, or see real attacks that Vigilance replays.

Known Risk versus New Risk

Known risk

A bug or a bad package someone already reported, with a name and a number. Most tools work here.

New risk

A file that gained a capability it never had, that no report covers yet. Vigilance works here.

Common Questions

Is Vigilance a Checkmarx alternative?

Not for SAST. Vigilance does a different job. It shows the file that gained a new capability in software you install. If you need to scan your own source code for flaws, Checkmarx is the right kind of tool.

What does Vigilance do that Checkmarx does not?

Vigilance compares the version you trust with a new one, including a vendor installer, a zip or a container, and reports the file that can now do more.

What does Checkmarx do that Vigilance does not?

Checkmarx scans your source code for flaws and offers SCA, DAST, API security and more in one suite. Vigilance does none of these.

How much does Checkmarx cost?

Checkmarx has no public list price. It quotes per package, based on modules, deployment and team size. It offers a personalised demo and no self-serve free trial.

Does Vigilance need the internet or a cloud account?

The Free plan runs online. Pro runs fully offline, with no cloud account.

Try It on Your Own Software.

Show it the version you run today and the one you are about to install.

Download Vigilance Talk to Us

Talk to Us

A question, a pilot, or a bigger fleet? Send a note. It reaches a person.