All comparisons

Vigilance vs Checkmarx

Checkmarx. A cloud platform that scans your code and open-source parts for known bugs.

Vigilance. Runs on your own machine and names the one file that gained a new power.

Vigilance as a Checkmarx alternative

Vigilance is a Checkmarx alternative that runs on your own machine. It names the one file that gained a new power, before you trust an update. Below, a plain table sets the two side by side.

Side by side

Question Checkmarx Vigilance
Finds known bugs in your code and dependencies Yes No
Flags a brand-new bad package by what it can do Some Yes
Spots a file that can do more than the version before No Yes
Covers a vendor file drop, an installer or a zip No Yes
Runs with no cloud account No Yes
Runs on your own machine, not just in the pipeline Some Yes

Which one do you need?

Checkmarx finds known bugs across your code. Vigilance finds new behaviour no report covers yet.

Known risk versus new risk

Known risk

A bug or a bad package someone already reported, with a name and a number. Most tools work here.

New risk

A file that gained a power it never had, that no report covers yet. Vigilance works here.

Common questions

Is Vigilance a Checkmarx alternative?

Yes, for one job. Vigilance names the file that gained a new power, on your own machine. Many teams run it next to Checkmarx.

What does Vigilance do that Checkmarx does not?

Vigilance can spot a file that can do more than the version before, and on Pro run with no internet at all.

What does Checkmarx do that Vigilance does not?

Checkmarx finds known bugs that already have a name and a number. Vigilance does not.

Does Vigilance need the internet or a cloud account?

The Free plan runs online. Pro runs fully offline, with no cloud account.

Try it on your own software.

Show it the version you run today and the one you are about to install.

See pricing Talk to us

Talk to us

A question, a pilot, or a bigger fleet? Send a note. It reaches a person.