checkmarx.com ↗ · required email domain for this vendor's users
Headquartered in IsraelHeadquarters countrySourced only from this vendor's own published headquarters address (schema.org structured data on their site) — never guessed from domain TLD. Source ↗
3 of 5 independent trust signals established
Checkmarx has 3 dimensions with established evidence. The rest have not been confirmed yet.
Not yet established: Independently verified · Disclosure posture
Has anyone other than the vendor confirmed this?
1 independent source(s) corroborate this vendor's claims.
Is this a real, durable business?
Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.
The platform admin controls the formula's weights.
Integrates with: AccuKnox ↗, Autonomous Security ↗, Black Duck ↗, Embed Security ↗, Endor Labs ↗, JFrog ↗, Journey ↗, Microsoft ↗
No buyer reviews yet.
No ratings in this window yet.
Application security testing platform. AI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →
Certifications & compliance claimsWhat the tiers meanVerified in a public registry — we confirmed this against an authoritative public registry (FedRAMP Marketplace, CSA STAR) and re-check it by the registry's own identifier. Stated by the vendor — the vendor says it on a page they control; a sourced claim about themselves, not an independent check. Detected on a page — found during automated enrichment, neither registry-confirmed nor stated on the vendor's own site.
Some certifications have no public registry at all — SOC 2 and HIPAA among them. For those, “not registry-verified” is not a shortfall and means nothing about the vendor.
Detected on a page
Some of these (SOC 2, HIPAA and similar) have no public registry, so no one can independently verify them — that is a fact about the framework, not about this vendor.
Security headers (3/5) — checked 8/13/2026
Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting in a stored cross-site scripting (XSS) v…
Datasheets, whitepapers, and case studies found on checkmarx.com by the enrichment loop. Links open the original documents on the vendor's own site.
Drawn from this vendor's own public materials and authored to keep category questionnaires balanced. Gaps reflect capabilities not emphasized in public materials, not rankings.
Strengths: Broad AppSec coverage (SAST, SCA, API, IaC, container, ASPM) built for enterprise scale.
Gaps: Breadth can add configuration/tuning overhead, and result volume needs strong prioritization.
Product information on this page is auto-generated by 0-Doubt from public sources and not yet confirmed by the vendor or an independent analyst, unless an item is individually labelled otherwise. How trust works →
How long this vendor has been operating, and who stands behind them.
What do they do when something goes wrong?
What their public record shows about handling vulnerabilities and outages.
Do they tell you the awkward things unprompted?
How much this vendor volunteers before you have to ask.
Are they still shipping, or coasting?
Whether this vendor is visibly still building.
Integrated by: AccuKnox, Bearer, Black Duck, Blink Ops, CloudDefense.AI, Conviso, Corgea, Cycode, Faradaysec, Jit, JupiterOne, Konvu, Leen, Mend, NopSec, Ox Security, Pentera, PlexTrac, Reco, Seal Security, Seemplicity, Semgrep, Snyk, Strobes Security, Sysdig, Tenzir, UncommonX, Wiz, ZeroPath
Infrastructure & transparency signals
Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified webserver using attacker-specified credentia…
A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials I…
Checkmarx CxSAST (formerly CxSuite) before 7.1.8 allows remote authenticated users to bypass the CxQL sandbox protection mechanism and execute arbitrary C# code by asserting the (1) System.Security.Pe…