sonarsource.com ↗ · required email domain for this vendor's users
1 of 5 independent trust signals established
Sonar has one dimension with established evidence. The rest have not been confirmed yet.
Not yet established: Independently verified · Operating durability · Disclosure posture · Momentum
Has anyone other than the vendor confirmed this?
Nothing here has been confirmed by an independent third party yet.
Is this a real, durable business?
How long this vendor has been operating, and who stands behind them.
What do they do when something goes wrong?
What their public record shows about handling vulnerabilities and outages.
Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.
The platform admin controls the formula's weights.
Integrated by: FirstWave Cloud Technology, JFrog
No buyer reviews yet.
No ratings in this window yet.
Code quality and static analysis (SonarQube). AI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →
Security headers (5/5) — checked 8/13/2026
Infrastructure & transparency signals
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the …
A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenk…
Datasheets, whitepapers, and case studies found on sonarsource.com by the enrichment loop. Links open the original documents on the vendor's own site.
Drawn from this vendor's own public materials and authored to keep category questionnaires balanced. Gaps reflect capabilities not emphasized in public materials, not rankings.
Strengths: Deep code quality plus security (SAST/SCA) with a mature IDE, server, and cloud footprint.
Gaps: Heritage is code quality; supply-chain and runtime concerns are less central than code analysis.
Product information on this page is auto-generated by 0-Doubt from public sources and not yet confirmed by the vendor or an independent analyst, unless an item is individually labelled otherwise. How trust works →
Do they tell you the awkward things unprompted?
How much this vendor volunteers before you have to ask.
Are they still shipping, or coasting?
Whether this vendor is visibly still building.
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allow…
Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in …
Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file s…
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from …