shouldiuse.io

Categories

VERDICT

Should I use Parasoft?

Select Language English Français Deutsch Español - parasoft.com

Depends. Buy if you ship safety-critical or embedded C/C++ and need certified static analysis, API testing, and virtualization at enterprise scale. Skip if you are a small team wanting simple, affordable test tooling with transparent pricing.

Confidence

Medium. Based on 15+ public sources; many review snippets truncated, limiting quote extraction.

Ratings

  • Value for money
  • Ease of useNo usability evidence in sources
  • Feature depth
  • Support qualityNo direct support-quality evidence found
  • Security posture

Pricing

Not public — request a quote

Enterprise licensing

ModelQuote-only
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Embedded C/C++ teams
  • Safety-critical industries (aerospace, defense, automotive)
  • Compliance-first SAST buyers
  • Enterprise CI/CD pipelines

Not for

  • Startups and small teams — enterprise pricing, enterprise process
  • Anyone wanting self-serve, transparent pricing
  • Web-only teams needing lightweight browser testing
  • Solo devs or hobby projects

Gotchas - check before you buy

high

Log4j CVE-2021-44228 affected DTP, C/C++test, Selenic; patched December 2021

medium

Quote-only pricing; expect enterprise negotiation, no self-serve option

medium

Jenkins Parasoft plugins had CVE-2020-2132 and an information disclosure

medium

Ecosystem lock-in: DTP reporting and rules tie you into the suite

Pros and cons

Pros

  • Broad suite: static analysis, API testing, service virtualization
  • Endorsed in embedded dev communities for C/C++ static analysis
  • Compliance-first positioning for critical software
  • Proven at aerospace/defense firms: Thales, Leonardo case studies
  • CI-friendly: official Jenkins plugin and tool integrations

Cons

  • No public pricing; everything behind sales quotes
  • Cost concerns raised publicly by jtest users
  • Flagship C/C++test has only 12 G2 reviews
  • Many separately licensed products complicate purchasing

Sources & method

Analyzed 10/02/2026 - 14 sources - Publishes a product security page and advisories; historical log4j and Jenkins plugin issues, since patched.

official x4review x6security x3news x1
  • Log4j (CVE-2021-44228) exposure, DTP, C/C++test, and Selenic were affected by Log4Shell; Parasoft released fixes December 13, 2021.
  • CVE-2020-2132 — Jenkins Parasoft Environment Manager plugin, Vulnerability disclosed in the Jenkins plugin package:parasoft-environment-manager.
  • Jenkins Parasoft Findings Plugin information disclosure, IBM X-Force tracked an information disclosure vulnerability in the Jenkins Parasoft Findings plugin.

Key stats

  • Value for money: 2/5

    Rating

  • Not public — request a quote

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 2/5. Quote-only; user cost questions on PeerSpot
  • Ease of use. No usability evidence in sources
  • Feature depth: 5/5. SAST, API testing, virtualization, compliance certifications in one suite
  • Support quality. No direct support-quality evidence found
  • Security posture: 3/5. Publishes advisories; past log4j exposure patched
  • 45 G2 reviews across the Parasoft suite
  • 12 C/C++test G2 reviews flagship product's review depth
  • Quote-only Pricing model no public price list

Pricing

Enterprise licensing

Not public — request a quote

  • Per-product licensing (C/C++test, SOAtest, Virtualize, Selenic)
  • ROI calculators provided
  • Contact-sales sales motion

Security

Publishes a product security page and advisories; historical log4j and Jenkins plugin issues, since patched.

  • Log4j (CVE-2021-44228) exposureDTP, C/C++test, and Selenic were affected by Log4Shell; Parasoft released fixes December 13, 2021.11
  • CVE-2020-2132 — Jenkins Parasoft Environment Manager pluginVulnerability disclosed in the Jenkins plugin package:parasoft-environment-manager.12
  • Jenkins Parasoft Findings Plugin information disclosureIBM X-Force tracked an information disclosure vulnerability in the Jenkins Parasoft Findings plugin.13

What users say

Embedded developers on Reddit recommend Parasoft for C/C++ static analysis, while enterprise review coverage is broad but thin (12 G2 reviews for the flagship).

“Seconding Parasoft”
Reddit, r/embedded

Alternatives

Compare Parasoft with each alternative.

  • VectorCAST

    Head-to-head rival for embedded safety-critical testing

  • Coverity (Synopsys)

    Enterprise SAST competitor of similar scope

  • Klocwork

    C/C++ static analysis alternative

    Parasoft vs Klocwork
  • SonarQube

    Guess: cheaper SAST for teams without compliance requirements

Companies that use it

  • Thales14
  • Leonardo
  • Lockheed Martin
  • University of Hull
Full analysis

Based on 15+ public sources; many review snippets truncated, limiting quote extraction.

Compliance-first enterprise testing suite for embedded/regulated teams — powerful, quote-priced, overkill for small projects.

Methodology

Based on 15+ public sources; many review snippets truncated, limiting quote extraction.

Sources

  1. official
  2. official
  3. official
  4. review
  5. review
  6. review
  7. review
  8. review
  9. review
  10. news
  11. security
  12. security
  13. security
  14. Thales case studyparasoft.com
    official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.