Comparison
Korthex vs SonarQube: Crypto Inventory vs Code Quality
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
SonarQube is a capable code-quality and SAST platform - bugs, code smells, coverage gates, taint analysis for injection rules in the commercial editions, and configuration rules that flag weak crypto parameters and TLS versions. Korthex is not a code-quality tool. It specializes in cryptography: a cross-engine inventory, post-quantum readiness scoring, a migration plan, and offensive verification.
Axis by axis on cryptography: cross-engine attack-paths vs per-project issues; cryptographic value tracking across 16 import hops vs injection-focused taint analysis; key-provenance classification vs parameter-level configuration rules; CBOM-PQC export vs no cryptographic inventory; a dependency-ordered migration plan vs finding-level guidance; and offensive verification against NIST Known-Answer Tests. Most teams run both: SonarQube as the quality gate and Korthex for the cryptographic inventory. Comparison based on public vendor documentation as of 2026-07-10.
How Korthex and SonarQube differ, axis by axis
| Axis | Korthex | SonarQube |
|---|---|---|
| Cross-engine attack-paths | Merges code, config, TLS/PKI, database and git findings into one reachability-scored chain | Per-project quality and security issues; no cryptographic attack-path correlation |
| Dataflow across import hops | Follows the cryptographic value across 16 import hops | Taint analysis for security-injection rules (commercial editions); not crypto-value tracking |
| Taint-classified key sources | Taint-classifies where keys and secrets originate before grading the finding | Configuration rules flag weak crypto parameters and TLS versions; no key-provenance classification |
| Cross-file crypto clusters | Union-find crypto clustering across files | No cryptographic clustering |
| CBOM-PQC export | Cryptographic Bill of Materials with per-finding post-quantum bucket (CycloneDX / SARIF / JSON / PDF / .kxr) | No cryptographic inventory export |
| Migration plan + simulation | Topologically-ordered plan with file:line, replacement algo, deadline, effort hours, dependency order | Finding-level remediation guidance; no cryptographic migration plan |
| Offensive verification | Extracted crypto graded by emulation against NIST KAT to prove weak or broken, plus side-channel timing verdict | Static detection; no emulation-based proof of cryptographic weakness |