From the experiment

Do coding agents recommend Checkmarx One?

Checkmarx One is the most chosen security platform, taking 33% of 118 judged security platforms sessions.

Published September 28, 2026 Updated September 30, 2026 Read as Markdown

Checkmarx One is the most chosen security platform, taking 33% of 118 judged security platforms sessions. It was also raised as a candidate in 36 further sessions without being chosen.

This page reports what happened when Claude Code, Codex, Grok Build CLI and Muse Code had to solve a problem in security platforms inside a realistic codebase. Not what a chat assistant says about Checkmarx One. What an agent actually chose.

The numbers

CategorySecurity platforms
Sessions in the category118
Sessions where Checkmarx One was chosen39
Install share33%
Rank in category1 of 19
Codebases it won in5
Raised as a candidate, not chosen36
Chosen when considered52%
Sitecheckmarx.com

By agent

Claude Code, Codex and Grok Build CLI land within 13 points of each other on Checkmarx One, which is closer than most products in this experiment manage. Muse Code ran fewer than 30 sessions here, too few to compare.

AgentSessionsChose Checkmarx OneShare
Claude Code301137%
Codex301550%
Grok Build CLI301240%
Muse Code2814%

What Checkmarx One was up against

The full ranking in security platforms, from the same sessions:

#ProductRuns wonShare
1Checkmarx One (this page)3933%
2GitLab Security2219%
3Snyk1916%
4Aikido Security98%
5HCL AppScan54%
6GitHub Advanced Security + ZAP43%
7GitHub Advanced Security + Microsoft Defender for Cloud33%
8DefectDojo + Gitleaks + Semgrep + Trivy + ZAP33%

What this means

Leading a category is a position to defend rather than a result to celebrate. In our data, leaders lose ground in exactly two situations: when the person asking is an enterprise buyer with procurement constraints, and when a competitor's documentation is easier for an agent to integrate correctly.

The defence is unglamorous. Keep the quickstart running. Keep the version current on the page. Keep the names aligned. Stay in the templates.

Where these numbers come from

The 118 sessions in security platforms are part of a published set of 15,000, run with real coding agents inside realistic codebases and judged blind. The full method is on one page: how we measured this.

Every security platforms run can be replayed on the board.

If you work on Checkmarx One: the judge recorded a reason for every session where it was raised and passed over. Those reasons are in the transcripts.

<!-- generated by scripts/write-data-pages.mjs -->

Common questions

Do coding agents recommend Checkmarx One?

Yes. Checkmarx One was chosen in 39 of the 118 judged sessions in security platforms, a 33% install share, ranking first in its category.

Does Claude Code recommend Checkmarx One?

In 11 of the 30 sessions in security platforms run with Claude Code, which is 37%.

Do different coding agents treat Checkmarx One differently?

Yes, and by a wide margin. Codex chose it in 50% of its runs and Claude Code in 37%.

How was this measured?

Real coding agents at pinned versions were run in sandboxes inside 92 realistic codebases and asked to solve real tasks. A simulated project owner approved or questioned each recommendation before any code was written, and a judge from a model family that builds none of the agents read every session blind.

How often is Checkmarx One considered but not chosen?

It was raised as a candidate in 36 sessions without being chosen, and chosen in 39. That is a 52% conversion from considered to chosen.

Where this comes from

Armature ran 15,000 judged sessions with Claude Code, Codex, Cursor, Grok Build CLI and Muse Code inside 92 realistic codebases, and published every run. The numbers on this page come from that work.

Read next

All library pages