# Do coding agents recommend Checkmarx One?

> Checkmarx One is the most chosen security platform, taking 33% of 118 judged security platforms sessions.

Source: https://armature.tech/library/do-coding-agents-recommend-checkmarx-one
Published: 2026-09-28 · Updated: 2026-09-30
Publisher: Armature, Inc. (https://armature.tech)

---

> Checkmarx One is the most chosen security platform, taking 33% of 118 judged security platforms sessions. It was also raised as a candidate in 36 further sessions without being chosen.

This page reports what happened when Claude Code, Codex, Grok Build CLI and Muse Code had to solve a problem in security platforms inside a realistic codebase. Not what a chat assistant says about Checkmarx One. What an agent actually chose.

## The numbers

| | |
| --- | --- |
| Category | Security platforms |
| Sessions in the category | 118 |
| Sessions where Checkmarx One was chosen | 39 |
| Install share | 33% |
| Rank in category | 1 of 19 |
| Codebases it won in | 5 |
| Raised as a candidate, not chosen | 36 |
| Chosen when considered | 52% |
| Site | checkmarx.com |

## By agent

Claude Code, Codex and Grok Build CLI land within 13 points of each other on Checkmarx One, which is closer than most products in this experiment manage. Muse Code ran fewer than 30 sessions here, too few to compare.

| Agent | Sessions | Chose Checkmarx One | Share |
| --- | --- | --- | --- |
| Claude Code | 30 | 11 | 37% |
| Codex | 30 | 15 | 50% |
| Grok Build CLI | 30 | 12 | 40% |
| Muse Code | 28 | 1 | 4% |

## What Checkmarx One was up against

The full ranking in security platforms, from the same sessions:

| # | Product | Runs won | Share |
| --- | --- | --- | --- |
| 1 | Checkmarx One **(this page)** | 39 | 33% |
| 2 | GitLab Security | 22 | 19% |
| 3 | Snyk | 19 | 16% |
| 4 | Aikido Security | 9 | 8% |
| 5 | HCL AppScan | 5 | 4% |
| 6 | GitHub Advanced Security + ZAP | 4 | 3% |
| 7 | GitHub Advanced Security + Microsoft Defender for Cloud | 3 | 3% |
| 8 | DefectDojo + Gitleaks + Semgrep + Trivy + ZAP | 3 | 3% |

## What this means

Leading a category is a position to defend rather than a result to celebrate. In our data, leaders lose ground in exactly two situations: when the person asking is an enterprise buyer with procurement constraints, and when a competitor's documentation is easier for an agent to integrate correctly.

The defence is unglamorous. Keep the quickstart running. Keep the version current on the page. Keep the names aligned. Stay in the templates.

## Where these numbers come from

The 118 sessions in security platforms are part of a published set of 15,000, run with real coding agents inside realistic codebases and judged blind. The full method is on one page: [how we measured this](/library/how-we-measured-this).

Every security platforms run can be replayed on [the board](/leaderboards/security-platforms).

If you work on Checkmarx One: the judge recorded a reason for every session where it was raised and passed over. Those reasons are in the transcripts.

<!-- generated by scripts/write-data-pages.mjs -->

## Common questions

### Do coding agents recommend Checkmarx One?

Yes. Checkmarx One was chosen in 39 of the 118 judged sessions in security platforms, a 33% install share, ranking first in its category.

### Does Claude Code recommend Checkmarx One?

In 11 of the 30 sessions in security platforms run with Claude Code, which is 37%.

### Do different coding agents treat Checkmarx One differently?

Yes, and by a wide margin. Codex chose it in 50% of its runs and Claude Code in 37%.

### How was this measured?

Real coding agents at pinned versions were run in sandboxes inside 92 realistic codebases and asked to solve real tasks. A simulated project owner approved or questioned each recommendation before any code was written, and a judge from a model family that builds none of the agents read every session blind.

### How often is Checkmarx One considered but not chosen?

It was raised as a candidate in 36 sessions without being chosen, and chosen in 39. That is a 52% conversion from considered to chosen.

## Read next

- [How to get picked for security platforms by coding agents](https://armature.tech/library/security-platforms-coding-agents-playbook) (Markdown: https://armature.tech/library/security-platforms-coding-agents-playbook.md)
- [Do coding agents recommend GitLab Security?](https://armature.tech/library/do-coding-agents-recommend-gitlab-security) (Markdown: https://armature.tech/library/do-coding-agents-recommend-gitlab-security.md)
- [Do Claude Code, Codex and Cursor pick the same tools?](https://armature.tech/library/do-claude-code-and-codex-agree) (Markdown: https://armature.tech/library/do-claude-code-and-codex-agree.md)

---

Armature helps software products get discovered and used by coding agents.
Service: https://armature.tech/discoverability · Results: https://armature.tech/leaderboards/sectors · Contact: contact@armature.tech
