The Checkmarx One Eclipse plugin enables you to import results from a Checkmarx One scan directly into your IDE.
Explore the docs »
Marketplace »
Table of Contents
Checkmarx continues to spearhead the shift-left approach to AppSec by bringing our powerful AppSec tools into your IDE. This empowers developers to identify vulnerabilities and remediate them as they code. The Checkmarx One Eclipse plugin integrates seamlessly into your IDE, enabling you to access the full functionality of your Checkmarx One account (SAST, SCA, IaC, and Secret Detection) directly from your IDE. This plugin contains two separate capabilities:
-
Checkmarx One Platform
-
Checkmarx Developer Assist
This tool enables Checkmarx One users to access the full functionality of your Checkmarx One account (SAST, SCA, IaC, and Secret Detection) directly from your IDE. You can run new scans, or import results from scans run in your Checkmarx One account. Checkmarx provides detailed info about each vulnerability, including remediation recommendations and examples of effective remediation. The plugin enables you to navigate from a vulnerability to the relevant source code, so that you can easily zero-in on the problematic code and start working on remediation.
- Access the full power of Checkmarx One (SAST, SCA, IaC, and Secret Detection) directly from your IDE
- Run a new scan from your IDE even before committing the code, or import scan results from your Checkmarx One account
- Provides actionable results including remediation recommendations. Navigate from results panel directly to the highlighted vulnerable code in the editor and get right down to work on the remediation.
- Group and filter results
- Triage results (by adjusting the severity and state and adding comments) directly from the Eclipse console (currently supported for SAST and IaC Security)
- Links to Codebashing lessons
-
An Eclipse installation, version 2020-09 or above.
Supported platforms: Windows, Mac, Linux/GTK
-
You have an API key for your Checkmarx One account. To create an API key, see Generating an API Key
In order to use this integration for running an end-to-end flow of scanning a project and viewing results with the minimum required permissions, the API Key or user account should have the role
plugin-scanner. Alternatively, they can have at a minimum the out-of-the-box composite roleast-scanneras well as the IAM roledefault-roles.
-
Verify that all prerequisites are in place.
-
Install the Checkmarx One plugin and configure the settings as described here.
To see how you can use our tool, please refer to the Documentation.
Developer Assist is an agentic AI tool that delivers real-time context-aware prevention, remediation, and guidance to developers inside the IDE.
- An advanced security agent that delivers real-time context-aware prevention, remediation, and guidance to developers from the IDE.
- Real-time scanners identify risks as you code.
- ASCA, a lightweight source code scanner, enables developers to identify secure coding best practice violations in the file that they are working on as they code.
- Specialized real-time scanners identify vulnerable open source packages and container images, as well as exposed secrets and IaC risks.
- MCP-based agentic AI remediation.
- AI-powered explanation of risk details.
- Reduce noise by marking false positives as ignored.
- Eclipse installation, version 2025-06 and above with GitHub Copilot
- A Checkmarx One account with a Checkmarx One Assist license. Also, Dev Assist must be activated for your tenant account in the Checkmarx One UI under Global Settings > Plugins page. This must be done by an account admin.
You will need to provide an API key for your Checkmarx One account. To create an API key, see Generating an API Key
-
Verify that all prerequisites are in place.
-
Install the Checkmarx One plugin and configure the settings as described here.
-
After authentication, in the welcome screen, select the checkbox next to "Code Smarter with Checkmarx One Assist".
To see how you can use our tool, please refer to the Documentation.
GIF - AI Remediation with Developer Assist
We appreciate feedback and contribution to the ECLIPSE PLUGIN! Before you get started, please see the following:
Distributed under the Apache 2.0. See LICENSE for more information.
Checkmarx - Integrations Team
Project Link: https://github.com/Checkmarx/ast-eclipse-plugin
Find more integrations from our team here
© 2026 Checkmarx Ltd. All Rights Reserved.
