Software Alternatives & Reviews

TOP 40 Static Code Analysis Tools (Best Source Code Analysis Tools)

Raxis RIPS PVS-Studio Kiuwan Code Security Embold.io Visual Expert Veracode Micro Focus Fortify On Demand
  1. 1
    Raxis is a cybersecurity company with ethical hacking (red team) experience. Years of penetration testing and general mischief-making have taught us that there’s always a way in. We’ll find it — and help you keep the bad guys out.
    Raxis communicates throughout to be sure your input is used within the code review, and they provide a report that details each finding with screenshots and remediation advice. A high-level summary that can be provided to management and a debriefing call are also included.

    #Cyber Security #Penetration Testing #Red Team Attacks

  2. 2
    Static code analysis tool for web application security
    It supports major frameworks, SDLC integration, relevant industry standards, and can be deployed as a self-hosted software or used as software-as-a-service. With its high accuracy and no false-positive noise, RIPS is the ideal choice for analyzing Java and PHP applications.

    #Security #Code Analysis #Travel

  3. PVS-Studio is a useful piece of software for detecting problems in source code. The software examines program codes written in C, C++, and C# for any problems that might prohibit the code from functioning properly.
    PVS-Studio is a tool for detecting bugs and security weaknesses in the source code of programs, written in C, C++, C#, and Java. It works in Windows, Linux, and macOS environment.

    #Code Analysis #Code Coverage #Code Review 10 social mentions

  4.  Learn how Kiuwan's Code Security (SAST) identifies and remediates cyber threats with a DevSecOps approach in a collaborative environment, with seamless integration in your SDLC.

    #Code Analysis #Code Review #Web Application Security

  5. Peer Code Review

    #Code Analysis #Code Review #Code Coverage 3 social mentions

  6. 6
    r

    reshift

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  7. 7
    ECS

    Empear Code Scene

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  8. An all-in-one Static Code Analysis + SAST tool for PowerBuilder, Oracle and SQL Server

    #Code Analysis #Code Review #Code Coverage

  9. Veracode's application security software products are simpler and more scalable to increase the resiliency of your application infrastructure.
    Veracode is a static analysis tool that is built on the SaaS model. This tool is mainly used to analyze the code from a security point of view.

    #Code Analysis #Web Application Security #Code Review

  10. Complete application security as a service (AppSec SaaS) solution with SAST, DAST, IAST, RASP, SCA (open source security), and developer security training.

    #Code Analysis #Code Review #Web Application Security

  11. 11
    PSA

    Parasoft Static Analysis

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  12. Find and fix defects in your Java, C/C++ or C# open source project for free
    Coverity Scan is an open-source cloud-based tool. It works for projects written using C, C++, Java C# or JavaScript. This tool provides a very detailed and clear description of the issues which help in faster resolution. A good choice if you are looking for an open-source tool.

    #Code Analysis #Code Coverage #Code Review 4 social mentions

  13. 13
    Record, edit, publish, and host your podcast

    #Business & Commerce #ERP #Mapping And GIS 6 social mentions

  14. CodeSonar, produced by GrammaTech, is source and binary code analysis software that finds critical defects that can crash systems, result in unexpected operations, threaten security, and more.

    #Code Analysis #Web Application Security #Code Coverage

  15. Combines a powerful Code Editor together with an impressive array of static analysis tools that will change the way you work with code.
    Pricing:
    • Paid
    • Free Trial
    Just like its name, this tool lets user UNDERSTAND code by analyzing, measuring, visualizing and maintaining. This allows quick analysis of massive codes. This is one tool that is mainly used by the aerospace and automakers industry. Supports major languages like C/C++, ADA, COBOL, FORTRAN, PASCAL, Python and other web languages.

    #Code Coverage #Code Analysis #Code Quality 1 social mentions

  16. Code Compare is an advanced file and folder comparison tool. Its intuitive interface allows you to merge differing files and folders fast and easily! And it's FREE!
    Pricing:
    • Open Source
    • Freemium
    • Free Trial
    • $69.95 / Annually

    #Code Review #Developer Tools #Software Development

  17. The Clang Static Analyzer is a source code analysis tool that finds bugs in C, C++, and Objective-C...

    #Code Analysis #Code Coverage #Development 7 social mentions

  18. Master Your C and C++ Codebase with Precision and Insight
    Pricing:
    • Freemium
    • Free Trial

    #Code Coverage #Code Analysis #Code Quality 4 user reviews

  19. Klocwork is a static code analysis and SAST tool for C, C++, C#, Java, and JavaScript.

    #Code Analysis #Code Coverage #Code Review

  20. Cppcheck is an analysis tool for C/C++ code. It detects the types of bugs that the compilers normally fail to detect. The goal is no false positives. CppCheckDownload cppcheck for free.
    Pricing:
    • Open Source

    #Code Analysis #Code Coverage #Development 10 social mentions

  21. Perforce Helix QAC is a handy, reliable, and highly rated Static Code Analysis solution that aids you in the process of finding vulnerabilities and problems within your C/C++ code.

    #Development #Tool #Code Analysis

  22. 22
    G

    Goanna

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  23. 23
    MPB

    Mathworks Polyspace Bug Finder

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  24. 24
    S

    Sourcemeter

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  25. 25
    CQA

    ConQAT

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  26. JArchitect is used by developers to measure, understand and improve their Java code quality.

    #Code Coverage #Code Analysis #Code Quality

  27. 27
    OCL

    OCLint.org

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  28. "Watchtower monitors your competition's websites and alerts you to important changes instantly."

    #Productivity #Security #Code Analysis

  29. 29
    OWA

    OWASP Code Crawler

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  30. 30
    OWA

    OWASP Orizon

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  31. 31
    GPC

    Gimpel PC-lint

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  32. 32
    IBM

    IBM Rational Software Analyzer

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  33. 33
    bSE

    bugSeng Eclair

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  34. SonarQube, a core component of the Sonar solution, is an open source, self-managed tool that systematically helps developers and organizations deliver Clean Code.
    Pricing:
    • Open Source
    • Freemium
    • Free Trial
    • $150.0 / Annually
    It is possible to integrate it into Visual Studio, IntelliJ IDEA, and other widespread IDE. The results of the analysis can be imported into SonarQube.

    #Code Analysis #Code Review #Code Coverage 1 social mentions

  35. 35
    R

    Rosecheckers

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  36. 36
    A unofficial Framer for Web desktop app for Mac

    #Code Analysis #Code Coverage #Design Tools

  37. 37
    Semmle analytics platform that provides data-driven software engineering for visibility for every project, location, team and timeframe.

    #Code Coverage #Code Analysis #Code Review

  38. 38

    Pmd

    PMD scans Java source code and looks for potential problems like:
    A tool that helps in analyzing C/C++, Java, C#, RPG and Python codes. Another good thing about this tool is it allows integration with free static checker tools like cppcheck, PMD, FindBugs. Basic Version of this tool is free but it comes with fewer features. Based on the need, you can decide whether the free version satisfies the requirement or not.

    #Code Coverage #Code Analysis #Code Quality

  39. Findbugs is a tool that looks for bugs in Java code. Findbugs finds the bugs by analyzing computer software without actually executing programs. Using this software allows for easy debugging and repairing broken script. Read more about FindBugs.
    Pricing:
    • Open Source
    A tool that helps in analyzing C/C++, Java, C#, RPG and Python codes. Another good thing about this tool is it allows integration with free static checker tools like cppcheck, PMD, FindBugs. Basic Version of this tool is free but it comes with fewer features. Based on the need, you can decide whether the free version satisfies the requirement or not.

    #Code Coverage #Code Analysis #Code Quality 3 social mentions

  40. HCL Software Site

    #Security & Privacy #Web Application Security #DevSecOps

  41. David A. Wheeler's Page for Flawfinder

    #Code Analysis #Code Coverage #Development

  42. 42
    Splint Home Page

    #Code Analysis #Code Coverage #Code Review 9 social mentions

  43. 43
    HFC

    Header Free Cyclomatic Complexity Analyzer

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  44. 44
    C

    Cloc

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  45. 45
    SLO

    SLOCCount

    This product hasn't been added to SaaSHub yet
    If you are looking for a tool to ensure the developed code is compliant with CERT coding rules, you can opt for Rosecheckers. It is available for free is SourceForge. This tool does check for C/C++ codes and sometimes finds the problem which other static analysis tools cannot find, but this cannot be considered a full-grown standalone tool due to its inability to fully test since this is only a prototype.

  46. 46
    New JSHint website. Anton Kovalyov Oct 1st, 2013. For the last couple of weeks I've been working on a new homepage for JSHint and today I'm proud to announce the new jshint. com! JSHint Website.
    Pricing:
    • Open Source

    #Front End Package Manager #JS Build Tools #JavaScript Package Manager 14 social mentions

  47. DeepScan is a static analysis tool for JavaScript that helps you to find security vulnerabilities and programming mistakes in your code.
    You can use DeepScan to find possible runtime errors and quality issues instead of coding conventions. Integrate with your GitHub repositories to get quality insight into your web project.

    #Development #Code Analysis #Code Coverage 2 social mentions

Discuss: TOP 40 Static Code Analysis Tools (Best Source Code Analysis Tools)

Log in or Post with