Software Alternatives, Accelerators & Startups

Flawfinder VS SonarSource

Compare Flawfinder VS SonarSource and see what are their differences

Flawfinder logo Flawfinder

David A. Wheeler's Page for Flawfinder

SonarSource logo SonarSource

Sonar empowers developers and organizations to achieve Clean Code, systematically and predictably.
  • Flawfinder Landing page
    Landing page //
    2019-05-02
  • SonarSource Landing page
    Landing page //
    2023-10-11

Sonar solves the trillion-dollar challenge of bad code. Sonar equips developers and organizations to systematically achieve a state of Clean Code so that all code is fit for development and production. By applying the Sonar Clean as You Code methodology, organizations minimize risk, reduce technical debt, and derive more value from their software in a predictable and sustainable way.

The open source and commercial Sonar solution – SonarLint, SonarCloud, and SonarQube – supports over 30 programming languages, frameworks, and infrastructure technologies. Trusted by 7 million developers and 400,000 organizations globally to clean more than half a trillion lines of code, Sonar has become integral to delivering better software.

Sonar is headquartered in Geneva, Switzerland with additional offices in Austin, Texas; Annecy, France; Bochum, Germany, and Singapore. The company is rapidly growing with over 450 employees and more than 21,000 customers deploying Sonar products worldwide.

Flawfinder features and specs

  • Ease of Use
    Flawfinder is straightforward to install and run, making it accessible for both beginners and experienced developers seeking to identify vulnerabilities in C/C++ code.
  • Open Source
    Being an open-source tool, Flawfinder allows developers to contribute to its development and modify it to suit their specific needs.
  • Focus on C/C++
    Flawfinder is specialized for C/C++, providing detailed analysis and understanding of common vulnerabilities specific to these programming languages.
  • Speed
    The tool offers fast scanning capabilities, enabling developers to quickly identify potential weaknesses in their code.
  • Integration
    Flawfinder can be easily integrated into existing workflows and automated scripts, enhancing continuous integration and development processes.

Possible disadvantages of Flawfinder

  • False Positives
    Like many static analysis tools, Flawfinder may generate a significant number of false positives, requiring manual review to verify actual issues.
  • Limited to C/C++
    Its focus on C/C++ limits its applicability to projects involving other programming languages.
  • No GUI
    Flawfinder operates via command line, which may not be as user-friendly for those preferring graphical user interfaces.
  • Basic Reporting
    The reporting features are relatively basic and may not provide the in-depth insights offered by more comprehensive static analysis tools.
  • Reliance on Pattern Matching
    Flawfinder relies heavily on pattern matching, which might overlook vulnerabilities that don’t match specific patterns or that require deeper semantic analysis.

SonarSource features and specs

  • Comprehensive Code Analysis
    SonarSource offers a wide range of code analysis tools that support multiple programming languages. It helps in identifying bugs, vulnerabilities, and code smells, leading to better code quality and maintainability.
  • Continuous Integration Support
    SonarSource integrates well with popular CI/CD tools like Jenkins, GitLab, and GitHub Actions, allowing for automated code quality checks as part of the development workflow.
  • Customizable Rules
    Users can customize the rules and quality profiles according to project requirements, making it flexible and adaptable for different development environments.
  • User-Friendly Interface
    The platform offers a clean and intuitive user interface that helps developers easily navigate through issues and improve their code effectively.
  • Active Community and Support
    SonarSource has an active user community and provides good support, including comprehensive documentation and forums, which facilitate problem-solving and knowledge sharing.

Possible disadvantages of SonarSource

  • Resource Consumption
    The platform can be resource-intensive, requiring significant computational power and memory, especially for large codebases.
  • Complex Setup for Custom Integrations
    While it provides strong integration capabilities, setting up custom integrations or configuring advanced features might require a steep learning curve for some users.
  • Licensing Costs
    For enterprise use, SonarSource's licensing fees can be quite high, potentially impacting small to medium-sized businesses' budgets.
  • Limited Out-of-the-Box Functionality for Some Languages
    Although it supports multiple languages, out-of-the-box functionality can be limited for less common languages, necessitating additional configuration or plugin development.
  • Potential Overhead in Development Time
    Integrating thorough code reviews and fixes based on SonarSource's analysis can initially increase development time, which might be a challenge for teams with tight deadlines.

Flawfinder videos

Static Code Analysis using Flawfinder | LightBoard Series | ASSDF | Under15Minutes | Sridhar Iyer

More videos:

  • Review - Experiment No 1 Flawfinder |Tutorial on Advanced System Security and Digital Forensics| Sridhar Iyer
  • Review - Software Security testing Using FlawFinder - Secure Software Development

SonarSource videos

Web Security 0x19 | Source-Code Review SonarSource #CodeChallenge !

Category Popularity

0-100% (relative to Flawfinder and SonarSource)
Code Analysis
67 67%
33% 33
Code Coverage
77 77%
23% 23
Development
63 63%
37% 37
Code Review
100 100%
0% 0

User comments

Share your experience with using Flawfinder and SonarSource. For example, how are they different and which one is better?
Log in or Post with

Reviews

These are some of the external sources and on-site user reviews we've used to compare Flawfinder and SonarSource

Flawfinder Reviews

Top 9 C++ Static Code Analysis Tools
Flawfinder is a free open-source tool developed by security expert David A. Wheeler. It focuses, not surprisingly, mainly on locating security flaws (hence the name), sorted by risk level (the riskiest first). It is pretty straightforward, simple and fast, which is why a lot of beginners use it.

SonarSource Reviews

We have no reviews of SonarSource yet.
Be the first one to post

Social recommendations and mentions

Based on our record, SonarSource seems to be more popular. It has been mentiond 1 time since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.

Flawfinder mentions (0)

We have not tracked any mentions of Flawfinder yet. Tracking of Flawfinder recommendations started around Mar 2021.

SonarSource mentions (1)

  • Ask HN: Who is hiring? (January 2022)
    Vulnerability Researcher³ SonarSource builds world-class products (SonarQube, SonarCloud, SonarLint) for Code Security and Code Quality, with over 15k customers and 300k instances of our Community Edition. Our Security Research & Development team drives the innovation and promotion of our security analysis engines used by millions of developers around the globe to find vulnerabilities. We are looking for Security... - Source: Hacker News / over 3 years ago

What are some alternatives?

When comparing Flawfinder and SonarSource, you can also consider the following products

Cppcheck - Cppcheck is an analysis tool for C/C++ code. It detects the types of bugs that the compilers normally fail to detect. The goal is no false positives. CppCheckDownload cppcheck for free.

Clang Static Analyzer - The Clang Static Analyzer is a source code analysis tool that finds bugs in C, C++, and Objective-C...

LDRA Testbed - Liverpool Data Research Associates (LDRA) is a provider of software analysis, test and requirements...

Parasoft C/C++test - Ensure compliance with a variety of functional safety, security, and coding standards in embedded C/C++ software.

lgtm.com - lgtm.com is a platform for code analytics.

SonarQube - SonarQube, a core component of the Sonar solution, is an open source, self-managed tool that systematically helps developers and organizations deliver Clean Code.