Peter India logo

Static Code Analysis Tools

A curated directory of 14 static code analysis tools — spanning code quality management, vulnerability detection, unit test coverage, and security scanning for Java, .NET, and multi-language codebases.

  1. CAST Imaging The first-ever imaging system for software — a living knowledge base of your software's inner workings that helps you find architectural insights in minutes instead of days.
  2. Codacy Catches code-level security vulnerabilities before merge — automating code reviews and surfacing quality issues across pull requests and repositories.
  3. Codiga Offers a bird's-eye view of code quality — reporting code violations, duplicates, long and complex functions, and overall quality metrics via a unified dashboard.
  4. DeepSource A Code Health Platform enabling developers, security teams, and engineering leaders to take proactive action at every stage of the software development lifecycle.
  5. CodeQL GitHub's industry-leading semantic code analysis engine — lets you query code as though it were data to discover vulnerabilities and security issues across an entire codebase.
  6. Sonargraph-Developer Allows developers to check for architectural issues and code smells via Eclipse or IntelliJ plugins, or using the Sonargraph-Architect application alongside their IDE.
  7. JetBrains dotCover A .NET unit test runner and code coverage tool that integrates seamlessly with Visual Studio and JetBrains Rider to measure and improve test coverage.
  8. NDepend Delivers in-depth .NET code quality management via an interactive web report — tracking technical debt, code metrics, dependency graphs, and rule violations over time.
  9. Parasoft JTest An AI-optimized static analysis and AI-powered automated unit testing tool for Java — accelerating development of reliable, secure, and maintainable software.
  10. CodeMRI Platform A command-line utility comprising CodeMRI Care and CodeMRI Portfolio products — providing deep code analysis for Windows and Linux environments.
  11. Snyk Code Secures your code as it's written with static application security testing built by, and for, developers — integrating directly into the IDE and CI/CD pipeline.
  12. SonarQube Empowers development teams with a code quality and security solution deeply integrated into enterprise environments — enabling consistently clean, reliable code deployments.
  13. Sonatype Vulnerability Scanner Quickly identifies potential vulnerabilities in your software so you can easily prioritize and remediate them — ensuring the highest quality and security standards.
  14. Squore An innovative decision-making dashboard that enables quality management of software development — aggregating metrics and trends to guide engineering decisions.