Best Static Code Analysis Tools

How Many Static Code Analysis Tools Products Does G2 Track?

Total Products under this Category: 135

Category Stats (Sep 2026)

  • Average Rating: 4.38/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Static Code Analysis Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 2,500+ Authentic Reviews
  • 135+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Code Analysis Tools

G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence

Highlighted products: SonarQube, Gearset DevOps, Checkmarx, SoftSpell, Semgrep, Black Duck Polaris Platform, CAST Imaging, and ReSharper C++.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=checkmarx&focus%5B%5D=softspell&focus%5B%5D=semgrep&focus%5B%5D=black-duck-polaris-platform&focus%5B%5D=cast-imaging&focus%5B%5D=resharper-c)

SonarQube

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

Average Rating: 4.4/5.0

Total Reviews: 152

How Do G2 Users Rate SonarQube?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.5/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind SonarQube?

  • Seller: SonarSource Sàrl
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Geneva, Switzerland
  • Twitter: @SonarSource
    10,913 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    973 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: DevOps Engineer, Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 42% Large, 40% Medium

What Do G2 Reviewers Say About SonarQube?

AI-generated summary from verified user reviews

Pros
  • Users value SonarQube for its ability to quickly flag code quality and security issues, ensuring a reliable codebase.
  • Users value the flexible issue filtering and prioritization features of SonarQube, enhancing team productivity and focus.
  • Users appreciate how SonarQube quickly flags code quality and security issues, ensuring a clean and reliable codebase.
  • Users appreciate the ease of use of SonarQube, finding integration and actionable feedback simple and effective.
  • Users appreciate the easy integrations with CI/CD tools, enhancing their workflow and improving code quality effectively.
Cons
  • Users face software bugs that lead to false positives, complicating the experience and requiring significant knowledge to manage.
  • Users find the complex configuration of SonarQube challenging, especially for beginners needing extensive knowledge.
  • Users encounter false positives that complicate usage, despite helpful tools for review and customization of analysis.
  • Users find SonarQube's complexity in configuration and excessive warnings can make it cumbersome to use.
  • Users find the complex setup of SonarQube time-consuming, requiring significant effort to configure and tune effectively.

What Are Recent G2 Reviews of SonarQube?

What Are G2 Users Discussing About SonarQube?

Gearset DevOps

Gearset is the global leader in Salesforce DevOps. It’s a DevOps platform that helps organizations manage, automate, and govern the full Salesforce development lifecycle, from planning and deployment to testing, data management, and compliance. The platform is designed for Salesforce teams that need reliable, scalable DevOps processes across complex org environments. Gearset is used by mid-market and enterprise organizations across regulated and non-regulated industries, including healthcare, financial services, insurance, and technology. Typical users include Salesforce administrators, developers, DevOps engineers, release managers, and platform owners responsible for maintaining deployment quality, security, and operational consistency. The platform supports a wide range of Salesforce use cases, including metadata and CPQ deployments, CI/CD automation, code review workflows, sandbox seeding, test automation, and monitoring. As well as deployment automation, Gearset includes tools for Salesforce data protection and long-term data management, such as automated backups, data restore, and archiving. Observability and Org Intelligence features provide insight into org health, deployment risk, and system changes over time. Gearset also includes governance and compliance capabilities designed for enterprise environments. These features help teams maintain audit readiness and enforce access controls while supporting compliance frameworks such as SOX, ISO, HIPAA, and GDPR. The platform is delivered as a managed service and integrates with Salesforce environments without requiring complex local infrastructure. Key features and capabilities include: - Salesforce metadata, CPQ, and data deployments with CI/CD automation and version control integration - Code review, test automation, and release validation to support quality and consistency - Automated Salesforce backups, restore, and data archiving for data protection and retention - Sandbox seeding, observability, and Org Intelligence to support environment management and visibility - Governance features including audit trails, role-based access controls, and compliance support Gearset is a Salesforce Partner and has supported Salesforce teams globally since 2015. The platform is used by organizations managing multiple orgs (across regions), frequent releases, and complex compliance requirements, helping teams reduce deployment risk, improve operational visibility, and maintain control over Salesforce change management processes.

Average Rating: 4.7/5.0

Total Reviews: 305

How Do G2 Users Rate Gearset DevOps?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.3/10 (Category avg: 8.5/10)
  • Ease of Use: 9.1/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Gearset DevOps?

  • Seller: Gearset
  • Company Website:
  • Year Founded: 2015
  • HQ Location: Cambridge, Cambridgeshire
  • Twitter: @GearsetHQ
    1,182 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    369 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Salesforce Developer, Salesforce Administrator
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 36% Medium, 33% Small

What Do G2 Reviewers Say About Gearset DevOps?

AI-generated summary from verified user reviews

Pros
  • Users praise the ease of use of Gearset DevOps, highlighting smooth setup and effective features for efficient deployments.
  • Users value the automation and ease of deployment with Gearset, significantly enhancing efficiency and reducing errors.
  • Users appreciate the easy deployment capabilities of Gearset DevOps, which streamline CI/CD processes and validations effortlessly.
  • Users commend the exceptional customer support from Gearset DevOps, highlighting prompt assistance and engagement with feature requests.
  • Users value the deployment ease of Gearset DevOps, enabling swift setup and efficient management of releases.
Cons
  • Users face deployment issues requiring manual activation of Flows and cautious management of production metadata changes.
  • Users find Gearset DevOps expensive, particularly for larger teams, affecting its accessibility despite its high quality.
  • Users find complexity in custom filters and CI/CD processes, wishing for enhanced automation and streamlined operations.
  • Users face limitations in data management, as some metadata and object settings fail to transfer accurately between environments.
  • Users express disappointment over the missing features in Gearset DevOps, particularly the lack of automated dependency tracking.

What Are Recent G2 Reviews of Gearset DevOps?

Checkmarx

Checkmarx offers leading application security solutions that help organizations safeguard software development while enhancing efficiency and reducing costs. At the center is Checkmarx Fusion, the highest-fidelity scanning architecture in the industry. Most scanners force a choice: catch more, or get buried in noise and miss what matters. Fusion ends that trade-off — deterministic precision and frontier AI coverage fused into one verified result, with the Findings Analysis Engine validating and deduplicating every finding before a developer sees it. The result is an F1 score of 0.64 today by using the Checkmarx NG SAST vs. an industry average of ~0.20, and an astonishing market leading F1 score of 0.74 with Checkmarx Fusion. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as NG SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

Average Rating: 4.2/5.0

Total Reviews: 45

How Do G2 Users Rate Checkmarx?

  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.3/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Checkmarx?

  • Seller: Checkmarx
  • Company Website:
  • Year Founded: 2006
  • HQ Location: Paramus, NJ
  • Twitter: @Checkmarx
    7,284 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    997 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 57% Large, 22% Medium

What Do G2 Reviewers Say About Checkmarx?

AI-generated summary from verified user reviews

Pros
  • Users value the easy implementation of Checkmarx into existing repositories, enhancing their security review processes effortlessly.
  • Users praise the intuitive user interface of Checkmarx, making security reviews and integrations straightforward and user-friendly.
  • Users value the accuracy of results in Checkmarx, finding it effective for automated security reviews.
  • Users appreciate the automation testing capabilities of Checkmarx, making security reviews efficient and user-friendly.
  • Users praise the responsive customer support of Checkmarx, consistently providing help when challenges arise.
Cons
  • Users experience a significant number of false positives with Checkmarx, particularly for Kotlin projects, leading to frustration.
  • Users face challenges with limited support for Kotlin, experiencing many false positives compared to other languages like Java or Javascript.
  • Users experience missing features in Checkmarx, particularly with Kotlin support, leading to numerous false positives.
  • Users find the navigation poor in Checkmarx, citing issues with dashboard layout and display clarity.

What Are Recent G2 Reviews of Checkmarx?

What Are G2 Users Discussing About Checkmarx?

Semgrep

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

Average Rating: 4.6/5.0

Total Reviews: 56

How Do G2 Users Rate Semgrep?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.1/10 (Category avg: 8.5/10)
  • Ease of Use: 9.1/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Semgrep?

  • Seller: Semgrep
  • Year Founded: 2017
  • HQ Location: San Francisco, US
  • Twitter: @semgrep
    4,433 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    268 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 45% Large, 43% Medium

What Do G2 Reviewers Say About Semgrep?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Semgrep, enabled by its intuitive syntax and smooth integration with CI/CD.
  • Users appreciate the flexibility and speed of Semgrep in enforcing coding standards and catching vulnerabilities effectively.
  • Users appreciate the effective vulnerability detection of Semgrep, facilitating quick identification and resolution of security issues.
  • Users appreciate the scanning efficiency of Semgrep, benefiting from rapid scans and streamlined CI/CD integration.
  • Users value Semgrep for its effective security vulnerability detection, enabling quick resolutions without hindering development speed.
Cons
  • Users find Semgrep not user-friendly due to a steep learning curve and complex initial setup requirements.
  • Users find the limited features of Semgrep restrict its usability and complicate effective vulnerability management.
  • Users find the difficult learning curve for Semgrep daunting, especially for creating advanced rules and setups.
  • Users express concerns about the lack of guidance in creating custom rules, complicating effective use of Semgrep.
  • Users note a steep learning curve for Semgrep's rule syntax, making it challenging for newcomers to master.

What Are Recent G2 Reviews of Semgrep?

SoftSpell

SoftSpell is an AI-powered platform that accelerates software delivery and simplifies legacy modernization. It transforms unstructured requirements and existing codebases into structured outputs, enabling faster development with clarity and control. By combining intelligent requirement analysis, context-aware code generation, and automated testing, it ensures end-to-end traceability while reducing manual effort and rework. SoftSpell integrates seamlessly into existing workflows, helping teams deliver high-quality software faster.

Average Rating: 4.4/5.0

Total Reviews: 43

How Do G2 Users Rate SoftSpell?

  • Has the product been a good partner in doing business?: 7.9/10 (Category avg: 8.7/10)
  • Ease of Admin: 7.5/10 (Category avg: 8.5/10)
  • Ease of Use: 9.2/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 0.0/10 (Category avg: 10/10)

Who Is the Company Behind SoftSpell?

Who Uses This Product?

  • Who Uses This: Senior Software Engineer
  • Top Industries: Computer Software, Program Development
  • Company Size: 43% Small, 43% Large

What Do G2 Reviewers Say About SoftSpell?

AI-generated summary from verified user reviews

Pros
  • Users value the time-saving capabilities of SoftSpell, making coding faster and enhancing overall productivity.
  • Users appreciate the coding assistance from SoftSpell, enhancing quality and speeding up the programming process effortlessly.
  • Users value the automation features of SoftSpell, significantly enhancing productivity and simplifying the development process.
  • Users praise the significant improvement in code quality that SoftSpell provides, enhancing productivity and development speed.
  • Users appreciate the ease of use of SoftSpell, enhancing their coding experience and simplifying problem-solving.
Cons
  • Users experience slow performance with SoftSpell, leading to delays and frustrating interruptions during use.
  • Users experience prompt issues with SoftSpell, citing delays and outdated solutions during usage, impacting their workflow.
  • Users express concerns about limited multimedia support, hoping future updates will enhance compatibility with tech stacks.
  • Users find the cluttered interface of SoftSpell challenging, leading to mistakes and requiring manual adjustments.
  • Users face limitations with browser compatibility, hoping updates will improve functionality in the future.

What Are Recent G2 Reviews of SoftSpell?

Black Duck Polaris Platform

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it, development and DevSecOps teams to automate testing within development pipelines without compromising velocity, and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Average Rating: 4.2/5.0

Total Reviews: 103

How Do G2 Users Rate Black Duck Polaris Platform?

  • Has the product been a good partner in doing business?: 8.4/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.5/10 (Category avg: 8.5/10)
  • Ease of Use: 8.4/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Black Duck Polaris Platform?

  • Seller: Black Duck
  • Year Founded: 2024
  • HQ Location: Burlington, US
  • LinkedIn® Page: www.linkedin.com
    1,317 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 53% Large, 32% Medium

What Do G2 Reviewers Say About Black Duck Polaris Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the accuracy of findings from Black Duck SCA, highlighting its powerful engine and extensive knowledge base.
  • Users value the powerful identification of open source issues by Black Duck SCA, aided by extensive knowledge resources.
Cons
  • Users find that Black Duck SCA requires huge resources to deploy on-prem, which can be a significant drawback.

What Are Recent G2 Reviews of Black Duck Polaris Platform?

What Are G2 Users Discussing About Black Duck Polaris Platform?

CAST Imaging

CAST Imaging helps software architects and AI agents understand, change, and modernize applications. It automatically reverse-engineers all database structures, code components, and interdependencies in any custom-built applications. CAST Imaging deterministically maps the entire system – architecture, dependencies, data access, and tech debt. It provides interactive and accurate architecture blueprints, zoomable to the tiniest details. as well as data call graphs and end-to-end transaction views. All this in a lightweight web UI with the ability for teams to collaborate by adding their own knowledge and sharing insights. A built-in MCP server streams this precise application architectural context to AI agents which can generate consistent, accurate, and safe code changes. Businesses move faster using CAST technology to understand, improve, and transform their software. Through semantic analysis of source code, CAST produces 3D maps and dashboards to navigate inside individual applications and across entire portfolios. This intelligence empowers executives and technology leaders to steer, speed, and report on initiatives such as technical debt, GenAI, modernization, and cloud. As the pioneer of the software intelligence field, CAST is trusted by the world’s leading companies and governments, their consultancies and cloud providers. See it all at castsoftware.com.

Average Rating: 4.6/5.0

Total Reviews: 36

How Do G2 Users Rate CAST Imaging?

  • Has the product been a good partner in doing business?: 8.4/10 (Category avg: 8.7/10)
  • Ease of Admin: 7.5/10 (Category avg: 8.5/10)
  • Ease of Use: 8.2/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind CAST Imaging?

  • Seller: CAST
  • Company Website:
  • Year Founded: 1990
  • HQ Location: New York
  • Twitter: @SW_Intelligence
    1,887 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,270 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 53% Large, 28% Small

What Are Recent G2 Reviews of CAST Imaging?

What Are G2 Users Discussing About CAST Imaging?

ReSharper C++

ReSharper C++ is a productivity extension for developing in C and C++ that fully integrates with Microsoft Visual Studio. It helps developers create efficient and correct code in modern C++ by providing safe refactorings, fast navigation, and code analysis for the trickiest aspects of the language. It also offers support for HLSL shaders, the C++/CLI specifications, and Unreal Engine code.

Average Rating: 4.6/5.0

Total Reviews: 20

How Do G2 Users Rate ReSharper C++?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.7/10)
  • Ease of Admin: 7.5/10 (Category avg: 8.5/10)
  • Ease of Use: 9.6/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 3.3/10 (Category avg: 10/10)

Who Is the Company Behind ReSharper C++?

  • Seller: JetBrains
  • Year Founded: 2000
  • HQ Location: Prague
  • Twitter: @jetbrains
    213,126 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,019 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 55% Small, 35% Large

What Are Recent G2 Reviews of ReSharper C++?

What Are G2 Users Discussing About ReSharper C++?

OpenText Static Application Security Testing

OpenText™ Static Application Security Testing (SAST) is a comprehensive solution designed to identify and remediate security vulnerabilities within an application's source code during the early stages of development. By analyzing code from the "inside out," SAST provides immediate feedback to developers, enabling them to address security issues promptly and effectively. Key Features and Functionality: - Extensive Language Support: Supports over 33 programming languages and more than 1,400 vulnerability categories, ensuring broad applicability across various development environments. - Integration with Development Tools: Seamlessly integrates with popular Integrated Development Environments (IDEs) such as Eclipse, Visual Studio, and JetBrains, as well as Continuous Integration/Continuous Deployment (CI/CD) tools like Jenkins and Bamboo, facilitating a smooth incorporation into existing workflows. - Scalable Deployment Options: Offers flexible deployment models, including on-premises, cloud-based, and Software as a Service (SaaS) solutions, allowing organizations to choose the setup that best fits their needs. - Advanced Analysis Capabilities: Utilizes multiple algorithms and an expansive knowledge base of secure coding rules to perform thorough code analysis, pinpointing the root causes of vulnerabilities and providing detailed remediation guidance. Primary Value and Problem Solved: OpenText SAST empowers organizations to proactively manage application security by detecting and addressing vulnerabilities early in the Software Development Life Cycle (SDLC). This proactive approach reduces the risk of security breaches, minimizes the cost and effort associated with late-stage remediation, and enhances the overall security posture of applications. By integrating security testing into the development process, OpenText SAST helps developers create more secure code, leading to robust and reliable software products.

Average Rating: 4.5/5.0

Total Reviews: 21

How Do G2 Users Rate OpenText Static Application Security Testing?

  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.1/10 (Category avg: 8.5/10)
  • Ease of Use: 8.7/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind OpenText Static Application Security Testing?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Who Uses This Product?

  • Top Industries: Banking, Financial Services
  • Company Size: 50% Large, 29% Small

What Do G2 Reviewers Say About OpenText Static Application Security Testing?

AI-generated summary from verified user reviews

Pros
  • Users value the easy integrations of OpenText Static Application Security Testing, enhancing their workflow with multiple tools.
  • Users value the extensive integration capabilities of OpenText Static Application Security Testing with various third-party tools.
  • Users value the extensive integration support for various technologies and third-party tools offered by OpenText Static Application Security Testing.
Cons
  • Users are disappointed by the false positives, but appreciate the ability to ignore issues in future scans.

What Are Recent G2 Reviews of OpenText Static Application Security Testing?

What Are G2 Users Discussing About OpenText Static Application Security Testing?

Typo

Typo is an AI-powered software engineering intelligence platform that gives engineering leaders real-time visibility into what's actually happening across their SDLC — and what to do about it. From a single platform, engineering teams can track DORA metrics and delivery health, measure the real impact of AI coding tools like Cursor, and Claude Code, run AI code reviews on every pull request, monitor R&D investment allocation, and measure developer experience through anonymous surveys. Typo connects to your existing stack — GitHub, GitLab, Bitbucket, Jira, Linear, and CI/CD tools — in 60 seconds. No complex onboarding. Used by 1,000+ engineering teams globally. 15M+ pull requests processed. Featured in Gartner's Market Guide for Software Engineering Intelligence Platforms.

Average Rating: 4.6/5.0

Total Reviews: 150

How Do G2 Users Rate Typo?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 8.9/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 9.8/10 (Category avg: 10/10)

Who Is the Company Behind Typo?

  • Seller: Typo
  • Year Founded: 2020
  • HQ Location: Dover, US
  • Twitter: @Typoapp_
    66 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    76 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 47% Medium, 43% Small

What Do G2 Reviewers Say About Typo?

AI-generated summary from verified user reviews

Pros
  • Users value the insightful productivity metrics of Typo, enhancing team performance and streamlining workflows effectively.
  • Users value the easy-to-use metrics analysis in Typo, enabling quick learning and effective team performance tracking.
  • Users appreciate the powerful AI-driven features of Typo for managing productivity and improving code quality effortlessly.
  • Users value Typo for its highly valid recommendations that enhance code readability and simplify review processes.
  • Users value the clear, actionable insights from Typo that enhance team performance and improve code quality efficiently.
Cons
  • Users find the complex configuration process frustrating, especially during onboarding and due to quality issues.
  • Users experience bug issues with Typo, but the team is responsive and quick to resolve them.
  • Users express frustration with the lack of customization options in Typo, limiting adaptability to unique team workflows.
  • Users note the limited features of Typo, particularly in customization and mobile access, impacting usability for diverse teams.
  • Users express concerns about the lack of customization and mobile app functionality, limiting effectiveness for their unique workflows.

What Are Recent G2 Reviews of Typo?

Mend.io

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

Average Rating: 4.3/5.0

Total Reviews: 117

How Do G2 Users Rate Mend.io?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.3/10 (Category avg: 8.5/10)
  • Ease of Use: 8.4/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Mend.io?

  • Seller: Mend
  • Company Website:
  • Year Founded: 2011
  • HQ Location: Boston, Massachusetts
  • Twitter: @Mend_io
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    259 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 36% Small, 33% Large

What Do G2 Reviewers Say About Mend.io?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the scanning efficiency of Mend.io, enabling quick and accurate scans across multiple repositories seamlessly.
  • Users appreciate the ease of use of Mend.io, made simpler by effective integrations and an attractive interface.
  • Users value the easy integrations of Mend.io, allowing seamless scanning across multiple repositories and CI/CD platforms.
  • Users appreciate the quick and accurate scanning capabilities of Mend.io, benefiting from a range of integrations.
  • Users value the automated vulnerability detection of Mend.io, enhancing efficiency in identifying and addressing issues seamlessly.
Cons
  • Users face integration issues with Mend.io, finding it difficult to connect on-premise tools and features like Jira.
  • Users express concern over limited features in Mend.io, necessitating workarounds for optimal functionality and integration.
  • Users find the missing features in Mend.io cumbersome, often resorting to workarounds for integration and functionality.
  • Users face complex implementation, with challenging integration and frequent false positives affecting their experience.
  • Users find the confusing interface challenging due to the awkward transitions between different portals.

What Are Recent G2 Reviews of Mend.io?

What Are G2 Users Discussing About Mend.io?

CodeScene

CodeScene is a code analysis, visualization, and reporting tool. Cross reference contextual factors such as code quality, team dynamics, and delivery output to get actionable insights to effectively reduce technical debt and deliver better code quality. We enable software development teams to make confident, data-driven decisions that fuel performance and developer productivity. CodeScene guides developers and technical leaders to: - Get a holistic overview and evolution of your software system in one single dashboard. - Identify, prioritize, and tackle technical debt based on return on investment. - Maintain a healthy codebase with powerful CodeHealth™ Metrics, spend less time on rework and more time on innovation. - Seamlessly integrate with Pull Requests and editors, get actionable code reviews and refactoring recommendations. - Set Improvement goals and quality gates for teams to work towards while monitoring the progress. - Support retrospectives by identifying areas for improvement. - Benchmark performance against personalized trends. - Understand the social side of the code, measure socio-technical factors like key personnel dependencies, knowledge sharing and inter-team coordination. - Put findings into context based on how your organization and your code evolves. Supporting 28+ programming languages, CodeScene offers an automated integration with GitHub, BitBucket, Azure DevOps or GitLab pull requests to incorporate the analysis results into existing delivery workflows. Get early warnings and recommendations about complex code before merging it to the main branch, set quality gates to trigger in case your code health declines.

Average Rating: 4.6/5.0

Total Reviews: 39

How Do G2 Users Rate CodeScene?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.6/10 (Category avg: 8.5/10)
  • Ease of Use: 8.1/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind CodeScene?

  • Seller: CodeScene AB
  • Company Website:
  • Year Founded: 2015
  • HQ Location: Malmö, SE
  • Twitter: @codescene
    1,239 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    29 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 41% Medium, 36% Small

What Do G2 Reviewers Say About CodeScene?

AI-generated summary from verified user reviews

Pros
  • Users value the knowledge base and code health features of CodeScene for improving team efficiency and code quality.
  • Users find issue identification with CodeScene invaluable for enhancing team knowledge and improving code quality.
  • Users value the actionable insights CodeScene provides, enhancing code quality and supporting informed decision-making in teams.
  • Users commend the fast and helpful customer support of CodeScene, enhancing their overall experience and satisfaction.
  • Users praise CodeScene for its actionable insights, improving code health and aiding informed decisions for development teams.
Cons
  • Users struggle with integration issues, particularly with proxies and firewall configurations, complicating workflow adoption.
  • Users find the difficult learning curve of CodeScene challenging due to advanced features and overwhelming terminology.
  • Users find the onboarding process challenging, making it difficult for beginners to effectively utilize CodeScene's features.
  • Users find the learning difficulty with CodeScene's advanced features and terminology challenging for newcomers.
  • Users struggle with difficult configuration and lack of seamless integration, impacting adoption and daily workflow usage.

What Are Recent G2 Reviews of CodeScene?

Kiuwan Code Security & Insights

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

Average Rating: 4.5/5.0

Total Reviews: 29

How Do G2 Users Rate Kiuwan Code Security & Insights?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.7/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Kiuwan Code Security & Insights?

  • Seller: Sembi
  • Company Website:
  • Year Founded: 2023
  • HQ Location: Austin, US
  • LinkedIn® Page: www.linkedin.com
    114 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Banking
  • Company Size: 41% Large, 35% Medium

What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the accuracy of the results from Kiuwan Code Security & Insights, enhancing their overall experience.
  • Users value the accuracy of findings from Kiuwan, enhancing their satisfaction with code security and reporting.
  • Users commend the efficient customer support of Kiuwan, ensuring timely assistance and strong satisfaction overall.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, making it very easy to navigate.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, enhancing ease of use for dashboards.

What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

TASKING Test & Verification Tools

TASKING Test & Verification Tools combine software analysis, verification, and compliance capabilities for safety- and security-critical software development. Products: LDRA tool suite and LDRA Productivity Packages.

Average Rating: 4.6/5.0

Total Reviews: 20

How Do G2 Users Rate TASKING Test & Verification Tools?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 10.0/10 (Category avg: 8.5/10)
  • Ease of Use: 8.7/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind TASKING Test & Verification Tools?

  • Seller: TASKING
  • Company Website:
  • Year Founded: 1977
  • HQ Location: Munich, Bavaria
  • LinkedIn® Page: www.linkedin.com
    262 employees on LinkedIn®
  • Ownership: TRUE

Who Uses This Product?

  • Company Size: 45% Large, 35% Medium

What Are Recent G2 Reviews of TASKING Test & Verification Tools?

Codacy

Codacy is the code quality and security platform for AI-assisted engineering teams. AI is now embedded through the engineering workflow, which has made teams faster, but also adds risk to everything they ship. Codacy helps AI-assisted teams ship high-quality, secure code across the full software development lifecycle, starting in the agent and editor, through pull requests in Git, and into containers and runtime security. At each stage we check for quality issues, security vulnerabilities and AI coding risk introduced into the codebase, and help devs and agent fix them effortlessly. A team's standards become automated guardrails that apply across every IDE, AI coding agent, and Pull Request. More than 250,000 developers rely on Codacy to keep quality and security stable as AI changes how software gets built. Add your repo and get your free scan report in minutes: https://codacy.com

Average Rating: 4.6/5.0

Total Reviews: 29

How Do G2 Users Rate Codacy?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.9/10 (Category avg: 8.5/10)
  • Ease of Use: 9.1/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Codacy?

  • Seller: Codacy
  • Year Founded: 2012
  • HQ Location: Lisbon, Lisboa
  • Twitter: @codacy
    5,002 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    62 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 59% Small, 24% Medium

What Do G2 Reviewers Say About Codacy?

AI-generated summary from verified user reviews

Pros
  • Users value the enhanced security features of Codacy, benefiting from integrated automation and insightful vulnerability management.
  • Users appreciate the integrated automation of Codacy, finding it easy to use and helpful for maintaining code quality.
  • Users find the out-of-the-box automation in Codacy to be user-friendly and effective for maintaining code quality.
  • Users value the high code quality provided by Codacy's integrated automation and effective static code analyses.
  • Users value the helpful customer support of Codacy, appreciating their immediate assistance during integration and security management.
Cons
  • Users find Codacy expensive at $19/month, which can be a barrier for smaller organizations.

What Are Recent G2 Reviews of Codacy?

Adam Crivello
AC
Researched and written by Adam Crivello
Updated October 3, 2024