# Best Static Code Analysis Tools with Python Capabilities

## How Many Static Code Analysis Tools Products Does G2 Track?

**Total Products under this Category:** 137

### Category Stats (Aug 2026)

- **Average Rating:** 4.38/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** TASKING Test & Verification Tools (+10.99%) - Among all products in this category, TASKING Test & Verification Tools recorded the largest rating increase compared to last month

_Last updated: August 19, 2026_

## How Does G2 Rank Static Code Analysis Tools Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 2,200+ Authentic Reviews
- 137+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Static Code Analysis Tools
 ![G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence](https://www.g2.com/categories/static-code-analysis/grids.png?focus%5B%5D=7775&focus%5B%5D=102905&focus%5B%5D=1385185&focus%5B%5D=4475&focus%5B%5D=1225549&focus%5B%5D=161987&focus%5B%5D=48275&focus%5B%5D=1225688)

Highlighted products: SonarQube, Gearset DevOps, SoftSpell, Checkmarx, Semgrep, CAST Imaging, ReSharper C++, and Typo.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=softspell&focus%5B%5D=checkmarx&focus%5B%5D=semgrep&focus%5B%5D=cast-imaging&focus%5B%5D=resharper-c&focus%5B%5D=typo)

**Sponsored**

### Endor Labs

Endor Labs turns application security into a competitive advantage. At the core is AURI, the security harness for agentic development. It helps coding agents write secure code by default, automates PR security reviews, and gives agents deterministic context to fix what matters fast. At the core is our patented code context graph: a continuously updated model of application behavior across code, dependencies, secrets, and containers. The result: 83% fewer blocked PRs, 10x fewer security tickets, and 6x faster remediation at Atlassian, Cursor, Rubrik, and Snowflake.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=564&secure%5Bchosen_at%5D=2026-08-21T06%3A50%3A35Z&secure%5Bdisplayable_resource_id%5D=2041&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=1520&secure%5Bplacement_resource_ids%5D%5B%5D=2041&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1317430&secure%5Bresource_id%5D=564&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fstatic-code-analysis%2Ff%2Fpython&secure%5Btoken%5D=e48f4ff770f43aff24de16fa9bb6ff0936dcc28a4aba3c7e009f69776abf86cf&secure%5Burl%5D=https%3A%2F%2Fwww.endorlabs.com%2Fplatform%3Futm_source%3Dg2%26utm_medium%3Ddisplay%26utm_campaign%3Dg2-ad&secure%5Burl_type%5D=custom_url)

### [SonarQube](https://www.g2.com/products/sonarqube/reviews)

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 153

#### How Do G2 Users Rate SonarQube?

- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind SonarQube?

- **Seller:** [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)
- **Company Website:** www.sonarsource.com
- **Year Founded:** 2008
- **HQ Location:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** DevOps Engineer, Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 41% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Users value SonarQube for its ability to quickly flag **code quality and security issues** , ensuring a reliable codebase.
- Users value the **flexible issue filtering and prioritization** features of SonarQube, enhancing team productivity and focus.
- Users appreciate how SonarQube quickly **flags code quality and security issues** , ensuring a clean and reliable codebase.
- Users appreciate the **ease of use** of SonarQube, finding integration and actionable feedback simple and effective.
- Users appreciate the **easy integrations** with CI/CD tools, enhancing their workflow and improving code quality effectively.

##### Cons

- Users face **software bugs** that lead to false positives, complicating the experience and requiring significant knowledge to manage.
- Users find the **complex configuration** of SonarQube challenging, especially for beginners needing extensive knowledge.
- Users encounter **false positives** that complicate usage, despite helpful tools for review and customization of analysis.
- Users find SonarQube's **complexity** in configuration and excessive warnings can make it cumbersome to use.
- Users find the **complex setup** of SonarQube time-consuming, requiring significant effort to configure and tune effectively.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube: Easy Integration, Simple UI, and Solid Free Code Quality Scanning"](https://www.g2.com/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-12975264)

**["SonarQube Catches Issues Early with Clear, Actionable Reports"](https://www.g2.com/survey_responses/sonarqube-review-13204491)**

**Rating:** 4.0/5.0 stars

_— Kewin M._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-13204491)

#### What Are G2 Users Discussing About SonarQube?

- [What is SonarLint used for?](https://www.g2.com/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)

### [Checkmarx](https://www.g2.com/products/checkmarx/reviews)

Checkmarx is a type of application security solution designed to help organizations safeguard their software development processes while enhancing efficiency and reducing costs. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. With the increasing reliance on AI technologies and the rapid pace of software development, Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as AI SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

**Average Rating:** 4.2/5.0

**Total Reviews:** 44

#### How Do G2 Users Rate Checkmarx?

- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.2/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Checkmarx?

- **Seller:** [Checkmarx](https://www.g2.com/sellers/checkmarx)
- **Company Website:** www.checkmarx.com
- **Year Founded:** 2006
- **HQ Location:** Paramus, NJ
- **Twitter:** @Checkmarx  
7,284 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=18f6741e77df71b112ecb3ec6620912d3a0f67666525358c0a4f3b1278b173df&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheckmarx&secure%5Burl_type%5D=linkedin_company_website)  
1,019 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 56% Large, 23% Medium

#### What Do G2 Reviewers Say About Checkmarx?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **easy implementation** of Checkmarx into existing repositories, enhancing their security review processes effortlessly.
- Users praise the **intuitive user interface** of Checkmarx, making security reviews and integrations straightforward and user-friendly.
- Users value the **accuracy of results** in Checkmarx, finding it effective for automated security reviews.
- Users appreciate the **automation testing** capabilities of Checkmarx, making security reviews efficient and user-friendly.
- Users praise the **responsive customer support** of Checkmarx, consistently providing help when challenges arise.

##### Cons

- Users experience a significant number of **false positives** with Checkmarx, particularly for Kotlin projects, leading to frustration.
- Users face challenges with **limited support for Kotlin** , experiencing many false positives compared to other languages like Java or Javascript.
- Users experience **missing features** in Checkmarx, particularly with Kotlin support, leading to numerous false positives.
- Users find the **navigation poor** in Checkmarx, citing issues with dashboard layout and display clarity.

#### What Are Recent G2 Reviews of Checkmarx?

**["Automated Checkmarx Scans Keep Us Ahead of Key Vulnerabilities"](https://www.g2.com/survey_responses/checkmarx-review-12983770)**

**Rating:** 4.5/5.0 stars

_— Nitesh A._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12983770)

**["Centralized Source Code Security with Seamless CI/CD Integration"](https://www.g2.com/survey_responses/checkmarx-review-12980590)**

**Rating:** 5.0/5.0 stars

_— Aman M._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12980590)

#### What Are G2 Users Discussing About Checkmarx?

- [What is Checkmarx used for?](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for) - 1 comment, 1 upvote
- [How much does Checkmarx cost?](https://www.g2.com/discussions/how-much-does-checkmarx-cost)
- [Which testing method does Checkmarx support?](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support) - 1 comment
- [Does Checkmarx support DAST?](https://www.g2.com/discussions/does-checkmarx-support-dast) - 1 comment
- [What is Checkmarx used for?](https://www.g2.com/discussions/what-is-checkmarx-used-for) - 2 comments

### [OpenText Static Application Security Testing](https://www.g2.com/it/products/opentext-static-application-security-testing/reviews)

OpenText™ Static Application Security Testing (SAST) è una soluzione completa progettata per identificare e risolvere le vulnerabilità di sicurezza all'interno del codice sorgente di un'applicazione nelle prime fasi dello sviluppo. Analizzando il codice dall'"interno verso l'esterno", SAST fornisce un feedback immediato agli sviluppatori, consentendo loro di affrontare i problemi di sicurezza in modo tempestivo ed efficace. Caratteristiche e Funzionalità Principali: - Ampio Supporto Linguistico: Supporta oltre 33 linguaggi di programmazione e più di 1.400 categorie di vulnerabilità, garantendo un'ampia applicabilità in vari ambienti di sviluppo. - Integrazione con Strumenti di Sviluppo: Si integra perfettamente con ambienti di sviluppo integrati (IDE) popolari come Eclipse, Visual Studio e JetBrains, nonché con strumenti di Continuous Integration/Continuous Deployment (CI/CD) come Jenkins e Bamboo, facilitando un'integrazione fluida nei flussi di lavoro esistenti. - Opzioni di Distribuzione Scalabili: Offre modelli di distribuzione flessibili, inclusi soluzioni on-premises, basate su cloud e Software as a Service (SaaS), permettendo alle organizzazioni di scegliere la configurazione che meglio si adatta alle loro esigenze. - Capacità di Analisi Avanzate: Utilizza molteplici algoritmi e una vasta base di conoscenze di regole di codifica sicura per eseguire un'analisi approfondita del codice, individuando le cause principali delle vulnerabilità e fornendo dettagliate linee guida per la risoluzione. Valore Primario e Problema Risolto: OpenText SAST consente alle organizzazioni di gestire proattivamente la sicurezza delle applicazioni rilevando e affrontando le vulnerabilità nelle prime fasi del ciclo di vita dello sviluppo software (SDLC). Questo approccio proattivo riduce il rischio di violazioni della sicurezza, minimizza i costi e gli sforzi associati alla risoluzione tardiva e migliora la postura complessiva di sicurezza delle applicazioni. Integrando i test di sicurezza nel processo di sviluppo, OpenText SAST aiuta gli sviluppatori a creare codice più sicuro, portando a prodotti software robusti e affidabili.

**Average Rating:** 4.5/5.0

**Total Reviews:** 21

#### How Do G2 Users Rate OpenText Static Application Security Testing?

- **Ritiene che the product sia stato un valido partner commerciale?:** 8.5/10 (Category avg: 8.7/10)
- **Facilità di amministrazione:** 8.1/10 (Category avg: 8.5/10)
- **Facilità d'uso:** 8.7/10 (Category avg: 8.8/10)
- **Qual è il ROI stimato della Sua organizzazione su the product (periodo di recupero in mesi)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind OpenText Static Application Security Testing?

- **Venditore:** [OpenText](https://www.g2.com/it/sellers/opentext)
- **Anno di Fondazione:** 1991
- **Sede centrale:** Waterloo, ON
- **Twitter:** @OpenText  
21,565 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c339a6555764b5ffce77c3df08d6ed9c9b1cb1ee1baeebac8435f0485b7cca5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2709%2F&secure%5Burl_type%5D=linkedin_company_website)  
23,048 dipendenti su LinkedIn®
- **Proprietà:** NASDAQ:OTEX

#### Who Uses This Product?

- **Top Industries:** Bancario, Servizi finanziari
- **Company Size:** 50% Large, 29% Small

#### What Do G2 Reviewers Say About OpenText Static Application Security Testing?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano le **facili integrazioni** di OpenText Static Application Security Testing, migliorando il loro flusso di lavoro con più strumenti.
- Gli utenti apprezzano le **ampie capacità di integrazione** di OpenText Static Application Security Testing con vari strumenti di terze parti.
- Gli utenti apprezzano il **supporto esteso per l'integrazione** con varie tecnologie e strumenti di terze parti offerto da OpenText Static Application Security Testing.

##### Cons

- Gli utenti sono delusi dai **falsi positivi** , ma apprezzano la possibilità di ignorare i problemi nelle scansioni future.

#### What Are Recent G2 Reviews of OpenText Static Application Security Testing?

**["Fortify Static Code Analyzer (SCA)"](https://www.g2.com/it/survey_responses/opentext-static-application-security-testing-review-10770814)**

**Rating:** 4.0/5.0 stars

_— Lokesh T._

[Read full review](https://www.g2.com/it/survey_responses/opentext-static-application-security-testing-review-10770814)

**["Analizzatore di Codice efficiente e facile da usare"](https://www.g2.com/it/survey_responses/opentext-static-application-security-testing-review-7271508)**

**Rating:** 4.5/5.0 stars

_— Nav N._

[Read full review](https://www.g2.com/it/survey_responses/opentext-static-application-security-testing-review-7271508)

#### What Are G2 Users Discussing About OpenText Static Application Security Testing?

- [A cosa serve Fortify Static Code Analyzer?](https://www.g2.com/it/discussions/what-is-fortify-static-code-analyzer-used-for)
- [What tools does fortify include?](https://www.g2.com/it/discussions/what-tools-does-fortify-include)
- [Quali sono i componenti principali di Fortify?](https://www.g2.com/it/discussions/fortify-static-code-analyzer-what-are-the-main-components-of-fortify) - 1 comment
- [What is Fortify software used for?](https://www.g2.com/it/discussions/fortify-static-code-analyzer-what-is-fortify-software-used-for)
- [What is Micro Focus Fortify static code analyzer?](https://www.g2.com/it/discussions/what-is-micro-focus-fortify-static-code-analyzer)

### [Kiuwan Code Security & Insights](https://www.g2.com/products/kiuwan-code-security-insights/reviews)

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

**Average Rating:** 4.5/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate Kiuwan Code Security & Insights?

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.7/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Kiuwan Code Security & Insights?

- **Seller:** [Sembi](https://www.g2.com/sellers/sembi)
- **Company Website:** www.sembi.com
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7ed5860a727a31b32edfba64808a6ea32fccad50d052e993a08b626d675d5c69&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsembi-inc%2F&secure%5Burl_type%5D=linkedin_company_website)  
94 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Banking
- **Company Size:** 41% Large, 35% Medium

#### What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **accuracy of the results** from Kiuwan Code Security & Insights, enhancing their overall experience.
- Users value the **accuracy of findings** from Kiuwan, enhancing their satisfaction with code security and reporting.
- Users commend the **efficient customer support** of Kiuwan, ensuring timely assistance and strong satisfaction overall.
- Users appreciate the **user-friendly interface** of Kiuwan Code Security & Insights, making it very easy to navigate.
- Users appreciate the **user-friendly interface** of Kiuwan Code Security & Insights, enhancing ease of use for dashboards.

#### What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

**["Impeccable Security and Code Analysis, with Potential for Improvement in Customization"](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)**

**Rating:** 5.0/5.0 stars

_— Abelardo I._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)

**["Elevated our software security to the next level. Improved our code quality."](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)**

**Rating:** 5.0/5.0 stars

_— Abdullah Enes K._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)

### [Codacy](https://www.g2.com/products/codacy/reviews)

Codacy is the code quality and security platform for AI-assisted engineering teams. AI is now embedded through the engineering workflow, which has made teams faster, but also adds risk to everything they ship. Codacy helps AI-assisted teams ship high-quality, secure code across the full software development lifecycle, starting in the agent and editor, through pull requests in Git, and into containers and runtime security. At each stage we check for quality issues, security vulnerabilities and AI coding risk introduced into the codebase, and help devs and agent fix them effortlessly. A team's standards become automated guardrails that apply across every IDE, AI coding agent, and Pull Request. More than 250,000 developers rely on Codacy to keep quality and security stable as AI changes how software gets built. Add your repo and get your free scan report in minutes: https://codacy.com

**Average Rating:** 4.6/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate Codacy?

- **Has the product been a good partner in doing business?:** 9.1/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Codacy?

- **Seller:** [Codacy](https://www.g2.com/sellers/codacy)
- **Year Founded:** 2012
- **HQ Location:** Lisbon, Lisboa
- **Twitter:** @codacy  
5,002 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=cfb2ce473f29d659861c3939070bb76f085fb14394ceeb1e11c4d3c449846d0f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F3310124%2F&secure%5Burl_type%5D=linkedin_company_website)  
69 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 59% Small, 24% Medium

#### What Do G2 Reviewers Say About Codacy?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **enhanced security features** of Codacy, benefiting from integrated automation and insightful vulnerability management.
- Users appreciate the **integrated automation** of Codacy, finding it easy to use and helpful for maintaining code quality.
- Users find the **out-of-the-box automation** in Codacy to be user-friendly and effective for maintaining code quality.
- Users value the **high code quality** provided by Codacy's integrated automation and effective static code analyses.
- Users value the **helpful customer support** of Codacy, appreciating their immediate assistance during integration and security management.

##### Cons

- Users find Codacy **expensive** at $19/month, which can be a barrier for smaller organizations.

#### What Are Recent G2 Reviews of Codacy?

**["Codacy is a security must-have tool in our company"](https://www.g2.com/survey_responses/codacy-review-10264506)**

**Rating:** 5.0/5.0 stars

_— David M._

[Read full review](https://www.g2.com/survey_responses/codacy-review-10264506)

**["Easy GitHub & CI/CD Integration That Catches Bugs Before Production"](https://www.g2.com/survey_responses/codacy-review-12739228)**

**Rating:** 4.5/5.0 stars

_— Arjun M._

[Read full review](https://www.g2.com/survey_responses/codacy-review-12739228)

### [Black Duck Coverity Static](https://www.g2.com/products/black-duck-coverity-static/reviews)

Coverity® is a fast, accurate, and highly scalable static analysis (SAST) solution that helps development and security teams address security and quality defects early in the software development life cycle (SDLC), track and manage risks across the application portfolio, and ensure compliance with security and coding standards.

**Average Rating:** 4.3/5.0

**Total Reviews:** 65

#### How Do G2 Users Rate Black Duck Coverity Static?

- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Black Duck Coverity Static?

- **Seller:** [Black Duck](https://www.g2.com/sellers/black-duck)
- **Year Founded:** 2024
- **HQ Location:** Burlington, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ca66ef383f133f101804712b9ed7a89aec2633a8efa048bd261db3b92eb47e73&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fblack-duck-software&secure%5Burl_type%5D=linkedin_company_website)  
1,304 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 55% Large, 34% Medium

#### What Are Recent G2 Reviews of Black Duck Coverity Static?

**["Effective Static Code Analysis with Great Integration, but Outdated UI"](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10763088)**

**Rating:** 5.0/5.0 stars

_— Lokesh T._

[Read full review](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10763088)

**["A decent security software for any organization which is lighweight and useful also."](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10522202)**

**Rating:** 4.5/5.0 stars

_— Ambrish M._

[Read full review](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10522202)

#### What Are G2 Users Discussing About Black Duck Coverity Static?

- [What is Coverity used for?](https://www.g2.com/discussions/what-is-coverity-used-for)
- [What is coverity connect?](https://www.g2.com/discussions/what-is-coverity-connect)
- [How does Coverity Static Analysis work?](https://www.g2.com/discussions/how-does-coverity-static-analysis-work)
- [What is Coverity report?](https://www.g2.com/discussions/what-is-coverity-report)
- [What is Coverity software?](https://www.g2.com/discussions/what-is-coverity-software)

### [OpenText Core Application Security](https://www.g2.com/products/opentext-core-application-security/reviews)

Fortify on Demand (FoD) is a complete Application Security as a Service solution. It offers an easy way to get started with the flexibility to scale. In addition to static and dynamic, Fortify on Demand covers in-depth mobile app security testing, open-source analysis, and vendor application security management. False positives are removed for every test and test results can be manually reviewed by application security experts.

**Average Rating:** 4.1/5.0

**Total Reviews:** 34

#### How Do G2 Users Rate OpenText Core Application Security?

- **Has the product been a good partner in doing business?:** 9.0/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.2/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind OpenText Core Application Security?

- **Seller:** [OpenText](https://www.g2.com/sellers/opentext)
- **Year Founded:** 1991
- **HQ Location:** Waterloo, ON
- **Twitter:** @OpenText  
21,565 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c339a6555764b5ffce77c3df08d6ed9c9b1cb1ee1baeebac8435f0485b7cca5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2709%2F&secure%5Burl_type%5D=linkedin_company_website)  
23,048 employees on LinkedIn®
- **Ownership:** NASDAQ:OTEX

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 41% Large, 32% Small

#### What Are Recent G2 Reviews of OpenText Core Application Security?

**["Review of MicroFocus Application Defender"](https://www.g2.com/survey_responses/opentext-core-application-security-review-8781016)**

**Rating:** 4.5/5.0 stars

_— sohrab a._

[Read full review](https://www.g2.com/survey_responses/opentext-core-application-security-review-8781016)

**["Safe and Secured Barrier"](https://www.g2.com/survey_responses/opentext-core-application-security-review-8819443)**

**Rating:** 4.5/5.0 stars

_— Ajinkya M._

[Read full review](https://www.g2.com/survey_responses/opentext-core-application-security-review-8819443)

#### What Are G2 Users Discussing About OpenText Core Application Security?

- [What are the main components of Fortify?](https://www.g2.com/discussions/micro-focus-fortify-on-demand-what-are-the-main-components-of-fortify)
- [How does Fortify on Demand work?](https://www.g2.com/discussions/how-does-fortify-on-demand-work)
- [What is Fortify software used for?](https://www.g2.com/discussions/micro-focus-fortify-on-demand-what-is-fortify-software-used-for)
- [What is Micro Focus Fortify on Demand?](https://www.g2.com/discussions/what-is-micro-focus-fortify-on-demand)

### [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews)

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

**Average Rating:** 3.8/5.0

**Total Reviews:** 25

#### How Do G2 Users Rate Veracode Application Security Platform?

- **Has the product been a good partner in doing business?:** 7.9/10 (Category avg: 8.7/10)
- **Ease of Admin:** 7.4/10 (Category avg: 8.5/10)
- **Ease of Use:** 7.3/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Veracode Application Security Platform?

- **Seller:** [VERACODE](https://www.g2.com/sellers/veracode)
- **Year Founded:** 2006
- **HQ Location:** Burlington, MA
- **Twitter:** @Veracode  
21,950 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d799a3c2e821841d648bc54266ea8fb1c07039938aa9c79b60d2cf275f0dcf34&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F27845%2F&secure%5Burl_type%5D=linkedin_company_website)  
500 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 69% Large, 31% Medium

#### What Do G2 Reviewers Say About Veracode Application Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **effective security vulnerability identification** offered by Veracode, enhancing overall application safety and code integrity.
- Users find Veracode's **vulnerability detection** excellent for identifying security issues and ensuring high application security standards.
- Users value the **automated scanning** of Veracode, streamlining security checks and enhancing code quality effortlessly.
- Users value the **effective detection of security vulnerabilities** , enabling robust protection and streamlined development processes.
- Users appreciate the **ease of integration** with GitHub and CI/CD pipelines, streamlining their development process effectively.

##### Cons

- Users find Veracode to be **expensive** , with high costs, complex licensing, and unfulfilled feature delivery.
- Users face a **lack of information** due to mismatches in documentation and delayed notifications during uploads.
- Users express concerns over **licensing issues** , including rising costs, complex models, and unequal feature availability.
- Users report **poor customer support** with pushy account executives and difficulties in resolving issues efficiently.
- Users express concerns about **pricing issues** , with rising costs and a complex licensing model affecting value perception.

#### What Are Recent G2 Reviews of Veracode Application Security Platform?

**["Streamlined Security, Effortless Integration"](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)**

**Rating:** 5.0/5.0 stars

_— Bhanu Prakash M._

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)

**["Clear, Unified View of Application Capabilities"](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)**

**Rating:** 4.5/5.0 stars

_— Christopher S._

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)

#### What Are G2 Users Discussing About Veracode Application Security Platform?

- [What is difference between veracode and SonarQube?](https://www.g2.com/discussions/what-is-difference-between-veracode-and-sonarqube)
- [What is veracode software composition analysis?](https://www.g2.com/discussions/what-is-veracode-software-composition-analysis)
- [What is veracode used for?](https://www.g2.com/discussions/what-is-veracode-used-for)
- [What is the veracode application security platform?](https://www.g2.com/discussions/what-is-the-veracode-application-security-platform)

### [DeepSource](https://www.g2.com/products/deepsource/reviews)

DeepSource is an all-in-one code health platform that equips organizations with everything they need to build maintainable and secure software while elevating the velocity of their software development cycle. - Guaranteed below 5% false-positive rate with highly accurate and fast static analyzers - Automated issue remediation with Autofix™️ - Code Issue and security reporting: OWASP Top 10, SANS Top 25, Code Coverage, and more - Self-hosted option with one-click installation and upgrades

**Average Rating:** 4.6/5.0

**Total Reviews:** 22

#### How Do G2 Users Rate DeepSource?

- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 8.7/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.3/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 3.3/10 (Category avg: 10/10)

#### Who Is the Company Behind DeepSource?

- **Seller:** [DeepSource](https://www.g2.com/sellers/deepsource)
- **Year Founded:** 2018
- **HQ Location:** San Francisco, California
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=20c7bc7353304ceb3d27b4a1c986a07b118ff9a41546330e1218fbaf1bfccbd2&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdeepsourcelabs%2F&secure%5Burl_type%5D=linkedin_company_website)  
20 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 82% Small, 9% Large

#### What Are Recent G2 Reviews of DeepSource?

**["Excellent service"](https://www.g2.com/survey_responses/deepsource-review-7648888)**

**Rating:** 4.5/5.0 stars

_— Verified User in Transportation/Trucking/Railroad_

[Read full review](https://www.g2.com/survey_responses/deepsource-review-7648888)

**["Code health automation at its best"](https://www.g2.com/survey_responses/deepsource-review-7636137)**

**Rating:** 4.5/5.0 stars

_— David P._

[Read full review](https://www.g2.com/survey_responses/deepsource-review-7636137)

#### What Are G2 Users Discussing About DeepSource?

- [Which type of tools perform static analysis of code?](https://www.g2.com/discussions/which-type-of-tools-perform-static-analysis-of-code)
- [What kind of analysis is performed by static checker?](https://www.g2.com/discussions/what-kind-of-analysis-is-performed-by-static-checker)
- [What is DeepSource io?](https://www.g2.com/discussions/what-is-deepsource-io)
- [How does DeepSource work?](https://www.g2.com/discussions/how-does-deepsource-work)

### [Embold](https://www.g2.com/products/embold/reviews)

Embold supports developers and development teams by finding critical code issues before they become roadblocks. It is the perfect tool to analyze, diagnose, transform, and sustain your software efficiently. With the use of A.I. and machine learning technologies, Embold can immediately prioritize issues, suggest ways to best solve them, and re-factor software where necessary. Run it within your current Dev-Ops stack, on premise or in the cloud privately or publicly.

**Average Rating:** 4.7/5.0

**Total Reviews:** 15

#### How Do G2 Users Rate Embold?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.7/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.4/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Embold?

- **Seller:** [Embold Technologies](https://www.g2.com/sellers/embold-technologies)
- **Year Founded:** 2009
- **HQ Location:** Frankfurt am Main, Hesse
- **Twitter:** @embold\_io  
1,054 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ba92789dafb1da172547fc9157f79da5c6998b039574051c7c0eef906acdcf64&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1727876%2F&secure%5Burl_type%5D=linkedin_company_website)  
12 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 56% Small, 28% Medium

#### What Are Recent G2 Reviews of Embold?

**["Simple and Meaningful"](https://www.g2.com/survey_responses/embold-review-4111852)**

**Rating:** 5.0/5.0 stars

_— Swarup B._

[Read full review](https://www.g2.com/survey_responses/embold-review-4111852)

**["Meaningful and actionable insights into your code"](https://www.g2.com/survey_responses/embold-review-4014679)**

**Rating:** 5.0/5.0 stars

_— Amit A._

[Read full review](https://www.g2.com/survey_responses/embold-review-4014679)

### [Codiga](https://www.g2.com/products/codiga/reviews)

Automate your code reviews and write faster code with Codiga Coding Assistant. Codiga proposes two products: 1. Automated Code Reviews on GitHub, GitLab, and Bitbucket 2. Smart Coding Assistant to help developers find and import safe and reliable code patterns directly in their IDE.

**Average Rating:** 4.6/5.0

**Total Reviews:** 21

#### How Do G2 Users Rate Codiga?

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 8.7/10)
- **Ease of Admin:** 9.2/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.5/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 3.3/10 (Category avg: 10/10)

#### Who Is the Company Behind Codiga?

- **Seller:** [Codiga](https://www.g2.com/sellers/codiga)
- **Year Founded:** 2020
- **HQ Location:** Denver, US
- **Twitter:** @getcodiga  
970 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=efb523bdecb2cf44585ac2b1fc59a585878ab952e61610637a8b57c8cff17c1c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcodigahq%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 67% Small, 19% Large

#### What Are Recent G2 Reviews of Codiga?

**["An extremely useful tool"](https://www.g2.com/survey_responses/codiga-review-6986608)**

**Rating:** 5.0/5.0 stars

_— Daniel G._

[Read full review](https://www.g2.com/survey_responses/codiga-review-6986608)

**["great automated code review"](https://www.g2.com/survey_responses/codiga-review-7141195)**

**Rating:** 4.0/5.0 stars

_— Glenn D._

[Read full review](https://www.g2.com/survey_responses/codiga-review-7141195)

#### What Are G2 Users Discussing About Codiga?

- [What is Codiga used for?](https://www.g2.com/discussions/what-is-codiga-used-for)

### [Pylint](https://www.g2.com/products/pylint/reviews)

Pylint is a tool that checks for errors in Python code, tries to enforce a coding standard and looks for bad code smells.

**Average Rating:** 4.2/5.0

**Total Reviews:** 18

#### How Do G2 Users Rate Pylint?

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.3/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Pylint?

- **Seller:** [Pylint](https://www.g2.com/sellers/pylint)
- **Year Founded:** 2019
- **HQ Location:** Z√ºrich, Z√ºrich
- **Twitter:** @pylint  
2 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7886df2ed926834e5eb248c77dcfa8e5c815d3ab1f0fe3132ced0dba45868834&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FNo-Linkedin-Presence-Added-Intentionally-By-DataOps&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 53% Large, 32% Medium

#### What Are Recent G2 Reviews of Pylint?

**["Best quality tracking tool for python"](https://www.g2.com/survey_responses/pylint-review-1820520)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/pylint-review-1820520)

**["Pylint quickly catches error in your python code"](https://www.g2.com/survey_responses/pylint-review-3375995)**

**Rating:** 4.5/5.0 stars

_— Ernest K._

[Read full review](https://www.g2.com/survey_responses/pylint-review-3375995)

### [GuardRails](https://www.g2.com/products/guardrails-guardrails/reviews)

GuardRails is an end-to-end security platform that makes AppSec easier for both security and development teams. We scan, detect, and provide real-time guidance to fix vulnerabilities early. Trusted by hundreds of teams around the world to build safer apps, GuardRails integrates seamlessly into the developers’ workflow, quietly scans as they code, and shows how to fix security issues on the spot via Just-in-Time training. GuardRails commits to keeping the noise low and only reporting high-impact vulnerabilities that are relevant to your organization. GuardRails helps organizations shift security everywhere and build a strong DevSecOps pipeline, so they can go faster to market without risking security.

**Average Rating:** 4.3/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate GuardRails?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.7/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.3/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind GuardRails?

- **Seller:** [GuardRails](https://www.g2.com/sellers/guardrails)
- **Year Founded:** 2017
- **HQ Location:** Singapore, Singapore
- **Twitter:** @guardrailsio  
1,553 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6be090277f6c8c141e1d2ae05a89f7c1ee759f1313bdebe23b0a48edda8ba158&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F13599521&secure%5Burl_type%5D=linkedin_company_website)  
13 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 52% Small, 48% Medium

#### What Do G2 Reviewers Say About GuardRails?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **robust security features** of GuardRails, ensuring efficient code scans and vulnerability management in DevSecOps.
- Users value the **vulnerability detection** capabilities of GuardRails, enhancing security with automated, comprehensive code scans.
- Users find GuardRails **easy to use** , offering integrated feedback on security issues directly within their development environment.
- Users value the **error reduction** capabilities of GuardRails, enabling early detection and swift resolution of security issues.
- Users value the **effective threat detection** of GuardRails, ensuring secure code and timely vulnerability alerts during development.

##### Cons

- Users note **missing features** in GuardRails, such as limited developer support and lack of report generation capabilities.
- Users find **time management challenging** with GuardRails due to insufficient resources and requirement for constant supervision.
- Users face **bug issues** with GuardRails, resulting in frequent bottlenecks and complications during code pushing.
- Users face challenges with **dashboard issues** , including insufficient report generation and syncing difficulties for new users.
- Users report **false positives** in GuardRails, which can complicate the vulnerability management process despite a helpful dashboard.

#### What Are Recent G2 Reviews of GuardRails?

**["A must tool for security"](https://www.g2.com/survey_responses/guardrails-review-8536638)**

**Rating:** 4.0/5.0 stars

_— Sanjeev M._

[Read full review](https://www.g2.com/survey_responses/guardrails-review-8536638)

**["Security and Flexibility with GuardRails"](https://www.g2.com/survey_responses/guardrails-review-8956655)**

**Rating:** 4.0/5.0 stars

_— Muhammad S._

[Read full review](https://www.g2.com/survey_responses/guardrails-review-8956655)

### [Codecov](https://www.g2.com/products/codecov/reviews)

Codecov is a code coverage tool.

**Average Rating:** 3.9/5.0

**Total Reviews:** 10

#### How Do G2 Users Rate Codecov?

- **Has the product been a good partner in doing business?:** 4.2/10 (Category avg: 8.7/10)
- **Ease of Admin:** 7.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.1/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Codecov?

- **Seller:** [Codecov](https://www.g2.com/sellers/codecov)
- **Year Founded:** 2015
- **HQ Location:** San Francisco, California
- **Twitter:** @codecov  
3,067 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fd91c7b3ba5e405ed94c1e1027654be62c088e0336ffb5b98028f7b4f23d6335&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcodecov%2F&secure%5Burl_type%5D=linkedin_company_website)  
2 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 50% Small, 40% Medium

#### What Are Recent G2 Reviews of Codecov?

**["The reports generated are informational and helpfull"](https://www.g2.com/survey_responses/codecov-review-9313369)**

**Rating:** 4.5/5.0 stars

_— Sagar S._

[Read full review](https://www.g2.com/survey_responses/codecov-review-9313369)

**["Decoding Codecov: Uncovering Ratings and Impact in Development"](https://www.g2.com/survey_responses/codecov-review-9074928)**

**Rating:** 4.5/5.0 stars

_— Verified User in Automotive_

[Read full review](https://www.g2.com/survey_responses/codecov-review-9074928)

#### What Are G2 Users Discussing About Codecov?

- [What is Codecov Yml?](https://www.g2.com/discussions/what-is-codecov-yml)
- [What is Codecov GitHub?](https://www.g2.com/discussions/what-is-codecov-github)
- [Who is using Codecov?](https://www.g2.com/discussions/who-is-using-codecov)

### [codebeat](https://www.g2.com/products/codebeat/reviews)

codebeat is an automated review for web and mobile that gathers the results of static code analysis into a single, real-time report that gives all project stakeholders the information required to identify code smells, security holes and improve code quality.

**Average Rating:** 4.8/5.0

**Total Reviews:** 6

#### How Do G2 Users Rate codebeat?

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 8.7/10)
- **Ease of Admin:** 9.4/10 (Category avg: 8.5/10)
- **Ease of Use:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind codebeat?

- **Seller:** [codequest](https://www.g2.com/sellers/codequest)
- **Year Founded:** 2014
- **HQ Location:** Warsaw, PL
- **Twitter:** @codebeatapp  
244 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a02e140a2e4eab23c6ae64801d3735a02b294bf8cc7c3b716f29556ec9433c63&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F9184059%2F&secure%5Burl_type%5D=linkedin_company_website)  
3 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 50% Small, 33% Medium

#### What Are Recent G2 Reviews of codebeat?

**["I just Love it!"](https://www.g2.com/survey_responses/codebeat-review-206516)**

**Rating:** 5.0/5.0 stars

_— Sacha D._

[Read full review](https://www.g2.com/survey_responses/codebeat-review-206516)

**["Great Code analysis tool for cloud CIs"](https://www.g2.com/survey_responses/codebeat-review-206968)**

**Rating:** 5.0/5.0 stars

_— Timothy S._

[Read full review](https://www.g2.com/survey_responses/codebeat-review-206968)

- &lsaquo; Prev ‹ Prev
- 1
- [2](/categories/static-code-analysis/f/python?filters%5BLanguages+and+Environments%5D%5B%5D=303&order=g2_score&page=2#product-list)
- [Next &rsaquo; Next ›](/categories/static-code-analysis/f/python?filters%5BLanguages+and+Environments%5D%5B%5D=303&order=g2_score&page=2#product-list)

Spotlight Categories

[Identity Verification Software](https://www.g2.com/categories/identity-verification)

[Business Continuity Management (BCM) Software Solutions](https://www.g2.com/categories/business-continuity-management-software)

[Survey Software](https://www.g2.com/categories/survey)

[Attribution Software](https://www.g2.com/categories/attribution)

[Threat Intelligence Software](https://www.g2.com/categories/threat-intelligence)

Similar Categories

- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)
- [Log Analysis](/categories/log-analysis)

- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Static Code Analysis Themes](/categories/static-code-analysis/themes)

Below are the top-rated Static Code Analysis Tools with Python capabilities, as verified by G2’s Research team. Real users have identified Python as an important function of Static Code Analysis Tools. Compare different products that offer this feature so you can decide which is best for your business needs.

Show More