# Best Static Code Analysis Tools with Ruby Capabilities

## How Many Static Code Analysis Tools Products Does G2 Track?

**Total Products under this Category:** 131

### Category Stats (Aug 2026)

- **Average Rating:** 4.38/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Black Duck Coverity Static (+0.61%) - Among all products in this category, Black Duck Coverity Static recorded the largest rating increase compared to last month

_Last updated: August 07, 2026_

## How Does G2 Rank Static Code Analysis Tools Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 2,200+ Authentic Reviews
- 131+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Static Code Analysis Tools
 ![G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence](https://www.g2.com/categories/static-code-analysis/grids.png?focus%5B%5D=7775&focus%5B%5D=102905&focus%5B%5D=1385185&focus%5B%5D=4475&focus%5B%5D=1225549&focus%5B%5D=161987&focus%5B%5D=48275&focus%5B%5D=1225688)

Highlighted products: SonarQube, Gearset DevOps, SoftSpell, Checkmarx, Semgrep, CAST Imaging, ReSharper C++, and Typo.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=softspell&focus%5B%5D=checkmarx&focus%5B%5D=semgrep&focus%5B%5D=cast-imaging&focus%5B%5D=resharper-c&focus%5B%5D=typo)

**Sponsored**

### Endor Labs

Endor Labs turns application security into a competitive advantage. At the core is AURI, the security harness for agentic development. It helps coding agents write secure code by default, automates PR security reviews, and gives agents deterministic context to fix what matters fast. At the core is our patented code context graph: a continuously updated model of application behavior across code, dependencies, secrets, and containers. The result: 83% fewer blocked PRs, 10x fewer security tickets, and 6x faster remediation at Atlassian, Cursor, Rubrik, and Snowflake.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=564&secure%5Bchosen_at%5D=2026-08-13T18%3A45%3A12Z&secure%5Bdisplayable_resource_id%5D=2041&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=2041&secure%5Bplacement_resource_ids%5D%5B%5D=1520&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1317430&secure%5Bresource_id%5D=564&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fstatic-code-analysis%2Ff%2Fruby&secure%5Btoken%5D=e22e437e7b79b971bccd08c46a4a769621a5eb11462efff746ca33724e64ed95&secure%5Burl%5D=https%3A%2F%2Fwww.endorlabs.com%2Fplatform%3Futm_source%3Dg2%26utm_medium%3Ddisplay%26utm_campaign%3Dg2-ad&secure%5Burl_type%5D=custom_url)

### [SonarQube](https://www.g2.com/products/sonarqube/reviews)

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 153

#### How Do G2 Users Rate SonarQube?

- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind SonarQube?

- **Seller:** [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)
- **Company Website:** www.sonarsource.com
- **Year Founded:** 2008
- **HQ Location:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** DevOps Engineer, Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 41% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Users value how SonarQube **efficiently flags code quality and security issues** , ensuring a clean and maintainable codebase.
- Users value the **issue filtering and prioritization features** of SonarQube, enhancing focus on high-priority tasks.
- Users value the **issue identification and prioritization** features of SonarQube, improving focus on critical tasks.
- Users find SonarQube's **ease of use** invaluable for maintaining code quality and integrating seamlessly into development workflows.
- Users appreciate the **easy integrations** with existing CI/CD tools, enhancing their development workflow seamlessly.

##### Cons

- Users face challenges with **software bugs** as SonarQube can consume excessive RAM and occasionally reports false positives.
- Users find SonarQube's configuration **complex** , especially for beginners, leading to difficulties and overwhelming warnings to manage.
- Users encounter **false positives** that complicate evaluations, though mitigation options exist through detailed analysis and rule customization.
- Users find that SonarQube's **complexity in configuration** and excessive warnings can hinder effective usage and efficiency.
- Users find the **complex setup** of SonarQube challenging, especially for beginners unfamiliar with the configuration process.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube: Easy Integration, Simple UI, and Solid Free Code Quality Scanning"](https://www.g2.com/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-12975264)

**["SonarQube Catches Issues Early with Clear, Actionable Reports"](https://www.g2.com/survey_responses/sonarqube-review-13204491)**

**Rating:** 4.0/5.0 stars

_— Kewin M._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-13204491)

#### What Are G2 Users Discussing About SonarQube?

- [What is SonarLint used for?](https://www.g2.com/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)

### [Checkmarx](https://www.g2.com/products/checkmarx/reviews)

Checkmarx is a type of application security solution designed to help organizations safeguard their software development processes while enhancing efficiency and reducing costs. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. With the increasing reliance on AI technologies and the rapid pace of software development, Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as AI SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

**Average Rating:** 4.2/5.0

**Total Reviews:** 44

#### How Do G2 Users Rate Checkmarx?

- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.2/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Checkmarx?

- **Seller:** [Checkmarx](https://www.g2.com/sellers/checkmarx)
- **Company Website:** www.checkmarx.com
- **Year Founded:** 2006
- **HQ Location:** Paramus, NJ
- **Twitter:** @Checkmarx  
7,284 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=18f6741e77df71b112ecb3ec6620912d3a0f67666525358c0a4f3b1278b173df&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheckmarx&secure%5Burl_type%5D=linkedin_company_website)  
1,019 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 56% Large, 23% Medium

#### What Do G2 Reviewers Say About Checkmarx?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Checkmarx **easy to implement** , seamlessly integrating into existing repositories with a user-friendly interface.
- Users appreciate the **intuitive user interface** of Checkmarx, making security reviews simple and user-friendly.
- Users value the **accuracy of results** from Checkmarx, as it simplifies security reviews with detailed vulnerability insights.
- Users value the **automation testing capabilities** of Checkmarx, finding it easy to integrate and use effectively.
- Users praise the **exceptional customer support** at Checkmarx, ensuring prompt assistance for any unresolved issues.

##### Cons

- Users face a high number of **false positives** in Checkmarx when working with Kotlin projects, affecting accuracy and reliability.
- Users report **lacking feature support** for Kotlin, leading to numerous false positives not seen in Java or JavaScript.
- Users experience **missing features** in Checkmarx, specifically regarding poor support for Kotlin that leads to false positives.
- Users find the **poor navigation** in Checkmarx frustrating, as the dashboard layout and display need enhancement.

#### What Are Recent G2 Reviews of Checkmarx?

**["Automated Checkmarx Scans Keep Us Ahead of Key Vulnerabilities"](https://www.g2.com/survey_responses/checkmarx-review-12983770)**

**Rating:** 4.5/5.0 stars

_— Nitesh A._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12983770)

**["Centralized Source Code Security with Seamless CI/CD Integration"](https://www.g2.com/survey_responses/checkmarx-review-12980590)**

**Rating:** 5.0/5.0 stars

_— Aman M._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12980590)

#### What Are G2 Users Discussing About Checkmarx?

- [What is Checkmarx used for?](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for) - 1 comment, 1 upvote
- [How much does Checkmarx cost?](https://www.g2.com/discussions/how-much-does-checkmarx-cost)
- [Which testing method does Checkmarx support?](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support) - 1 comment
- [Does Checkmarx support DAST?](https://www.g2.com/discussions/does-checkmarx-support-dast) - 1 comment
- [What is Checkmarx used for?](https://www.g2.com/discussions/what-is-checkmarx-used-for) - 2 comments

### [OpenText Static Application Security Testing](https://www.g2.com/products/opentext-static-application-security-testing/reviews)

OpenText™ Static Application Security Testing (SAST) is a comprehensive solution designed to identify and remediate security vulnerabilities within an application's source code during the early stages of development. By analyzing code from the "inside out," SAST provides immediate feedback to developers, enabling them to address security issues promptly and effectively. Key Features and Functionality: - Extensive Language Support: Supports over 33 programming languages and more than 1,400 vulnerability categories, ensuring broad applicability across various development environments. - Integration with Development Tools: Seamlessly integrates with popular Integrated Development Environments (IDEs) such as Eclipse, Visual Studio, and JetBrains, as well as Continuous Integration/Continuous Deployment (CI/CD) tools like Jenkins and Bamboo, facilitating a smooth incorporation into existing workflows. - Scalable Deployment Options: Offers flexible deployment models, including on-premises, cloud-based, and Software as a Service (SaaS) solutions, allowing organizations to choose the setup that best fits their needs. - Advanced Analysis Capabilities: Utilizes multiple algorithms and an expansive knowledge base of secure coding rules to perform thorough code analysis, pinpointing the root causes of vulnerabilities and providing detailed remediation guidance. Primary Value and Problem Solved: OpenText SAST empowers organizations to proactively manage application security by detecting and addressing vulnerabilities early in the Software Development Life Cycle (SDLC). This proactive approach reduces the risk of security breaches, minimizes the cost and effort associated with late-stage remediation, and enhances the overall security posture of applications. By integrating security testing into the development process, OpenText SAST helps developers create more secure code, leading to robust and reliable software products.

**Average Rating:** 4.5/5.0

**Total Reviews:** 21

#### How Do G2 Users Rate OpenText Static Application Security Testing?

- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.1/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.7/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind OpenText Static Application Security Testing?

- **Seller:** [OpenText](https://www.g2.com/sellers/opentext)
- **Year Founded:** 1991
- **HQ Location:** Waterloo, ON
- **Twitter:** @OpenText  
21,565 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c339a6555764b5ffce77c3df08d6ed9c9b1cb1ee1baeebac8435f0485b7cca5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2709%2F&secure%5Burl_type%5D=linkedin_company_website)  
23,048 employees on LinkedIn®
- **Ownership:** NASDAQ:OTEX

#### Who Uses This Product?

- **Top Industries:** Banking, Financial Services
- **Company Size:** 50% Large, 29% Small

#### What Do G2 Reviewers Say About OpenText Static Application Security Testing?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **easy integrations** of OpenText Static Application Security Testing with various third-party tools for enhanced functionality.
- Users value the **extensive integration capabilities** of OpenText Static Application Security Testing with various third-party tools.
- Users value the **integration support** of OpenText Static Application Security Testing, enhancing compatibility with various tools and technologies.

##### Cons

- Users find the **false positives** in OpenText Static Application Security Testing somewhat problematic, despite options to ignore them.

#### What Are Recent G2 Reviews of OpenText Static Application Security Testing?

**["Fortify Static Code Analyzer (SCA)"](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-10770814)**

**Rating:** 4.0/5.0 stars

_— Lokesh T._

[Read full review](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-10770814)

**["Efficient and easy to use Code Analyzer"](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-7271508)**

**Rating:** 4.5/5.0 stars

_— Nav N._

[Read full review](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-7271508)

#### What Are G2 Users Discussing About OpenText Static Application Security Testing?

- [What is Fortify Static Code Analyzer used for?](https://www.g2.com/discussions/what-is-fortify-static-code-analyzer-used-for)
- [What tools does fortify include?](https://www.g2.com/discussions/what-tools-does-fortify-include)
- [What are the main components of Fortify?](https://www.g2.com/discussions/fortify-static-code-analyzer-what-are-the-main-components-of-fortify) - 1 comment
- [What is Fortify software used for?](https://www.g2.com/discussions/fortify-static-code-analyzer-what-is-fortify-software-used-for)
- [What is Micro Focus Fortify static code analyzer?](https://www.g2.com/discussions/what-is-micro-focus-fortify-static-code-analyzer)

### [Kiuwan Code Security & Insights](https://www.g2.com/products/kiuwan-code-security-insights/reviews)

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

**Average Rating:** 4.5/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate Kiuwan Code Security & Insights?

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.7/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Kiuwan Code Security & Insights?

- **Seller:** [Sembi](https://www.g2.com/sellers/sembi)
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7ed5860a727a31b32edfba64808a6ea32fccad50d052e993a08b626d675d5c69&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsembi-inc%2F&secure%5Burl_type%5D=linkedin_company_website)  
94 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Banking
- **Company Size:** 41% Large, 35% Medium

#### What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **accuracy** of Kiuwan's code scans, ensuring reliable results and satisfaction with reporting capabilities.
- Users value the **accuracy of findings** from Kiuwan Code Security & Insights, enhancing their confidence in code security.
- Users appreciate the **efficient customer support** of Kiuwan, enhancing their overall experience and satisfaction with the product.
- Users value the **user-friendly interface** of Kiuwan, enhancing their experience with efficient code scans and reporting.
- Users appreciate the **user-friendly interface** of Kiuwan Code Security & Insights, making dashboard navigation easy and efficient.

#### What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

**["Impeccable Security and Code Analysis, with Potential for Improvement in Customization"](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)**

**Rating:** 5.0/5.0 stars

_— Abelardo I._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)

**["Elevated our software security to the next level. Improved our code quality."](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)**

**Rating:** 5.0/5.0 stars

_— Abdullah Enes K._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)

### [Codacy](https://www.g2.com/products/codacy/reviews)

Codacy is the code quality and security platform for AI-assisted engineering teams. AI is now embedded through the engineering workflow, which has made teams faster, but also adds risk to everything they ship. Codacy helps AI-assisted teams ship high-quality, secure code across the full software development lifecycle, starting in the agent and editor, through pull requests in Git, and into containers and runtime security. At each stage we check for quality issues, security vulnerabilities and AI coding risk introduced into the codebase, and help devs and agent fix them effortlessly. A team's standards become automated guardrails that apply across every IDE, AI coding agent, and Pull Request. More than 250,000 developers rely on Codacy to keep quality and security stable as AI changes how software gets built. Add your repo and get your free scan report in minutes: https://codacy.com

**Average Rating:** 4.6/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate Codacy?

- **Has the product been a good partner in doing business?:** 9.1/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Codacy?

- **Seller:** [Codacy](https://www.g2.com/sellers/codacy)
- **Year Founded:** 2012
- **HQ Location:** Lisbon, Lisboa
- **Twitter:** @codacy  
5,002 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=cfb2ce473f29d659861c3939070bb76f085fb14394ceeb1e11c4d3c449846d0f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F3310124%2F&secure%5Burl_type%5D=linkedin_company_website)  
69 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 59% Small, 24% Medium

#### What Do G2 Reviewers Say About Codacy?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **security dashboard and vulnerability management** features of Codacy for enhanced insights and code safety.
- Users value the **integrated automation** of Codacy, finding it user-friendly and effective for maintaining code quality.
- Users value the **integrated automation testing** in Codacy, appreciating its ease of use and effective quality control.
- Users value the **excellent code quality** features of Codacy, finding it easy to maintain clean and secure code.
- Users value the **helpful customer support** of Codacy, appreciating their immediate assistance for quick resolutions.

##### Cons

- Users find Codacy to be **a bit expensive** at $19/month, which may burden smaller organizations financially.

#### What Are Recent G2 Reviews of Codacy?

**["Codacy is a security must-have tool in our company"](https://www.g2.com/survey_responses/codacy-review-10264506)**

**Rating:** 5.0/5.0 stars

_— David M._

[Read full review](https://www.g2.com/survey_responses/codacy-review-10264506)

**["Easy GitHub & CI/CD Integration That Catches Bugs Before Production"](https://www.g2.com/survey_responses/codacy-review-12739228)**

**Rating:** 4.5/5.0 stars

_— Arjun M._

[Read full review](https://www.g2.com/survey_responses/codacy-review-12739228)

### [Black Duck Coverity Static](https://www.g2.com/products/black-duck-coverity-static/reviews)

Coverity® is a fast, accurate, and highly scalable static analysis (SAST) solution that helps development and security teams address security and quality defects early in the software development life cycle (SDLC), track and manage risks across the application portfolio, and ensure compliance with security and coding standards.

**Average Rating:** 4.3/5.0

**Total Reviews:** 65

#### How Do G2 Users Rate Black Duck Coverity Static?

- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Black Duck Coverity Static?

- **Seller:** [Black Duck](https://www.g2.com/sellers/black-duck)
- **Year Founded:** 2024
- **HQ Location:** Burlington, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ca66ef383f133f101804712b9ed7a89aec2633a8efa048bd261db3b92eb47e73&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fblack-duck-software&secure%5Burl_type%5D=linkedin_company_website)  
1,304 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 55% Large, 34% Medium

#### What Are Recent G2 Reviews of Black Duck Coverity Static?

**["Effective Static Code Analysis with Great Integration, but Outdated UI"](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10763088)**

**Rating:** 5.0/5.0 stars

_— Lokesh T._

[Read full review](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10763088)

**["A decent security software for any organization which is lighweight and useful also."](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10522202)**

**Rating:** 4.5/5.0 stars

_— Ambrish M._

[Read full review](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10522202)

#### What Are G2 Users Discussing About Black Duck Coverity Static?

- [What is Coverity used for?](https://www.g2.com/discussions/what-is-coverity-used-for)
- [What is coverity connect?](https://www.g2.com/discussions/what-is-coverity-connect)
- [How does Coverity Static Analysis work?](https://www.g2.com/discussions/how-does-coverity-static-analysis-work)
- [What is Coverity report?](https://www.g2.com/discussions/what-is-coverity-report)
- [What is Coverity software?](https://www.g2.com/discussions/what-is-coverity-software)

### [OpenText Core Application Security](https://www.g2.com/products/opentext-core-application-security/reviews)

Fortify on Demand (FoD) is a complete Application Security as a Service solution. It offers an easy way to get started with the flexibility to scale. In addition to static and dynamic, Fortify on Demand covers in-depth mobile app security testing, open-source analysis, and vendor application security management. False positives are removed for every test and test results can be manually reviewed by application security experts.

**Average Rating:** 4.1/5.0

**Total Reviews:** 34

#### How Do G2 Users Rate OpenText Core Application Security?

- **Has the product been a good partner in doing business?:** 9.0/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.2/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind OpenText Core Application Security?

- **Seller:** [OpenText](https://www.g2.com/sellers/opentext)
- **Year Founded:** 1991
- **HQ Location:** Waterloo, ON
- **Twitter:** @OpenText  
21,565 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c339a6555764b5ffce77c3df08d6ed9c9b1cb1ee1baeebac8435f0485b7cca5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2709%2F&secure%5Burl_type%5D=linkedin_company_website)  
23,048 employees on LinkedIn®
- **Ownership:** NASDAQ:OTEX

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 41% Large, 32% Small

#### What Are Recent G2 Reviews of OpenText Core Application Security?

**["Safe and Secured Barrier"](https://www.g2.com/survey_responses/opentext-core-application-security-review-8819443)**

**Rating:** 4.5/5.0 stars

_— Ajinkya M._

[Read full review](https://www.g2.com/survey_responses/opentext-core-application-security-review-8819443)

**["Review of MicroFocus Application Defender"](https://www.g2.com/survey_responses/opentext-core-application-security-review-8781016)**

**Rating:** 4.5/5.0 stars

_— sohrab a._

[Read full review](https://www.g2.com/survey_responses/opentext-core-application-security-review-8781016)

#### What Are G2 Users Discussing About OpenText Core Application Security?

- [What are the main components of Fortify?](https://www.g2.com/discussions/micro-focus-fortify-on-demand-what-are-the-main-components-of-fortify)
- [How does Fortify on Demand work?](https://www.g2.com/discussions/how-does-fortify-on-demand-work)
- [What is Fortify software used for?](https://www.g2.com/discussions/micro-focus-fortify-on-demand-what-is-fortify-software-used-for)
- [What is Micro Focus Fortify on Demand?](https://www.g2.com/discussions/what-is-micro-focus-fortify-on-demand)

### [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews)

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

**Average Rating:** 3.8/5.0

**Total Reviews:** 25

#### How Do G2 Users Rate Veracode Application Security Platform?

- **Has the product been a good partner in doing business?:** 7.9/10 (Category avg: 8.7/10)
- **Ease of Admin:** 7.4/10 (Category avg: 8.5/10)
- **Ease of Use:** 7.3/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Veracode Application Security Platform?

- **Seller:** [VERACODE](https://www.g2.com/sellers/veracode)
- **Year Founded:** 2006
- **HQ Location:** Burlington, MA
- **Twitter:** @Veracode  
21,950 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d799a3c2e821841d648bc54266ea8fb1c07039938aa9c79b60d2cf275f0dcf34&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F27845%2F&secure%5Burl_type%5D=linkedin_company_website)  
500 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 69% Large, 31% Medium

#### What Do G2 Reviewers Say About Veracode Application Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **comprehensive security analysis** offered by Veracode, effectively addressing vulnerabilities and streamlining development.
- Users value Veracode for its **effective vulnerability detection** , ensuring high-security standards and seamless integration into development processes.
- Users appreciate the **automated scanning** feature of Veracode, which effectively identifies vulnerabilities and enhances security standards.
- Users value the **effective detection capabilities** of Veracode, enabling thorough security checks and vulnerability identification.
- Users value the **ease of use** of Veracode, benefiting from seamless integration and comprehensive security analysis.

##### Cons

- Users find the platform to be **expensive** , with rising costs and unjustifiable investment in customer success packages.
- Users face a **lack of information** regarding features and services, leading to confusion and unmet expectations.
- Users express concerns about **licensing issues** , citing high costs, complex models, and unmet feature expectations.
- Users report **poor customer support** , experiencing pressure from sales and challenges with feature delivery and documentation.
- Users express concerns over **pricing issues** , citing increased costs, complex licensing, and pressure from sales executives.

#### What Are Recent G2 Reviews of Veracode Application Security Platform?

**["Streamlined Security, Effortless Integration"](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)**

**Rating:** 5.0/5.0 stars

_— Bhanu Prakash M._

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)

**["Clear, Unified View of Application Capabilities"](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)**

**Rating:** 4.5/5.0 stars

_— Christopher S._

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)

#### What Are G2 Users Discussing About Veracode Application Security Platform?

- [What is difference between veracode and SonarQube?](https://www.g2.com/discussions/what-is-difference-between-veracode-and-sonarqube)
- [What is veracode software composition analysis?](https://www.g2.com/discussions/what-is-veracode-software-composition-analysis)
- [What is veracode used for?](https://www.g2.com/discussions/what-is-veracode-used-for)
- [What is the veracode application security platform?](https://www.g2.com/discussions/what-is-the-veracode-application-security-platform)

### [DeepSource](https://www.g2.com/products/deepsource/reviews)

DeepSource is an all-in-one code health platform that equips organizations with everything they need to build maintainable and secure software while elevating the velocity of their software development cycle. - Guaranteed below 5% false-positive rate with highly accurate and fast static analyzers - Automated issue remediation with Autofix™️ - Code Issue and security reporting: OWASP Top 10, SANS Top 25, Code Coverage, and more - Self-hosted option with one-click installation and upgrades

**Average Rating:** 4.6/5.0

**Total Reviews:** 22

#### How Do G2 Users Rate DeepSource?

- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 8.7/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.3/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 3.3/10 (Category avg: 10/10)

#### Who Is the Company Behind DeepSource?

- **Seller:** [DeepSource](https://www.g2.com/sellers/deepsource)
- **Year Founded:** 2018
- **HQ Location:** San Francisco, California
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=20c7bc7353304ceb3d27b4a1c986a07b118ff9a41546330e1218fbaf1bfccbd2&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdeepsourcelabs%2F&secure%5Burl_type%5D=linkedin_company_website)  
20 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 82% Small, 9% Large

#### What Are Recent G2 Reviews of DeepSource?

**["Excellent service"](https://www.g2.com/survey_responses/deepsource-review-7648888)**

**Rating:** 4.5/5.0 stars

_— Verified User in Transportation/Trucking/Railroad_

[Read full review](https://www.g2.com/survey_responses/deepsource-review-7648888)

**["Code health automation at its best"](https://www.g2.com/survey_responses/deepsource-review-7636137)**

**Rating:** 4.5/5.0 stars

_— David P._

[Read full review](https://www.g2.com/survey_responses/deepsource-review-7636137)

#### What Are G2 Users Discussing About DeepSource?

- [Which type of tools perform static analysis of code?](https://www.g2.com/discussions/which-type-of-tools-perform-static-analysis-of-code)
- [What kind of analysis is performed by static checker?](https://www.g2.com/discussions/what-kind-of-analysis-is-performed-by-static-checker)
- [What is DeepSource io?](https://www.g2.com/discussions/what-is-deepsource-io)
- [How does DeepSource work?](https://www.g2.com/discussions/how-does-deepsource-work)

### [Codiga](https://www.g2.com/products/codiga/reviews)

Automate your code reviews and write faster code with Codiga Coding Assistant. Codiga proposes two products: 1. Automated Code Reviews on GitHub, GitLab, and Bitbucket 2. Smart Coding Assistant to help developers find and import safe and reliable code patterns directly in their IDE.

**Average Rating:** 4.6/5.0

**Total Reviews:** 21

#### How Do G2 Users Rate Codiga?

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 8.7/10)
- **Ease of Admin:** 9.2/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.5/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 3.3/10 (Category avg: 10/10)

#### Who Is the Company Behind Codiga?

- **Seller:** [Codiga](https://www.g2.com/sellers/codiga)
- **Year Founded:** 2020
- **HQ Location:** Denver, US
- **Twitter:** @getcodiga  
970 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=efb523bdecb2cf44585ac2b1fc59a585878ab952e61610637a8b57c8cff17c1c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcodigahq%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 67% Small, 19% Large

#### What Are Recent G2 Reviews of Codiga?

**["An extremely useful tool"](https://www.g2.com/survey_responses/codiga-review-6986608)**

**Rating:** 5.0/5.0 stars

_— Daniel G._

[Read full review](https://www.g2.com/survey_responses/codiga-review-6986608)

**["great automated code review"](https://www.g2.com/survey_responses/codiga-review-7141195)**

**Rating:** 4.0/5.0 stars

_— Glenn D._

[Read full review](https://www.g2.com/survey_responses/codiga-review-7141195)

#### What Are G2 Users Discussing About Codiga?

- [What is Codiga used for?](https://www.g2.com/discussions/what-is-codiga-used-for)

### [GuardRails](https://www.g2.com/products/guardrails-guardrails/reviews)

GuardRails is an end-to-end security platform that makes AppSec easier for both security and development teams. We scan, detect, and provide real-time guidance to fix vulnerabilities early. Trusted by hundreds of teams around the world to build safer apps, GuardRails integrates seamlessly into the developers’ workflow, quietly scans as they code, and shows how to fix security issues on the spot via Just-in-Time training. GuardRails commits to keeping the noise low and only reporting high-impact vulnerabilities that are relevant to your organization. GuardRails helps organizations shift security everywhere and build a strong DevSecOps pipeline, so they can go faster to market without risking security.

**Average Rating:** 4.3/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate GuardRails?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.7/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.3/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind GuardRails?

- **Seller:** [GuardRails](https://www.g2.com/sellers/guardrails)
- **Year Founded:** 2017
- **HQ Location:** Singapore, Singapore
- **Twitter:** @guardrailsio  
1,553 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6be090277f6c8c141e1d2ae05a89f7c1ee759f1313bdebe23b0a48edda8ba158&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F13599521&secure%5Burl_type%5D=linkedin_company_website)  
13 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 52% Small, 48% Medium

#### What Do G2 Reviewers Say About GuardRails?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **robust security features** of GuardRails, enabling better vulnerability management and compliance in development processes.
- Users value the **vulnerability detection** capabilities of GuardRails, ensuring quick and effective security for their code.
- Users find GuardRails **easy to use** , benefiting from seamless IDE integration and real-time security feedback.
- Users value the **error reduction** capabilities of GuardRails, which enhance security and improve overall development efficiency.
- Users commend the **effective threat detection** of GuardRails, ensuring robust security throughout the development process.

##### Cons

- Users note the **missing features** in GuardRails, such as limited developer access and inadequate report generation capabilities.
- Users find **time management challenging** with GuardRails due to features being overwhelming and limited developer capacity.
- Users face **bug issues** with GuardRails, including code push failures and delays due to low-quality coding practices.
- Users experience **dashboard issues** , facing challenges with report generation and syncing new user dashboards.
- Users report **numerous false positives** in GuardRails, potentially complicating the vulnerability management process.

#### What Are Recent G2 Reviews of GuardRails?

**["A must tool for security"](https://www.g2.com/survey_responses/guardrails-review-8536638)**

**Rating:** 4.0/5.0 stars

_— Sanjeev M._

[Read full review](https://www.g2.com/survey_responses/guardrails-review-8536638)

**["Security and Flexibility with GuardRails"](https://www.g2.com/survey_responses/guardrails-review-8956655)**

**Rating:** 4.0/5.0 stars

_— Muhammad S._

[Read full review](https://www.g2.com/survey_responses/guardrails-review-8956655)

### [Codecov](https://www.g2.com/products/codecov/reviews)

Codecov is a code coverage tool.

**Average Rating:** 3.9/5.0

**Total Reviews:** 10

#### How Do G2 Users Rate Codecov?

- **Has the product been a good partner in doing business?:** 4.2/10 (Category avg: 8.7/10)
- **Ease of Admin:** 7.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.1/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Codecov?

- **Seller:** [Codecov](https://www.g2.com/sellers/codecov)
- **Year Founded:** 2015
- **HQ Location:** San Francisco, California
- **Twitter:** @codecov  
3,067 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fd91c7b3ba5e405ed94c1e1027654be62c088e0336ffb5b98028f7b4f23d6335&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcodecov%2F&secure%5Burl_type%5D=linkedin_company_website)  
2 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 50% Small, 40% Medium

#### What Are Recent G2 Reviews of Codecov?

**["The reports generated are informational and helpfull"](https://www.g2.com/survey_responses/codecov-review-9313369)**

**Rating:** 4.5/5.0 stars

_— Sagar S._

[Read full review](https://www.g2.com/survey_responses/codecov-review-9313369)

**["Decoding Codecov: Uncovering Ratings and Impact in Development"](https://www.g2.com/survey_responses/codecov-review-9074928)**

**Rating:** 4.5/5.0 stars

_— Verified User in Automotive_

[Read full review](https://www.g2.com/survey_responses/codecov-review-9074928)

#### What Are G2 Users Discussing About Codecov?

- [What is Codecov Yml?](https://www.g2.com/discussions/what-is-codecov-yml)
- [What is Codecov GitHub?](https://www.g2.com/discussions/what-is-codecov-github)
- [Who is using Codecov?](https://www.g2.com/discussions/who-is-using-codecov)

### [codebeat](https://www.g2.com/products/codebeat/reviews)

codebeat is an automated review for web and mobile that gathers the results of static code analysis into a single, real-time report that gives all project stakeholders the information required to identify code smells, security holes and improve code quality.

**Average Rating:** 4.8/5.0

**Total Reviews:** 6

#### How Do G2 Users Rate codebeat?

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 8.7/10)
- **Ease of Admin:** 9.4/10 (Category avg: 8.5/10)
- **Ease of Use:** 10.0/10 (Category avg: 8.7/10)

#### Who Is the Company Behind codebeat?

- **Seller:** [codequest](https://www.g2.com/sellers/codequest)
- **Year Founded:** 2014
- **HQ Location:** Warsaw, PL
- **Twitter:** @codebeatapp  
244 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a02e140a2e4eab23c6ae64801d3735a02b294bf8cc7c3b716f29556ec9433c63&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F9184059%2F&secure%5Burl_type%5D=linkedin_company_website)  
3 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 50% Small, 33% Medium

#### What Are Recent G2 Reviews of codebeat?

**["I just Love it!"](https://www.g2.com/survey_responses/codebeat-review-206516)**

**Rating:** 5.0/5.0 stars

_— Sacha D._

[Read full review](https://www.g2.com/survey_responses/codebeat-review-206516)

**["Great Code analysis tool for cloud CIs"](https://www.g2.com/survey_responses/codebeat-review-206968)**

**Rating:** 5.0/5.0 stars

_— Timothy S._

[Read full review](https://www.g2.com/survey_responses/codebeat-review-206968)

### [bugScout](https://www.g2.com/products/bugscout/reviews)

Platform for detecting security vulnerabilities in applications by analyzing the source code. bugScout® is the most complete and versatile SAST platform on the market for detecting application security vulnerabilities through source code analysis. Designed by ethical hackers and reputable security auditors, bugScout® follows international security rules and standards and is at the forefront of cybercrime techniques to keep customer applications safe and secure. It is multiplatform, offered On-Premise or Cloud, and made available in SaaS mode. The internationality of bugScout® allows you to work in 3 languages, easily selectable in the settings of the platform itself. bugScout® has the ability to perform complete application audits and, at the same time, integrate seamlessly into the DevOps lifecycle, facilitating continuous analysis of the source code, without any interference in the application development processes. The excellent results of bugScout® are the result of the development for the different programming languages, which allow to track all possible execution flows of the applications to be audited and cover each and every one of the execution paths, detecting security vulnerabilities and quality errors. bugScout® provides complete reports and reports of your activity, fully customizable through various filters, depending on the recipient and the information you want to view. The different formats of reports and reports allow to obtain final reports and exportable files to other management platforms, for integration in the Customer Information Systems.

**Average Rating:** 3.5/5.0

**Total Reviews:** 2

#### How Do G2 Users Rate bugScout?

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 8.7/10)
- **Ease of Admin:** 6.7/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.3/10 (Category avg: 8.7/10)

#### Who Is the Company Behind bugScout?

- **Seller:** [NalbaTech](https://www.g2.com/sellers/nalbatech)
- **Year Founded:** 2010
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=3f4714541d05ed2174db42938e938af13225a30bf9efe9bd91a764bd409dc0b9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fbugscout-international&secure%5Burl_type%5D=linkedin_company_website)  
2 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 50% Medium, 50% Large

#### What Are Recent G2 Reviews of bugScout?

**["Scouting Vulnerabilities"](https://www.g2.com/survey_responses/bugscout-review-948592)**

**Rating:** 4.0/5.0 stars

_— Verified User in Computer & Network Security_

[Read full review](https://www.g2.com/survey_responses/bugscout-review-948592)

#### What Are G2 Users Discussing About bugScout?

- [What is bugScout used for?](https://www.g2.com/discussions/what-is-bugscout-used-for)

### [Sider](https://www.g2.com/products/sider/reviews)

Seamless GitHub integration

**Average Rating:** 3.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate Sider?

- **Ease of Use:** 8.3/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Sider?

- **Seller:** [Sider](https://www.g2.com/sellers/sider)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7886df2ed926834e5eb248c77dcfa8e5c815d3ab1f0fe3132ced0dba45868834&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FNo-Linkedin-Presence-Added-Intentionally-By-DataOps&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Medium

#### What Are G2 Users Discussing About Sider?

- [What is Sider used for?](https://www.g2.com/discussions/what-is-sider-used-for)

- &lsaquo; Prev ‹ Prev
- 1
- [2](/categories/static-code-analysis/f/ruby?filters%5BLanguages+and+Environments%5D%5B%5D=305&order=g2_score&page=2#product-list)
- [Next &rsaquo; Next ›](/categories/static-code-analysis/f/ruby?filters%5BLanguages+and+Environments%5D%5B%5D=305&order=g2_score&page=2#product-list)

Spotlight Categories

[Demand Side Platform (DSP)](https://www.g2.com/categories/demand-side-platform-dsp)

[Marketing Analytics Tools](https://www.g2.com/categories/marketing-analytics)

[Network Monitoring Software](https://www.g2.com/categories/network-monitoring)

[Help Desk Software](https://www.g2.com/categories/help-desk)

[Payment Processing Software](https://www.g2.com/categories/payment-processing)

Similar Categories

- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)
- [Log Analysis](/categories/log-analysis)

- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Static Code Analysis Themes](/categories/static-code-analysis/themes)

Below are the top-rated Static Code Analysis Tools with Ruby capabilities, as verified by G2’s Research team. Real users have identified Ruby as an important function of Static Code Analysis Tools. Compare different products that offer this feature so you can decide which is best for your business needs.

Show More