Best Static Code Analysis Tools with Salesforce Capabilities

How Many Static Code Analysis Tools Products Does G2 Track?

Total Products under this Category: 134

Category Stats (Sep 2026)

  • Average Rating: 4.38/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: TASKING Test & Verification Tools (+10.99%) - Among all products in this category, TASKING Test & Verification Tools recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Static Code Analysis Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 2,200+ Authentic Reviews
  • 134+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Code Analysis Tools

G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence

Highlighted products: SonarQube, Gearset DevOps, Checkmarx, Semgrep, SoftSpell, Black Duck Polaris Platform, CAST Imaging, and ReSharper C++.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=checkmarx&focus%5B%5D=semgrep&focus%5B%5D=softspell&focus%5B%5D=black-duck-polaris-platform&focus%5B%5D=cast-imaging&focus%5B%5D=resharper-c)

SonarQube

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

Average Rating: 4.4/5.0

Total Reviews: 152

How Do G2 Users Rate SonarQube?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.5/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind SonarQube?

  • Seller: SonarSource Sàrl
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Geneva, Switzerland
  • Twitter: @SonarSource
    10,913 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    973 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: DevOps Engineer, Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 42% Large, 40% Medium

What Do G2 Reviewers Say About SonarQube?

AI-generated summary from verified user reviews

Pros
  • Users value SonarQube for its ability to quickly flag code quality and security issues, ensuring a reliable codebase.
  • Users value the flexible issue filtering and prioritization features of SonarQube, enhancing team productivity and focus.
  • Users appreciate how SonarQube quickly flags code quality and security issues, ensuring a clean and reliable codebase.
  • Users appreciate the ease of use of SonarQube, finding integration and actionable feedback simple and effective.
  • Users appreciate the easy integrations with CI/CD tools, enhancing their workflow and improving code quality effectively.
Cons
  • Users face software bugs that lead to false positives, complicating the experience and requiring significant knowledge to manage.
  • Users find the complex configuration of SonarQube challenging, especially for beginners needing extensive knowledge.
  • Users encounter false positives that complicate usage, despite helpful tools for review and customization of analysis.
  • Users find SonarQube's complexity in configuration and excessive warnings can make it cumbersome to use.
  • Users find the complex setup of SonarQube time-consuming, requiring significant effort to configure and tune effectively.

What Are Recent G2 Reviews of SonarQube?

What Are G2 Users Discussing About SonarQube?

Gearset DevOps

Gearset is the global leader in Salesforce DevOps. It’s a DevOps platform that helps organizations manage, automate, and govern the full Salesforce development lifecycle, from planning and deployment to testing, data management, and compliance. The platform is designed for Salesforce teams that need reliable, scalable DevOps processes across complex org environments. Gearset is used by mid-market and enterprise organizations across regulated and non-regulated industries, including healthcare, financial services, insurance, and technology. Typical users include Salesforce administrators, developers, DevOps engineers, release managers, and platform owners responsible for maintaining deployment quality, security, and operational consistency. The platform supports a wide range of Salesforce use cases, including metadata and CPQ deployments, CI/CD automation, code review workflows, sandbox seeding, test automation, and monitoring. As well as deployment automation, Gearset includes tools for Salesforce data protection and long-term data management, such as automated backups, data restore, and archiving. Observability and Org Intelligence features provide insight into org health, deployment risk, and system changes over time. Gearset also includes governance and compliance capabilities designed for enterprise environments. These features help teams maintain audit readiness and enforce access controls while supporting compliance frameworks such as SOX, ISO, HIPAA, and GDPR. The platform is delivered as a managed service and integrates with Salesforce environments without requiring complex local infrastructure. Key features and capabilities include: - Salesforce metadata, CPQ, and data deployments with CI/CD automation and version control integration - Code review, test automation, and release validation to support quality and consistency - Automated Salesforce backups, restore, and data archiving for data protection and retention - Sandbox seeding, observability, and Org Intelligence to support environment management and visibility - Governance features including audit trails, role-based access controls, and compliance support Gearset is a Salesforce Partner and has supported Salesforce teams globally since 2015. The platform is used by organizations managing multiple orgs (across regions), frequent releases, and complex compliance requirements, helping teams reduce deployment risk, improve operational visibility, and maintain control over Salesforce change management processes.

Average Rating: 4.7/5.0

Total Reviews: 305

How Do G2 Users Rate Gearset DevOps?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.3/10 (Category avg: 8.5/10)
  • Ease of Use: 9.1/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Gearset DevOps?

  • Seller: Gearset
  • Company Website:
  • Year Founded: 2015
  • HQ Location: Cambridge, Cambridgeshire
  • Twitter: @GearsetHQ
    1,182 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    369 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Salesforce Developer, Salesforce Administrator
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 36% Medium, 33% Small

What Do G2 Reviewers Say About Gearset DevOps?

AI-generated summary from verified user reviews

Pros
  • Users praise the ease of use of Gearset DevOps, highlighting smooth setup and effective features for efficient deployments.
  • Users value the automation and ease of deployment with Gearset, significantly enhancing efficiency and reducing errors.
  • Users appreciate the easy deployment capabilities of Gearset DevOps, which streamline CI/CD processes and validations effortlessly.
  • Users commend the exceptional customer support from Gearset DevOps, highlighting prompt assistance and engagement with feature requests.
  • Users value the deployment ease of Gearset DevOps, enabling swift setup and efficient management of releases.
Cons
  • Users face deployment issues requiring manual activation of Flows and cautious management of production metadata changes.
  • Users find Gearset DevOps expensive, particularly for larger teams, affecting its accessibility despite its high quality.
  • Users find complexity in custom filters and CI/CD processes, wishing for enhanced automation and streamlined operations.
  • Users face limitations in data management, as some metadata and object settings fail to transfer accurately between environments.
  • Users express disappointment over the missing features in Gearset DevOps, particularly the lack of automated dependency tracking.

What Are Recent G2 Reviews of Gearset DevOps?

Checkmarx

Checkmarx offers leading application security solutions that help organizations safeguard software development while enhancing efficiency and reducing costs. At the center is Checkmarx Fusion, the highest-fidelity scanning architecture in the industry. Most scanners force a choice: catch more, or get buried in noise and miss what matters. Fusion ends that trade-off — deterministic precision and frontier AI coverage fused into one verified result, with the Findings Analysis Engine validating and deduplicating every finding before a developer sees it. The result is an F1 score of 0.64 today by using the Checkmarx NG SAST vs. an industry average of ~0.20, and an astonishing market leading F1 score of 0.74 with Checkmarx Fusion. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as NG SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

Average Rating: 4.2/5.0

Total Reviews: 45

How Do G2 Users Rate Checkmarx?

  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.3/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Checkmarx?

  • Seller: Checkmarx
  • Company Website:
  • Year Founded: 2006
  • HQ Location: Paramus, NJ
  • Twitter: @Checkmarx
    7,284 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    997 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 57% Large, 22% Medium

What Do G2 Reviewers Say About Checkmarx?

AI-generated summary from verified user reviews

Pros
  • Users value the easy implementation of Checkmarx into existing repositories, enhancing their security review processes effortlessly.
  • Users praise the intuitive user interface of Checkmarx, making security reviews and integrations straightforward and user-friendly.
  • Users value the accuracy of results in Checkmarx, finding it effective for automated security reviews.
  • Users appreciate the automation testing capabilities of Checkmarx, making security reviews efficient and user-friendly.
  • Users praise the responsive customer support of Checkmarx, consistently providing help when challenges arise.
Cons
  • Users experience a significant number of false positives with Checkmarx, particularly for Kotlin projects, leading to frustration.
  • Users face challenges with limited support for Kotlin, experiencing many false positives compared to other languages like Java or Javascript.
  • Users experience missing features in Checkmarx, particularly with Kotlin support, leading to numerous false positives.
  • Users find the navigation poor in Checkmarx, citing issues with dashboard layout and display clarity.

What Are Recent G2 Reviews of Checkmarx?

What Are G2 Users Discussing About Checkmarx?

OpenText Static Application Security Testing

OpenText™ Static Application Security Testing (SAST) is a comprehensive solution designed to identify and remediate security vulnerabilities within an application's source code during the early stages of development. By analyzing code from the "inside out," SAST provides immediate feedback to developers, enabling them to address security issues promptly and effectively. Key Features and Functionality: - Extensive Language Support: Supports over 33 programming languages and more than 1,400 vulnerability categories, ensuring broad applicability across various development environments. - Integration with Development Tools: Seamlessly integrates with popular Integrated Development Environments (IDEs) such as Eclipse, Visual Studio, and JetBrains, as well as Continuous Integration/Continuous Deployment (CI/CD) tools like Jenkins and Bamboo, facilitating a smooth incorporation into existing workflows. - Scalable Deployment Options: Offers flexible deployment models, including on-premises, cloud-based, and Software as a Service (SaaS) solutions, allowing organizations to choose the setup that best fits their needs. - Advanced Analysis Capabilities: Utilizes multiple algorithms and an expansive knowledge base of secure coding rules to perform thorough code analysis, pinpointing the root causes of vulnerabilities and providing detailed remediation guidance. Primary Value and Problem Solved: OpenText SAST empowers organizations to proactively manage application security by detecting and addressing vulnerabilities early in the Software Development Life Cycle (SDLC). This proactive approach reduces the risk of security breaches, minimizes the cost and effort associated with late-stage remediation, and enhances the overall security posture of applications. By integrating security testing into the development process, OpenText SAST helps developers create more secure code, leading to robust and reliable software products.

Average Rating: 4.5/5.0

Total Reviews: 21

How Do G2 Users Rate OpenText Static Application Security Testing?

  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.1/10 (Category avg: 8.5/10)
  • Ease of Use: 8.7/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind OpenText Static Application Security Testing?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Who Uses This Product?

  • Top Industries: Banking, Financial Services
  • Company Size: 50% Large, 29% Small

What Do G2 Reviewers Say About OpenText Static Application Security Testing?

AI-generated summary from verified user reviews

Pros
  • Users value the easy integrations of OpenText Static Application Security Testing, enhancing their workflow with multiple tools.
  • Users value the extensive integration capabilities of OpenText Static Application Security Testing with various third-party tools.
  • Users value the extensive integration support for various technologies and third-party tools offered by OpenText Static Application Security Testing.
Cons
  • Users are disappointed by the false positives, but appreciate the ability to ignore issues in future scans.

What Are Recent G2 Reviews of OpenText Static Application Security Testing?

What Are G2 Users Discussing About OpenText Static Application Security Testing?

Kiuwan Code Security & Insights

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

Average Rating: 4.5/5.0

Total Reviews: 29

How Do G2 Users Rate Kiuwan Code Security & Insights?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.7/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Kiuwan Code Security & Insights?

  • Seller: Sembi
  • Company Website:
  • Year Founded: 2023
  • HQ Location: Austin, US
  • LinkedIn® Page: www.linkedin.com
    114 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Banking
  • Company Size: 41% Large, 35% Medium

What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the accuracy of the results from Kiuwan Code Security & Insights, enhancing their overall experience.
  • Users value the accuracy of findings from Kiuwan, enhancing their satisfaction with code security and reporting.
  • Users commend the efficient customer support of Kiuwan, ensuring timely assistance and strong satisfaction overall.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, making it very easy to navigate.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, enhancing ease of use for dashboards.

What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

Codacy

Codacy is the code quality and security platform for AI-assisted engineering teams. AI is now embedded through the engineering workflow, which has made teams faster, but also adds risk to everything they ship. Codacy helps AI-assisted teams ship high-quality, secure code across the full software development lifecycle, starting in the agent and editor, through pull requests in Git, and into containers and runtime security. At each stage we check for quality issues, security vulnerabilities and AI coding risk introduced into the codebase, and help devs and agent fix them effortlessly. A team's standards become automated guardrails that apply across every IDE, AI coding agent, and Pull Request. More than 250,000 developers rely on Codacy to keep quality and security stable as AI changes how software gets built. Add your repo and get your free scan report in minutes: https://codacy.com

Average Rating: 4.6/5.0

Total Reviews: 29

How Do G2 Users Rate Codacy?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.9/10 (Category avg: 8.5/10)
  • Ease of Use: 9.1/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Codacy?

  • Seller: Codacy
  • Year Founded: 2012
  • HQ Location: Lisbon, Lisboa
  • Twitter: @codacy
    5,002 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    62 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 59% Small, 24% Medium

What Do G2 Reviewers Say About Codacy?

AI-generated summary from verified user reviews

Pros
  • Users value the enhanced security features of Codacy, benefiting from integrated automation and insightful vulnerability management.
  • Users appreciate the integrated automation of Codacy, finding it easy to use and helpful for maintaining code quality.
  • Users find the out-of-the-box automation in Codacy to be user-friendly and effective for maintaining code quality.
  • Users value the high code quality provided by Codacy's integrated automation and effective static code analyses.
  • Users value the helpful customer support of Codacy, appreciating their immediate assistance during integration and security management.
Cons
  • Users find Codacy expensive at $19/month, which can be a barrier for smaller organizations.

What Are Recent G2 Reviews of Codacy?

OpenText Core Application Security

Fortify on Demand (FoD) is a complete Application Security as a Service solution. It offers an easy way to get started with the flexibility to scale. In addition to static and dynamic, Fortify on Demand covers in-depth mobile app security testing, open-source analysis, and vendor application security management. False positives are removed for every test and test results can be manually reviewed by application security experts.

Average Rating: 4.1/5.0

Total Reviews: 34

How Do G2 Users Rate OpenText Core Application Security?

  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.9/10 (Category avg: 8.5/10)
  • Ease of Use: 8.2/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind OpenText Core Application Security?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 41% Large, 32% Small

What Are Recent G2 Reviews of OpenText Core Application Security?

What Are G2 Users Discussing About OpenText Core Application Security?

Veracode Application Security Platform

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

Average Rating: 3.8/5.0

Total Reviews: 25

How Do G2 Users Rate Veracode Application Security Platform?

  • Has the product been a good partner in doing business?: 7.9/10 (Category avg: 8.7/10)
  • Ease of Admin: 7.4/10 (Category avg: 8.5/10)
  • Ease of Use: 7.3/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Veracode Application Security Platform?

  • Seller: VERACODE
  • Year Founded: 2006
  • HQ Location: Burlington, MA
  • Twitter: @Veracode
    21,950 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    500 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 69% Large, 31% Medium

What Do G2 Reviewers Say About Veracode Application Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the effective security vulnerability identification offered by Veracode, enhancing overall application safety and code integrity.
  • Users find Veracode's vulnerability detection excellent for identifying security issues and ensuring high application security standards.
  • Users value the automated scanning of Veracode, streamlining security checks and enhancing code quality effortlessly.
  • Users value the effective detection of security vulnerabilities, enabling robust protection and streamlined development processes.
  • Users appreciate the ease of integration with GitHub and CI/CD pipelines, streamlining their development process effectively.
Cons
  • Users find Veracode to be expensive, with high costs, complex licensing, and unfulfilled feature delivery.
  • Users face a lack of information due to mismatches in documentation and delayed notifications during uploads.
  • Users express concerns over licensing issues, including rising costs, complex models, and unequal feature availability.
  • Users report poor customer support with pushy account executives and difficulties in resolving issues efficiently.
  • Users express concerns about pricing issues, with rising costs and a complex licensing model affecting value perception.

What Are Recent G2 Reviews of Veracode Application Security Platform?

What Are G2 Users Discussing About Veracode Application Security Platform?

CodeScan

CodeScan Shield addresses code quality, security, and compliance liabilities with two automated modules: CodeScan and OrgScan. CodeScan provides static code analysis for total visibility into code health from the moment it’s written through production. OrgScan governs organizational policies by enforcing the security and compliance rules mandated for your Salesforce environment. Together, they ensure the code that makes up your Salesforce environment and the way the environment is being utilized will always meet high standards. The result is strengthened data security, streamlined DevSecOps processes, and an assurance of meeting compliance standards—avoiding potentially thousands of dollars in fines and lost opportunities. CodeScan Shield protects your Salesforce org from both the inside and outside. CodeScan provides dashboards and reports for consistent code visibility, while also alerting developers the moment new errors are introduced. OrgScan analyzes Salesforce policies to ensure the organization remains compliant with client-mandated specifications and guidelines. Violations are flagged and recorded in an interactive dashboard. Progress is tracked for policy reviews. Collectively, these features ensure admins maintain governance control within their organization. CodeScan Shield is part of AutoRABIT’s complete DevSecOps platform. Enabling Salesforce DevOps teams with CodeScan Shield’s powerful technology produces high-quality, secure applications and updates at speed.

Average Rating: 4.6/5.0

Total Reviews: 30

How Do G2 Users Rate CodeScan?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 8.6/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind CodeScan?

  • Seller: AutoRABIT
  • Year Founded: 2015
  • HQ Location: San Francisco, US
  • Twitter: @autorabit
    1,245 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    283 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 44% Large, 38% Medium

What Are Recent G2 Reviews of CodeScan?

What Are G2 Users Discussing About CodeScan?

bugScout

Platform for detecting security vulnerabilities in applications by analyzing the source code. bugScout® is the most complete and versatile SAST platform on the market for detecting application security vulnerabilities through source code analysis. Designed by ethical hackers and reputable security auditors, bugScout® follows international security rules and standards and is at the forefront of cybercrime techniques to keep customer applications safe and secure. It is multiplatform, offered On-Premise or Cloud, and made available in SaaS mode. The internationality of bugScout® allows you to work in 3 languages, easily selectable in the settings of the platform itself. bugScout® has the ability to perform complete application audits and, at the same time, integrate seamlessly into the DevOps lifecycle, facilitating continuous analysis of the source code, without any interference in the application development processes. The excellent results of bugScout® are the result of the development for the different programming languages, which allow to track all possible execution flows of the applications to be audited and cover each and every one of the execution paths, detecting security vulnerabilities and quality errors. bugScout® provides complete reports and reports of your activity, fully customizable through various filters, depending on the recipient and the information you want to view. The different formats of reports and reports allow to obtain final reports and exportable files to other management platforms, for integration in the Customer Information Systems.

Average Rating: 3.5/5.0

Total Reviews: 2

How Do G2 Users Rate bugScout?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 6.7/10 (Category avg: 8.5/10)
  • Ease of Use: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind bugScout?

Who Uses This Product?

  • Company Size: 50% Medium, 50% Large

What Are Recent G2 Reviews of bugScout?

What Are G2 Users Discussing About bugScout?