Top Free Static Code Analysis Tools - Page 2

How Many Static Code Analysis Tools Products Does G2 Track?

Total Products under this Category: 137

Category Stats (Sep 2026)

  • Average Rating: 4.38/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: TASKING Test & Verification Tools (+10.99%) - Among all products in this category, TASKING Test & Verification Tools recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Static Code Analysis Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 2,200+ Authentic Reviews
  • 137+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Code Analysis Tools

G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence

Highlighted products: SonarQube, Gearset DevOps, Checkmarx, Semgrep, SoftSpell, Black Duck Polaris Platform, CAST Imaging, and ReSharper C++.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=checkmarx&focus%5B%5D=semgrep&focus%5B%5D=softspell&focus%5B%5D=black-duck-polaris-platform&focus%5B%5D=cast-imaging&focus%5B%5D=resharper-c)

ZeroPath

ZeroPath (YC S24) is the first AI-native application security platform that fundamentally reimagines how organizations find and fix vulnerabilities. Unlike deterministic SAST tools that bolt AI onto legacy rule engines, ZeroPath was built from the ground up to combine large language models with advanced program analysis (AST, data flow, taint tracking) by Ex-Tesla Red Team and Google Security engineers. ZeroPath's core differentiation is detecting critical vulnerabilities that pattern-matching SAST fundamentally cannot find. It catches IDORs, authorization bypasses, race conditions, and authentication bugs by reasoning about application behavior and developer intent. This capability achieved a 92% alert reduction when triaging findings from legacy tools. ZeroPath is best suited for enterprises and startups that want a complete appsec experience with: AI-powered SAST across 16+ languages, SCA with exploitability analysis (90% noise reduction by determining if dependency CVEs are actually reachable in your code), secrets detection with validation, IaC scanning for Terraform/CloudFormation/Kubernetes, and natural language security policies. Context-aware autopatch generation fixes 70% of vulnerabilities automatically with framework-specific patches that match your coding standards. To keep the developer experience seamless, ZeroPath integrates into existing workflows with zero configuration. It provides Sub-60-second PR scans on GitHub, GitLab, Bitbucket, and Azure DevOps to provide instant security feedback without blocking development. Developers receive clear explanations, one-click fixes, and can refine patches using natural language commands directly in PR comments. The platform automatically attributes vulnerabilities to responsible developers and syncs bidirectionally with Jira, Linear, and more. Overall, less noise, along with the breadth of integrations, has already made security teams faster in triaging and finding real vulnerabilities. Having been security engineers ourselves, we also understand how important visibility is for the evaluations. ZeroPath users get executive dashboards with real-time MTTR tracking, automated compliance reporting for SOC2 and ISO27001, and risk-based prioritization using CVSS 4.0 scoring. The platform provides complete visibility across organizational repositories, including security models, authentication patterns, and filtering logic, without manual configuration. Our research team dogfeeds our own technology and has discovered CVE-2025-61928 (critical account takeover in better-auth with 300k+ weekly downloads), identified 170+ verified bugs in curl, found 7 vulnerabilities in django-allauth enabling account impersonation, and discovered 0-days in production systems at Netflix, Hulu, and Salesforce. Currently trusted by 750+ companies running 200k+ scans monthly, ZeroPath delivers what security-conscious engineering teams need: more real vulnerabilities, dramatically less noise, and automated fixes that actually work.

Average Rating: 4.5/5.0

Total Reviews: 11

How Do G2 Users Rate ZeroPath?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.4/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 0/10 (Category avg: 10/10)

Who Is the Company Behind ZeroPath?

  • Seller: ZeroPath
  • Company Website:
  • Year Founded: 2024
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 36% Small, 27% Medium

What Do G2 Reviewers Say About ZeroPath?

AI-generated summary from verified user reviews

Pros
  • Users value the high accuracy of ZeroPath, effectively identifying real security issues with minimal false alarms.
  • Users value the accuracy of findings from ZeroPath, as it effectively identifies real security issues with minimal false alarms.
  • Users commend ZeroPath for its high accuracy in security detection, minimizing false alarms and enhancing issue resolution.
  • Users commend ZeroPath for its highly accurate vulnerability detection, minimizing false alarms and enhancing security efforts.
  • Users commend ZeroPath for its accurate vulnerability identification, significantly reducing false alarms and enhancing security efforts.
Cons
  • Users report bug issues with ZeroPath, but the support team addresses them quickly and effectively.
  • Users experience some bugs with ZeroPath, but the support team quickly resolves them to improve functionality.
  • Users face some software bugs in ZeroPath, though the team is responsive in resolving them quickly.
  • Users feel that the pricing structure of ZeroPath is not currently suitable for their organization's budget.
  • Users experience bugs in the dashboard, though the ZeroPath team swiftly addresses these problems.

What Are Recent G2 Reviews of ZeroPath?

OpsPilot

OpsPilot OpsPilot is an AI-powered observability and autonomous reliability platform with an AI Site Reliability Engineering (SRE) teammate that helps engineering and operations teams detect, understand, and resolve incidents faster — and increasingly prevent them from happening at all. Your 24/7 stack expert Modern production systems — microservices, distributed architectures, cloud and hybrid environments — generate enormous volumes of telemetry. Your existing tools surface that data. But they still leave engineers responsible for interpreting signals, finding root causes, and deciding what to do next. OpsPilot closes that gap. It continuously analyzes telemetry across your applications, infrastructure, and services — then tells your team what is happening, why it is happening, and what to do about it. From dashboards to autonomous reliability OpsPilot goes beyond alerting and visualization. It correlates signals across metrics, logs, traces, and deployment events to identify abnormal behavior, explain root causes, and guide teams toward faster resolution — dramatically reducing time spent on incident investigation and operational troubleshooting. Over time, it evolves from reactive investigation toward proactive and autonomous operations. Your AI SRE teammate OpsPilot acts as an AI SRE teammate — augmenting your operations team by answering the questions engineers face during incidents: What changed? Where is the failure occurring? Which service is responsible? What should we investigate next? Three core capabilities Observability — collects and correlates telemetry across metrics, logs, traces, JVM data, and application-level diagnostics for a complete picture of system behavior. Operational Intelligence — applies AI-driven analysis to surface what changed, what is causing the issue, which components are involved, and what actions may resolve it. Foundational capabilities include anomaly detection, alert reduction, telemetry correlation, and root cause analysis. Action and Automation — supports guided incident response, runbook generation, automated remediation, and continuous operational learning — moving teams progressively toward autonomous reliability. OpenTelemetry-native. No new agents required. OpsPilot ingests telemetry via OTLP over gRPC or HTTP — no proprietary agent required. It works with your existing OpenTelemetry instrumentation across Kubernetes, microservices, cloud services, and serverless platforms. Prometheus-compatible metrics, Loki log ingestion, and Jaeger/Zipkin trace formats are also supported. For teams needing deep JVM or ColdFusion diagnostics, the optional FusionReactor APM agent provides additional application-level telemetry. Built for DevOps, SRE, and platform engineering teams OpsPilot is designed for organizations running modern production systems that require high reliability and operational efficiency — particularly teams moving toward SRE or platform engineering models who need deeper operational insight without increasing headcount. Deployed as SaaS, hybrid, or agentless via OpenTelemetry.

Average Rating: 4.8/5.0

Total Reviews: 174

How Do G2 Users Rate OpsPilot?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.0/10 (Category avg: 8.5/10)
  • Ease of Use: 8.8/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind OpsPilot?

  • Seller: Intergral
  • Company Website:
  • Year Founded: 1998
  • HQ Location: Boeblingen, DE
  • Twitter: @Fusion_Reactor
    9,345 Twitter followers
  • LinkedIn® Page: www.linkedin.com

Who Uses This Product?

  • Who Uses This: CTO, Developer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 61% Small, 29% Medium

What Do G2 Reviewers Say About OpsPilot?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of OpsPilot, facilitating quick access to crucial metrics and troubleshooting insights.
  • Users find the real-time web metrics invaluable, enabling quick insights and identification of performance issues in their applications.
  • Users appreciate the real-time visibility and detailed insights provided by FusionReactor APM for effective monitoring.
  • Users value the real-time monitoring of OpsPilot, enabling effective performance management and quick issue resolution.
  • Users praise the responsive and friendly customer support of OpsPilot, making troubleshooting and assistance seamless.
Cons
  • Users find the learning curve challenging, as advanced features require careful configuration and can be overwhelming.
  • Users face difficult configuration challenges, leading to confusion and potentially missing out on important insights.
  • Users find the learning difficulty of OpsPilot challenging initially, requiring some research before effective use.
  • Users find the UI confusing, especially the Cloud version, despite ongoing improvements for clarity and usability.
  • Users find the UI design confusing, noting that it can complicate the initial experience with OpsPilot.

What Are Recent G2 Reviews of OpsPilot?

What Are G2 Users Discussing About OpsPilot?

OpenText Core Application Security

Fortify on Demand (FoD) is a complete Application Security as a Service solution. It offers an easy way to get started with the flexibility to scale. In addition to static and dynamic, Fortify on Demand covers in-depth mobile app security testing, open-source analysis, and vendor application security management. False positives are removed for every test and test results can be manually reviewed by application security experts.

Average Rating: 4.1/5.0

Total Reviews: 34

How Do G2 Users Rate OpenText Core Application Security?

  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.9/10 (Category avg: 8.5/10)
  • Ease of Use: 8.2/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind OpenText Core Application Security?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,048 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 41% Large, 32% Small

What Are Recent G2 Reviews of OpenText Core Application Security?

What Are G2 Users Discussing About OpenText Core Application Security?

Klocwork

Perforce Klocwork is an enterprise grade SAST solution for C, C++, C#, Rust, Java, JavaScript, Python, and Kotlin. It helps development teams detect security vulnerabilities, quality issues, and reliability defects early, while supporting compliance with industry and regulatory standards. Klocwork is purpose built to analyze very large, complex codebases and scales to hundreds of millions of lines of code, well beyond the practical limits of many traditional SAST tools. This makes it especially suited for organizations developing long lived, safety critical, or security critical systems. Designed for DevOps and DevSecOps, Klocwork integrates with complex build systems, CI/CD pipelines, cloud and containerized environments, and common developer tools—enabling consistent security and quality enforcement without slowing development. Static Application Security Testing (SAST) Klocwork identifies a wide range of security vulnerabilities, including SQL injection, tainted data flows, buffer overflows, and other insecure coding practices. It also detects bugs and quality issues such as null pointer dereferences, memory and resource leaks, uncaught exceptions, and code smells. The solution supports compliance with internationally recognized standards including CWE, OWASP, CERT, PCI DSS, DISA STIG, and ISO/IEC TS 17961. Automated CI/CD integrations make continuous security testing practical even for very large systems. AI Assisted Code Remediation with MCP Klocwork extends static analysis with AI assisted code remediation, designed to help developers resolve findings faster and with greater confidence. Using MCP based capabilities, Klocwork securely exposes rich static analysis context—defect data, rule knowledge, and precise fix guidance—to supported AI code assist tools directly within the IDE. Rather than relying on generic AI suggestions, Klocwork’s remediation feature combines deep static analysis insights with comprehensive documentation and exact fix instructions, enabling AI assistants to propose accurate, context aware corrections for security vulnerabilities, quality defects, and coding standard violations. Fixes are presented as clear diffs and require developer review and approval, making the approach suitable for safety and security critical environments. By integrating remediation into the developer workflow, Klocwork reduces time spent interpreting analysis results, researching fixes, and switching between tools. Developers stay in their IDE, receive guided remediation aligned with secure coding standards and project specific rules, and can immediately re analyze code to validate fixes. This completes the optimal shift left approach—helping teams not only find issues early, but fix them efficiently and consistently. Project Streams and Enterprise Scalability Klocwork’s Project Streams feature simplifies managing shared codebases with multiple variants or branches. A single rule configuration can be applied across streams, issues common to multiple variants stay synchronized, and stream specific findings are clearly identified for reporting and compliance. Developer Focused and Centralized Klocwork integrates directly into popular IDEs to deliver fast, contextual feedback as developers write code. Out of the box compiler support eliminates manual setup, while centralized dashboards provide visibility into trends, risk, and compliance across projects of any size.

Average Rating: 4.4/5.0

Total Reviews: 22

How Do G2 Users Rate Klocwork?

  • Has the product been a good partner in doing business?: 8.1/10 (Category avg: 8.7/10)
  • Ease of Admin: 7.3/10 (Category avg: 8.5/10)
  • Ease of Use: 7.9/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Klocwork?

  • Seller: Perforce
  • Year Founded: 1995
  • HQ Location: Minneapolis, MN
  • Twitter: @perforce
    5,090 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,034 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 48% Medium, 35% Small

What Are Recent G2 Reviews of Klocwork?

CodeScan

CodeScan Shield addresses code quality, security, and compliance liabilities with two automated modules: CodeScan and OrgScan. CodeScan provides static code analysis for total visibility into code health from the moment it’s written through production. OrgScan governs organizational policies by enforcing the security and compliance rules mandated for your Salesforce environment. Together, they ensure the code that makes up your Salesforce environment and the way the environment is being utilized will always meet high standards. The result is strengthened data security, streamlined DevSecOps processes, and an assurance of meeting compliance standards—avoiding potentially thousands of dollars in fines and lost opportunities. CodeScan Shield protects your Salesforce org from both the inside and outside. CodeScan provides dashboards and reports for consistent code visibility, while also alerting developers the moment new errors are introduced. OrgScan analyzes Salesforce policies to ensure the organization remains compliant with client-mandated specifications and guidelines. Violations are flagged and recorded in an interactive dashboard. Progress is tracked for policy reviews. Collectively, these features ensure admins maintain governance control within their organization. CodeScan Shield is part of AutoRABIT’s complete DevSecOps platform. Enabling Salesforce DevOps teams with CodeScan Shield’s powerful technology produces high-quality, secure applications and updates at speed.

Average Rating: 4.6/5.0

Total Reviews: 30

How Do G2 Users Rate CodeScan?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 8.6/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind CodeScan?

  • Seller: AutoRABIT
  • Year Founded: 2015
  • HQ Location: San Francisco, US
  • Twitter: @autorabit
    1,245 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    283 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 44% Large, 38% Medium

What Are Recent G2 Reviews of CodeScan?

What Are G2 Users Discussing About CodeScan?

Quality Clouds for ServiceNow

Quality Clouds is the most comprehensive governance and quality management platform for the ServiceNow ecosystem. As organizations move toward Now Assist (GenAI) and democratized development through Creator Studio, Quality Clouds provides the automated guardrails required to keep your instance "Clean, Lean, and Green." We help ServiceNow Platform Owners, Architects, and Centers of Excellence (CoE) maintain a high-performing, upgrade-ready environment while accelerating the delivery of new digital workflows. The Solution for ServiceNow Platform Owners: - Now Assist & AI Governance: Automatically audit AI-generated scripts and configurations from ServiceNow’s GenAI tools. Ensure that "Prompt-to-Code" logic follows your internal security standards and platform best practices. - Upgrade Readiness & OOTB Integrity: Identify "Hard-coded" logic and "Spaghetti" customizations that block upgrades. Quality Clouds ensures you stay as close to Out-of-the-Box (OOTB) as possible, reducing the cost of ownership. - Citizen Development Oversight: Safely scale Creator Studio and App Engine. Monitor the quality of apps built by citizen developers to prevent technical debt from exploding across your production instance. - Native DevOps Integration: Embed automated quality gates directly into your ServiceNow CI/CD pipelines. Stop high-risk Update Sets from moving to Production before they pass your custom architectural checks. - Instance Consolidation: Use our cross-instance dashboard to compare the health of your Dev, Test, and Prod environments, ensuring consistency across your entire ServiceNow footprint.

Average Rating: 4.6/5.0

Total Reviews: 11

How Do G2 Users Rate Quality Clouds for ServiceNow?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.2/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Quality Clouds for ServiceNow?

  • Seller: Quality Clouds Ltd
  • Year Founded: 2015
  • HQ Location: London, England
  • Twitter: @QualityClouds
    410 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    47 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 55% Large, 27% Small

What Are Recent G2 Reviews of Quality Clouds for ServiceNow?

What Are G2 Users Discussing About Quality Clouds for ServiceNow?

DeepSource

DeepSource is an all-in-one code health platform that equips organizations with everything they need to build maintainable and secure software while elevating the velocity of their software development cycle. - Guaranteed below 5% false-positive rate with highly accurate and fast static analyzers - Automated issue remediation with Autofix™️ - Code Issue and security reporting: OWASP Top 10, SANS Top 25, Code Coverage, and more - Self-hosted option with one-click installation and upgrades

Average Rating: 4.6/5.0

Total Reviews: 22

How Do G2 Users Rate DeepSource?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 8.7/10)
  • Ease of Admin: 10.0/10 (Category avg: 8.5/10)
  • Ease of Use: 9.3/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 3.3/10 (Category avg: 10/10)

Who Is the Company Behind DeepSource?

  • Seller: DeepSource
  • Year Founded: 2018
  • HQ Location: San Francisco, California
  • LinkedIn® Page: www.linkedin.com
    20 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 82% Small, 9% Large

What Are Recent G2 Reviews of DeepSource?

What Are G2 Users Discussing About DeepSource?

Embold

Embold supports developers and development teams by finding critical code issues before they become roadblocks. It is the perfect tool to analyze, diagnose, transform, and sustain your software efficiently. With the use of A.I. and machine learning technologies, Embold can immediately prioritize issues, suggest ways to best solve them, and re-factor software where necessary. Run it within your current Dev-Ops stack, on premise or in the cloud privately or publicly.

Average Rating: 4.7/5.0

Total Reviews: 15

How Do G2 Users Rate Embold?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.7/10 (Category avg: 8.5/10)
  • Ease of Use: 9.4/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Embold?

  • Seller: Embold Technologies
  • Year Founded: 2009
  • HQ Location: Frankfurt am Main, Hesse
  • Twitter: @embold_io
    1,054 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 56% Small, 28% Medium

What Are Recent G2 Reviews of Embold?

Codiga

Automate your code reviews and write faster code with Codiga Coding Assistant. Codiga proposes two products: 1. Automated Code Reviews on GitHub, GitLab, and Bitbucket 2. Smart Coding Assistant to help developers find and import safe and reliable code patterns directly in their IDE.

Average Rating: 4.6/5.0

Total Reviews: 21

How Do G2 Users Rate Codiga?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.2/10 (Category avg: 8.5/10)
  • Ease of Use: 9.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 3.3/10 (Category avg: 10/10)

Who Is the Company Behind Codiga?

  • Seller: Codiga
  • Year Founded: 2020
  • HQ Location: Denver, US
  • Twitter: @getcodiga
    970 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 67% Small, 19% Large

What Are Recent G2 Reviews of Codiga?

What Are G2 Users Discussing About Codiga?

VISUAL ASSIST

Visual Assist (VA) is a productivity plugin for Microsoft's Visual Studio developed by Whole Tomato Software. VA has been enhancing the overall IDE experience for thousands of C/C++ and C# developers for over fifteen years. Things You Can Do with Visual Assist • Navigate your code effortlessly • Inspect code and syntax automatically • Restructure code without affecting external behavior • Modernize legacy code • Improve readability • Access to a variety of accessibility features • Tailored support for Unreal Engine The plugin lets programmers code significantly faster and more efficiently with features such as autocomplete, code correction, and code navigation among others. These help you stay focused on more important tasks without the hassle. Visual Assist supports Visual Studio 2022, 2019, 2017 and 2015. Older versions also supported with limited features.

Average Rating: 4.4/5.0

Total Reviews: 29

How Do G2 Users Rate VISUAL ASSIST?

  • Has the product been a good partner in doing business?: 5.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 6.7/10 (Category avg: 8.5/10)
  • Ease of Use: 9.0/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 3.3/10 (Category avg: 10/10)

Who Is the Company Behind VISUAL ASSIST?

  • Seller: Idera, Inc.
  • Year Founded: 2007
  • HQ Location: Austin, US
  • Twitter: @MigrationWiz
    482 Twitter followers
  • LinkedIn® Page: www.linkedin.com

Who Uses This Product?

  • Top Industries: Computer Games, Computer Software
  • Company Size: 66% Small, 24% Medium

What Are Recent G2 Reviews of VISUAL ASSIST?

What Are G2 Users Discussing About VISUAL ASSIST?

GuardRails

GuardRails is an end-to-end security platform that makes AppSec easier for both security and development teams. We scan, detect, and provide real-time guidance to fix vulnerabilities early. Trusted by hundreds of teams around the world to build safer apps, GuardRails integrates seamlessly into the developers’ workflow, quietly scans as they code, and shows how to fix security issues on the spot via Just-in-Time training. GuardRails commits to keeping the noise low and only reporting high-impact vulnerabilities that are relevant to your organization. GuardRails helps organizations shift security everywhere and build a strong DevSecOps pipeline, so they can go faster to market without risking security.

Average Rating: 4.3/5.0

Total Reviews: 29

How Do G2 Users Rate GuardRails?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.7/10 (Category avg: 8.5/10)
  • Ease of Use: 8.3/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind GuardRails?

  • Seller: GuardRails
  • Year Founded: 2017
  • HQ Location: Singapore, Singapore
  • Twitter: @guardrailsio
    1,553 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    13 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 52% Small, 48% Medium

What Do G2 Reviewers Say About GuardRails?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the robust security features of GuardRails, ensuring efficient code scans and vulnerability management in DevSecOps.
  • Users value the vulnerability detection capabilities of GuardRails, enhancing security with automated, comprehensive code scans.
  • Users find GuardRails easy to use, offering integrated feedback on security issues directly within their development environment.
  • Users value the error reduction capabilities of GuardRails, enabling early detection and swift resolution of security issues.
  • Users value the effective threat detection of GuardRails, ensuring secure code and timely vulnerability alerts during development.
Cons
  • Users note missing features in GuardRails, such as limited developer support and lack of report generation capabilities.
  • Users find time management challenging with GuardRails due to insufficient resources and requirement for constant supervision.
  • Users face bug issues with GuardRails, resulting in frequent bottlenecks and complications during code pushing.
  • Users face challenges with dashboard issues, including insufficient report generation and syncing difficulties for new users.
  • Users report false positives in GuardRails, which can complicate the vulnerability management process despite a helpful dashboard.

What Are Recent G2 Reviews of GuardRails?

Visual Expert

Visual Expert is a static code analyzer for Oracle PL/SQL, SQL Server T-SQL and PowerBuilder. Identify code dependencies to modify your code without breaking your application. Leverage hundreds of features to improve the quality, performance, and security of your applications. Find Cross References Identify code dependencies to estimate the impact of a change and modify your code without breaking your application. Detect Security Vulnerabilities Automatically scan your code to detect and fix security issues. Generate Code Inspection Report to clean it up, streamline maintenance efforts and avoid unexpected behavior. Review CRUD Operations Automatically generate a CRUD matrix showing which programs access your data. Generate Diagrams from your code to visualize objects and dependencies: Call graphs, Data Models, impact analysis diagrams… Automatically generate comprehensive HTML documentation of your source code. Analyze and Improve Code Performance Find the slow pieces of code, analyze processes, and remove bottlenecks. Compare two versions of your application or sets of code. Filter changes and save snapshots of your code to compare them anytime in the future.

Average Rating: 4.6/5.0

Total Reviews: 13

How Do G2 Users Rate Visual Expert?

  • Has the product been a good partner in doing business?: 7.8/10 (Category avg: 8.7/10)
  • Ease of Admin: 7.9/10 (Category avg: 8.5/10)
  • Ease of Use: 8.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Visual Expert?

  • Seller: Novalys
  • Year Founded: 1998
  • HQ Location: Boulogne-Billancourt, Ile-de-France
  • Twitter: @PowerBuilderTV
    615 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    32 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 62% Medium, 23% Small

What Do G2 Reviewers Say About Visual Expert?

AI-generated summary from verified user reviews

Pros
  • Users find the easy setup of Visual Expert to be straightforward, allowing for seamless and quick usage.
  • Users appreciate the clear breakdown and diagrams of Visual Expert, enhancing understanding of complex software connections.
  • Users appreciate the enhanced privacy and security features of Visual Expert, ensuring safe handling of sensitive data.
Cons
  • Users find the confusing interface of Visual Expert challenging, especially if they're not tech-savvy or familiar with code.
  • Users find the difficulty for beginners overwhelming due to its technical nature and clunky interface.
  • Users find the ability to correct specific data somewhat limited, indicating a need for better accuracy and modifications.
  • Users experience slow performance with Visual Expert, especially during large projects, affecting usability and efficiency.

What Are Recent G2 Reviews of Visual Expert?

What Are G2 Users Discussing About Visual Expert?

JetBrains Qodana

Qodana is a smart code quality platform by JetBrains best suited for working in teams. It can analyze code written in 60+ languages including Java, JavaScript, TypeScript, PHP, Kotlin, Python, Go, and C#. You can use Qodana to follow agreed quality standards, and deliver readable, maintainable, and secure code. It includes options for code quality, license audits, custom inspections and vulnerable dependancy checks. Powered by the analysis engine of JetBrains IDEs

Average Rating: 4.6/5.0

Total Reviews: 9

How Do G2 Users Rate JetBrains Qodana?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.6/10 (Category avg: 8.5/10)
  • Ease of Use: 9.1/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 9.6/10 (Category avg: 10/10)

Who Is the Company Behind JetBrains Qodana?

  • Seller: JetBrains
  • Year Founded: 2000
  • HQ Location: Prague
  • Twitter: @jetbrains
    213,126 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,941 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Small, 50% Medium

What Are Recent G2 Reviews of JetBrains Qodana?

Hubbl Diagnostics

Hubbl Diagnostics is setting the standard for Salesforce success through secure, automated, AI-driven org intelligence. - Monitor health and performance: Instantly gain a holistic view of your org. - Improve security: Pinpoint security and compliance risks. - Unlock ecosystem insights: Benchmark against industry standards. - Take action: Identify and fix your high priority issues—fast. - Streamline processes: Optimize your business process, inside Salesforce. Our solution provides the C-suite, Salesforce admins, architects, and consultants with the broadest and most actionable insights into any Salesforce org. Tackle technical debt, redundant automation, and ever-expanding org complexity to get the best return on your Salesforce investment, faster.

Average Rating: 4.8/5.0

Total Reviews: 18

How Do G2 Users Rate Hubbl Diagnostics?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.6/10 (Category avg: 8.5/10)
  • Ease of Use: 9.4/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 6.7/10 (Category avg: 10/10)

Who Is the Company Behind Hubbl Diagnostics?

  • Seller: Hubbl Diagnostics
  • Year Founded: 2022
  • HQ Location: Vancouver
  • Twitter: @HubblTech
    5 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    36 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Consulting, Non-Profit Organization Management
  • Company Size: 56% Medium, 22% Large

What Do G2 Reviewers Say About Hubbl Diagnostics?

AI-generated summary from verified user reviews

Pros
  • Users find Hubbl Diagnostics to be incredibly easy to use, streamlining the analysis of Salesforce orgs effectively.
  • Users appreciate the data accuracy of Hubbl Diagnostics, aiding in effective analysis and tech debt reduction.
  • Users appreciate Hubbl Diagnostics for its efficiency in diagnosing issues and enhancing development effortlessly.
  • Users appreciate the in-depth issue identification of Hubbl Diagnostics, saving time in diagnosing Salesforce ecosystem problems.
  • Users appreciate the seamless integration with Salesforce, which saves time and enhances diagnostic capabilities across multiple orgs.
Cons
  • Users wish that exports would provide more detailed information and be as digestible as the online interface.
  • Users experience occasional bugs on the platform, which can disrupt their overall usage and satisfaction.
  • Users experience occasional software bugs on Hubbl Diagnostics, impacting the overall user experience.

What Are Recent G2 Reviews of Hubbl Diagnostics?

DryRun Security

Security leaders face a paradox: ship faster and enable agentic development while staying secure and keeping developers productive. DryRun Security resolves this by securing every pull request and repo with a high-precision, automated security engineer review right where developers and their agents build. DryRun Security is the industry’s most accurate agentic code security intelligence platform. Powered by its proprietary Contextual Security Analysis (CSA) engine, DryRun Security delivers the AI moment for security teams in an AI-native developer world. Traditional static application security testing (SAST) floods teams with alerts, misses higher-order risk, and burns time in triage. DryRun Security goes beyond SAST with contextual analysis that prioritizes what is exploitable and impactful in your codebase, then helps engineers remediate fast. Instead of “find everything and hope someone sorts it out,” DryRun Security delivers code security intelligence that is ready to act on. DryRun Security puts a security engineer directly into developer workflows. In pull requests, the Code Review Agent reviews changes in context, explains risk in plain language, and guides fixes where developers already work. In repos, the DeepScan Agent produces focused, human-grade findings for the issues that actually matter, without weeks of manual review before major milestones. The Custom Policy Agent enforces guardrails with Natural Language Code Policies, so you can standardize security and compliance requirements across teams without brittle rule sets. Codebase Insights allows leaders to ask questions of their entire codebase like "Are we exposed to this new vulnerability" and have confidence in minutes. DryRun Security also integrates with AI coding workflows, so remediation happens with the precision of a security engineer working at machine speed. Teams connect DryRun Security insights and guidance into Claude, Cursor, OpenAI Codex, and Windsurf, helping developers and their agents fix issues with contextual, security-engineered direction tied to the PR and codebase. What DryRun Security delivers (beyond SAST) • Automated secure code review in every pull request with high-signal findings and low noise • Contextual Security Analysis that catches common vulnerabilities and deeper multi-dependency and logic risks • Automated remediation guidance that helps engineers fix faster, with explanations and next steps • Secrets analysis identifies genuine hardcoded secrets and suppresses the usual false alarms • Policy enforcement in PRs using Natural Language Code Policies for consistent guardrails across repos • Codebase intelligence and reporting for AppSec visibility, prioritization, and audit-ready evidence DryRun Security supports most code environments, languages, and frameworks, including: • GitHub, GitLab • C#, Golang, Elixir, JavaScript, TypeScript, Python, Ruby, Java, Kotlin, PHP, Swift, HTML • Infrastructure as Code (Terraform, YAML) • And more

Average Rating: 4.9/5.0

Total Reviews: 20

How Do G2 Users Rate DryRun Security?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 10.0/10 (Category avg: 8.5/10)
  • Ease of Use: 10.0/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind DryRun Security?

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 40% Small, 30% Medium

What Do G2 Reviewers Say About DryRun Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the context-aware security feedback from DryRun Security, enabling efficient vulnerability mitigation in real-time.
  • Users appreciate the quick and context-aware vulnerability detection of DryRun Security, enhancing code security during development.
  • Users commend DryRun Security for its seamless integration and effective detections, enhancing code security and development efficiency.
  • Users appreciate the accuracy of DryRun Security, effectively identifying vulnerabilities in AI-generated code and traditional applications.
  • Users commend the easy setup of DryRun Security, providing seamless integration and efficient workflow for code scanning.
Cons
  • Users experience slow performance in the management portal, affecting usability and efficiency with linked repositories.
  • Users find the slow speed of the management portal frustrating, though improvements to the UI have been noted.
  • Users note a need for improved UX investment in DryRun Security to enhance the developer experience and engagement.
  • Users desire more customization options for tuning analyzers, indicating limited flexibility in current features.
  • Users feel that greater focus on workflow issues could enhance DryRun Security's adoption among developers.

What Are Recent G2 Reviews of DryRun Security?