Top Free Static Code Analysis Tools - Page 3

How Many Static Code Analysis Tools Products Does G2 Track?

Total Products under this Category: 137

Category Stats (Sep 2026)

  • Average Rating: 4.38/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: TASKING Test & Verification Tools (+10.99%) - Among all products in this category, TASKING Test & Verification Tools recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Static Code Analysis Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 2,200+ Authentic Reviews
  • 137+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Code Analysis Tools

G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence

Highlighted products: SonarQube, Gearset DevOps, Checkmarx, Semgrep, SoftSpell, Black Duck Polaris Platform, CAST Imaging, and ReSharper C++.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=checkmarx&focus%5B%5D=semgrep&focus%5B%5D=softspell&focus%5B%5D=black-duck-polaris-platform&focus%5B%5D=cast-imaging&focus%5B%5D=resharper-c)

OverOps

OverOps root cause analysis at runtime instantly pinpoints why critical issues break backend Java and .NET environments in pre-prod through production. Detective-work such as searching logs is not required to reproduce critical issues. OverOps delivers the precise line of code and associated variables. OverOps requires no code changes so engineering teams can develop fast without sacrificing quality.

Average Rating: 3.6/5.0

Total Reviews: 12

How Do G2 Users Rate OverOps?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.7/10)
  • Ease of Admin: 5.0/10 (Category avg: 8.5/10)
  • Ease of Use: 7.6/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind OverOps?

  • Seller: Overops
  • Year Founded: 2011
  • HQ Location: San Francisco, CA
  • Twitter: @OverOps
    7 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 67% Small, 25% Medium

What Are Recent G2 Reviews of OverOps?

What Are G2 Users Discussing About OverOps?

Understand

Understand is a customizable integrated development environment (IDE) that enables static code analysis through an array of visuals, documentation, and metric tools. It was built to help software developers comprehend, maintain, and document their source code. It enables code comprehension by providing flow charts of relationships and building a dictionary of variables and procedures from a provided source code. In addition to functioning as an integrated development environment, Understand provides tools for metrics and reports, standards testing, documentation, searching, graphing, and code knowledge. It is capable of analyzing projects with millions of lines of code and works with code bases written in multiple languages. Understand supports projects written in Ada, Cobol, Ansi C, K&R C, Ansi C++, C#, FORTRAN, Java, Jovial, Pascal, PL/M, Python, VHDL, Objective C, Objective C++, HTML, PHP, JavaScript, and XML.

Average Rating: 4.2/5.0

Total Reviews: 5

How Do G2 Users Rate Understand?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 10.0/10 (Category avg: 8.5/10)
  • Ease of Use: 8.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Understand?

Who Uses This Product?

  • Company Size: 60% Large, 20% Medium

What Are Recent G2 Reviews of Understand?

What Are G2 Users Discussing About Understand?

Codeant AI Code Reviewer

CodeAnt AI reviews every pull request with the whole codebase and business logic behind it, not just the diff. It learns what your team accepts, rejects and argues about. Zero false positives, 70% fix acceptance, 80% less review time.

Average Rating: 4.7/5.0

Total Reviews: 7

How Do G2 Users Rate Codeant AI Code Reviewer?

  • Has the product been a good partner in doing business?: 6.7/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.2/10 (Category avg: 8.5/10)
  • Ease of Use: 9.7/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 5.0/10 (Category avg: 10/10)

Who Is the Company Behind Codeant AI Code Reviewer?

  • Seller: CodeAnt AI
  • Year Founded: 2023
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    22 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 57% Small, 43% Medium

What Do G2 Reviewers Say About Codeant AI Code Reviewer?

AI-generated summary from verified user reviews

Pros
  • Users value the exceptional code quality from Codeant AI Code Reviewer, benefiting from smart suggestions and custom rules.
  • Users appreciate the comprehensive all-in-one features of Codeant AI Code Reviewer, simplifying code reviews and security analysis.
  • Users appreciate the comprehensive coverage of Codeant AI Code Reviewer, simplifying code review and security processes.
  • Users value the custom rules feature for its tailored context and enhanced code review efficiency.
  • Users value the ease of use of Codeant AI Code Reviewer, appreciating its simple interface for comprehensive reviews.
Cons
  • Users find the difficult learning curve with Codeant AI Code Reviewer due to cautious suggestions and slow onboarding.
  • Users find the false positives from Codeant AI Code Reviewer often overly cautious, requiring manual adjustments during onboarding.
  • Users find the improvement needed as suggestions can be overly cautious and onboarding requires significant time.
  • Users find the inefficient notifications sometimes overly cautious and require manual adjustments, complicating the onboarding process.
  • Users find the lack of guidance frustrating, as suggestions may be overly cautious and require manual adjustments.

What Are Recent G2 Reviews of Codeant AI Code Reviewer?

Codefactor

CodeFactor.io is an automated code review tool for GitHub.

Average Rating: 3.8/5.0

Total Reviews: 3

How Do G2 Users Rate Codefactor?

  • Has the product been a good partner in doing business?: 6.7/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.3/10 (Category avg: 8.5/10)
  • Ease of Use: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Codefactor?

  • Seller: Codefactor
  • HQ Location: Los Angeles, US
  • Twitter: @CodeFactor_io
    374 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 67% Medium

What Are Recent G2 Reviews of Codefactor?

Plato

JavaScript Source Analysis

Average Rating: 4.5/5.0

Total Reviews: 3

How Do G2 Users Rate Plato?

  • Ease of Use: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Plato?

  • Seller: FreeCAD
  • Year Founded: 2021
  • HQ Location: Brussels
  • LinkedIn® Page: www.linkedin.com
    10 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 67% Small, 33% Medium

What Are Recent G2 Reviews of Plato?

Qwiet AI

Qwiet AI delivers comprehensive application security by combining agentic AI with advanced code analysis. In a single scan, the platform provides uniquely accurate SAST, SCA, SBOM, secrets detection, and container analysis that helps dev and security teams find and fix vulnerabilities faster. With its proprietary Code Property Graph (CPG) technology and AI/ML models, Qwiet AI achieves up to 95% reduction in false positives compared to traditional tools, while offering contextual AutoFix that understands the unique context of your code, even across complex enterprise applications. Q: What makes Qwiet AI different from other AppSec solutions? A: Qwiet AI stands out through its agentic AI approach, which enables autonomous vulnerability detection and remediation. The platform's Code Property Graph technology allows for deeper code analysis and more accurate vulnerability detection, resulting in dramatically fewer false positives than traditional tools. This advanced technology enables the platform to understand code relationships and context at a deeper level, leading to precise vuln detection and contextually appropriate fixes. Q: What security capabilities does the platform include? A: The platform provides comprehensive security coverage including: - Static Application Security Testing (SAST) using a patented CPG-based approach, for vuln detection that is objectively the fastest and most accurate available per the OWASP benchmark - Software Composition Analysis (SCA) for third-party dependency scanning and vulnerability detection in open source components - Automated SBOM generation for supply chain transparency and compliance requirements - Advanced secrets detection to prevent credential exposure and secure sensitive information - Container security analysis built in - AI-powered AutoFix for automated vulnerability remediation with contextually aware patches, powered by the CPG and a custom AI/ML engine with its own LLM - Custom rule creation capabilities for organization-specific security requirements Q: How does Qwiet AI improve development workflows? A: Qwiet AI integrates seamlessly into existing CI/CD pipelines and developer workflows. The platform's speed (up to 40x faster than traditional scanners) and accuracy mean developers spend less time investigating false positives and more time coding. The AutoFix capability helps developers resolve issues quickly with AI-generated patches that are contextually aware and tailored to your codebase. Additionally, the platform provides IDE integrations and pull request analysis to catch vulnerabilities early in the development process. Q: What do customers think? A: Qwiet AI provides enterprise-grade support with dedicated customer success representatives and technical account managers. The platform consistently receives high marks for customer support, with a 97% "would recommend" rate in Gartner's Voice of the Customer. Customers receive comprehensive onboarding assistance, ongoing technical support, and regular check-ins to ensure successful implementation and adoption. Q: How can I get started with Qwiet AI? A: Qwiet AI offers self-service access, self-guided demos, and AE-guided demos, depending on your needs. You can request a personalized demo through the company website at qwiet.ai to see how the platform addresses their specific security challenges. You can also sign up for self-service access through the web site, or access documentation and integration guides there.

Average Rating: 4.8/5.0

Total Reviews: 3

How Do G2 Users Rate Qwiet AI?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 10.0/10 (Category avg: 8.5/10)
  • Ease of Use: 10.0/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Qwiet AI?

  • Seller: Qwiet AI
  • HQ Location: San Jose, California, United States
  • Twitter: @ShiftLeftInc
    1,164 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    45 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 67% Large, 33% Small

What Do G2 Reviewers Say About Qwiet AI?

AI-generated summary from verified user reviews

Pros
  • Users value the collaborative support from Qwiet AI, facilitating seamless integration into CI/CD pipelines.
  • Users commend the highly responsive customer support of Qwiet AI, enhancing their integration experience significantly.
  • Users value the easy integrations of Qwiet AI, facilitating seamless incorporation into CI/CD pipelines effortlessly.
  • Users value the thorough documentation of Qwiet AI, facilitating seamless integration into CI/CD pipelines.
  • Users value the strong team collaboration facilitated by Qwiet AI, enhancing integration and support for their workflows.
Cons
  • Users find the command line difficulty frustrating, as custom policies require technical expertise without a user-friendly interface.
  • Users express frustration over limited customization as custom policies can only be created via CLI, not a user interface.
  • Users are frustrated by the limited features of Qwiet AI, lacking a user interface for custom policies.
  • Users find the lack of user interface for policy creation limits accessibility and ease of use in Qwiet AI.

What Are Recent G2 Reviews of Qwiet AI?

Fornux C++ Superset

Fornux C++ Superset is a source-to-source compiler that injects an innovative deterministic memory manager into existing C/C++ code thus making the resulting application crash proof and free from any memory leaks. The resulting application remains real-time and works on all embedded platforms. The targeted industries are: cyber-security, defense, fintech, aerospace, aeronautic, telecommunication and gaming and works on any platforms: Windows, Linux and as a SaaS.

Average Rating: 4.0/5.0

Total Reviews: 2

How Do G2 Users Rate Fornux C++ Superset?

  • Has the product been a good partner in doing business?: 6.7/10 (Category avg: 8.7/10)
  • Ease of Admin: 6.7/10 (Category avg: 8.5/10)
  • Ease of Use: 7.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 3.3/10 (Category avg: 10/10)

Who Is the Company Behind Fornux C++ Superset?

  • Seller: Fornux
  • Year Founded: 2018
  • HQ Location: Gatineau, CA
  • LinkedIn® Page: www.linkedin.com
    2 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Large, 50% Medium

What Are Recent G2 Reviews of Fornux C++ Superset?

What Are G2 Users Discussing About Fornux C++ Superset?

BluBracket

BluBracket was forged by security industry veterans who’ve secured millions of assets for many of the world’s largest companies. During our time securing documents, one question kept coming up—can you secure code? We founded BluBracket to give companies the freedom to innovate, with the safety of a secure solution. BluBracket is the leader in comprehensive code security. Its products give companies visibility into where source code introduces security risk while also enabling them to fully secure their code—without altering developer workflows or productivity. Understand who has access to your valuable code and how it puts your infrastructure at risk. Pass audit and compliance requirements with ease. BluBracket bridges the gap between your security, development and devops teams by making security policies actionable and enforceable in your CICD pipeline.

Average Rating: 3.5/5.0

Total Reviews: 2

How Do G2 Users Rate BluBracket?

  • Has the product been a good partner in doing business?: 6.7/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.3/10 (Category avg: 8.5/10)
  • Ease of Use: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind BluBracket?

Who Uses This Product?

  • Company Size: 150% Large

bugScout

Platform for detecting security vulnerabilities in applications by analyzing the source code. bugScout® is the most complete and versatile SAST platform on the market for detecting application security vulnerabilities through source code analysis. Designed by ethical hackers and reputable security auditors, bugScout® follows international security rules and standards and is at the forefront of cybercrime techniques to keep customer applications safe and secure. It is multiplatform, offered On-Premise or Cloud, and made available in SaaS mode. The internationality of bugScout® allows you to work in 3 languages, easily selectable in the settings of the platform itself. bugScout® has the ability to perform complete application audits and, at the same time, integrate seamlessly into the DevOps lifecycle, facilitating continuous analysis of the source code, without any interference in the application development processes. The excellent results of bugScout® are the result of the development for the different programming languages, which allow to track all possible execution flows of the applications to be audited and cover each and every one of the execution paths, detecting security vulnerabilities and quality errors. bugScout® provides complete reports and reports of your activity, fully customizable through various filters, depending on the recipient and the information you want to view. The different formats of reports and reports allow to obtain final reports and exportable files to other management platforms, for integration in the Customer Information Systems.

Average Rating: 3.5/5.0

Total Reviews: 2

How Do G2 Users Rate bugScout?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 6.7/10 (Category avg: 8.5/10)
  • Ease of Use: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind bugScout?

Who Uses This Product?

  • Company Size: 50% Large, 50% Medium

What Are Recent G2 Reviews of bugScout?

What Are G2 Users Discussing About bugScout?

Context

Context is the first AI Office Suite that automates your workflow by creating documents, presentations, spreadsheets, and more using your data, tools, and style.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Context?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 10.0/10 (Category avg: 8.5/10)
  • Ease of Use: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Context?

  • Seller: Context
  • Year Founded: 2024
  • HQ Location: Palo Alto, US
  • LinkedIn® Page: www.linkedin.com
    24 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Context?

PT Application Inspector

PT Application Inspector™ (PT AI™) is a comprehensive source code analysis tool that offers protection for web applications of any scale. Its holistic approach combines the advantages of static, dynamic, and interactive analysis to maintain application security throughout every stage of development—from the very first line of code to the go-live.

Average Rating: 5.0/5.0

Total Reviews: 2

How Do G2 Users Rate PT Application Inspector?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 10.0/10 (Category avg: 8.5/10)
  • Ease of Use: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind PT Application Inspector?

Who Uses This Product?

  • Company Size: 67% Large, 33% Small

What Are Recent G2 Reviews of PT Application Inspector?

What Are G2 Users Discussing About PT Application Inspector?

PVS-Studio

PVS-Studio is a SAST solution that helps enhance code quality, security, and safety. The analyzer detects bugs and potential vulnerabilities in C, C++, C#, and Java code on Windows, Linux, and macOS. Features - Supports various analysis types (intermodular, incremental, data flow analysis, taint analysis); - Can be used offline; - Provides cross-platform integration; - Offers ways to handle false positives; - Helps small and large teams maintain code quality. Pros - Quick and high-quality support from the analyzer developers; - 900+ diagnostic rules with detailed descriptions and examples; - Compliance with safety and security standards: OWASP TOP 10, MISRA C, C++, AUTOSAR, CWE; - Detailed reports and reminders for developers and managers (Blame Notifier); - User-friendly ways to handle legacy code, including mass suppression of analyzer’s warnings; - Support of the Open Source Community, analysis of open-source projects; - Integration with SonarQube. Pricing - In the commercial version, prices are set on request and can be changed depending on the required set of features; - Free trial is available; - PVS-Studio may offer a free licensing option to students, MVPs, public experts in security, and contributors to open-source projects.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate PVS-Studio?

  • Ease of Use: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind PVS-Studio?

  • Seller: PVS-Studio
  • Year Founded: 2008
  • HQ Location: Astana, KZ
  • Twitter: @Code_Analysis
    5,907 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    29 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of PVS-Studio?

What Are G2 Users Discussing About PVS-Studio?

Bearer

Bearer helps modern teams ship trustworthy products with the help of our code security SAST solution built for security, privacy and engineering teams. We combine sensitive data context with static code analysis to make security and privacy engineering simpler and smarter to maximize the ROI for your DevSecOps and central security team driven programs.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Bearer?

  • Ease of Use: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Bearer?

  • Seller: Bearer
  • Year Founded: 2019
  • HQ Location: Cambridge, US
  • Twitter: @BearerSH
    16 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    25 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Bearer?

Bugsmirror MASST (Mobile Application Security Suite & Tools)

Bugsmirror Mobile Application Security Suite & Tools (MASST) is designed specifically for your business, providing scalable, end-to-end security for your mobile app. From detection to protection, MASST ensures your app is safeguarded against evolving security threats. With MASST, you can focus on growing your business, knowing your app is fully protected at every stage.

Who Is the Company Behind Bugsmirror MASST (Mobile Application Security Suite & Tools)?

Cyclopt Panorama

Cyclopt Panorama is a software quality assurance platform that evaluates code according to the ISO/IEC 25010:2023 model, with a focus on maintainability and security. It measures source code metrics like complexity, coupling, cohesion, and documentation, while detecting coding violations, duplicated code, and architectural issues. In addition, Panorama highlights security risks through dependency vulnerability checks and static application security testing (SAST). All insights are consolidated into a clear dashboard, giving teams the visibility they need to monitor quality, ensure compliance, and take timely corrective action across projects.

Who Is the Company Behind Cyclopt Panorama?

  • Seller: Cyclopt
  • Year Founded: 2017
  • HQ Location: Pylaia, GR
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®