Best Static Code Analysis Tools - Page 2

How Many Static Code Analysis Tools Products Does G2 Track?

Total Products under this Category: 134

Category Stats (Sep 2026)

  • Average Rating: 4.38/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: TASKING Test & Verification Tools (+10.99%) - Among all products in this category, TASKING Test & Verification Tools recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Static Code Analysis Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 2,200+ Authentic Reviews
  • 134+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Code Analysis Tools

G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence

Highlighted products: SonarQube, Gearset DevOps, Checkmarx, Semgrep, SoftSpell, Black Duck Polaris Platform, CAST Imaging, and ReSharper C++.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=checkmarx&focus%5B%5D=semgrep&focus%5B%5D=softspell&focus%5B%5D=black-duck-polaris-platform&focus%5B%5D=cast-imaging&focus%5B%5D=resharper-c)

Cyclopt Companion

Cyclopt Companion is a code quality and security tool that helps developers ship secure, maintainable code with confidence, whether written by humans or AI. Built on the ISO 25010:2023 methodology, Companion analyzes every commit and flags coding violations, security vulnerabilities, code duplication, and maintainability issues in real time. You get instant feedback showing exactly how each commit changes your code quality, down to the precise file and line. Companion meets you where you already work. Connect the MCP Server to your AI coding assistant (Claude Code, GitHub Copilot, Open Code) so your agent can query analyzers and surface findings without leaving your environment. Install the IDE Plugin for VS Code or JetBrains to run analysis inside your editor, see issues inline, jump straight to the flagged line, and generate ready-to-use fix prompts. Optional automation analyzes files on save or immediately after AI edits, so quality and security issues in AI-generated code are caught the moment they occur. With Cyclopt Profile, developers track their growth across eight skill categories, earn badges, and build a shareable profile that reflects real coding ability. Companion integrates with GitHub, GitLab, Bitbucket, and Azure DevOps, as well as Slack, Teams, and Discord. Setup takes under five minutes with no credit card required, making it an ideal fit for developers, freelancers, and engineering teams who want to reduce technical debt and ship reliable software faster.

Average Rating: 4.6/5.0

Total Reviews: 13

How Do G2 Users Rate Cyclopt Companion?

  • Ease of Use: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Cyclopt Companion?

  • Seller: Cyclopt
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Pylaia, GR
  • LinkedIn® Page: www.linkedin.com
    11 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 100% Small

What Do G2 Reviewers Say About Cyclopt Companion?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the meaningful insights of Cyclopt Companion, enhancing coding skills with helpful feedback and tracking progress.
  • Users value the strong focus on security in Cyclopt Companion, enhancing code safety in development workflow.
  • Users value the actionable feedback on code quality from Cyclopt Companion, enhancing improvement and security with clear metrics.
  • Users value the effective issue identification in Cyclopt Companion, enhancing project health and simplifying error resolution.
  • Users appreciate the instant alert notifications from Cyclopt Companion, keeping them informed about code quality improvements immediately.
Cons
  • Users find the difficult learning curve of Cyclopt Companion challenging without prior software engineering knowledge.
  • Users note a steep learning curve for understanding metrics, requiring prior knowledge of software engineering principles.
  • Users struggle with difficult navigation due to information being hidden too deep within the screens and menus.
  • Users find the difficulty for beginners in navigating features challenging, often needing to figure things out independently.
  • Users report a short learning curve for metrics in Cyclopt Companion, requiring prior software engineering knowledge for effective use.

What Are Recent G2 Reviews of Cyclopt Companion?

ReSharper

ReSharper is a renowned productivity tool that turns Microsoft Visual Studio into a much better IDE. Both individual .NET developers and teams rely on ReSharper to write and maintain code in a more manageable and enjoyable way, adopt the best coding practices, and deliver higher quality applications faster.

Average Rating: 4.5/5.0

Total Reviews: 83

How Do G2 Users Rate ReSharper?

  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.1/10 (Category avg: 8.5/10)
  • Ease of Use: 8.8/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind ReSharper?

  • Seller: JetBrains
  • Year Founded: 2000
  • HQ Location: Prague
  • Twitter: @jetbrains
    213,126 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,019 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Software Developer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 38% Medium, 38% Small

What Are Recent G2 Reviews of ReSharper?

What Are G2 Users Discussing About ReSharper?

ZeroPath

ZeroPath (YC S24) is the first AI-native application security platform that fundamentally reimagines how organizations find and fix vulnerabilities. Unlike deterministic SAST tools that bolt AI onto legacy rule engines, ZeroPath was built from the ground up to combine large language models with advanced program analysis (AST, data flow, taint tracking) by Ex-Tesla Red Team and Google Security engineers. ZeroPath's core differentiation is detecting critical vulnerabilities that pattern-matching SAST fundamentally cannot find. It catches IDORs, authorization bypasses, race conditions, and authentication bugs by reasoning about application behavior and developer intent. This capability achieved a 92% alert reduction when triaging findings from legacy tools. ZeroPath is best suited for enterprises and startups that want a complete appsec experience with: AI-powered SAST across 16+ languages, SCA with exploitability analysis (90% noise reduction by determining if dependency CVEs are actually reachable in your code), secrets detection with validation, IaC scanning for Terraform/CloudFormation/Kubernetes, and natural language security policies. Context-aware autopatch generation fixes 70% of vulnerabilities automatically with framework-specific patches that match your coding standards. To keep the developer experience seamless, ZeroPath integrates into existing workflows with zero configuration. It provides Sub-60-second PR scans on GitHub, GitLab, Bitbucket, and Azure DevOps to provide instant security feedback without blocking development. Developers receive clear explanations, one-click fixes, and can refine patches using natural language commands directly in PR comments. The platform automatically attributes vulnerabilities to responsible developers and syncs bidirectionally with Jira, Linear, and more. Overall, less noise, along with the breadth of integrations, has already made security teams faster in triaging and finding real vulnerabilities. Having been security engineers ourselves, we also understand how important visibility is for the evaluations. ZeroPath users get executive dashboards with real-time MTTR tracking, automated compliance reporting for SOC2 and ISO27001, and risk-based prioritization using CVSS 4.0 scoring. The platform provides complete visibility across organizational repositories, including security models, authentication patterns, and filtering logic, without manual configuration. Our research team dogfeeds our own technology and has discovered CVE-2025-61928 (critical account takeover in better-auth with 300k+ weekly downloads), identified 170+ verified bugs in curl, found 7 vulnerabilities in django-allauth enabling account impersonation, and discovered 0-days in production systems at Netflix, Hulu, and Salesforce. Currently trusted by 750+ companies running 200k+ scans monthly, ZeroPath delivers what security-conscious engineering teams need: more real vulnerabilities, dramatically less noise, and automated fixes that actually work.

Average Rating: 4.5/5.0

Total Reviews: 11

How Do G2 Users Rate ZeroPath?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.4/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 0/10 (Category avg: 10/10)

Who Is the Company Behind ZeroPath?

  • Seller: ZeroPath
  • Company Website:
  • Year Founded: 2024
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 36% Small, 27% Medium

What Do G2 Reviewers Say About ZeroPath?

AI-generated summary from verified user reviews

Pros
  • Users value the high accuracy of ZeroPath, effectively identifying real security issues with minimal false alarms.
  • Users value the accuracy of findings from ZeroPath, as it effectively identifies real security issues with minimal false alarms.
  • Users commend ZeroPath for its high accuracy in security detection, minimizing false alarms and enhancing issue resolution.
  • Users commend ZeroPath for its highly accurate vulnerability detection, minimizing false alarms and enhancing security efforts.
  • Users commend ZeroPath for its accurate vulnerability identification, significantly reducing false alarms and enhancing security efforts.
Cons
  • Users report bug issues with ZeroPath, but the support team addresses them quickly and effectively.
  • Users experience some bugs with ZeroPath, but the support team quickly resolves them to improve functionality.
  • Users face some software bugs in ZeroPath, though the team is responsive in resolving them quickly.
  • Users feel that the pricing structure of ZeroPath is not currently suitable for their organization's budget.
  • Users experience bugs in the dashboard, though the ZeroPath team swiftly addresses these problems.

What Are Recent G2 Reviews of ZeroPath?

Closure Compiler

The Closure Compiler is a tool for making JavaScript download and run faster. Instead of compiling from a source language to machine code, it compiles from JavaScript to better JavaScript.

Average Rating: 3.9/5.0

Total Reviews: 13

How Do G2 Users Rate Closure Compiler?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.7/10)
  • Ease of Admin: 10.0/10 (Category avg: 8.5/10)
  • Ease of Use: 8.2/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Closure Compiler?

  • Seller: Google
  • Year Founded: 1998
  • HQ Location: Mountain View, CA
  • Twitter: @google
    31,899,995 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    301,144 employees on LinkedIn®
  • Ownership: NASDAQ:GOOG

Who Uses This Product?

  • Company Size: 46% Small, 38% Medium

What Are Recent G2 Reviews of Closure Compiler?

What Are G2 Users Discussing About Closure Compiler?

OpsPilot

OpsPilot OpsPilot is an AI-powered observability and autonomous reliability platform with an AI Site Reliability Engineering (SRE) teammate that helps engineering and operations teams detect, understand, and resolve incidents faster — and increasingly prevent them from happening at all. Your 24/7 stack expert Modern production systems — microservices, distributed architectures, cloud and hybrid environments — generate enormous volumes of telemetry. Your existing tools surface that data. But they still leave engineers responsible for interpreting signals, finding root causes, and deciding what to do next. OpsPilot closes that gap. It continuously analyzes telemetry across your applications, infrastructure, and services — then tells your team what is happening, why it is happening, and what to do about it. From dashboards to autonomous reliability OpsPilot goes beyond alerting and visualization. It correlates signals across metrics, logs, traces, and deployment events to identify abnormal behavior, explain root causes, and guide teams toward faster resolution — dramatically reducing time spent on incident investigation and operational troubleshooting. Over time, it evolves from reactive investigation toward proactive and autonomous operations. Your AI SRE teammate OpsPilot acts as an AI SRE teammate — augmenting your operations team by answering the questions engineers face during incidents: What changed? Where is the failure occurring? Which service is responsible? What should we investigate next? Three core capabilities Observability — collects and correlates telemetry across metrics, logs, traces, JVM data, and application-level diagnostics for a complete picture of system behavior. Operational Intelligence — applies AI-driven analysis to surface what changed, what is causing the issue, which components are involved, and what actions may resolve it. Foundational capabilities include anomaly detection, alert reduction, telemetry correlation, and root cause analysis. Action and Automation — supports guided incident response, runbook generation, automated remediation, and continuous operational learning — moving teams progressively toward autonomous reliability. OpenTelemetry-native. No new agents required. OpsPilot ingests telemetry via OTLP over gRPC or HTTP — no proprietary agent required. It works with your existing OpenTelemetry instrumentation across Kubernetes, microservices, cloud services, and serverless platforms. Prometheus-compatible metrics, Loki log ingestion, and Jaeger/Zipkin trace formats are also supported. For teams needing deep JVM or ColdFusion diagnostics, the optional FusionReactor APM agent provides additional application-level telemetry. Built for DevOps, SRE, and platform engineering teams OpsPilot is designed for organizations running modern production systems that require high reliability and operational efficiency — particularly teams moving toward SRE or platform engineering models who need deeper operational insight without increasing headcount. Deployed as SaaS, hybrid, or agentless via OpenTelemetry.

Average Rating: 4.8/5.0

Total Reviews: 174

How Do G2 Users Rate OpsPilot?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.0/10 (Category avg: 8.5/10)
  • Ease of Use: 8.8/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind OpsPilot?

  • Seller: Intergral
  • Company Website:
  • Year Founded: 1998
  • HQ Location: Boeblingen, DE
  • Twitter: @Fusion_Reactor
    9,345 Twitter followers
  • LinkedIn® Page: www.linkedin.com

Who Uses This Product?

  • Who Uses This: CTO, Developer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 61% Small, 29% Medium

What Do G2 Reviewers Say About OpsPilot?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of OpsPilot, facilitating quick access to crucial metrics and troubleshooting insights.
  • Users find the real-time web metrics invaluable, enabling quick insights and identification of performance issues in their applications.
  • Users appreciate the real-time visibility and detailed insights provided by FusionReactor APM for effective monitoring.
  • Users value the real-time monitoring of OpsPilot, enabling effective performance management and quick issue resolution.
  • Users praise the responsive and friendly customer support of OpsPilot, making troubleshooting and assistance seamless.
Cons
  • Users find the learning curve challenging, as advanced features require careful configuration and can be overwhelming.
  • Users face difficult configuration challenges, leading to confusion and potentially missing out on important insights.
  • Users find the learning difficulty of OpsPilot challenging initially, requiring some research before effective use.
  • Users find the UI confusing, especially the Cloud version, despite ongoing improvements for clarity and usability.
  • Users find the UI design confusing, noting that it can complicate the initial experience with OpsPilot.

What Are Recent G2 Reviews of OpsPilot?

What Are G2 Users Discussing About OpsPilot?

Babel

Babel is a JavaScript compiler. It helps shape the future of the JavaScript language itself.

Average Rating: 4.5/5.0

Total Reviews: 20

How Do G2 Users Rate Babel?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.0/10 (Category avg: 8.5/10)
  • Ease of Use: 8.8/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 3.3/10 (Category avg: 10/10)

Who Is the Company Behind Babel?

  • Seller: BABEL
  • Year Founded: 2012
  • HQ Location: Paris, FR
  • LinkedIn® Page: www.linkedin.com
    123 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 48% Medium, 43% Small

What Are Recent G2 Reviews of Babel?

What Are G2 Users Discussing About Babel?

OpenText Core Application Security

Fortify on Demand (FoD) is a complete Application Security as a Service solution. It offers an easy way to get started with the flexibility to scale. In addition to static and dynamic, Fortify on Demand covers in-depth mobile app security testing, open-source analysis, and vendor application security management. False positives are removed for every test and test results can be manually reviewed by application security experts.

Average Rating: 4.1/5.0

Total Reviews: 34

How Do G2 Users Rate OpenText Core Application Security?

  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.9/10 (Category avg: 8.5/10)
  • Ease of Use: 8.2/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind OpenText Core Application Security?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 41% Large, 32% Small

What Are Recent G2 Reviews of OpenText Core Application Security?

What Are G2 Users Discussing About OpenText Core Application Security?

Klocwork

Perforce Klocwork is an enterprise grade SAST solution for C, C++, C#, Rust, Java, JavaScript, Python, and Kotlin. It helps development teams detect security vulnerabilities, quality issues, and reliability defects early, while supporting compliance with industry and regulatory standards. Klocwork is purpose built to analyze very large, complex codebases and scales to hundreds of millions of lines of code, well beyond the practical limits of many traditional SAST tools. This makes it especially suited for organizations developing long lived, safety critical, or security critical systems. Designed for DevOps and DevSecOps, Klocwork integrates with complex build systems, CI/CD pipelines, cloud and containerized environments, and common developer tools—enabling consistent security and quality enforcement without slowing development. Static Application Security Testing (SAST) Klocwork identifies a wide range of security vulnerabilities, including SQL injection, tainted data flows, buffer overflows, and other insecure coding practices. It also detects bugs and quality issues such as null pointer dereferences, memory and resource leaks, uncaught exceptions, and code smells. The solution supports compliance with internationally recognized standards including CWE, OWASP, CERT, PCI DSS, DISA STIG, and ISO/IEC TS 17961. Automated CI/CD integrations make continuous security testing practical even for very large systems. AI Assisted Code Remediation with MCP Klocwork extends static analysis with AI assisted code remediation, designed to help developers resolve findings faster and with greater confidence. Using MCP based capabilities, Klocwork securely exposes rich static analysis context—defect data, rule knowledge, and precise fix guidance—to supported AI code assist tools directly within the IDE. Rather than relying on generic AI suggestions, Klocwork’s remediation feature combines deep static analysis insights with comprehensive documentation and exact fix instructions, enabling AI assistants to propose accurate, context aware corrections for security vulnerabilities, quality defects, and coding standard violations. Fixes are presented as clear diffs and require developer review and approval, making the approach suitable for safety and security critical environments. By integrating remediation into the developer workflow, Klocwork reduces time spent interpreting analysis results, researching fixes, and switching between tools. Developers stay in their IDE, receive guided remediation aligned with secure coding standards and project specific rules, and can immediately re analyze code to validate fixes. This completes the optimal shift left approach—helping teams not only find issues early, but fix them efficiently and consistently. Project Streams and Enterprise Scalability Klocwork’s Project Streams feature simplifies managing shared codebases with multiple variants or branches. A single rule configuration can be applied across streams, issues common to multiple variants stay synchronized, and stream specific findings are clearly identified for reporting and compliance. Developer Focused and Centralized Klocwork integrates directly into popular IDEs to deliver fast, contextual feedback as developers write code. Out of the box compiler support eliminates manual setup, while centralized dashboards provide visibility into trends, risk, and compliance across projects of any size.

Average Rating: 4.4/5.0

Total Reviews: 22

How Do G2 Users Rate Klocwork?

  • Has the product been a good partner in doing business?: 8.1/10 (Category avg: 8.7/10)
  • Ease of Admin: 7.3/10 (Category avg: 8.5/10)
  • Ease of Use: 7.9/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Klocwork?

  • Seller: Perforce
  • Year Founded: 1995
  • HQ Location: Minneapolis, MN
  • Twitter: @perforce
    5,090 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,009 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 48% Medium, 35% Small

What Are Recent G2 Reviews of Klocwork?

Veracode Application Security Platform

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

Average Rating: 3.8/5.0

Total Reviews: 25

How Do G2 Users Rate Veracode Application Security Platform?

  • Has the product been a good partner in doing business?: 7.9/10 (Category avg: 8.7/10)
  • Ease of Admin: 7.4/10 (Category avg: 8.5/10)
  • Ease of Use: 7.3/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Veracode Application Security Platform?

  • Seller: VERACODE
  • Year Founded: 2006
  • HQ Location: Burlington, MA
  • Twitter: @Veracode
    21,950 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    500 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 69% Large, 31% Medium

What Do G2 Reviewers Say About Veracode Application Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the effective security vulnerability identification offered by Veracode, enhancing overall application safety and code integrity.
  • Users find Veracode's vulnerability detection excellent for identifying security issues and ensuring high application security standards.
  • Users value the automated scanning of Veracode, streamlining security checks and enhancing code quality effortlessly.
  • Users value the effective detection of security vulnerabilities, enabling robust protection and streamlined development processes.
  • Users appreciate the ease of integration with GitHub and CI/CD pipelines, streamlining their development process effectively.
Cons
  • Users find Veracode to be expensive, with high costs, complex licensing, and unfulfilled feature delivery.
  • Users face a lack of information due to mismatches in documentation and delayed notifications during uploads.
  • Users express concerns over licensing issues, including rising costs, complex models, and unequal feature availability.
  • Users report poor customer support with pushy account executives and difficulties in resolving issues efficiently.
  • Users express concerns about pricing issues, with rising costs and a complex licensing model affecting value perception.

What Are Recent G2 Reviews of Veracode Application Security Platform?

What Are G2 Users Discussing About Veracode Application Security Platform?

CodeScan

CodeScan Shield addresses code quality, security, and compliance liabilities with two automated modules: CodeScan and OrgScan. CodeScan provides static code analysis for total visibility into code health from the moment it’s written through production. OrgScan governs organizational policies by enforcing the security and compliance rules mandated for your Salesforce environment. Together, they ensure the code that makes up your Salesforce environment and the way the environment is being utilized will always meet high standards. The result is strengthened data security, streamlined DevSecOps processes, and an assurance of meeting compliance standards—avoiding potentially thousands of dollars in fines and lost opportunities. CodeScan Shield protects your Salesforce org from both the inside and outside. CodeScan provides dashboards and reports for consistent code visibility, while also alerting developers the moment new errors are introduced. OrgScan analyzes Salesforce policies to ensure the organization remains compliant with client-mandated specifications and guidelines. Violations are flagged and recorded in an interactive dashboard. Progress is tracked for policy reviews. Collectively, these features ensure admins maintain governance control within their organization. CodeScan Shield is part of AutoRABIT’s complete DevSecOps platform. Enabling Salesforce DevOps teams with CodeScan Shield’s powerful technology produces high-quality, secure applications and updates at speed.

Average Rating: 4.6/5.0

Total Reviews: 30

How Do G2 Users Rate CodeScan?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 8.6/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind CodeScan?

  • Seller: AutoRABIT
  • Year Founded: 2015
  • HQ Location: San Francisco, US
  • Twitter: @autorabit
    1,245 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    283 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 44% Large, 38% Medium

What Are Recent G2 Reviews of CodeScan?

What Are G2 Users Discussing About CodeScan?

Semmle

Semmle makes the management of software development easier than ever before. By giving you complete visibility _ for every project, location, team, developer, timeframe and cost _ Semmle is engineering intelligence at its most advanced.

Average Rating: 4.4/5.0

Total Reviews: 75

How Do G2 Users Rate Semmle?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 8.6/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Semmle?

  • Seller: Semmle
  • Year Founded: 2006
  • HQ Location: San Francisco, California
  • Twitter: @SemmleInc
    1 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 54% Small, 36% Medium

What Are Recent G2 Reviews of Semmle?

Quality Clouds for ServiceNow

Quality Clouds is the most comprehensive governance and quality management platform for the ServiceNow ecosystem. As organizations move toward Now Assist (GenAI) and democratized development through Creator Studio, Quality Clouds provides the automated guardrails required to keep your instance "Clean, Lean, and Green." We help ServiceNow Platform Owners, Architects, and Centers of Excellence (CoE) maintain a high-performing, upgrade-ready environment while accelerating the delivery of new digital workflows. The Solution for ServiceNow Platform Owners: - Now Assist & AI Governance: Automatically audit AI-generated scripts and configurations from ServiceNow’s GenAI tools. Ensure that "Prompt-to-Code" logic follows your internal security standards and platform best practices. - Upgrade Readiness & OOTB Integrity: Identify "Hard-coded" logic and "Spaghetti" customizations that block upgrades. Quality Clouds ensures you stay as close to Out-of-the-Box (OOTB) as possible, reducing the cost of ownership. - Citizen Development Oversight: Safely scale Creator Studio and App Engine. Monitor the quality of apps built by citizen developers to prevent technical debt from exploding across your production instance. - Native DevOps Integration: Embed automated quality gates directly into your ServiceNow CI/CD pipelines. Stop high-risk Update Sets from moving to Production before they pass your custom architectural checks. - Instance Consolidation: Use our cross-instance dashboard to compare the health of your Dev, Test, and Prod environments, ensuring consistency across your entire ServiceNow footprint.

Average Rating: 4.6/5.0

Total Reviews: 11

How Do G2 Users Rate Quality Clouds for ServiceNow?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 8.7/10)
  • Ease of Admin: 9.2/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 10/10 (Category avg: 10/10)

Who Is the Company Behind Quality Clouds for ServiceNow?

  • Seller: Quality Clouds Ltd
  • Year Founded: 2015
  • HQ Location: London, England
  • Twitter: @QualityClouds
    410 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    46 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 55% Large, 27% Small

What Are Recent G2 Reviews of Quality Clouds for ServiceNow?

What Are G2 Users Discussing About Quality Clouds for ServiceNow?

Parasoft Jtest

Parasoft Jtest is an integrated Java testing tool for Application Software Development. Develop high-quality code within an Agile workflow. Jtest’s comprehensive set of Java testing tools ensures high code coverage through every stage of software development. Parasoft Jtest integrates tightly into your development ecosystem and CI/CD pipeline for real-time, intelligent feedback on your testing and compliance progress. Jtest highlights code coverage and code quality, leverages AI for JUnit test creation, and identifies security and reliability issues so stakeholders can understand the quality of the deliverables and make informed decisions about risk of release.

Average Rating: 4.6/5.0

Total Reviews: 13

How Do G2 Users Rate Parasoft Jtest?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Parasoft Jtest?

  • Seller: Parasoft
  • Year Founded: 1987
  • HQ Location: Monrovia, CA
  • Twitter: @Parasoft
    2,602 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    295 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 38% Large, 31% Medium

What Are Recent G2 Reviews of Parasoft Jtest?

What Are G2 Users Discussing About Parasoft Jtest?

Roslyn

The .NET Compiler Platform ("Roslyn") provides open-source C# and Visual Basic compilers with rich code analysis APIs.

Average Rating: 4.4/5.0

Total Reviews: 11

How Do G2 Users Rate Roslyn?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 8.7/10)
  • Ease of Admin: 8.3/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 3.3/10 (Category avg: 10/10)

Who Is the Company Behind Roslyn?

  • Seller: Codeplex
  • Year Founded: 2007
  • HQ Location: N/A
  • Twitter: @codeplex
    28,239 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    45 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 58% Large, 42% Small

What Are Recent G2 Reviews of Roslyn?

What Are G2 Users Discussing About Roslyn?

DeepSource

DeepSource is an all-in-one code health platform that equips organizations with everything they need to build maintainable and secure software while elevating the velocity of their software development cycle. - Guaranteed below 5% false-positive rate with highly accurate and fast static analyzers - Automated issue remediation with Autofix™️ - Code Issue and security reporting: OWASP Top 10, SANS Top 25, Code Coverage, and more - Self-hosted option with one-click installation and upgrades

Average Rating: 4.6/5.0

Total Reviews: 22

How Do G2 Users Rate DeepSource?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 8.7/10)
  • Ease of Admin: 10.0/10 (Category avg: 8.5/10)
  • Ease of Use: 9.3/10 (Category avg: 8.8/10)
  • What is your organization's estimated ROI on the product (payback period in months)?: 3.3/10 (Category avg: 10/10)

Who Is the Company Behind DeepSource?

  • Seller: DeepSource
  • Year Founded: 2018
  • HQ Location: San Francisco, California
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 82% Small, 9% Large

What Are Recent G2 Reviews of DeepSource?

What Are G2 Users Discussing About DeepSource?

Adam Crivello
AC
Researched and written by Adam Crivello
Updated October 3, 2024