# Best Static Code Analysis Tools - Page 6

## How Many Static Code Analysis Tools Products Does G2 Track?

**Total Products under this Category:** 131

### Category Stats (Aug 2026)

- **Average Rating:** 4.38/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Black Duck Coverity Static (+0.61%) - Among all products in this category, Black Duck Coverity Static recorded the largest rating increase compared to last month

_Last updated: August 07, 2026_

## How Does G2 Rank Static Code Analysis Tools Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 2,200+ Authentic Reviews
- 131+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Static Code Analysis Tools
 ![G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence](https://www.g2.com/categories/static-code-analysis/grids.png?focus%5B%5D=7775&focus%5B%5D=102905&focus%5B%5D=1385185&focus%5B%5D=4475&focus%5B%5D=1225549&focus%5B%5D=161987&focus%5B%5D=1225688&focus%5B%5D=48275)

Highlighted products: SonarQube, Gearset DevOps, SoftSpell, Checkmarx, Semgrep, CAST Imaging, Typo, and ReSharper C++.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=softspell&focus%5B%5D=checkmarx&focus%5B%5D=semgrep&focus%5B%5D=cast-imaging&focus%5B%5D=typo&focus%5B%5D=resharper-c)

**Sponsored**

### Endor Labs

Endor Labs turns application security into a competitive advantage. At the core is AURI, the security harness for agentic development. It helps coding agents write secure code by default, automates PR security reviews, and gives agents deterministic context to fix what matters fast. At the core is our patented code context graph: a continuously updated model of application behavior across code, dependencies, secrets, and containers. The result: 83% fewer blocked PRs, 10x fewer security tickets, and 6x faster remediation at Atlassian, Cursor, Rubrik, and Snowflake.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=564&secure%5Bchosen_at%5D=2026-08-15T05%3A05%3A42Z&secure%5Bdisplayable_resource_id%5D=2041&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=2041&secure%5Bplacement_resource_ids%5D%5B%5D=1520&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1317430&secure%5Bresource_id%5D=564&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fstatic-code-analysis%3Fpage%3D6%26selected_view%3Dgrid&secure%5Btoken%5D=30e976a5a3cbfebd2acecdae3106b565a6e8ef89a7e7f96b1e8b48757ed9cabb&secure%5Burl%5D=https%3A%2F%2Fwww.endorlabs.com%2Fplatform%3Futm_source%3Dg2%26utm_medium%3Ddisplay%26utm_campaign%3Dg2-ad&secure%5Burl_type%5D=custom_url)

### [JArchitect](https://www.g2.com/products/jarchitect/reviews)

JArchitect simplifies managing a complex Java code base. You can analyze code structure, specify design rules, do effective code reviews and master evolution by comparing different versions of the code.

**Average Rating:** 4.0/5.0

**Total Reviews:** 1

#### Who Is the Company Behind JArchitect?

- **Seller:** [CoderGears](https://www.g2.com/sellers/codergears)
- **Year Founded:** 2009
- **HQ Location:** Wilmington, US
- **Twitter:** @CoderGears  
81 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7859925e675be7388be89ec9eb613c1712c9ba3748fcfdae2a3c86e796906849&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5385116&secure%5Burl_type%5D=linkedin_company_website)  
2 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Medium

#### What Are Recent G2 Reviews of JArchitect?

**["Useful Application"](https://www.g2.com/survey_responses/jarchitect-review-5302184)**

**Rating:** 4.0/5.0 stars

_— Verified User in Computer & Network Security_

[Read full review](https://www.g2.com/survey_responses/jarchitect-review-5302184)

#### What Are G2 Users Discussing About JArchitect?

- [What is JArchitect used for?](https://www.g2.com/discussions/what-is-jarchitect-used-for)

### [OCLint](https://www.g2.com/products/oclint/reviews)

OCLint is a static code analysis tool for improving quality and reducing defects by inspecting C, C++ and Objective-C code.

**Average Rating:** 4.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate OCLint?

- **Ease of Use:** 3.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind OCLint?

- **Seller:** [OCLint](https://www.g2.com/sellers/oclint)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7886df2ed926834e5eb248c77dcfa8e5c815d3ab1f0fe3132ced0dba45868834&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FNo-Linkedin-Presence-Added-Intentionally-By-DataOps&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Medium

#### What Are Recent G2 Reviews of OCLint?

**["Good extension for Clang Analyzer, finds more problems, more bothersome to configure"](https://www.g2.com/survey_responses/oclint-review-102574)**

**Rating:** 4.0/5.0 stars

_— Aleksander B._

[Read full review](https://www.g2.com/survey_responses/oclint-review-102574)

#### What Are G2 Users Discussing About OCLint?

- [What is OCLint used for?](https://www.g2.com/discussions/oclint-what-is-oclint-used-for)
- [What is OCLint used for?](https://www.g2.com/discussions/what-is-oclint-used-for)

### [PT Application Inspector](https://www.g2.com/products/pt-application-inspector/reviews)

PT Application Inspector™ (PT AI™) is a comprehensive source code analysis tool that offers protection for web applications of any scale. Its holistic approach combines the advantages of static, dynamic, and interactive analysis to maintain application security throughout every stage of development—from the very first line of code to the go-live.

**Average Rating:** 5.0/5.0

**Total Reviews:** 2

#### How Do G2 Users Rate PT Application Inspector?

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 8.7/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.5/10)
- **Ease of Use:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind PT Application Inspector?

- **Seller:** [Positive Technologies](https://www.g2.com/sellers/positive-technologies)
- **HQ Location:** N/A
- **Twitter:** @PTsecurity\_UK  
6 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=72d1f72f1158c4fa727ba2e5c23b6cdf81412fcdbe1d7abe21c044b6641c9991&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpositivetechnologies%2F&secure%5Burl_type%5D=linkedin_company_website)  
776 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Large, 33% Small

#### What Are Recent G2 Reviews of PT Application Inspector?

**["We chose PT AI for SDL"](https://www.g2.com/survey_responses/pt-application-inspector-review-3356602)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/pt-application-inspector-review-3356602)

**["Nice source code analyzer "](https://www.g2.com/survey_responses/pt-application-inspector-review-3394127)**

**Rating:** 5.0/5.0 stars

_— Verified User in Banking_

[Read full review](https://www.g2.com/survey_responses/pt-application-inspector-review-3394127)

#### What Are G2 Users Discussing About PT Application Inspector?

- [What is PT Application Inspector used for?](https://www.g2.com/discussions/what-is-pt-application-inspector-used-for)

### [PVS-Studio](https://www.g2.com/products/pvs-studio/reviews)

PVS-Studio is a SAST solution that helps enhance code quality, security, and safety. The analyzer detects bugs and potential vulnerabilities in C, C++, C#, and Java code on Windows, Linux, and macOS. Features - Supports various analysis types (intermodular, incremental, data flow analysis, taint analysis); - Can be used offline; - Provides cross-platform integration; - Offers ways to handle false positives; - Helps small and large teams maintain code quality. Pros - Quick and high-quality support from the analyzer developers; - 900+ diagnostic rules with detailed descriptions and examples; - Compliance with safety and security standards: OWASP TOP 10, MISRA C, C++, AUTOSAR, CWE; - Detailed reports and reminders for developers and managers (Blame Notifier); - User-friendly ways to handle legacy code, including mass suppression of analyzer’s warnings; - Support of the Open Source Community, analysis of open-source projects; - Integration with SonarQube. Pricing - In the commercial version, prices are set on request and can be changed depending on the required set of features; - Free trial is available; - PVS-Studio may offer a free licensing option to students, MVPs, public experts in security, and contributors to open-source projects.

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate PVS-Studio?

- **Ease of Use:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind PVS-Studio?

- **Seller:** [PVS-Studio](https://www.g2.com/sellers/pvs-studio)
- **Year Founded:** 2008
- **HQ Location:** Astana, KZ
- **Twitter:** @Code\_Analysis  
5,907 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=24750e0570ac956558844ec0d0ba968eacd92d6b53897f1cdfe9e30c00a23060&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpvs-studio%2F&secure%5Burl_type%5D=linkedin_company_website)  
29 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Small

#### What Are Recent G2 Reviews of PVS-Studio?

**["The best static analysis app I have ever tried"](https://www.g2.com/survey_responses/pvs-studio-review-6645325)**

**Rating:** 5.0/5.0 stars

_— Michael F._

[Read full review](https://www.g2.com/survey_responses/pvs-studio-review-6645325)

#### What Are G2 Users Discussing About PVS-Studio?

- [What is PVS-Studio used for?](https://www.g2.com/discussions/what-is-pvs-studio-used-for)

### [Sider](https://www.g2.com/products/sider/reviews)

Seamless GitHub integration

**Average Rating:** 3.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate Sider?

- **Ease of Use:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Sider?

- **Seller:** [Sider](https://www.g2.com/sellers/sider)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7886df2ed926834e5eb248c77dcfa8e5c815d3ab1f0fe3132ced0dba45868834&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FNo-Linkedin-Presence-Added-Intentionally-By-DataOps&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Medium

#### What Are G2 Users Discussing About Sider?

- [What is Sider used for?](https://www.g2.com/discussions/what-is-sider-used-for)

### [Symbiotic Security](https://www.g2.com/products/symbiotic-security/reviews)

Symbiotic Security is an AI-powered cybersecurity company that embeds security directly into developer workflows. Symbiotic offers two complementary solutions: Symbiotic Flow for real-time detection and remediation in the IDE, Symbiotic Code for secure AI code generation with built-in policy enforcement. Our platform detects vulnerabilities as they're introduced whether from developers, AI assistants, or open source and instantly provides context-aware fixes with over 70% fewer false positives. Agentic AI remediation analyzes full context and automatically resolves issues before code reaches production. Customizable guardrails enforce organizational security policies directly into AI code generation, making secure-by-design the default. Each fix includes just-in-time training tailored to the vulnerability, helping developers build real security expertise. Teams see a 68% reduction in recurring vulnerabilities after three months while maintaining development velocity.

**Average Rating:** 5.0/5.0

**Total Reviews:** 3

#### How Do G2 Users Rate Symbiotic Security?

- **Ease of Use:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Symbiotic Security?

- **Seller:** [Symbiotic Security](https://www.g2.com/sellers/symbiotic-security)
- **Year Founded:** 2024
- **HQ Location:** New York, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6a1df1a1a8348c702f46a5a4412bfd339edc809f48a5865c95bd4804c6e18fda&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsymbiotic-security&secure%5Burl_type%5D=linkedin_company_website)  
14 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Small, 33% Large

#### What Do G2 Reviewers Say About Symbiotic Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **efficiency improvement** of Symbiotic Security, significantly saving time and enhancing proactive security measures.
- Users commend Symbiotic Security for its **speed** in identifying security issues early, enhancing development efficiency and product safety.
- Users find Symbiotic Security **super easy to use** , significantly speeding up internal processes and enhancing proactive security measures.
- Users value the **proactive security integration** of Symbiotic Security, significantly enhancing the development process and product safety.
- Users value the **high accuracy** of Symbiotic Security in identifying potential security issues early in development.

#### What Are Recent G2 Reviews of Symbiotic Security?

**["Easy to use security tool!"](https://www.g2.com/survey_responses/symbiotic-security-review-10703729)**

**Rating:** 5.0/5.0 stars

_— Daniel D._

[Read full review](https://www.g2.com/survey_responses/symbiotic-security-review-10703729)

**["Excellent platform to shift security left"](https://www.g2.com/survey_responses/symbiotic-security-review-10786885)**

**Rating:** 5.0/5.0 stars

_— Justin S._

[Read full review](https://www.g2.com/survey_responses/symbiotic-security-review-10786885)

### [Yasca](https://www.g2.com/products/yasca/reviews)

Yasca is an open source program which looks for security vulnerabilities, code-quality, performance, and conformance to best practices in program source code, integrating with other open-source tools as needed.

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### Who Is the Company Behind Yasca?

- **Seller:** [Michael Scovetta](https://www.g2.com/sellers/michael-scovetta)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c0315fb0aa1ed8af31e9febdc91fb504acd18f3536eebb319a76f26db1a9ca9c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsourceforge.net%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Large

#### What Are Recent G2 Reviews of Yasca?

**["Really good"](https://www.g2.com/survey_responses/yasca-review-748746)**

**Rating:** 5.0/5.0 stars

_— Verified User in Outsourcing/Offshoring_

[Read full review](https://www.g2.com/survey_responses/yasca-review-748746)

#### What Are G2 Users Discussing About Yasca?

- [What is Yasca used for?](https://www.g2.com/discussions/yasca-what-is-yasca-used-for)
- [What is Yasca used for?](https://www.g2.com/discussions/what-is-yasca-used-for)

### [AI-code Verification Platform](https://www.g2.com/products/ai-code-verification-platform/reviews)

Shipmoor is a local, vendor-neutral verification layer for AI-agent-written code. It composes deterministic scans, test evidence, and advisory review into one binding verdict instead of trusting an agent's word that a task is done. No source upload, no account required to start.

#### Who Is the Company Behind AI-code Verification Platform?

- **Seller:** [Shipmoor](https://www.g2.com/sellers/shipmoor)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=365f4bb4dbfbac0590ba220e83ea14c8678bd8c95f2118e3bf4512a2ab8581bd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fshipmoor-dev&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [AutoReview](https://www.g2.com/products/autoreview/reviews)

Review collection on autopilot.

#### Who Is the Company Behind AutoReview?

- **Seller:** [AutoReview](https://www.g2.com/sellers/autoreview)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7886df2ed926834e5eb248c77dcfa8e5c815d3ab1f0fe3132ced0dba45868834&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FNo-Linkedin-Presence-Added-Intentionally-By-DataOps&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [Axivion](https://www.g2.com/products/axivion/reviews)

Axivion Static Code Analysis helps developers check standard compliance, security vulnerabilities, and code quality issues for C and C++ code. It performs automated analysis to identify violations of coding guidelines like MISRA C and detect clones, dead code, and security vulnerabilities. Key features include coding standards compliance checking, metric monitoring, defect analysis, and certification for safety-critical software development.

#### Who Is the Company Behind Axivion?

- **Seller:** [Qt Group](https://www.g2.com/sellers/qt-group)
- **Year Founded:** 1995
- **HQ Location:** Espoo, Finland
- **Twitter:** @qtproject  
21,456 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6a2495552dacd153e9beb62f01a89167324b4e81c62c8e844647541d7d75c1fd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fqt-quality-assurance%2F&secure%5Burl_type%5D=linkedin_company_website)  
20 employees on LinkedIn®

### [Bearer](https://www.g2.com/products/bearer/reviews)

Bearer helps modern teams ship trustworthy products with the help of our code security SAST solution built for security, privacy and engineering teams. We combine sensitive data context with static code analysis to make security and privacy engineering simpler and smarter to maximize the ROI for your DevSecOps and central security team driven programs.

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate Bearer?

- **Ease of Use:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Bearer?

- **Seller:** [Bearer](https://www.g2.com/sellers/bearer)
- **Year Founded:** 2019
- **HQ Location:** Cambridge, US
- **Twitter:** @BearerSH  
16 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0855685d4cc09cd0206dc0667bc6e7d0b014c336a87035afff95dfbfb26e0f10&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FBearer&secure%5Burl_type%5D=linkedin_company_website)  
25 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Medium

#### What Are Recent G2 Reviews of Bearer?

**["Has made our overall security so much better!"](https://www.g2.com/survey_responses/bearer-review-8774052)**

**Rating:** 5.0/5.0 stars

_— kristin b._

[Read full review](https://www.g2.com/survey_responses/bearer-review-8774052)

### [Better Code Hub](https://www.g2.com/products/better-code-hub/reviews)

Write better code. With a Definition of Done. Better Code Hub checks your code base for compliance against 10 software engineering guidelines - and gives you immediate feedback on where to focus for quality improvements. https://github.com/marketplace/better-code-hub

#### Who Is the Company Behind Better Code Hub?

- **Seller:** [Software Improvement Group](https://www.g2.com/sellers/software-improvement-group)
- **Year Founded:** 2000
- **HQ Location:** Amsterdam, NL
- **Twitter:** @sig\_eu  
870 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=caf2b3b38f41576cb5e186dbf82d7ccb9330f754fba0cbb316bb1d25378ee832&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsoftware-improvement-group&secure%5Burl_type%5D=linkedin_company_website)  
138 employees on LinkedIn®

### [Bugsmirror MASST (Mobile Application Security Suite & Tools)](https://www.g2.com/products/bugsmirror-masst-mobile-application-security-suite-tools/reviews)

Bugsmirror Mobile Application Security Suite & Tools (MASST) is designed specifically for your business, providing scalable, end-to-end security for your mobile app. From detection to protection, MASST ensures your app is safeguarded against evolving security threats. With MASST, you can focus on growing your business, knowing your app is fully protected at every stage.

#### Who Is the Company Behind Bugsmirror MASST (Mobile Application Security Suite & Tools)?

- **Seller:** [Bugsmirror](https://www.g2.com/sellers/bugsmirror)
- **Year Founded:** 2021
- **HQ Location:** Indore, IN
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e96879b9554540eb5e0ded6a7cf720915be1bc63851a268525300d2c10b8af90&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fbugsmirror%2F&secure%5Burl_type%5D=linkedin_company_website)  
17 employees on LinkedIn®

### [Clean.do](https://www.g2.com/products/clean-do/reviews)

Clean.do is a Salesforce Health Check tool that displays the results of your Salesforce audit for your metadata, code, security, and errors. Metadata Audit We check all objects, fields, workflows, process builder, validation rules etc to find any areas of improvement. Code Audit We check 50 different parameters in code including best practices, code style, design, performance, security etc. Security Audit We do a health check of all users, profiles, permission sets and other major security updates recommended by Salesforce.

#### Who Is the Company Behind Clean.do?

- **Seller:** [Chitiz Agrawal](https://www.g2.com/sellers/chitiz-agrawal)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7886df2ed926834e5eb248c77dcfa8e5c815d3ab1f0fe3132ced0dba45868834&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FNo-Linkedin-Presence-Added-Intentionally-By-DataOps&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [ClearDB Documenter](https://www.g2.com/products/cleardb-documenter/reviews)

A platform to create highly detailed database documentation and perform comprehensive security audits.

#### Who Is the Company Behind ClearDB Documenter?

- **Seller:** [Conquest Software Solutions](https://www.g2.com/sellers/conquest-software-solutions)
- **HQ Location:** Las Vegas, US
- **Twitter:** @Conquest\_soft  
21 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1bb93acead23019a9a0b23f2ae8563175b54a8a88f045ba3a2d351468d198dc6&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F24774241%2F&secure%5Burl_type%5D=linkedin_company_website)  
2 employees on LinkedIn®

- [&lsaquo; Prev ‹ Prev](/categories/static-code-analysis?order=g2_score&page=5&selected_view=grid#product-list)
- [1](/categories/static-code-analysis?order=g2_score&selected_view=grid#product-list)
- [2](/categories/static-code-analysis?order=g2_score&page=2&selected_view=grid#product-list)
- [3](/categories/static-code-analysis?order=g2_score&page=3&selected_view=grid#product-list)
- [4](/categories/static-code-analysis?order=g2_score&page=4&selected_view=grid#product-list)
- [5](/categories/static-code-analysis?order=g2_score&page=5&selected_view=grid#product-list)
- 6
- [7](/categories/static-code-analysis?order=g2_score&page=7&selected_view=grid#product-list)
- [8](/categories/static-code-analysis?order=g2_score&page=8&selected_view=grid#product-list)
- [9](/categories/static-code-analysis?order=g2_score&page=9&selected_view=grid#product-list)
- [Next &rsaquo; Next ›](/categories/static-code-analysis?order=g2_score&page=7&selected_view=grid#product-list)

Spotlight Categories

[Relational Databases](https://www.g2.com/categories/relational-databases)

[Background Check Software](https://www.g2.com/categories/background-check)

[Procure to Pay Software](https://www.g2.com/categories/procure-to-pay)

[Workforce Management Software](https://www.g2.com/categories/workforce-management)

[SMS Marketing Software](https://www.g2.com/categories/sms-marketing)

Similar Categories

- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)
- [Log Analysis](/categories/log-analysis)

- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Static Code Analysis Themes](/categories/static-code-analysis/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated October 3, 2024

Static code analysis is the analysis of computer software performed without actually executing the code. Static code analysis tools scan all code in a project and seek out vulnerabilities, validates code against industry best practices, and some software tools validate against company-specific project specifications. Static code analysis tools are used by software development and quality assurance teams to ensure the quality and security of code, and that project requirements are met. Static code analysis is a type of source code management and can integrate with version control systems and through build automation tasks using continuous integration software.

To qualify as a static code analysis tool, a product must:

- Scan code without executing that code
- List security vulnerabilities after scanning
- Validate code against industry best practices
- Provide recommendations on where and how to fix issues

Show More