# Best Static Code Analysis Tools - Page 8

## How Many Static Code Analysis Tools Products Does G2 Track?

**Total Products under this Category:** 131

### Category Stats (Aug 2026)

- **Average Rating:** 4.38/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Black Duck Coverity Static (+0.61%) - Among all products in this category, Black Duck Coverity Static recorded the largest rating increase compared to last month

_Last updated: August 07, 2026_

## How Does G2 Rank Static Code Analysis Tools Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 2,200+ Authentic Reviews
- 131+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Static Code Analysis Tools
 ![G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence](https://www.g2.com/categories/static-code-analysis/grids.png?focus%5B%5D=7775&focus%5B%5D=102905&focus%5B%5D=1385185&focus%5B%5D=4475&focus%5B%5D=1225549&focus%5B%5D=161987&focus%5B%5D=1225688&focus%5B%5D=48275)

Highlighted products: SonarQube, Gearset DevOps, SoftSpell, Checkmarx, Semgrep, CAST Imaging, Typo, and ReSharper C++.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=softspell&focus%5B%5D=checkmarx&focus%5B%5D=semgrep&focus%5B%5D=cast-imaging&focus%5B%5D=typo&focus%5B%5D=resharper-c)

**Sponsored**

### Acquia DAM (Widen)

Acquia DAM is a digital asset management system built for enterprise marketing, creative, and brand teams managing high volumes of digital content across channels, regions, and teams. Marketing teams use it to get approved assets to campaigns faster. Creative teams use it to minimize time fielding small production requests and focus on bigger projects. AI organizes assets at upload, surfaces them through plain-language search, and connects them to the tools that act on them. Trusted by over 1.5 million users worldwide, Acquia DAM manages more than 166 million assets and processes over 300 million API calls per month across connected tools and channels. Manufacturing and consumer goods teams manage high-SKU libraries distributed to retailers and regional teams. Financial services teams maintain controlled distribution with audit trails and rights management. Healthcare organizations govern clinical and partner content in HIPAA-ready environments. Higher education institutions give departments access to approved assets while central brand teams retain oversight. Technology and media companies coordinate pre-release and campaign assets across internal teams and agencies. Core capabilities include: AI-powered search and organization. Natural Language Search finds assets by intent, in any language. Auto-tagging, video transcription, alt text generation, and deduplication run at upload. Brand governance. Rights management, expiration enforcement, multi-stage approval workflows, and role-based permissions protect brand integrity at every touchpoint, with full audit trails. Content production. Built-in templates and a video editor with AI-assisted localization let teams adapt assets for new markets without a creative request. Publishing and activation. Smart Embed publishes web-optimized assets directly to CMS. Asset Insights tracks usage after publishing. Integration depth. Connects with nearly 300 tools including marketing automation, CMS, PIM, e-commerce, and digital marketplaces. Native Drupal CMS integration included. Published outcomes include a 50% reduction in time to distribute assets to customers, agencies, and partners (Autodesk) and an 83% reduction in time to find images across a 20,000-user deployment (Zurich Insurance). Acquia DAM is available standalone or as part of Acquia's Digital Experience Platform, connecting to Acquia's CMS, web governance, and content optimization products.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=564&secure%5Bchosen_at%5D=2026-08-15T04%3A19%3A21Z&secure%5Bdisplayable_resource_id%5D=260&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=retargeted_product&secure%5Bplacement_resource_ids%5D%5B%5D=4007&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=4007&secure%5Bresource_id%5D=564&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fstatic-code-analysis%3Fpage%3D8%26selected_view%3Dgrid&secure%5Btoken%5D=1f8171182c334745bafab6d955002d8496f81f8112e1c1a7ed1a8d480b1b6c9c&secure%5Burl%5D=https%3A%2F%2Fwww.acquia.com%2Fabout-us%2Fcontact%2Fdam-request-a-demo%3Futm_source%3Dg2-clicks%26utm_medium%3Dpaid-referral%26utm_campaign%3Dgtm_26_pp_g2_dam%26utm_content%3D701Pb00002lT69GIAS%26utm_term%3Dg2-dam-request-a-demo_btn&secure%5Burl_type%5D=custom_url)

### [Meta Code Llama](https://www.g2.com/products/meta-code-llama/reviews)

Code Llama has the potential to make workflows faster and more efficient for current developers and lower the barrier to entry for people who are learning to code. Code Llama has the potential to be used as a productivity and educational tool to help programmers write more robust, well-documented software.

#### Who Is the Company Behind Meta Code Llama?

- **Seller:** [Meta Platforms, Inc](https://www.g2.com/sellers/meta-platforms-inc)
- **Year Founded:** 2008
- **HQ Location:** Menlo Park, CA
- **Twitter:** @Meta  
9,891,711 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8ddd5ae494d43c8871a4a073a634fa2f05131a85b5f7f4df13a9fc1cffa0ec84&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmeta%2F&secure%5Burl_type%5D=linkedin_company_website)  
158,764 employees on LinkedIn®
- **Ownership:** NASDAQ: META

### [Moose](https://www.g2.com/products/moose/reviews)

Moose is a platform for software and data analysis. It helps programmers craft custom analyses cheaply. It's based on Pharo and it's open source under BSD/MIT. Install

#### Who Is the Company Behind Moose?

- **Seller:** [Moose Technology](https://www.g2.com/sellers/moose-technology)
- **HQ Location:** N/A
- **Twitter:** @moosetechnology  
704 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7886df2ed926834e5eb248c77dcfa8e5c815d3ab1f0fe3132ced0dba45868834&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FNo-Linkedin-Presence-Added-Intentionally-By-DataOps&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [Omnext Fit Test Platform](https://www.g2.com/products/omnext-fit-test-platform/reviews)

Omnext helps both managers and software developers gain insight in their applications technical quality and risks.

#### Who Is the Company Behind Omnext Fit Test Platform?

- **Seller:** [Omnext](https://www.g2.com/sellers/omnext)
- **HQ Location:** N/A
- **Twitter:** @Omnext  
132 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6e24f5adce0095c2732404e30085b49a6a6432733109c82d239e0eff5bd1eebc&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fomnext%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [OutputDebugString Checker](https://www.g2.com/products/outputdebugstring-checker/reviews)

OutputDebugString Checker is a software tool that scans source code looking for calls to OutputDebugString() that are not conditionally compiled. Reasons to look for OutputDebugString(): 1) Leaving these calls in your program slows down execution. The method to communicate the string to a debugger is by raising an exception. This is slow, and if a debugger is monitoring the exception, it’s slower than without the debugger. 2) Leaving these calls in your program allows data to leak out of your program. The contents of these calls many contain function names, debugging information, data the program is processing. Do you want your customers to see this information?

#### Who Is the Company Behind OutputDebugString Checker?

- **Seller:** [Software Verify](https://www.g2.com/sellers/software-verify)
- **Year Founded:** 2002
- **HQ Location:** Ely, GB
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c2f780d2a383318e312c0cefe217cda5531c49fc233ae750090ff9c893d75c8b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsoftware-verification-limited&secure%5Burl_type%5D=linkedin_company_website)  
2 employees on LinkedIn®

### [Parasoft dotTEST](https://www.g2.com/products/parasoft-dottest/reviews)

Parasoft dotTEST, automates a broad range of software quality practices for your C# and VB.NET development activities. Deep code analysis uncovers reliability and security issues. Code coverage, requirements traceability, and automated compliance reporting helps achieve compliance for security standards and safety-critical industries.

#### Who Is the Company Behind Parasoft dotTEST?

- **Seller:** [Parasoft](https://www.g2.com/sellers/parasoft)
- **Year Founded:** 1987
- **HQ Location:** Monrovia, CA
- **Twitter:** @Parasoft  
2,602 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e0cc1e9b128b54b280c5df9e752a80b9fa4a32248d4a398f37502d4212a72a77&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fparasoft%2F&secure%5Burl_type%5D=linkedin_company_website)  
298 employees on LinkedIn®

### [PATHTOSHIP](https://www.g2.com/products/pathtoship/reviews)

PathToShip is a production-readiness scanner for applications built with AI coding tools. Paste a GitHub URL and in about 30 seconds you get a 0–100 score, a prioritized list of findings with concrete fixes, and a clear answer to the question every AI-assisted builder eventually faces: is this actually safe to ship? The scanner runs more than 75 checks across seven dimensions: security, architecture, scalability, production readiness, code quality, cost efficiency, and infrastructure. Findings are ranked by severity with file-and-line locations and plain-language explanations of what's wrong and how to fix it, so the results work whether you read them yourself or hand them to your AI coding assistant. The scan also estimates your monthly infrastructure cost today and at 10x scale, and flags vendor lock-in before it gets expensive. PathToShip is built for founders, agencies, and small teams shipping apps made with Bolt, Lovable, Cursor, v0, Replit, Windsurf, and similar tools. These tools are remarkable at producing working software quickly; what they don't reliably produce is software hardened for real users. We scanned 521 public AI-built repositories and found that only 20 percent met the production-ready bar of 80/100, 36 percent had at least one critical security finding, and 25 percent shipped a hardcoded secret or API key. The gap between a working demo and a shippable product is real, and it is usually the same handful of issues. The free tier is the complete scan: every finding, no signup, public or private repositories. Apps that score 80 or higher earn a shareable, embeddable PathToShip Certified badge with per-dimension scores. For teams that want to close the gap quickly, a one-time $99 ASSESS report adds AI-generated remediation specs for each finding, a step-by-step mitigation checklist designed to paste directly into your AI coding tool, a vendor lock-in and exit-cost analysis, and a downloadable PDF. We hold ourselves to the same standard we apply to everyone else. Our own repository initially scored 56/100 on our own scanner. We bought our own report, worked the checklist, and reached 97, earning our own Certified badge, and we published every finding and fix along the way, including the false positives we corrected in the scanner itself. If you've built an app with AI assistance, find out where you stand before your users do.

#### Who Is the Company Behind PATHTOSHIP?

- **Seller:** [PathToShip](https://www.g2.com/sellers/pathtoship)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7886df2ed926834e5eb248c77dcfa8e5c815d3ab1f0fe3132ced0dba45868834&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FNo-Linkedin-Presence-Added-Intentionally-By-DataOps&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [PITSS.CON](https://www.g2.com/products/pitss-con/reviews)

PITSS.CON is a comprehensive software suite designed to analyze, modernize, and optimize legacy Oracle Forms and Reports applications. By providing in-depth static and dynamic code analysis, it enables organizations to fully understand their existing systems, identify areas for improvement, and implement efficient modernization strategies. PITSS.CON facilitates the extraction of business logic, code reengineering, and thorough documentation, ensuring that legacy applications are transformed to meet current and future business needs. Key Features and Functionality: - Static Code Analysis: Offers a detailed examination of Oracle Forms and Reports applications, regardless of their size or complexity, to eliminate uncertainties in development and maintenance processes. - Dynamic Code Analysis: Provides a comprehensive 360-degree assessment of code status, enabling precise planning for upgrades or migrations by identifying automated, semi-automated, and manual processes. - Legacy Code Reengineering and Re-Architecting: Analyzes and restructures existing Oracle Forms code to preserve technical investments, reduce development time and costs, and mitigate risks associated with outdated software. - Code Documentation: Generates thorough documentation of software code and processes, mitigating risks linked to unsupported systems and personnel changes, and offering clear insights into software operations. - Business Logic Extraction: Extracts and preserves existing code to facilitate its reuse in alignment with new business objectives, supporting the development of modern, future-proof applications. Primary Value and Problem Solved: PITSS.CON addresses the challenges associated with maintaining and modernizing legacy Oracle Forms and Reports applications. By delivering comprehensive analysis, efficient code reengineering, and detailed documentation, it empowers organizations to: - Reduce Project Costs: By streamlining the modernization process, organizations can achieve significant cost savings. - Decrease Development Time: Automated tools and clear insights expedite development timelines. - Lower Overall Risk: Thorough analysis and documentation minimize uncertainties and potential issues during modernization projects. Ultimately, PITSS.CON ensures that legacy applications are transformed into efficient, scalable, and maintainable systems that align with contemporary business requirements.

#### Who Is the Company Behind PITSS.CON?

- **Seller:** [PITSS](https://www.g2.com/sellers/pitss)
- **Year Founded:** 2014
- **HQ Location:** Bangalore, IN
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fac91930c7cf434cf1d9a7d903e65dcf18b28e42580a20b3d717d30b13a3e608&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpisignage%2F&secure%5Burl_type%5D=linkedin_company_website)  
7 employees on LinkedIn®

### [prelint](https://www.g2.com/products/prelint/reviews)

It’s a non-negotiable that shipped code matches product specs, not just that it passes code review. When AI agents move autonomously and fast, code drifts from specs, business rules, and compliance expectations. That drift shows up as rework, missed deadlines, and features that technically work, but break how the product should behave. prelint reduces that drift. It synthesises your specs, tickets, emails, call transcripts, and meeting notes into a product knowledge graph and checks every pull request against those decisions before it merges, so you see which changes quietly contradict the spec while there is still time to adjust. You spend less time re‑opening tickets, fixing last minute issues, or rolling back work that should never have shipped. Not another tool in your tech stack: your team keeps its current GitHub‑based workflow and documents the expected behaviour where it already exists. prelint turns those decisions into checks that run with your existing pipeline and review flow. Leaders keep control over what is allowed to ship without adding more meetings. Developers and agents keep moving at the speed the business expects, inside clear boundaries that protect the product and your compliance workflows.

#### Who Is the Company Behind prelint?

- **Seller:** [Prelint](https://www.g2.com/sellers/prelint)
- **Year Founded:** 2025
- **HQ Location:** San Francisco, CA
- **Twitter:** @prelint\_ai  
33 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9cde791ba959e9d63182453363959fafdd6d2817dc7999313391d898dba74fda&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fprelint%2F&secure%5Burl_type%5D=linkedin_company_website)  
5 employees on LinkedIn®

### [PrivJs Safe](https://www.g2.com/products/privjs-safe/reviews)

PrivJs Safe blocks the installation of malicious npm packages and provides with an ESLint plugin to detect vulnerable dependencies in a project.

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate PrivJs Safe?

- **Ease of Use:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind PrivJs Safe?

- **Seller:** [PrivJs](https://www.g2.com/sellers/privjs)
- **HQ Location:** Tallinn, EE
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8fbded22f81d73bf454a2b94e1f2c5d987b57ce45306816744bc3cc8aba84c40&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fprivjs%2F%3ForiginalSubdomain%3Dee&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Large

#### What Are Recent G2 Reviews of PrivJs Safe?

**["Gorgeous product"](https://www.g2.com/survey_responses/privjs-safe-review-8734911)**

**Rating:** 5.0/5.0 stars

_— Rajkumar y._

[Read full review](https://www.g2.com/survey_responses/privjs-safe-review-8734911)

### [Quality Clouds AI Code Governance](https://www.g2.com/products/quality-clouds-ai-code-governance/reviews)

Quality Clouds is an AI Code Governance platform that makes AI-generated code production-ready. As enterprises adopt AI coding assistants and agentic platforms — from ServiceNow Now Assist and Salesforce Agentforce to tools like Cursor, Lovable, Replit, and Claude Code — Quality Clouds scans what they produce before it reaches production, catching configuration drift, security risks, technical debt, and compliance violations across dev, test, and UAT environments. The platform provides a single governance layer that works across multiple enterprise platforms. Rather than relying on post-deployment monitoring, Quality Clouds operates upstream — analysing AI-generated code, configurations, and agent logic in pre-production to ensure they meet organisational standards before go-live. LivecheckAI, the platform's core engine, continuously evaluates code against hundreds of best-practice rules and provides guided remediation so teams can fix issues before they become incidents. Quality Clouds is purpose-built for enterprises in regulated industries — financial services, energy, healthcare, retail, and the public sector — where the speed of AI-generated code must be matched by rigorous governance. The platform is used by global organisations including Barclays, Shell, Nestlé, BP, and Sainsbury's to govern their most critical business platforms at scale.

#### Who Is the Company Behind Quality Clouds AI Code Governance?

- **Seller:** [Quality Clouds Ltd](https://www.g2.com/sellers/quality-clouds-ltd)
- **Year Founded:** 2015
- **HQ Location:** London, England
- **Twitter:** @QualityClouds  
410 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=25cfde717e058a1feadfb0e47da97b3745096e3caca157e2b1da1201b99c7159&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fqualityclouds%2Fabout&secure%5Burl_type%5D=linkedin_company_website)  
47 employees on LinkedIn®

### [Quality Clouds for Salesforce](https://www.g2.com/products/quality-clouds-for-salesforce/reviews)

Quality Clouds embeds governance and best practices into your Salesforce development workflow to build and release functionality quickly, securely, and with greater reliability, enabling your business to innovate and thrive. DevOps Excellence Quality Clouds helps redefine your development workflow, introducing best practices to the heart of the Salesforce platform build, and ensuring consistency across your development team. We restore lost agility, and streamline efficiency, liberating your developers from time-consuming manual checks to focus on what matters most. Continuous Active Governance Quality Clouds empowers your business with efficient, cost-effective solutions that accelerate the performance of your Salesforce platform. We equip you with full control and oversight of your platform, with a full suite of tools to prevent technical debt and other costly performance issues. Risk & Compliance​ Quality Clouds is committed to addressing your platform security concerns, offering solutions that effortlessly adapt to new regulations, future-proof your operations, and enhance compliance.

#### Who Is the Company Behind Quality Clouds for Salesforce?

- **Seller:** [Quality Clouds Ltd](https://www.g2.com/sellers/quality-clouds-ltd)
- **Year Founded:** 2015
- **HQ Location:** London, England
- **Twitter:** @QualityClouds  
410 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=25cfde717e058a1feadfb0e47da97b3745096e3caca157e2b1da1201b99c7159&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fqualityclouds%2Fabout&secure%5Burl_type%5D=linkedin_company_website)  
47 employees on LinkedIn®

### [RIPS](https://www.g2.com/products/rips/reviews)

RIPS is a tool written in PHP to find vulnerabilities in PHP applications using static code analysis.

#### Who Is the Company Behind RIPS?

- **Seller:** [RIPS Technologies](https://www.g2.com/sellers/rips-technologies-9dd80c95-3cb3-4465-bd48-26b3d0c20a57)
- **Year Founded:** 2008
- **HQ Location:** Vernier, Geneva, Switzerland
- **Twitter:** @ripstech  
19 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
827 employees on LinkedIn®

### [RIPS PHP Analyser](https://www.g2.com/products/rips-php-analyser/reviews)

RIPS is the code analysis solution dedicated to the PHP language. It supports all major PHP frameworks, SDLC integration, relevant industry standards and can be deployed as a self-hosted software or used as a cloud service.

#### Who Is the Company Behind RIPS PHP Analyser?

- **Seller:** [RIPS Technologies](https://www.g2.com/sellers/rips-technologies-9dd80c95-3cb3-4465-bd48-26b3d0c20a57)
- **Year Founded:** 2008
- **HQ Location:** Vernier, Geneva, Switzerland
- **Twitter:** @ripstech  
19 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
827 employees on LinkedIn®

### [RIPS Static Code Analysis](https://www.g2.com/products/rips-static-code-analysis/reviews)

RIPS Static Code Analysis is a PCI compliance software that detects the most complex security vulnerabilities deeply nested within the PHP code that no other tools are able to find.

#### Who Is the Company Behind RIPS Static Code Analysis?

- **Seller:** [RIPS Technologies](https://www.g2.com/sellers/rips-technologies-9dd80c95-3cb3-4465-bd48-26b3d0c20a57)
- **Year Founded:** 2008
- **HQ Location:** Vernier, Geneva, Switzerland
- **Twitter:** @ripstech  
19 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
827 employees on LinkedIn®

### [Semgrep Supply Chain](https://www.g2.com/products/semgrep-supply-chain/reviews)

Semgrep Supply Chain is a software composition analysis (SCA) tool designed to identify and remediate security vulnerabilities introduced by open-source dependencies within your codebase. By leveraging high-signal rules and reachability analysis, it effectively filters out false positives, allowing development teams to focus on the most critical and actionable issues.

#### Who Is the Company Behind Semgrep Supply Chain?

- **Seller:** [Semgrep](https://www.g2.com/sellers/semgrep)
- **Year Founded:** 2017
- **HQ Location:** San Francisco, US
- **Twitter:** @semgrep  
4,433 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=968a71f2060531e986a3873882c34b492bee4d8d264ff88e0089e53b8f7771f4&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freturntocorp&secure%5Burl_type%5D=linkedin_company_website)  
262 employees on LinkedIn®

- [&lsaquo; Prev ‹ Prev](/categories/static-code-analysis?order=g2_score&page=7&selected_view=grid#product-list)
- [1](/categories/static-code-analysis?order=g2_score&selected_view=grid#product-list)
- [2](/categories/static-code-analysis?order=g2_score&page=2&selected_view=grid#product-list)
- …
- [4](/categories/static-code-analysis?order=g2_score&page=4&selected_view=grid#product-list)
- [5](/categories/static-code-analysis?order=g2_score&page=5&selected_view=grid#product-list)
- [6](/categories/static-code-analysis?order=g2_score&page=6&selected_view=grid#product-list)
- [7](/categories/static-code-analysis?order=g2_score&page=7&selected_view=grid#product-list)
- 8
- [9](/categories/static-code-analysis?order=g2_score&page=9&selected_view=grid#product-list)
- [Next &rsaquo; Next ›](/categories/static-code-analysis?order=g2_score&page=9&selected_view=grid#product-list)

Spotlight Categories

[Relational Databases](https://www.g2.com/categories/relational-databases)

[Background Check Software](https://www.g2.com/categories/background-check)

[Procure to Pay Software](https://www.g2.com/categories/procure-to-pay)

[Workforce Management Software](https://www.g2.com/categories/workforce-management)

[SMS Marketing Software](https://www.g2.com/categories/sms-marketing)

Similar Categories

- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)
- [Log Analysis](/categories/log-analysis)

- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Static Code Analysis Themes](/categories/static-code-analysis/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated October 3, 2024

Static code analysis is the analysis of computer software performed without actually executing the code. Static code analysis tools scan all code in a project and seek out vulnerabilities, validates code against industry best practices, and some software tools validate against company-specific project specifications. Static code analysis tools are used by software development and quality assurance teams to ensure the quality and security of code, and that project requirements are met. Static code analysis is a type of source code management and can integrate with version control systems and through build automation tasks using continuous integration software.

To qualify as a static code analysis tool, a product must:

- Scan code without executing that code
- List security vulnerabilities after scanning
- Validate code against industry best practices
- Provide recommendations on where and how to fix issues

Show More