# Best Static Code Analysis Tools

## How Many Static Code Analysis Tools Products Does G2 Track?

**Total Products under this Category:** 139

### Category Stats (Aug 2026)

- **Average Rating:** 4.38/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** TASKING Test & Verification Tools (+10.99%) - Among all products in this category, TASKING Test & Verification Tools recorded the largest rating increase compared to last month

_Last updated: August 19, 2026_

## How Does G2 Rank Static Code Analysis Tools Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 2,200+ Authentic Reviews
- 139+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Static Code Analysis Tools
 ![G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence](https://www.g2.com/categories/static-code-analysis/grids.png?focus%5B%5D=7775&focus%5B%5D=102905&focus%5B%5D=4475&focus%5B%5D=1385185&focus%5B%5D=1225549&focus%5B%5D=161987&focus%5B%5D=48275&focus%5B%5D=1225688)

Highlighted products: SonarQube, Gearset DevOps, Checkmarx, SoftSpell, Semgrep, CAST Imaging, ReSharper C++, and Typo.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=checkmarx&focus%5B%5D=softspell&focus%5B%5D=semgrep&focus%5B%5D=cast-imaging&focus%5B%5D=resharper-c&focus%5B%5D=typo)

**Sponsored**

### Endor Labs

Endor Labs turns application security into a competitive advantage. At the core is AURI, the security harness for agentic development. It helps coding agents write secure code by default, automates PR security reviews, and gives agents deterministic context to fix what matters fast. At the core is our patented code context graph: a continuously updated model of application behavior across code, dependencies, secrets, and containers. The result: 83% fewer blocked PRs, 10x fewer security tickets, and 6x faster remediation at Atlassian, Cursor, Rubrik, and Snowflake.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=564&secure%5Bchosen_at%5D=2026-08-23T00%3A44%3A11Z&secure%5Bdisplayable_resource_id%5D=2041&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=1520&secure%5Bplacement_resource_ids%5D%5B%5D=2041&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1317430&secure%5Bresource_id%5D=564&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fstatic-code-analysis&secure%5Btoken%5D=37aa5c38f6cbd8f2326b9d786a06d06d83cb18fe08f4b723c0e3206b4f432285&secure%5Burl%5D=https%3A%2F%2Fwww.endorlabs.com%2Fplatform%3Futm_source%3Dg2%26utm_medium%3Ddisplay%26utm_campaign%3Dg2-ad&secure%5Burl_type%5D=custom_url)

### [SonarQube](https://www.g2.com/products/sonarqube/reviews)

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 153

#### How Do G2 Users Rate SonarQube?

- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind SonarQube?

- **Seller:** [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)
- **Company Website:** www.sonarsource.com
- **Year Founded:** 2008
- **HQ Location:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** DevOps Engineer, Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 42% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Users value SonarQube for its ability to quickly flag **code quality and security issues** , ensuring a reliable codebase.
- Users value the **flexible issue filtering and prioritization** features of SonarQube, enhancing team productivity and focus.
- Users appreciate how SonarQube quickly **flags code quality and security issues** , ensuring a clean and reliable codebase.
- Users appreciate the **ease of use** of SonarQube, finding integration and actionable feedback simple and effective.
- Users appreciate the **easy integrations** with CI/CD tools, enhancing their workflow and improving code quality effectively.

##### Cons

- Users face **software bugs** that lead to false positives, complicating the experience and requiring significant knowledge to manage.
- Users encounter **false positives** that complicate usage, despite helpful tools for review and customization of analysis.
- Users find the **complex configuration** of SonarQube challenging, especially for beginners needing extensive knowledge.
- Users find SonarQube's **complexity** in configuration and excessive warnings can make it cumbersome to use.
- Users find SonarQube's **limited features** frustrating, particularly with restrictions on scanning and analysis capabilities.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube: Easy Integration, Simple UI, and Solid Free Code Quality Scanning"](https://www.g2.com/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-12975264)

**["SonarQube Catches Issues Early with Clear, Actionable Reports"](https://www.g2.com/survey_responses/sonarqube-review-13204491)**

**Rating:** 4.0/5.0 stars

_— Kewin M._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-13204491)

#### What Are G2 Users Discussing About SonarQube?

- [What is SonarLint used for?](https://www.g2.com/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)

### [Gearset DevOps](https://www.g2.com/products/gearset-devops/reviews)

Gearset is the global leader in Salesforce DevOps. It’s a DevOps platform that helps organizations manage, automate, and govern the full Salesforce development lifecycle, from planning and deployment to testing, data management, and compliance. The platform is designed for Salesforce teams that need reliable, scalable DevOps processes across complex org environments. Gearset is used by mid-market and enterprise organizations across regulated and non-regulated industries, including healthcare, financial services, insurance, and technology. Typical users include Salesforce administrators, developers, DevOps engineers, release managers, and platform owners responsible for maintaining deployment quality, security, and operational consistency. The platform supports a wide range of Salesforce use cases, including metadata and CPQ deployments, CI/CD automation, code review workflows, sandbox seeding, test automation, and monitoring. As well as deployment automation, Gearset includes tools for Salesforce data protection and long-term data management, such as automated backups, data restore, and archiving. Observability and Org Intelligence features provide insight into org health, deployment risk, and system changes over time. Gearset also includes governance and compliance capabilities designed for enterprise environments. These features help teams maintain audit readiness and enforce access controls while supporting compliance frameworks such as SOX, ISO, HIPAA, and GDPR. The platform is delivered as a managed service and integrates with Salesforce environments without requiring complex local infrastructure. Key features and capabilities include: - Salesforce metadata, CPQ, and data deployments with CI/CD automation and version control integration - Code review, test automation, and release validation to support quality and consistency - Automated Salesforce backups, restore, and data archiving for data protection and retention - Sandbox seeding, observability, and Org Intelligence to support environment management and visibility - Governance features including audit trails, role-based access controls, and compliance support Gearset is a Salesforce Partner and has supported Salesforce teams globally since 2015. The platform is used by organizations managing multiple orgs (across regions), frequent releases, and complex compliance requirements, helping teams reduce deployment risk, improve operational visibility, and maintain control over Salesforce change management processes.

**Average Rating:** 4.7/5.0

**Total Reviews:** 304

#### How Do G2 Users Rate Gearset DevOps?

- **Has the product been a good partner in doing business?:** 9.5/10 (Category avg: 8.7/10)
- **Ease of Admin:** 9.3/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Gearset DevOps?

- **Seller:** [Gearset](https://www.g2.com/sellers/gearset)
- **Company Website:** www.gearset.com
- **Year Founded:** 2015
- **HQ Location:** Cambridge, Cambridgeshire
- **Twitter:** @GearsetHQ  
1,182 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=cb0a1d1a51dafae67aaf930cdb09c5683dea58d96c6c97e17a838b129a1f7c7a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F10478150%2F&secure%5Burl_type%5D=linkedin_company_website)  
369 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Salesforce Developer, Salesforce Administrator
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 37% Medium, 33% Small

#### What Do G2 Reviewers Say About Gearset DevOps?

_AI-generated summary from verified user reviews_

##### Pros

- Users praise the **ease of use** of Gearset DevOps, highlighting smooth setup and effective features for efficient deployments.
- Users value the **automation and ease of deployment** with Gearset, significantly enhancing efficiency and reducing errors.
- Users appreciate the **easy deployment** capabilities of Gearset DevOps, which streamline CI/CD processes and validations effortlessly.
- Users commend the **exceptional customer support** from Gearset DevOps, highlighting prompt assistance and engagement with feature requests.
- Users value the **deployment ease** of Gearset DevOps, enabling swift setup and efficient management of releases.

##### Cons

- Users face **deployment issues** requiring manual activation of Flows and cautious management of production metadata changes.
- Users find Gearset DevOps **expensive** , particularly for larger teams, affecting its accessibility despite its high quality.
- Users find **complexity in custom filters and CI/CD processes** , wishing for enhanced automation and streamlined operations.
- Users face **limitations in data management** , as some metadata and object settings fail to transfer accurately between environments.
- Users express disappointment over the **missing features** in Gearset DevOps, particularly the lack of automated dependency tracking.

#### What Are Recent G2 Reviews of Gearset DevOps?

**["Rollbacks, Conflict Resolution, and Precise Deployments That Elevate CI/CD"](https://www.g2.com/survey_responses/gearset-devops-review-13189639)**

**Rating:** 4.5/5.0 stars

_— Chris P._

[Read full review](https://www.g2.com/survey_responses/gearset-devops-review-13189639)

**["Powerful Salesforce DevOps That Makes Every Release Easier"](https://www.g2.com/survey_responses/gearset-devops-review-13031923)**

**Rating:** 5.0/5.0 stars

_— Paul B._

[Read full review](https://www.g2.com/survey_responses/gearset-devops-review-13031923)

### [Checkmarx](https://www.g2.com/products/checkmarx/reviews)

Checkmarx is a type of application security solution designed to help organizations safeguard their software development processes while enhancing efficiency and reducing costs. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. With the increasing reliance on AI technologies and the rapid pace of software development, Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as AI SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

**Average Rating:** 4.2/5.0

**Total Reviews:** 44

#### How Do G2 Users Rate Checkmarx?

- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.2/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Checkmarx?

- **Seller:** [Checkmarx](https://www.g2.com/sellers/checkmarx)
- **Company Website:** www.checkmarx.com
- **Year Founded:** 2006
- **HQ Location:** Paramus, NJ
- **Twitter:** @Checkmarx  
7,284 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=18f6741e77df71b112ecb3ec6620912d3a0f67666525358c0a4f3b1278b173df&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheckmarx&secure%5Burl_type%5D=linkedin_company_website)  
1,019 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 56% Large, 23% Medium

#### What Do G2 Reviewers Say About Checkmarx?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **easy implementation** of Checkmarx into existing repositories, enhancing their security review processes effortlessly.
- Users praise the **intuitive user interface** of Checkmarx, making security reviews and integrations straightforward and user-friendly.
- Users value the **accuracy of results** in Checkmarx, finding it effective for automated security reviews.
- Users appreciate the **automation testing** capabilities of Checkmarx, making security reviews efficient and user-friendly.
- Users praise the **responsive customer support** of Checkmarx, consistently providing help when challenges arise.

##### Cons

- Users experience a significant number of **false positives** with Checkmarx, particularly for Kotlin projects, leading to frustration.
- Users face challenges with **limited support for Kotlin** , experiencing many false positives compared to other languages like Java or Javascript.
- Users experience **missing features** in Checkmarx, particularly with Kotlin support, leading to numerous false positives.
- Users find the **navigation poor** in Checkmarx, citing issues with dashboard layout and display clarity.

#### What Are Recent G2 Reviews of Checkmarx?

**["Automated Checkmarx Scans Keep Us Ahead of Key Vulnerabilities"](https://www.g2.com/survey_responses/checkmarx-review-12983770)**

**Rating:** 4.5/5.0 stars

_— Nitesh A._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12983770)

**["Centralized Source Code Security with Seamless CI/CD Integration"](https://www.g2.com/survey_responses/checkmarx-review-12980590)**

**Rating:** 5.0/5.0 stars

_— Aman M._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12980590)

#### What Are G2 Users Discussing About Checkmarx?

- [What is Checkmarx used for?](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for) - 1 comment, 1 upvote
- [How much does Checkmarx cost?](https://www.g2.com/discussions/how-much-does-checkmarx-cost)
- [Which testing method does Checkmarx support?](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support) - 1 comment
- [Does Checkmarx support DAST?](https://www.g2.com/discussions/does-checkmarx-support-dast) - 1 comment
- [What is Checkmarx used for?](https://www.g2.com/discussions/what-is-checkmarx-used-for) - 2 comments

### [Semgrep](https://www.g2.com/products/semgrep/reviews)

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

**Average Rating:** 4.6/5.0

**Total Reviews:** 56

#### How Do G2 Users Rate Semgrep?

- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 8.7/10)
- **Ease of Admin:** 9.1/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Semgrep?

- **Seller:** [Semgrep](https://www.g2.com/sellers/semgrep)
- **Year Founded:** 2017
- **HQ Location:** San Francisco, US
- **Twitter:** @semgrep  
4,433 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=968a71f2060531e986a3873882c34b492bee4d8d264ff88e0089e53b8f7771f4&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freturntocorp&secure%5Burl_type%5D=linkedin_company_website)  
262 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 45% Large, 43% Medium

#### What Do G2 Reviewers Say About Semgrep?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Semgrep, enabled by its intuitive syntax and smooth integration with CI/CD.
- Users appreciate the **flexibility and speed** of Semgrep in enforcing coding standards and catching vulnerabilities effectively.
- Users appreciate the **effective vulnerability detection** of Semgrep, facilitating quick identification and resolution of security issues.
- Users appreciate the **scanning efficiency** of Semgrep, benefiting from rapid scans and streamlined CI/CD integration.
- Users value Semgrep for its **effective security vulnerability detection** , enabling quick resolutions without hindering development speed.

##### Cons

- Users find Semgrep **not user-friendly** due to a steep learning curve and complex initial setup requirements.
- Users find the **limited features** of Semgrep restrict its usability and complicate effective vulnerability management.
- Users find the **difficult learning** curve for Semgrep daunting, especially for creating advanced rules and setups.
- Users express concerns about the **lack of guidance** in creating custom rules, complicating effective use of Semgrep.
- Users note a **steep learning curve** for Semgrep's rule syntax, making it challenging for newcomers to master.

#### What Are Recent G2 Reviews of Semgrep?

**["Fast, Easy-to-Customize Rules That Catch Security and Code-Quality Issues Early"](https://www.g2.com/survey_responses/semgrep-review-13079252)**

**Rating:** 4.5/5.0 stars

_— Milan K._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-13079252)

**["Streamlined Code Security with Semgrep"](https://www.g2.com/survey_responses/semgrep-review-11971635)**

**Rating:** 5.0/5.0 stars

_— Shreekanth k._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-11971635)

### [SoftSpell](https://www.g2.com/products/softspell/reviews)

SoftSpell is an AI-powered platform that accelerates software delivery and simplifies legacy modernization. It transforms unstructured requirements and existing codebases into structured outputs, enabling faster development with clarity and control. By combining intelligent requirement analysis, context-aware code generation, and automated testing, it ensures end-to-end traceability while reducing manual effort and rework. SoftSpell integrates seamlessly into existing workflows, helping teams deliver high-quality software faster.

**Average Rating:** 4.5/5.0

**Total Reviews:** 40

#### How Do G2 Users Rate SoftSpell?

- **Has the product been a good partner in doing business?:** 7.9/10 (Category avg: 8.7/10)
- **Ease of Admin:** 7.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.2/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 0.0/10 (Category avg: 10/10)

#### Who Is the Company Behind SoftSpell?

- **Seller:** [Aspire Systems](https://www.g2.com/sellers/aspire-systems-2026-08-03)
- **Year Founded:** 1996
- **HQ Location:** Chennai, IN
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9107d3257da97f6860000e95c23206076736660cd145b9fc58ebc9245c285ddc&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faspire-systems&secure%5Burl_type%5D=linkedin_company_website)  
5,175 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Senior Software Engineer
- **Top Industries:** Computer Software, Program Development
- **Company Size:** 46% Large, 37% Small

#### What Do G2 Reviewers Say About SoftSpell?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **time-saving capabilities** of SoftSpell, making coding faster and enhancing overall productivity.
- Users appreciate the **coding assistance** from SoftSpell, enhancing quality and speeding up the programming process effortlessly.
- Users value the **automation features** of SoftSpell, significantly enhancing productivity and simplifying the development process.
- Users praise the **significant improvement in code quality** that SoftSpell provides, enhancing productivity and development speed.
- Users appreciate the **ease of use** of SoftSpell, enhancing their coding experience and simplifying problem-solving.

##### Cons

- Users experience **slow performance** with SoftSpell, leading to delays and frustrating interruptions during use.
- Users experience **prompt issues** with SoftSpell, citing delays and outdated solutions during usage, impacting their workflow.
- Users express concerns about **limited multimedia support** , hoping future updates will enhance compatibility with tech stacks.
- Users find the **cluttered interface** of SoftSpell challenging, leading to mistakes and requiring manual adjustments.
- Users face **limitations with browser compatibility** , hoping updates will improve functionality in the future.

#### What Are Recent G2 Reviews of SoftSpell?

**["Streamlined Development with AI-Powered Efficiency"](https://www.g2.com/survey_responses/softspell-review-13193911)**

**Rating:** 4.0/5.0 stars

_— Jeni J._

[Read full review](https://www.g2.com/survey_responses/softspell-review-13193911)

**["SoftSpell Streamlines the Entire SDLC with Seamless IDE Integration"](https://www.g2.com/survey_responses/softspell-review-13251816)**

**Rating:** 4.5/5.0 stars

_— Atharva S._

[Read full review](https://www.g2.com/survey_responses/softspell-review-13251816)

### [CAST Imaging](https://www.g2.com/products/cast-imaging/reviews)

CAST Imaging helps software architects and AI agents understand, change, and modernize applications. It automatically reverse-engineers all database structures, code components, and interdependencies in any custom-built applications. CAST Imaging deterministically maps the entire system – architecture, dependencies, data access, and tech debt. It provides interactive and accurate architecture blueprints, zoomable to the tiniest details. as well as data call graphs and end-to-end transaction views. All this in a lightweight web UI with the ability for teams to collaborate by adding their own knowledge and sharing insights. A built-in MCP server streams this precise application architectural context to AI agents which can generate consistent, accurate, and safe code changes. Businesses move faster using CAST technology to understand, improve, and transform their software. Through semantic analysis of source code, CAST produces 3D maps and dashboards to navigate inside individual applications and across entire portfolios. This intelligence empowers executives and technology leaders to steer, speed, and report on initiatives such as technical debt, GenAI, modernization, and cloud. As the pioneer of the software intelligence field, CAST is trusted by the world’s leading companies and governments, their consultancies and cloud providers. See it all at castsoftware.com.

**Average Rating:** 4.6/5.0

**Total Reviews:** 36

#### How Do G2 Users Rate CAST Imaging?

- **Has the product been a good partner in doing business?:** 8.4/10 (Category avg: 8.7/10)
- **Ease of Admin:** 7.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.2/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind CAST Imaging?

- **Seller:** [CAST](https://www.g2.com/sellers/cast)
- **Company Website:** www.castsoftware.com
- **Year Founded:** 1990
- **HQ Location:** New York
- **Twitter:** @SW\_Intelligence  
1,887 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0ce2f19bfa683d9d06fc56898a1568de05de4c4332e22f1fb046292c65ff44c9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcast%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,264 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 53% Large, 28% Small

#### What Are Recent G2 Reviews of CAST Imaging?

**["Engineering Dashboard Boosts Code Quality"](https://www.g2.com/survey_responses/cast-imaging-review-13075743)**

**Rating:** 4.5/5.0 stars

_— Vinsensius Samuel H._

[Read full review](https://www.g2.com/survey_responses/cast-imaging-review-13075743)

**["CAST Imaging Turns Complex Apps into an Intuitive, High-Performance Visual Map"](https://www.g2.com/survey_responses/cast-imaging-review-13101049)**

**Rating:** 4.0/5.0 stars

_— Verified User in Maritime_

[Read full review](https://www.g2.com/survey_responses/cast-imaging-review-13101049)

#### What Are G2 Users Discussing About CAST Imaging?

- [What is CAST Imaging used for?](https://www.g2.com/discussions/what-is-cast-imaging-used-for) - 1 comment, 1 upvote

### [ReSharper C++](https://www.g2.com/products/resharper-c/reviews)

ReSharper C++ is a productivity extension for developing in C and C++ that fully integrates with Microsoft Visual Studio. It helps developers create efficient and correct code in modern C++ by providing safe refactorings, fast navigation, and code analysis for the trickiest aspects of the language. It also offers support for HLSL shaders, the C++/CLI specifications, and Unreal Engine code.

**Average Rating:** 4.6/5.0

**Total Reviews:** 20

#### How Do G2 Users Rate ReSharper C++?

- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 8.7/10)
- **Ease of Admin:** 7.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.6/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 3.3/10 (Category avg: 10/10)

#### Who Is the Company Behind ReSharper C++?

- **Seller:** [JetBrains](https://www.g2.com/sellers/jetbrains)
- **Year Founded:** 2000
- **HQ Location:** Prague
- **Twitter:** @jetbrains  
213,126 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=38aa98843aee51e51c2eda5cdc7b29c3e6a7d48f3897c88088b0af7cfcb6f37d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F12515%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,941 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 55% Small, 35% Large

#### What Are Recent G2 Reviews of ReSharper C++?

**["Detects Every Syntax Error with Consistent, Proper Indentation"](https://www.g2.com/survey_responses/resharper-c-review-13051310)**

**Rating:** 5.0/5.0 stars

_— Megh D._

[Read full review](https://www.g2.com/survey_responses/resharper-c-review-13051310)

**["Insightful AI Coding Features Make It Perfect"](https://www.g2.com/survey_responses/resharper-c-review-12205837)**

**Rating:** 5.0/5.0 stars

_— Antawn S._

[Read full review](https://www.g2.com/survey_responses/resharper-c-review-12205837)

#### What Are G2 Users Discussing About ReSharper C++?

- [What is ReSharper C++ used for?](https://www.g2.com/discussions/what-is-resharper-c-used-for)

### [Typo](https://www.g2.com/products/typo/reviews)

Typo is an AI-powered software engineering intelligence platform that gives engineering leaders real-time visibility into what's actually happening across their SDLC — and what to do about it. From a single platform, engineering teams can track DORA metrics and delivery health, measure the real impact of AI coding tools like Cursor, and Claude Code, run AI code reviews on every pull request, monitor R&D investment allocation, and measure developer experience through anonymous surveys. Typo connects to your existing stack — GitHub, GitLab, Bitbucket, Jira, Linear, and CI/CD tools — in 60 seconds. No complex onboarding. Used by 1,000+ engineering teams globally. 15M+ pull requests processed. Featured in Gartner's Market Guide for Software Engineering Intelligence Platforms.

**Average Rating:** 4.6/5.0

**Total Reviews:** 150

#### How Do G2 Users Rate Typo?

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.8/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.9/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 9.8/10 (Category avg: 10/10)

#### Who Is the Company Behind Typo?

- **Seller:** [Typo](https://www.g2.com/sellers/typo)
- **Year Founded:** 2020
- **HQ Location:** Dover, US
- **Twitter:** @Typoapp\_  
66 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=978e78e847141b121898277ce3abdd8408cbb9980ccb16a9d6d1e94c082a6d06&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftypoapp%2Fabout%2F&secure%5Burl_type%5D=linkedin_company_website)  
76 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 47% Medium, 43% Small

#### What Do G2 Reviewers Say About Typo?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **insightful productivity metrics** of Typo, enhancing team performance and streamlining workflows effectively.
- Users value the **easy-to-use metrics analysis** in Typo, enabling quick learning and effective team performance tracking.
- Users appreciate the **powerful AI-driven features** of Typo for managing productivity and improving code quality effortlessly.
- Users value the **clear, actionable insights** from Typo that enhance team performance and improve code quality efficiently.
- Users value Typo for its **highly valid recommendations** that enhance code readability and simplify review processes.

##### Cons

- Users find the **complex configuration** process frustrating, especially during onboarding and due to quality issues.
- Users note the **limited features** of Typo, particularly in customization and mobile access, impacting usability for diverse teams.
- Users find it challenging to grasp **metrics issues** due to unclear thresholds and lack of customizable dashboards.
- Users express concerns about the **lack of customization and mobile app functionality** , limiting effectiveness for their unique workflows.
- Users experience significant **performance issues** with Typo, including slow scanning and struggles with large pull requests.

#### What Are Recent G2 Reviews of Typo?

**["Outstanding Metrics and Insights for Code Quality"](https://www.g2.com/survey_responses/typo-review-12104366)**

**Rating:** 4.0/5.0 stars

_— Amarjeet ._

[Read full review](https://www.g2.com/survey_responses/typo-review-12104366)

**["Intuitive Tool with Powerful Analytics and Seamless GitHub Integration"](https://www.g2.com/survey_responses/typo-review-12066335)**

**Rating:** 5.0/5.0 stars

_— Eduardo V._

[Read full review](https://www.g2.com/survey_responses/typo-review-12066335)

### [OpenText Static Application Security Testing](https://www.g2.com/products/opentext-static-application-security-testing/reviews)

OpenText™ Static Application Security Testing (SAST) is a comprehensive solution designed to identify and remediate security vulnerabilities within an application's source code during the early stages of development. By analyzing code from the "inside out," SAST provides immediate feedback to developers, enabling them to address security issues promptly and effectively. Key Features and Functionality: - Extensive Language Support: Supports over 33 programming languages and more than 1,400 vulnerability categories, ensuring broad applicability across various development environments. - Integration with Development Tools: Seamlessly integrates with popular Integrated Development Environments (IDEs) such as Eclipse, Visual Studio, and JetBrains, as well as Continuous Integration/Continuous Deployment (CI/CD) tools like Jenkins and Bamboo, facilitating a smooth incorporation into existing workflows. - Scalable Deployment Options: Offers flexible deployment models, including on-premises, cloud-based, and Software as a Service (SaaS) solutions, allowing organizations to choose the setup that best fits their needs. - Advanced Analysis Capabilities: Utilizes multiple algorithms and an expansive knowledge base of secure coding rules to perform thorough code analysis, pinpointing the root causes of vulnerabilities and providing detailed remediation guidance. Primary Value and Problem Solved: OpenText SAST empowers organizations to proactively manage application security by detecting and addressing vulnerabilities early in the Software Development Life Cycle (SDLC). This proactive approach reduces the risk of security breaches, minimizes the cost and effort associated with late-stage remediation, and enhances the overall security posture of applications. By integrating security testing into the development process, OpenText SAST helps developers create more secure code, leading to robust and reliable software products.

**Average Rating:** 4.5/5.0

**Total Reviews:** 21

#### How Do G2 Users Rate OpenText Static Application Security Testing?

- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.1/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.7/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind OpenText Static Application Security Testing?

- **Seller:** [OpenText](https://www.g2.com/sellers/opentext)
- **Year Founded:** 1991
- **HQ Location:** Waterloo, ON
- **Twitter:** @OpenText  
21,565 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c339a6555764b5ffce77c3df08d6ed9c9b1cb1ee1baeebac8435f0485b7cca5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2709%2F&secure%5Burl_type%5D=linkedin_company_website)  
23,048 employees on LinkedIn®
- **Ownership:** NASDAQ:OTEX

#### Who Uses This Product?

- **Top Industries:** Banking, Financial Services
- **Company Size:** 50% Large, 29% Small

#### What Do G2 Reviewers Say About OpenText Static Application Security Testing?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **easy integrations** of OpenText Static Application Security Testing, enhancing their workflow with multiple tools.
- Users value the **extensive integration capabilities** of OpenText Static Application Security Testing with various third-party tools.
- Users value the **extensive integration support** for various technologies and third-party tools offered by OpenText Static Application Security Testing.

##### Cons

- Users are disappointed by the **false positives** , but appreciate the ability to ignore issues in future scans.

#### What Are Recent G2 Reviews of OpenText Static Application Security Testing?

**["Fortify Static Code Analyzer (SCA)"](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-10770814)**

**Rating:** 4.0/5.0 stars

_— Lokesh T._

[Read full review](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-10770814)

**["Efficient and easy to use Code Analyzer"](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-7271508)**

**Rating:** 4.5/5.0 stars

_— Nav N._

[Read full review](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-7271508)

#### What Are G2 Users Discussing About OpenText Static Application Security Testing?

- [What is Fortify Static Code Analyzer used for?](https://www.g2.com/discussions/what-is-fortify-static-code-analyzer-used-for)
- [What tools does fortify include?](https://www.g2.com/discussions/what-tools-does-fortify-include)
- [What are the main components of Fortify?](https://www.g2.com/discussions/fortify-static-code-analyzer-what-are-the-main-components-of-fortify) - 1 comment
- [What is Fortify software used for?](https://www.g2.com/discussions/fortify-static-code-analyzer-what-is-fortify-software-used-for)
- [What is Micro Focus Fortify static code analyzer?](https://www.g2.com/discussions/what-is-micro-focus-fortify-static-code-analyzer)

### [CodeScene](https://www.g2.com/products/codescene/reviews)

CodeScene is a code analysis, visualization, and reporting tool. Cross reference contextual factors such as code quality, team dynamics, and delivery output to get actionable insights to effectively reduce technical debt and deliver better code quality. We enable software development teams to make confident, data-driven decisions that fuel performance and developer productivity. CodeScene guides developers and technical leaders to: - Get a holistic overview and evolution of your software system in one single dashboard. - Identify, prioritize, and tackle technical debt based on return on investment. - Maintain a healthy codebase with powerful CodeHealth™ Metrics, spend less time on rework and more time on innovation. - Seamlessly integrate with Pull Requests and editors, get actionable code reviews and refactoring recommendations. - Set Improvement goals and quality gates for teams to work towards while monitoring the progress. - Support retrospectives by identifying areas for improvement. - Benchmark performance against personalized trends. - Understand the social side of the code, measure socio-technical factors like key personnel dependencies, knowledge sharing and inter-team coordination. - Put findings into context based on how your organization and your code evolves. Supporting 28+ programming languages, CodeScene offers an automated integration with GitHub, BitBucket, Azure DevOps or GitLab pull requests to incorporate the analysis results into existing delivery workflows. Get early warnings and recommendations about complex code before merging it to the main branch, set quality gates to trigger in case your code health declines.

**Average Rating:** 4.6/5.0

**Total Reviews:** 39

#### How Do G2 Users Rate CodeScene?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.6/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.1/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind CodeScene?

- **Seller:** [CodeScene AB](https://www.g2.com/sellers/codescene-ab)
- **Company Website:** www.codescene.com
- **Year Founded:** 2015
- **HQ Location:** Malmö, SE
- **Twitter:** @codescene  
1,239 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=3cfa1c6a5137d85c0b88d5202f5784e459c44e0221ccaf8ee6bde39e2d0c2c4c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcodescene%2F&secure%5Burl_type%5D=linkedin_company_website)  
32 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 41% Medium, 36% Small

#### What Do G2 Reviewers Say About CodeScene?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **knowledge base and code health features** of CodeScene for improving team efficiency and code quality.
- Users find **issue identification** with CodeScene invaluable for enhancing team knowledge and improving code quality.
- Users value the **actionable insights** CodeScene provides, enhancing code quality and supporting informed decision-making in teams.
- Users commend the **fast and helpful customer support** of CodeScene, enhancing their overall experience and satisfaction.
- Users praise CodeScene for its **actionable insights** , improving code health and aiding informed decisions for development teams.

##### Cons

- Users struggle with **integration issues** , particularly with proxies and firewall configurations, complicating workflow adoption.
- Users find the **difficult learning curve** of CodeScene challenging due to advanced features and overwhelming terminology.
- Users find the **onboarding process challenging** , making it difficult for beginners to effectively utilize CodeScene's features.
- Users find the **learning difficulty** with CodeScene's advanced features and terminology challenging for newcomers.
- Users struggle with **difficult configuration** and lack of seamless integration, impacting adoption and daily workflow usage.

#### What Are Recent G2 Reviews of CodeScene?

**["CodeScene Delivers Smart, Actionable Insights Beyond Static Analysis"](https://www.g2.com/survey_responses/codescene-review-11658139)**

**Rating:** 4.5/5.0 stars

_— Saravana K._

[Read full review](https://www.g2.com/survey_responses/codescene-review-11658139)

**["Impactful code quality mesurements"](https://www.g2.com/survey_responses/codescene-review-11656380)**

**Rating:** 4.5/5.0 stars

_— Yossi Z._

[Read full review](https://www.g2.com/survey_responses/codescene-review-11656380)

### [Mend.io](https://www.g2.com/products/mend-io/reviews)

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

**Average Rating:** 4.3/5.0

**Total Reviews:** 119

#### How Do G2 Users Rate Mend.io?

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.3/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.4/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Mend.io?

- **Seller:** [Mend](https://www.g2.com/sellers/mend-ab79a83a-6747-4682-8072-a3c176489d0b)
- **Company Website:** mend.io
- **Year Founded:** 2011
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @Mend\_io  
11,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=041c6c79eefb0ef528e05bab57503847c90096672ecceb998f987d3daebef99a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2440656%2F&secure%5Burl_type%5D=linkedin_company_website)  
259 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 35% Small, 33% Large

#### What Do G2 Reviewers Say About Mend.io?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **scanning efficiency** of Mend.io, enabling quick and accurate scans across multiple repositories seamlessly.
- Users appreciate the **ease of use** of Mend.io, made simpler by effective integrations and an attractive interface.
- Users value the **easy integrations** of Mend.io, allowing seamless scanning across multiple repositories and CI/CD platforms.
- Users appreciate the **quick and accurate scanning** capabilities of Mend.io, benefiting from a range of integrations.
- Users value the **automated vulnerability detection** of Mend.io, enhancing efficiency in identifying and addressing issues seamlessly.

##### Cons

- Users face **integration issues** with Mend.io, finding it difficult to connect on-premise tools and features like Jira.
- Users express concern over **limited features** in Mend.io, necessitating workarounds for optimal functionality and integration.
- Users find the **missing features** in Mend.io cumbersome, often resorting to workarounds for integration and functionality.
- Users face **complex implementation** , with challenging integration and frequent false positives affecting their experience.
- Users find the **confusing interface** challenging due to the awkward transitions between different portals.

#### What Are Recent G2 Reviews of Mend.io?

**["Mend.io Makes Vulnerability Scanning and Prioritization Easy"](https://www.g2.com/survey_responses/mend-io-review-13187391)**

**Rating:** 4.5/5.0 stars

_— Ratna P._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-13187391)

**["Comprehensive AppSec Platform with Fast Scans and Clear Remediation Guidance"](https://www.g2.com/survey_responses/mend-io-review-13209300)**

**Rating:** 4.5/5.0 stars

_— Atharva S._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-13209300)

#### What Are G2 Users Discussing About Mend.io?

- [What is your experience regarding pricing and costs for Mend.io, and how does it compare to other open-source security solutions?](https://www.g2.com/discussions/what-is-your-experience-regarding-pricing-and-costs-for-mend-io-and-how-does-it-compare-to-other-open-source-security-solutions)
- [What is Mend (formerly WhiteSource) used for?](https://www.g2.com/discussions/what-is-mend-formerly-whitesource-used-for)
- [What is white Source bolt?](https://www.g2.com/discussions/what-is-white-source-bolt)
- [What are SCA tools?](https://www.g2.com/discussions/what-are-sca-tools)
- [What is software composition analysis SCA?](https://www.g2.com/discussions/what-is-software-composition-analysis-sca)

### [Kiuwan Code Security & Insights](https://www.g2.com/products/kiuwan-code-security-insights/reviews)

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

**Average Rating:** 4.5/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate Kiuwan Code Security & Insights?

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.7/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Kiuwan Code Security & Insights?

- **Seller:** [Sembi](https://www.g2.com/sellers/sembi)
- **Company Website:** www.sembi.com
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7ed5860a727a31b32edfba64808a6ea32fccad50d052e993a08b626d675d5c69&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsembi-inc%2F&secure%5Burl_type%5D=linkedin_company_website)  
94 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Banking
- **Company Size:** 41% Large, 35% Medium

#### What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **accuracy of the results** from Kiuwan Code Security & Insights, enhancing their overall experience.
- Users value the **accuracy of findings** from Kiuwan, enhancing their satisfaction with code security and reporting.
- Users commend the **efficient customer support** of Kiuwan, ensuring timely assistance and strong satisfaction overall.
- Users appreciate the **user-friendly interface** of Kiuwan Code Security & Insights, making it very easy to navigate.
- Users appreciate the **user-friendly interface** of Kiuwan Code Security & Insights, enhancing ease of use for dashboards.

#### What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

**["Impeccable Security and Code Analysis, with Potential for Improvement in Customization"](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)**

**Rating:** 5.0/5.0 stars

_— Abelardo I._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)

**["Elevated our software security to the next level. Improved our code quality."](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)**

**Rating:** 5.0/5.0 stars

_— Abdullah Enes K._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)

### [TASKING Test & Verification Tools](https://www.g2.com/products/tasking-test-verification-tools/reviews)

TASKING Test & Verification Tools combine software analysis, verification, and compliance capabilities for safety- and security-critical software development. Products: LDRA tool suite and LDRA Productivity Packages.

**Average Rating:** 4.6/5.0

**Total Reviews:** 20

#### How Do G2 Users Rate TASKING Test & Verification Tools?

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 8.7/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.7/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind TASKING Test & Verification Tools?

- **Seller:** [TASKING](https://www.g2.com/sellers/tasking)
- **Company Website:** www.tasking.com
- **Year Founded:** 1977
- **HQ Location:** Munich, Bavaria
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=4c26167a871628a4445d0de06e1ba544715d536a25638f92049057442da96563&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftasking-inc%2F&secure%5Burl_type%5D=linkedin_company_website)  
254 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 45% Large, 35% Medium

#### What Are Recent G2 Reviews of TASKING Test & Verification Tools?

**["Robust Coverage and MISRA Checking with Top-Notch ISO 26262 Support"](https://www.g2.com/survey_responses/tasking-test-verification-tools-review-13269651)**

**Rating:** 4.5/5.0 stars

_— Krish D._

[Read full review](https://www.g2.com/survey_responses/tasking-test-verification-tools-review-13269651)

**["Comprehensive, Automated Verification That Strengthens Safety and Compliance"](https://www.g2.com/survey_responses/tasking-test-verification-tools-review-13269567)**

**Rating:** 4.5/5.0 stars

_— Gaga H._

[Read full review](https://www.g2.com/survey_responses/tasking-test-verification-tools-review-13269567)

### [Codacy](https://www.g2.com/products/codacy/reviews)

Codacy is the code quality and security platform for AI-assisted engineering teams. AI is now embedded through the engineering workflow, which has made teams faster, but also adds risk to everything they ship. Codacy helps AI-assisted teams ship high-quality, secure code across the full software development lifecycle, starting in the agent and editor, through pull requests in Git, and into containers and runtime security. At each stage we check for quality issues, security vulnerabilities and AI coding risk introduced into the codebase, and help devs and agent fix them effortlessly. A team's standards become automated guardrails that apply across every IDE, AI coding agent, and Pull Request. More than 250,000 developers rely on Codacy to keep quality and security stable as AI changes how software gets built. Add your repo and get your free scan report in minutes: https://codacy.com

**Average Rating:** 4.6/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate Codacy?

- **Has the product been a good partner in doing business?:** 9.1/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.8/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Codacy?

- **Seller:** [Codacy](https://www.g2.com/sellers/codacy)
- **Year Founded:** 2012
- **HQ Location:** Lisbon, Lisboa
- **Twitter:** @codacy  
5,002 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=cfb2ce473f29d659861c3939070bb76f085fb14394ceeb1e11c4d3c449846d0f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F3310124%2F&secure%5Burl_type%5D=linkedin_company_website)  
69 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 59% Small, 24% Medium

#### What Do G2 Reviewers Say About Codacy?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **enhanced security features** of Codacy, benefiting from integrated automation and insightful vulnerability management.
- Users appreciate the **integrated automation** of Codacy, finding it easy to use and helpful for maintaining code quality.
- Users find the **out-of-the-box automation** in Codacy to be user-friendly and effective for maintaining code quality.
- Users value the **high code quality** provided by Codacy's integrated automation and effective static code analyses.
- Users value the **helpful customer support** of Codacy, appreciating their immediate assistance during integration and security management.

##### Cons

- Users find Codacy **expensive** at $19/month, which can be a barrier for smaller organizations.

#### What Are Recent G2 Reviews of Codacy?

**["Codacy is a security must-have tool in our company"](https://www.g2.com/survey_responses/codacy-review-10264506)**

**Rating:** 5.0/5.0 stars

_— David M._

[Read full review](https://www.g2.com/survey_responses/codacy-review-10264506)

**["Easy GitHub & CI/CD Integration That Catches Bugs Before Production"](https://www.g2.com/survey_responses/codacy-review-12739228)**

**Rating:** 4.5/5.0 stars

_— Arjun M._

[Read full review](https://www.g2.com/survey_responses/codacy-review-12739228)

### [Cyclopt Companion](https://www.g2.com/products/cyclopt-companion/reviews)

Cyclopt Companion is a code quality and security tool that helps developers ship secure, maintainable code with confidence, whether written by humans or AI. Built on the ISO 25010:2023 methodology, Companion analyzes every commit and flags coding violations, security vulnerabilities, code duplication, and maintainability issues in real time. You get instant feedback showing exactly how each commit changes your code quality, down to the precise file and line. Companion meets you where you already work. Connect the MCP Server to your AI coding assistant (Claude Code, GitHub Copilot, Open Code) so your agent can query analyzers and surface findings without leaving your environment. Install the IDE Plugin for VS Code or JetBrains to run analysis inside your editor, see issues inline, jump straight to the flagged line, and generate ready-to-use fix prompts. Optional automation analyzes files on save or immediately after AI edits, so quality and security issues in AI-generated code are caught the moment they occur. With Cyclopt Profile, developers track their growth across eight skill categories, earn badges, and build a shareable profile that reflects real coding ability. Companion integrates with GitHub, GitLab, Bitbucket, and Azure DevOps, as well as Slack, Teams, and Discord. Setup takes under five minutes with no credit card required, making it an ideal fit for developers, freelancers, and engineering teams who want to reduce technical debt and ship reliable software faster.

**Average Rating:** 4.6/5.0

**Total Reviews:** 13

#### How Do G2 Users Rate Cyclopt Companion?

- **Ease of Use:** 8.5/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Cyclopt Companion?

- **Seller:** [Cyclopt](https://www.g2.com/sellers/cyclopt)
- **Company Website:** www.cyclopt.com
- **Year Founded:** 2017
- **HQ Location:** Pylaia, GR
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a92682e9950091e8cb93511b51612e41cb88b42787b27d9a99c77c428f09109c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcyclopt&secure%5Burl_type%5D=linkedin_company_website)  
12 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 100% Small

#### What Do G2 Reviewers Say About Cyclopt Companion?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **meaningful insights** of Cyclopt Companion, enhancing coding skills with helpful feedback and tracking progress.
- Users value the **strong focus on security** in Cyclopt Companion, enhancing code safety in development workflow.
- Users value the **actionable feedback on code quality** from Cyclopt Companion, enhancing improvement and security with clear metrics.
- Users value the **effective issue identification** in Cyclopt Companion, enhancing project health and simplifying error resolution.
- Users appreciate the **instant alert notifications** from Cyclopt Companion, keeping them informed about code quality improvements immediately.

##### Cons

- Users find the **difficult learning curve** of Cyclopt Companion challenging without prior software engineering knowledge.
- Users note a **steep learning curve** for understanding metrics, requiring prior knowledge of software engineering principles.
- Users struggle with **difficult navigation** due to information being hidden too deep within the screens and menus.
- Users find the **difficulty for beginners** in navigating features challenging, often needing to figure things out independently.
- Users report a **short learning curve for metrics** in Cyclopt Companion, requiring prior software engineering knowledge for effective use.

#### What Are Recent G2 Reviews of Cyclopt Companion?

**["The Student/Junior Dev Angle"](https://www.g2.com/survey_responses/cyclopt-companion-review-12275784)**

**Rating:** 4.0/5.0 stars

_— Dimitris T._

[Read full review](https://www.g2.com/survey_responses/cyclopt-companion-review-12275784)

**["A reliable guardrail for code quality and security"](https://www.g2.com/survey_responses/cyclopt-companion-review-12314745)**

**Rating:** 5.0/5.0 stars

_— Matthieu N._

[Read full review](https://www.g2.com/survey_responses/cyclopt-companion-review-12314745)

- &lsaquo; Prev ‹ Prev
- 1
- [2](/categories/static-code-analysis?order=g2_score&page=2#product-list)
- [3](/categories/static-code-analysis?order=g2_score&page=3#product-list)
- [4](/categories/static-code-analysis?order=g2_score&page=4#product-list)
- [5](/categories/static-code-analysis?order=g2_score&page=5#product-list)
- …
- [9](/categories/static-code-analysis?order=g2_score&page=9#product-list)
- [10](/categories/static-code-analysis?order=g2_score&page=10#product-list)
- [Next &rsaquo; Next ›](/categories/static-code-analysis?order=g2_score&page=2#product-list)

Spotlight Categories

[Corporate Performance Management (CPM) Software](https://www.g2.com/categories/corporate-performance-management-cpm)

[Survey Software](https://www.g2.com/categories/survey)

[Audit Management Software Solutions](https://www.g2.com/categories/audit-management)

[Identity Verification Software](https://www.g2.com/categories/identity-verification)

[Security Compliance Software](https://www.g2.com/categories/security-compliance)

Similar Categories

- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)
- [Log Analysis](/categories/log-analysis)

- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Static Code Analysis Themes](/categories/static-code-analysis/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated October 3, 2024

Static code analysis is the analysis of computer software performed without actually executing the code. Static code analysis tools scan all code in a project and seek out vulnerabilities, validates code against industry best practices, and some software tools validate against company-specific project specifications. Static code analysis tools are used by software development and quality assurance teams to ensure the quality and security of code, and that project requirements are met. Static code analysis is a type of source code management and can integrate with version control systems and through build automation tasks using continuous integration software.

To qualify as a static code analysis tool, a product must:

- Scan code without executing that code
- List security vulnerabilities after scanning
- Validate code against industry best practices
- Provide recommendations on where and how to fix issues

Show More

### Static Code Analysis Topics

- [What is Static Code Analysis Software?](#what-is-static-code-analysis-software)
- [Why Use Static Code Analysis Software?](#why-use-static-code-analysis-software)
- [What are the Common Features of Static Code Analysis Software?](#what-are-the-common-features-of-static-code-analysis-software)
- [Trends Related to Static Code Analysis Software](#trends-related-to-static-code-analysis-software)
- [Software and Services Related to Static Code Analysis Software](#software-and-services-related-to-static-code-analysis-software)

[
### Static Code Analysis Topics
 Expand/Collapse ](#)
- [What is Static Code Analysis Software?](#what-is-static-code-analysis-software)
- [Why Use Static Code Analysis Software?](#why-use-static-code-analysis-software)
- [What are the Common Features of Static Code Analysis Software?](#what-are-the-common-features-of-static-code-analysis-software)
- [Trends Related to Static Code Analysis Software](#trends-related-to-static-code-analysis-software)
- [Software and Services Related to Static Code Analysis Software](#software-and-services-related-to-static-code-analysis-software)

## Learn More About Static Code Analysis Tools

### What is Static Code Analysis Software?
 

Static code analysis is a debugging and quality assurance method that inspects a computer program’s code without executing the program. Static code analysis software scans code to identify security vulnerabilities, catch bugs, and ensure the code adheres to industry standards. These tools help software developers automate the core aspects of program comprehension. Rather than manually combing through lines of code with visual inspection alone, developers and programmers can rely on static code analysis software’s automatic scans and alerts to gain deeper insight into their code. This automation decreases software developers overall workload and frees up resources by streamlining the debugging and quality assurance process.

 

Static code analysis software serves as an automated standardization check in many different development environments. A common concern among development teams is code readability—if developer A writes a chunk of code which is passed to developer B, that code must be comprehensible and easy to digest. Constantly checking code against the industry standard or even custom best practices, static code analysis software helps software developers keep their code consistent to improve team collaboration.

 

Ideally, static code analysis software does more than save developers time, it greatly enhances the quality of their debugging processes. Manual code inspection is both time-consuming and subject to human error. Oftentimes, developers don’t find bugs until they manifest themselves post-deployment. Static code analysis software helps find and alert developers to the existence of bugs months before they can manifest in a deployed application. Static code analysis software ensures cleaner, higher-quality releases by minimizing bugs and errors, enhancing cybersecurity, and promoting coding best practices.

 

Key Benefits of Static Code Analysis Software

 
- Fewer undetected bugs upon deployment
- Save software developers time and resources
- Minimize human error
- Facilitate best industry or custom practices
- Promote DevOps security by ensuring more secure applications

 

### Why Use Static Code Analysis Software?
 

**Reduced workload —** Since static code analysis software runs automated scans, developers are free to spend more time working on new code and less time combing through existing code. Static code analysis automatically hunts down and alerts users to bad code. This means that software developers don’t have to spend time and resources manually combing through lines and lines of code.

 

**Thorough debugging —** Software developers are all too familiar with bugs that don’t show themselves known until months, or even years after an application’s release. Often, finding bugs via manual code inspection relies on running the code and hoping an error reveals itself during quality assurance testing. However, with static code analysis software, developers can find and resolve bugs that would otherwise have been hidden in the code allowing for cleaner deployments and less issues down the line.

 

**Standardized best practices —** Beyond debugging, static code analysis software checks code against industry standard benchmarks for best practices. This standardized regulation keeps teams on the same page by ensuring that everyone’s code is clear and optimized. Additionally, some software allows users to customize best practices to fit the specifications of their company or department.

 

**Better security —** Static code analysis software is often capable of finding and alerting developers of security vulnerabilities in their code. Developers can prioritize cybersecurity thanks to static code analysis.

 

### What are the Common Features of Static Code Analysis Software?
 

**Integrated development environment (IDE) integration —** Most static code analysis software integrates with developers’ IDEs to provide a seamless solution within a pre-existing development environment. This integration means developers can continuously scan their code without interrupting their workflow.

 

**Timely alerts —** Because static code analysis software can scan code for bugs and vulnerabilities in a matter of seconds, developers receive timely alerts that help them enhance work efficiency. These timely alerts also help users react appropriately to bugs early on, saving them time and stress later.

 

**Recommendations —** Beyond alerting developers to code issues, static code analysis software generates actionable recommendations based on different errors or vulnerabilities that are detected. These suggestions give developer a starting point to resolve various problems, which saves time and mental energy.

 

Static Code Analysis Tools for Programming Languages and Features: [C#](https://www.g2.com/categories/static-code-analysis/f/c), [C/C++](https://www.g2.com/categories/static-code-analysis/f/c-c), [Java](https://www.g2.com/categories/static-code-analysis/f/java), [.NET](https://www.g2.com/categories/static-code-analysis/f/net), [PHP](https://www.g2.com/categories/static-code-analysis/f/php), [Python](https://www.g2.com/categories/static-code-analysis/f/python), [Ruby](https://www.g2.com/categories/static-code-analysis/f/ruby), [Salesforce](https://www.g2.com/categories/static-code-analysis/f/salesforce)

 

### Trends Related to Static Code Analysis Software

**DevOps —** DevOps refers to the marriage of development and IT operations management to make unified software development pipelines. Teams have implemented DevOps best practices to build, test, and release software. Static code analysis software’s seamless integration with IDE’s means it fits right in with any DevOps cycle.

**Cybersecurity —** Calls for standardized cybersecurity best practices as part of DevOps philosophy, often referred to as DevSecOps, have shifted the onus of responsibility for secure applications onto developers. Static code analysis software’s vulnerability detection functionality plays a necessary role in establishing secure DevOps practices.

### Software and Services Related to Static Code Analysis Software

[**Vulnerability scanner software**](https://www.g2.com/categories/vulnerability-scanner) **—** Vulnerability scanners constantly monitor applications and networks to identify security vulnerabilities. While static code analysis software often has the functionality to find vulnerabilities at the code level, vulnerability scanners are usually more robust. These tools scan full applications and networks then test them against known vulnerabilities. All of these functions help enhance cybersecurity.

[**Dynamic application security testing (DAST) software**](https://www.g2.com/categories/dynamic-application-security-testing-dast) **—** Dynamic application security testing (DAST) tools automate security tests for a variety of real-world threats. These tools run applications against simulated attacks and other cybersecurity scenarios using black-box testing, or testing performed outside of an application, as opposed to in-app solutions like static code analysis.

[**Software composition analysis (SCA) software**](https://www.g2.com/categories/software-composition-analysis) **—** Software composition analysis (SCA) software enables users to manage open-source and third-party components of their applications. SCA software scans an application’s components to verify licensing and compliance, assess vulnerabilities, and check for version updates. These tools serve as an essential component for any secure DevOps repertoire in addition to static code analysis software and other cybersecurity solutions.