# Best Static Code Analysis Tools

## How Many Static Code Analysis Tools Products Does G2 Track?

**Total Products under this Category:** 131

### Category Stats (Aug 2026)

- **Average Rating:** 4.38/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Black Duck Coverity Static (+0.61%) - Among all products in this category, Black Duck Coverity Static recorded the largest rating increase compared to last month

_Last updated: August 01, 2026_

## How Does G2 Rank Static Code Analysis Tools Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 2,200+ Authentic Reviews
- 131+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Static Code Analysis Tools
 ![G2 Grid® for Static Code Analysis Tools plotting products by satisfaction and market presence](https://www.g2.com/categories/static-code-analysis/grids.png?focus%5B%5D=7775&focus%5B%5D=102905&focus%5B%5D=4475&focus%5B%5D=1225549&focus%5B%5D=161987&focus%5B%5D=1225688&focus%5B%5D=48275&focus%5B%5D=41321)

Highlighted products: SonarQube, Gearset DevOps, Checkmarx, Semgrep, CAST Imaging, Typo, ReSharper C++, and OpenText Static Application Security Testing.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-code-analysis/grids.json?focus%5B%5D=sonarqube&focus%5B%5D=gearset-devops&focus%5B%5D=checkmarx&focus%5B%5D=semgrep&focus%5B%5D=cast-imaging&focus%5B%5D=typo&focus%5B%5D=resharper-c&focus%5B%5D=opentext-static-application-security-testing)

**Sponsored**

### Cake Equity

Cake Equity is an equity management platform that helps startups and growing companies manage their cap table, equity compensation, and compliance in one place. It moves with a company from its first SAFE or option grant through complex funding rounds, giving founders, finance, legal, and employees one system to stay aligned as the company scales. Designed as a system of action, Cake brings cap table management, stock option and ESOP administration, equity plan design, and built-in compliance into a single platform, with automated workflows and intelligent insights that surface what matters before teams have to ask. Core capabilities include: - Cap table management and modeling: a real-time cap table with scenario modeling for funding rounds, SAFE conversions, and exits. - Stock option and ESOP administration: grant issuance, vesting schedules, and equity plan management in one place. - Built-in compliance: 409A valuations, ASC 718 reporting, and board approval workflows for audit-ready records. - Automated document workflows: document generation, scanning, and contract editing that reduce manual equity admin. - Employee equity education: built-in tools that help employees understand what they own, how their equity works, and why it matters. What sets Cake apart is motivation. Beyond managing equity, Cake gives every stakeholder a reason to care about it: founders get a cap table they can trust, finance and legal teams get audit-ready reporting and faster document workflows, and employees get real clarity on their ownership.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=564&secure%5Bchosen_at%5D=2026-08-03T15%3A41%3A52Z&secure%5Bdisplayable_resource_id%5D=1715&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=retargeted_product&secure%5Bplacement_resource_ids%5D%5B%5D=134444&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=134444&secure%5Bresource_id%5D=564&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fstatic-code-analysis&secure%5Btoken%5D=b9f186dbf8f75f6abc6f4efdee952583e57cda488d3a81d1c1adc744eff20b68&secure%5Burl%5D=https%3A%2F%2Fcakeequity.com%3Futm_source%3Dg2%26utm_medium%3Dpaid-social%26utm_campaign%3Dclicks%26utm_term%3Dem%26utm_content%3Dcta&secure%5Burl_type%5D=custom_url)

### [SonarQube](https://www.g2.com/products/sonarqube/reviews)

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 153

#### How Do G2 Users Rate SonarQube?

- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind SonarQube?

- **Seller:** [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)
- **Company Website:** www.sonarsource.com
- **Year Founded:** 2008
- **HQ Location:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, DevOps Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 42% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Users value how SonarQube **efficiently flags code quality and security issues** , ensuring a clean and maintainable codebase.
- Users value the **issue filtering and prioritization features** of SonarQube, enhancing focus on high-priority tasks.
- Users value the **issue identification and prioritization** features of SonarQube, improving focus on critical tasks.
- Users find SonarQube's **ease of use** invaluable for maintaining code quality and integrating seamlessly into development workflows.
- Users appreciate the **easy integrations** with existing CI/CD tools, enhancing their development workflow seamlessly.

##### Cons

- Users face challenges with **software bugs** as SonarQube can consume excessive RAM and occasionally reports false positives.
- Users find SonarQube's configuration **complex** , especially for beginners, leading to difficulties and overwhelming warnings to manage.
- Users encounter **false positives** that complicate evaluations, though mitigation options exist through detailed analysis and rule customization.
- Users find that SonarQube's **complexity in configuration** and excessive warnings can hinder effective usage and efficiency.
- Users find the **complex setup** of SonarQube challenging, especially for beginners unfamiliar with the configuration process.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube: Easy Integration, Simple UI, and Solid Free Code Quality Scanning"](https://www.g2.com/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-12975264)

**["SonarQube Makes Code Quality Clear with Strong Quality Gates and CI/CD Integration"](https://www.g2.com/survey_responses/sonarqube-review-13142666)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-13142666)

#### What Are G2 Users Discussing About SonarQube?

- [What is SonarLint used for?](https://www.g2.com/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)

### [Gearset DevOps](https://www.g2.com/products/gearset-devops/reviews)

Gearset is the global leader in Salesforce DevOps. It’s a DevOps platform that helps organizations manage, automate, and govern the full Salesforce development lifecycle, from planning and deployment to testing, data management, and compliance. The platform is designed for Salesforce teams that need reliable, scalable DevOps processes across complex org environments. Gearset is used by mid-market and enterprise organizations across regulated and non-regulated industries, including healthcare, financial services, insurance, and technology. Typical users include Salesforce administrators, developers, DevOps engineers, release managers, and platform owners responsible for maintaining deployment quality, security, and operational consistency. The platform supports a wide range of Salesforce use cases, including metadata and CPQ deployments, CI/CD automation, code review workflows, sandbox seeding, test automation, and monitoring. As well as deployment automation, Gearset includes tools for Salesforce data protection and long-term data management, such as automated backups, data restore, and archiving. Observability and Org Intelligence features provide insight into org health, deployment risk, and system changes over time. Gearset also includes governance and compliance capabilities designed for enterprise environments. These features help teams maintain audit readiness and enforce access controls while supporting compliance frameworks such as SOX, ISO, HIPAA, and GDPR. The platform is delivered as a managed service and integrates with Salesforce environments without requiring complex local infrastructure. Key features and capabilities include: - Salesforce metadata, CPQ, and data deployments with CI/CD automation and version control integration - Code review, test automation, and release validation to support quality and consistency - Automated Salesforce backups, restore, and data archiving for data protection and retention - Sandbox seeding, observability, and Org Intelligence to support environment management and visibility - Governance features including audit trails, role-based access controls, and compliance support Gearset is a Salesforce Partner and has supported Salesforce teams globally since 2015. The platform is used by organizations managing multiple orgs (across regions), frequent releases, and complex compliance requirements, helping teams reduce deployment risk, improve operational visibility, and maintain control over Salesforce change management processes.

**Average Rating:** 4.7/5.0

**Total Reviews:** 303

#### How Do G2 Users Rate Gearset DevOps?

- **Has the product been a good partner in doing business?:** 9.5/10 (Category avg: 8.7/10)
- **Ease of Admin:** 9.3/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Gearset DevOps?

- **Seller:** [Gearset](https://www.g2.com/sellers/gearset)
- **Company Website:** www.gearset.com
- **Year Founded:** 2015
- **HQ Location:** Cambridge, Cambridgeshire
- **Twitter:** @GearsetHQ  
1,182 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=cb0a1d1a51dafae67aaf930cdb09c5683dea58d96c6c97e17a838b129a1f7c7a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F10478150%2F&secure%5Burl_type%5D=linkedin_company_website)  
366 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Salesforce Developer, Salesforce Administrator
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 37% Medium, 33% Small

#### What Do G2 Reviewers Say About Gearset DevOps?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **ease of use** of Gearset DevOps, praising its smooth setup and efficient management of deployments.
- Users value the **ease and flexibility of deployments** with Gearset, enhancing efficiency and minimizing human error.
- Users value the **easy deployment** of Gearset DevOps, enabling quick and efficient management of projects and releases.
- Users value the **exceptional customer support** from Gearset DevOps, highlighting their responsiveness and helpfulness with issues and requests.
- Users praise the **deployment ease** of Gearset DevOps, noting a smooth setup and efficient management of releases.

##### Cons

- Users struggle with **deployment issues** such as manual activation of Flows and potential metadata overwrites during production changes.
- Users find Gearset DevOps to be **expensive for larger teams** , impacting budget considerations despite its advanced features.
- Users find the **complexity of Gearset DevOps** overwhelming, seeking improvements in automation and simplified processes.
- Users face **limitations in data management** with Gearset, as some metadata does not transfer accurately between environments.
- Users find the **missing features** of Gearset DevOps, like automated dependency tracking and mobile support, limiting their efficiency.

#### What Are Recent G2 Reviews of Gearset DevOps?

**["Powerful Salesforce DevOps That Makes Every Release Easier"](https://www.g2.com/survey_responses/gearset-devops-review-13031923)**

**Rating:** 5.0/5.0 stars

_— Paul B._

[Read full review](https://www.g2.com/survey_responses/gearset-devops-review-13031923)

**["Rollbacks, Conflict Resolution, and Precise Deployments That Elevate CI/CD"](https://www.g2.com/survey_responses/gearset-devops-review-13189639)**

**Rating:** 4.5/5.0 stars

_— Chris P._

[Read full review](https://www.g2.com/survey_responses/gearset-devops-review-13189639)

### [Checkmarx](https://www.g2.com/products/checkmarx/reviews)

Checkmarx is a type of application security solution designed to help organizations safeguard their software development processes while enhancing efficiency and reducing costs. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. With the increasing reliance on AI technologies and the rapid pace of software development, Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as AI SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

**Average Rating:** 4.2/5.0

**Total Reviews:** 44

#### How Do G2 Users Rate Checkmarx?

- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.2/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Checkmarx?

- **Seller:** [Checkmarx](https://www.g2.com/sellers/checkmarx)
- **Company Website:** www.checkmarx.com
- **Year Founded:** 2006
- **HQ Location:** Paramus, NJ
- **Twitter:** @Checkmarx  
7,284 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=18f6741e77df71b112ecb3ec6620912d3a0f67666525358c0a4f3b1278b173df&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheckmarx&secure%5Burl_type%5D=linkedin_company_website)  
1,019 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 56% Large, 23% Medium

#### What Do G2 Reviewers Say About Checkmarx?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Checkmarx **easy to implement** , seamlessly integrating into existing repositories with a user-friendly interface.
- Users appreciate the **intuitive user interface** of Checkmarx, making security reviews simple and user-friendly.
- Users value the **accuracy of results** from Checkmarx, as it simplifies security reviews with detailed vulnerability insights.
- Users value the **automation testing capabilities** of Checkmarx, finding it easy to integrate and use effectively.
- Users praise the **exceptional customer support** at Checkmarx, ensuring prompt assistance for any unresolved issues.

##### Cons

- Users face a high number of **false positives** in Checkmarx when working with Kotlin projects, affecting accuracy and reliability.
- Users report **lacking feature support** for Kotlin, leading to numerous false positives not seen in Java or JavaScript.
- Users experience **missing features** in Checkmarx, specifically regarding poor support for Kotlin that leads to false positives.
- Users find the **poor navigation** in Checkmarx frustrating, as the dashboard layout and display need enhancement.

#### What Are Recent G2 Reviews of Checkmarx?

**["Centralized Source Code Security with Seamless CI/CD Integration"](https://www.g2.com/survey_responses/checkmarx-review-12980590)**

**Rating:** 5.0/5.0 stars

_— Aman M._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12980590)

**["Checkmarx: Reliable SAST Solution for Strengthening Application Security"](https://www.g2.com/survey_responses/checkmarx-review-13085824)**

**Rating:** 4.0/5.0 stars

_— Naushad T._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-13085824)

#### What Are G2 Users Discussing About Checkmarx?

- [What is Checkmarx used for?](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for) - 1 comment, 1 upvote
- [How much does Checkmarx cost?](https://www.g2.com/discussions/how-much-does-checkmarx-cost)
- [Which testing method does Checkmarx support?](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support) - 1 comment
- [Does Checkmarx support DAST?](https://www.g2.com/discussions/does-checkmarx-support-dast) - 1 comment
- [What is Checkmarx used for?](https://www.g2.com/discussions/what-is-checkmarx-used-for) - 2 comments

### [Semgrep](https://www.g2.com/products/semgrep/reviews)

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

**Average Rating:** 4.6/5.0

**Total Reviews:** 56

#### How Do G2 Users Rate Semgrep?

- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 8.7/10)
- **Ease of Admin:** 9.1/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Semgrep?

- **Seller:** [Semgrep](https://www.g2.com/sellers/semgrep)
- **Company Website:** semgrep.dev
- **Year Founded:** 2017
- **HQ Location:** San Francisco, US
- **Twitter:** @semgrep  
4,433 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=968a71f2060531e986a3873882c34b492bee4d8d264ff88e0089e53b8f7771f4&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freturntocorp&secure%5Burl_type%5D=linkedin_company_website)  
262 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 45% Large, 43% Medium

#### What Do G2 Reviewers Say About Semgrep?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Semgrep, praising its intuitive syntax and smooth CI/CD integration.
- Users appreciate the **intuitive pattern-matching syntax** of Semgrep, enabling effective custom rules for various programming languages.
- Users appreciate Semgrep's **effective vulnerability detection** , enabling quick identification of security issues with low false positives.
- Users value the **scanning efficiency** of Semgrep, benefiting from rapid scans and seamless CI/CD integration.
- Users appreciate the **robust security features** of Semgrep, enabling effective identification and remediation of vulnerabilities effortlessly.

##### Cons

- Users find Semgrep **not user-friendly** , citing a steep learning curve and challenges in initial setup and customization.
- Users note the **limited features** of Semgrep, making categorization and comprehensive analysis more challenging.
- Users find the **difficult learning** curve for custom rules in Semgrep challenging, impacting new user experiences and efficiency.
- Users face a **lack of guidance** in mastering rule creation and initial setup, impacting effective tool utilization.
- Users find the **learning curve steep** for rule writing, especially for those new to static analysis tools.

#### What Are Recent G2 Reviews of Semgrep?

**["Streamlined Code Security with Semgrep"](https://www.g2.com/survey_responses/semgrep-review-11971635)**

**Rating:** 5.0/5.0 stars

_— Shreekanth k._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-11971635)

**["Fast, Easy-to-Customize Rules That Catch Security and Code-Quality Issues Early"](https://www.g2.com/survey_responses/semgrep-review-13079252)**

**Rating:** 4.5/5.0 stars

_— Milan K._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-13079252)

### [CAST Imaging](https://www.g2.com/products/cast-imaging/reviews)

CAST Imaging helps software architects and AI agents understand, change, and modernize applications. It automatically reverse-engineers all database structures, code components, and interdependencies in any custom-built applications. CAST Imaging deterministically maps the entire system – architecture, dependencies, data access, and tech debt. It provides interactive and accurate architecture blueprints, zoomable to the tiniest details. as well as data call graphs and end-to-end transaction views. All this in a lightweight web UI with the ability for teams to collaborate by adding their own knowledge and sharing insights. A built-in MCP server streams this precise application architectural context to AI agents which can generate consistent, accurate, and safe code changes. Businesses move faster using CAST technology to understand, improve, and transform their software. Through semantic analysis of source code, CAST produces 3D maps and dashboards to navigate inside individual applications and across entire portfolios. This intelligence empowers executives and technology leaders to steer, speed, and report on initiatives such as technical debt, GenAI, modernization, and cloud. As the pioneer of the software intelligence field, CAST is trusted by the world’s leading companies and governments, their consultancies and cloud providers. See it all at castsoftware.com.

**Average Rating:** 4.6/5.0

**Total Reviews:** 36

#### How Do G2 Users Rate CAST Imaging?

- **Has the product been a good partner in doing business?:** 8.4/10 (Category avg: 8.7/10)
- **Ease of Admin:** 7.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.2/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind CAST Imaging?

- **Seller:** [CAST](https://www.g2.com/sellers/cast)
- **Company Website:** www.castsoftware.com
- **Year Founded:** 1990
- **HQ Location:** New York
- **Twitter:** @SW\_Intelligence  
1,887 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0ce2f19bfa683d9d06fc56898a1568de05de4c4332e22f1fb046292c65ff44c9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcast%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,264 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 53% Large, 28% Small

#### What Are Recent G2 Reviews of CAST Imaging?

**["Engineering Dashboard Boosts Code Quality"](https://www.g2.com/survey_responses/cast-imaging-review-13075743)**

**Rating:** 4.5/5.0 stars

_— Vinsensius Samuel H._

[Read full review](https://www.g2.com/survey_responses/cast-imaging-review-13075743)

**["CAST Imaging Turns Complex Apps into an Intuitive, High-Performance Visual Map"](https://www.g2.com/survey_responses/cast-imaging-review-13101049)**

**Rating:** 4.0/5.0 stars

_— Verified User in Maritime_

[Read full review](https://www.g2.com/survey_responses/cast-imaging-review-13101049)

#### What Are G2 Users Discussing About CAST Imaging?

- [What is CAST Imaging used for?](https://www.g2.com/discussions/what-is-cast-imaging-used-for) - 1 comment, 1 upvote

### [Typo](https://www.g2.com/products/typo/reviews)

Typo is an AI-powered software engineering intelligence platform that gives engineering leaders real-time visibility into what's actually happening across their SDLC — and what to do about it. From a single platform, engineering teams can track DORA metrics and delivery health, measure the real impact of AI coding tools like Cursor, and Claude Code, run AI code reviews on every pull request, monitor R&D investment allocation, and measure developer experience through anonymous surveys. Typo connects to your existing stack — GitHub, GitLab, Bitbucket, Jira, Linear, and CI/CD tools — in 60 seconds. No complex onboarding. Used by 1,000+ engineering teams globally. 15M+ pull requests processed. Featured in Gartner's Market Guide for Software Engineering Intelligence Platforms.

**Average Rating:** 4.6/5.0

**Total Reviews:** 150

#### How Do G2 Users Rate Typo?

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.8/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.9/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 9.8/10 (Category avg: 10/10)

#### Who Is the Company Behind Typo?

- **Seller:** [Typo](https://www.g2.com/sellers/typo)
- **Year Founded:** 2020
- **HQ Location:** Dover, US
- **Twitter:** @Typoapp\_  
66 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=978e78e847141b121898277ce3abdd8408cbb9980ccb16a9d6d1e94c082a6d06&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftypoapp%2Fabout%2F&secure%5Burl_type%5D=linkedin_company_website)  
76 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 47% Medium, 43% Small

#### What Do G2 Reviewers Say About Typo?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **comprehensive metrics** of Typo, enhancing insights and enabling effective self-management for developers.
- Users value the **clear metrics and insights** from Typo that enhance engineering performance and team alignment.
- Users value the **powerful insights** and automation features of Typo, significantly enhancing productivity and efficiency analysis.
- Users value the **automated code reviews** of Typo, enhancing code quality and streamlining the development process.
- Users appreciate the **powerful automation** of Typo, which enhances productivity insights and code quality remarkably.

##### Cons

- Users struggle with **complex configurations** and limitations in sprint-related features, impacting customization and functionality.
- Users experience **bug issues** with Typo, but the team is responsive and quick to resolve them.
- Users express frustration with the **lack of customization** options in Typo, limiting adaptability to unique team workflows.
- Users find **limited features** in Typo, particularly in customization options and mobile accessibility, affecting usability.
- Users highlight a **lack of important features** in Typo, including customization options and mobile app availability.

#### What Are Recent G2 Reviews of Typo?

**["Outstanding Metrics and Insights for Code Quality"](https://www.g2.com/survey_responses/typo-review-12104366)**

**Rating:** 4.0/5.0 stars

_— Amarjeet ._

[Read full review](https://www.g2.com/survey_responses/typo-review-12104366)

**["Intuitive Tool with Powerful Analytics and Seamless GitHub Integration"](https://www.g2.com/survey_responses/typo-review-12066335)**

**Rating:** 5.0/5.0 stars

_— Eduardo V._

[Read full review](https://www.g2.com/survey_responses/typo-review-12066335)

### [ReSharper C++](https://www.g2.com/products/resharper-c/reviews)

ReSharper C++ is a productivity extension for developing in C and C++ that fully integrates with Microsoft Visual Studio. It helps developers create efficient and correct code in modern C++ by providing safe refactorings, fast navigation, and code analysis for the trickiest aspects of the language. It also offers support for HLSL shaders, the C++/CLI specifications, and Unreal Engine code.

**Average Rating:** 4.6/5.0

**Total Reviews:** 20

#### How Do G2 Users Rate ReSharper C++?

- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 8.7/10)
- **Ease of Admin:** 7.5/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.6/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 3.3/10 (Category avg: 10/10)

#### Who Is the Company Behind ReSharper C++?

- **Seller:** [JetBrains](https://www.g2.com/sellers/jetbrains)
- **Year Founded:** 2000
- **HQ Location:** Prague
- **Twitter:** @jetbrains  
213,126 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=38aa98843aee51e51c2eda5cdc7b29c3e6a7d48f3897c88088b0af7cfcb6f37d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F12515%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,941 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 55% Small, 35% Large

#### What Are Recent G2 Reviews of ReSharper C++?

**["Detects Every Syntax Error with Consistent, Proper Indentation"](https://www.g2.com/survey_responses/resharper-c-review-13051310)**

**Rating:** 5.0/5.0 stars

_— Megh D._

[Read full review](https://www.g2.com/survey_responses/resharper-c-review-13051310)

**["Insightful AI Coding Features Make It Perfect"](https://www.g2.com/survey_responses/resharper-c-review-12205837)**

**Rating:** 5.0/5.0 stars

_— Antawn S._

[Read full review](https://www.g2.com/survey_responses/resharper-c-review-12205837)

#### What Are G2 Users Discussing About ReSharper C++?

- [What is ReSharper C++ used for?](https://www.g2.com/discussions/what-is-resharper-c-used-for)

### [OpenText Static Application Security Testing](https://www.g2.com/products/opentext-static-application-security-testing/reviews)

OpenText™ Static Application Security Testing (SAST) is a comprehensive solution designed to identify and remediate security vulnerabilities within an application's source code during the early stages of development. By analyzing code from the "inside out," SAST provides immediate feedback to developers, enabling them to address security issues promptly and effectively. Key Features and Functionality: - Extensive Language Support: Supports over 33 programming languages and more than 1,400 vulnerability categories, ensuring broad applicability across various development environments. - Integration with Development Tools: Seamlessly integrates with popular Integrated Development Environments (IDEs) such as Eclipse, Visual Studio, and JetBrains, as well as Continuous Integration/Continuous Deployment (CI/CD) tools like Jenkins and Bamboo, facilitating a smooth incorporation into existing workflows. - Scalable Deployment Options: Offers flexible deployment models, including on-premises, cloud-based, and Software as a Service (SaaS) solutions, allowing organizations to choose the setup that best fits their needs. - Advanced Analysis Capabilities: Utilizes multiple algorithms and an expansive knowledge base of secure coding rules to perform thorough code analysis, pinpointing the root causes of vulnerabilities and providing detailed remediation guidance. Primary Value and Problem Solved: OpenText SAST empowers organizations to proactively manage application security by detecting and addressing vulnerabilities early in the Software Development Life Cycle (SDLC). This proactive approach reduces the risk of security breaches, minimizes the cost and effort associated with late-stage remediation, and enhances the overall security posture of applications. By integrating security testing into the development process, OpenText SAST helps developers create more secure code, leading to robust and reliable software products.

**Average Rating:** 4.5/5.0

**Total Reviews:** 21

#### How Do G2 Users Rate OpenText Static Application Security Testing?

- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.1/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.7/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind OpenText Static Application Security Testing?

- **Seller:** [OpenText](https://www.g2.com/sellers/opentext)
- **Year Founded:** 1991
- **HQ Location:** Waterloo, ON
- **Twitter:** @OpenText  
21,565 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c339a6555764b5ffce77c3df08d6ed9c9b1cb1ee1baeebac8435f0485b7cca5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2709%2F&secure%5Burl_type%5D=linkedin_company_website)  
23,048 employees on LinkedIn®
- **Ownership:** NASDAQ:OTEX

#### Who Uses This Product?

- **Top Industries:** Banking, Financial Services
- **Company Size:** 50% Large, 29% Small

#### What Do G2 Reviewers Say About OpenText Static Application Security Testing?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **easy integrations** of OpenText Static Application Security Testing with various third-party tools for enhanced functionality.
- Users value the **extensive integration capabilities** of OpenText Static Application Security Testing with various third-party tools.
- Users value the **integration support** of OpenText Static Application Security Testing, enhancing compatibility with various tools and technologies.

##### Cons

- Users find the **false positives** in OpenText Static Application Security Testing somewhat problematic, despite options to ignore them.

#### What Are Recent G2 Reviews of OpenText Static Application Security Testing?

**["Fortify Static Code Analyzer (SCA)"](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-10770814)**

**Rating:** 4.0/5.0 stars

_— Lokesh T._

[Read full review](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-10770814)

**["Efficient and easy to use Code Analyzer"](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-7271508)**

**Rating:** 4.5/5.0 stars

_— Nav N._

[Read full review](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-7271508)

#### What Are G2 Users Discussing About OpenText Static Application Security Testing?

- [What is Fortify Static Code Analyzer used for?](https://www.g2.com/discussions/what-is-fortify-static-code-analyzer-used-for)
- [What tools does fortify include?](https://www.g2.com/discussions/what-tools-does-fortify-include)
- [What are the main components of Fortify?](https://www.g2.com/discussions/fortify-static-code-analyzer-what-are-the-main-components-of-fortify) - 1 comment
- [What is Fortify software used for?](https://www.g2.com/discussions/fortify-static-code-analyzer-what-is-fortify-software-used-for)
- [What is Micro Focus Fortify static code analyzer?](https://www.g2.com/discussions/what-is-micro-focus-fortify-static-code-analyzer)

### [Mend.io](https://www.g2.com/products/mend-io/reviews)

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

**Average Rating:** 4.3/5.0

**Total Reviews:** 114

#### How Do G2 Users Rate Mend.io?

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.3/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.3/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Mend.io?

- **Seller:** [Mend](https://www.g2.com/sellers/mend-ab79a83a-6747-4682-8072-a3c176489d0b)
- **Company Website:** mend.io
- **Year Founded:** 2011
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @Mend\_io  
11,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=041c6c79eefb0ef528e05bab57503847c90096672ecceb998f987d3daebef99a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2440656%2F&secure%5Burl_type%5D=linkedin_company_website)  
257 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 36% Small, 32% Medium

#### What Do G2 Reviewers Say About Mend.io?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **scanning efficiency** of Mend.io, appreciating its quick and accurate results across multiple repositories.
- Users appreciate the **ease of use** of Mend.io, highlighting simple integration and efficient navigation to find vulnerabilities.
- Users appreciate the **easy integrations** of Mend.io, enabling efficient scanning and streamlined workflows across multiple repositories.
- Users appreciate the **quick and accurate scanning** capabilities of Mend.io, enhancing their development workflow and security.
- Users commend the **excellent automated vulnerability detection** in Mend.io, enhancing efficiency in their CI/CD processes.

##### Cons

- Users struggle with **integration issues** , finding the setup process for tools like Jira and on-premise systems challenging.
- Users find **limited features** in Mend.io, struggling with functionality and integration challenges for various tools and cases.
- Users note that Mend.io lacks **essential features** , requiring additional tools and workarounds for effective integration.
- Users experience **complex implementation** with Mend.io, citing difficulties in integration and frequent false positives.
- Users find the **confusing interface** of Mend.io awkward, especially when switching between different product portals.

#### What Are Recent G2 Reviews of Mend.io?

**["Great Tool for Managing 3rd party libraries"](https://www.g2.com/survey_responses/mend-io-review-6728890)**

**Rating:** 4.5/5.0 stars

_— Johannes B._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-6728890)

**["Mend.io Makes Vulnerability Scanning and Prioritization Easy"](https://www.g2.com/survey_responses/mend-io-review-13187391)**

**Rating:** 4.5/5.0 stars

_— Ratna P._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-13187391)

#### What Are G2 Users Discussing About Mend.io?

- [What is your experience regarding pricing and costs for Mend.io, and how does it compare to other open-source security solutions?](https://www.g2.com/discussions/what-is-your-experience-regarding-pricing-and-costs-for-mend-io-and-how-does-it-compare-to-other-open-source-security-solutions)
- [What is Mend (formerly WhiteSource) used for?](https://www.g2.com/discussions/what-is-mend-formerly-whitesource-used-for)
- [What is white Source bolt?](https://www.g2.com/discussions/what-is-white-source-bolt)
- [What are SCA tools?](https://www.g2.com/discussions/what-are-sca-tools)
- [What is software composition analysis SCA?](https://www.g2.com/discussions/what-is-software-composition-analysis-sca)

### [CodeScene](https://www.g2.com/products/codescene/reviews)

CodeScene is a code analysis, visualization, and reporting tool. Cross reference contextual factors such as code quality, team dynamics, and delivery output to get actionable insights to effectively reduce technical debt and deliver better code quality. We enable software development teams to make confident, data-driven decisions that fuel performance and developer productivity. CodeScene guides developers and technical leaders to: - Get a holistic overview and evolution of your software system in one single dashboard. - Identify, prioritize, and tackle technical debt based on return on investment. - Maintain a healthy codebase with powerful CodeHealth™ Metrics, spend less time on rework and more time on innovation. - Seamlessly integrate with Pull Requests and editors, get actionable code reviews and refactoring recommendations. - Set Improvement goals and quality gates for teams to work towards while monitoring the progress. - Support retrospectives by identifying areas for improvement. - Benchmark performance against personalized trends. - Understand the social side of the code, measure socio-technical factors like key personnel dependencies, knowledge sharing and inter-team coordination. - Put findings into context based on how your organization and your code evolves. Supporting 28+ programming languages, CodeScene offers an automated integration with GitHub, BitBucket, Azure DevOps or GitLab pull requests to incorporate the analysis results into existing delivery workflows. Get early warnings and recommendations about complex code before merging it to the main branch, set quality gates to trigger in case your code health declines.

**Average Rating:** 4.6/5.0

**Total Reviews:** 39

#### How Do G2 Users Rate CodeScene?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.6/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.1/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind CodeScene?

- **Seller:** [CodeScene AB](https://www.g2.com/sellers/codescene-ab)
- **Company Website:** www.codescene.com
- **Year Founded:** 2015
- **HQ Location:** Malmö, SE
- **Twitter:** @codescene  
1,239 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=3cfa1c6a5137d85c0b88d5202f5784e459c44e0221ccaf8ee6bde39e2d0c2c4c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcodescene%2F&secure%5Burl_type%5D=linkedin_company_website)  
32 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 41% Medium, 36% Small

#### What Do G2 Reviewers Say About CodeScene?

_AI-generated summary from verified user reviews_

##### Pros

- Users praise CodeScene for its **excellent code health overview and powerful pull request reviews** , greatly enhancing maintainability and quality.
- Users appreciate the **issue identification** capabilities of CodeScene, helping teams improve knowledge and prioritize code quality effectively.
- Users appreciate the **enhanced code quality** features of CodeScene, significantly improving maintainability and reducing technical debt.
- Users commend CodeScene's **responsive customer support** , facilitating quick deployments and effective use of the software.
- Users value the **actionable insights** provided by CodeScene, enhancing code quality and supporting informed decision-making in teams.

##### Cons

- Users struggle with **integration issues** , needing manual configuration and lacking seamless CI/CD tool compatibility.
- Users find the **difficult learning** curve of CodeScene challenging, especially with its complex features and terminology.
- Users find the **difficulty for beginners** in CodeScene's onboarding process can hinder their initial experience and utilization.
- Users find the **initial learning difficulty** of CodeScene daunting, especially with advanced features and complex terminology.
- Users struggle with the **difficult configuration** of CodeScene, facing challenges in setup and integration with existing tools.

#### What Are Recent G2 Reviews of CodeScene?

**["CodeScene Delivers Smart, Actionable Insights Beyond Static Analysis"](https://www.g2.com/survey_responses/codescene-review-11658139)**

**Rating:** 4.5/5.0 stars

_— Saravana K._

[Read full review](https://www.g2.com/survey_responses/codescene-review-11658139)

**["Impactful code quality mesurements"](https://www.g2.com/survey_responses/codescene-review-11656380)**

**Rating:** 4.5/5.0 stars

_— Yossi Z._

[Read full review](https://www.g2.com/survey_responses/codescene-review-11656380)

### [Kiuwan Code Security & Insights](https://www.g2.com/products/kiuwan-code-security-insights/reviews)

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

**Average Rating:** 4.5/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate Kiuwan Code Security & Insights?

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.7/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Kiuwan Code Security & Insights?

- **Seller:** [Sembi](https://www.g2.com/sellers/sembi)
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7ed5860a727a31b32edfba64808a6ea32fccad50d052e993a08b626d675d5c69&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsembi-inc%2F&secure%5Burl_type%5D=linkedin_company_website)  
94 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Banking
- **Company Size:** 41% Large, 35% Medium

#### What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **accuracy** of Kiuwan's code scans, ensuring reliable results and satisfaction with reporting capabilities.
- Users value the **accuracy of findings** from Kiuwan Code Security & Insights, enhancing their confidence in code security.
- Users appreciate the **efficient customer support** of Kiuwan, enhancing their overall experience and satisfaction with the product.
- Users value the **user-friendly interface** of Kiuwan, enhancing their experience with efficient code scans and reporting.
- Users appreciate the **user-friendly interface** of Kiuwan Code Security & Insights, making dashboard navigation easy and efficient.

#### What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

**["Impeccable Security and Code Analysis, with Potential for Improvement in Customization"](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)**

**Rating:** 5.0/5.0 stars

_— Abelardo I._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)

**["Elevated our software security to the next level. Improved our code quality."](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)**

**Rating:** 5.0/5.0 stars

_— Abdullah Enes K._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)

### [Codacy](https://www.g2.com/products/codacy/reviews)

Codacy is the code quality and security platform for AI-assisted engineering teams. AI is now embedded through the engineering workflow, which has made teams faster, but also adds risk to everything they ship. Codacy helps AI-assisted teams ship high-quality, secure code across the full software development lifecycle, starting in the agent and editor, through pull requests in Git, and into containers and runtime security. At each stage we check for quality issues, security vulnerabilities and AI coding risk introduced into the codebase, and help devs and agent fix them effortlessly. A team's standards become automated guardrails that apply across every IDE, AI coding agent, and Pull Request. More than 250,000 developers rely on Codacy to keep quality and security stable as AI changes how software gets built. Add your repo and get your free scan report in minutes: https://codacy.com

**Average Rating:** 4.6/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate Codacy?

- **Has the product been a good partner in doing business?:** 9.1/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.5/10)
- **Ease of Use:** 9.1/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Codacy?

- **Seller:** [Codacy](https://www.g2.com/sellers/codacy)
- **Year Founded:** 2012
- **HQ Location:** Lisbon, Lisboa
- **Twitter:** @codacy  
5,002 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=cfb2ce473f29d659861c3939070bb76f085fb14394ceeb1e11c4d3c449846d0f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F3310124%2F&secure%5Burl_type%5D=linkedin_company_website)  
69 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 59% Small, 24% Medium

#### What Do G2 Reviewers Say About Codacy?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **security dashboard and vulnerability management** features of Codacy for enhanced insights and code safety.
- Users value the **integrated automation** of Codacy, finding it user-friendly and effective for maintaining code quality.
- Users value the **integrated automation testing** in Codacy, appreciating its ease of use and effective quality control.
- Users value the **excellent code quality** features of Codacy, finding it easy to maintain clean and secure code.
- Users value the **helpful customer support** of Codacy, appreciating their immediate assistance for quick resolutions.

##### Cons

- Users find Codacy to be **a bit expensive** at $19/month, which may burden smaller organizations financially.

#### What Are Recent G2 Reviews of Codacy?

**["Codacy is a security must-have tool in our company"](https://www.g2.com/survey_responses/codacy-review-10264506)**

**Rating:** 5.0/5.0 stars

_— David M._

[Read full review](https://www.g2.com/survey_responses/codacy-review-10264506)

**["Easy GitHub & CI/CD Integration That Catches Bugs Before Production"](https://www.g2.com/survey_responses/codacy-review-12739228)**

**Rating:** 4.5/5.0 stars

_— Arjun M._

[Read full review](https://www.g2.com/survey_responses/codacy-review-12739228)

### [Cyclopt Companion](https://www.g2.com/products/cyclopt-companion/reviews)

Cyclopt Companion is a code quality and security tool that helps developers ship secure, maintainable code with confidence, whether written by humans or AI. Built on the ISO 25010:2023 methodology, Companion analyzes every commit and flags coding violations, security vulnerabilities, code duplication, and maintainability issues in real time. You get instant feedback showing exactly how each commit changes your code quality, down to the precise file and line. Companion meets you where you already work. Connect the MCP Server to your AI coding assistant (Claude Code, GitHub Copilot, Open Code) so your agent can query analyzers and surface findings without leaving your environment. Install the IDE Plugin for VS Code or JetBrains to run analysis inside your editor, see issues inline, jump straight to the flagged line, and generate ready-to-use fix prompts. Optional automation analyzes files on save or immediately after AI edits, so quality and security issues in AI-generated code are caught the moment they occur. With Cyclopt Profile, developers track their growth across eight skill categories, earn badges, and build a shareable profile that reflects real coding ability. Companion integrates with GitHub, GitLab, Bitbucket, and Azure DevOps, as well as Slack, Teams, and Discord. Setup takes under five minutes with no credit card required, making it an ideal fit for developers, freelancers, and engineering teams who want to reduce technical debt and ship reliable software faster.

**Average Rating:** 4.6/5.0

**Total Reviews:** 13

#### How Do G2 Users Rate Cyclopt Companion?

- **Ease of Use:** 8.5/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Cyclopt Companion?

- **Seller:** [Cyclopt](https://www.g2.com/sellers/cyclopt)
- **Company Website:** www.cyclopt.com
- **Year Founded:** 2017
- **HQ Location:** Pylaia, GR
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a92682e9950091e8cb93511b51612e41cb88b42787b27d9a99c77c428f09109c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcyclopt&secure%5Burl_type%5D=linkedin_company_website)  
12 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 100% Small

#### What Do G2 Reviewers Say About Cyclopt Companion?

_AI-generated summary from verified user reviews_

##### Pros

- Users love the **insightful feedback** from Cyclopt Companion, enhancing coding skills and tracking project progress effectively.
- Users praise Cyclopt Companion for its **strong focus on security issues** , enhancing code safety and project health.
- Users value the **actionable feedback on committed code** from Cyclopt Companion, enhancing code quality and developer confidence.
- Users appreciate the **effective issue identification** of Cyclopt Companion, making coding smoother and enhancing project quality.
- Users appreciate the **immediate alert notifications** that keep them informed about code improvements right after committing.

##### Cons

- Users find a **difficult learning curve** due to complex metrics and underlying software engineering concepts.
- Users note a **steep learning curve** for those unfamiliar with software engineering principles, affecting usability and engagement.
- Users find the **difficult navigation** challenging due to information being obscured within screens and menus.
- Users find the **difficulty for beginners** challenging due to complex feature presentations requiring self-learning.
- Users experience a **steep learning curve** for understanding metrics, impacting their ability to utilize insights effectively.

#### What Are Recent G2 Reviews of Cyclopt Companion?

**["The Student/Junior Dev Angle"](https://www.g2.com/survey_responses/cyclopt-companion-review-12275784)**

**Rating:** 4.0/5.0 stars

_— Dimitris T._

[Read full review](https://www.g2.com/survey_responses/cyclopt-companion-review-12275784)

**["A reliable guardrail for code quality and security"](https://www.g2.com/survey_responses/cyclopt-companion-review-12314745)**

**Rating:** 5.0/5.0 stars

_— Matthieu N._

[Read full review](https://www.g2.com/survey_responses/cyclopt-companion-review-12314745)

### [ReSharper](https://www.g2.com/products/resharper/reviews)

ReSharper is a renowned productivity tool that turns Microsoft Visual Studio into a much better IDE. Both individual .NET developers and teams rely on ReSharper to write and maintain code in a more manageable and enjoyable way, adopt the best coding practices, and deliver higher quality applications faster.

**Average Rating:** 4.5/5.0

**Total Reviews:** 83

#### How Do G2 Users Rate ReSharper?

- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 8.7/10)
- **Ease of Admin:** 8.1/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.8/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind ReSharper?

- **Seller:** [JetBrains](https://www.g2.com/sellers/jetbrains)
- **Year Founded:** 2000
- **HQ Location:** Prague
- **Twitter:** @jetbrains  
213,126 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=38aa98843aee51e51c2eda5cdc7b29c3e6a7d48f3897c88088b0af7cfcb6f37d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F12515%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,941 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Software Developer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 38% Medium, 38% Small

#### What Are Recent G2 Reviews of ReSharper?

**["Extends your capabilities. Must have tool!"](https://www.g2.com/survey_responses/resharper-review-9443303)**

**Rating:** 4.5/5.0 stars

_— Rajat A._

[Read full review](https://www.g2.com/survey_responses/resharper-review-9443303)

**["Great Productivity tool for Programming"](https://www.g2.com/survey_responses/resharper-review-9335129)**

**Rating:** 4.0/5.0 stars

_— Dilan P._

[Read full review](https://www.g2.com/survey_responses/resharper-review-9335129)

#### What Are G2 Users Discussing About ReSharper?

- [How has ReSharper impacted your code quality, and what features do you find most valuable?](https://www.g2.com/discussions/how-has-resharper-impacted-your-code-quality-and-what-features-do-you-find-most-valuable)
- [What is ReSharper used for?](https://www.g2.com/discussions/what-is-resharper-used-for)
- [Is ReSharper worth 2019?](https://www.g2.com/discussions/is-resharper-worth-2019)
- [Why is ReSharper so slow?](https://www.g2.com/discussions/why-is-resharper-so-slow)
- [Is there a free version of ReSharper?](https://www.g2.com/discussions/is-there-a-free-version-of-resharper)

### [Closure Compiler](https://www.g2.com/products/closure-compiler/reviews)

The Closure Compiler is a tool for making JavaScript download and run faster. Instead of compiling from a source language to machine code, it compiles from JavaScript to better JavaScript.

**Average Rating:** 3.9/5.0

**Total Reviews:** 13

#### How Do G2 Users Rate Closure Compiler?

- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 8.7/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.5/10)
- **Ease of Use:** 8.2/10 (Category avg: 8.7/10)
- **What is your organization's estimated ROI on the product (payback period in months)?:** 10/10 (Category avg: 10/10)

#### Who Is the Company Behind Closure Compiler?

- **Seller:** [Google](https://www.g2.com/sellers/google)
- **Year Founded:** 1998
- **HQ Location:** Mountain View, CA
- **Twitter:** @google  
31,899,995 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fe4a5936665c9702418dd53c477fef5a7baea08078bb117ed67e966fc581b9ec&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1441%2F&secure%5Burl_type%5D=linkedin_company_website)  
341,888 employees on LinkedIn®
- **Ownership:** NASDAQ:GOOG

#### Who Uses This Product?

- **Company Size:** 46% Small, 38% Medium

#### What Are Recent G2 Reviews of Closure Compiler?

**["Best Efficent Compiler for JS"](https://www.g2.com/survey_responses/closure-compiler-review-4850716)**

**Rating:** 4.5/5.0 stars

_— Sanjay K._

[Read full review](https://www.g2.com/survey_responses/closure-compiler-review-4850716)

**["Well designed tool"](https://www.g2.com/survey_responses/closure-compiler-review-4908172)**

**Rating:** 5.0/5.0 stars

_— Nitya M._

[Read full review](https://www.g2.com/survey_responses/closure-compiler-review-4908172)

#### What Are G2 Users Discussing About Closure Compiler?

- [Which of the following are the three compilation levels that can be applied to the JavaScript code to define the degree of compression and optimization required?](https://www.g2.com/discussions/which-of-the-following-are-the-three-compilation-levels-that-can-be-applied-to-the-javascript-code-to-define-the-degree-of-compression-and-optimization-required)
- [What is closure Google what is closure in JavaScript?](https://www.g2.com/discussions/what-is-closure-google-what-is-closure-in-javascript)
- [Who uses Closure Library?](https://www.g2.com/discussions/who-uses-closure-library)
- [How do you run a compiler closure?](https://www.g2.com/discussions/how-do-you-run-a-compiler-closure)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/static-code-analysis?order=g2_score&page=2#product-list)
- [3](/categories/static-code-analysis?order=g2_score&page=3#product-list)
- [4](/categories/static-code-analysis?order=g2_score&page=4#product-list)
- [5](/categories/static-code-analysis?order=g2_score&page=5#product-list)
- …
- [8](/categories/static-code-analysis?order=g2_score&page=8#product-list)
- [9](/categories/static-code-analysis?order=g2_score&page=9#product-list)
- [Next &rsaquo;Next ›](/categories/static-code-analysis?order=g2_score&page=2#product-list)

Spotlight Categories

[Lead Intelligence Software](https://www.g2.com/categories/lead-intelligence)

[Multi-Country Payroll Software](https://www.g2.com/categories/multi-country-payroll)

[E-commerce Fraud Protection Software](https://www.g2.com/categories/e-commerce-fraud-protection)

[Job Search Sites](https://www.g2.com/categories/job-search-sites)

[Media Monitoring Software](https://www.g2.com/categories/media-monitoring)

Similar Categories

- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)
- [Log Analysis](/categories/log-analysis)

- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Static Code Analysis Themes](/categories/static-code-analysis/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated October 3, 2024

Static code analysis is the analysis of computer software performed without actually executing the code. Static code analysis tools scan all code in a project and seek out vulnerabilities, validates code against industry best practices, and some software tools validate against company-specific project specifications. Static code analysis tools are used by software development and quality assurance teams to ensure the quality and security of code, and that project requirements are met. Static code analysis is a type of source code management and can integrate with version control systems and through build automation tasks using continuous integration software.

To qualify as a static code analysis tool, a product must:

- Scan code without executing that code
- List security vulnerabilities after scanning
- Validate code against industry best practices
- Provide recommendations on where and how to fix issues

Show More

* * *

## How Do You Choose the Right Static Code Analysis Tools?

### What You Should Know About Static Code Analysis Software

### What is Static Code Analysis Software?

Static code analysis is a debugging and quality assurance method that inspects a computer program’s code without executing the program. Static code analysis software scans code to identify security vulnerabilities, catch bugs, and ensure the code adheres to industry standards. These tools help software developers automate the core aspects of program comprehension. Rather than manually combing through lines of code with visual inspection alone, developers and programmers can rely on static code analysis software’s automatic scans and alerts to gain deeper insight into their code. This automation decreases software developers overall workload and frees up resources by streamlining the debugging and quality assurance process.

Static code analysis software serves as an automated standardization check in many different development environments. A common concern among development teams is code readability—if developer A writes a chunk of code which is passed to developer B, that code must be comprehensible and easy to digest. Constantly checking code against the industry standard or even custom best practices, static code analysis software helps software developers keep their code consistent to improve team collaboration.

Ideally, static code analysis software does more than save developers time, it greatly enhances the quality of their debugging processes. Manual code inspection is both time-consuming and subject to human error. Oftentimes, developers don’t find bugs until they manifest themselves post-deployment. Static code analysis software helps find and alert developers to the existence of bugs months before they can manifest in a deployed application. Static code analysis software ensures cleaner, higher-quality releases by minimizing bugs and errors, enhancing cybersecurity, and promoting coding best practices.

Key Benefits of Static Code Analysis Software

- Fewer undetected bugs upon deployment
- Save software developers time and resources
- Minimize human error
- Facilitate best industry or custom practices
- Promote DevOps security by ensuring more secure applications

### Why Use Static Code Analysis Software?

**Reduced workload —** Since static code analysis software runs automated scans, developers are free to spend more time working on new code and less time combing through existing code. Static code analysis automatically hunts down and alerts users to bad code. This means that software developers don’t have to spend time and resources manually combing through lines and lines of code.

**Thorough debugging —** Software developers are all too familiar with bugs that don’t show themselves known until months, or even years after an application’s release. Often, finding bugs via manual code inspection relies on running the code and hoping an error reveals itself during quality assurance testing. However, with static code analysis software, developers can find and resolve bugs that would otherwise have been hidden in the code allowing for cleaner deployments and less issues down the line.

**Standardized best practices —** Beyond debugging, static code analysis software checks code against industry standard benchmarks for best practices. This standardized regulation keeps teams on the same page by ensuring that everyone’s code is clear and optimized. Additionally, some software allows users to customize best practices to fit the specifications of their company or department.

**Better security —** Static code analysis software is often capable of finding and alerting developers of security vulnerabilities in their code. Developers can prioritize cybersecurity thanks to static code analysis.

### What are the Common Features of Static Code Analysis Software?

**Integrated development environment (IDE) integration —** Most static code analysis software integrates with developers’ IDEs to provide a seamless solution within a pre-existing development environment. This integration means developers can continuously scan their code without interrupting their workflow.

**Timely alerts —** Because static code analysis software can scan code for bugs and vulnerabilities in a matter of seconds, developers receive timely alerts that help them enhance work efficiency. These timely alerts also help users react appropriately to bugs early on, saving them time and stress later.

**Recommendations —** Beyond alerting developers to code issues, static code analysis software generates actionable recommendations based on different errors or vulnerabilities that are detected. These suggestions give developer a starting point to resolve various problems, which saves time and mental energy.

Static Code Analysis Tools for Programming Languages and Features: [C#](https://www.g2.com/categories/static-code-analysis/f/c), [C/C++](https://www.g2.com/categories/static-code-analysis/f/c-c), [Java](https://www.g2.com/categories/static-code-analysis/f/java), [.NET](https://www.g2.com/categories/static-code-analysis/f/net), [PHP](https://www.g2.com/categories/static-code-analysis/f/php), [Python](https://www.g2.com/categories/static-code-analysis/f/python), [Ruby](https://www.g2.com/categories/static-code-analysis/f/ruby), [Salesforce](https://www.g2.com/categories/static-code-analysis/f/salesforce)

### Trends Related to Static Code Analysis Software

**DevOps —** DevOps refers to the marriage of development and IT operations management to make unified software development pipelines. Teams have implemented DevOps best practices to build, test, and release software. Static code analysis software’s seamless integration with IDE’s means it fits right in with any DevOps cycle.

**Cybersecurity —** Calls for standardized cybersecurity best practices as part of DevOps philosophy, often referred to as DevSecOps, have shifted the onus of responsibility for secure applications onto developers. Static code analysis software’s vulnerability detection functionality plays a necessary role in establishing secure DevOps practices.

### Software and Services Related to Static Code Analysis Software

[**Vulnerability scanner software**](https://www.g2.com/categories/vulnerability-scanner) **—** Vulnerability scanners constantly monitor applications and networks to identify security vulnerabilities. While static code analysis software often has the functionality to find vulnerabilities at the code level, vulnerability scanners are usually more robust. These tools scan full applications and networks then test them against known vulnerabilities. All of these functions help enhance cybersecurity.

[**Dynamic application security testing (DAST) software**](https://www.g2.com/categories/dynamic-application-security-testing-dast) **—** Dynamic application security testing (DAST) tools automate security tests for a variety of real-world threats. These tools run applications against simulated attacks and other cybersecurity scenarios using black-box testing, or testing performed outside of an application, as opposed to in-app solutions like static code analysis.

[**Software composition analysis (SCA) software**](https://www.g2.com/categories/software-composition-analysis) **—** Software composition analysis (SCA) software enables users to manage open-source and third-party components of their applications. SCA software scans an application’s components to verify licensing and compliance, assess vulnerabilities, and check for version updates. These tools serve as an essential component for any secure DevOps repertoire in addition to static code analysis software and other cybersecurity solutions.