
For me, Xanitizer is my must-have to do source code analysis for Java applications. The taint analysis, based on a data flow analysis. Besides of the classic static source code analysis, which is pattern based, Xanitizer analyses the source code from the user's entry points as the source all the ways through to the sinks. The findings are extraordinary good, much better than in the other tools we evaluated.
I like also the integration of the OWASP Dependency Check and FindBugs, which brings up even more security relevant findings. Review collected by and hosted on G2.com.
It is limited to Java. Up until now to backend Java, but I know that they also work on JS analysis.
But to be good as a tool, it is better to focus on one field and do well with it, instead of working on all languages and having poor results. Review collected by and hosted on G2.com.