Free Coverity Scan Alternatives

The best free alternative to Coverity Scan is SonarQube, which is also Open Source. If that doesn't suit you, our users have ranked more than 10 alternatives to Coverity Scan and 14 is free so hopefully you can find a suitable replacement. Other interesting free alternatives to Coverity Scan are Shellcheck, Cppcheck, SlowQL and Flawfinder.

Copy a direct link to this comment to your clipboard
Coverity Scan alternatives page was last updated

Alternatives list

  1. SonarQube icon
     28 likes

    SonarQube is an open source quality management platform, dedicated to continuously analyze and measure source code quality, from the portfolio to the method. Static code analysis is available in the "Community Edition" (free / open source) for:

    32 SonarQube alternatives

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
     
  2. Shellcheck icon
     5 likes

    A simple tool for finding bugs in shell scripts.

    Cost / License

    Platforms

    • Online
    • Visual Studio Code
    • Vim
    • Sublime Text
    • GNU Emacs
    • Atom
     
  3. Cppcheck icon
     23 likes

    Cppcheck is an static analysis tool for C/C++ code. Unlike C/C++ compilers and many other analysis tools it does not detect syntax errors in the code. Cppcheck primarily detects the types of bugs that the compilers normally do not detect.

    Cost / License

    Platforms

    • Windows
    • Linux
    • PortableApps.com
    • Eclipse
     
  4. SlowQL icon
     1 like

    SlowQL is a production-focused offline SQL static analyzer that catches security vulnerabilities, performance regressions, reliability issues, compliance risks, cost inefficiencies, and code quality problems before they reach production.

    Cost / License

    • Free
    • Open Source

    Platforms

    • Docker
    • Windows
    • Mac
    • Linux
     
  5. Flawfinder icon
     3 likes

    Flawfinder examines C/C++ source code and reports possible security weaknesses ("flaws'') sorted by risk level. It's very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public.

    Cost / License

    Platforms

    • Windows
    • Linux
     
  6.  2 likes

    Splint is a tool for statically checking C programs for security vulnerabilities and coding mistakes. With minimal effort, Splint can be used as a better lint. If additional effort is invested adding annotations to programs, Splint can perform stronger checking than can be done...

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Windows
    • Linux
     
  7. Infer icon
     Like

    Facebook Infer is a static analysis tool - if you give Infer some Objective-C, Java, or C code, it produces a list of potential bugs.

    Cost / License

    • Free
    • Open Source

    Platforms

    • Linux
     
  8.  Like

    EDoC++ is a C++ source analysis tool designed to identify problems associated with the use of exceptions in C++ code. Additionally EDoC++ can be used to generate detailed documentation

    Cost / License

    • Free
    • Open Source

    Platforms

    • Windows
     
  9. Semgrep icon
     Like

    Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or...

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
     
  10. Go from prototype to production with AI-driven code quality, security, compliance, orchestration, testing and documentation.

    Cost / License

    • Freemium
    • Proprietary

    Platforms

    • Online
     
  11. Opengrep icon
     Like

    We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀

    27 Opengrep alternatives

    Cost / License

    Platforms

    • Mac
    • Linux
     
12 of 14 Coverity Scan alternatives