Coverity Scan Alternatives

Coverity Scan is described as 'Static Analysis allows to find and fix defects in your Java, C/C++ or C# open source project for free' and is an app in the development category. There are more than 10 alternatives to Coverity Scan for a variety of platforms, including Linux, Windows, Mac, Web-based and Visual Studio Code apps. The best Coverity Scan alternative is SonarQube, which is both free and Open Source. Other great apps like Coverity Scan are Shellcheck, Cppcheck, SlowQL and Axivion Suite.

Copy a direct link to this comment to your clipboard
Coverity Scan alternatives page was last updated

Alternatives list

  1. Semgrep icon
     Like

    Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or...

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
     
  2. Dromeas icon
     Like

    AI-powered code review and release management: security and compliance scanning, documentation generation, and observability instrumentation, from PR to production.

    Cost / License

    • Freemium
    • Proprietary

    Application type

    Platforms

    • Online
     
  3. DefenseCode ThunderScan® is a SAST (Static Application Security Testing, WhiteBox Testing) solution for performing deep and extensive security analysis of application source code.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Windows
    • Linux
    • Online
    • Software as a Service (SaaS)
     
  4. Qodana icon
     Like

    Qodana is a smart code quality platform by JetBrains best suited for working in teams. It can analyze code written in 60+ languages including Java, JavaScript, TypeScript, PHP, Kotlin, Python, Go, and C#.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Visual Studio Code
    • Online
    • Self-Hosted
     
  5. Opengrep icon
     Like

    We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀

    Cost / License

    Platforms

    • Mac
    • Linux
     
  6. Code Buster reports dependency wiring, dead code, cycles, duplication, complexity, architecture-policy violations, feature flags, security and style heuristics, quality scores, and remediation plans.

    Cost / License

    • Free
    • Open Source (MIT)

    Platforms

    • Windows
    • Mac
    • Linux
     
  7. Yetus icon
     Like

    Apache Yetus is a collection of libraries and tools that enable contribution and release processes for software projects.

    Cost / License

    Platforms

    • Mac
    • Linux
     
  8. VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:

    Cost / License

    Platforms

    • Windows
     
You are at page 2 of Coverity Scan alternatives