Flawfinder Alternatives

Flawfinder is described as 'Examines C/C++ source code and reports possible security weaknesses ("flaws'') sorted by risk level. It's very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public' and is an app in the development category. There are more than 10 alternatives to Flawfinder for a variety of platforms, including Windows, Linux, Web-based, Mac and Visual Studio Code apps. The best Flawfinder alternative is SonarQube, which is both free and Open Source. Other great apps like Flawfinder are Shellcheck, Cppcheck, Coverity Scan and Splint.

  • FreeOpen Source
  • ...

Flawfinder examines C/C++ source code and reports possible security weaknesses ("flaws'') sorted by risk...

More about Flawfinder
Flawfinder alternatives page was last updated Feb 18, 2025
Copy a direct link to this comment to your clipboard
Alternatives
  1. SonarQube icon
     26 likes
    Copy a direct link to this comment to your clipboard

    SonarQube is an open source quality management platform, dedicated to continuously analyze and measure source code quality, from the portfolio to the method. Static code analysis is available in the "Community Edition" (free / open source) for:

    30 SonarQube alternatives

    License model

    • FreemiumOpen Source

    Country of Origin

    • CH flagSwitzerland

    Platforms

    • Mac
    • Windows
    • Linux
    • Online

    SonarQube Features

    1.  Static Code Analysis
    2.  Continuous Integration
    3.  Metrics

    SonarQube VS Flawfinder

     
    • SonarQube is the most popular Web-based, Windows, Mac & Linux alternative to Flawfinder.

    • SonarQube is the most popular Open Source & free alternative to Flawfinder.

    • SonarQube is Freemium and Open SourceFlawfinder is Free and Open Source
  2. Shellcheck icon
     4 likes
    Copy a direct link to this comment to your clipboard

    A simple tool for finding bugs in shell scripts.

    17 Shellcheck alternatives

    License model

    • FreeOpen Source

    Country of Origin

    • NO flagNorway

    Platforms

    • Online
    • Visual Studio Code
    • Vim
    • Sublime Text
    • GNU Emacs
    • Atom

    Shellcheck Features

    1.  Static Code Analysis
    2.  Security Testing
    3.  Metrics
    4.  Coding

    Shellcheck VS Flawfinder

     
  3. Cppcheck icon
     23 likes
    Copy a direct link to this comment to your clipboard

    Cppcheck is an static analysis tool for C/C++ code. Unlike C/C++ compilers and many other analysis tools it does not detect syntax errors in the code. Cppcheck primarily detects the types of bugs that the compilers normally do not detect.

    17 Cppcheck alternatives

    License model

    • FreeOpen Source

    Country of Origin

    • SE flagSweden
    • European Union flagEU

    Platforms

    • Windows
    • Linux
    • PortableApps.com
    • Eclipse

    Properties

    1.  Lightweight

    Features

    1.  Portable
    2.  C++

    Cppcheck VS Flawfinder

     
  4.  4 likes
    Copy a direct link to this comment to your clipboard

    Coverity Scan Static Analysis allows to find and fix defects in your Java, C/C++ or C# open source project for free.

    17 Coverity Scan alternatives

    License model

    • FreemiumProprietary

    Country of Origin

    • US flagUnited States

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • BSD

    Coverity Scan Features

    1.  Debugging
    2.  C++
    3.  Static Code Analysis

    Coverity Scan VS Flawfinder

     
  5.  2 likes
    Copy a direct link to this comment to your clipboard

    Splint is a tool for statically checking C programs for security vulnerabilities and coding mistakes. With minimal effort, Splint can be used as a better lint. If additional effort is invested adding annotations to programs, Splint can perform stronger checking than can be done...

    8 Splint alternatives

    License model

    • FreeOpen Source

    Platforms

    • Windows
    • Linux
    Discontinued

    Last version 3.1.2 is from August 2007.

    Splint Features

    1.  Static Code Analysis
    2.  Static analysis
    3.  Coding

    Splint VS Flawfinder

     
  6.  Like
    Copy a direct link to this comment to your clipboard

    EDoC++ is a C++ source analysis tool designed to identify problems associated with the use of exceptions in C++ code. Additionally EDoC++ can be used to generate detailed documentation

    17 EDoC++ alternatives

    License model

    • FreeOpen Source

    Platforms

    • Windows

    EDoC++ Features

    1.  C++

    EDoC++ VS Flawfinder

     
  7. Astrée icon
     Like
    Copy a direct link to this comment to your clipboard

    Astrée statically analyzes whether the programming language is used correctly and whether there can be any runtime errors during any execution in any environment. This covers any use of C or C++ that, according to the selected language standard, has undefined behavior or...

    4 Astrée alternatives

    License model

    Platforms

    • Windows
    • Linux

    Astrée Features

    1.  Static Code Analysis

    Astrée VS Flawfinder

     
    • Astrée is the most popular commercial alternative to Flawfinder.

    • Astrée is Paid and ProprietaryFlawfinder is Free and Open Source
  8. Copy a direct link to this comment to your clipboard

    VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:

    16 VisualCodeGrepper alternatives

    License model

    • FreeOpen Source

    Platforms

    • Windows

    VisualCodeGrepper Features

    1.  C++
    2.  C-sharp

    VisualCodeGrepper VS Flawfinder

     
  9. Qodana icon
     Like
    Copy a direct link to this comment to your clipboard

    Qodana is a smart code quality platform by JetBrains best suited for working in teams. It can analyze code written in 60+ languages including Java, JavaScript, TypeScript, PHP, Kotlin, Python, Go, and C#.

    30 Qodana alternatives

    License model

    Country of Origin

    • CZ flagCzechia
    • European Union flagEU

    Platforms

    • Visual Studio Code
    • Online
    • Self-Hosted

    Qodana Features

    1.  Dark Mode
    2.  Code Quality
    3.  Ide integration
    4.  Static Code Analysis

    Qodana VS Flawfinder

     
    • Qodana is the most popular Self-Hosted alternative to Flawfinder.

    • Qodana is Paid and ProprietaryFlawfinder is Free and Open Source
  10. Copy a direct link to this comment to your clipboard

    Parasoft’s C/C++test is the fully-integrated software testing solution for embedded safety-critical industries. Its automated software testing capabilities are also made for today’s high-velocity Agile DevOps environments.

    19 Parasoft C/C++test alternatives

    License model

    Country of Origin

    • US flagUnited States

    Platforms

    • Windows
    • Linux

    Parasoft C/C++test Features

    1.  Ide integration
    2.  Automated code review
    3.  Security Testing
    4.  Static Code Analysis

    Parasoft C/C++test VS Flawfinder

     
  11. Semgrep icon
     Like
    Copy a direct link to this comment to your clipboard

    Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or...

    28 Semgrep alternatives

    License model

    • FreemiumOpen Source

    Country of Origin

    • US flagUnited States

    Platforms

    • Mac
    • Windows
    • Linux

    Semgrep Features

    1.  Security Testing
    2.  Static Code Analysis
    3.  Static analysis

    Semgrep VS Flawfinder

     
  12. Opengrep icon
     Like
    Copy a direct link to this comment to your clipboard

    We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀

    28 Opengrep alternatives

    License model

    • FreeOpen Source

    Platforms

    • Mac
    • Linux

    Opengrep Features

    1.  Static Code Analysis

    Opengrep VS Flawfinder

     
12 of 13 Flawfinder alternatives