Flawfinder Alternatives
Flawfinder is described as 'Examines C/C++ source code and reports possible security weaknesses ("flaws'') sorted by risk level. It's very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public' and is an app in the development category. There are more than 10 alternatives to Flawfinder for a variety of platforms, including Windows, Linux, Web-based, Mac and Visual Studio Code apps. The best Flawfinder alternative is SonarQube, which is both free and Open Source. Other great apps like Flawfinder are Shellcheck, Cppcheck, Coverity Scan and Splint.
- Free • Open Source
- 30 SonarQube alternatives
SonarQube is an open source quality management platform, dedicated to continuously analyze and measure source code quality, from the portfolio to the method. Static code analysis is available in the "Community Edition" (free / open source) for:
License model
- Freemium • Open Source
Country of Origin
Switzerland
Platforms
- Mac
- Windows
- Linux
- Online
SonarQube Features
License model
- Free • Open Source
Country of Origin
Norway
Platforms
- Online
- Visual Studio Code
- Vim
- Sublime Text
- GNU Emacs
- Atom
Shellcheck Features
- 17 Cppcheck alternatives
Cppcheck is an static analysis tool for C/C++ code. Unlike C/C++ compilers and many other analysis tools it does not detect syntax errors in the code. Cppcheck primarily detects the types of bugs that the compilers normally do not detect.
License model
- Free • Open Source
Country of Origin
Sweden
EU
Platforms
- Windows
- Linux
- PortableApps.com
- Eclipse
- 17 Coverity Scan alternatives
Coverity Scan Static Analysis allows to find and fix defects in your Java, C/C++ or C# open source project for free.
License model
- Freemium • Proprietary
Country of Origin
United States
Platforms
- Mac
- Windows
- Linux
- Online
- BSD
Coverity Scan Features
- 8 Splint alternatives
Splint is a tool for statically checking C programs for security vulnerabilities and coding mistakes. With minimal effort, Splint can be used as a better lint. If additional effort is invested adding annotations to programs, Splint can perform stronger checking than can be done...
License model
- Free • Open Source
Platforms
- Windows
- Linux
DiscontinuedLast version 3.1.2 is from August 2007.
Splint Features
- 17 EDoC++ alternatives
EDoC++ is a C++ source analysis tool designed to identify problems associated with the use of exceptions in C++ code. Additionally EDoC++ can be used to generate detailed documentation
License model
- Free • Open Source
Platforms
- Windows
EDoC++ Features
- 4 Astrée alternatives
Astrée statically analyzes whether the programming language is used correctly and whether there can be any runtime errors during any execution in any environment. This covers any use of C or C++ that, according to the selected language standard, has undefined behavior or...
License model
- Paid • Proprietary
Platforms
- Windows
- Linux
Astrée Features
- 16 VisualCodeGrepper alternatives
VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:
License model
- Free • Open Source
Platforms
- Windows
VisualCodeGrepper Features
- 30 Qodana alternatives
Qodana is a smart code quality platform by JetBrains best suited for working in teams. It can analyze code written in 60+ languages including Java, JavaScript, TypeScript, PHP, Kotlin, Python, Go, and C#.
License model
- Paid • Proprietary
Country of Origin
Czechia
EU
Platforms
- Visual Studio Code
- Online
- Self-Hosted
Qodana Features
- 19 Parasoft C/C++test alternatives
Parasoft’s C/C++test is the fully-integrated software testing solution for embedded safety-critical industries. Its automated software testing capabilities are also made for today’s high-velocity Agile DevOps environments.
License model
- Paid • Proprietary
Country of Origin
United States
Platforms
- Windows
- Linux
Parasoft C/C++test Features
- 28 Semgrep alternatives
Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or...
License model
- Freemium • Open Source
Country of Origin
United States
Platforms
- Mac
- Windows
- Linux
Semgrep Features
- 28 Opengrep alternatives
We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀
License model
- Free • Open Source
Platforms
- Mac
- Linux
Opengrep Features