PhpMetrics provides metrics about PHP project and classes, with beautiful and readable HTML report.
Cost / License
- Free
- Open Source
Platforms
- Self-Hosted


Opengrep is described as 'We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀' and is an app in the development category. There are more than 25 alternatives to Opengrep for a variety of platforms, including Windows, Web-based, Linux, SaaS and Mac apps. The best Opengrep alternative is SonarQube, which is both free and Open Source. Other great apps like Opengrep are Codacy, Shellcheck, Cppcheck and Coverity Scan.
PhpMetrics provides metrics about PHP project and classes, with beautiful and readable HTML report.


Teamscale analyzes the quality of your code. Analyze your code with a variety of static and dynamic analyses to identify specific maintainability constraints and avoid unexpected maintenance costs in the future.



Code analysis tool, including breakdown of developer contributions, and a clear breakdown of different types of problems with trends over time.
Code Inspector is a platform that helps developers and managers to deliver better code. Main features:




Kiuwan Application Security is an end-to-end Appsec platform. Monitoring, action plans and seamless integration within unlocalized teams are but a few of the features offered by Kiuwan.
Kiuwan Application Security is the most popular Android alternative to Opengrep.
DefenseCode ThunderScan® is a SAST (Static Application Security Testing, WhiteBox Testing) solution for performing deep and extensive security analysis of application source code.

Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or...
Parasoft’s C/C++test is the fully-integrated software testing solution for embedded safety-critical industries. Its automated software testing capabilities are also made for today’s high-velocity Agile DevOps environments.
Improve quality, reduce risk, and ship with confidence. GrammaTech's static analysis SAST tool as part of your secure SDLC identifies bugs that can result in system crashes, unexpected behavior, and security breaches.

VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:

The freeware program SourceMonitor lets you see inside your software source code to find out how much code you have and to identify the relative complexity of your modules.

Codegrip is an automated code review SaaS platform that helps developers to save time in code reviews and to tackle technical debt efficiently.



