Shellcheck Alternatives

Shellcheck is described as 'A simple tool for finding bugs in shell scripts' and is an app in the development category. There are more than 10 alternatives to Shellcheck for a variety of platforms, including Linux, Windows, Mac, Web-based and BSD apps. The best Shellcheck alternative is SonarQube, which is both free and Open Source. Other great apps like Shellcheck are Cppcheck, Coverity Scan, PVS-Studio and Flawfinder.

Copy a direct link to this comment to your clipboard
Shellcheck alternatives page was last updated

Alternatives list

  1. SonarQube icon
     27 likes

    SonarQube is an open source quality management platform, dedicated to continuously analyze and measure source code quality, from the portfolio to the method. Static code analysis is available in the "Community Edition" (free / open source) for:

    28 SonarQube alternatives

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
     
  2. Cppcheck icon
     23 likes

    Cppcheck is an static analysis tool for C/C++ code. Unlike C/C++ compilers and many other analysis tools it does not detect syntax errors in the code. Cppcheck primarily detects the types of bugs that the compilers normally do not detect.

    Cost / License

    Platforms

    • Windows
    • Linux
    • PortableApps.com
    • Eclipse
     
  3.  4 likes

    Coverity Scan Static Analysis allows to find and fix defects in your Java, C/C++ or C# open source project for free.

    17 Coverity Scan alternatives

    Cost / License

    • Freemium
    • Proprietary

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • BSD
     
  4. PVS-Studio icon
     17 likes

    PVS-Studio is a static analyzer that detects errors in source code of C, C++ and C# applications. The PVS-Studio tool is intended for developers of contemporary applications and it integrates into the Visual Studio 2005/2008/2010/2012/2013 environment.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Windows
    • Linux
    • MinGW
    • Microsoft Visual Studio
    • clang
     
  5. Flawfinder icon
     3 likes

    Flawfinder examines C/C++ source code and reports possible security weaknesses ("flaws'') sorted by risk level. It's very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public.

    Cost / License

    Platforms

    • Windows
    • Linux
     
  6.  2 likes

    Splint is a tool for statically checking C programs for security vulnerabilities and coding mistakes. With minimal effort, Splint can be used as a better lint. If additional effort is invested adding annotations to programs, Splint can perform stronger checking than can be done...

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Windows
    • Linux
     
  7. VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:

    Cost / License

    Platforms

    • Windows
     
  8. Yetus icon
     Like

    Apache Yetus is a collection of libraries and tools that enable contribution and release processes for software projects.

    Cost / License

    Platforms

    • Mac
    • Linux
     
  9. Liverpool Data Research Associates (LDRA) is a provider of software analysis, test and requirements traceability tools for the Public and Private sectors and a pioneer in static and dynamic software analysis.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Windows
    • Linux
     
  10. Qodana icon
     Like

    Qodana is a smart code quality platform by JetBrains best suited for working in teams. It can analyze code written in 60+ languages including Java, JavaScript, TypeScript, PHP, Kotlin, Python, Go, and C#.

    28 Qodana alternatives

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Visual Studio Code
    • Online
    • Self-Hosted
     
  11. Semgrep icon
     Like

    Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or...

    26 Semgrep alternatives

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
     
  12. Opengrep icon
     Like

    We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀

    26 Opengrep alternatives

    Cost / License

    Platforms

    • Mac
    • Linux
     
12 of 17 Shellcheck alternatives