Open Source SonarQube Alternatives

The best open source alternative to SonarQube is Codacy. It's not free, so if you're looking for a free alternative, you could try Codacy or Shellcheck. If that doesn't suit you, our users have ranked more than 25 alternatives to SonarQube and nine of them is open source so hopefully you can find a suitable replacement. Other interesting open source alternatives to SonarQube are Flawfinder, PhpMetrics, VisualCodeGrepper and Semgrep.

Copy a direct link to this comment to your clipboard
SonarQube alternatives page was last updated

Alternatives list

  1. Codacy icon
     25 likes

    Automatically reviews code style, security, duplication, complexity, and coverage on every change while tracking code quality throughout your sprints.

    50 Codacy alternatives

    Cost / License

    • Free Personal
    • Open Source

    Platforms

    • Online
    • Self-Hosted
    • Software as a Service (SaaS)
     
    |
    1
    Codacy vs SonarQube Comments
    Guest
    Positive
    1

    Measure evaluation of the code quality over time.

    Review by a new / low-activity user.
    • Codacy is Free Personal and Open SourceSonarQube is Freemium and Open Source
  2. Cppcheck icon
     23 likes

    Cppcheck is an static analysis tool for C/C++ code. Unlike C/C++ compilers and many other analysis tools it does not detect syntax errors in the code. Cppcheck primarily detects the types of bugs that the compilers normally do not detect.

    17 Cppcheck alternatives

    Cost / License

    Platforms

    • Windows
    • Linux
    • PortableApps.com
    • Eclipse
     
  3. Flawfinder icon
     3 likes

    Flawfinder examines C/C++ source code and reports possible security weaknesses ("flaws'') sorted by risk level. It's very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public.

    13 Flawfinder alternatives

    Cost / License

    Platforms

    • Windows
    • Linux
     
  4. PhpMetrics icon
     1 like

    PhpMetrics provides metrics about PHP project and classes, with beautiful and readable HTML report.

    Cost / License

    • Free
    • Open Source (MIT)

    Platforms

    • Self-Hosted
     
  5. VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:

    Cost / License

    Platforms

    • Windows
     
  6. Semgrep icon
     Like

    Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or...

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
     
  7. Exlint icon
     Like

    Exlint is a an open source project that enables developers to centralize their open source coding standards and policies, so that configuring repositories becomes as easy as typing one command.

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Self-Hosted
    • Software as a Service (SaaS)
     
  8. Opengrep icon
     Like

    We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀

    Cost / License

    Platforms

    • Mac
    • Linux
     
9 of 9 SonarQube alternatives