SonarQube Alternatives

SonarQube is described as 'Open source quality management platform, dedicated to continuously analyze and measure source code quality, from the portfolio to the method. Static code analysis vailable in the "Community Edition" (free / open source) for:' and is an app in the development category. There are more than 25 alternatives to SonarQube for a variety of platforms, including Windows, Linux, Web-based, SaaS and Mac apps. The best SonarQube alternative is Codacy. It's not free, so if you're looking for a free alternative, you could try Codacy or Shellcheck. Other great apps like SonarQube are Coverity Scan, Flawfinder, SAST Online and Teamscale.

Copy a direct link to this comment to your clipboard
SonarQube alternatives page was last updated

Alternatives list

  1. Copy a direct link to this comment to your clipboard

    Landscape is an early warning system for the Python codebase. It integrates into GitHub, uses the Prospector code analysis tool for Python, and aggregates the analysis results nicely.

    Cost / License

    • Free Personal
    • Proprietary

    Platforms

    • Online
     
  2. DeepSource icon
     1 like
    Copy a direct link to this comment to your clipboard

    Find and fix bug risks, anti-patterns, performance issues, security flaws automatically during code reviews. In addition, DeepSource automatically fixes some of the most commonly occurring issues. It works for Python, Go, Ruby, and JavaScript.

    Cost / License

    • Freemium (Subscription)
    • Proprietary

    Platforms

    • Online
    • Software as a Service (SaaS)
    • CircleCI
    • Bitbucket
    • GitHub
    • Travis CI
    • GitLab
     
  3. Codegrip icon
     Like
    Copy a direct link to this comment to your clipboard

    Codegrip is an automated code review SaaS platform that helps developers to save time in code reviews and to tackle technical debt efficiently.

    Cost / License

    • Freemium (Subscription)
    • Proprietary

    Platforms

    • Software as a Service (SaaS)
     
  4. Copy a direct link to this comment to your clipboard

    The freeware program SourceMonitor lets you see inside your software source code to find out how much code you have and to identify the relative complexity of your modules.

    Cost / License

    • Free
    • Proprietary

    Platforms

    • Windows
     
  5. Copy a direct link to this comment to your clipboard

    Code Inspector is a platform that helps developers and managers to deliver better code. Main features:

    • Automated Code Review
    • Historical values of software metrics
    • Evaluation of technical debt

    Cost / License

    • Freemium (Subscription)
    • Proprietary

    Platforms

    • Software as a Service (SaaS)
     
  6. Copy a direct link to this comment to your clipboard

    VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:

    Cost / License

    Platforms

    • Windows
     
  7. Semgrep icon
     Like
    Copy a direct link to this comment to your clipboard

    Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or...

    Cost / License

    • Freemium (Subscription)
    • Open Source (LGPL-2.1)

    Platforms

    • Mac
    • Windows
    • Linux
     
  8. Exlint icon
     Like
    Copy a direct link to this comment to your clipboard

    Exlint is a an open source project that enables developers to centralize their open source coding standards and policies, so that configuring repositories becomes as easy as typing one command.

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Self-Hosted
    • Software as a Service (SaaS)
     
  9. Copy a direct link to this comment to your clipboard

    Parasoft’s C/C++test is the fully-integrated software testing solution for embedded safety-critical industries. Its automated software testing capabilities are also made for today’s high-velocity Agile DevOps environments.

    Cost / License

    • Pay once
    • Proprietary

    Platforms

    • Windows
    • Linux
     
  10. CodeSonar icon
     Like
    Copy a direct link to this comment to your clipboard

    Improve quality, reduce risk, and ship with confidence. GrammaTech's static analysis SAST tool as part of your secure SDLC identifies bugs that can result in system crashes, unexpected behavior, and security breaches.

    Cost / License

    • Pay once
    • Proprietary

    Platforms

    • Online
     
  11. Copy a direct link to this comment to your clipboard

    DefenseCode ThunderScan® is a SAST (Static Application Security Testing, WhiteBox Testing) solution for performing deep and extensive security analysis of application source code.

    Cost / License

    • Pay once
    • Proprietary

    Platforms

    • Windows
    • Linux
    • Online
    • Software as a Service (SaaS)
     
  12. Qodana icon
     Like
    Copy a direct link to this comment to your clipboard

    Qodana is a smart code quality platform by JetBrains best suited for working in teams. It can analyze code written in 60+ languages including Java, JavaScript, TypeScript, PHP, Kotlin, Python, Go, and C#.

    28 Qodana alternatives

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Visual Studio Code
    • Online
    • Self-Hosted
     
You are at page 2 of SonarQube alternatives