PhpMetrics provides metrics about PHP project and classes, with beautiful and readable HTML report.
Cost / License
- Free
- Open Source (MIT)
Platforms
- Self-Hosted


SonarQube is described as 'Open source quality management platform, dedicated to continuously analyze and measure source code quality, from the portfolio to the method. Static code analysis vailable in the "Community Edition" (free / open source) for:' and is an app in the development category. There are more than 25 alternatives to SonarQube for a variety of platforms, including Windows, Web-based, Linux, SaaS and Mac apps. The best SonarQube alternative is Codacy. It's not free, so if you're looking for a free alternative, you could try Codacy or Shellcheck. Other great apps like SonarQube are Coverity Scan, SlowQL, Flawfinder and SAST Online.
PhpMetrics provides metrics about PHP project and classes, with beautiful and readable HTML report.


Landscape is an early warning system for the Python codebase. It integrates into GitHub, uses the Prospector code analysis tool for Python, and aggregates the analysis results nicely.

Find and fix bug risks, anti-patterns, performance issues, security flaws automatically during code reviews. In addition, DeepSource automatically fixes some of the most commonly occurring issues. It works for Python, Go, Ruby, and JavaScript.




High-precision Python SAST & Dead Code Remover. Finds unused functions, secrets, and security flaws with hybrid static analysis + local LLM agents. Privacy-first & low noise. MCP server for SAST too.

Codegrip is an automated code review SaaS platform that helps developers to save time in code reviews and to tackle technical debt efficiently.




The freeware program SourceMonitor lets you see inside your software source code to find out how much code you have and to identify the relative complexity of your modules.

AI-powered GitHub repository health analysis — get instant health scores, risk signals, and contributor insights for any repo from a single URL.

Code Inspector is a platform that helps developers and managers to deliver better code. Main features:




VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:

Get high-quality feedback on every Pull Request. Only pay for developers who actively ship code — unlimited reviews, no per-seat waste.

Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or...
Exlint is a an open source project that enables developers to centralize their open source coding standards and policies, so that configuring repositories becomes as easy as typing one command.



