Skip to content
91

Static Analysis

⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.

15k stars1,512 forks528 entriesLast push Sep 21, 2026 (8 days ago)License MIT

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

General

gawk --lint

Warns about constructs that are dubious or nonportable to other awk implementations.

Astrée

copyright: — Astrée automatically proves the absence of runtime errors and invalid con­current behavior in C/C++ applications. It is sound for floating-point computations, very fast, and exceptionally precise. The analyzer also checks for MISRA/CERT/CWE/Adaptive Autosar coding rules and supports…

In 2 lists

CBMC

Bounded model-checker for C programs, user-defined assertions, standard assertions, several coverage metric analyses.

clang-tidy

Clang-based C++ linter tool with the (limited) ability to fix issues, too.

clazy

Qt-oriented static code analyzer based on the Clang framework. clazy is a compiler plugin which allows clang to understand Qt semantics. You get more than 50 Qt related compiler warnings, ranging from unneeded memory allocations to misusage of API, including fix-its for automatic refactoring.

codechecker

A defect database and viewer extension for the Clang Static Analyzer with web GUI.

CPAchecker

A tool for configurable software verification of C programs. The name CPAchecker was chosen to reflect that the tool is based on the CPA concepts and is used for checking software programs.

cppcheck

Static analysis of C/C++ code.

CppDepend

copyright: — Measure, query and visualize your code and avoid unexpected issues, technical debt and complexity.

In 2 lists

cpplint

Automated C++ checker that follows Google's style guide.

In 2 lists

CScout

Complexity and quality metrics for C and C preprocessor code.

In 2 lists

ESBMC

ESBMC is an open source, permissively licensed, context-bounded model checker based on satisfiability modulo theories for the verification of single- and multi-threaded C/C++ programs.

In 2 lists

flawfinder

Finds possible security weaknesses.

Frama-C

A sound and extensible static analyzer for C code.

In 2 lists

GCC

The GCC compiler has static analysis capabilities since version 10. This option is only available if GCC was configured with analyzer support enabled. It can also output its diagnostics to a JSON file in the SARIF format (from v13).

Goblint

A static analyzer for the analysis of multi-threaded C programs. Its primary focus is the detection of data races, but it also reports other runtime errors, such as buffer overflows and null-pointer dereferences.

Helix QAC

copyright: — Enterprise-grade static analysis for embedded software. Supports MISRA, CERT, and AUTOSAR coding standards.

In 2 lists

KLEE

A dynamic symbolic execution engine built on top of the LLVM compiler infrastructure. It can auto-generate test cases for programs such that the test cases exercise as much of the program as possible.

In 2 lists

LDRA

copyright: — A tool suite including static analysis (TBVISION) to various standards including MISRA C & C++, JSF++ AV, CWE, CERT C, CERT C++ & Custom Rules.

PC-lint

copyright: — Static analysis for C/C++. Runs natively under Windows/Linux/MacOS. Analyzes code for virtually any platform, supporting C11/C18 and C++17.

Phasar

A LLVM-based static analysis framework which comes with a taint and type state analysis.

Polyspace Bug Finder

copyright: — Identifies run-time errors, concurrency issues, security vulnerabilities, and other defects in C and C++ embedded software.

Polyspace Code Prover

copyright: — Provide code verification that proves the absence of overflow, divide-by-zero, out-of-bounds array access, and certain other run-time errors in C and C++ source code.

scan-build

Frontend to drive the Clang Static Analyzer built into Clang via a regular build.

splint

Annotation-assisted static program checker.

SVF

A static tool that enables scalable and precise interprocedural dependence analysis for C and C++ programs.

TrustInSoft Analyzer

copyright: — Exhaustive detection of coding errors and their associated security vulnerabilities. This encompasses a sound undefined behavior detection (buffer overflows, out-of-bounds array accesses, null-pointer dereferences, use-after-free, divide-by-zeros, uninitialized memory accesses, signed…

.NET Analyzers

An organization for the development of analyzers (diagnostics and code fixes) using the .NET Compiler Platform.

In 2 lists

ArchUnitNET

A C# architecture test library to specify and assert architecture rules in C# for automated testing.

Designite

copyright: — Designite supports detection of various architecture, design, and implementation smells, computation of various code quality metrics, and trend analysis.

In 2 lists

Meziantou.Analyzer

A Roslyn analyzer to enforce some good practices in C# in terms of design, usage, security, performance, and style.

NDepend

copyright: — Measure, query and visualize your code and avoid unexpected issues, technical debt and complexity.

Puma Scan

Puma Scan provides real time secure code analysis for common vulnerabilities (XSS, SQLi, CSRF, LDAPi, crypto, deserialization, etc.) as development teams write code in Visual Studio.

Roslynator

A collection of 190+ analyzers and 190+ refactorings for C#, powered by Roslyn.

In 2 lists

SonarAnalyzer.CSharp

These Roslyn analyzers allow you to produce Clean Code that is safe, reliable, and maintainable by helping you find and correct bugs, vulnerabilities, and code smells in your codebase.

clj-kondo

A linter for Clojure code that sparks joy. It informs you about potential errors while you are typing.

In 2 lists

Fixinator

copyright: — Static security code analysis for ColdFusion or CFML code. Designed to work within a CI pipeline or from the developers terminal.

ameba

A static code analysis tool for Crystal.

crystal

The Crystal compiler has built-in linting functionality.

In 4 listsDetails

lint

An opinionated, community-driven set of lint rules for Dart and Flutter projects. Like pedantic but stricter

DelphiLint

A Delphi IDE package providing on-the-fly code analysis and linting, powered by SonarDelphi.

Fix Insight

copyright: — A free IDE Plugin for static code analysis. A Pro edition includes a command line tool for automation purposes.

Pascal Analyzer

copyright: — A static code analysis tool with numerous reports. A free Lite version is available with limited reporting.

Pascal Expert

copyright: — IDE plugin for code analysis. Includes a subset of Pascal Analyzer reporting capabilities and is available for Delphi versions 2007 and later.

SonarDelphi

Delphi static analyzer for the SonarQube code quality platform.

In 2 lists

D-scanner

D-Scanner is a tool for analyzing D source code.

In 2 lists

credo

A static code analysis tool with a focus on code consistency and teaching.

In 2 lists

dialyxir

Mix tasks to simplify use of Dialyzer in Elixir projects.

In 2 lists

elm-review

Analyzes whole Elm projects, with a focus on shareable and custom rules written in Elm that add guarantees the Elm compiler doesn't give you.

dialyzer

The DIALYZER, a DIscrepancy AnaLYZer for ERlang programs. Dialyzer is a static analysis tool that identifies software discrepancies, such as definite type errors, code that has become dead or unreachable because of programming error, and unnecessary tests, in single Erlang modules or entire (sets…

elvis

Erlang Style Reviewer.

In 2 lists

fantomas

F# source code formatter.

FSharpLint

Lint tool for F#.

In 2 lists

ionide-analyzers

A collection of F# analyzers, built with the FSharp.Analyzers.SDK.

Fortitude

Fortran linter, inspired by (and built on) Ruff, and based on community best practices. Supports latest Fortran (2023) standard.

fprettify

Auto-formatter for modern fortran source code, written in Python. Fprettify is a tool that provides consistent whitespace, indentation, and delimiter alignment in code, including the ability to change letter case and handle preprocessor directives, all while preserving revision history and tested…

aligncheck

Find inefficiently packed structs.

In 2 lists

bodyclose

Checks whether HTTP response body is closed.

In 2 lists

dupl

Reports potentially duplicated code.

In 3 lists

errcheck

Check that error return values are used.

In 6 listsDetails

flen

Get info on length of functions in a Go package.

In 2 lists

go tool vet --shadow

Reports variables that may have been unintentionally shadowed.

In 2 lists

go-critic

Go source code linter that maintains checks which are currently not implemented in other linters.

In 4 listsDetails

go/ast

Package ast declares the types used to represent syntax trees for Go packages.

goast

Go AST (Abstract Syntax Tree) based static analysis tool with Rego.

goconst

Finds repeated strings that could be replaced by a constant.

In 3 lists

gocyclo

Calculate cyclomatic complexities of functions in Go source code.

gofmt -s

Checks if the code is properly formatted and could not be further simplified.

In 2 lists

gofumpt

Enforce a stricter format than gofmt, while being backwards-compatible. That is, gofumpt is happy with a subset of the formats that gofmt is happy with. The tool is a fork of gofmt as of Go 1.19, and requires Go 1.18 or later. It can be used as a drop-in replacement to format your Go code, and…

In 4 listsDetails

goimports

Checks missing or unreferenced package imports.

In 2 lists

GolangCI-Lint

Fast linters runner for Go. It aggregates multiple Go linters and provides a unified configuration, caching, and output format. Alternative to Go Meta Linter.

gosec (gas)

Inspects source code for security problems by scanning the Go AST.

gotype

Syntactic and semantic analysis similar to the Go compiler.

govulncheck

Govulncheck reports known vulnerabilities that affect Go code. It uses static analysis of source code or a binary's symbol table to narrow down reports to only those that could affect the application. By default, govulncheck makes requests to the Go vulnerability database at https://vuln.go.dev.…

OSV-Scanner

Vulnerability scanner written in Go which uses the data provided by OSV.dev. Developed by Google to scan dependencies across multiple languages and package managers for known vulnerabilities. Supports container scanning, license scanning, and guided remediation. Works with lockfiles, SBOMs, and…

In 3 lists

prealloc

Finds slice declarations that could potentially be preallocated.

In 2 lists

Reviewdog

A tool for posting review comments from any linter in any code hosting service.

In 2 lists

revive

Fast, configurable, extensible, flexible, and beautiful linter for Go. Drop-in replacement of golint.

staticcheck

Go static analysis that specialises in finding bugs, simplifying code and improving performance.

test

Show location of test failures from the stdlib testing module.

unconvert

Detect redundant type conversions.

In 3 lists

unparam

Find unused function parameters.

In 2 lists

wsl

Enforces empty lines at the right places.

CodeNarc

A static analysis tool for Groovy source code, enabling monitoring and enforcement of many coding standards and best practices.

HLint

HLint is a tool for suggesting possible improvements to Haskell code.

Liquid Haskell

Liquid Haskell is a refinement type checker for Haskell programs.

Stan

Stan is a command-line tool for analysing Haskell projects and outputting discovered vulnerabilities in a helpful way with possible solutions for detected problems.

Weeder

A tool for detecting dead exports or package imports in Haskell code.

Haxe Checkstyle

A static analysis tool to help developers write Haxe code that adheres to a coding standard.

Checker Framework

Pluggable type-checking for Java. This is not just a bug-finder, but a verification tool that gives a guarantee of correctness. It comes with 27 pre-built type systems, and it enables users to define their own type system; the manual lists over 30 user-contributed type systems.

checkstyle

Checking Java source code for adherence to a Code Standard or set of validation rules (best practices).

ck

Calculates Chidamber and Kemerer object-oriented metrics by processing the source Java files.

Dataflow Framework

An industrial-strength dataflow framework for Java. The Dataflow Framework is used in the Checker Framework, Google’s Error Prone, Uber’s NullAway, Meta’s Nullsafe, and in other contexts. It is distributed with the Checker Framework.

In 2 lists

DesigniteJava

copyright: — DesigniteJava supports detection of various architecture, design, and implementation smells along with computation of various code quality metrics.

Diffblue

copyright: — Diffblue is a software company that provides AI-powered code analysis and testing solutions for software development teams. Its technology helps developers automate testing, find bugs, and reduce manual labor in their software development processes. The company's main product,…

In 2 lists

Doop

Doop is a declarative framework for static analysis of Java/Android programs, centered on pointer analysis algorithms. Doop provides a large variety of analyses and also the surrounding scaffolding to run an analysis end-to-end (fact generation, processing, statistics, etc.).

Error Prone

Catch common Java mistakes as compile-time errors.

fb-contrib

A plugin for FindBugs with additional bug detectors.

forbidden-apis

Detects and forbids invocations of specific method/class/field (like reading from a text stream without a charset). Maven/Gradle/Ant compatible.

google-java-format

Reformats Java source code to comply with Google Java Style

In 2 lists

IntelliJ IDEA

copyright: — Comes bundled with a lot of inspections for Java and Kotlin and includes tools for refactoring, formatting and more.

In 8 listsDetails

JArchitect

copyright: — Measure, query and visualize your code and avoid unexpected issues, technical debt and complexity.

JBMC

Bounded model-checker for Java (bytecode), verifies user-defined assertions, standard assertions, several coverage metric analyses.

JLiSA

An abstract interpretation-based static analyzer for Java build upon the LiSA framekwork.

Mariana Trench

Our security focused static analysis tool for Android and Java applications. Mariana Trench analyzes Dalvik bytecode and is built to run fast on large codebases (10s of millions of lines of code). It can find vulnerabilities as code changes, before it ever lands in your repository.

NullAway

Type-based null-pointer checker with low build-time overhead; an Error Prone plugin.

In 3 lists

qulice

Combines a few (pre-configured) static analysis tools (checkstyle, PMD, Findbugs, ...).

RefactorFirst

Identifies and prioritizes God Classes and Highly Coupled classes in Java codebases you should refactor first.

In 2 lists

Soot

A framework for analyzing and transforming Java and Android applications.

Spoon

Spoon is a metaprogramming library to analyze and transform Java source code (incl Java 9, 10, 11, 12, 13, 14). It parses source files to build a well-designed AST with powerful analysis and transformation API. Can be integrated in Maven and Gradle.

SpotBugs

SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.

Violations Lib

Java library for parsing report files from static code analysis. Used by a bunch of Jenkins, Maven and Gradle plugins.

Closure Compiler

A compiler tool to increase efficiency, reduce size, and provide code warnings in JavaScript files.

DeepScan

copyright: — An analyzer for JavaScript which targets runtime errors and quality issues rather than coding conventions.

flow

A static type checker for JavaScript.

In 2 lists

JSLint

information_source: — The JavaScript Code Quality Tool.

In 2 lists

NodeJSScan

A static security code scanner for Node.js applications powered by libsast and semgrep that builds on the njsscan cli tool. It features a UI with various dashboards about an application's security status.

Polymer-analyzer

A static analysis framework for Web Components.

In 2 lists

retire.js

Scanner detecting the use of JavaScript libraries with known vulnerabilities.

In 2 lists

squirrelscan

squirrelscan is a website QA tool built for coding agents such as Claude Code and Cursor. Its squirrel CLI crawls a live site and runs 260+ audit rules across SEO, performance, security, accessibility, structured data and agent experience, then returns exact source-mapped fixes. Runs from the…

In 3 lists

tern

A JavaScript code analyzer for deep, cross-editor language support.

xo

Opinionated but configurable ESLint wrapper with lots of goodies included. Enforces strict and readable code.

In 4 listsDetails

JET

Static type inference system to detect bugs and type instabilities.

StaticLint

Static Code Analysis for Julia

detekt

Static code analysis for Kotlin code.

ktfmt

A program that reformats Kotlin source code to comply with the common community standard for Kotlin code conventions. A ktfmt IntelliJ plugin is available from the plugin repository. To install it, go to your IDE's settings and select the Plugins category. Click the Marketplace tab, search for the…

ktlint

An anti-bikeshedding Kotlin linter with built-in formatter.

luacheck

A tool for linting and static analysis of Lua code.

mlint

copyright: — Check MATLAB code files for possible problems.

DrNim

DrNim combines the Nim frontend with the Z3 proof engine in order to allow verify / validate software written in Nim.

In 2 lists

VeriFast

A tool for modular formal verification of correctness properties of single-threaded and multithreaded C and Java programs annotated with preconditions and postconditions written in separation logic. To express rich specifications, the programmer can define inductive datatypes, primitive recursive…

churn-php

Helps discover good candidates for refactoring.

composer-dependency-analyser

Fast detection of composer dependency issues.

In 2 lists

dephpend

Dependency analysis tool.

deptrac

Enforce rules for dependencies between software layers.

EasyCodingStandard

Combine PHP_CodeSniffer and PHP-CS-Fixer.

GrumPHP

Checks code on every commit.

larastan

Adds static analysis to Laravel improving developer productivity and code quality. It is a wrapper around PHPStan.

mago

Mago is a complete toolchain for PHP, written in Rust, designed from the ground up for maximum performance.

parallel-lint

This tool checks syntax of PHP files faster than serial check with a fancier output.

pdepend

Calculates software metrics like cyclomatic complexity for PHP code.

phan

A modern static analyzer from etsy.

In 2 lists

PHP Architecture Tester

Easy to use architecture testing tool for PHP.

PHP Coding Standards Fixer

Fixes your code according to standards like PSR-1, PSR-2, and the Symfony standard.

In 2 lists

PHP Insights

Instant PHP quality checks from your console. Analysis of code quality and coding style as well as overview of code architecture and its complexity.

In 2 lists

Php Inspections (EA Extended)

A Static Code Analyzer for PHP.

PHP Semantic Versioning Checker

Suggests a next version according to semantic versioning.

PHP-Parser

A PHP parser written in PHP.

PHPArkitect

PHPArkitect helps you to keep your PHP codebase coherent and solid, by permitting to add some architectural constraint check to your workflow. You can express the constraint that you want to enforce, in simple and readable PHP code.

phpDocumentor

Analyzes PHP source code to generate documentation.

PHPMD

Finds possible bugs in your code.

PhpMetrics

Calculates and visualizes various code quality metrics.

phpmnd

Helps to detect magic numbers.

PHPQA

A tool for running QA tools (phploc, phpcpd, phpcs, pdepend, phpmd, phpmetrics).

phpqa - jakzal

Many tools for PHP static analysis in one container.

PHPStan

PHP Static Analysis Tool - discover bugs in your code without running it!

Psalm

Static analysis tool for finding type errors in PHP applications.

rector

Instant Upgrades and Automated Refactoring of any PHP 5.3+ code. It upgrades your code for PHP 7.4, 8.0 and beyond. Rector promises a low false-positive rate because it looks for narrowly defined AST (abstract syntax tree) patterns. The main use-case are tackling technical debt in your legacy code…

Reflection

Reflection library to do Static Analysis for PHP Projects

Symfony Insight

copyright: — Detect security risks, find bugs and provide actionable metrics for PHP projects.

WAP

Tool to detect and correct input validation vulnerabilities in PHP (4.0 or higher) web applications and predicts false positives by combining static analysis and data mining.

ZPA

An open source parser and code analyzer for PL/SQL and Oracle SQL code.

Perl::Critic

Critique Perl source code for best-practices.

perltidy

Perltidy is a Perl script which indents and reformats Perl scripts to make them easier to read. The formatting can be controlled with command line parameters. The default parameter settings approximately follow the suggestions in the Perl Style Guide. Besides reformatting scripts, Perltidy can be…

zarn

A lightweight static security analysis tool for modern Perl Apps

autoflake

Autoflake removes unused imports and unused variables from Python code.

In 2 lists

autopep8

A tool that automatically formats Python code to conform to the PEP 8 style guide. It uses the pycodestyle utility to determine what parts of the code needs to be formatted.

bandit

A tool to find common security issues in Python code.

Black

The uncompromising Python code formatter.

deal

Design by contract for Python. Write bug-free code. By adding a few decorators to your code, you get for free tests, static analysis, formal verification, and much more.

Dlint

A tool for ensuring Python code is secure.

In 3 lists

fixit

A framework for creating lint rules and corresponding auto-fixes for source code.

flake8

A wrapper around pyflakes, pycodestyle and mccabe.

In 4 listsDetails

Griffe

Signatures for entire Python programs. Extract the structure, the frame, the skeleton of your project, to generate API documentation or find breaking changes in your API.

jedi

Autocompletion/static analysis library for Python.

mbake

mbake is a Makefile formatter and linter. It only took 50 years!

mccabe

Check McCabe complexity.

In 2 lists

mypy

A static type checker that aims to combine the benefits of duck typing and static typing, frequently used with MonkeyType.

pip-audit

Tool for scanning Python packages for known vulnerabilities. Developed by the Python Packaging Authority (PyPA) and supported by Trail of Bits and Google. Scans Python environments and requirements files to identify vulnerable packages and suggests remediation. Supports GitHub Actions, pre-commit…

In 2 lists

prospector

A wrapper around pylint, pep8, mccabe and others.

In 2 lists

pyanalyze

A tool for programmatically detecting common mistakes in Python code, such as references to undefined variables and type errors. It can be extended to add additional rules and perform checks specific to particular functions.

pycodestyle

(Formerly pep8) Check Python code against some of the style conventions in PEP 8.

pyflakes

Check Python source files for errors.

In 2 lists

pylint

Looks for programming errors, helps enforcing a coding standard and sniffs for some code smells. It additionally includes pyreverse (an UML diagram generator) and symilar (a similarities checker).

Pyra

Pyra is a high-level linter static analyzer for data science applications written in Python, that helps developers identify potential issues in their data science code written in Python, as an extension of Lyra.

pyre-check

A fast, scalable type checker for large Python codebases. Pyre-check has been superseded by Pyrefly, its next iteration.

pyrefly

A fast, incremental type checker and language server for Python, providing IDE features like code navigation, semantic highlighting, and code completion.

pyright

Static type checker for Python, created to address gaps in existing tools like mypy.

In 6 listsDetails

pyroma

Rate how well a Python project complies with the best practices of the Python packaging ecosystem, and list issues that could be improved.

Pysa

A tool based on Facebook's pyre-check to identify potential security issues in Python code identified with taint analysis.

pyscn

Intelligent Python code quality analyzer with CFG-based cyclomatic complexity analysis, dead code detection, clone detection (Type 1-4), and coupling metrics. Uses tree-sitter for parsing. Written in Go.

pytype

A static type analyzer for Python code.

pyupgrade

A tool (and pre-commit hook) to automatically upgrade syntax for newer versions of the language.

refurb

A tool for refurbishing and modernizing Python codebases. Refurb is heavily inspired by clippy, the built-in linter for Rust.

In 2 lists

ruff

Fast Python linter, written in Rust. 10-100x faster than existing linters. Compatible with Python 3.10. Supports file watcher.

Safety

Python dependency vulnerability scanner designed to enhance software supply chain security by detecting packages with known vulnerabilities. Checks Python dependencies against a database of known security vulnerabilities and provides detailed reports. Supports CI/CD integration and multiple output…

ty

An extremely fast Python type checker written in Rust.

unimport

A linter, formatter for finding and removing unused import statements.

vulture

Find unused classes, functions and variables in Python code.

In 5 listsDetails

wemake-python-styleguide

The strictest and most opinionated python linter ever.

wily

A command-line tool for archiving, exploring and graphing the complexity of Python source code.

In 2 lists

CodeDepends

Static Code Analysis for R.

flowR

A program slicer and dataflow analyzer for the R programming language. Its slicer allows you to reduce a complicated program just to the parts related for a specific task (e.g., the generation of a single or collection of plots, a significance test, ...). The dataflow analysis provides you with a…

goodpractice

Analyses the source code for R packages and provides best-practice recommendations.

lintr

Static Code Analysis for R.

In 2 lists

R Language Server

Provides code completion, refactoring, folding, diagnostics (with lintr), and more for R.

styler

Formatting of R source code files and pretty-printing of R code.

Regal

Regal is a linter for the policy language Rego. Regal aims to catch bugs and mistakes in policy code, while at the same time helping people learn the language, best practices and idiomatic constructs.

Active Record Doctor

Identify database issues before they hit production.

brakeman

A static analysis security vulnerability scanner for Ruby on Rails applications.

Bullet

Help to kill N+1 queries and unused eager loading.

In 3 lists

bundler-audit

Audit Gemfile.lock for gems with security vulnerabilities reported in Ruby Advisory Database.

In 4 listsDetails

DatabaseConsistency

The tool to avoid various issues due to inconsistencies and inefficiencies between a database schema and application models.

In 2 lists

ERB Lint

Lint your ERB or HTML files

flay

Flay analyzes code for structural similarities.

flog

Flog reports the most tortured code in an easy to read pain report. The higher the score, the more pain the code is in.

rails_best_practices

A code metric tool for Rails projects

reek

Code smell detector for Ruby.

In 3 lists

RuboCop

A Ruby static code analyzer, based on the community Ruby style guide.

rubycritic

A Ruby code quality reporter.

In 3 lists

rufo

An opinionated ruby formatter, intended to be used via the command line as a text-editor plugin, to autoformat files on save or on demand.

Skunk

A SkunkScore Calculator for Ruby Code -- Find the most complicated code without test coverage!

Sorbet

A fast, powerful type checker designed for Ruby.

Standard Ruby

Ruby Style Guide, with linter & automatic code fixer

Steep

Gradual Typing for Ruby.

In 2 lists

C2Rust

C2Rust helps you migrate C99-compliant code to Rust. The translator (or transpiler) produces unsafe Rust code that closely mirrors the input C code.

cargo udeps

Find unused dependencies in Cargo.toml. It either prints out a "unused crates" line listing the crates, or it prints out a line saying that no crates were unused.

In 2 lists

cargo-audit

Audit Cargo.lock for crates with security vulnerabilities reported to the RustSec Advisory Database.

cargo-deny

A cargo plugin for linting your dependencies. It can be used either as a command line too, a Rust crate, or a Github action for CI. It checks for valid license information, duplicate crates, security vulnerabilities, and more.

cargo-expand

Cargo subcommand to show result of macro expansion and #[derive] expansion applied to the current crate. This is a wrapper around a more verbose compiler command.

In 3 lists

cargo-geiger

A cargo plugin for analysing the usage of unsafe Rust code Provides statistical output to aid security auditing

In 2 lists

cargo-semver-checks

Scan your Rust crate releases for semver violations. It can be used either directly via the CLI, as a GitHub Action in CI, or via release managers like release-plz. It found semver violations in more than 1 in 6 of the top 1000 most-downloaded crates on crates.io.

cargo-show-asm

cargo subcommand showing the assembly, LLVM-IR and MIR generated for Rust code

cargo-spellcheck

Checks all your documentation for spelling and grammar mistakes with hunspell (ready) and languagetool (preview)

clippy

A code linter to catch common mistakes and improve your Rust code.

diff.rs

Web application (WASM) to render a diff between Rust crate versions.

dylint

A tool for running Rust lints from dynamic libraries. Dylint makes it easy for developers to maintain their own personal lint collections.

kani

The Kani Rust Verifier is a bit-precise model checker for Rust. Kani is particularly useful for verifying unsafe code blocks in Rust, where the "unsafe superpowers" are unchecked by the compiler. Kani verifies:

lockbud

Statically detects Rust deadlocks bugs. It currently detects two common kinds of deadlock bugs: doublelock and locks in conflicting order. It will print bugs in JSON format together with the source code location and an explanation of each bug.

Rudra

Rust Memory Safety & Undefined Behavior Detection. It is capable of analyzing single Rust packages as well as all the packages on crates.io.

rust-analyzer

Supports functionality such as 'goto definition', type inference, symbol search, reformatting, and code completion, and enables renaming and refactorings.

rust-audit

Audit Rust binaries for known bugs or security vulnerabilities. This works by embedding data about the dependency tree (Cargo.lock) in JSON format into a dedicated linker section of the compiled executable.

rustfmt

A tool for formatting Rust code according to style guidelines.

In 3 lists

RustViz

RustViz is a tool that generates visualizations from simple Rust programs to assist users in better understanding the Rust Lifetime and Borrowing mechanism. It generates SVG files with graphical indicators that integrate with mdbook to render visualizations of data-flow in Rust programs.

In 2 lists

TangleGuard

copyright: — Helps you understand and maintain a scalable software architecture. To do so, it generates a interactive, nested dependency graph out of the source code. You can choose the level of details and get the portion of your codebase that matters to you.

Bytebase

Database DevSecOps platform with a built-in SQL Review engine that lints schema migrations and queries against 100+ configurable rules — naming conventions, anti-patterns, and safety checks — across MySQL, PostgreSQL, Oracle, SQL Server, Snowflake, and more.

In 2 lists

dbcritic

dbcritic finds problems in a database schema, such as a missing primary key constraint in a table.

holistic

More than 1,300 rules to analyze SQL queries. Takes an SQL schema definition and the query source code to generate improvement recommendations. Detects code smells, unused indexes, unused tables, views, materialized views, and more.

In 2 lists

pgspot

Spot vulnerabilities in postgres extension scripts. Finds unsafe search_path usage and unsafe object creation in PostgreSQL extension scripts or any other PostgreSQL SQL code.

scythe

Polyglot SQL compiler and linter that generates type-safe code from SQL with schema-aware linting.

In 2 lists

SQLFluff

Multiple dialect SQL linter and formatter.

sqlint

Simple SQL linter.

squawk

Linter for PostgreSQL, focused on migrations. Prevents unexpected downtime caused by database migrations and encourages best practices around Postgres schemas and SQL.

tsqllint

T-SQL-specific linter.

In 3 lists

Visual Expert

copyright: — Code analysis for PowerBuilder, Oracle, and SQL Server Explores, analyzes, and documents Code

scapegoat

Scala compiler plugin for static code analysis.

WartRemover

A flexible Scala code linting tool.

sh

A shell parser, formatter, and interpreter with bash support; includes shfmt

shellcheck

ShellCheck, a static analysis tool that gives warnings and suggestions for bash/sh shell scripts.

In 2 lists

shellharden

A syntax highlighter and a tool to semi-automate the rewriting of scripts to ShellCheck conformance, mainly focused on quoting.

In 2 lists

SwiftFormat

A library and command-line formatting tool for reformatting Swift code.

In 4 listsDetails

SwiftLint

A tool to enforce Swift style and conventions.

Frink

A Tcl formatting and static check program (can prettify the program, minimise, obfuscate or just sanity check it).

Nagelfar

A static syntax checker for Tcl.

tclchecker

A static syntax analysis module (as part of TDK).

Angular ESLint

Linter for Angular projects

In 3 lists

fta

Rust-based static analysis for TypeScript projects

TypeScript Call Graph

CLI to generate an interactive graph of functions and calls from your TypeScript files

TypeScript ESLint

TypeScript language extension for eslint.

In 2 lists

zod

TypeScript-first schema validation with static type inference. The goal is to eliminate duplicative type declarations. With Zod, you declare a validator once and Zod will automatically infer the static TypeScript type. It is easy to compose simpler types into complex data structures.

svls

A Language Server Protocol implementation for Verilog and SystemVerilog, including lint capabilities.

Verilator

A tool which converts Verilog to a cycle-accurate behavioral model in C++ or SystemC. Performs lint code-quality checks.

In 2 lists

vscode-verilog-hdl-support

Verilog HDL/SystemVerilog/Bluespec SystemVerilog support for VS Code. Provides syntax highlighting and Linting support from Icarus Verilog, Vivado Logical Simulation, Modelsim and Verilator

Twiggy

Analyzes a binary's call graph to profile code size. The goal is to slim down wasm binary size.

wasm-language-tools

WebAssembly Language Tools aims to provide and improve the editing experience of WebAssembly Text Format. It also provides an out-of-the-box formatter (a.k.a. pretty printer) for WebAssembly Text Format.

angr

Binary code analysis tool that also supports symbolic execution.

In 5 listsDetails

BinSkim

A binary static analysis tool that provides security and correctness results for Windows portable executables.

Black Duck

copyright: — Tool to analyze source code and binaries for reusable code, necessary licenses and potential security aspects.

bloaty

Ever wondered what's making your binary big? Bloaty McBloatface will show you a size profile of the binary so you can understand what's taking up space inside. Bloaty performs a deep analysis of the binary. Using custom ELF, DWARF, and Mach-O parsers, Bloaty aims to accurately attribute every byte…

In 2 lists

cwe_checker

cwe_checker finds vulnerable patterns in binary executables.

In 5 listsDetails

Ghidra

A software reverse engineering (SRE) suite of tools developed by NSA's Research Directorate in support of the Cybersecurity mission

In 5 listsDetails

Hopper

copyright: — macOS and Linux reverse engineering tool that lets you disassemble, decompile and debug applications. Hopper displays the code using different representations, e.g. the Control Flow Graph, and the pseudo-code of a procedure. Supports Apple Silicon.

In 5 listsDetails

IDA Free

copyright: — Binary code analysis tool.

JEB Decompiler

copyright: — Decompile and debug binary code. Break down and analyze document files. Android Dalvik, MIPS, ARM, Intel x86, Java, WebAssembly & Ethereum Decompilers.

In 2 lists

Malcat

copyright: — Hexadecimal editor and disassembler for malware analysis and binary file inspection. Supports over 50 file formats and multiple CPU architectures (x86/x64, MIPS, .NET, Python, VB p-code). Features rapid analysis, embedded file extraction, Yara signature scanning, anomaly detection,…

In 2 lists

Manalyze

A static analyzer, which checks portable executables for malicious content.

In 3 lists

Nauz File Detector

Static Linker/Compiler/Tool detector for Windows, Linux and MacOS.

In 3 lists

rhabdomancer

IDA Pro headless plugin that locates calls to potentially insecure API functions in a binary file.

zydis

Fast and lightweight x86/x86-64 disassembler library

checkmake

Linter / Analyzer for Makefiles.

portlint

A verifier for FreeBSD and DragonFlyBSD port directories.

Nu Html Checker

Helps you catch problems in your HTML/CSS/SVG

PostCSS

A tool for transforming styles with JS plugins. These plugins can lint your CSS, support variables and mixins, transpile future CSS syntax, inline images, and more.

In 2 lists

Project Wallace CSS Analyzer

Analytics for CSS, part of Project Wallace.

Stylelint

Linter for SCSS/CSS files.

dotenv-linter

Linting dotenv files like a charm.

dotenv-linter (Rust)

Lightning-fast linter for .env files. Written in Rust

ansible-lint

Checks playbooks for practices and behaviour that could potentially be improved.

AWS CloudFormation Guard

Check local CloudFormation templates against policy-as-code rules and generate rules from existing templates.

cfn-lint

AWS Labs CloudFormation linter.

In 2 lists

checkov

Static analysis tool for Terraform files (tf>=v0.12), preventing cloud misconfigs at build time.

In 3 lists

cookstyle

Cookstyle is a linting tool based on the RuboCop Ruby linting tool for Chef cookbooks.

metadata-json-lint

Tool to check the validity of Puppet metadata.json files.

terraform-compliance

A lightweight, compliance- and security focused, BDD test framework against Terraform.

In 2 lists

terrascan

Collection of security and best practice tests for static code analysis of Terraform templates.

tflint

A Terraform linter for detecting errors that can not be detected by terraform plan.

tfsec

Terraform static analysis tool that prevents potential security issues by checking cloud misconfigurations at build time and directly integrates with the HCL parser for better results. Checks for violations of AWS, Azure and GCP security best practice recommendations.

In 2 lists

clair

Vulnerability Static Analysis for Containers.

In 3 lists

Dockle

Container Image Linter for Security helping build the Best-Practice Docker Image. Scans Docker images for security vulnerabilities and CIS Benchmark compliance. Checks for secrets, credential exposure, and security best practices. Provides multiple severity levels (FATAL, WARN, INFO) and supports…

In 3 lists

Grype

Vulnerability scanner for container images and filesystems. Developed by Anchore, it scans container images, directories, and archives for known vulnerabilities. Supports multiple image formats, SBOM integration, and VEX (Vulnerability Exploitability eXchange) for accurate vulnerability…

In 6 listsDetails

Haskell Dockerfile Linter

A smarter Dockerfile linter that helps you build best practice Docker images.

krane

Krane is a simple Kubernetes RBAC static analysis tool. It identifies potential security risks in K8s RBAC design and makes suggestions on how to mitigate them. Krane dashboard presents current RBAC security posture and lets you navigate through its definition.

OpenSCAP

Suite of automated audit tools to examine the configuration and known vulnerabilities following the NIST-certified Security Content Automation Protocol (SCAP).

In 3 lists

Qualys Container Security

copyright: — Container native application protection to provide visibility and control of containerized applications.

sysdig

copyright: — A secure DevOps platform for cloud and container forensics. Built on an open source stack, Sysdig provides Docker image scanning and created Falco, the open standard for runtime threat detection for containers, Kubernetes and cloud.

In 4 listsDetails

Vuls

Agent-less Linux vulnerability scanner based on information from NVD, OVAL, etc. It has some container image support, although is not a container specific tool.

actionlint

Static checker for GitHub Actions workflow files. Provides an online version.

Code Climate

The open and extensible static analysis platform, for everyone.

In 8 listsDetails

Codecov

copyright: — Codecov is a company that provides code coverage tools for developers and engineering leaders to gain visibility into their code coverage. They offer flexible and unified reporting, seamless coverage insights, and robust coverage controls. Codecov supports over 20 languages and is…

CodeRabbit

copyright: — AI-powered code review tool that helps developers write better code faster. CodeRabbit provides automated code reviews, identifies security vulnerabilities, and suggests code improvements. It integrates with GitHub and GitLab.

In 7 listsDetails

PullRequest

copyright: — Code review as a service with built-in static analysis. Increase velocity and reduce technical debt through quality code review by expert engineers backed by best-in-class automation.

In 2 lists

zizmor

Static analysis for GitHub Actions workflows, detecting insecure CI/CD patterns such as excessive token permissions, template injection risks, credential persistence, and unsafe workflow references.

deno_lint

Official linter for Deno.

Cloud (IaC) Security for JetBrains IDEs

Cloud (IaC) Security plugin for JetBrains IDEs. Performs real-time inspections of Docker & Kubernetes IaC with 50+ rules based on Docker image/build security best practices, Kubernetes Pod Security Standards, and NSA/CISA Kubernetes Hardening Guidance.

oelint-adv

Linter for bitbake recipes used in open-embedded and YOCTO

axe-core

Accessibility engine for automated Web UI testing. Tests HTML against WCAG 2.0, 2.1, and 2.2 guidelines. Used by Google Lighthouse, Microsoft Accessibility Insights, and thousands of organizations worldwide.

In 2 lists

HTML-Validate

Offline HTML5 validator.

HTMLHint

A Static Code Analysis Tool for HTML.

Pa11y

Automated accessibility testing tool that runs HTML CodeSniffer or axe-core from the command line. Supports CI/CD integration, multiple reporters, and testing against WCAG 2.1 AA standards.

In 2 lists

Spectral

A flexible JSON/YAML linter, with out-of-the-box support for OpenAPI v2/v3 and AsyncAPI v2.

chart-testing

ct is the tool for testing Helm charts. It is meant to be used for linting and testing pull requests. It automatically detects charts changed against the target branch.

clusterlint

Clusterlint queries live Kubernetes clusters for resources, executes common and platform specific checks against these resources and provides actionable feedback to cluster operators. It is a non invasive tool that is run externally. Clusterlint does not alter the resource configurations.

kube-hunter

Hunt for security weaknesses in Kubernetes clusters.

kube-linter

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.

In 2 lists

kube-score

Static code analysis of your Kubernetes object definitions.

kubeconform

A fast Kubernetes manifests validator with support for custom resources.

lacheck

A tool for finding common mistakes in LaTeX documents.

TeXLab

A Language Server Protocol implementation for TeX/LaTeX, including lint capabilities.

markdownlint

Node.js -based style checker and lint tool for Markdown/CommonMark files.

In 2 lists

mdformat

CommonMark compliant Markdown formatter

mdl

A tool to check Markdown files and flag style issues.

mdsf

Format markdown code blocks using your favorite code formatters.

remark-lint

Pluggable Markdown code style linter written in JavaScript.

In 2 lists

textlint

textlint is an open source text linting utility written in JavaScript.

In 3 lists

Android Lint

Run static analysis on Android projects.

FlowDroid

Static taint analysis tool for Android applications.

In 2 lists

Oversecured

copyright: — Enterprise vulnerability scanner for Android and iOS apps. It allows app owners and developers to secure each new version of a mobile app by integrating Oversecured into the development process.

In 3 lists

redex

Redex provides a framework for reading, writing, and analyzing .dex files, and a set of optimization passes that use this framework to improve the bytecode. An APK optimized by Redex should be smaller and faster.

deadnix

Scan Nix files for dead code (unused variable bindings)

In 2 lists

statix

Lints and suggestions for the Nix programming language. "statix check" highlights antipatterns in Nix code. "statix fix" can fix several such occurrences.

lockfile-lint

Lint an npm or yarn lockfile to analyze and detect security issues

In 3 lists

lintian

Static analysis tool for Debian packages.

rpmlint

Tool for checking common errors in rpm packages.

promformat

Promformat is a PromQL formatter written in Python.

buf

Provides a CLI linter that enforces good API design choices and structure

In 2 lists

protolint

Pluggable linter and fixer to enforce Protocol Buffer style and conventions.

In 2 lists

detect-secrets

An enterprise friendly way of detecting and preventing secrets in code. It does this by running periodic diff outputs against heuristically crafted regex statements, to identify whether any new secret has been committed. This way, it avoids the overhead of digging through all git history, as well…

In 3 lists

Gitleaks

A SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repos.

In 5 listsDetails

HasMySecretLeaked

copyright: — HasMySecretLeaked is a project from GitGuardian that aims to help individual users and organizations search across 20 million exposed secrets to verify if their developer secrets have leaked on public repositories, gists, and issues on GitHub projects.

OWASP Noir

Attack surface detector that identifies endpoints by static analysis.

PT Application Inspector

copyright: — Identifies code flaws and detects vulnerabilities to prevent web attacks. Demonstrates remote code execution by presenting possible exploits.

scorecard

Security Scorecards - Security health metrics for Open Source

In 3 lists

trufflehog

Find credentials all over the place TruffleHog is an open source secret-scanning engine that resolves exposed secrets across your company’s entire tech stack.

Tsunami Security Scanner

A general purpose network security scanner with an extensible plugin system for detecting high severity RCE-like vulnerabilities with high confidence. Custom detectors for finding vulnerabilities (e.g. open APIs) can be added.

In 3 lists

MythX

copyright: — MythX is an easy to use analysis platform which integrates several analysis methods like fuzzing, symbolic execution and static analysis to find vulnerabilities with high precision. It can be integrated with toolchains like Remix or VSCode or called from the command-line.

In 3 lists

slither

Static analysis framework that runs a suite of vulnerability detectors, prints visual information about contract details, and provides an API to easily write custom analyses.

solhint

Solhint is an open source project created by https://protofire.io. Its goal is to provide a linting utility for Solidity code.

haml-lint

Tool for writing clean and consistent HAML.

slim-lint

Configurable tool for analyzing Slim templates.

yamllint

Checks YAML files for syntax validity, key repetition and cosmetic problems such as lines length, trailing spaces, and indentation.

dennis

A set of utilities for working with PO files to ease development and improve quality.

codespell

Check code for common misspellings.

languagetool

Style and grammar checker for 25+ languages. It finds many errors that a simple spell checker cannot detect.

In 4 listsDetails

Misspelled Words In Context

A spell-checker that groups possible misspellings and shows them in their contexts.

proselint

A linter for English prose with a focus on writing style instead of grammar.

In 3 lists

vale

A syntax-aware linter for prose built with speed and extensibility in mind.

vastlint

copyright: — Validator and linter for VAST XML ad tags. Checks wrappers and inline tags against the IAB VAST 2.0-4.3 specification and can auto-fix deterministic issues.

In 2 lists

commitlint

checks if your commit messages meet the conventional commit format

Programming Languages

abaplint

Linter for ABAP, written in TypeScript.

abapOpenChecks

Enhances the SAP Code Inspector with new and customizable checks.

Polyspace for Ada

copyright: — Provide code verification that proves the absence of overflow, divide-by-zero, out-of-bounds array access, and certain other run-time errors in source code.

SPARK

copyright: — Static analysis and formal verification toolset for Ada.

Multiple languages

ale

Asynchronous Lint Engine for Vim and NeoVim with support for many languages.

In 2 lists

Android Studio

Based on IntelliJ IDEA, and comes bundled with tools for Android including Android Lint.

In 4 listsDetails

AppChecker

copyright: — Static analysis for C/C++/C#, PHP and Java.

Application Inspector

copyright: — Commercial Static Code Analysis which generates exploits to verify vulnerabilities.

ApplicationInspector

Creates reports of over 400 rule patterns for feature detection (e.g. the use of cryptography or version control in apps).

ArchUnit

Unit test your Java or Kotlin architecture.

AST Metrics

Multi-language maintainability analyzer. Computes cyclomatic and cognitive complexity, Halstead volume, afferent/efferent coupling and maintainability index, detects communities in the dependency graph, and generates an explorable HTML report plus JSON, Markdown, SARIF and OpenMetrics output.…

ast-grep

ast-grep is a powerful tool designed for managing code at scale using Abstract Syntax Trees (AST). Think of it as a hybrid of grep, eslint, and codemod, with the ability to search, lint, and rewrite code based on its structure rather than plain text. It supports multiple languages and is designed…

autocorrect

A linter and formatter to help you to improve copywriting, correct spaces, words, punctuations between CJK (Chinese, Japanese, Korean).

Axivion Bauhaus Suite

copyright: — Tracks down error-prone code locations, style violations, cloned or dead code, cyclic dependencies and more for C/C++, C#/.NET, Java and Ada 83/Ada 95.

Bearer

Open-Source static code analysis tool to discover, filter and prioritize security risks and vulnerabilities leading to sensitive data exposures (PII, PHI, PD). Highly configurable and easily extensible, built for security and engineering teams.

In 6 listsDetails

Better Code Hub

copyright: — Better Code Hub checks your GitHub codebase against 10 engineering guidelines devised by the authority in software quality, Software Improvement Group.

In 2 lists

biome

A toolchain for web projects, aimed to provide functionalities to maintain them. Biome formats and lints code in a fraction of a second. It is the successor to Rome. It is designed to eventually replace Biome is designed to eventually replace Babel, ESLint, webpack, Prettier, Jest, and others.

In 2 lists

BlockWatch

A language-agnostic linter that keeps code, documentation, and configuration in sync and enforces strict formatting and validation rules.

In 2 lists

CAST Highlight

copyright: — Commercial Static Code Analysis which runs locally, but uploads the results to its cloud for presentation.

Checkmarx CxSAST

copyright: — Commercial Static Code Analysis which doesn't require pre-compilation.

ClassGraph

A classpath and module path scanner for querying or visualizing class metadata or class relatedness.

In 2 lists

Clayton

copyright: — AI-powered code reviews for Salesforce. Secure your developments, enforce best practice and control your technical debt in real-time.

In 2 lists

Cobra

copyright: — Structural source code analyzer by NASA's Jet Propulsion Laboratory.

Codacy

copyright: — Code Analysis to ship Better Code, Faster.

In 8 listsDetails

Code Intelligence

copyright: — CI/CD-agnostic DevSecOps platform which combines industry-leading fuzzing engines for finding bugs and visualizing code coverage

In 2 lists

Code Pathfinder

Opensource Static Code Analysis for security teams with Inter file dataflow taint analysis. Built for finding vulnerabilities, advanced structural search, derive insights and supports MCP server.

Code-Graph-RAG

Builds knowledge graphs from multi-language codebases using Tree-sitter AST parsing and stores them in Memgraph. Supports 11 programming languages with a unified graph schema and enables natural language querying and editing of code structure and relationships. Functions as an MCP server for AI…

Codeac

copyright: — Automated code review tool integrates with GitHub, Bitbucket and GitLab (even self-hosted). Available for JavaScript, TypeScript, Python, Ruby, Go, PHP, Java, Docker, and more. (open-source free)

CodeFactor

copyright: — Automated Code Analysis for repos on GitHub or BitBucket.

In 3 lists

CodeFlow

copyright: — Automated code analysis tool to deal with technical depth. Integrates with Bitbucket and Gitlab. (free for Open Source Projects)

codeql

Deep code analysis - semantic queries and dataflow for several languages with VSCode plugin support.

CodeQue

Ecosystem for structural matching JavaScript and TypeScript code. Offers search tool that understands code structure. Available as CLI tool and Visual Studio Code extension. It helps to search code faster and more accurately making you workflow more effective. Soon it will offer ESLint plugin to…

CodeRush

copyright: — Code creation, debugging, navigation, refactoring, analysis and visualization tools that use the Roslyn engine in Visual Studio 2015 and up.

CodeScan

copyright: — Code Quality and Security for Salesforce Developers. Made exclusively for the Salesforce platform, CodeScan’s code analysis solutions provide you with total visibility into your code health.

CodeScene

copyright: — CodeScene is a quality visualization tool for software. Prioritize technical debt, detect delivery risks, and measure organizational aspects. Fully automated.

CodeSonar from GrammaTech

copyright: — Advanced, whole program, deep path, static analysis of C, C++, Java and C# with easy-to-understand explanations and code and path visualization.

Codiga

copyright: — Automated Code Reviews and Technical Debt management platform that supports 12+ languages.

Corgea

copyright: — Corgea is an AI-powered SAST scanner that helps developers find and fix insecure code. It finds business logic flaws, broken authentication, API vulnerabilities, and more with little false positives. Additionally, it automatically writes security fixes for them to approve. Corgea…

In 2 lists

Coverity

copyright: — Synopsys Coverity supports 20 languages and over 70 frameworks including Ruby on rails, Scala, PHP, Python, JavaScript, TypeScript, Java, Fortran, C, C++, C#, VB.NET.

cpp-linter-action

A Github Action for linting C/C++ code integrating clang-tidy and clang-format to collect feedback provided in the form of thread comments and/or annotations.

DeepSource

copyright: — In-depth static analysis to find issues in verticals of bug risks, security, anti-patterns, performance, documentation and style. Native integrations with GitHub, GitLab and Bitbucket. Less than 5% false positives.

deleaker

copyright: — Deleaker is a memory leak detection tool for C++, .NET, and Delphi, integrating with Visual Studio, Qt Creator, and RAD Studio or running as a standalone application. It helps developers find and fix memory, GDI, and handle leaks efficiently.

In 2 lists

Depends

Analyses the comprehensive dependencies of code elements for Java, C/C++, Ruby.

DepWarden

copyright: — Free, anonymous SCA + SAST scanner. SCA: scans npm, PyPI, Maven, Go, Cargo, Ruby, NuGet dependencies for CVEs (OSV/KEV/EPSS), typosquats and supply-chain risk. SAST: pattern + taint analysis for 15 languages, 300+ rules. No account, no source upload. Available as a web tool,…

DerScanner

copyright: — Multi-language Static Application Security Testing (SAST) platform that detects critical vulnerabilities, including hardcoded secrets, weak cryptography, backdoors, SQL injections, insecure configurations, etc.

DevSkim

Regex-based static analysis tool for Visual Studio, VS Code, and Sublime Text - C/C++, C#, PHP, ASP, Python, Ruby, Java, and others.

In 5 listsDetails

diesel-guard

Linter for dangerous Postgres migration patterns in Diesel and SQLx. Prevents downtime caused by unsafe schema changes.

In 3 lists

dotnet-format

A code formatter for .NET. Preferences will be read from an .editorconfig file, if present, otherwise a default set of preferences will be used. At this time dotnet-format is able to format C# and Visual Basic projects with a subset of supported .editorconfig options.

Embold

copyright: — Intelligent software analytics platform that identifies design issues, code issues, duplication and metrics. Supports Java, C, C++, C#, JavaScript, TypeScript, Python, Go, Kotlin and more.

In 2 lists

emerge

Emerge is a source code and dependency visualizer that can be used to gather insights about source code structure, metrics, dependencies and complexity of software projects. After scanning the source code of a project it provides you an interactive web interface to explore and analyze your project…

Enforster AI

copyright: — Enforster AI performs Contextual Code Security SAST, leveraging LLMs and artificial intelligence to reduce and enrich the detection of Logic Flaws, Secrets, Data leaks, Supply chain and technical vulnerabilities.

ESLint

An extensible linter for JS, following the ECMAScript standard.

In 7 listsDetails

ezno

A JavaScript compiler and TypeScript checker written in Rust with a focus on static analysis and runtime performance. Ezno's type checker is built from scratch. The checker is fully compatible with TypeScript type annotations and can work without any type annotations at all.

Fallow

Rust-native static analysis for JavaScript and TypeScript. Maps a repository as one dependency graph to find unused code and structural problems across file boundaries. Runs from the CLI or GitHub Actions, with VS Code, LSP, MCP, and Node API integrations.

Find Security Bugs

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

Fortify

copyright: — A commercial static analysis platform that supports the scanning of C/C++, C#, VB.NET, VB6, ABAP/BSP, ActionScript, Apex, ASP.NET, Classic ASP, VB Script, Cobol, ColdFusion, HTML, Java, JS, JSP, MXML/Flex, Objective-C, PHP, PL/SQL, T-SQL, Python (2.6, 2.7), Ruby (1.9.3), Swift, Scala,…

Freeplane Code Explorer

The Code Explorer mode in Freeplane is designed for analyzing the structure and dependencies of code compiled to JVM class files. It also allows displaying ArchUnit test results directly in Freeplane, if Freeplane is running and ArchUnit detects rule violations during the tests.

Goodcheck

Regexp based customizable linter.

graudit

Grep rough audit - source code auditing tool.

HCL AppScan Source

copyright: — Commercial Static Code Analysis.

Hound CI

Comments on style violations in GitHub pull requests. Supports Coffeescript, Go, HAML, JavaScript, Ruby, SCSS and Swift.

In 7 listsDetails

Infer

A static analyzer for Java, C and Objective-C

In 2 lists

Inkog

AI agent security scanner. Detects behavioral vulnerabilities (prompt injection, infinite loops, token bombing, SQL injection via LLM) across 11 framework adapters including LangChain, CrewAI, and pydantic-ai. Audits MCP servers. Maps findings to EU AI Act, OWASP LLM Top 10, and NIST AI RMF.

Joern

Joern is a platform for analyzing source code, bytecode, and binary executables. It generates code property graphs (CPGs), a graph representation of code for cross-language code analysis. Code property graphs are stored in a custom graph database. This allows code to be mined using search queries…

jQAssistant

jQAssistant is a plugin based software analytics platform which allows scanning code structures and metadata from repositories into a Neo4j graph database. The gathered data can be used for ad-hoc exploration using queries, visualization or defining rules for continuous architecture validation.

jscpd

Copy/paste detector for programming source code. Finds duplicated blocks in 200+ file formats — JavaScript, TypeScript, Python, Java, C#, C/C++, Go, Rust, PHP, Ruby and more — using token-based detection. Supports configurable thresholds and ignore patterns, git blame integration, and reporters…

keploy

Keploy is an open-source testing platform that helps developers automate and streamline their testing process. It provides API, and integration testing agents, generating tests, mocks/stubs for APIs that actually work. Additionally, Keploy offers an AI-powered Unit Testing Agent that generates…

In 8 listsDetails

Kiuwan

copyright: — Identify and remediate cyber threats in a blazingly fast, collaborative environment, with seamless integration in your SDLC. Python, C\C++, Java, C#, PHP and more.

Klocwork

copyright: — Quality and Security Static analysis for C/C++, Java and C#.

LGTM

copyright: — Find security vulnerabilities, variants, and critical code quality issues using CodeQL queries over source code. Automatic PR code review; free for open source. Formerly semmle. It supports public Git repositories hosted on Bitbucket Cloud, GitHub.com, GitLab.com.

In 4 listsDetails

lizard

Lizard is an extensible Cyclomatic Complexity Analyzer for many programming languages including C/C++ (doesn't require all the header files or Java imports). It also does copy-paste detection (code clone detection/code duplicate detection) and many other forms of static code analysis. Counts lines…

Mega-Linter

Mega-Linter can handle any type of project thanks to its 70+ embedded Linters, its advanced reporting, runnable on any CI system or locally, with assisted installation and configuration, able to apply formatting and fixes

Mobb

copyright: — Mobb is a trusted, automatic vulnerability fixer that secures applications, reduces security backlogs, and frees developers to focus on innovation. Mobb is free for open-source projects.

MOPSA

A static analyzer designed to easily reuse abstract domains across widely different languages (such as C and Python).

nestjs-doctor

Static analysis tool for NestJS applications. Detects anti-patterns across security, performance, correctness, and architecture with 30+ built-in rules. Outputs a 0-100 health score. Includes module graph visualization, endpoint dependency graphs, and database schema analysis. CLI and VS Code…

In 2 lists

Neurolint-CLI

Deterministic code transformation tool using AST parsing and rule-based transformations. Automatically fixes 50+ issues including accessibility violations, hydration errors, React 19/Next.js 16 migrations, and configuration updates. Features 5-step fail-safe orchestration to ensure zero breaking…

oclint

A static source code analysis tool to improve quality and reduce defects for C, C++ and Objective-C.

In 2 lists

Offensive 360

copyright: — Commercial Static Code Analysis system doesn't require building the source code or pre-compilation.

OpenRewrite

OpenRewrite fixes common static analysis issues reported through Sonar and other tools using a Maven and Gradle plugin or the Moderne CLI.

OpenStaticAnalyzer

OpenStaticAnalyzer is a source code analyzer tool, which can perform deep static analysis of the source code of complex systems.

OpenTaint

Open-source taint analysis engine for Java and Kotlin applications, formerly Seqra. Tracks data flow across function boundaries to find security vulnerabilities, with Spring support, YAML rules, and CI integrations.

oxc

The Oxidation Compiler is creating a suite of high-performance tools for the JavaScript / TypeScript language re-written in Rust.

parasoft

copyright: — Automated Software Testing Solutions for unit-, API-, and web UI testing. Complies with MISRA, OWASP, and others.

In 2 lists

pfff

Facebook's tools for code analysis, visualizations, or style-preserving source transformation for many languages.

Pixee

copyright: — Pixeebot finds security and code quality issues in your code and creates merge-ready pull requests with recommended fixes.

In 3 lists

PMD

A source code analyzer for Java, Salesforce Apex, Javascript, PLSQL, XML, XSL and others.

pre-commit

A framework for managing and maintaining multi-language pre-commit hooks.

In 3 lists

Precaution

Precaution is a static analysis security tool (SAST) designed to find potentially critical vulnerabilities in source code prior to production. It is available as a CLI, GitHub Action, and GitHub App.

Prettier

An opinionated code formatter.

In 3 lists

Pronto

Quick automated code review of your changes. Supports more than 40 runners for various languages, including Clang, Elixir, JavaScript, PHP, Ruby and more.

In 2 lists

Putout

Pluggable and configurable code transformer with built-in eslint, babel plugins support for js, jsx typescript, flow, markdown, yaml and json.

In 3 lists

PVS-Studio

copyright: — PVS-Studio is a SAST tool that enhances code quality, security, and safety. Supported languages: C, C++, C#, Java, Go, JavaScript and TypeScript. Works on Windows, macOS, Linux. Supports intermodular, incremental, data flow analysis, taint analysis. Provides compliance with OWASP TOP…

Qwiet AI

copyright: — Identify vulnerabilities that are unique to your code base before they reach production. Leverages the Code Property Graph (CPG) to run its analyses concurrently in a single graph of graphs. Automatically finds business logic flaws in dev like hardcoded secrets and logic bombs

relint

A static file linter that allows you to write custom rules using regular expressions (RegEx).

Repowise

Deterministic, zero-LLM code-health analysis. Scores every file 1-10 for defect risk, maintainability, and performance from 25 markers: McCabe complexity, LCOM4 cohesion, god classes, Rabin-Karp clone detection, change entropy, and untested hotspots. Adds a dependency graph, dead-code detection,…

ReSharper

copyright: — Extends Visual Studio with on-the-fly code inspections for C#, VB.NET, ASP.NET, JavaScript, TypeScript and other technologies.

Rev-dep

Dependency analysis and optimization toolkit for modern JavaScript and TypeScript projects. Trace imports, identify circular dependencies, find unused code, clean node modules.

In 2 lists

RIPS

copyright: — A static source code analyser for vulnerabilities in PHP scripts.

In 3 lists

Roslyn Analyzers

Roslyn-based implementation of FxCop analyzers.

In 4 listsDetails

SafeQL

Validate and auto-generate TypeScript types from raw SQL queries in PostgreSQL. SafeQL is an ESLint plugin for writing SQL queries in a type-safe way.

SAST Online

copyright: — Check the Android Source code thoroughly to uncover and address potential security concerns and vulnerabilities. Static application security testing (Static Code Analysis) tool Online

sem

Semantic version control CLI that provides entity-level diffs, blame, and impact analysis on top of git. Uses tree-sitter to parse 26 languages and builds a cross-file dependency graph with structural hashing. Commands include sem diff, sem blame, sem graph, and sem impact for blast-radius…

In 2 lists

Semgrep

A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.

In 4 listsDetails

Semgrep Supply Chain

copyright: — Quickly find and remediate high-priority security issues. Semgrep Supply Chain prioritizes the 2% of vulnerabilities that are reachable from your code.

Sigrid

copyright: — Sigrid helps you to improve your software by measuring your system's code quality, and then compares the results against a benchmark of thousands of industry systems to give you concrete advice on areas where you can improve.

Similarity Tester

A tool that finds similarities between or within files to support you encountering DRY principle violations.

Skylos

Dead code detection, security scanning, secrets detection, and code quality analysis for Python, TypeScript, and Go. Framework-aware analysis with 98% recall. Includes CI/CD GitHub Action, VS Code extension, and MCP server for AI agent integration.

Snyk Code

copyright: — Snyk Code finds security vulnerabilities based on AI. Its speed of analysis allow us to analyse your code in real time and deliver results when you hit the save button in your IDE. Supported languages are Java, JavaScript, Python, PHP, C#, Go and TypeScript. Integrations with GitHub,…

In 14 listsDetails

SonarQube Cloud

copyright: — SonarQube Cloud enables your team to deliver clean code consistently and efficiently with a code review tool that easily integrates into the cloud DevOps platforms and extend your CI/CD workflow. SonarQube Cloud provides a free plan.

In 3 lists

SonarQube for IDE

SonarQube for IDE (formerly SonarLint) is a free IDE extension available for IntelliJ, VS Code, Visual Studio, and Eclipse, to find and fix coding issues in real-time, flagging issues as you code, just like a spell-checker. More than a linter, it also delivers rich contextual guidance to help…

In 2 lists

SonarQube Server

SonarQube empowers development teams with a code quality and security solution that deeply integrates into your enterprise environment; enabling you to deploy clean code consistently and reliably. SonarQube provides a free and open source Community Build.

In 6 listsDetails

Sonatype

copyright: — Reports known vulnerabilities in common dependencies and recommends updated packages to minimize breaking changes

Soto Platform

copyright: — Suite of static analysis tools consisting of the three components Sotoarc (Architecture Analysis), Sotograph (Quality Analysis), and Sotoreport (Quality report). Helps find differences between architecture and implementation, interface violations (e.g. external access of private parts…

SourceMeter

copyright: — Static Code Analysis for C/C++, Java, C#, Python, and RPG III and RPG IV versions (including free-form).

sqlvet

Performs static analysis on raw SQL queries in your Go code base to surface potential runtime errors. It checks for SQL syntax error, identifies unsafe queries that could potentially lead to SQL injections makes sure column count matches value count in INSERT statements and validates table- and…

StaticReviewer

copyright: — Static Reviewer executes code checks according to the most relevant Secure Coding Standards, OWASP, CWE, CVE, CVSS, MISRA, CERT, for 40+ programming languages, using 1000+ built-in validation rules for Security, Deadcode & Best Practices Available a module for Software Composition…

Super-Linter

Combination of multiple linters to install as a GitHub Action.

Svace

copyright: — Static code analysis tool for Java,C,C++,C#,Go.

Teamscale

copyright: — Static and dynamic analysis tool supporting more than 25 languages and direct IDE integration. Free hosting for Open Source projects available on request. Free academic licenses available.

TencentCodeAnalysis

Tencent Cloud Code Analysis (TCA for short, code-named CodeDog inside the company early) is a comprehensive platform for code analysis and issue tracking. TCA consist of three components, server, web and client. It integrates of a number of self-developed tools, and also supports dynamic…

thailint

Multi-language linter targeting anti-patterns that appear disproportionately in AI-generated code: duplicated blocks across files, excessive nesting, magic numbers, Single Responsibility violations, and linter suppressions added without justification. Covers Python, TypeScript, JavaScript and Rust…

ThreatMapper

Vulnerability Scanner and Risk Evaluation for containers, serverless and hosts at runtime. ThreatMapper generates runtime BOMs from dependencies and operating system packages, matches against multiple threat feeds, scans for unprotected secrets, and scores issues based on severity and…

In 6 listsDetails

todocheck

Linter for integrating annotated TODOs with your issue trackers

In 3 lists

trivy

A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI. Trivy detects vulnerabilities of OS packages (Alpine, RHEL, CentOS, etc.) and application dependencies (Bundler, Composer, npm, yarn, etc.). Checks containers and filesystems.

In 9 listsDetails

trunk

copyright: — Modern repositories include many technologies, each with its own set of linters. With 30+ linters and counting, Trunk makes it dead-simple to identify, install, configure, and run the right linters, static analyzers, and formatters for all your repos.

In 2 lists

Understand

copyright: — Code visualization tool that provides code analysis, standards testing, metrics, graphing, dependency analysis and more for Ada, VHDL, and others.

Unibeautify

Universal code beautifier with a GitHub app. Supports HTML, CSS, JavaScript, TypeScript, JSX, Vue, C++, Go, Objective-C, Java, Python, PHP, GraphQL, Markdown, and more.

Upsource

copyright: — Code review tool with static code analysis and code-aware navigation for Java, PHP, JavaScript and Kotlin.

In 4 listsDetails

Veracode

copyright: — Find flaws in binaries and bytecode without requiring source. Support all major programming languages: Java, .NET, JavaScript, Swift, Objective-C, C, C++ and more.

Wakaru

JavaScript decompiler that turns bundled, minified, transpiled production code back into readable modules. Unpacks webpack, esbuild, Metro, Browserify, SystemJS, and AMD/UMD bundles, then reverses minifier artifacts and Babel/TypeScript/SWC helpers (async/await, classes, optional chaining, and…

WALA

Static analysis capabilities for Java bytecode and related languages and for JavaScript.

weave

Entity-level semantic merge driver for git. Resolves false conflicts that line-based merge produces when independent changes touch the same file. Parses functions and classes via tree-sitter, matches by name, and merges at the entity level. Benchmarked at 100% clean merges vs git's 48% on a…

In 2 lists

WhiteHat Application Security Platform

copyright: — WhiteHat Scout (for Developers) combined with WhiteHat Sentinel Source (for Operations) supporting WhiteHat Top 40 and OWASP Top 10.

XCode

copyright: — XCode provides a pretty decent UI for Clang's static code analyzer (C/C++, Obj-C).

In 5 listsDetails

Xygeni

copyright: — Xygeni is a comprehensive Software Supply Chain Security platform. It provides Advanced SAST with AI-powered remediation, Software Composition Analysis (SCA) with real-time malware detection, Infrastructure as Code (IaC) scanning, and Secrets detection to ensure end-to-end code…

Other

GitGuardian ggshield

ggshield is a CLI application that runs in your local environment or in a CI environment to help you detect more than 350+ types of secrets, as well as other potential security vulnerabilities or policy breaks affecting your codebase.

thailint

Multi-language linter targeting anti-patterns that appear disproportionately in AI-generated code: duplicated blocks across files, excessive nesting, magic numbers, Single Responsibility violations, and linter suppressions added without justification. Covers Python, TypeScript, JavaScript and Rust…

LintLang

Static linter for natural-language instructions that control AI agents. Detects ambiguous tool descriptions, missing limits, conflicting directives, and schema gaps in local files and CI without model or network calls.

skillsaw

Configurable linter for the files that steer AI coding agents, including skills, plugins, instruction files, hooks, and related configuration. Detects structural, content-quality, and security issues and provides deterministic autofixes, baselines, and CI-ready output.

trentclaw

Security assessment for your OpenClaw agent environment. Flags misconfigurations and risky skills — prompt injection, permission escalation, data exfiltration — and the chained attack paths between them, across gateway config, tool permissions, MCP servers, and plugins.

kics

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations in your infrastructure-as-code. Supports Terraform, Kubernetes, Docker, AWS CloudFormation and Ansible

Steampunk Spotter

copyright: — Ansible Playbook Scanning Tool that analyzes and offers recommendations for your playbooks.

In 2 lists

packj

Packj (pronounced package) is a command line (CLI) tool to vet open-source software packages for "risky" attributes that make them vulnerable to supply chain attacks. This is the tool behind our large-scale security analysis platform Packj.dev that continuously vets packages and provides free…

More collections

AppSec Santa — SAST Tools

Independent comparison of 30+ static analysis security testing tools with features, pricing, and alternatives

Clean code linters

A collection of linters in github collections

Code Quality Checker Tools For PHP Projects

A collection of PHP linters in github collections

go-tools

A collection of tools and libraries for working with Go code, including linters and static analysis

In 5 listsDetails

linters

An introduction to static code analysis

OWASP Source Code Analysis Tools

List of tools maintained by the Open Web Application Security Project

In 2 lists

php-static-analysis-tools

A reviewed list of useful PHP static analysis tools

Wikipedia

A list of tools for static code analysis.

In 2 lists
See category
94

Table of Contents

hesreallyhim/awesome-claude-code

A hand-picked collection of the finest of resources for the most awesome of agents, Claude Code, the undisputed champion of coding companions, from the unstoppable team…

Fresh★ 55k202 entriesPushed today
94

Awesome Agent Skills

VoltAgent/awesome-agent-skills

A curated collection of 1000+ agent skills from official dev teams and the community, compatible with Claude Code, Codex, Gemini CLI, Cursor, and more.

Fresh★ 35k839 entriesPushed today
93

Awesome Machine Learning

josephmisiti/awesome-machine-learning

A curated list of awesome Machine Learning frameworks, libraries and software.

Fresh★ 74k1188 entriesPushed 7 days ago
92

Awesome Production Machine Learning

EthicalML/awesome-production-machine-learning

A curated list of awesome open source libraries to deploy, monitor, version and scale your machine learning

Fresh★ 21k519 entriesPushed 3 days ago
92

AWESOME DATA SCIENCE

academic/awesome-datascience

:memo: An awesome Data Science repository to learn and apply for real world problems.

Fresh★ 30k881 entriesPushed today
90

Awesome LangChain

kyrolabs/awesome-langchain

😎 Awesome list of tools and projects with the awesome LangChain framework

Fresh★ 9.6k216 entriesPushed 6 days ago