SonarQube Server is a static code analysis platform that performs automated security testing and code quality assessment across multiple programming languages. The platform implements static application security testing (SAST) capabilities to identify security vulnerabilities, code defects, and maintainability issues during the development process. Core functionalities: - Continuous code analysis with support for over 6,000 predefined rules - Integration with common CI/CD platforms and development environments - Implementation of quality gates to enforce security and coding standards - Detection of exposed secrets and credentials in source code - Taint analysis for tracking data flow and identifying security weaknesses - Code coverage measurement and tracking capabilities - AI-assisted code review with remediation suggestions Technical capabilities: - Multi-language support including Java, JavaScript, Python, C#, and C++ - On-premises or cloud deployment options - Container-based installation support - IDE plugin integration for real-time analysis - Multi-threaded analysis processing - Centralized configuration management Security and compliance features: - Automated vulnerability detection and classification - Compliance checking against security standards like NIST SSDF - Security metrics and reporting functionality - Project portfolio security management - Team collaboration and review tools
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
ffufai is an AI-enhanced wrapper for ffuf that automatically suggests file extensions for web fuzzing based on the target URL and headers.
SearchCode is an extensive code search engine that indexes 75 billion lines of code from millions of projects to help developers find coding examples and libraries.
An open-source tool for detecting and analyzing Android apps' vulnerabilities and security issues.
A full python tool for analyzing Android files with various functionalities.
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.
A tool to conduct preliminary security checks in code, infrastructure, or IAM configurations using various open-source tools.
A PHP port of Rack::Honeypot, a spam trap that detects and blocks spambots
An integrated application security platform that combines multiple security scanning tools with developer-focused workflows for automated code and infrastructure security testing.
A Dynamic Application Security Testing (DAST) platform that provides automated security testing for web applications, APIs, and LLM-powered applications throughout the software development lifecycle.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.