{"id":88170,"url":"https://github.com/correia-jpv/fucking-static-analysis","name":"fucking-static-analysis","description":"⚙️ A curated list of static analysis (SAST) tools for all programming languages, config files, build tools, and more. With repository stars⭐ and forks🍴","projects_count":263,"last_synced_at":"2026-09-25T20:00:39.449Z","repository":{"id":38126602,"uuid":"456141208","full_name":"Correia-jpv/fucking-static-analysis","owner":"Correia-jpv","description":"⚙️ A curated list of static analysis (SAST) tools for all programming languages, config files, build tools, and more. With repository stars⭐ and forks🍴","archived":false,"fork":false,"pushed_at":"2026-09-22T06:40:28.000Z","size":42278,"stargazers_count":28,"open_issues_count":2,"forks_count":2,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-09-22T09:43:55.854Z","etag":null,"topics":["analysis","awesome","awesome-list","code-quality","lint","linter","sast","static-analysis","static-analyzer","static-code-analysis"],"latest_commit_sha":null,"homepage":"","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Correia-jpv.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","claude":"CLAUDE.md","gemini":null,"cursor":".cursorrules","copilot":".github/copilot-instructions.md","dco":null,"cla":null,"disclosure":null},"funding":{"github":"Correia-jpv"}},"created_at":"2022-02-06T12:13:39.000Z","updated_at":"2026-09-22T06:40:15.000Z","dependencies_parsed_at":"2026-09-22T08:47:58.731Z","dependency_job_id":null,"html_url":"https://github.com/Correia-jpv/fucking-static-analysis","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/Correia-jpv/fucking-static-analysis","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Correia-jpv%2Ffucking-static-analysis","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Correia-jpv%2Ffucking-static-analysis/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Correia-jpv%2Ffucking-static-analysis/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Correia-jpv%2Ffucking-static-analysis/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Correia-jpv","download_url":"https://codeload.github.com/Correia-jpv/fucking-static-analysis/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Correia-jpv%2Ffucking-static-analysis/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":341189360,"owners_count":37688581,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-09-25T02:00:20.896Z","response_time":55,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2025-04-27T09:56:46.070Z","updated_at":"2026-09-25T20:00:39.449Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Source","Programming Languages","Sponsors","Multiple languages","More Collections","Other","Meaning of Symbols:","License"],"sub_categories":[],"readme":"\u003c!-- 🚨🚨 DON'T EDIT THIS FILE DIRECTLY. Edit files in `data/tools/` instead. 🚨🚨 --\u003e\n\n\u003ca href=\"https://analysis-tools.dev/\"\u003e\n  \u003cimg alt=\"Analysis Tools Website\" src=\"https://raw.githubusercontent.com/analysis-tools-dev/assets/master/static/redesign.svg\" /\u003e\n\u003c/a\u003e\n\nThis repository lists **static analysis tools** for all programming languages, build tools, config files and more. The focus is on tools which improve code quality such as linters and formatters.\nThe official website, 🌎 [analysis-tools.dev](analysis-tools.dev/) is based on this repository and adds rankings, user comments, and additional resources like videos for each tool.\n\n[![Website](https://img.shields.io/badge/Website-Online-2B5BAE)](https://analysis-tools.dev)\n[![CI](https://github.com/correia-jpv/fucking-static-analysis/workflows/CI/badge.svg)](https://github.com/correia-jpv/fucking-static-analysis/actions/workflows/ci.yml)\n[![Links](https://github.com/correia-jpv/fucking-static-analysis/actions/workflows/links.yml/badge.svg)](https://github.com/correia-jpv/fucking-static-analysis/actions/workflows/links.yml)\n\n## Sponsors\n\nThank you to CodeRabbit for sponsoring this project, and to everyone who has supported it over the years.\n\n\u003ca href=\"https://coderabbit.ai\"\u003e\n  \u003cimg width=\"200px\" alt=\"CodeRabbit\" src=\"https://raw.githubusercontent.com/analysis-tools-dev/assets/master/static/sponsors/code-rabbit.svg\" /\u003e\n\u003c/a\u003e\n\nSupport this project through \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?🍴\u003c/code\u003e\u003c/b\u003e [GitHub Sponsors](https://github.com/sponsors/analysis-tools-dev)) or 🌎 [Open Collective](opencollective.com/analysis-tools).\n\n## Meaning of symbols\n\n- :copyright: stands for proprietary software. All other tools are open source.\n- :information_source: indicates that the community does not recommend the tool for new projects. The icon links to the discussion issue.\n- :warning: means that the tool was not updated for more than one year, or its repository was archived.\n\nContributions are welcome for tools that already meet the [contribution criteria](CONTRIBUTING.md): at least six months of history, 20 GitHub stars, and more than one human contributor. **Please do not submit tools before they qualify.** Pull requests with verified criteria failures will be closed; you are welcome to resubmit once all criteria are met.\n\nAlso check out the sister project, \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1105⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;118🍴\u003c/code\u003e\u003c/b\u003e [awesome-dynamic-analysis](https://github.com/mre/awesome-dynamic-analysis)).\n\n## Table of Contents\n\n#### [Programming Languages](#programming-languages-1)\n\n| | | |\n|---|---|---|\n| [ABAP](#abap) | [Erlang](#erlang) | [PL/SQL](#plsql) |\n| [Ada](#ada) | [F#](#fsharp) | [Perl](#perl) |\n| [Assembly](#asm) | [Fortran](#fortran) | [Python](#python) |\n| [Awk](#awk) | [Go](#go) | [R](#r) |\n| [C](#c) | [Groovy](#groovy) | [Rego](#rego) |\n| [C#](#csharp) | [Haskell](#haskell) | [Ruby](#ruby) |\n| [C++](#cpp) | [Haxe](#haxe) | [Rust](#rust) |\n| [Clojure](#clojure) | [Java](#java) | [SQL](#sql) |\n| [CoffeeScript](#coffeescript) | [JavaScript](#javascript) | [Scala](#scala) |\n| [ColdFusion](#coldfusion) | [Julia](#julia) | [Shell](#shell) |\n| [Crystal](#crystal) | [Kotlin](#kotlin) | [Swift](#swift) |\n| [Dart](#dart) | [Lua](#lua) | [Tcl](#tcl) |\n| [Delphi](#delphi) | [MATLAB](#matlab) | [TypeScript](#typescript) |\n| [Dlang](#dlang) | [Nim](#nim) | [Verilog/SystemVerilog](#verilog) |\n| [Elixir](#elixir) | [Ocaml](#ocaml) | [Vim Script](#vim-script) |\n| [Elm](#elm) | [PHP](#php) | [WebAssembly](#wasm) |\n\n#### [Multiple Languages](#multiple-languages-1)\n\n#### [Other](#other-1)\n\u003cdetails\u003e\n \u003csummary\u003eShow Other\u003c/summary\u003e\n\n| | | |\n|---|---|---|\n| [.env](#dotenv) | [Embedded Ruby (a.k.a. ERB, eRuby)](#erb) | [Puppet](#puppet) |\n| [AI-generated code](#ai-generated-code) | [Gherkin](#gherkin) | [Rails](#rails) |\n| [Agent Skills](#skill) | [HTML](#html) | [Security/SAST](#security) |\n| [Ansible](#ansible) | [JSON](#json) | [Smart Contracts](#smart-contracts) |\n| [Archive](#archive) | [Kubernetes](#kubernetes) | [Support](#support) |\n| [Azure Resource Manager](#arm) | [LaTeX](#latex) | [Template-Languages](#template) |\n| [Binaries](#binary) | [Laravel](#laravel) | [Terraform](#terraform) |\n| [Build tools](#buildtool) | [Makefiles](#make) | [Translation](#translation) |\n| [CSS/SASS/SCSS](#css) | [Markdown](#markdown) | [Uses LLM/model](#uses-llm) |\n| [Config Files](#configfile) | [Metalinter](#meta) | [Vue.js](#vue) |\n| [Configuration Management](#configmanagement) | [Mobile](#mobile) | [Writing](#writing) |\n| [Containers](#container) | [Nix](#nix) | [XML](#xml) |\n| [Continuous Integration](#ci) | [Node.js](#nodejs) | [YAML](#yaml) |\n| [Deno](#deno) | [Packages](#package) | [git](#git) |\n| [Dockerfile](#dockerfile) | [Prometheus](#prometheus) |\n| [Embedded](#embedded) | [Protocol Buffers](#protobuf) |\n\n\u003c/details\u003e\n\n---\n\n## Programming Languages\n\n\u003ca id=\"abap\"\u003e\u003c/a\u003e\n\u003ch2\u003eABAP\u003c/h2\u003e\n\n\n- 🌎 [abaplint](abaplint.org) — Linter for ABAP, written in TypeScript.\n\n- 🌎 [abapOpenChecks](docs.abapopenchecks.org) — Enhances the SAP Code Inspector with new and customizable checks.\n\n\n\n\u003ca id=\"ada\"\u003e\u003c/a\u003e\n\u003ch2\u003eAda\u003c/h2\u003e\n\n\n- 🌎 [Polyspace for Ada](www.mathworks.com/products/polyspace-ada.html) :copyright: — Provide code verification that proves the absence of overflow, divide-by-zero, out-of-bounds array access, and certain other run-time errors in source code.\n\n- 🌎 [SPARK](www.adacore.com/about-spark) :copyright: — Static analysis and formal verification toolset for Ada.\n\n\n\n\u003ca id=\"asm\"\u003e\u003c/a\u003e\n\u003ch2\u003eAssembly\u003c/h2\u003e\n\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **STOKE** :warning: — A programming-language agnostic stochastic optimizer for the x86_64 instruction set. It uses random search to explore the extremely high-dimensional space of all possible program transformations.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"awk\"\u003e\u003c/a\u003e\n\u003ch2\u003eAwk\u003c/h2\u003e\n\n\n- 🌎 [gawk --lint](www.gnu.org/software/gawk/manual/html_node/Options.html) — Warns about constructs that are dubious or nonportable to other awk implementations.\n\n\n\n\u003ca id=\"c\"\u003e\u003c/a\u003e\n\u003ch2\u003eC\u003c/h2\u003e\n\n\n- 🌎 [Astrée](www.absint.com/astree/index.htm) :copyright: — Astrée automatically proves the absence of runtime errors and invalid con­current behavior in C/C++ applications. It is sound for floating-point computations, very fast, and exceptionally precise. The analyzer also checks for MISRA/CERT/CWE/Adaptive Autosar coding rules and supports qualification for ISO 26262, DO-178C level A, and other safety standards. Jenkins and Eclipse plugins are available.\n\n- [CBMC](http://www.cprover.org/cbmc) — Bounded model-checker for C programs, user-defined assertions, standard assertions, several coverage metric analyses.\n\n- 🌎 [clang-tidy](clang.llvm.org/extra/clang-tidy) — Clang-based C++ linter tool with the (limited) ability to fix issues, too.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;746⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;96🍴\u003c/code\u003e\u003c/b\u003e [clazy](https://github.com/KDE/clazy)) — Qt-oriented static code analyzer based on the Clang framework. clazy is a compiler plugin which allows clang to understand Qt semantics. You get more than 50 Qt related compiler warnings, ranging from unneeded memory allocations to misusage of API, including fix-its for automatic refactoring.\n\n- 🌎 [codechecker](codechecker.readthedocs.io/en/latest) — A defect database and viewer extension for the Clang Static Analyzer with web GUI.\n\n- 🌎 [CPAchecker](cpachecker.sosy-lab.org) — A tool for configurable software verification of C programs.  The name CPAchecker was chosen to reflect that the tool is based on the CPA concepts and is used for checking software programs.\n\n- 🌎 [cppcheck](cppcheck.sourceforge.io) — Static analysis of C/C++ code.\n\n- 🌎 [CppDepend](www.cppdepend.com) :copyright: — Measure, query and visualize your code and avoid unexpected issues, technical debt and complexity.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1852⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;316🍴\u003c/code\u003e\u003c/b\u003e [cpplint](https://github.com/cpplint/cpplint)) — Automated C++ checker that follows Google's style guide.\n\n- 🌎 [CScout](www.spinellis.gr/cscout) — Complexity and quality metrics for C and C preprocessor code.\n\n- [ESBMC](http://esbmc.org) — ESBMC is an open source, permissively licensed, context-bounded model checker based on satisfiability modulo theories for the verification of single- and multi-threaded C/C++ programs.\n\n- [flawfinder](http://dwheeler.com/flawfinder/) — Finds possible security weaknesses.\n\n- 🌎 [Frama-C](www.frama-c.com) — A sound and extensible static analyzer for C code.\n\n- 🌎 [GCC](gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html) — The GCC compiler has static analysis capabilities since version 10. This option is only available if GCC was configured with analyzer support enabled.  It can also output its diagnostics to a JSON file in the SARIF format (from v13).\n\n- 🌎 [Goblint](goblint.in.tum.de) — A static analyzer for the analysis of multi-threaded C programs. Its primary focus is the  detection of data races, but it also reports other runtime errors, such as buffer overflows and null-pointer dereferences.\n\n- 🌎 [Helix QAC](www.perforce.com/products/helix-qac) :copyright: — Enterprise-grade static analysis for embedded software. Supports MISRA, CERT, and AUTOSAR coding standards.\n\n- [KLEE](http://klee.github.io/) — A dynamic symbolic execution engine built on top of the LLVM compiler infrastructure.  It can auto-generate test cases for programs such that the test cases exercise as much of the program as possible.\n\n- 🌎 [LDRA](ldra.com) :copyright: — A tool suite including static analysis (TBVISION) to various standards including MISRA C \u0026 C++, JSF++ AV, CWE, CERT C, CERT C++ \u0026 Custom Rules.\n\n- 🌎 [PC-lint](pclintplus.com/) :copyright: — Static analysis for C/C++. Runs natively under Windows/Linux/MacOS. Analyzes code for virtually any platform, supporting C11/C18 and C++17.\n\n- 🌎 [Phasar](phasar.org) — A LLVM-based static analysis framework which comes with a taint and type state analysis.\n\n- 🌎 [Polyspace Bug Finder](www.mathworks.com/products/polyspace-bug-finder.html) :copyright: — Identifies run-time errors, concurrency issues, security vulnerabilities, and other defects in C and C++ embedded software.\n\n- 🌎 [Polyspace Code Prover](www.mathworks.com/products/polyspace-code-prover.html) :copyright: — Provide code verification that proves the absence of overflow, divide-by-zero, out-of-bounds array access, and certain other run-time errors in C and C++ source code.\n\n- 🌎 [scan-build](clang-analyzer.llvm.org/scan-build.html) — Frontend to drive the Clang Static Analyzer built into Clang via a regular build.\n\n- [splint](http://splint.org) — Annotation-assisted static program checker.\n\n- 🌎 [SVF](svf-tools.github.io/SVF) — A static tool that enables scalable and precise interprocedural dependence analysis for C and C++ programs.\n\n- 🌎 [TrustInSoft Analyzer](trust-in-soft.com) :copyright: — Exhaustive detection of coding errors and their associated security vulnerabilities. This encompasses a sound undefined behavior detection (buffer overflows, out-of-bounds array accesses, null-pointer dereferences, use-after-free, divide-by-zeros, uninitialized memory accesses, signed overflows, invalid pointer arithmetic, etc.), data flow and control flow verification as well as full functional verification of formal specifications. All versions of C up to C18 and C++ up to C++20 are supported. TrustInSoft Analyzer will acquire ISO 26262 qualification in Q2'2023 (TCL3). A MISRA C checker is also bundled.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **CMetrics** :warning: — Measures size and complexity for C files.\n\n\n\n- **cqmetrics** :warning: — Quality metrics for C code.\n\n\n\n- **ENRE-cpp** :warning: — ENRE (ENtity Relationship Extractor) is a tool for extraction of code entity dependencies or relationships from source code. ENRE-cpp is a ENtity Relationship Extractor for C/C++ based on @eclipse/CDT. (Under development)\n\n\n\n- **flint++** :warning: — Cross-platform, zero-dependency port of flint, a lint program for C++ developed and used at Facebook.\n\n\n\n- **IKOS** :warning: — A sound static analyzer for C/C++ code based on LLVM.\n\n\n\n- **MATE** :warning: — A suite of tools for interactive program analysis with a focus on hunting for bugs in C and C++ code. MATE unifies application-specific and low-level vulnerability analysis using code property graphs (CPGs), enabling the discovery of highly application-specific vulnerabilities that depend on both implementation details and the high-level semantics of target C/C++ programs.\n\n\n\n- **vera++** :warning: — Vera++ is a programmable tool for verification, analysis and transformation of C++ source code.\n\n\n\n- **weggli** :warning: — A fast and robust semantic search tool for C and C++ codebases. It is designed to help security researchers identify interesting functionality in large codebases.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"csharp\"\u003e\u003c/a\u003e\n\u003ch2\u003eC#\u003c/h2\u003e\n\n\n- [.NET Analyzers](https://github.com/DotNetAnalyzers) — An organization for the development of analyzers (diagnostics and code fixes) using the .NET Compiler Platform.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1366⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;81🍴\u003c/code\u003e\u003c/b\u003e [ArchUnitNET](https://github.com/TNG/ArchUnitNET)) — A C# architecture test library to specify and assert architecture rules in C# for automated testing.\n\n- [Designite](http://www.designite-tools.com) :copyright: — Designite supports detection of various architecture, design, and implementation smells, computation of various code quality metrics, and trend analysis.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1202⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;71🍴\u003c/code\u003e\u003c/b\u003e [Meziantou.Analyzer](https://github.com/meziantou/Meziantou.Analyzer)) — A Roslyn analyzer to enforce some good practices in C# in terms of design, usage, security, performance, and style.\n\n- [NDepend](http://www.ndepend.com) :copyright: — Measure, query and visualize your code and avoid unexpected issues, technical debt and complexity.\n\n- 🌎 [Puma Scan](pumasecurity.io) — Puma Scan provides real time secure code analysis for common vulnerabilities (XSS, SQLi, CSRF, LDAPi, crypto, deserialization, etc.) as development teams write code in Visual Studio.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;3482⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;294🍴\u003c/code\u003e\u003c/b\u003e [Roslynator](https://github.com/JosefPihrt/Roslynator)) — A collection of 190+ analyzers and 190+ refactorings for C#, powered by Roslyn.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;919⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;244🍴\u003c/code\u003e\u003c/b\u003e [SonarAnalyzer.CSharp](https://github.com/SonarSource/sonar-dotnet)) — These Roslyn analyzers allow you to produce Clean Code that is safe, reliable, and maintainable by helping you find and correct bugs, vulnerabilities, and code smells in your codebase.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **code-cracker** :warning: — An analyzer library for C# and VB that uses Roslyn to produce refactorings, code analysis, and other niceties.\n\n\n\n- **CSharpEssentials** :warning: — C# Essentials is a collection of Roslyn diagnostic analyzers, code fixes and refactorings that make it easy to work with C# 6 language features.\n\n\n\n- **Gendarme** :warning: — Gendarme inspects programs and libraries that contain code in ECMA CIL format (Mono and .NET).\n\n\n\n- **Infer#** :warning: — InferSharp (also referred to as Infer#) is an interprocedural and  scalable static code analyzer for C#. Via the capabilities of Facebook's Infer,  this tool detects null pointer dereferences and resource leaks.\n\n\n\n- **VSDiagnostics** :warning: — A collection of static analyzers based on Roslyn that integrates with VS.\n\n\n\n- **Wintellect.Analyzers** :warning: — .NET Compiler Platform (\"Roslyn\") diagnostic analyzers and code fixes.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"cpp\"\u003e\u003c/a\u003e\n\u003ch2\u003eC++\u003c/h2\u003e\n\n\n- 🌎 [Astrée](www.absint.com/astree/index.htm) :copyright: — Astrée automatically proves the absence of runtime errors and invalid con­current behavior in C/C++ applications. It is sound for floating-point computations, very fast, and exceptionally precise. The analyzer also checks for MISRA/CERT/CWE/Adaptive Autosar coding rules and supports qualification for ISO 26262, DO-178C level A, and other safety standards. Jenkins and Eclipse plugins are available.\n\n- [CBMC](http://www.cprover.org/cbmc) — Bounded model-checker for C programs, user-defined assertions, standard assertions, several coverage metric analyses.\n\n- 🌎 [clang-tidy](clang.llvm.org/extra/clang-tidy) — Clang-based C++ linter tool with the (limited) ability to fix issues, too.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;746⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;96🍴\u003c/code\u003e\u003c/b\u003e [clazy](https://github.com/KDE/clazy)) — Qt-oriented static code analyzer based on the Clang framework. clazy is a compiler plugin which allows clang to understand Qt semantics. You get more than 50 Qt related compiler warnings, ranging from unneeded memory allocations to misusage of API, including fix-its for automatic refactoring.\n\n- 🌎 [codechecker](codechecker.readthedocs.io/en/latest) — A defect database and viewer extension for the Clang Static Analyzer with web GUI.\n\n- 🌎 [cppcheck](cppcheck.sourceforge.io) — Static analysis of C/C++ code.\n\n- 🌎 [CppDepend](www.cppdepend.com) :copyright: — Measure, query and visualize your code and avoid unexpected issues, technical debt and complexity.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1852⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;316🍴\u003c/code\u003e\u003c/b\u003e [cpplint](https://github.com/cpplint/cpplint)) — Automated C++ checker that follows Google's style guide.\n\n- 🌎 [CScout](www.spinellis.gr/cscout) — Complexity and quality metrics for C and C preprocessor code.\n\n- [ESBMC](http://esbmc.org) — ESBMC is an open source, permissively licensed, context-bounded model checker based on satisfiability modulo theories for the verification of single- and multi-threaded C/C++ programs.\n\n- [flawfinder](http://dwheeler.com/flawfinder/) — Finds possible security weaknesses.\n\n- 🌎 [GCC](gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html) — The GCC compiler has static analysis capabilities since version 10. This option is only available if GCC was configured with analyzer support enabled.  It can also output its diagnostics to a JSON file in the SARIF format (from v13).\n\n- 🌎 [Helix QAC](www.perforce.com/products/helix-qac) :copyright: — Enterprise-grade static analysis for embedded software. Supports MISRA, CERT, and AUTOSAR coding standards.\n\n- [KLEE](http://klee.github.io/) — A dynamic symbolic execution engine built on top of the LLVM compiler infrastructure.  It can auto-generate test cases for programs such that the test cases exercise as much of the program as possible.\n\n- 🌎 [LDRA](ldra.com) :copyright: — A tool suite including static analysis (TBVISION) to various standards including MISRA C \u0026 C++, JSF++ AV, CWE, CERT C, CERT C++ \u0026 Custom Rules.\n\n- 🌎 [PC-lint](pclintplus.com/) :copyright: — Static analysis for C/C++. Runs natively under Windows/Linux/MacOS. Analyzes code for virtually any platform, supporting C11/C18 and C++17.\n\n- 🌎 [Phasar](phasar.org) — A LLVM-based static analysis framework which comes with a taint and type state analysis.\n\n- 🌎 [Polyspace Bug Finder](www.mathworks.com/products/polyspace-bug-finder.html) :copyright: — Identifies run-time errors, concurrency issues, security vulnerabilities, and other defects in C and C++ embedded software.\n\n- 🌎 [Polyspace Code Prover](www.mathworks.com/products/polyspace-code-prover.html) :copyright: — Provide code verification that proves the absence of overflow, divide-by-zero, out-of-bounds array access, and certain other run-time errors in C and C++ source code.\n\n- 🌎 [scan-build](clang-analyzer.llvm.org/scan-build.html) — Frontend to drive the Clang Static Analyzer built into Clang via a regular build.\n\n- [splint](http://splint.org) — Annotation-assisted static program checker.\n\n- 🌎 [SVF](svf-tools.github.io/SVF) — A static tool that enables scalable and precise interprocedural dependence analysis for C and C++ programs.\n\n- 🌎 [TrustInSoft Analyzer](trust-in-soft.com) :copyright: — Exhaustive detection of coding errors and their associated security vulnerabilities. This encompasses a sound undefined behavior detection (buffer overflows, out-of-bounds array accesses, null-pointer dereferences, use-after-free, divide-by-zeros, uninitialized memory accesses, signed overflows, invalid pointer arithmetic, etc.), data flow and control flow verification as well as full functional verification of formal specifications. All versions of C up to C18 and C++ up to C++20 are supported. TrustInSoft Analyzer will acquire ISO 26262 qualification in Q2'2023 (TCL3). A MISRA C checker is also bundled.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **CMetrics** :warning: — Measures size and complexity for C files.\n\n\n\n- **cqmetrics** :warning: — Quality metrics for C code.\n\n\n\n- **ENRE-cpp** :warning: — ENRE (ENtity Relationship Extractor) is a tool for extraction of code entity dependencies or relationships from source code. ENRE-cpp is a ENtity Relationship Extractor for C/C++ based on @eclipse/CDT. (Under development)\n\n\n\n- **flint++** :warning: — Cross-platform, zero-dependency port of flint, a lint program for C++ developed and used at Facebook.\n\n\n\n- **IKOS** :warning: — A sound static analyzer for C/C++ code based on LLVM.\n\n\n\n- **MATE** :warning: — A suite of tools for interactive program analysis with a focus on hunting for bugs in C and C++ code. MATE unifies application-specific and low-level vulnerability analysis using code property graphs (CPGs), enabling the discovery of highly application-specific vulnerabilities that depend on both implementation details and the high-level semantics of target C/C++ programs.\n\n\n\n- **vera++** :warning: — Vera++ is a programmable tool for verification, analysis and transformation of C++ source code.\n\n\n\n- **weggli** :warning: — A fast and robust semantic search tool for C and C++ codebases. It is designed to help security researchers identify interesting functionality in large codebases.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"clojure\"\u003e\u003c/a\u003e\n\u003ch2\u003eClojure\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1854⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;309🍴\u003c/code\u003e\u003c/b\u003e [clj-kondo](https://github.com/borkdude/clj-kondo)) — A linter for Clojure code that sparks joy. It informs you about potential errors while you are typing.\n\n\n\n\u003ca id=\"coffeescript\"\u003e\u003c/a\u003e\n\u003ch2\u003eCoffeeScript\u003c/h2\u003e\n\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **coffeelint** :warning: — A style checker that helps keep CoffeeScript code clean and consistent.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"coldfusion\"\u003e\u003c/a\u003e\n\u003ch2\u003eColdFusion\u003c/h2\u003e\n\n\n- 🌎 [Fixinator](fixinator.app) :copyright: — Static security code analysis for ColdFusion or CFML code. Designed to work within a CI pipeline or from the developers terminal.\n\n\n\n\u003ca id=\"crystal\"\u003e\u003c/a\u003e\n\u003ch2\u003eCrystal\u003c/h2\u003e\n\n\n- 🌎 [ameba](crystal-ameba.github.io) — A static code analysis tool for Crystal.\n\n- 🌎 [crystal](crystal-lang.org) — The Crystal compiler has built-in linting functionality.\n\n\n\n\u003ca id=\"dart\"\u003e\u003c/a\u003e\n\u003ch2\u003eDart\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;278⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;79🍴\u003c/code\u003e\u003c/b\u003e [lint](https://github.com/passsy/dart-lint)) — An opinionated, community-driven set of lint rules for Dart and Flutter projects. Like pedantic but stricter\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **Dart Code Metrics** :warning: — Additional linter for Dart. Reports code metrics, checks for anti-patterns and provides additional rules for Dart analyzer.\n\n\n\n- **effective_dart** :warning: — Linter rules corresponding to the guidelines in Effective Dart\n\n\n\n- **Linter for dart** :warning: — Style linter for Dart.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"delphi\"\u003e\u003c/a\u003e\n\u003ch2\u003eDelphi\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;146⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;31🍴\u003c/code\u003e\u003c/b\u003e [DelphiLint](https://github.com/integrated-application-development/delphilint)) — A Delphi IDE package providing on-the-fly code analysis and linting, powered by SonarDelphi.\n\n- 🌎 [Fix Insight](www.tmssoftware.com/site/fixinsight.asp) :copyright: — A free IDE Plugin for static code analysis. A _Pro_ edition includes a command line tool for automation purposes.\n\n- 🌎 [Pascal Analyzer](peganza.com/products_pal.html) :copyright: — A static code analysis tool with numerous reports. A free _Lite_ version is available with limited reporting.\n\n- 🌎 [Pascal Expert](peganza.com/products_pex.html) :copyright: — IDE plugin for code analysis. Includes a subset of Pascal Analyzer reporting capabilities and is available for Delphi versions 2007 and later.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;159⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;32🍴\u003c/code\u003e\u003c/b\u003e [SonarDelphi](https://github.com/integrated-application-development/sonar-delphi)) — Delphi static analyzer for the SonarQube code quality platform.\n\n\n\n\u003ca id=\"dlang\"\u003e\u003c/a\u003e\n\u003ch2\u003eDlang\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;258⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;85🍴\u003c/code\u003e\u003c/b\u003e [D-scanner](https://github.com/dlang-community/D-Scanner)) — D-Scanner is a tool for analyzing D source code.\n\n\n\n\u003ca id=\"elixir\"\u003e\u003c/a\u003e\n\u003ch2\u003eElixir\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;5222⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;457🍴\u003c/code\u003e\u003c/b\u003e [credo](https://github.com/rrrene/credo)) — A static code analysis tool with a focus on code consistency and teaching.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1796⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;161🍴\u003c/code\u003e\u003c/b\u003e [dialyxir](https://github.com/jeremyjh/dialyxir)) — Mix tasks to simplify use of Dialyzer in Elixir projects.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **sobelow** :warning: — Security-focused static analysis for the Phoenix Framework.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"elm\"\u003e\u003c/a\u003e\n\u003ch2\u003eElm\u003c/h2\u003e\n\n\n- 🌎 [elm-review](package.elm-lang.org/packages/jfmengels/elm-review/latest) — Analyzes whole Elm projects, with a focus on shareable and custom rules written in Elm that add guarantees the Elm compiler doesn't give you.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **elm-analyse** :warning: — A tool that allows you to analyse your Elm code, identify deficiencies and apply best practices.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"erlang\"\u003e\u003c/a\u003e\n\u003ch2\u003eErlang\u003c/h2\u003e\n\n\n- 🌎 [dialyzer](www.erlang.org/doc/man/dialyzer.html) — The DIALYZER, a DIscrepancy AnaLYZer for ERlang programs. Dialyzer is a static analysis tool that identifies software discrepancies,  such as definite type errors, code that has become dead or unreachable  because of programming error, and unnecessary tests,  in single Erlang modules or entire (sets of) applications.\nDialyzer starts its analysis from either debug-compiled BEAM bytecode  or from Erlang source code. The file and line number of a discrepancy  is reported along with an indication of what the discrepancy is about.  Dialyzer bases its analysis on the concept of success typings,  which allows for sound warnings (no false positives).\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;435⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;85🍴\u003c/code\u003e\u003c/b\u003e [elvis](https://github.com/inaka/elvis)) — Erlang Style Reviewer.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **Primitive Erlang Security Tool (PEST)** :warning: — A tool to do a basic scan of Erlang source code and report any function calls that may cause Erlang source code to be insecure.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"fsharp\"\u003e\u003c/a\u003e\n\u003ch2\u003eF#\u003c/h2\u003e\n\n\n- 🌎 [fantomas](fsprojects.github.io/fantomas/) — F# source code formatter.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;327⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;74🍴\u003c/code\u003e\u003c/b\u003e [FSharpLint](https://github.com/fsprojects/FSharpLint)) — Lint tool for F#.\n\n- 🌎 [ionide-analyzers](ionide.io/ionide-analyzers/) — A collection of F# analyzers, built with the FSharp.Analyzers.SDK.\n\n\n\n\u003ca id=\"fortran\"\u003e\u003c/a\u003e\n\u003ch2\u003eFortran\u003c/h2\u003e\n\n\n- 🌎 [Fortitude](fortitude.readthedocs.io) — Fortran linter, inspired by (and built on) Ruff, and based on community best practices. Supports latest Fortran (2023) standard.\n\n- 🌎 [fprettify](pypi.python.org/pypi/fprettify) — Auto-formatter for modern fortran source code, written in Python.\nFprettify is a tool that provides consistent whitespace, indentation, and delimiter alignment in code, including the ability to change letter case and handle preprocessor directives, all while preserving revision history and tested for editor integration.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **i-Code CNES for Fortran** :warning: — An open source static code analysis tool for Fortran 77, Fortran 90 and Shell.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"go\"\u003e\u003c/a\u003e\n\u003ch2\u003eGo\u003c/h2\u003e\n\n\n- 🌎 [aligncheck](gitlab.com/opennota/check) — Find inefficiently packed structs.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;323⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;39🍴\u003c/code\u003e\u003c/b\u003e [bodyclose](https://github.com/timakin/bodyclose)) — Checks whether HTTP response body is closed.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;370⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;23🍴\u003c/code\u003e\u003c/b\u003e [dupl](https://github.com/mibk/dupl)) — Reports potentially duplicated code.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;2528⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;148🍴\u003c/code\u003e\u003c/b\u003e [errcheck](https://github.com/kisielk/errcheck)) — Check that error return values are used.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;50⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;4🍴\u003c/code\u003e\u003c/b\u003e [flen](https://github.com/lafolle/flen)) — Get info on length of functions in a Go package.\n\n- 🌎 [go tool vet --shadow](golang.org/cmd/vet#hdr-Shadowed_variables) — Reports variables that may have been unintentionally shadowed.\n\n- 🌎 [go vet](golang.org/cmd/vet) — Examines Go source code and reports suspicious.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;2071⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;141🍴\u003c/code\u003e\u003c/b\u003e [go-critic](https://github.com/go-critic/go-critic)) — Go source code linter that maintains checks which are currently not implemented in other linters.\n\n- 🌎 [go/ast](golang.org/pkg/go/ast) — Package ast declares the types used to represent syntax trees for Go packages.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;78⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;3🍴\u003c/code\u003e\u003c/b\u003e [goast](https://github.com/m-mizutani/goast)) — Go AST (Abstract Syntax Tree) based static analysis tool with Rego.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;320⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;20🍴\u003c/code\u003e\u003c/b\u003e [goconst](https://github.com/jgautheron/goconst)) — Finds repeated strings that could be replaced by a constant.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1610⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;97🍴\u003c/code\u003e\u003c/b\u003e [gocyclo](https://github.com/fzipp/gocyclo)) — Calculate cyclomatic complexities of functions in Go source code.\n\n- 🌎 [gofmt -s](golang.org/cmd/gofmt) — Checks if the code is properly formatted and could not be further simplified.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;4091⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;134🍴\u003c/code\u003e\u003c/b\u003e [gofumpt](https://github.com/mvdan/gofumpt)) — Enforce a stricter format than `gofmt`, while being backwards-compatible.  That is, `gofumpt` is happy with a subset of the formats that `gofmt` is happy with.\nThe tool is a fork of `gofmt` as of Go 1.19, and requires Go 1.18 or later.  It can be used as a drop-in replacement to format your Go code, and running gofmt  after gofumpt should produce no changes.\n`gofumpt` will never add rules which disagree with `gofmt` formatting. So we extend `gofmt` rather than compete with it.\n\n- 🌎 [goimports](pkg.go.dev/golang.org/x/tools/cmd/goimports) — Checks missing or unreferenced package imports.\n\n- 🌎 [GolangCI-Lint](golangci-lint.run) — Fast linters runner for Go. It aggregates multiple Go linters and provides a unified configuration, caching, and output format. Alternative to `Go Meta Linter`.\n\n- 🌎 [gosec (gas)](securego.io) — Inspects source code for security problems by scanning the Go AST.\n\n- 🌎 [gotype](pkg.go.dev/golang.org/x/tools/cmd/gotype) — Syntactic and semantic analysis similar to the Go compiler.\n\n- 🌎 [govulncheck](go.dev/blog/vuln) — Govulncheck reports known vulnerabilities that affect Go code.  It uses static analysis of source code or a binary's symbol table to narrow down reports to only those that could affect the application.\nBy default, govulncheck makes requests to the Go vulnerability database at https://vuln.go.dev. Requests to the vulnerability database contain only module paths, not code or other properties of your program.\n\n- 🌎 [OSV-Scanner](osv.dev/) — Vulnerability scanner written in Go which uses the data provided by OSV.dev. Developed by Google to scan dependencies across multiple languages and package managers for known vulnerabilities. Supports container scanning, license scanning, and guided remediation. Works with lockfiles, SBOMs, and container images to identify security issues.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;665⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;26🍴\u003c/code\u003e\u003c/b\u003e [prealloc](https://github.com/alexkohler/prealloc)) — Finds slice declarations that could potentially be preallocated.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;9619⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;498🍴\u003c/code\u003e\u003c/b\u003e [Reviewdog](https://github.com/haya14busa/reviewdog)) — A tool for posting review comments from any linter in any code hosting service.\n\n- 🌎 [revive](revive.run) — Fast, configurable, extensible, flexible, and beautiful linter for Go. Drop-in replacement of golint.\n\n- 🌎 [staticcheck](staticcheck.io) — Go static analysis that specialises in finding bugs, simplifying code and improving performance.\n\n- 🌎 [structcheck](gitlab.com/opennota/check) — Find unused struct fields.\n\n- 🌎 [test](pkg.go.dev/testing) — Show location of test failures from the stdlib testing module.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;388⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;26🍴\u003c/code\u003e\u003c/b\u003e [unconvert](https://github.com/mdempsky/unconvert)) — Detect redundant type conversions.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;572⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;31🍴\u003c/code\u003e\u003c/b\u003e [unparam](https://github.com/mvdan/unparam)) — Find unused function parameters.\n\n- 🌎 [varcheck](gitlab.com/opennota/check) — Find unused global variables and constants.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;361⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;45🍴\u003c/code\u003e\u003c/b\u003e [wsl](https://github.com/bombsimon/wsl)) — Enforces empty lines at the right places.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **deadcode** :warning: — Finds unused code.\n\n\n\n- **dingo-hunter** :warning: — Static analyser for finding deadlocks in Go.\n\n\n\n- **dogsled** :warning: — Finds assignments/declarations with too many blank identifiers.\n\n\n\n- **errwrap** :warning: — Wrap and fix Go errors with the new %w verb directive.  This tool analyzes fmt.Errorf() calls and reports calls that contain a verb directive that  is different than the new %w verb directive introduced in Go v1.13.  It's also capable of rewriting calls to use the new %w wrap verb directive.\n\n\n\n- **Go Meta Linter** :warning: — Concurrently run Go lint tools and normalise their output. Use `golangci-lint` for new projects.\n\n\n\n- **go-consistent** :warning: — Analyzer that helps you to make your Go programs more consistent.\n\n\n\n- **gochecknoglobals** :warning: — Checks that no globals are present.\n\n\n\n- **gokart** :warning: — Golang security analysis with a focus on minimizing false positives. It is capable of tracing the source of variables and function arguments  to determine whether input sources are safe.\n\n\n\n- **golint** :warning: — Prints out coding style mistakes in Go source code.\n\n\n\n- **goreporter** :warning: — Concurrently runs many linters and normalises their output to a report.\n\n\n\n- **goroutine-inspect** :warning: — An interactive tool to analyze Golang goroutine dump.\n\n\n\n- **ineffassign** :warning: — Detect ineffectual assignments in Go code.\n\n\n\n- **interfacer** :warning: — Suggest narrower interfaces that can be used.\n\n\n\n- **lll** :warning: — Report long lines.\n\n\n\n- **maligned** :warning: — Detect structs that would take less memory if their fields were sorted.\n\n\n\n- **misspell** :warning: — Finds commonly misspelled English words.\n\n\n\n- **nakedret** :warning: — Finds naked returns.\n\n\n\n- **nargs** :warning: — Finds unused arguments in function declarations.\n\n\n\n- **safesql** :warning: — Static analysis tool for Golang that protects against SQL injections.\n\n\n\n- **shisho** :warning: — A lightweight static code analyzer designed for developers and security teams. It allows you to analyze and transform source code with an intuitive DSL similar to sed, but for code.\n\n\n\n- **structslop** :warning: — Static analyzer for Go that recommends struct field rearrangements to provide for maximum space/allocation efficiency\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"groovy\"\u003e\u003c/a\u003e\n\u003ch2\u003eGroovy\u003c/h2\u003e\n\n\n- 🌎 [CodeNarc](codenarc.github.io/CodeNarc) — A static analysis tool for Groovy source code, enabling monitoring and enforcement of many coding standards and best practices.\n\n\n\n\u003ca id=\"haskell\"\u003e\u003c/a\u003e\n\u003ch2\u003eHaskell\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1612⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;210🍴\u003c/code\u003e\u003c/b\u003e [HLint](https://github.com/ndmitchell/hlint)) — HLint is a tool for suggesting possible improvements to Haskell code.\n\n- 🌎 [Liquid Haskell](ucsd-progsys.github.io/liquidhaskell-blog/) — Liquid Haskell is a refinement type checker for Haskell programs.\n\n- 🌎 [Stan](kowainik.github.io/projects/stan) — Stan is a command-line tool for analysing Haskell projects and outputting discovered vulnerabilities in a helpful way with possible solutions for detected problems.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;189⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;35🍴\u003c/code\u003e\u003c/b\u003e [Weeder](https://github.com/ocharles/weeder)) — A tool for detecting dead exports or package imports in Haskell code.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **brittany** :warning: — Haskell source code formatter\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"haxe\"\u003e\u003c/a\u003e\n\u003ch2\u003eHaxe\u003c/h2\u003e\n\n\n- 🌎 [Haxe Checkstyle](haxecheckstyle.github.io/docs/haxe-checkstyle/home.html) — A static analysis tool to help developers write Haxe code that adheres to a coding standard.\n\n\n\n\u003ca id=\"java\"\u003e\u003c/a\u003e\n\u003ch2\u003eJava\u003c/h2\u003e\n\n\n- 🌎 [Checker Framework](checkerframework.org) — Pluggable type-checking for Java.  This is not just a bug-finder, but a verification tool that gives a guarantee of correctness.  It comes with 27 pre-built type systems, and it enables users to define their own type system; the manual lists over 30 user-contributed type systems.\n\n- 🌎 [checkstyle](checkstyle.org) — Checking Java source code for adherence to a Code Standard or set of validation rules (best practices).\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;458⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;169🍴\u003c/code\u003e\u003c/b\u003e [ck](https://github.com/mauricioaniche/ck)) — Calculates Chidamber and Kemerer object-oriented metrics by processing the source Java files.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1149⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;441🍴\u003c/code\u003e\u003c/b\u003e [Dataflow Framework](https://github.com/typetools/checker-framework)) — An industrial-strength dataflow framework for Java. The Dataflow Framework is used in the Checker Framework, Google’s Error Prone, Uber’s NullAway, Meta’s Nullsafe, and in other contexts. It is distributed with the Checker Framework.\n\n- [DesigniteJava](http://www.designite-tools.com/designitejava) :copyright: — DesigniteJava supports detection of various architecture, design, and implementation smells along with computation of various code quality metrics.\n\n- 🌎 [Diffblue](www.diffblue.com/) :copyright: — Diffblue is a software company that provides AI-powered code analysis and testing solutions for software development teams.\nIts technology helps developers automate testing, find bugs, and reduce manual labor in their software development processes. The company's main product, Diffblue Cover, uses AI to generate and run unit tests for Java code, helping to catch errors and improve code quality.\n\n- 🌎 [Doop](plast-lab.github.io/doop-pldi15-tutorial/) — Doop is a declarative framework for static analysis of Java/Android programs, centered on pointer analysis algorithms. Doop provides a large variety of analyses and also the surrounding scaffolding to run an analysis end-to-end (fact generation, processing, statistics, etc.).\n\n- 🌎 [Error Prone](errorprone.info) — Catch common Java mistakes as compile-time errors.\n\n- [fb-contrib](http://fb-contrib.sourceforge.net) — A plugin for FindBugs with additional bug detectors.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;372⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;39🍴\u003c/code\u003e\u003c/b\u003e [forbidden-apis](https://github.com/policeman-tools/forbidden-apis)) — Detects and forbids invocations of specific method/class/field (like reading from a text stream without a charset). Maven/Gradle/Ant compatible.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;6202⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;936🍴\u003c/code\u003e\u003c/b\u003e [google-java-format](https://github.com/google/google-java-format)) — Reformats Java source code to comply with Google Java Style\n\n- 🌎 [IntelliJ IDEA](www.jetbrains.com/idea) :copyright: — Comes bundled with a lot of inspections for Java and Kotlin and includes tools for refactoring, formatting and more.\n\n- 🌎 [JArchitect](www.jarchitect.com) :copyright: — Measure, query and visualize your code and avoid unexpected issues, technical debt and complexity.\n\n- 🌎 [JBMC](www.cprover.org/jbmc) — Bounded model-checker for Java (bytecode), verifies user-defined assertions, standard assertions, several coverage metric analyses.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;32⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;2🍴\u003c/code\u003e\u003c/b\u003e [JLiSA](https://github.com/lisa-analyzer/jlisa)) — An abstract interpretation-based static analyzer for Java build upon the \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;85⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;36🍴\u003c/code\u003e\u003c/b\u003e [LiSA](https://github.com/lisa-analyzer/lisa)) framekwork.\n\n- 🌎 [Mariana Trench](mariana-tren.ch/) — Our security focused static analysis tool for Android and Java applications. Mariana Trench analyzes Dalvik bytecode and is built to run fast on large codebases (10s of millions of lines of code). It can find vulnerabilities as code changes, before it ever lands in your repository.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;4109⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;369🍴\u003c/code\u003e\u003c/b\u003e [NullAway](https://github.com/uber/NullAway)) — Type-based null-pointer checker with low build-time overhead; an [Error Prone](http://errorprone.info/) plugin.\n\n- 🌎 [qulice](www.qulice.com) — Combines a few (pre-configured) static analysis tools (checkstyle, PMD, Findbugs, ...).\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;549⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;46🍴\u003c/code\u003e\u003c/b\u003e [RefactorFirst](https://github.com/jimbethancourt/RefactorFirst)) — Identifies and prioritizes God Classes and Highly Coupled classes in Java codebases you should refactor first.\n\n- 🌎 [Soot](soot-oss.github.io/soot) — A framework for analyzing and transforming Java and Android applications.\n\n- 🌎 [Spoon](spoon.gforge.inria.fr) — Spoon is a metaprogramming library to analyze and transform Java source code (incl Java 9, 10, 11, 12, 13, 14). It parses source files to build a well-designed AST with powerful analysis and transformation API. Can be integrated in Maven and Gradle.\n\n- 🌎 [SpotBugs](spotbugs.github.io) — SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;161⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;42🍴\u003c/code\u003e\u003c/b\u003e [Violations Lib](https://github.com/tomasbjerre/violations-lib)) — Java library for parsing report files from static code analysis. Used by a bunch of Jenkins, Maven and Gradle plugins.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **ckjm** :warning: — Calculates Chidamber and Kemerer object-oriented metrics by processing the bytecode of compiled Java files.\n\n\n\n- **CogniCrypt** :warning: — Checks Java source and byte code for incorrect uses of cryptographic APIs.\n\n\n\n- **ENRE-java** :warning: — ENRE (ENtity Relationship Extractor) is a tool for extraction of code entity dependencies or relationships from source code. ENRE-java is a ENtity Relationship Extractor for Java projects based on @Eclipse JDT/parser.\n\n\n\n- **HuntBugs** :warning: — Bytecode static analyzer tool based on Procyon Compiler Tools aimed to supersede FindBugs.\n\n\n\n- **OWASP Dependency Check** :warning: — Checks dependencies for known, publicly disclosed, vulnerabilities.\n\n\n\n- **steady** :warning: — Analyses your Java applications for open-source dependencies with known vulnerabilities, using both static analysis and testing to determine code context and usage for greater accuracy.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"javascript\"\u003e\u003c/a\u003e\n\u003ch2\u003eJavaScript\u003c/h2\u003e\n\n\n- 🌎 [Closure Compiler](developers.google.com/closure/compiler) — A compiler tool to increase efficiency, reduce size, and provide code warnings in JavaScript files.\n\n- 🌎 [DeepScan](deepscan.io) :copyright: — An analyzer for JavaScript which targets runtime errors and quality issues rather than coding conventions.\n\n- 🌎 [flow](flow.org) — A static type checker for JavaScript.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;3655⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;473🍴\u003c/code\u003e\u003c/b\u003e [JSLint](https://github.com/douglascrockford/JSLint)) [:information_source:](\u003chttps://github.com/correia-jpv/fucking-static-analysis/issues/223\u003e) — The JavaScript Code Quality Tool.\n\n- 🌎 [NodeJSScan](opensecurity.in) — A static security code scanner for Node.js applications powered by libsast and semgrep that builds on the njsscan cli tool. It features a UI with various dashboards about an application's security status.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;437⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;199🍴\u003c/code\u003e\u003c/b\u003e [Polymer-analyzer](https://github.com/Polymer/tools/tree/master/packages/analyzer)) — A static analysis framework for Web Components.\n\n- 🌎 [retire.js](retirejs.github.io/retire.js) — Scanner detecting the use of JavaScript libraries with known vulnerabilities.\n\n- 🌎 [squirrelscan](squirrelscan.com) — squirrelscan is a website QA tool built for coding agents such as Claude Code and Cursor. Its squirrel CLI crawls a live site and runs 260+ audit rules across SEO, performance, security, accessibility, structured data and agent experience, then returns exact source-mapped fixes. Runs from the terminal, CI, the cloud, or over MCP.\n\n- 🌎 [tern](ternjs.net) — A JavaScript code analyzer for deep, cross-editor language support.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;7988⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;309🍴\u003c/code\u003e\u003c/b\u003e [xo](https://github.com/xojs/xo)) — Opinionated but configurable ESLint wrapper with lots of goodies included. Enforces strict and readable code.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **aether** :warning: — Lint, analyze, normalize, transform, sandbox, run, step through, and visualize user JavaScript, in node or the browser.\n\n\n\n- **ClosureLinter** :warning: — Ensures that all of your project's JavaScript code follows the guidelines in the Google JavaScript Style Guide. It can also automatically fix many common errors.\n\n\n\n- **complexity-report** :warning: — Software complexity analysis for JavaScript projects.\n\n\n\n- **es6-plato** :warning: — Visualize JavaScript (ES6) source complexity.\n\n\n\n- **escomplex** :warning: — Software complexity analysis of JavaScript-family abstract syntax trees.\n\n\n\n- **Esprima** :warning: — ECMAScript parsing infrastructure for multipurpose analysis.\n\n\n\n- **hegel** :warning: — A static type checker for JavaScript with a bias on type inference and strong type systems.\n\n\n\n- **jshint** [:information_source:](\u003chttps://github.com/correia-jpv/fucking-static-analysis/issues/223\u003e) :warning: — Detect errors and potential problems in JavaScript code and enforce your team's coding conventions.\n\n\n\n- **JSPrime** :warning: — Static security analysis tool.\n\n\n\n- **plato** :warning: — Visualize JavaScript source complexity.\n\n\n\n- **RSLint** :warning: — A (WIP) JavaScript linter written in Rust designed to be as fast as possible, customizable, and easy to use.\n\n\n\n- **standard** :warning: — An npm module that checks for Javascript Styleguide issues.\n\n\n\n- **TypL** :warning: — With TypL, you just write completely standard JS, and the tool figures out your types via powerful inferencing.\n\n\n\n- **yardstick** :warning: — Javascript code metrics.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"julia\"\u003e\u003c/a\u003e\n\u003ch2\u003eJulia\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;881⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;43🍴\u003c/code\u003e\u003c/b\u003e [JET](https://github.com/aviatesk/JET.jl)) — Static type inference system to detect bugs and type instabilities.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;155⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;30🍴\u003c/code\u003e\u003c/b\u003e [StaticLint](https://github.com/julia-vscode/StaticLint.jl)) — Static Code Analysis for Julia\n\n\n\n\u003ca id=\"kotlin\"\u003e\u003c/a\u003e\n\u003ch2\u003eKotlin\u003c/h2\u003e\n\n\n- 🌎 [detekt](detekt.github.io/detekt) — Static code analysis for Kotlin code.\n\n- 🌎 [ktfmt](kotlin.github.io/ktfmt/) — A program that reformats Kotlin source code to comply with the common community standard for Kotlin code conventions.\nA ktfmt IntelliJ plugin is available from the plugin repository. To install it, go to your IDE's settings and select the Plugins category. Click the Marketplace tab, search for the ktfmt plugin, and click the Install button.\n\n- 🌎 [ktlint](ktlint.github.io) — An anti-bikeshedding Kotlin linter with built-in formatter.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **diktat** :warning: — Strict coding standard for Kotlin and a linter that detects and auto-fixes code smells.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"lua\"\u003e\u003c/a\u003e\n\u003ch2\u003eLua\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;460⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;62🍴\u003c/code\u003e\u003c/b\u003e [luacheck](https://github.com/lunarmodules/luacheck)) — A tool for linting and static analysis of Lua code.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **lualint** :warning: — lualint performs luac-based static analysis of global variable usage in Lua source code.\n\n\n\n- **Luanalysis** :warning: — An IDE for statically typed Lua development.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"matlab\"\u003e\u003c/a\u003e\n\u003ch2\u003eMATLAB\u003c/h2\u003e\n\n\n- 🌎 [mlint](www.mathworks.com/help/matlab/ref/mlint.html) :copyright: — Check MATLAB code files for possible problems.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **MISS_HIT** :warning: — MISS_HIT is a free, open-source code quality toolset for MATLAB, Simulink, and Octave. It includes MH Style (style checker and formatter), MH Metrics (complexity metrics), MH Lint (static analysis), MH Trace (requirements traceability), and MH Copyright (copyright management). Designed to work standalone without requiring MATLAB/Octave installation.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"nim\"\u003e\u003c/a\u003e\n\u003ch2\u003eNim\u003c/h2\u003e\n\n\n- 🌎 [DrNim](nim-lang.org/docs/drnim.html) — DrNim combines the Nim frontend with the Z3 proof engine in order to allow verify / validate software written in Nim.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **nimfmt** :warning: — Nim code formatter / linter / style checker\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"ocaml\"\u003e\u003c/a\u003e\n\u003ch2\u003eOcaml\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;510⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;73🍴\u003c/code\u003e\u003c/b\u003e [VeriFast](https://github.com/verifast/verifast)) — A tool for modular formal verification of correctness properties of single-threaded and multithreaded  C and Java programs annotated with preconditions and postconditions written in separation logic.  To express rich specifications, the programmer can define inductive datatypes,  primitive recursive pure functions over these datatypes, and abstract separation logic predicates.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **Sys** :warning: — A static/symbolic Tool for finding bugs in (browser) code. It uses the LLVM AST to find bugs like uninitialized memory access.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"php\"\u003e\u003c/a\u003e\n\u003ch2\u003ePHP\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1381⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;60🍴\u003c/code\u003e\u003c/b\u003e [churn-php](https://github.com/bmitch/churn-php)) — Helps discover good candidates for refactoring.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;632⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;15🍴\u003c/code\u003e\u003c/b\u003e [composer-dependency-analyser](https://github.com/shipmonk-rnd/composer-dependency-analyser)) — Fast detection of composer dependency issues.\n\n* 💪 Powerful: Detects unused, shadow and misplaced composer dependencies\n* ⚡ Performant: Scans 15 000 files in 2s!\n* ⚙️ Configurable: Fine-grained ignores via PHP config\n* 🕸️ Lightweight: No composer dependencies\n* 🍰 Easy-to-use: No config needed for first try\n* ✨ Compatible: PHP \u003e= 7.2\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;533⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;24🍴\u003c/code\u003e\u003c/b\u003e [dephpend](https://github.com/mihaeu/dephpend)) — Dependency analysis tool.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;3019⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;153🍴\u003c/code\u003e\u003c/b\u003e [deptrac](https://github.com/sensiolabs-de/deptrac)) — Enforce rules for dependencies between software layers.\n\n- 🌎 [EasyCodingStandard](www.tomasvotruba.com/blog/2017/05/03/combine-power-of-php-code-sniffer-and-php-cs-fixer-in-3-lines) — Combine \u003cb\u003e\u003ccode\u003e\u0026nbsp;10774⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1445🍴\u003c/code\u003e\u003c/b\u003e [PHP_CodeSniffer](https://github.com/squizlabs/PHP_CodeSniffer)) and \u003cb\u003e\u003ccode\u003e\u0026nbsp;13554⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1647🍴\u003c/code\u003e\u003c/b\u003e [PHP-CS-Fixer](https://github.com/FriendsOfPHP/PHP-CS-Fixer)).\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;4315⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;451🍴\u003c/code\u003e\u003c/b\u003e [GrumPHP](https://github.com/phpro/grumphp)) — Checks code on every commit.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;6517⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;509🍴\u003c/code\u003e\u003c/b\u003e [larastan](https://github.com/larastan/larastan)) — Adds static analysis to Laravel improving developer productivity and code quality. It is a wrapper around PHPStan.\n\n- 🌎 [mago](mago.carthage.software) — Mago is a complete toolchain for PHP, written in Rust, designed from the ground up for maximum performance.\n- ✨ A blazing-fast formatter that automatically formats your code according to PER-CS, ending style debates forever. - 🔎 An intelligent linter that catches stylistic issues, inconsistencies, and code smells before they become problems. - 🔬 A powerful static analyzer that finds type errors and logical bugs in your code without you ever having to run it. - 🛡️ A robust architectural guard that enforces dependency rules and structural conventions.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;357⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;26🍴\u003c/code\u003e\u003c/b\u003e [parallel-lint](https://github.com/php-parallel-lint/PHP-Parallel-Lint)) — This tool checks syntax of PHP files faster than serial check with a fancier output.\n\n- 🌎 [pdepend](pdepend.org) — Calculates software metrics like cyclomatic complexity for PHP code.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?🍴\u003c/code\u003e\u003c/b\u003e [phan](https://github.com/phan/phan/wiki)) — A modern static analyzer from etsy.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1279⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;61🍴\u003c/code\u003e\u003c/b\u003e [PHP Architecture Tester](https://github.com/carlosas/phpat)) — Easy to use architecture testing tool for PHP.\n\n- 🌎 [PHP Coding Standards Fixer](cs.symfony.com) — Fixes your code according to standards like PSR-1, PSR-2, and the Symfony standard.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;5636⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;301🍴\u003c/code\u003e\u003c/b\u003e [PHP Insights](https://github.com/nunomaduro/phpinsights)) — Instant PHP quality checks from your console. Analysis of code quality and coding style as well as overview of code architecture and its complexity.\n\n- 🌎 [Php Inspections (EA Extended)](plugins.jetbrains.com/plugin/7622-php-inspections-ea-extended-) — A Static Code Analyzer for PHP.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;437⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;29🍴\u003c/code\u003e\u003c/b\u003e [PHP Semantic Versioning Checker](https://github.com/tomzx/php-semver-checker)) — Suggests a next version according to semantic versioning.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;17471⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1133🍴\u003c/code\u003e\u003c/b\u003e [PHP-Parser](https://github.com/nikic/PHP-Parser)) — A PHP parser written in PHP.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;933⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;53🍴\u003c/code\u003e\u003c/b\u003e [PHPArkitect](https://github.com/phparkitect/arkitect)) — PHPArkitect helps you to keep your PHP codebase coherent and solid, by permitting to add some architectural constraint check to your workflow. You can express the constraint that you want to enforce, in simple and readable PHP code.\n\n- 🌎 [phpDocumentor](www.phpdoc.org) — Analyzes PHP source code to generate documentation.\n\n- 🌎 [PHPMD](phpmd.org) — Finds possible bugs in your code.\n\n- [PhpMetrics](http://www.phpmetrics.org) — Calculates and visualizes various code quality metrics.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;586⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;47🍴\u003c/code\u003e\u003c/b\u003e [phpmnd](https://github.com/povils/phpmnd)) — Helps to detect magic numbers.\n\n- 🌎 [PHPQA](edgedesigncz.github.io/phpqa) — A tool for running QA tools (phploc, phpcpd, phpcs, pdepend, phpmd, phpmetrics).\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1321⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;67🍴\u003c/code\u003e\u003c/b\u003e [phpqa - jakzal](https://github.com/jakzal/phpqa)) — Many tools for PHP static analysis in one container.\n\n- 🌎 [PHPStan](phpstan.org) — PHP Static Analysis Tool - discover bugs in your code without running it!\n\n- 🌎 [Psalm](psalm.dev) — Static analysis tool for finding type errors in PHP applications.\n\n- 🌎 [rector](getrector.org) — Instant Upgrades and Automated Refactoring of any PHP 5.3+ code. It upgrades your code for PHP 7.4, 8.0 and beyond. Rector promises a low false-positive rate because it looks for narrowly defined AST (abstract syntax tree) patterns.  The main use-case are tackling technical debt in your legacy code and removing dead code. Rector provides a set of special rules for Symfony, Doctrine, PHPUnit, and many more.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;125⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;60🍴\u003c/code\u003e\u003c/b\u003e [Reflection](https://github.com/phpDocumentor/Reflection)) — Reflection library to do Static Analysis for PHP Projects\n\n- 🌎 [Symfony Insight](insight.symfony.com/) :copyright: — Detect security risks, find bugs and provide actionable metrics for PHP projects.\n\n- 🌎 [WAP](awap.sourceforge.net/) — Tool to detect and correct input validation vulnerabilities in PHP (4.0 or higher) web applications and predicts false positives by combining static analysis and data mining.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **CakeFuzzer** :warning: — Web application security testing tool for CakePHP-based web applications. CakeFuzzer employs a predefined set of attacks that are randomly modified before execution. Leveraging its deep understanding of the Cake PHP framework, Cake Fuzzer launches attacks on all potential application entry points.\n\n\n\n- **deprecation-detector** :warning: — Finds usages of deprecated (Symfony) code.\n\n\n\n- **DesignPatternDetector** :warning: — Detection of design patterns in PHP code.\n\n\n\n- **Enlightn** :warning: — A static and dynamic analysis tool for Laravel applications that provides recommendations to improve the performance, security and code reliability of Laravel apps. Contains 120 automated checks.\n\n\n\n- **exakat** :warning: — An automated code reviewing engine for PHP.\n\n\n\n- **Mondrian** :warning: — A set of static analysis and refactoring tools which use graph theory.\n\n\n\n- **Parse** :warning: — A Static Security Scanner.\n\n\n\n- **PHP Assumptions** :warning: — Checks for weak assumptions.\n\n\n\n- **PHP Refactoring Browser** :warning: — Refactoring helper.\n\n\n\n- **php-speller** :warning: — PHP spell check library.\n\n\n\n- **PHP-Token-Reflection** :warning: — Library emulating the PHP internal reflection.\n\n\n\n- **php7cc** :warning: — PHP 7 Compatibility Checker.\n\n\n\n- **php7mar** :warning: — Assist developers in porting their code quickly to PHP 7.\n\n\n\n- **PHP_CodeSniffer** :warning: — Detects violations of a defined set of coding standards.\n\n\n\n- **phpca** :warning: — Finds usage of non-built-in extensions.\n\n\n\n- **phpcpd** :warning: — Copy/Paste Detector for PHP code.\n\n\n\n- **phpdcd** :warning: — Dead Code Detector (DCD) for PHP code.\n\n\n\n- **PhpDependencyAnalysis** :warning: — Builds a dependency graph for a project.\n\n\n\n- **PhpDeprecationDetector** :warning: — Analyzer of PHP code to search issues with deprecated functionality in newer interpreter versions.  It finds removed objects (functions, variables, constants and ini-directives),  deprecated functions functionality, and usage of forbidden names or tricks (e.g. reserved identifiers in newer versions).\n\n\n\n- **phpdoc-to-typehint** :warning: — Add scalar type hints and return types to existing PHP projects using PHPDoc annotations.\n\n\n\n- **phploc** :warning: — A tool for quickly measuring the size and analyzing the structure of a PHP project.\n\n\n\n- **phpqa - jmolivas** :warning: — PHPQA all-in-one Analyzer CLI tool.\n\n\n\n- **phpsa** :warning: — Static analysis tool for PHP.\n\n\n\n- **Progpilot** :warning: — A static analysis tool for security purposes.\n\n\n\n- **Qafoo Quality Analyzer** :warning: — Visualizes metrics and source code.\n\n\n\n- **Tuli** :warning: — A static analysis engine.\n\n\n\n- **twig-lint** :warning: — twig-lint is a lint tool for your twig files.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"plsql\"\u003e\u003c/a\u003e\n\u003ch2\u003ePL/SQL\u003c/h2\u003e\n\n\n- 🌎 [ZPA](zpa.felipebz.com) — An open source parser and code analyzer for PL/SQL and Oracle SQL code.\n\n\n\n\u003ca id=\"perl\"\u003e\u003c/a\u003e\n\u003ch2\u003ePerl\u003c/h2\u003e\n\n\n- 🌎 [Perl::Critic](metacpan.org/pod/Perl::Critic) — Critique Perl source code for best-practices.\n\n- 🌎 [perltidy](perltidy.sourceforge.net/) — Perltidy is a Perl script which indents and reformats Perl scripts to make them easier to read. \nThe formatting can be controlled with command line parameters. The default parameter settings approximately follow the suggestions in the Perl Style Guide. \nBesides reformatting scripts, Perltidy can be a great help in tracking down errors with missing or extra braces, parentheses, and square brackets because it is very good at localizing errors.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;60⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;10🍴\u003c/code\u003e\u003c/b\u003e [zarn](https://github.com/htrgouvea/zarn)) — A lightweight static security analysis tool for modern Perl Apps\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **Perl::Analyzer** :warning: — Perl-Analyzer is a set of programs and modules that allow users to analyze and visualize Perl  codebases by providing information about namespaces and their relations, dependencies,  inheritance, and methods implemented, inherited, and redefined in packages,  as well as calls to methods from parent packages via SUPER. \n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"python\"\u003e\u003c/a\u003e\n\u003ch2\u003ePython\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;951⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;97🍴\u003c/code\u003e\u003c/b\u003e [autoflake](https://github.com/PyCQA/autoflake)) — Autoflake removes unused imports and unused variables from Python code.\n\n- 🌎 [autopep8](pypi.org/project/autopep8/) — A tool that automatically formats Python code to conform to the PEP 8 style guide.\nIt uses the pycodestyle utility to determine what parts of the code needs to be formatted.\n\n- 🌎 [bandit](bandit.readthedocs.io/en/latest) — A tool to find common security issues in Python code.\n\n- 🌎 [Black](black.readthedocs.io/en/stable) — The uncompromising Python code formatter.\n\n- 🌎 [deal](deal.readthedocs.io/) — Design by contract for Python. Write bug-free code.  By adding a few decorators to your code, you get for free tests, static analysis, formal verification, and much more.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;178⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;17🍴\u003c/code\u003e\u003c/b\u003e [Dlint](https://github.com/dlint-py/dlint)) — A tool for ensuring Python code is secure.\n\n- 🌎 [fixit](pypi.org/project/fixit) — A framework for creating lint rules and corresponding auto-fixes for source code.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;3824⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;360🍴\u003c/code\u003e\u003c/b\u003e [flake8](https://github.com/PyCQA/flake8)) — A wrapper around `pyflakes`, `pycodestyle` and `mccabe`.\n\n- 🌎 [Griffe](mkdocstrings.github.io/griffe/) — Signatures for entire Python programs. Extract the structure, the frame, the skeleton of your project, to generate API documentation or find breaking changes in your API.\n\n- 🌎 [jedi](jedi.readthedocs.io/en/latest) — Autocompletion/static analysis library for Python.\n\n- 🌎 [mbake](pypi.org/project/mbake/) — mbake is a Makefile formatter and linter. It only took 50 years!\n\n- 🌎 [mccabe](pypi.org/project/mccabe) — Check McCabe complexity.\n\n- [mypy](http://www.mypy-lang.org) — A static type checker that aims to combine the benefits of duck typing and static typing, frequently used with \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;5003⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;209🍴\u003c/code\u003e\u003c/b\u003e [MonkeyType](https://github.com/Instagram/MonkeyType)).\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1366⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;135🍴\u003c/code\u003e\u003c/b\u003e [pip-audit](https://github.com/pypa/pip-audit)) — Tool for scanning Python packages for known vulnerabilities. Developed by the Python Packaging Authority (PyPA) and supported by Trail of Bits and Google. Scans Python environments and requirements files to identify vulnerable packages and suggests remediation. Supports GitHub Actions, pre-commit hooks, and multiple vulnerability service integrations.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;2082⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;180🍴\u003c/code\u003e\u003c/b\u003e [prospector](https://github.com/PyCQA/prospector)) — A wrapper around `pylint`, `pep8`, `mccabe` and others.\n\n- 🌎 [pyanalyze](pyanalyze.readthedocs.io/en/latest/) — A tool for programmatically detecting common mistakes in Python code, such as references to undefined variables and type errors. It can be extended to add additional rules and perform checks specific to particular functions.\n\n- 🌎 [pycodestyle](pycodestyle.pycqa.org/en/latest) — (Formerly `pep8`) Check Python code against some of the style conventions in PEP 8.\n\n- 🌎 [pyflakes](pypi.org/project/pyflakes) — Check Python source files for errors.\n\n- [pylint](http://pylint.pycqa.org/en/latest) — Looks for programming errors, helps enforcing a coding standard and sniffs for some code smells. It additionally includes `pyreverse` (an UML diagram generator) and `symilar` (a similarities checker).\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;30⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;2🍴\u003c/code\u003e\u003c/b\u003e [Pyra](https://github.com/spangea/Pyra)) — Pyra is a high-level linter static analyzer for data science applications written in Python, that helps developers identify potential issues in their data science code written in Python, as an extension of \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;31⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;11🍴\u003c/code\u003e\u003c/b\u003e [Lyra](https://github.com/caterinaurban/Lyra)).\n\n- 🌎 [pyre-check](pyre-check.org) — A fast, scalable type checker for large Python codebases. Pyre-check has been superseded by Pyrefly, its next iteration.\n\n- 🌎 [pyrefly](pyrefly.org/) — A fast, incremental type checker and language server for Python, providing IDE features like code navigation, semantic highlighting, and code completion.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;15655⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1817🍴\u003c/code\u003e\u003c/b\u003e [pyright](https://github.com/Microsoft/pyright)) — Static type checker for Python, created to address gaps in existing tools like mypy.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;235⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;23🍴\u003c/code\u003e\u003c/b\u003e [pyroma](https://github.com/regebro/pyroma)) — Rate how well a Python project complies with the best practices of the Python packaging ecosystem, and list issues that could be improved.\n\n- 🌎 [Pysa](pyre-check.org/docs/pysa-basics.html) — A tool based on Facebook's pyre-check to identify potential security issues in Python code identified with taint analysis.\n\n- 🌎 [pyscn](ludo-technologies.github.io/pyscn/) — Intelligent Python code quality analyzer with CFG-based cyclomatic complexity analysis, dead code detection, clone detection (Type 1-4), and coupling metrics. Uses tree-sitter for parsing. Written in Go.\n\n- 🌎 [pytype](google.github.io/pytype) — A static type analyzer for Python code.\n\n- 🌎 [pyupgrade](pypi.org/project/pyupgrade-docs/) — A tool (and pre-commit hook) to automatically upgrade syntax for newer versions of the language.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;2533⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;60🍴\u003c/code\u003e\u003c/b\u003e [refurb](https://github.com/dosisod/refurb)) — A tool for refurbishing and modernizing Python codebases. Refurb is heavily inspired by clippy, the built-in linter for Rust.\n\n- 🌎 [ruff](astral.sh/ruff) — Fast Python linter, written in Rust. 10-100x faster than existing linters. Compatible with Python 3.10. Supports file watcher.\n\n- 🌎 [Safety](safetycli.com/) — Python dependency vulnerability scanner designed to enhance software supply chain security by detecting packages with known vulnerabilities. Checks Python dependencies against a database of known security vulnerabilities and provides detailed reports. Supports CI/CD integration and multiple output formats.\n\n- 🌎 [ty](docs.astral.sh/ty/) — An extremely fast Python type checker written in Rust.\n\n- 🌎 [unimport](unimport.hakancelik.dev) — A linter, formatter for finding and removing unused import statements.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;4814⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;202🍴\u003c/code\u003e\u003c/b\u003e [vulture](https://github.com/jendrikseipp/vulture)) — Find unused classes, functions and variables in Python code.\n\n- 🌎 [wemake-python-styleguide](wemake-python-styleguide.rtfd.io/) — The strictest and most opinionated python linter ever.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1329⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;68🍴\u003c/code\u003e\u003c/b\u003e [wily](https://github.com/tonybaloney/wily)) — A command-line tool for archiving, exploring and graphing the complexity of Python source code.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **bellybutton** :warning: — A linting engine supporting custom project-specific rules.\n\n\n\n- **Bowler** :warning: — Safe code refactoring for modern Python.  Bowler is a refactoring tool for manipulating Python at the syntax tree level.  It enables safe, large scale code modifications while guaranteeing that the  resulting code compiles and runs. It provides both a simple command line interface  and a fluent API in Python for generating complex code modifications in code.\n\n\n\n- **ciocheck** :warning: — Linter, formatter and test suite helper. As a linter, it is a wrapper around `pep8`, `pydocstyle`, `flake8`, and `pylint`.\n\n\n\n- **cohesion** :warning: — A tool for measuring Python class cohesion.\n\n\n\n- **Dodgy** :warning: — Dodgy is a very basic tool to run against your codebase to search for \"dodgy\" looking values. It is a series of simple regular expressions designed to detect things such as accidental SCM diff checkins, or passwords or secret keys hard coded into files.\n\n\n\n- **ENRE-py** :warning: — ENRE (ENtity Relationship Extractor) is a tool for extraction of code entity dependencies or relationships from source code. ENRE-py is a ENtity Relationship Extractor for Python based on Python Language Services of The Standard Library.\n\n\n\n- **flakeheaven** :warning: — flakeheaven is a python linter built around flake8 to enable inheritable and complex toml configuration.\n\n\n\n- **InspectorTiger** :warning: — IT, Inspector Tiger, is a modern python code review tool / framework. It comes with bunch of pre-defined handlers which warns you about improvements and possible bugs. Beside these handlers, you can write your own or use community ones.\n\n\n\n- **linty fresh** :warning: — Parse lint errors and report them to Github as comments on a pull request.\n\n\n\n- **multilint** :warning: — A wrapper around `flake8`, `isort` and `modernize`.\n\n\n\n- **py-find-injection** :warning: — Find SQL injection vulnerabilities in Python code.\n\n\n\n- **pydocstyle** :warning: — Check compliance with Python docstring conventions.\n\n\n\n- **pylyzers** :warning: — A static code analyzer / language server for Python, written in Rust, focused on type checking and readable output.\n\n\n\n- **PyT - Python Taint** :warning: — A static analysis tool for detecting security vulnerabilities in Python web applications.\n\n\n\n- **QuantifiedCode** :warning: — Automated code review \u0026 repair. It helps you to keep track of issues and metrics in your software projects, and can be easily extended to support new types of analyses.\n\n\n\n- **radon** :warning: — A Python tool that computes various metrics from the source code.\n\n\n\n- **xenon** :warning: — Monitor code complexity using \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;2030⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;140🍴\u003c/code\u003e\u003c/b\u003e [`radon`](https://github.com/rubik/radon)).\n\n\n\n- **yapf** :warning: — A formatter for Python files created by Google\nYAPF follows a distinctive methodology, originating from the 'clang-format' tool created by Daniel Jasper. Essentially, the program reframes the code to the most suitable formatting that abides by the style guide, even if the original code already follows the style guide. This concept is similar to the Go programming language's 'gofmt' tool, which aims to put an end to debates about formatting by having the entire codebase of a project pass through YAPF whenever changes are made, thereby maintaining a consistent style throughout the project and eliminating the need to argue about style in every code review.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"r\"\u003e\u003c/a\u003e\n\u003ch2\u003eR\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;93⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;15🍴\u003c/code\u003e\u003c/b\u003e [CodeDepends](https://github.com/duncantl/CodeDepends)) — Static Code Analysis for R.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;104⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;13🍴\u003c/code\u003e\u003c/b\u003e [flowR](https://github.com/flowr-analysis/flowr)) — A \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?🍴\u003c/code\u003e\u003c/b\u003e [program slicer](https://github.com/flowr-analysis/flowr/wiki/Terminology#program-slice)) and 🌎 [dataflow analyzer](en.wikipedia.org/wiki/Data-flow_analysis) for the 🌎 [R](www.r-project.org/) programming language. Its slicer allows you to reduce a complicated program just to the parts related for a specific task (e.g., the generation of a single or collection of plots, a significance test, ...). The dataflow analysis provides you with a detailed view on the semantics of the R code which can greatly improve other analyses. To use _flowR_, check out the 🌎 [Visual Studio Code extension](marketplace.visualstudio.com/items?itemName=code-inspect.vscode-flowr), the \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;6⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;0🍴\u003c/code\u003e\u003c/b\u003e [RStudio Addin](https://github.com/flowr-analysis/rstudio-addin-flowr)), the 🌎 [Docker image](hub.docker.com/r/eagleoutice/flowr), or the \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;4⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;0🍴\u003c/code\u003e\u003c/b\u003e [R package](https://github.com/flowr-analysis/flowr-r-adapter)).\n\n- 🌎 [goodpractice](docs.ropensci.org/goodpractice/) — Analyses the source code for R packages and provides best-practice recommendations.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1295⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;202🍴\u003c/code\u003e\u003c/b\u003e [lintr](https://github.com/jimhester/lintr)) — Static Code Analysis for R.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?🍴\u003c/code\u003e\u003c/b\u003e [R Language Server](https://github.com/REditorSupport/languageserver/)) — Provides code completion, refactoring, folding, diagnostics (with lintr), and more for R.\n\n- 🌎 [styler](styler.r-lib.org) — Formatting of R source code files and pretty-printing of R code.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **cyclocomp** :warning: — Quantifies the cyclomatic complexity of R functions / expressions.\n\n\n\n- **rco** :warning: — Performance optimizer for R code (with GUI).\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"rego\"\u003e\u003c/a\u003e\n\u003ch2\u003eRego\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;409⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;58🍴\u003c/code\u003e\u003c/b\u003e [Regal](https://github.com/styrainc/regal)) — Regal is a linter for the policy language Rego. Regal aims to catch bugs and mistakes in policy code, while at the same time helping people learn the language, best practices and idiomatic constructs.\n\n\n\n\u003ca id=\"ruby\"\u003e\u003c/a\u003e\n\u003ch2\u003eRuby\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1916⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;70🍴\u003c/code\u003e\u003c/b\u003e [Active Record Doctor](https://github.com/gregnavis/active_record_doctor)) — Identify database issues before they hit production.\n\n- 🌎 [brakeman](brakemanscanner.org) — A static analysis security vulnerability scanner for Ruby on Rails applications.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;7340⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;456🍴\u003c/code\u003e\u003c/b\u003e [Bullet](https://github.com/flyerhzm/bullet)) — Help to kill N+1 queries and unused eager loading.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;2760⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;247🍴\u003c/code\u003e\u003c/b\u003e [bundler-audit](https://github.com/rubysec/bundler-audit)) — Audit Gemfile.lock for gems with security vulnerabilities reported in \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1073⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;246🍴\u003c/code\u003e\u003c/b\u003e [Ruby Advisory Database](https://github.com/rubysec/ruby-advisory-db)).\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1193⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;67🍴\u003c/code\u003e\u003c/b\u003e [DatabaseConsistency](https://github.com/djezzzl/database_consistency)) — The tool to avoid various issues due to inconsistencies and inefficiencies between a database schema and application models.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;749⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;139🍴\u003c/code\u003e\u003c/b\u003e [ERB Lint](https://github.com/Shopify/erb-lint)) — Lint your ERB or HTML files\n\n- 🌎 [flay](ruby.sadi.st/Flay.html) — Flay analyzes code for structural similarities.\n\n- 🌎 [flog](ruby.sadi.st/Flog.html) — Flog reports the most tortured code in an easy to read pain report. The higher the score, the more pain the code is in.\n\n- 🌎 [rails_best_practices](rails-bestpractices.com) — A code metric tool for Rails projects\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;4130⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;282🍴\u003c/code\u003e\u003c/b\u003e [reek](https://github.com/troessner/reek)) — Code smell detector for Ruby.\n\n- 🌎 [RuboCop](docs.rubocop.org/rubocop) — A Ruby static code analyzer, based on the community Ruby style guide.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;3502⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;234🍴\u003c/code\u003e\u003c/b\u003e [rubycritic](https://github.com/whitesmith/rubycritic)) — A Ruby code quality reporter.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;938⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;60🍴\u003c/code\u003e\u003c/b\u003e [rufo](https://github.com/ruby-formatter/rufo)) — An opinionated ruby formatter, intended to be used via the command line as a text-editor plugin, to autoformat files on save or on demand.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;547⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;33🍴\u003c/code\u003e\u003c/b\u003e [Skunk](https://github.com/fastruby/skunk)) — A SkunkScore Calculator for Ruby Code -- Find the most complicated code without test coverage!\n\n- 🌎 [Sorbet](sorbet.org) — A fast, powerful type checker designed for Ruby.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;2925⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;233🍴\u003c/code\u003e\u003c/b\u003e [Standard Ruby](https://github.com/testdouble/standard)) — Ruby Style Guide, with linter \u0026 automatic code fixer\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1490⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;118🍴\u003c/code\u003e\u003c/b\u003e [Steep](https://github.com/soutaro/steep)) — Gradual Typing for Ruby.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **cane** :warning: — Code quality threshold checking as part of your build.\n\n\n\n- **Churn** :warning: — A Project to give the churn file, class, and method for a project for a given checkin. Over time the tool adds up the history of churns to give the number of times a file, class, or method is changing during the life of a project.\n\n\n\n- **dawnscanner** :warning: — A static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.\n\n\n\n- **ERB::Formatter** :warning: — Format ERB files with speed and precision.\n\n\n\n- **Fasterer** :warning: — Common Ruby idioms checker.\n\n\n\n- **Fukuzatsu** :warning: — A tool for measuring code complexity in Ruby class files. Its analysis generates scores based on cyclomatic complexity algorithms with no added \"opinions\".\n\n\n\n- **htmlbeautifier** :warning: — A normaliser/beautifier for HTML that also understands embedded Ruby. Ideal for tidying up Rails templates.\n\n\n\n- **laser** :warning: — Static analysis and style linter for Ruby code.\n\n\n\n- **MetricFu** :warning: — MetricFu is a set of tools to provide reports that show which parts of your code might need extra work.\n\n\n\n- **pelusa** :warning: — Static analysis Lint-type tool to improve your OO Ruby code.\n\n\n\n- **quality** :warning: — Runs quality checks on your code using community tools, and makes sure your numbers don't get any worse over time.\n\n\n\n- **Querly** :warning: — Pattern Based Checking Tool for Ruby.\n\n\n\n- **Railroader** :warning: — An open source static analysis security vulnerability scanner for Ruby on Rails applications.\n\n\n\n- **Roodi** :warning: — Roodi stands for Ruby Object Oriented Design Inferometer. It parses your Ruby code and warns you about design issues you have based on the checks that it has configured.\n\n\n\n- **Rubrowser** :warning: — Ruby classes interactive dependency graph generator.\n\n\n\n- **ruby-lint** :warning: — Static code analysis for Ruby.\n\n\n\n- **Saikuro** :warning: — A Ruby cyclomatic complexity analyzer.\n\n\n\n- **SandiMeter** :warning: — Static analysis tool for checking Ruby code for Sandi Metz' rules.\n\n\n\n- **Traceroute** :warning: — A Rake task gem that helps you find the unused routes and controller actions for your Rails 3+ app.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"rust\"\u003e\u003c/a\u003e\n\u003ch2\u003eRust\u003c/h2\u003e\n\n\n- 🌎 [C2Rust](c2rust.com) — C2Rust helps you migrate C99-compliant code to Rust. The translator (or transpiler) produces unsafe Rust code that closely mirrors the input C code.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;2136⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;53🍴\u003c/code\u003e\u003c/b\u003e [cargo udeps](https://github.com/est31/cargo-udeps)) — Find unused dependencies in Cargo.toml. It either prints out a \"unused crates\" line listing the crates,  or it prints out a line saying that no crates were unused.\n\n- 🌎 [cargo-audit](rustsec.org) — Audit Cargo.lock for crates with security vulnerabilities reported to the \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?🍴\u003c/code\u003e\u003c/b\u003e [RustSec Advisory Database](https://github.com/RustSec/advisory-db/)).\n\n- 🌎 [cargo-deny](embarkstudios.github.io/cargo-deny) — A cargo plugin for linting your dependencies. It can be used either as a command line too, a Rust crate, or a Github action for CI. It checks for valid license information, duplicate crates, security vulnerabilities, and more.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;3128⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;78🍴\u003c/code\u003e\u003c/b\u003e [cargo-expand](https://github.com/dtolnay/cargo-expand)) — Cargo subcommand to show result of macro expansion  and #[derive] expansion applied to the current crate.  This is a wrapper around a more verbose compiler command.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1651⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;80🍴\u003c/code\u003e\u003c/b\u003e [cargo-geiger](https://github.com/geiger-rs/cargo-geiger)) — A cargo plugin for analysing the usage of unsafe Rust code Provides statistical output to aid security auditing\n\n- 🌎 [cargo-semver-checks](crates.io/crates/cargo-semver-checks) — Scan your Rust crate releases for semver violations. It can be used either directly via the CLI, as a GitHub Action in CI,  or via release managers like `release-plz`. It found semver violations in  🌎 [more than 1 in 6 of the top 1000 most-downloaded crates](predr.ag/blog/semver-violations-are-common-better-tooling-is-the-answer/) on crates.io.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;981⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;50🍴\u003c/code\u003e\u003c/b\u003e [cargo-show-asm](https://github.com/pacak/cargo-show-asm)) — cargo subcommand showing the assembly, LLVM-IR and MIR generated for Rust code\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;364⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;39🍴\u003c/code\u003e\u003c/b\u003e [cargo-spellcheck](https://github.com/drahnr/cargo-spellcheck)) — Checks all your documentation for spelling and grammar mistakes  with hunspell (ready) and languagetool (preview)\n\n- 🌎 [clippy](rust-lang.github.io/rust-clippy) — A code linter to catch common mistakes and improve your Rust code.\n\n- 🌎 [diff.rs](diff.rs) — Web application (WASM) to render a diff between Rust crate versions.\n\n- 🌎 [dylint](blog.trailofbits.com/2021/11/09/write-rust-lints-without-forking-clippy/) — A tool for running Rust lints from dynamic libraries. Dylint makes it easy for developers to maintain their own personal lint collections.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;3477⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;177🍴\u003c/code\u003e\u003c/b\u003e [kani](https://github.com/model-checking/kani)) — The Kani Rust Verifier is a bit-precise model checker for Rust. \nKani is particularly useful for verifying unsafe code blocks in Rust, \nwhere the \"unsafe superpowers\" are unchecked by the compiler.\nKani verifies:\n\n* Memory safety (e.g., null pointer dereferences)\n* User-specified assertions (i.e., assert!(...))\n* The absence of panics (e.g., unwrap() on None values)\n* The absence of some types of unexpected behavior (e.g., arithmetic overflows)\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;591⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;39🍴\u003c/code\u003e\u003c/b\u003e [lockbud](https://github.com/BurtonQin/lockbud)) — Statically detects Rust deadlocks bugs. It currently detects two common kinds of deadlock bugs: doublelock and locks in conflicting order. It will print bugs in JSON format together with the source code location and an explanation of each bug.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1367⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;48🍴\u003c/code\u003e\u003c/b\u003e [Rudra](https://github.com/sslab-gatech/Rudra)) — Rust Memory Safety \u0026 Undefined Behavior Detection. It is capable of analyzing single Rust packages as well as all the packages on crates.io.\n\n- 🌎 [rust-analyzer](rust-analyzer.github.io) — Supports functionality such as 'goto definition', type inference, symbol search, reformatting, and code completion, and enables renaming and refactorings.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;859⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;44🍴\u003c/code\u003e\u003c/b\u003e [rust-audit](https://github.com/Shnatsel/rust-audit)) — Audit Rust binaries for known bugs or security vulnerabilities. This works by embedding data about the dependency tree (Cargo.lock) in JSON format into a dedicated linker section of the compiled executable.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;6971⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1054🍴\u003c/code\u003e\u003c/b\u003e [rustfmt](https://github.com/rust-lang/rustfmt)) — A tool for formatting Rust code according to style guidelines.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;2851⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;75🍴\u003c/code\u003e\u003c/b\u003e [RustViz](https://github.com/rustviz/rustviz)) — RustViz is a tool that generates visualizations  from simple Rust programs to assist users in better  understanding the Rust Lifetime and Borrowing mechanism. It generates SVG files with graphical indicators that integrate  with mdbook to render visualizations of data-flow in Rust programs.\n\n- 🌎 [TangleGuard](tangleguard.com/) :copyright: — Helps you understand and maintain a scalable software architecture. To do so, it generates a interactive, nested dependency graph out of the source code. You can choose the level of details and get the portion of your codebase that matters to you.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **cargo-bloat** :warning: — Find out what takes most of the space in your executable. supports ELF (Linux, BSD), Mach-O (macOS) and PE (Windows) binaries.\n\n\n\n- **cargo-breaking** :warning: — cargo-breaking compares a crate's public API between two different branches, shows what changed, and suggests the next version according to semver.\n\n\n\n- **cargo-call-stack** :warning: — Whole program static stack analysis The tool produces the full call graph of a program as a dot file.\n\n\n\n- **cargo-inspect** :warning: — Inspect Rust code without syntactic sugar to see what the compiler does behind the curtains.\n\n\n\n- **cargo-unused-features** :warning: — Find potential unused enabled feature flags and prune them. You can generate a simple HTML report from the json to make it easier to inspect results.\nIt removes a feature of a dependency and then compiles the project to see if it still compiles. If it does, the feature flag can possibly be removed, but it can be a false-positive.\n\n\n\n- **electrolysis** :warning: — A tool for formally verifying Rust programs by transpiling them into definitions in the Lean theorem prover.\n\n\n\n- **herbie** :warning: — Adds warnings or errors to your crate when using a numerically unstable floating point expression.\n\n\n\n- **linter-rust** :warning: — Linting your Rust-files in Atom, using rustc and cargo.\n\n\n\n- **MIRAI** :warning: — And abstract interpreter operating on Rust's mid-level intermediate language, and providing warnings based on taint analysis.\n\n\n\n- **prae** :warning: — Provides a convenient macro that allows you to generate type wrappers  that promise to always uphold arbitrary invariants that you specified. \n\n\n\n- **Prusti** :warning: — A static verifier for Rust, based on the Viper verification infrastructure. By default Prusti verifies absence of panics by proving that statements such as unreachable!() and panic!() are unreachable.\n\n\n\n- **Rust Language Server** :warning: — Supports functionality such as 'goto definition', symbol search, reformatting, and code completion, and enables renaming and refactorings.\n\n\n\n- **rustfix** :warning: — Read and apply the suggestions made by rustc (and third-party lints, like those offered by clippy).\n\n\n\n- **warnalyzer** :warning: — Show unused code from multi-crate Rust projects\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"sql\"\u003e\u003c/a\u003e\n\u003ch2\u003eSQL\u003c/h2\u003e\n\n\n- 🌎 [Bytebase](www.bytebase.com) — Database DevSecOps platform with a built-in SQL Review engine that lints schema migrations and queries against 100+ configurable rules — naming conventions, anti-patterns, and safety checks — across MySQL, PostgreSQL, Oracle, SQL Server, Snowflake, and more.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;180⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;2🍴\u003c/code\u003e\u003c/b\u003e [dbcritic](https://github.com/channable/dbcritic)) — dbcritic finds problems in a database schema, such as a missing primary key constraint in a table.\n\n- 🌎 [holistic](holistic.dev/) — More than 1,300 rules to analyze SQL queries. Takes an SQL schema definition and the query source code to generate improvement recommendations. Detects code smells, unused indexes, unused tables, views, materialized views, and more.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;148⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;10🍴\u003c/code\u003e\u003c/b\u003e [pgspot](https://github.com/timescale/pgspot)) — Spot vulnerabilities in postgres extension scripts. Finds unsafe search_path usage and unsafe object creation in PostgreSQL extension scripts or any other PostgreSQL SQL code.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;71⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;6🍴\u003c/code\u003e\u003c/b\u003e [scythe](https://github.com/Goldziher/scythe)) — Polyglot SQL compiler and linter that generates type-safe code from SQL with schema-aware linting.\n\n- 🌎 [SQLFluff](www.sqlfluff.com/) — Multiple dialect SQL linter and formatter.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;441⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;26🍴\u003c/code\u003e\u003c/b\u003e [sqlint](https://github.com/purcell/sqlint)) — Simple SQL linter.\n\n- 🌎 [squawk](squawkhq.com) — Linter for PostgreSQL, focused on migrations. Prevents unexpected downtime caused by database migrations and encourages best practices around Postgres schemas and SQL.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;230⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;75🍴\u003c/code\u003e\u003c/b\u003e [tsqllint](https://github.com/tsqllint/tsqllint)) — T-SQL-specific linter.\n\n- 🌎 [Visual Expert](www.visual-expert.com) :copyright: — Code analysis for PowerBuilder, Oracle, and SQL Server Explores, analyzes, and documents Code \n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **sleek** :warning: — Sleek is a CLI tool for formatting SQL.  It helps you maintain a consistent style across your SQL code, enhancing readability and productivity. The heavy lifting is done by the sqlformat crate.\n\n\n\n- **sqlcheck** :warning: — Automatically identify anti-patterns in SQL queries.\n\n\n\n- **TSqlRules** :warning: — TSQL Static Code Analysis Rules for SQL Server.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"scala\"\u003e\u003c/a\u003e\n\u003ch2\u003eScala\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;557⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;95🍴\u003c/code\u003e\u003c/b\u003e [scapegoat](https://github.com/sksamuel/scapegoat)) — Scala compiler plugin for static code analysis.\n\n- 🌎 [WartRemover](www.wartremover.org) — A flexible Scala code linting tool.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **linter** :warning: — Linter is a Scala static analysis compiler plugin which adds compile-time checks for various possible bugs, inefficiencies, and style problems.\n\n\n\n- **Scalastyle** :warning: — Scalastyle examines your Scala code and indicates potential problems with it.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"shell\"\u003e\u003c/a\u003e\n\u003ch2\u003eShell\u003c/h2\u003e\n\n\n- 🌎 [sh](pkg.go.dev/mvdan.cc/sh/v3) — A shell parser, formatter, and interpreter with bash support; includes shfmt\n\n- 🌎 [shellcheck](www.shellcheck.net) — ShellCheck, a static analysis tool that gives warnings and suggestions for bash/sh shell scripts.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;4806⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;133🍴\u003c/code\u003e\u003c/b\u003e [shellharden](https://github.com/anordal/shellharden)) — A syntax highlighter and a tool to semi-automate the rewriting of scripts to ShellCheck conformance, mainly focused on quoting.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **bashate** :warning: — Code style enforcement for bash programs. The output format aims to follow pycodestyle (pep8) default output format.\n\n\n\n- **i-Code CNES for Shell** :warning: — An open source static code analysis tool for Shell and Fortran (77 and 90).\n\n\n\n- **kmdr** :warning: — CLI tool for learning commands from your terminal. kmdr delivers a break down of commands with every attribute explained.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"swift\"\u003e\u003c/a\u003e\n\u003ch2\u003eSwift\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;8931⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;701🍴\u003c/code\u003e\u003c/b\u003e [SwiftFormat](https://github.com/nicklockwood/SwiftFormat)) — A library and command-line formatting tool for reformatting Swift code.\n\n- 🌎 [SwiftLint](realm.github.io/SwiftLint) — A tool to enforce Swift style and conventions.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **Tailor** :warning: — A static analysis and lint tool for source code written in Apple's Swift programming language.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"tcl\"\u003e\u003c/a\u003e\n\u003ch2\u003eTcl\u003c/h2\u003e\n\n\n- [Frink](http://catless.ncl.ac.uk/Programs/Frink) — A Tcl formatting and static check program (can prettify the program, minimise, obfuscate or just sanity check it).\n\n- 🌎 [Nagelfar](sourceforge.net/projects/nagelfar) — A static syntax checker for Tcl.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;86⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;38🍴\u003c/code\u003e\u003c/b\u003e [tclchecker](https://github.com/ActiveState/tdk/blob/master/docs/3.0/TDK_3.0_Checker.txt)) — A static syntax analysis module (as part of \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;86⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;38🍴\u003c/code\u003e\u003c/b\u003e [TDK](https://github.com/ActiveState/tdk))).\n\n\n\n\u003ca id=\"typescript\"\u003e\u003c/a\u003e\n\u003ch2\u003eTypeScript\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;1785⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;274🍴\u003c/code\u003e\u003c/b\u003e [Angular ESLint](https://github.com/angular-eslint/angular-eslint#readme)) — Linter for Angular projects\n\n- 🌎 [fta](ftaproject.dev/) — Rust-based static analysis for TypeScript projects\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;291⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;24🍴\u003c/code\u003e\u003c/b\u003e [TypeScript Call Graph](https://github.com/whyboris/TypeScript-Call-Graph)) — CLI to generate an interactive graph of functions and calls from your TypeScript files\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;16395⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;3020🍴\u003c/code\u003e\u003c/b\u003e [TypeScript ESLint](https://github.com/typescript-eslint/typescript-eslint)) — TypeScript language extension for eslint.\n\n- 🌎 [zod](zod.dev) — TypeScript-first schema validation with static type inference. The goal is to eliminate duplicative type declarations. With Zod, you declare a validator once and Zod will automatically infer the static TypeScript type. It is easy to compose simpler types into complex data structures.\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **Codelyzer** :warning: — A set of tslint rules for static code analysis of Angular 2 TypeScript projects.\n\n\n\n- **ENRE-ts** :warning: — ENRE (ENtity Relationship Extractor) is a tool for extraction of code entity dependencies or relationships from source code. ENRE-ts is a ENtity Relationship Extractor for ECMAScript and TypeScript based on @babel/parser.\n\n\n\n- **stc** :warning: — Speedy TypeScript type checker written in Rust\n\n\n\n- **tslint** :warning: — TSLint has been deprecated as of 2019. Please see \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;?🍴\u003c/code\u003e\u003c/b\u003e [this issue](https://github.com/palantir/tslint/issues/4534)) for more details. `typescript-eslint` is now your best option for linting TypeScript.\nTSLint is an extensible static analysis tool that checks TypeScript code for readability, maintainability,  and functionality errors. It is widely supported across modern editors \u0026 build systems and can be customized  with your own lint rules, configurations, and formatters.\n\n\n\n- **tslint-clean-code** :warning: — A set of TSLint rules inspired by the Clean Code handbook.\n\n\n\n- **tslint-microsoft-contrib** :warning: — A set of tslint rules for static code analysis of TypeScript projects maintained by Microsoft.\n\n\u003c/details\u003e\n\n\n\n\u003ca id=\"verilog\"\u003e\u003c/a\u003e\n\u003ch2\u003eVerilog/SystemVerilog\u003c/h2\u003e\n\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;585⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;31🍴\u003c/code\u003e\u003c/b\u003e [svls](https://github.com/dalance/svls)) — A Language Server Protocol implementation for Verilog and SystemVerilog, including lint capabilities.\n\n- 🌎 [Verilator](www.veripool.org/verilator) — A tool which converts Verilog to a cycle-accurate behavioral model in C++ or SystemC. Performs lint code-quality checks.\n\n- \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;387⭐\u003c/code\u003e\u003c/b\u003e \u003cb\u003e\u003ccode\u003e\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;84🍴\u003c/code\u003e\u003c/b\u003e [vscode-verilog-hdl-support](https://github.com/mshr-h/vscode-verilog-hdl-support)) — Verilog HDL/SystemVerilog/Bluespec SystemVerilog support for VS Code. Provides syntax highlighting and Linting support from Icarus Verilog, Vivado Logical Simulation, Modelsim and Verilator\n\n\n\n\u003cdetails\u003e\n\u003csummary\u003eShow Deprecated\u003c/summary\u003e\n\n- **Icarus Verilog** :warning: — A Verilog simulation and synthesis tool that oper","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/correia-jpv%2Ffucking-static-analysis/projects"}