Coverity
Black Duck
A build-integrated static analyzer known for deep interprocedural analysis of C and C++, covering memory safety, concurrency and injection defects.
SAST
Analyze source code or bytecode for vulnerable patterns without running the application.
31 tools profiled
How it differs Reads the code you wrote without running it. SCA checks the third party packages you depend on; IAST watches the running app while your tests exercise it.
Black Duck
A build-integrated static analyzer known for deep interprocedural analysis of C and C++, covering memory safety, concurrency and injection defects.
Kiuwan (Idera)
A static analysis platform pairing security rules with code quality and technical debt metrics, covering both modern and legacy enterprise languages.
OpenText
A long-established enterprise static analyzer with very broad language support, rule-driven taint analysis and detailed compliance reporting.
Black Duck
A build-integrated static analyzer known for deep interprocedural analysis of C and C++, covering memory safety, concurrency and injection defects.
Kiuwan (Idera)
A static analysis platform pairing security rules with code quality and technical debt metrics, covering both modern and legacy enterprise languages.
OpenText
A long-established enterprise static analyzer with very broad language support, rule-driven taint analysis and detailed compliance reporting.