SonarQube
softwareAbout
Self-managed code quality and security analysis platform. Performs static analysis to detect bugs, vulnerabilities, and code smells across 30+ programming languages.
Overview
SonarQube is the leading code quality and security analysis platform, providing continuous inspection of code to detect bugs, vulnerabilities, and code smells. Its integration into CI/CD pipelines makes it essential for teams prioritizing code quality at scale.
Pros
- +Industry standard for code quality
- +Rich rule set
- +Self-hosted (data stays on premises)
- +Community edition is free
Cons
- -Self-hosted requires maintenance
- -UI feels dated
- -Can be slow on large codebases
- -Advanced features require paid edition
This may be an affiliate link — the creator and GuruStacks may earn a commission, at no extra cost to you. Learn more
Details
Pricing
Model
open source
Platforms
Community
Listed in Stacks
SaaS Developer
The complete developer toolkit for building, shipping, and scaling SaaS products — from code editors and CI/CD to payments, monitoring, and AI-powered development tools.
DevOps Engineer Stack
Comprehensive DevOps engineering tools and platforms for CI/CD, infrastructure automation, monitoring, and cloud operations
Related
Similar tools
View alternatives →Codiga
4.4Real-time static code analysis tool that detects security vulnerabilities and coding issues across IDEs and CI/CD pipelines with customizable rules.
Checkov
4.4Policy-as-code static analysis tool that scans IaC configurations across Terraform, CloudFormation, and Kubernetes for security misconfigurations.
Slither
4.2Static analysis framework for Solidity smart contracts detecting vulnerabilities and code quality issues
Snyk
4.4Developer-first security platform that finds and fixes vulnerabilities in code, open-source dependencies, containers, and infrastructure as code. Integrates into the development workflow.
Coolify
4.4Open-source, self-hostable PaaS alternative to Vercel, Heroku, and Netlify. Deploy static sites, databases, and 280+ services on your own servers.
Harbor
4.4Open-source cloud-native container registry that provides vulnerability scanning, image signing, content trust, and role-based access control for container images.