Flawfinder Alternatives

Flawfinder is described as 'Examines C/C++ source code and reports possible security weaknesses ("flaws'') sorted by risk level. It's very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public' and is an app in the development category. There are more than 10 alternatives to Flawfinder for a variety of platforms, including Windows, Linux, Mac, Web-based and Visual Studio Code apps. The best Flawfinder alternative is SonarQube, which is both free and Open Source. Other great apps like Flawfinder are Shellcheck, Cppcheck, Coverity Scan and VibeGuard.

Copy a direct link to this comment to your clipboard
Alternatives
Get a badge for your siteFlawfinder alternatives page was last updated

Alternatives list

  1. SonarQube icon
     28 likes

    SonarQube is an open source quality management platform, dedicated to continuously analyze and measure source code quality, from the portfolio to the method. Static code analysis is available in the "Community Edition" (free / open source) for:

    41 SonarQube alternatives

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    Good alternative?
     
  2. Shellcheck icon
     4 likes

    A simple tool for finding bugs in shell scripts.

    Cost / License

    Platforms

    • Online
    • Visual Studio Code
    • Vim
    • Sublime Text
    • GNU Emacs
    • Atom
    Good alternative?
     
  3. Cppcheck icon
     23 likes

    Cppcheck is an static analysis tool for C/C++ code. Unlike C/C++ compilers and many other analysis tools it does not detect syntax errors in the code. Cppcheck primarily detects the types of bugs that the compilers normally do not detect.

    Cost / License

    Platforms

    • Windows
    • Linux
    • PortableApps.com
    • Eclipse
    Good alternative?
     
  4. Coverity Scan Static Analysis allows to find and fix defects in your Java, C/C++ or C# open source project for free.

    Cost / License

    • Freemium
    • Proprietary

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • BSD
    Good alternative?
     
  5. VibeGuard icon
     1 like

    Security linter that catches vulnerabilities in AI-generated code from Copilot, Cursor, Claude, and ChatGPT.

    Cost / License

    • Free
    • Open Source (MIT)

    Platforms

    • Online
    • Mac
    • Linux
    • Windows
    Good alternative?
     
  6. SlowQL icon
     1 like

    SlowQL is a production-focused offline SQL static analyzer that catches security vulnerabilities, performance regressions, reliability issues, compliance risks, cost inefficiencies, and code quality problems before they reach production.

    Cost / License

    • Free
    • Open Source

    Platforms

    • Docker
    • Windows
    • Mac
    • Linux
    Good alternative?
     
  7. Semgrep icon
     1 like

    Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or...

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    Good alternative?
     
  8.  2 likes

    Splint is a tool for statically checking C programs for security vulnerabilities and coding mistakes. With minimal effort, Splint can be used as a better lint. If additional effort is invested adding annotations to programs, Splint can perform stronger checking than can be done...

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Windows
    • Linux
    Good alternative?
     
  9.  Like

    EDoC++ is a C++ source analysis tool designed to identify problems associated with the use of exceptions in C++ code. Additionally EDoC++ can be used to generate detailed documentation

    Cost / License

    • Free
    • Open Source

    Platforms

    • Windows
    Good alternative?
     
  10. Astrée icon
     Like

    Astrée statically analyzes whether the programming language is used correctly and whether there can be any runtime errors during any execution in any environment. This covers any use of C or C++ that, according to the selected language standard, has undefined behavior or...

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Windows
    • Linux
    Good alternative?
     
  11. VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:

    Cost / License

    Platforms

    • Windows
    Good alternative?
     
  12. Code Buster reports dependency wiring, dead code, cycles, duplication, complexity, architecture-policy violations, feature flags, security and style heuristics, quality scores, and remediation plans.

    Cost / License

    • Free
    • Open Source (MIT)

    Platforms

    • Windows
    • Mac
    • Linux
    Good alternative?
     
12 of 16 Flawfinder alternatives