We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀
Cost / License
- Free
- Open Source (LGPL-2.1)
Platforms
- Mac
- Linux




Flawfinder is described as 'Examines C/C++ source code and reports possible security weaknesses ("flaws'') sorted by risk level. It's very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public' and is an app in the development category. There are more than 10 alternatives to Flawfinder for a variety of platforms, including Windows, Linux, Mac, Web-based and Visual Studio Code apps. The best Flawfinder alternative is SonarQube, which is both free and Open Source. Other great apps like Flawfinder are Shellcheck, Cppcheck, Coverity Scan and SlowQL.
We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀




Facebook Infer is a static analysis tool - if you give Infer some Objective-C, Java, or C code, it produces a list of potential bugs.