Java static-code-analysis

Open-source Java projects categorized as static-code-analysis

Top 11 Java static-code-analysis Projects

static-code-analysis
  1. Checkstyle

    Checkstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.

    Project mention: Contribution Instructions: Formate Code and Linting | dev.to | 2024-11-01

    We had a list of suggested code formation tools, as my code was written in Java I decided to use suggested formatter GoogleJavaFormat. However, I didn't decide to pick suggested tool for Linter. I picked Checkstyle; for the reason, that SpotBugs wasn't available for JDK 22.

  2. Sevalla

    Deploy and host your apps and databases, now with $50 credit! Sevalla is the PaaS you have been looking for! Advanced deployment pipelines, usage-based pricing, preview apps, templates, human support by developers, and much more!

    Sevalla logo
  3. PMD

    An extensible multilanguage static code analyzer.

    Project mention: Top 17 Must-Have Resources for Software Refactoring Excellence | dev.to | 2025-06-23

    Utilize PMD for Code Analysis

  4. NullAway

    A tool to help eliminate NullPointerExceptions (NPEs) in your Java code with low build-time overhead

  5. Spotbugs

    SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.

  6. phpinspectionsea

    A Static Code Analyzer for PHP (a PhpStorm/Idea Plugin)

  7. SonarJava

    :coffee: SonarSource Static Analyzer for Java Code Quality and Security

  8. SootUp

    A new version of Soot with a completely overhauled architecture

    Project mention: Show HN: FlowTracker – Track data flowing through Java programs | news.ycombinator.com | 2024-09-13

    Last time I was this blown away was with jitwatch ( https://github.com/AdoptOpenJDK/jitwatch )

    FlowTracker reminds me a little of taint analysis, which is used for tracking unvalidated user inputs or secrets through a program, making sure it is not leaked or used without validation.

    search keywords are "dynamic taint tracking/analysis"

    https://github.com/gmu-swe/phosphor

    https://github.com/soot-oss/SootUp

    https://github.com/feliam/klee-taint

  9. InfluxDB

    InfluxDB – Built for High-Performance Time Series Workloads. InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.

    InfluxDB logo
  10. sonar-php

    :elephant: SonarPHP: PHP static analyzer for SonarQube & SonarLint

  11. forbidden-apis

    Policeman's Forbidden API Checker

  12. warnings-ng-plugin

    Jenkins Warnings Plugin - Next Generation

  13. fb-contrib

    a FindBugs/SpotBugs plugin for doing static code analysis for java code bases

NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Java static-code-analysis discussion

Log in or Post with

Java static-code-analysis related posts

  • Análise Comparativa: Aider vs. PMD vs. Semgrep

    3 projects | dev.to | 27 Feb 2025
  • Contribution Instructions: Formate Code and Linting

    2 projects | dev.to | 1 Nov 2024
  • Show HN: FlowTracker – Track data flowing through Java programs

    7 projects | news.ycombinator.com | 13 Sep 2024
  • We Have Code Quality At Home: Open Source Java Code Quality Tools

    4 projects | dev.to | 6 May 2024
  • Handling EI_EXPOSE_REP & EI_EXPOSE_REP2 👨🏻‍💻

    1 project | dev.to | 30 Apr 2024
  • PMD 7 Is Here

    1 project | news.ycombinator.com | 22 Mar 2024
  • Amazon CodeGuru Reviewer: already time for retirement?

    2 projects | dev.to | 1 Aug 2023
  • A note from our sponsor - InfluxDB
    www.influxdata.com | 1 Sep 2025
    InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now. Learn more →

Index

What are some of the best open-source static-code-analysis projects in Java? This list will help you:

# Project Stars
1 Checkstyle 8,658
2 PMD 5,190
3 NullAway 3,836
4 Spotbugs 3,725
5 phpinspectionsea 1,471
6 SonarJava 1,179
7 SootUp 727
8 sonar-php 416
9 forbidden-apis 354
10 warnings-ng-plugin 348
11 fb-contrib 163

Sponsored
Deploy and host your apps and databases, now with $50 credit!
Sevalla is the PaaS you have been looking for! Advanced deployment pipelines, usage-based pricing, preview apps, templates, human support by developers, and much more!
sevalla.com