Open source static-analysis projects
Every project in the registry tagged static-analysis, ranked by real GitHub adoption.
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked contex
🐶 Automated code review tool integrated with any code analysis tools regardless of programming language
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by
Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.
Frequently asked questions
How many open source static-analysis projects are there?
This registry tracks 4 projects tagged static-analysis, with 51,906 GitHub stars between them. The most-adopted is code-review-graph at 31,548 stars.
Are these static-analysis projects free to use?
Yes — 4 of the 4 carry an explicit open-source licence across 2 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.
Which static-analysis project should I choose?
The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.
Are these static-analysis projects still maintained?
4 of the 4 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.