Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

CodeSonar uses a unified dataflow with symbolic execution analysis to examine the entire application's computations. CodeSonar's static analyze engine is extremely deep and does not rely on pattern matching or similar approximations. It finds 3-5 times more defects than other static analysis tools. SAST tools are able to be easily integrated into any team's software development process, unlike many other tools such as testing tools and compilers. SAST technologies such as CodeSonar attach to existing build environments to add analysis information. CodeSonar works in the same way as a compiler. However, CodeSonar creates an abstraction model of your entire program, instead of creating object codes. CodeSonar's symbolic execution engine analyzes the derived model and makes connections between them.

Description

The Secure Programming Group at the University of Virginia's Department of Computer Science is responsible for the development and ongoing maintenance of Splint. David Evans leads the project and serves as its main developer. Memory bounds checking was created by David Larochelle. Significant contributions to Splint's development were also made by University of Virginia students, including Chris Barker, David Friedman, Mike Lanouette, and Hien Phan. Splint serves as the evolution of LCLint, a tool that originated from a collaborative research effort between the Massachusetts Institute of Technology and Digital Equipment Corporation's System Research Center. David Evans was also the chief designer and developer of LCLint. The initial concept for a static checking tool aimed at identifying discrepancies between LCL specifications and their C implementations came from John Guttag and Jim Horning. Their insights into the design and functionality proved invaluable, playing a crucial role in shaping both LCLint and its successor, Splint. Together, the team has fostered a robust environment for developing tools that enhance software reliability and security.

API Access

Has API Yes 

API Access

Has API No 

Screenshots View All

Screenshots View All

No images available

Integrations

C Yes 
C++ Yes 
Amazon Web Services (AWS) Yes 
Android Yes 
C# Yes 
CodeSentry Yes 
Docker Yes 
Eclipse IDE Yes 
GitLab Yes 
Java Yes 
JavaScript Yes 
Jenkins Yes 
Jira Yes 
Kotlin Yes 
MATLAB No 
Python Yes 
Rust Yes 
Seeker Yes 
Visual Studio Yes 
Visual Studio Code Yes 

Integrations

C Yes 
C++ Yes 
Amazon Web Services (AWS) No 
Android No 
C# No 
CodeSentry No 
Docker No 
Eclipse IDE No 
GitLab No 
Java No 
JavaScript No 
Jenkins No 
Jira No 
Kotlin No 
MATLAB Yes 
Python No 
Rust No 
Seeker No 
Visual Studio No 
Visual Studio Code No 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Pricing Details

No price information available.
Free Trial No 
Free Version Yes 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

CodeSecure

Country

United States

Website

www.grammatech.com/products/source-code-analysis

Vendor Details

Company Name

University of Virginia

Founded

2007

Country

United States

Website

splint.org

Product Features

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Static Code Analysis

Analytics / Reporting No 
Code Standardization / Validation No 
Multiple Programming Language Support No 
Provides Recommendations No 
Standard Security/Industry Libraries No 
Vulnerability Management No 

Product Features

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Static Code Analysis

Analytics / Reporting No 
Code Standardization / Validation No 
Multiple Programming Language Support No 
Provides Recommendations No 
Standard Security/Industry Libraries No 
Vulnerability Management No 

Alternatives

Flawnter Reviews

Flawnter

CyberTest

Alternatives

MB&G MobileMap Reviews

MB&G MobileMap

Mason Bruce & Girard
david3 Reviews

david3

Tobit Software
SonarQube Cloud Reviews

SonarQube Cloud

SonarSource
david.net Reviews

david.net

2R Software GmbH
SonarQube Server Reviews

SonarQube Server

SonarSource
Oscar Reviews

Oscar

Oscar McMaster