Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

OpenText Static Application Security Testing (SAST) provides precise identification and remediation of application security flaws directly within source code, helping organizations reduce risks early in development. The platform supports over 33 major programming languages and frameworks, enabling broad language coverage for diverse development environments. It integrates smoothly with widely used CI/CD pipelines and developer tools such as Jenkins, Atlassian Bamboo, Azure DevOps, and Microsoft Visual Studio, ensuring security fits naturally into existing workflows. AI-driven analysis prioritizes vulnerabilities and dramatically reduces false positives by customizing rules and scan depths, speeding up development cycles by up to 25%. OpenText SAST meets compliance benchmarks like OWASP 1.2b, offering developers detailed guidance to efficiently fix issues and improve code quality. Its flexible deployment options include multi-tenant SaaS, private cloud, and on-premises installations, allowing organizations to scale securely and according to their infrastructure needs. Backed by a dedicated Software Security Research team, the solution receives agile updates to stay current with emerging threats. Customers praise the tool for reducing manual code review efforts while increasing vulnerability detection accuracy.

Description

PVS-Studio is a static application security testing tool that enhances code quality, security, and safety. It helps find errors and potential vulnerabilities in C, C++, C#, Java, JavaScript, TypeScript and Go code. It works on Windows, Linux, and macOS. Pros: - Various analysis types: intermodular, incremental, data flow analysis, taint analysis; - Integrates into cloud platforms; - Works offline & on-premise; - Provides cross-platform integration; - Offers ways to handle false positives; - Quick technical support directly from developers; - 1200+ diagnostics with descriptions and examples; - Provides compliance with safety & security standards: OWASP TOP 10, MISRA C/C++, CWE, SEI CERT; - Provides detailed reports and reminders for developers and managers; - Efficiently handles legacy code (baselining of analyzer results); - Active support of the Open Source Community, analysis of open-source projects; - Has integration with popular IDEs, code quality platforms, CI/CD, build systems. Good option for: - game developers (Unity & UE integration included) - embedded developers (embedded platform support); - DevSecOps experts (CLI) - project managers (code quality platform integration included) - FinTech (compliance with OWASP ASVS) - mature projects (seamless legacy handling)

API Access

Has API

API Access

Has API

Screenshots View All

Screenshots View All

Integrations

GitHub
Gradle
Jenkins
SonarQube Server
Visual Studio
Amazon Web Services (AWS)
Apache Maven
Black Duck
Bugzilla
C
GitLab
HTML
Make
Maven
Selenium
Snowflake
SonarQube for IDE
Sonatype Nexus Repository
TaskList
Unity

Integrations

GitHub
Gradle
Jenkins
SonarQube Server
Visual Studio
Amazon Web Services (AWS)
Apache Maven
Black Duck
Bugzilla
C
GitLab
HTML
Make
Maven
Selenium
Snowflake
SonarQube for IDE
Sonatype Nexus Repository
TaskList
Unity

Pricing Details

No price information available.
Free Trial
Free Version

Pricing Details

Trial version and pricing can be found on the website PVS-Studio or be requested via the contact form.
Free Trial
Free Version

Deployment

Web-Based
On-Premises
iPhone App
iPad App
Android App
Windows
Mac
Linux
Chromebook

Deployment

Web-Based
On-Premises
iPhone App
iPad App
Android App
Windows
Mac
Linux
Chromebook

Customer Support

Business Hours
Live Rep (24/7)
Online Support

Customer Support

Business Hours
Live Rep (24/7)
Online Support

Types of Training

Training Docs
Webinars
Live Training (Online)
In Person

Types of Training

Training Docs
Webinars
Live Training (Online)
In Person

Vendor Details

Company Name

OpenText

Founded

1991

Country

Canada

Website

www.opentext.com/products/static-application-security-testing

Vendor Details

Company Name

PVS-Studio

Founded

2008

Country

Kazakhstan

Website

pvs-studio.com/en/pvs-studio/

Product Features

Application Security

Analytics / Reporting
Open Source Component Monitoring
Source Code Analysis
Third-Party Tools Integration
Training Resources
Vulnerability Detection
Vulnerability Remediation

Static Application Security Testing (SAST)

Application Security
Dashboard
Debugging
Deployment Management
IDE
Multi-Language Scanning
Real-Time Analytics
Source Code Scanning
Vulnerability Scanning

Static Code Analysis

Analytics / Reporting
Code Standardization / Validation
Multiple Programming Language Support
Provides Recommendations
Standard Security/Industry Libraries
Vulnerability Management

Product Features

Application Development

Access Controls/Permissions
Code Assistance
Code Refactoring
Collaboration Tools
Compatibility Testing
Data Modeling
Debugging
Deployment Management
Graphical User Interface
Mobile Development
No-Code
Reporting/Analytics
Software Development
Source Control
Testing Management
Version Control
Web App Development

Automated Testing

Hierarchical View
Move & Copy
Parameterized Testing
Requirements-Based Testing
Security Testing
Supports Parallel Execution
Test Script Reviews
Unicode Compliance

DevOps

Approval Workflow
Dashboard
KPIs
Policy Management
Portfolio Management
Prioritization
Release Management
Timeline Management
Troubleshooting Reports

Source Code Management

Access Controls/Permissions
Bug Tracking
Build Automation
Change Management
Code Review
Collaboration
Continuous Integration
Repository Management
Version Control

Static Application Security Testing (SAST)

Application Security
Dashboard
Debugging
Deployment Management
IDE
Multi-Language Scanning
Real-Time Analytics
Source Code Scanning
Vulnerability Scanning

Alternatives

Alternatives

SonarQube Cloud Reviews

SonarQube Cloud

SonarSource