Comment Re:static_analysis++ (Score 1) 212
PMD's an amazing tool - In v3.6 there's the ability to scan JSP's, I've written an entire suite around secure coding guidelines using both the Java and JSP engines.
"It is better to have tried and failed than to have failed to try, but the result's the same." - Mike Dennison