Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Static analysis is a valuable technique for identifying possible problems within your code by examining it at the source code level. C-STAT offers nearly 700 different checks, many of which adhere to guidelines outlined in MISRA C:2012, MISRA C++:2008, and MISRA C:2004, in addition to more than 250 checks that correspond to issues recognized by CWE. Furthermore, it assesses adherence to the CERT C coding standard, which focuses on secure coding practices. C-STAT operates swiftly and provides extensive and detailed error reports, allowing for effective troubleshooting. There’s no need to be concerned about complicated tool configurations or dealing with language support and overarching build challenges. Fully integrated into the IAR Embedded Workbench IDE, C-STAT empowers you to effortlessly maintain code quality throughout your development processes. This tool is compatible with a wide range of IAR Embedded Workbench products. By utilizing static analysis, not only can potential code issues be detected, but it also facilitates compliance with established industry coding standards. Ultimately, this enhances overall software reliability and maintainability.

Description

CodeSonar uses a unified dataflow with symbolic execution analysis to examine the entire application's computations. CodeSonar's static analyze engine is extremely deep and does not rely on pattern matching or similar approximations. It finds 3-5 times more defects than other static analysis tools. SAST tools are able to be easily integrated into any team's software development process, unlike many other tools such as testing tools and compilers. SAST technologies such as CodeSonar attach to existing build environments to add analysis information. CodeSonar works in the same way as a compiler. However, CodeSonar creates an abstraction model of your entire program, instead of creating object codes. CodeSonar's symbolic execution engine analyzes the derived model and makes connections between them.

API Access

Has API Yes 

API Access

Has API Yes 

Screenshots View All

Screenshots View All

Integrations

C Yes 
C++ Yes 
AWS GovCloud No 
Amazon Web Services (AWS) No 
Android No 
C# No 
CodeSentry No 
Docker No 
Eclipse IDE No 
GitLab No 
Go No 
IAR Embedded Workbench Yes 
Java No 
JavaScript No 
Jira No 
Python No 
Rust No 
Seeker No 
Visual Studio No 
Visual Studio Code No 

Integrations

C Yes 
C++ Yes 
AWS GovCloud Yes 
Amazon Web Services (AWS) Yes 
Android Yes 
C# Yes 
CodeSentry Yes 
Docker Yes 
Eclipse IDE Yes 
GitLab Yes 
Go Yes 
IAR Embedded Workbench No 
Java Yes 
JavaScript Yes 
Jira Yes 
Python Yes 
Rust Yes 
Seeker Yes 
Visual Studio Yes 
Visual Studio Code Yes 

Pricing Details

No price information available.
Free Trial Yes 
Free Version No 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) Yes 
In Person Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

IAR Systems

Founded

1983

Country

Sweden

Website

www.iar.com/products/c-stat/

Vendor Details

Company Name

CodeSecure

Country

United States

Website

www.grammatech.com/products/source-code-analysis

Product Features

Static Code Analysis

Analytics / Reporting No 
Code Standardization / Validation No 
Multiple Programming Language Support No 
Provides Recommendations No 
Standard Security/Industry Libraries No 
Vulnerability Management No 

Product Features

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Static Code Analysis

Analytics / Reporting No 
Code Standardization / Validation No 
Multiple Programming Language Support No 
Provides Recommendations No 
Standard Security/Industry Libraries No 
Vulnerability Management No 

Alternatives

CppDepend Reviews

CppDepend

CoderGears

Alternatives

Flawnter Reviews

Flawnter

CyberTest
Helix QAC Reviews

Helix QAC

Perforce
SonarQube Cloud Reviews

SonarQube Cloud

SonarSource
SonarQube Server Reviews

SonarQube Server

SonarSource