Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Static analysis is a valuable technique for identifying possible problems within your code by examining it at the source code level. C-STAT offers nearly 700 different checks, many of which adhere to guidelines outlined in MISRA C:2012, MISRA C++:2008, and MISRA C:2004, in addition to more than 250 checks that correspond to issues recognized by CWE. Furthermore, it assesses adherence to the CERT C coding standard, which focuses on secure coding practices. C-STAT operates swiftly and provides extensive and detailed error reports, allowing for effective troubleshooting. There’s no need to be concerned about complicated tool configurations or dealing with language support and overarching build challenges. Fully integrated into the IAR Embedded Workbench IDE, C-STAT empowers you to effortlessly maintain code quality throughout your development processes. This tool is compatible with a wide range of IAR Embedded Workbench products. By utilizing static analysis, not only can potential code issues be detected, but it also facilitates compliance with established industry coding standards. Ultimately, this enhances overall software reliability and maintainability.

Description

Contemporary security teams are essentially creating a supportive environment for developers by implementing code guardrails with each commit. With the capabilities of r2c’s Semgrep, organizations can effectively eradicate classes of vulnerabilities across the board. Enhance the efficiency of your security team through the use of lightweight static analysis tools. Semgrep stands out as a rapid, open-source static analysis solution that simplifies the expression of coding standards without the need for complex queries, allowing for early detection of bugs in the development process. The rules are designed to mirror the code being analyzed, eliminating the challenges associated with navigating abstract syntax trees or dealing with regex complexities. You can easily get started with over 900 pre-existing rules and utilize SaaS infrastructure to receive quick feedback directly in your editor, at the time of commit, or within continuous integration environments. If the standard rules do not meet your specific needs, you can swiftly and easily craft custom rules that reflect your organization’s unique coding standards, with the syntax resembling the target code. For instance, rules tailored for Go are presented in a way that aligns closely with the Go language itself, enabling you to identify function calls, class and method definitions, and much more without the burden of abstract syntax trees or regex challenges. This approach not only streamlines the security process but also empowers developers to maintain high-quality code more efficiently.

API Access

Has API Yes 

API Access

Has API Yes 

Screenshots View All

Screenshots View All

Integrations

Amazon S3 No 
Archipelo No 
Betterscan.io No 
C Yes 
C++ Yes 
Cider No 
Claude Code No 
Cortex No 
DefectDojo No 
Earthly Lunar No 
GitHub No 
Hexway ASOC No 
Jira No 
Jit No 
MCPTotal No 
Metorial No 
OpenAI Codex No 
Pixee No 
Tromzo No 

Integrations

Amazon S3 Yes 
Archipelo Yes 
Betterscan.io Yes 
C No 
C++ No 
Cider Yes 
Claude Code Yes 
Cortex Yes 
DefectDojo Yes 
Earthly Lunar Yes 
GitHub Yes 
Hexway ASOC Yes 
Jira Yes 
Jit Yes 
MCPTotal Yes 
Metorial Yes 
OpenAI Codex Yes 
Pixee Yes 
Tromzo Yes 

Pricing Details

No price information available.
Free Trial Yes 
Free Version No 

Pricing Details

$40 per month
Free Trial No 
Free Version Yes 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) Yes 
In Person Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

IAR Systems

Founded

1983

Country

Sweden

Website

www.iar.com/products/c-stat/

Vendor Details

Company Name

r2c

Founded

2003

Country

United Kingdom

Website

r2c.dev/

Product Features

Static Code Analysis

Analytics / Reporting No 
Code Standardization / Validation No 
Multiple Programming Language Support No 
Provides Recommendations No 
Standard Security/Industry Libraries No 
Vulnerability Management No 

Product Features

Application Security

Analytics / Reporting No 
Open Source Component Monitoring No 
Source Code Analysis No 
Third-Party Tools Integration No 
Training Resources No 
Vulnerability Detection No 
Vulnerability Remediation No 

Bug Tracking

Backlog Management No 
Filtering No 
Issue Tracking No 
Release Management No 
Task Management No 
Ticket Management No 
Workflow Management No 

Static Code Analysis

Analytics / Reporting No 
Code Standardization / Validation No 
Multiple Programming Language Support No 
Provides Recommendations No 
Standard Security/Industry Libraries No 
Vulnerability Management No 

Alternatives

CppDepend Reviews

CppDepend

CoderGears

Alternatives

CodeQL Reviews

CodeQL

GitHub
Helix QAC Reviews

Helix QAC

Perforce
Jsmon Reviews

Jsmon

Jsmon Inc.