SonarCloud is an online code review service that can be hooked up to cloud DevOps services like GitHub, Bitbucket, Azure DevOps and GitLab. It supports more than 30 programming languages and frameworks, with automated analysis, clear quality gates and results you can act on. Its dashboard offers unified configuration, broad security tools and AI-assisted code support, making it a good pick for ensuring good software quality and good coding practices.
Another contender is Codiga, which offers immediate feedback on code quality and flags problems with rules you can customize. It works with multiple languages and libraries and can be hooked up to IDEs and code hosting sites. Codiga offers a dashboard to monitor code quality metrics like violations, duplicates and complex functions, and security analysis with the OWASP 10 and SANS-CWE25 standards.
If you want the most tools and features, check out Codacy. The service supports more than 40 programming languages and frameworks with tools to enforce coding standards, find vulnerabilities and track test coverage. Codacy can be hooked up to common development tools and offers AI-based fixes, too. It offers several pricing tiers, including a free option for open-source projects.