Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Claimed
Claimed

Top Rated CodeScan Alternatives

CodeScan Reviews & Product Details

Dino K.
DK
Salesforce Developer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
Business partner of the seller or seller's competitor, not included in G2 scores.
What do you like best about CodeScan?

The ability to set different Quality Gates for different projects combined with different Quality Profiles. Out-of-the-box ruleset is just huge and the option to customize the ruleset is useful. The setup is really easy.

You can use an IDE plugin combined with the cloud solution (IntelliJ or VS Code) so it acts like a lint tool and that is really useful for development. Works with JavaScript (LWC) as well as other languages (out-of-the-box).

CI/CD is also supported which is brilliant. Copado, Jenkins, GitLab it's all there. In addition to CI/CD, you can also configure a webhook and send it to Slack :)

From the reporting point of view, Leak Period gives an overview of arising issues which is really useful as well as the Technical Debt. Another pro is the option to send the reports periodically.

Overall a fantastic tool every Salesforce developer should use. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

Wish there was a bit more documentation available and a custom report option for an individual member of the project. Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

Neatly fits into the Agile methodology. It helps in speeding up the development process and greatly contributes to overall code quality. Additionally, it saves a lot of time and effort on setup and maintenance.

UI is simple to use and the configuration is simple. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Developers on the projects follow the enforced standards hence overall code quality improved. Enforced test coverage significantly increased = fewer bugs. Code reviews take less time as the obvious mistakes are pointed out during development. Saves a lot of time (and stress!) during the two-week sprints :). CI/CD integration is a must-have and codescan integrates nicely into it. Review collected by and hosted on G2.com.

CodeScan Overview

What is CodeScan?

CodeScan Shield addresses code quality, security, and compliance liabilities with two automated modules: CodeScan and OrgScan. CodeScan provides static code analysis for total visibility into code health from the moment it’s written through production. OrgScan governs organizational policies by enforcing the security and compliance rules mandated for your Salesforce environment. Together, they ensure the code that makes up your Salesforce environment and the way the environment is being utilized will always meet high standards. The result is strengthened data security, streamlined DevSecOps processes, and an assurance of meeting compliance standards—avoiding potentially thousands of dollars in fines and lost opportunities. CodeScan Shield protects your Salesforce org from both the inside and outside. CodeScan provides dashboards and reports for consistent code visibility, while also alerting developers the moment new errors are introduced. OrgScan analyzes Salesforce policies to ensure the organization remains compliant with client-mandated specifications and guidelines. Violations are flagged and recorded in an interactive dashboard. Progress is tracked for policy reviews. Collectively, these features ensure admins maintain governance control within their organization. CodeScan Shield is part of AutoRABIT’s complete DevSecOps platform. Enabling Salesforce DevOps teams with CodeScan Shield’s powerful technology produces high-quality, secure applications and updates at speed.

CodeScan Details
Languages Supported
English
Show LessShow More
Product Description

CodeScan is a plugin for SonarQube and runs over 160 different checks for the quality on the Apex and VisualForce code.

How do you position yourself against your competitors?

CodeScan is an end-to-end static analysis solution is made exclusively for the Salesforce platform. Unlike other solutions, CodeScan's static code analysis solution is compatible with all Salesforce languages, APEX, Visualforce, Lightning, and Metadata. CodeScan provides the largest set of rules in the market and are able to provide customized quality gates. CodeScan's automated review process directly integrates with the Salesforce platform and CD/CI pipelines. CodeScan's self-hosted and cloud solutions integrate with popular IDE plug-ins.


Seller Details
Year Founded
2015
HQ Location
San Diego, California
Twitter
@autorabit
1,243 Twitter followers
LinkedIn® Page
www.linkedin.com
232 employees on LinkedIn®
Description

CodeScan.io is a leading provider of static code analysis tools designed to enhance the quality and security of codebases. Their platform offers automated code reviews, identifying potential vulnerabilities and code quality issues in real-time, thereby facilitating best practices in software development. With a focus on Salesforce development, CodeScan.io helps teams ensure compliance, improve maintainability, and streamline their development processes. For more information, visit their website at https://www.codescan.io.


Kris G.
KG
Overview Provided by:
Vice President Marketing at AutoRABIT

Recent CodeScan Reviews

Santosh T.
ST
Santosh T.Enterprise (> 1000 emp.)
4.5 out of 5
"Codescan : for better code quality"
Vs code plugin and Autorabit integration
Ramkumar N.
RN
Ramkumar N.Enterprise (> 1000 emp.)
4.0 out of 5
"CodeScan effectively helps mitigating Salesforce metadata risks thanks to its splendid scan engines"
We prioritize Salesforce code quality as it's integral to our retail organization. We work with sensitive customer data and encode security roles, ...
Tyronica  O.
TO
Tyronica O.Mid-Market (51-1000 emp.)
5.0 out of 5
"CodeScan"
CodeScan is the most awesome with the tools that help in writing the most secure and quality codes on the salesforce platform. It's the best in the...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

CodeScan Media

CodeScan Demo - CodeScan Static Code Analysis for Salesforce
Robust analysis for high-quality code and intuitive governance. Total visibility over the health of your environment reduces costs and increases time to market.
CodeScan Demo - CodeScan Static Code Analysis for Salesforce
Immediately fixing coding errors is 150x cheaper compared to addressing them in post-production. 100% adherence to native and custom Salesforce policies eliminate costly mistakes. Guaranteed regulatory compliance eliminates the risk of incurring fines and penalties.
CodeScan Demo - CodeScan Static Code Analysis for Salesforce
Reduce manual processes and support data security.
Answer a few questions to help the CodeScan community
Have you used CodeScan before?
Yes

33 out of 34 Total Reviews for CodeScan

4.6 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
33 out of 34 Total Reviews for CodeScan
4.6 out of 5
33 out of 34 Total Reviews for CodeScan
4.6 out of 5

Overall Review Sentiment for CodeScanQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Ramkumar N.
RN
Salesforce Developer
Information Technology and Services
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about CodeScan?

We prioritize Salesforce code quality as it's integral to our retail organization. We work with sensitive customer data and encode security roles, permissions & access control definitions & overviewing them is made convenient with CodeScan. As we incorporate our metadata, the possibility of errors is high, resulting in poor code quality. CodeScan provides a sophisticated platform to overcome these challenges and keep our code security intact & compliant. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

In my opinion, its pricing model seems to be costly. Each pricing block is evaluated based on scanning 40,000 lines of code & your expenditure can be calculated with this. For small retail businesses, their framework & codes would mostly have fewer lines of code & they would be paying for a standard pricing block. It would be great to have granularity in its pricing block so that any organization would opt CodeScan's pricing model that fits their requirements without paying additional charges. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

CodeScan offers our retail organization with excellent static code analysis platform. We obtain superb visibility about our code quality, reliability in code analysis & also ensure proper Salesforce development provisions. Regarding the Salesforce platform, a few regulatory metrics need to be upheld & CodeScan governs these metrics through its well-structured rule policies. Before carrying out the production deployments, we need to validate our Salesforce codes & metadata to avoid exposure of sensitive client data & poor release quality. CodeScan platform is excellent for handling these commitments, and we provide satisfactory deliverables to our customers. Review collected by and hosted on G2.com.

Tyronica  O.
TO
Data quality and clean up consultant
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about CodeScan?

CodeScan is the most awesome with the tools that help in writing the most secure and quality codes on the salesforce platform. It's the best in the market Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

The only downside is if the code in unrecognised or has errors, it sometimes misses where the error is. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

With CodeScan you know you are providing quality and secure codes. Review collected by and hosted on G2.com.

Santosh T.
ST
Tech Lead
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
(Original )Information
What do you like best about CodeScan?

Vs code plugin and

Autorabit integration Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

No dislikes as such .great product indeed. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Code best practices

Avoided Salesforce governor limit related issues. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
(Original )Information
What do you like best about CodeScan?

Through this we can code efficient and learn standard coding techniques. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

It takes few minutes to run or to finish the execution. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Code refactoring, removing vulnerability, bug, code smell, Duplicate lines of code can be identified and can be resolved. Review collected by and hosted on G2.com.

Verified User in Management Consulting
UM
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about CodeScan?

Easy to use and aldo suggestions it offer for each violations Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

It shows a lot of false positives and there's no option to mark a bug as false positive Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Static review of code and it helps maintain code quality Review collected by and hosted on G2.com.

OU
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about CodeScan?

It's specific to Salesforce Apex. There aren't many tools out there for this language. And it does it well with SonarCloud integration so you have the ability to see what aspect of OWASP Top 10 the vulnerability falls under. Recently, they included security hotspots, to give you more insight to areas your organisation's code needs more security improvement.

CodeScan is very understanding about your business needs, and try to fit into your budget as much as they can. They also value customer loyalty and they listen to their customers. They provide hands-on help as needed and do not leave you hanging.

The pricing for CodeScan eliminates any general SonarCloud languages. It only includes programming languages specific to Salesforce - i.e. lightning pages, aura component, apex classes, visualforce pages (excluding js files which is included with SonarCloud]. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

There isn't much to dislike about the product, although it does not integrate with a ticketing system, it does the job. It will be helpful if it integrated with a ticketing system, to create a ticket for security or quality bugs. It also results in a lot of false positives but you may modify this as you please in the administrative part of SonarCloud.

You cannot get a specific report for newer codes in your repository or Salesforce org. The security report generated is for collated code from your org or repository.

I would also appreciate more help with working in SonarCloud for those who are not versatile with the application. Although, CodeScan provides hands- on help. The team needs to consider writing up a manual for specific operations in SonarCloud that organisations might be interested in. Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

CodeScan does the job for security vulnerabilities and quality assessment more than most high-end commercial tools. It is just as good as the very expensive tools and integrates well with your CI/CD process.

The company ensures their clients are satisfied and always check in with their customers. They do not leave you hanging like some other organisations do.

Lots of opportunities to ask for help if you are stuck. Overall, for secure code reviews, it is brilliant! We do not currently use if for SAST but it does a great job with overall reporting of your code-base - projects. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

We currently use CodeScan to facilitate in our internal secure code reviews and it does well with in-depth information regarding new and existing code security.

It also provides more than Security vulnerabilities or hotspots, it is very beneficial for Quality bugs relating to Salesforce Apex. We do not currently use this aspect of CodeScan.

We have used it to improve our deployment process by 50%, and SonarCloud is easily integrated with our CI/CD process, which automates CodeScan scans for our teams. Review collected by and hosted on G2.com.

Alex B.
AB
Senior IT Solutions Architect for People & Culture
Tobacco
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about CodeScan?

First of all, CodeScan is just great to deal with: they are extremely flexible, helpful, and do respect customers' internal procedures (even if they are overcomplicated for sometimes small purchases).

We're using it with SonarQube, it's quite straightforward to install and use by the DevOps Engineers. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

I can't actually find anything that I dislike, sorry... Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

As I have mentioned above CodeScan team is great so it's a plus already.

If you are using it with SonarQube make sure it's not a Sonar used globally and somehow you get your own "space". You're paying here for lines of the code and you don't want to run out of the nr of lines you've purchased (of you can if you have a budget)

Ask your developers which tools they prefer in the majority fo the cases it will be CodeScan Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Before going live with our Project that mainly was developed by the third-party it was important for me to understand the code complexity and its impact on dev-ops processes we've envisioned here. We had a couple of less than a pleasant conversation with our implementation partner since they hold that they deliver a product of the highest quality...and then came CodeScan. The result was something we had a feeling about - poor coding standards, a lot of loops, etc.

Ok, CodeScan is not a real human so don't expect that there's nothing to do for you after you have it. Sometimes it does overuse "code smell" and so on but you can mark it once and just re-check with the next deployments.

If you are in a similar position where you are in the dark how your code looks like or you want something that easily will identify if one developer is not destroying the work of the other one I can't recommend CodeScan more Review collected by and hosted on G2.com.

SK
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about CodeScan?

CodeScan really has saved us a lot of time in doing code reviews. We had the opportunity to let our developers install it in the VS Code IDE and codeScan did everything else.

The prompt warnings with the mention of lines, and the best way to correct it is what eased it all for us. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

Nothing really as of now. CodeScan infact has been so much flexible in integrating with Copado. So our CI/CD process was actually well streamlined. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

The user interface of CodeScan.

The flexibility of integrating it with Copado.

Ease of installation with VS Code. Review collected by and hosted on G2.com.

JH
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about CodeScan?

Its biggest pro is the centralized analysis for multiple different languages.

Typically you'd need to set up and configure a linter for JS, Java, Python, etc separately, per repo but codescan works out of the box on all the major languages and provides a single UI for managing the rules.

It also is simple to set up and integrate into CI/CD and takes away the pain of having to do that integration for each language pipeline.

Another pro is that it works at the project level so you can have multiple repos, each of different languages (or mixed) which all have their own coverage and health grade.

You can also customize each ruleset (self hosted) for each language to suit the teams needs. Some people enjoy trailing commas and the others are just wrong. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

There are a few quirks that, though provide rare frustrations, are by no means large deterrents.

One such rarity is a rule being flagged as incorrect due to a misinterpreted context.

Of course, you can just mark it as ignored but then the real frustration comes from the email notification sent out that a rule was ignored. Typically this is a useful feature as people shouldn't be bypassing rules, but in this case it's a bit frustrating to hold off on a deploy while you explain why the rule was ignored.

Also, during CI/CD, if an upstream branch was merged to master, a branch of that branch will fail. Of course, the simple solution is to point the branch at master now and rerun but sometimes you just want things to unrealistically work.

No VIM plugin :( Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

If your team has multiple different languages, repos, etc or constantly generating new microservices, CodeScan is going to dramatically decrease setup time.

Also, as the rules become standards for the team the dev iterations speeds up due to less PR churn and yak shaving. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

As mentioned above, it solves the critical problem of maintaining multiple different linter and ci/cd integration pipelines.

It runs against most languages and has a single integration pattern.

The UI allows a single source of truth for the rules so each new project automatically has them applied without any additional configurations or boilerplate 3rd party library setups. Review collected by and hosted on G2.com.

Stefan A.
SA
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about CodeScan?

IDE plugin which allows developer to have immediate scan of the new code they are preparing. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

I'm missing option to export reports and show it i.e. in Jenkins similar to PMD plugins. Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

Build better integration with CI/CD tools like Jenkins so the analysis can be used as quality gate on the builds. Allow reports to be easily exported and integrated with CI/CD tool so users can have all information needed in one place. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Security code review. Duplications in code. Unused variables and methods. It help to keep code clean. Love it. Review collected by and hosted on G2.com.