Codebase intelligence for TypeScript and JavaScript. Free static analysis of code and styles: unused code, duplication, circular deps, complexity hotspots, architecture boundaries, design-system drift. Optional paid runtime layer (Fallow Runtime): hot-path review and cold-path deletion evidence from real production traffic.
Top CODE-QUALITY GitHub Repositories & Tools (2026)
Discover the most starred and trending open source tools tagged with #code-quality.
Static analysis for the debt AI agents leave in PHP: 25 rules, Claude Code hooks, git-diff review, a Rector and Pint fix pass, Pest expectations, CI annotations and an MCP server. Deterministic, local, no LLM.
Coverage, security and code quality for coding agents
A fast type checker and language server for Python
Continuous Inspection
A tool to enforce Swift style and conventions.
Static code analysis for Kotlin
Codebase intelligence for AI and humans: code health scores, auto-generated docs, git analytics, dead code detection, and architectural decisions via MCP.
Code coverage for Ruby with a powerful configuration library and automatic merging of coverage across test suites
A PHP code-quality tool
⚙️ The static code analysis tool you need for your HTML
A powerful C# Roslyn analyzer that uses static analysis to detect bugs, surface security issues, and enforce best practices—helping developers and AI write more reliable code.
PHP_Depend is an adaptation of the established Java development tool JDepend. This tool shows you the quality of your design in terms of extensibility, reusability and maintainability.
undercover warns about methods, classes and blocks that were changed without tests, to help you easily find untested code and reduce the number of bugs. It does so by analysing data from git diffs, code structure and SimpleCov coverage reports
SonarQube extension for Visual Studio providing code quality and security feedback directly in the IDE
Regal is a linter and language server for Rego, bringing your policy development experience to the next level!
Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/
SonarQube plugin for Eclipse providing code quality and security feedback directly in the IDE
🔧 JetBrains Qodana’s official command line tool
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.