
CodeChecker
Summary
CodeChecker is open-source static analysis infrastructure built on the LLVM and Clang Static Analyzer toolchain. Its command-line tools run supported analyzers against a JSON compilation database and produce results for review. The web interface can store, filter, compare, and visualize reports, including code bug paths; users can comment and set review status there. Analysis can be restricted to changed files and their dependencies. Listed analyzer coverage includes C/C++, C#, Java, Python, JavaScript, TypeScript, Go, and Markdown. The documentation describes Gerrit and GitLab review integrations, a reusable GitHub Actions workflow, and a Visual Studio Code extension that can run analysis, reanalyze a saved file, and browse reports. Users can run the web and storage server locally or deploy it with Docker, using PostgreSQL or SQLite. Analysis runs locally and can only be invoked from the command line; sending reports to a server also requires the command line. Windows installation is available through pip, but build logging is unavailable on Windows. CodeChecker requires Python 3.11 or later.
Who it is for
CodeChecker suits developers and teams seeking open-source static analysis, report review, and CI or editor integrations. It is relevant to projects using its listed languages and able to work with its command-line workflow.
What is good
- Open-source static analysis infrastructure
- Supports multiple listed programming languages
- Reports can be filtered and compared in a web interface
- Visual Studio Code extension can run analysis
- Local or Docker server deployment
What to know first
- Analysis can only be invoked from the command line
- Server report storage also requires the command line
- Windows build logging is unavailable
- Requires Python 3.11 or later
Verdict
CodeChecker combines local analyzer runs with web-based report review and integrations for development workflows. Its command-line requirements and Windows build-logging limitation are important constraints to account for.
Compared on static analysis tools
- Security analysis
- Yescodechecker.readthedocs.io
Facts
- Purpose
- CodeChecker is static analysis infrastructure built on the LLVM/Clang Static Analyzer toolchain.codechecker.readthedocs.io · 3 Oct 2026
- Analysis
- Its command-line tools run supported analyzers against a JSON compilation database and produce analysis results.codechecker.readthedocs.io · 3 Oct 2026
- Supported analyzers
- The documentation lists analyzers for C/C++, C#, Java, Python, JavaScript, TypeScript, Go, and Markdown.codechecker.readthedocs.io · 3 Oct 2026
- Report management
- The web interface can store, filter, compare, and visualize analyzer reports, including bug paths in code.codechecker.readthedocs.io · 3 Oct 2026
- Review workflow
- Users can comment on reports and set review status in the web GUI.codechecker.readthedocs.io · 3 Oct 2026
- Incremental analysis
- CodeChecker can limit reanalysis to changed files and their dependencies.codechecker.readthedocs.io · 3 Oct 2026
- Integrations
- The documentation describes Gerrit and GitLab review integrations and a reusable GitHub Actions workflow.codechecker.readthedocs.io · 3 Oct 2026
- Editor extension
- The Visual Studio Code extension can run analysis, reanalyze a file when saved, and browse reports in the editor.codechecker.readthedocs.io · 3 Oct 2026
- Deployment
- Users can run a CodeChecker web and storage server locally or deploy the server with Docker.codechecker.readthedocs.io · 3 Oct 2026
- Storage
- The web application supports PostgreSQL or SQLite backends.codechecker.readthedocs.io · 3 Oct 2026
- Access control
- The server supports authentication and permissions scoped globally or by product; the documentation also describes LDAP and PAM as external authentication methods.codechecker.readthedocs.io · 3 Oct 2026
- Analysis limitation
- Analysis runs locally and can only be invoked from the command line; storing reports to a server also requires the command line.codechecker.readthedocs.io · 3 Oct 2026
- Platform limitation
- The documentation says Windows installation is available through pip, but build logging is unavailable on Windows.codechecker.readthedocs.io · 3 Oct 2026
- Runtime requirement
- The packaging requirements specify Python 3 version 3.11 or later.codechecker.readthedocs.io · 3 Oct 2026
- Analyzer support
- It runs Clang-Tidy, Clang Static Analyzer, Cppcheck, GCC Static Analyzer and Facebook Infer for command-line C/C++ analysis.codechecker.readthedocs.io · 3 Oct 2026
- Broader analyzer support
- The supported analyzer list includes tools for C/C++, C#, Java, Python, JavaScript, TypeScript, Go and Markdown.codechecker.readthedocs.io · 3 Oct 2026
- Authentication
- Server authentication options include dictionary credentials, PAM, LDAP and OAuth, with OAuth templates documented for GitHub, Google Workspace and Microsoft Entra.codechecker.readthedocs.io · 3 Oct 2026
Best CodeChecker alternatives
See all 12Where it ranks on Everything Xiaomi
Is CodeChecker yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- codechecker.readthedocs.io/en/latest/· checked 3 Oct 2026
- codechecker.readthedocs.io/en/latest/feature_comparison/· checked 3 Oct 2026
- codechecker.readthedocs.io/en/latest/web/permissions/· checked 3 Oct 2026
- codechecker.readthedocs.io/en/latest/deps/· checked 3 Oct 2026
- codechecker.readthedocs.io/en/latest/supported_code_analyzers/· checked 3 Oct 2026
- codechecker.readthedocs.io/en/latest/web/authentication/· checked 3 Oct 2026


