
Summary
PMD is a free, extensible static code analyzer that checks source code for programming flaws such as unused variables, empty catch blocks, and unnecessary object creation. It includes more than 400 built-in rules, and teams can write custom rules in Java or XPath. Its bundled CPD tool detects duplicated code. PMD can check source directories from the command line or run as a Maven, Ant, Gradle, or bld build operation. Supported languages include Java, JavaScript, Apex, Visualforce, Kotlin, Swift, Modelica, PL/SQL, Velocity, JSP, WSDL, Maven POM, HTML, XML, and XSL; Scala is supported without Scala rules. PMD runs on Linux, macOS, and Windows and requires Java 8 or later. For CI, its GitHub Action can create SARIF reports and fail builds based on violation counts, and its documentation covers integrations with GitLab, Jenkins, and Bamboo. IDE integrations include Eclipse, IntelliJ IDEA, and Visual Studio Code, though some listed plugins are not actively maintained. Only the latest major version receives active development and regular feature and bug-fix work.
Who it is for
PMD suits developers and teams who want static checks across supported languages, custom rules, and duplicate-code detection. It can fit command-line, build-tool, and CI workflows, provided the required Java version is available.
What is good
- Free static analyzer with more than 400 built-in rules.
- Custom rules can be written in Java or XPath.
- Bundled CPD detects duplicated code.
- GitHub Action can create SARIF reports and fail builds.
- Runs on Linux, macOS, and Windows.
What to know first
- Requires Java 8 or above.
- Scala support comes without Scala rules.
- Only the latest major version is actively developed.
- Some listed IDE plugins are not actively maintained.
Everything Xiaomi review
PMD: the full review
PMD offers broad language coverage, configurable checks, and CI integrations without a listed price. Keep its Java requirement and major-version support policy in mind when adopting it.
Overview
PMD is a free, extensible static code analyzer for teams that want to catch common programming flaws across a broad mix of languages. Its built-in rules, custom-rule support and companion duplicate-code detector make it a strong fit for projects that want configurable checks in both local and CI workflows.
Its breadth comes with a practical constraint: running PMD requires Java 8 or above, and only the latest major version receives active development and regular fixes.
Key features
PMD ships with more than 400 rules for issues such as unused variables, empty catch blocks and unnecessary object creation. Teams can extend its checks with rules written in Java or XPath, which is useful when standard rules do not reflect a project's conventions. That flexibility also means the tool is best suited to teams prepared to choose and maintain a ruleset rather than expecting one fixed set of checks to fit every codebase.
Language coverage spans Java, JavaScript, Apex and Visualforce, Kotlin, Swift, Modelica, PL/SQL, Velocity, JSP, WSDL, Maven POM, HTML, XML and XSL. Scala is supported without Scala-specific rules, so coverage is not equally deep across the full list. CPD, distributed with PMD, adds duplicate-code detection across many programming languages; it makes PMD relevant to teams looking for both static analysis and copy-paste checks in one distribution.
PMD can run from the command line or as a Maven, Ant, Gradle or bld build operation. Its GitHub Action accepts a custom ruleset, produces SARIF reports and can fail builds according to violation counts. For GitLab, a documented CI/CD component converts PMD reports into GitLab Code Quality format. These options suit teams that want findings incorporated into build checks and reports, though the project also documents integrations for Bamboo and Jenkins rather than limiting CI use to GitHub.
IDE integrations include Eclipse, IntelliJ IDEA and Visual Studio Code, among others. Some listed plugins, including those for Apache NetBeans and Emacs, are marked as not actively maintained; teams relying on those editors should weigh that status before making the plugin their primary workflow.
Pricing
PMD is free under a BSD-style license. The PMD plan costs 0.00 USD per free and provides a downloadable static code analyzer. There is no free trial because the software is free to use; no paid tier or seat-based plan is part of this offer. That makes it a straightforward option for individuals and teams that can run and manage the tool themselves, rather than buyers seeking a priced hosted service or commercial support plan.
Platforms
PMD supports Linux, macOS, Windows and self-hosted use. It is distributed as a ZIP archive containing PMD and CPD, and requires Java 8 or above. Documentation covers execution on Linux/Unix and Windows through the pmd or pmd.bat commands. Since PMD 7.11.0, binary distributions have GPG signatures for download verification.
Who it's for
PMD is a good match for development teams working across its supported languages who want configurable static checks, duplicate detection and integration with build or CI pipelines without a license fee. It is less suitable for a team that cannot accommodate the Java runtime requirement, needs Scala-specific rules, or depends on an IDE integration marked as not actively maintained.
Pros and cons
- Pros: More than 400 built-in rules plus Java- and XPath-based custom rules let teams tailor checks to their codebase.
- Pros: CPD adds copy-paste detection in the same distribution, broadening its usefulness beyond flaw checks.
- Pros: Build-tool, command-line and CI integrations let teams place checks in existing development workflows, including SARIF output and violation-based build failures in GitHub Actions.
- Cons: Java 8 or above is required, which adds a runtime dependency for teams that do not already use Java.
- Cons: Only the latest major version is actively developed and regularly updated, so older major versions become unsupported.
- Cons: Scala has no Scala rules, and some IDE plugins are not actively maintained, limiting the consistency of support across languages and editors.
Alternatives
For a broader comparison, see Linters, Code Clone Detection Tools and Static Analysis Tools.
- Biome is a free toolchain for web projects; choose it when that focus and its extension, desktop and web platform options better match your needs.
- Cppcheck has a free core static-analysis plan and a freemium model; consider it when you want to compare another static-analysis option.
- Ruff is a free option for readers evaluating another linter.
- Astral offers free, open-source and permissively licensed tools including Ruff, uv and ty; choose it when that tool set better fits your needs.
- golangci-lint is a free and open-source project built by volunteers; consider it when comparing another free linting tool.
- Oxc is free and open source, making it another option to compare.
- Stylelint is a free option for readers comparing another linting tool.
- ESLint is an open-source JavaScript linting utility; choose it when you want a JavaScript-focused alternative.
Verdict
Choose PMD if you want free, configurable static analysis across several languages, with duplicate detection and practical build and CI integration. Its breadth and custom rules are compelling for teams willing to manage their own setup; look elsewhere if Java is an obstacle, Scala-specific checks are essential, or support for an older major version matters.
PMD plans and pricing
All plansCompared on static analysis tools
- Free plan
- Yespmd.github.io
Facts
- Purpose
- PMD is an extensible multilanguage static code analyzer that finds programming flaws such as unused variables, empty catch blocks and unnecessary object creation.pmd.github.io · 1 Oct 2026
- Rules
- PMD includes 400+ built-in rules and supports custom rules written in Java or XPath.pmd.github.io · 1 Oct 2026
- Languages
- PMD supports Java, JavaScript, Salesforce Apex and Visualforce, Kotlin, Swift, Modelica, PL/SQL, Apache Velocity, JSP, WSDL, Maven POM, HTML, XML and XSL; Scala is supported without Scala rules.pmd.github.io · 1 Oct 2026
- Copy-paste detection
- PMD includes CPD, a copy-paste detector distributed with PMD.pmd.github.io · 1 Oct 2026
- Build integrations
- PMD can run as Maven, Ant, Gradle and bld build operations or from the command line.pmd.github.io · 1 Oct 2026
- Installation
- PMD requires Java 8 or above and is distributed as a ZIP archive containing PMD and CPD.pmd.github.io · 1 Oct 2026
- Operating systems
- The documentation provides execution instructions for Linux/Unix and Windows, using pmd or pmd.bat.pmd.github.io · 1 Oct 2026
- CI integration
- PMD provides a GitHub Action that runs custom rulesets, creates SARIF reports and can fail builds based on violation counts.pmd.github.io · 1 Oct 2026
- CI ecosystem
- The project documents integrations for Atlassian Bamboo, GitHub Actions, GitLab and Jenkins.pmd.github.io · 1 Oct 2026
- Other integrations
- The project lists integrations including Codacy, Codiga, Tencent Cloud Code Analysis, MegaLinter and a SonarQube PMD plugin.pmd.github.io · 1 Oct 2026
- Support
- Users can ask questions through Stack Overflow, GitHub Discussions, Gitter or PMD Guru at Gurubase, and report bugs through GitHub issues.github.com · 1 Oct 2026
- License
- The PMD repository identifies its license as BSD Style.github.com · 1 Oct 2026
- Security reporting
- PMD directs security issue reports to its SECURITY.md policy.pmd.github.io · 1 Oct 2026
- Release verification
- Since PMD 7.11.0, binary distribution files have GPG signatures for download verification.pmd.github.io · 1 Oct 2026
- Support lifecycle
- Only the latest major version is in active development and regularly receives new features and bug fixes; older major versions become unsupported.pmd.github.io · 1 Oct 2026
- Built-in rules
- PMD includes more than 400 built-in rules and supports custom rules written in Java or XPath.pmd.github.io · 2 Oct 2026
- Duplicate detection
- PMD includes CPD, a copy-paste detector that finds duplicated code across many programming languages.pmd.github.io · 2 Oct 2026
- Usage
- PMD provides a command-line interface for checking source directories against a ruleset.pmd.github.io · 2 Oct 2026
- IDE integrations
- The project lists integrations for Eclipse, IntelliJ IDEA, and Visual Studio Code, among other IDEs.docs.pmd-code.org · 2 Oct 2026
- IDE plugin status
- The IDE integration page marks some plugins as not actively maintained, including its listed Apache NetBeans and Emacs integrations.docs.pmd-code.org · 2 Oct 2026
- GitHub Actions
- PMD's GitHub Action runs a user-supplied ruleset, creates a SARIF report, and can fail a build based on violation count.docs.pmd-code.org · 2 Oct 2026
- GitLab
- PMD documents a CI/CD component to convert PMD reports into GitLab's Code Quality report format.docs.pmd-code.org · 2 Oct 2026
Best PMD alternatives
See all 12Where it ranks on Everything Xiaomi
- Best Static Analysis Tools in 2026#6 of 38
- Best Linters in 2026#1 of 33
- Best Code Clone Detection Tools in 2026#4 of 23
Is PMD yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- pmd.github.io/pmd/index.html· checked 1 Oct 2026
- pmd.github.io/pmd/pmd_userdocs_installation.html· checked 1 Oct 2026
- pmd.github.io/pmd/pmd_userdocs_tools_ci.html· checked 1 Oct 2026
- pmd.github.io/pmd/pmd_userdocs_tools.html· checked 1 Oct 2026
- github.com/pmd/pmd· checked 1 Oct 2026
- pmd.github.io/pmd/pmd_about_security.html· checked 1 Oct 2026
- pmd.github.io/pmd/pmd_userdocs_signed_releases.html· checked 1 Oct 2026
- pmd.github.io/pmd/pmd_about_support_lifecycle.html· checked 1 Oct 2026
- pmd.github.io· checked 2 Oct 2026
- docs.pmd-code.org/latest/pmd_userdocs_tools_ide_plugins.h· checked 2 Oct 2026
- docs.pmd-code.org/latest/pmd_userdocs_tools_ci.html· checked 2 Oct 2026


