The PMD homepage
Score7.2
Rank#6 of 38
PriceFree
Free planYes
Runs onLinux, macOS, Self-hosted, Windows

Summary

PMD is a free, extensible static code analyzer that checks source code for programming flaws such as unused variables, empty catch blocks, and unnecessary object creation. It includes more than 400 built-in rules, and teams can write custom rules in Java or XPath. Its bundled CPD tool detects duplicated code. PMD can check source directories from the command line or run as a Maven, Ant, Gradle, or bld build operation. Supported languages include Java, JavaScript, Apex, Visualforce, Kotlin, Swift, Modelica, PL/SQL, Velocity, JSP, WSDL, Maven POM, HTML, XML, and XSL; Scala is supported without Scala rules. PMD runs on Linux, macOS, and Windows and requires Java 8 or later. For CI, its GitHub Action can create SARIF reports and fail builds based on violation counts, and its documentation covers integrations with GitLab, Jenkins, and Bamboo. IDE integrations include Eclipse, IntelliJ IDEA, and Visual Studio Code, though some listed plugins are not actively maintained. Only the latest major version receives active development and regular feature and bug-fix work.

Who it is for

PMD suits developers and teams who want static checks across supported languages, custom rules, and duplicate-code detection. It can fit command-line, build-tool, and CI workflows, provided the required Java version is available.

What is good

  • Free static analyzer with more than 400 built-in rules.
  • Custom rules can be written in Java or XPath.
  • Bundled CPD detects duplicated code.
  • GitHub Action can create SARIF reports and fail builds.
  • Runs on Linux, macOS, and Windows.

What to know first

  • Requires Java 8 or above.
  • Scala support comes without Scala rules.
  • Only the latest major version is actively developed.
  • Some listed IDE plugins are not actively maintained.

Everything Xiaomi review

PMD: the full review

PMD offers broad language coverage, configurable checks, and CI integrations without a listed price. Keep its Java requirement and major-version support policy in mind when adopting it.

Overview

PMD is a free, extensible static code analyzer for teams that want to catch common programming flaws across a broad mix of languages. Its built-in rules, custom-rule support and companion duplicate-code detector make it a strong fit for projects that want configurable checks in both local and CI workflows.

Its breadth comes with a practical constraint: running PMD requires Java 8 or above, and only the latest major version receives active development and regular fixes.

Key features

PMD ships with more than 400 rules for issues such as unused variables, empty catch blocks and unnecessary object creation. Teams can extend its checks with rules written in Java or XPath, which is useful when standard rules do not reflect a project's conventions. That flexibility also means the tool is best suited to teams prepared to choose and maintain a ruleset rather than expecting one fixed set of checks to fit every codebase.

Language coverage spans Java, JavaScript, Apex and Visualforce, Kotlin, Swift, Modelica, PL/SQL, Velocity, JSP, WSDL, Maven POM, HTML, XML and XSL. Scala is supported without Scala-specific rules, so coverage is not equally deep across the full list. CPD, distributed with PMD, adds duplicate-code detection across many programming languages; it makes PMD relevant to teams looking for both static analysis and copy-paste checks in one distribution.

PMD can run from the command line or as a Maven, Ant, Gradle or bld build operation. Its GitHub Action accepts a custom ruleset, produces SARIF reports and can fail builds according to violation counts. For GitLab, a documented CI/CD component converts PMD reports into GitLab Code Quality format. These options suit teams that want findings incorporated into build checks and reports, though the project also documents integrations for Bamboo and Jenkins rather than limiting CI use to GitHub.

IDE integrations include Eclipse, IntelliJ IDEA and Visual Studio Code, among others. Some listed plugins, including those for Apache NetBeans and Emacs, are marked as not actively maintained; teams relying on those editors should weigh that status before making the plugin their primary workflow.

Pricing

PMD is free under a BSD-style license. The PMD plan costs 0.00 USD per free and provides a downloadable static code analyzer. There is no free trial because the software is free to use; no paid tier or seat-based plan is part of this offer. That makes it a straightforward option for individuals and teams that can run and manage the tool themselves, rather than buyers seeking a priced hosted service or commercial support plan.

Platforms

PMD supports Linux, macOS, Windows and self-hosted use. It is distributed as a ZIP archive containing PMD and CPD, and requires Java 8 or above. Documentation covers execution on Linux/Unix and Windows through the pmd or pmd.bat commands. Since PMD 7.11.0, binary distributions have GPG signatures for download verification.

Who it's for

PMD is a good match for development teams working across its supported languages who want configurable static checks, duplicate detection and integration with build or CI pipelines without a license fee. It is less suitable for a team that cannot accommodate the Java runtime requirement, needs Scala-specific rules, or depends on an IDE integration marked as not actively maintained.

Pros and cons

  • Pros: More than 400 built-in rules plus Java- and XPath-based custom rules let teams tailor checks to their codebase.
  • Pros: CPD adds copy-paste detection in the same distribution, broadening its usefulness beyond flaw checks.
  • Pros: Build-tool, command-line and CI integrations let teams place checks in existing development workflows, including SARIF output and violation-based build failures in GitHub Actions.
  • Cons: Java 8 or above is required, which adds a runtime dependency for teams that do not already use Java.
  • Cons: Only the latest major version is actively developed and regularly updated, so older major versions become unsupported.
  • Cons: Scala has no Scala rules, and some IDE plugins are not actively maintained, limiting the consistency of support across languages and editors.

Alternatives

For a broader comparison, see Linters, Code Clone Detection Tools and Static Analysis Tools.

  • Biome is a free toolchain for web projects; choose it when that focus and its extension, desktop and web platform options better match your needs.
  • Cppcheck has a free core static-analysis plan and a freemium model; consider it when you want to compare another static-analysis option.
  • Ruff is a free option for readers evaluating another linter.
  • Astral offers free, open-source and permissively licensed tools including Ruff, uv and ty; choose it when that tool set better fits your needs.
  • golangci-lint is a free and open-source project built by volunteers; consider it when comparing another free linting tool.
  • Oxc is free and open source, making it another option to compare.
  • Stylelint is a free option for readers comparing another linting tool.
  • ESLint is an open-source JavaScript linting utility; choose it when you want a JavaScript-focused alternative.

Verdict

Choose PMD if you want free, configurable static analysis across several languages, with duplicate detection and practical build and CI integration. Its breadth and custom rules are compelling for teams willing to manage their own setup; look elsewhere if Java is an obstacle, Scala-specific checks are essential, or support for an older major version matters.

PMD plans and pricing

All plans
PMD Free BSD-style license · downloadable static code analyzer pmd.github.io · 2 Oct 2026

Compared on static analysis tools

Free plan
Yespmd.github.io

Facts

Purpose
PMD is an extensible multilanguage static code analyzer that finds programming flaws such as unused variables, empty catch blocks and unnecessary object creation.pmd.github.io · 1 Oct 2026
Rules
PMD includes 400+ built-in rules and supports custom rules written in Java or XPath.pmd.github.io · 1 Oct 2026
Languages
PMD supports Java, JavaScript, Salesforce Apex and Visualforce, Kotlin, Swift, Modelica, PL/SQL, Apache Velocity, JSP, WSDL, Maven POM, HTML, XML and XSL; Scala is supported without Scala rules.pmd.github.io · 1 Oct 2026
Copy-paste detection
PMD includes CPD, a copy-paste detector distributed with PMD.pmd.github.io · 1 Oct 2026
Build integrations
PMD can run as Maven, Ant, Gradle and bld build operations or from the command line.pmd.github.io · 1 Oct 2026
Installation
PMD requires Java 8 or above and is distributed as a ZIP archive containing PMD and CPD.pmd.github.io · 1 Oct 2026
Operating systems
The documentation provides execution instructions for Linux/Unix and Windows, using pmd or pmd.bat.pmd.github.io · 1 Oct 2026
CI integration
PMD provides a GitHub Action that runs custom rulesets, creates SARIF reports and can fail builds based on violation counts.pmd.github.io · 1 Oct 2026
CI ecosystem
The project documents integrations for Atlassian Bamboo, GitHub Actions, GitLab and Jenkins.pmd.github.io · 1 Oct 2026
Other integrations
The project lists integrations including Codacy, Codiga, Tencent Cloud Code Analysis, MegaLinter and a SonarQube PMD plugin.pmd.github.io · 1 Oct 2026
Support
Users can ask questions through Stack Overflow, GitHub Discussions, Gitter or PMD Guru at Gurubase, and report bugs through GitHub issues.github.com · 1 Oct 2026
License
The PMD repository identifies its license as BSD Style.github.com · 1 Oct 2026
Security reporting
PMD directs security issue reports to its SECURITY.md policy.pmd.github.io · 1 Oct 2026
Release verification
Since PMD 7.11.0, binary distribution files have GPG signatures for download verification.pmd.github.io · 1 Oct 2026
Support lifecycle
Only the latest major version is in active development and regularly receives new features and bug fixes; older major versions become unsupported.pmd.github.io · 1 Oct 2026
Built-in rules
PMD includes more than 400 built-in rules and supports custom rules written in Java or XPath.pmd.github.io · 2 Oct 2026
Duplicate detection
PMD includes CPD, a copy-paste detector that finds duplicated code across many programming languages.pmd.github.io · 2 Oct 2026
Usage
PMD provides a command-line interface for checking source directories against a ruleset.pmd.github.io · 2 Oct 2026
IDE integrations
The project lists integrations for Eclipse, IntelliJ IDEA, and Visual Studio Code, among other IDEs.docs.pmd-code.org · 2 Oct 2026
IDE plugin status
The IDE integration page marks some plugins as not actively maintained, including its listed Apache NetBeans and Emacs integrations.docs.pmd-code.org · 2 Oct 2026
GitHub Actions
PMD's GitHub Action runs a user-supplied ruleset, creates a SARIF report, and can fail a build based on violation count.docs.pmd-code.org · 2 Oct 2026
GitLab
PMD documents a CI/CD component to convert PMD reports into GitLab's Code Quality report format.docs.pmd-code.org · 2 Oct 2026

Best PMD alternatives

See all 12

Where it ranks on Everything Xiaomi

Is PMD yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources