Alternatives

Qodana alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

Qodana

📝 Source repository of Qodana Help

83
Quality
83
Trust
403
Stars
#1

Reviewdog

Similarity 125Trust 93Excellent 100

🐶 Automated code review tool integrated with any code analysis tools regardless of programming language

9.4K starsJun 12, 2026 pushdevelopmentGoCode Review
$ npx skills add reviewdog/reviewdog
#2

DeepAudit

Similarity 117Trust 95Excellent 100

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。​让安全不再昂贵,让审计不再复杂。

6.4K starsApr 1, 2026 pushdevelopmentPythonCode Review
$ npx skills add lintsinghua/DeepAudit
#3

Danger

Similarity 117Trust 94Excellent 100

🚫 Stop saying "you forgot to …" in code review (in Ruby)

5.7K starsJun 11, 2026 pushdevelopmentRubyCode Review
$ npx skills add danger/danger
#4

Danger Js

Similarity 116Trust 92Excellent 100

⚠️ Stop saying "you forgot to …" in code review

5.5K starsApr 13, 2026 pushdevelopmentTypeScriptCode Review
$ npx skills add danger/danger-js
#5

Horusec

Similarity 116Trust 92Excellent 100

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

1.3K starsMay 24, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add ZupIT/horusec
#6

Reviewboard

Similarity 115Trust 95Excellent 100

An extensible and friendly code review tool for projects and companies of all sizes.

1.7K starsJun 12, 2026 pushdevelopmentPythonCode Review
$ npx skills add reviewboard/reviewboard
#7

Qodana Action

Similarity 114Trust 85Strong 82

⚙️ Scan your Go, Java, Kotlin, PHP, Python, JavaScript, TypeScript, .NET projects at GitHub with Qodana. This repository contains Qodana for Azure, GitHub, CircleCI and Gradle

304 starsJun 15, 2026 pushdevelopmentJavaScriptCode Review
$ npx skills add JetBrains/qodana-action
#8

Aislop

Similarity 114Trust 81Strong 83

Catch the slop AI coding agents leave in your code: narrative comments, swallowed exceptions, as-any casts, dead code, oversized functions. 50+ rules across 8 languages (TypeScript, JavaScript, Python, Go, Rust, Ruby, PHP). Sub-second, deterministic, no LLM at runtime. MIT-licensed.

391 starsJun 11, 2026 pushdevelopmentTypeScriptCode Review
$ npx skills add scanaislop/aislop
#9

Brooks Lint

Similarity 114Trust 94Excellent 100

AI code reviews grounded in 12 classic engineering books — decay risk diagnostics with book citations, severity labels, and 6 analysis modes including full-sweep auto-fix

1.1K starsJun 13, 2026 pushdevelopmentJavaScriptCode Review
$ npx skills add hyhmrright/brooks-lint
#10

Semgrep

Similarity 113Trust 97Excellent 100

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

16K starsJun 16, 2026 pushdevelopmentOCamlStatic Analysis
$ npx skills add semgrep/semgrep
#11

Nodejsscan

Similarity 112Trust 88Excellent 87

nodejsscan is a static security code scanner for Node.js applications.

2.6K starsOct 10, 2025 pushdevelopmentCSSCode Review
$ npx skills add ajinabraham/nodejsscan
#12

Gitpod

Similarity 111Trust 98Excellent 100

The developer platform for on-demand cloud development environments to create software faster and more securely.

14K starsJun 12, 2026 pushdevelopmentTypeScriptCode Review
$ npx skills add gitpod-io/gitpod
#13

Pr Agent

Similarity 111Trust 98Excellent 100

🚀 PR Agent: The Original Open-Source PR Reviewer. This project It is not the Qodo free tier.

12K starsJun 6, 2026 pushdevelopmentPythonCode Review
$ npx skills add The-PR-Agent/pr-agent
#14

React Doctor

Similarity 110Trust 93Excellent 100

Your agent writes bad React. This catches it

13K starsJun 14, 2026 pushdevelopmentTypeScriptCode Review
$ npx skills add millionco/react-doctor
#15

Fallow

Similarity 109Trust 91Excellent 100

Codebase intelligence for TypeScript and JavaScript. Free static layer: unused code, duplication, circular deps, complexity hotspots, architecture boundaries. Optional paid runtime layer: hot-path review and cold-path deletion evidence from real production traffic. Rust-native, sub-second, zero-config framework support.

3.6K starsJun 14, 2026 pushdevelopmentRustStatic Analysis
$ npx skills add fallow-rs/fallow
#16

CodeAnalysis

Similarity 109Trust 84Strong 81

Static Code Analysis - 静态代码分析

1.8K starsNov 3, 2025 pushdevelopmentPythonCode Review
$ npx skills add Tencent/CodeAnalysis

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Qodana if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.