Measured · 2026-08-07

Who ChatGPT and Gemini recommend for static code analysis tools

We put 6 buyer questions about static code analysis tools to ChatGPT and Gemini. Only Semgrep was named in all 6 answers. Here is the full list, the pages the answers were built from, and what it means whether or not your product is on it.

Answers read
6
Products named
24
Top source
github.com

Semgrep was the only static code analysis tool that ChatGPT and Gemini named in all six of the six buyer questions we tested on 2026-08-07, a clean 100% hit rate. No other tool came close to that consistency.

Two tools tied for second place: Snyk Code and SonarQube were each named in 4 of the 6 answers (67%). Behind them, Clang Static Analyzer and DeepSource each landed in 3 of 6 (50%), and Checkmarx, CodeQL and PMD each in 2 of 6 (33%).

Across the six answers, ChatGPT and Gemini named 24 distinct tools in total, but only 8 of those 24 were named in more than one answer. The other 16 tools each appeared exactly once (1 of 6, 17%). The agreement in this category is thin: one universal pick and a very long tail.

The shortlist splits into two different worlds

The category does not have one shortlist, it has two that barely touch. Snyk Code and SonarQube (4 of 6 each) and DeepSource (3 of 6) only ever showed up in the buyer-situation questions ('for small teams', 'what should I use', 'recommendations') and never once in the 'free' or 'affordable' answers. Clang Static Analyzer (3 of 6) did the exact opposite, appearing in the 'best', 'free' and 'affordable' answers and in none of the buyer-situation three. Semgrep (6 of 6) was the only tool that lived in both worlds.

The bare 'best static code analysis tools' question returned 7 tools: SonarQube, Clang Static Analyzer, CodeSonar, Semgrep, PMD, Snyk Code and Qodana. Two of those, CodeSonar and Qodana, appeared in this one question and nowhere else across the six.

The 'best free static code analysis tools' question returned a completely different set, again 7 tools: PMD, Clang Static Analyzer, Semgrep, Cppcheck, Pylint, PHPStan and OCLint. Four of them, Cppcheck, Pylint, PHPStan and OCLint, appeared only in the free question, and the paid platforms that led the 'best' answer (SonarQube and Snyk Code) dropped out of it entirely.

The 'most affordable static code analysis tools' question returned a third, mostly separate set of 6 tools: Semgrep, Clang Static Analyzer, Flawfinder, Bearer, fallow and Critik. Four of them, Flawfinder, Bearer, fallow and Critik, showed up only in the affordable question.

Here is the part marketers underestimate: 'free' and 'affordable' sound like the same request, but their answers overlapped on only 2 tools, Semgrep and Clang Static Analyzer. Ask for free and you get open-source linters (PMD, Cppcheck, Pylint, PHPStan, OCLint); ask for affordable and you get a different crowd (Flawfinder, Bearer, fallow, Critik). One word changed the list almost completely.

The 'for small teams' question returned 6 tools (Semgrep, SonarQube, DeepSource, Codacy, Snyk Code and CodeClimate), a SaaS-heavy answer with not one of the open-source-only linters that filled the free list, and Codacy and CodeClimate appeared here and nowhere else.

The other two buyer-situation questions were the widest: 'what should I use' and 'recommendations' each returned 8 tools. Cycode SAST and Rafter appeared only in 'what should I use', while Veracode and Fortify appeared only in 'recommendations'. Counting all six questions, 16 of the 24 tools were named in exactly one of them.

Where the answers came from

The single most-cited source across the six answers was github.com, which fed 4 of the 6 answers. That is where the open-source tools keep their code (Semgrep, PMD and Pylint all host there), so 'be on GitHub' is doing real work in this category.

The key insight is that a tool's own website kept feeding the very answer that named it. clang-analyzer.llvm.org fed 3 answers and Clang Static Analyzer was named 3 times; snyk.io fed 3 answers and Snyk Code was named 4 times; sonarsource.com fed the 'best' answer that named SonarQube. Owning the page the assistant reads is most of the game here, not a nice-to-have.

The clearest example is the 'best free' answer, which drew on 6 sources and every one of them was a tool's own home or repo: clang-analyzer.llvm.org, phpstan.org, pmd.github.io, cppcheck.sourceforge.io, oclint.org and github.com. Zero third-party roundups fed that answer, and the tools it named were exactly the tools whose pages were read.

Even a small vendor benefited from this. rafter.so fed 3 of the 6 answers, and Rafter itself was named once, in the 'what should I use' answer that its own domain also fed. A single well-placed vendor page carried a one-count product into the results.

The buyer-situation questions leaned on independent roundup and blog sites instead. gitautoreview.com fed 3 answers, and devtoollab.com, expertinsights.com, offensive360.com, safeguard.sh and sourcegraph.com each fed 2, all of them 'best tools' articles rather than vendor pages. owasp.org, a security nonprofit, fed 2 answers.

Two source types that marketers assume matter were completely absent. Not one of the 24 source domains was a review directory: no G2, no Capterra and no TrustRadius appeared in any of the 6 answers. And not one was a community forum: no Reddit thread and no Quora thread was cited either. In this category the assistants read project docs, vendor pages and roundup articles, and skipped the directories.

If you sell a static analysis tool, this is what moves the needle

The lesson from 24 tools and 24 source domains is blunt: the source list, not your market share, decides whether ChatGPT and Gemini name you. Semgrep did not reach 6 of 6 because it is the biggest brand, it reached it because its material sat in the pages the assistants pulled for every phrasing.

So the work is specific. Get your own domain into these answers the way clang-analyzer.llvm.org and snyk.io did, each feeding 3 of the 6 answers, and get onto the roundups that fed the buyer-situation questions, where gitautoreview.com fed 3 and five more sites fed 2 each. If a rival is named in 4 of 6 answers and you are named in 0, that gap is a list of exact pages you are missing from, not a vague branding problem.

Phrasing is also a targeting choice. Because 'free' and 'affordable' shared only 2 of their names, a free tier puts you in a different answer than a low price does. Pick which of the six buyer questions you want to win, then go be present in that question's specific sources.

The full list, counted

These are the 8 tools ChatGPT and Gemini named in more than one of the six answers. Share is out of 6.

ProductNamed inShare
Semgrep6 of 6100%
Snyk Code4 of 667%
SonarQube4 of 667%
Clang Static Analyzer3 of 650%
DeepSource3 of 650%
Checkmarx2 of 633%
CodeQL2 of 633%
PMD2 of 633%

The remaining 16 tools were each named once (1 of 6, 17%): Bearer, Codacy, CodeClimate, CodeSonar, Cppcheck, Critik, Cycode SAST, fallow, Flawfinder, Fortify, OCLint, PHPStan, Pylint, Qodana, Rafter and Veracode. We kept every name exactly as the assistants said it, so close-sounding but separate products such as CodeQL, Codacy, CodeClimate and CodeSonar each get their own line instead of being folded into one number the data never showed.

Glotier does not sell this, on purpose

Glotier is not a static code analysis tool, so it is correctly absent from all 6 of these answers, and we would be suspicious if it appeared. We ran this check on someone else's category to show the method, not to rank ourselves.

This measurement is exactly what we do for the category you sell in: we put the real buyer questions to ChatGPT and Gemini, record every product named and every source behind each answer, and hand you the gap between where you are named and where you are not. The same six-question check is free, needs no account, and takes about a minute.

The questions we asked

One live web search per question, put to exa+or:chatgpt,gemini on 2026-08-07. 6 of 6 came back with an answer we could read. Whether a product was named is decided by looking for it in the answer text, not by asking a model for its opinion.

  1. best static code analysis tools
  2. best static code analysis tools for small teams
  3. what static code analysis tools should I use
  4. best free static code analysis tools
  5. most affordable static code analysis tools
  6. static code analysis tools recommendations

Questions people ask

What is the best static code analysis tool according to AI assistants right now?
Semgrep. It was the only tool ChatGPT and Gemini named in all six of our six buyer questions (6 of 6, 100%) when we measured on 2026-08-07. Snyk Code and SonarQube tied for second at 4 of 6 (67%), and Clang Static Analyzer and DeepSource followed at 3 of 6 (50%).
What are the best free static code analysis tools?
When we asked ChatGPT and Gemini specifically for free tools, the answer named 7: PMD, Clang Static Analyzer, Semgrep, Cppcheck, Pylint, PHPStan and OCLint. Four of those (Cppcheck, Pylint, PHPStan and OCLint) appeared only in the free question, and the paid platforms that led the 'best' answer, SonarQube and Snyk Code, did not appear in the free list at all.
Do 'free' and 'affordable' return the same shortlist?
No. The 'best free' and 'most affordable' answers overlapped on only 2 of their tools, Semgrep and Clang Static Analyzer. 'Free' surfaced open-source linters (PMD, Cppcheck, Pylint, PHPStan, OCLint), while 'affordable' surfaced a different group (Flawfinder, Bearer, fallow, Critik). Changing one word changed almost the entire list.
Do G2 and Capterra reviews affect which static analysis tools AI recommends?
In this measurement, no. None of the 24 source domains behind the 6 answers was a review directory, so G2, Capterra and TrustRadius did not appear at all. No Reddit or Quora threads appeared either. The answers were built from project docs, vendor pages and 'best tools' roundup articles instead.
How does a static analysis vendor get named by ChatGPT and Gemini?
Be in the exact pages the assistants read. Tools whose own domain fed an answer usually got named: snyk.io fed 3 answers and Snyk Code was named 4 times, clang-analyzer.llvm.org fed 3 and Clang Static Analyzer was named 3 times, and the entire 'best free' answer was built from tools' own homepages. Getting onto roundups matters too, since gitautoreview.com alone fed 3 of the 6 answers. The source list, not market share, decides who is named.

Do you sell in static code analysis tools? Find out whether you are in that list.

Paste your domain and watch the same run happen for your own buyer questions: which of the three assistants names you, who gets named instead, and the exact pages those answers were built from. Free, no card, no account for the first check.

Show my visibility

For reference, Semgrep was named in 6 of the 6 answers we read.

Start with Solo

Get Glotier Solo

Everything on this page is one measurement, taken by hand, on one day. Solo runs it for your product every day and writes the work it points to.

  • The Citation Agent: which of your pages an assistant can actually cite, and the fix for each
  • A paragraph-quality read of your pages: what an assistant can lift whole, and where a claim is missing its source
  • An X agent and a Reddit agent: the live threads worth answering in your category, with a reply drafted for each
  • A daily check, and an article written from what it measured that day, ready to publish
  • The same buyer questions re-asked every day, with every source page behind each answer

Track 3 products and up to 150 buyer questions across ChatGPT, Gemini and Perplexity. $39/month.

Cancel any time. Not for you? Email us within 7 days of a charge and we refund it in full. Refund policy

Not ready to pay? The check is free, with no card and no account. Run it on your own product.