- OWASP and CWE25 for GitLab
- Support 12+ languages
- Custom rules for your IDE and CI/CD pipeline
- Secrets and auth key detection at each push
- Complex and duplicated code detection
The simplest static code analysis for Bitbucket
Install the Codiga Bitbucket app, connect your repository, and inspect your codebase on Bitbucket with the Codiga static analysis engine. Configure your rules and get feedback on your code in just a few minutes.
Learn more about the Codiga Static Analysis Engine
Code reviews in seconds, not minutes
Get real-time feedback faster at each Pull Request! Codiga highlights bugs, security, and maintainability issues within seconds.
Team statistics
Get statistics about your team and individual performance
- Number of code reviews over time
- Most common code violation
- Most modified files that cause merge conflicts
Static Code Analysis Features
Automated Code Reviews
Lightning fast feedback on each code reviews that highlights bugs, security and maintainability issues within seconds.
Support for more than 12 languages
Support 1800+ rules across 12 languages with specific analysis for the most popular frameworks (React, Vue, Next).
Multi-branches support
Works with the most popular languages and libraries.
Dependency scanning
Find outdated dependency and alerts when your dependencies need to be updated.
OWASP and CWE support
Detection of OWASP Top 10 bugs and Common Weakness Enumeration (CWE) issues.
Detect leaked credentials
Works with the most popular languages and libraries.
Check good coding practices
Detect long functions, complex functions and duplicated code in seconds.
Code Duplicate detection
Detect when a developer duplicates code and refactor with a function.
Verify design and architecture flaws
Detect any architectural flaws in your code and get feedback in seconds.
Infrastructure security analysis
Check your code quality in CircleCI, Travis-CI, GitHub action, GitLab or any other CI pipeline tool.
CI/CD integration
Using code to deploy your infrastructure with languages such as Terraform? We detect potential security issues.