On this page
- Which open-source SAST tools are still maintained in 2026?
- Which open-source SAST tool should you run for your language?
- Is Semgrep still open source?
- Which "free" SAST tools are not open source?
- How do you run several open-source SAST tools together?
- What do open-source SAST tools leave to you?
- Where does CybeDefend fit?
- Frequently asked questions
- What are the best free open-source SAST tools?
- Is Semgrep free and open source?
- Is SonarQube free?
- Is CodeQL open source?
- What is the best open-source SAST tool for Python?
- What is the difference between SAST and SCA?
- What is SARIF?

The open-source SAST setup worth running in 2026 is one multi-language engine, Opengrep or Semgrep Community Edition, plus the specialist for each main language: Bandit for Python, gosec for Go, SpotBugs with Find Security Bugs for Java, Psalm for PHP, Cppcheck or Flawfinder for C and C++. We checked the twenty tools in this guide on GitHub on 1 October 2026: their licence, their latest release, and how each one writes SARIF, the format that lets you merge their results. Three findings stand out. Horusec has not shipped a release since June 2022. Brakeman and Bearer are free to run on your own code but are not open source: Brakeman's licence forbids commercial resale, and Bearer is source-available. And the CodeQL CLI, often listed as free, may not be run on private code without a paid GitHub licence.
Which open-source SAST tools are still maintained in 2026?
Eighteen of the twenty tools below are maintained, and two have stopped. The table is what GitHub's API returned on 1 October 2026: the licence each repository declares, its latest tagged release, and our reading of the status. Stars measure attention, not maintenance, so they are left out.
| Tool | What it scans | Licence | Latest release | Status |
|---|---|---|---|---|
| Opengrep | 30+ languages | LGPL-2.1 | v1.30.0, 7 Sep 2026 | Active |
| Semgrep Community Edition | 30+ languages | LGPL-2.1 engine, rules under their own licence | v1.178.0, 23 Sep 2026 | Active |
| SonarQube Community Build | Many languages | LGPL-3.0 | 26.9, 2 Sep 2026 | Active |
| CodeQL CLI | C/C++, C#, Go, Java, Kotlin, JavaScript, TypeScript, Python, Ruby, Rust, Swift, GitHub Actions | GitHub CodeQL Terms, not open source | v2.27.1, 22 Sep 2026 | Active, restricted |
| Datadog Static Analyzer | Several languages, Datadog rulesets | Apache-2.0 | 0.9.8, 25 Sep 2026 | Active |
| OpenAI Codex Security | Model-based, any language | Apache-2.0 client | 0.1.30, 23 Sep 2026 | Active, needs an OpenAI account |
| Joern | C/C++, Java, JavaScript, Python, PHP, Go, Ruby, Swift, C#, Kotlin, binaries | Apache-2.0 | v4.0.644, 1 Oct 2026 | Active |
| Bearer CLI | Go, Java, JavaScript, TypeScript, PHP, Python, Ruby | Elastic License 2.0 | v2.1.1, 24 Aug 2026 | Active, source-available |
| Horusec | 18 languages | Apache-2.0 | v2.8.0, 8 Jun 2022 | Last commit August 2023 |
| Bandit | Python | Apache-2.0 | 1.9.4, 25 Feb 2026 | Active |
| gosec | Go | Apache-2.0 | v2.29.0, 26 Aug 2026 | Active |
| Brakeman | Ruby on Rails | Brakeman Public Use License | v8.1.0, 30 Sep 2026 | Active, not open source |
| SpotBugs + Find Security Bugs | Java and JVM bytecode | LGPL-2.1 + LGPL-3.0 | 4.10.4, 20 Aug 2026 + 1.14.0, 17 Jun 2025 | Active |
| eslint-plugin-security | JavaScript, Node.js | Apache-2.0 | v4.2.0, 1 Oct 2026 | Active |
| njsscan | Node.js | LGPL-3.0 | 1.0.1, 21 Sep 2026 | Active |
| Psalm | PHP | MIT | 6.19.1, 29 Sep 2026 | Active |
| Flawfinder | C/C++ | GPL-2.0 | No GitHub release, last commit 17 May 2026 | Maintained |
| Cppcheck | C/C++ | GPL-3.0 | 2.22.0, 19 Sep 2026 | Active |
| mobsfscan | Android and iOS: Java, Kotlin, Swift, Objective-C | LGPL-3.0 | 1.0.1, 21 Sep 2026 | Active |
| Security Code Scan | C#, VB.NET | LGPL-3.0 | 5.6.7, 5 Sep 2022 | Last commit November 2022 |
Two warnings hide in that table. Horusec is not archived and still appears in lists of "free SAST tools", yet its main branch has not changed since 7 August 2023. And the classic open-source analyser for .NET, Security Code Scan, stopped in 2022: a C# team today relies on a multi-language engine rather than a specialist.
Which open-source SAST tool should you run for your language?
One specialist for your main language, next to a multi-language engine. The specialist knows the framework's idioms and its dangerous APIs in depth; the engine catches the patterns that cross languages and lets you write one rule for the whole repository.
| Language | Specialist | Notes |
|---|---|---|
| Python | Bandit | Install the [sarif] extra for SARIF output |
| Go | gosec | Native SARIF |
| Java, JVM | SpotBugs with Find Security Bugs | Analyses compiled bytecode, so build first |
| JavaScript, Node.js | eslint-plugin-security, njsscan | ESLint needs a separate SARIF formatter |
| PHP | Psalm | Taint analysis runs as its own pass |
| Ruby on Rails | Brakeman | Free to scan your own code, not open source |
| C, C++ | Cppcheck, Flawfinder | Cppcheck writes SARIF from 2.16.0 |
| Android, iOS | mobsfscan | Covers Swift and Objective-C too |
| C#, VB.NET | None maintained in this list | Use a multi-language engine |
For the engine, Opengrep and Semgrep Community Edition read the same rule syntax, so the choice is about governance, covered in the next section. Joern is a different kind of tool: it builds a code property graph you query yourself, powerful for research and custom audits; its scanner has no SARIF flag, though its query console can export findings as SARIF.
Is Semgrep still open source?
The engine is. Semgrep Community Edition is licensed LGPL-2.1 and shipped v1.178.0 on 23 September 2026. Two things changed around it. The rules Semgrep publishes in its registry are under the Semgrep Rules License v1.0, a licence of its own rather than an open-source one, so read it before you reuse those rules inside a commercial product. And a group of AppSec vendors forked the engine as Opengrep, in a repository created on 14 December 2024. Its README gives the reason in one line: it "was created when Semgrep moved critical features behind a commercial licence".
Opengrep stays LGPL-2.1, runs existing Semgrep rules unchanged, writes JSON and SARIF, and has added intra-file taint tracking (--taint-intrafile). Its backers named in the README are Aikido, Amplify, Endor Labs, Kodem and Orca Security. Pick Semgrep if you want its managed rules and platform; pick Opengrep if you want the engine's governance outside a single company. Your rules work in both.
Which "free" SAST tools are not open source?
Four tools in this guide cost nothing to download and still restrict how you use them. Check these before a tool reaches your CI:
- CodeQL CLI. It ships under the GitHub CodeQL Terms and Conditions, not an open-source licence. Without a paid licence you may use it for academic research, demonstrations and the analysis of open-source code under an OSI-approved licence; automated use in CI is allowed only when that open-source code is hosted on GitHub.com. Private code requires a paid licence, which the terms still call GitHub Advanced Security and GitHub now sells as GitHub Code Security. The queries are MIT-licensed, the engine is not.
- Brakeman. The Brakeman Public Use License, whose text names Synopsys as licensor, lists "using the Software to analyze Licensee's software" as a non-commercial use, so scanning your own Rails code costs nothing. What needs a paid licence is commercial use: offering Brakeman as a managed or SaaS service, or shipping it inside a product. That restriction is why it is not an open-source licence. Only code committed before 15 June 2018 is MIT.
- Bearer CLI. The Elastic License 2.0 makes it source-available: the README says you "can use it freely inside your organization", while more languages and cross-file analysis sit in a paid edition sold by Cycode.
- OpenAI Codex Security. The CLI and SDK are Apache-2.0, but the analysis runs on OpenAI's models. You sign in, or set
OPENAI_API_KEYin CI, and your code is sent to OpenAI. Some findings require approval through OpenAI's Trusted Access for Cyber programme.
The free tiers of commercial platforms belong to the same family: free to start, never open source, and your code is analysed in the vendor's cloud. That is a reasonable trade for many teams. It is just a different one.
How do you run several open-source SAST tools together?
Have every tool write SARIF 2.1.0, the OASIS standard for static analysis results, then merge the files. Every command below comes from the project's own documentation or source, checked on 1 October 2026:
# Multi-language engine
opengrep scan --sarif-output=opengrep.sarif -f rules/ .
# Python
pip install "bandit[sarif]"
bandit -r . -f sarif -o bandit.sarif
# Go
gosec -fmt sarif -out gosec.sarif ./...
# Java: build first, SpotBugs reads bytecode
spotbugs -textui -pluginList findsecbugs-plugin.jar -sarif=spotbugs.sarif target/app.jar
# JavaScript: SARIF needs Microsoft's formatter
npm install --save-dev @microsoft/eslint-formatter-sarif
npx eslint -f @microsoft/eslint-formatter-sarif -o eslint.sarif .
# Node.js
njsscan --sarif -o njsscan.sarif .
# PHP: taint analysis is its own pass
psalm --taint-analysis --report=psalm.sarif
# C and C++
cppcheck --output-format=sarif --output-file=cppcheck.sarif .
flawfinder --sarif ./ > flawfinder.sarif
Two details save an afternoon. ESLint has no built-in SARIF output: -f sarif fails, and the formatter is a separate package from Microsoft's SARIF SDK. And SonarQube Community Build imports SARIF through sonar.sarifReportPaths, but we found no documented SARIF export, so it sits at the end of a pipeline, not in the middle.
A merged file is not a triaged backlog. Three gaps remain:
- Duplicates. The same SQL injection in a Python service can come back from Opengrep and Bandit under two rule IDs, and the two findings do not know about each other.
- Triage state. A finding you dismissed as a false positive is not dismissed in the next run, unless something remembers the decision.
- History. Teams preparing a SOC 2 or an ISO 27001 audit are asked to show that findings are tracked and fixed over time. A pile of SARIF files from CI logs does not show that by itself.
That is the part teams end up building, or buying.
What do open-source SAST tools leave to you?
The engine is free. The rules, the triage and the upkeep are your time:
Rules
An engine is only as good as its rules. Semgrep's registry rules carry their own licence, and Opengrep's rule repository, which describes itself as a fork of Semgrep's from December 2024, has had no commit since January 2025. Expect to maintain rules yourself.
Triage
Pattern matching reports what looks dangerous, not what can actually be reached. Most of the effort goes into sorting, which we cover in why most SAST findings are noise.
Upkeep
Twenty projects means twenty release cadences, licences that can change, and tools that stop, as Horusec and Security Code Scan did.
Where does CybeDefend fit?
If you would rather not assemble and maintain this stack, CybeDefend runs SAST, SCA, secrets, IaC, container and CI/CD scanning in one place, sorted by reachability so the findings on top are the ones an attacker can actually reach. Its SAST page shows how. And if your code is increasingly written by coding agents, VibeDefend hands the SAST, SCA, secrets, IaC and CI/CD findings to the agent while it writes, instead of after the pull request. For a comparison of commercial tools by need, see the best AI code security tools in 2026.
Frequently asked questions
What are the best free open-source SAST tools?
A multi-language engine plus a language specialist. Opengrep or Semgrep Community Edition for the engine; Bandit for Python, gosec for Go, SpotBugs with Find Security Bugs for Java, Psalm for PHP, Cppcheck and Flawfinder for C and C++, eslint-plugin-security and njsscan for Node.js, mobsfscan for mobile. All of them were maintained on 1 October 2026 and all can write SARIF, ESLint through a separate formatter.
Is Semgrep free and open source?
The Semgrep Community Edition engine is free and open source under LGPL-2.1. The rules in Semgrep's registry are under the Semgrep Rules License v1.0, which is not an open-source licence, and Semgrep's paid platform adds features on top. Opengrep is an LGPL-2.1 fork that runs the same rules.
Is SonarQube free?
SonarQube Community Build is free and open source under LGPL-3.0; its latest release on 1 October 2026 was 26.9, published on 2 September. SonarSource sells paid editions with more features. The Community Build can import SARIF from other scanners; we found no documented SARIF export.
Is CodeQL open source?
No. The CodeQL queries are MIT-licensed, but the CodeQL CLI ships under GitHub's own terms. It is free for academic research, demonstrations and analysing open-source code; scanning private code requires a paid GitHub licence.
What is the best open-source SAST tool for Python?
Bandit, maintained by the Python Code Quality Authority and licensed Apache-2.0, with release 1.9.4 in February 2026. Pair it with a multi-language engine such as Opengrep for project-specific rules. Install bandit[sarif] to get SARIF output.
What is the difference between SAST and SCA?
SAST reads the code your team writes and looks for vulnerable patterns, such as an injection or a hard-coded secret. SCA reads your dependency manifests and lockfiles and reports the known vulnerabilities in the open-source packages you use. Most teams need both, because most of the code they ship is dependencies.
What is SARIF?
The Static Analysis Results Interchange Format, an OASIS standard. Version 2.1.0 is a JSON format that most SAST tools can write, so the results of several scanners can be merged, uploaded to a code host or imported into a vulnerability management tool.


