Compare software

SpotBugs vs CodeQL: catalog facts
SpotBugsCodeQL

Best for: Java developers who want automated bug detection in builds

Best for: Security researchers and developers hunting vulnerability patterns in source code

Free

Free software under the GNU Lesser General Public License.

Free + paid options

Free for research and open source code; other use falls under GitHub's CodeQL terms.

Windows, macOS, Linux, Command line Command line
  • Checks more than 400 bug patterns
  • Integrations for Maven, Gradle, Ant and Eclipse
All 4 strengths for SpotBugs
  • Checks more than 400 bug patterns
  • Integrations for Maven, Gradle, Ant and Eclipse
  • Extensible with plugins such as find-sec-bugs
  • Analyses code compiled for any Java version
  • Queries follow data flow from source to sink across a codebase
  • Finds every variant of a known bug pattern
All 4 strengths for CodeQL
  • Queries follow data flow from source to sink across a codebase
  • Finds every variant of a known bug pattern
  • Visual Studio Code extension and a CLI
  • Ready-made databases for many open source projects
  • Requires Java 11 or later to run
  • Java bytecode only, not other languages
  • Free use is limited to research and open source code
  • Writing custom queries means learning the QL language
All 3 limitations for CodeQL
  • Free use is limited to research and open source code
  • Writing custom queries means learning the QL language
  • The analysis engine itself is not open source
Downloadable app Downloadable app
Open source Not open source
License: LGPL-2.1-only License: GitHub CodeQL Terms and Conditions
No account needed Not stated if an account is needed
Offline features available Not stated if it works offline
Sources for SpotBugs

Catalog checked October 2, 2026

Sources for CodeQL

Catalog checked September 24, 2026

“Not stated” means we have not confirmed it. Features can vary by device and plan.