[Home](<https://pvs-studio.com/en/>)

>

PVS‑Studio analyzer 

#  PVS-Studio is a static analyzer on guard of code quality, security (SAST), and code safety 

##  What is PVS-Studio? 

###  If you are asking: "What is PVS-Studio?" - this video answers your question. 

Here we'll talk about the most important topics and aspects related to the PVS-Studio static analyzer. You'll find out not just how PVS-Studio can help you - but also what mechanisms and approaches it uses. 

[ See all videos about PVS-Studio ](<https://pvs-studio.com/en/blog/video/opportunities/>)

Or you can view the presentation about the product features. 

![Presentation icon](/static/images/icons/presentation.svg) [ View the presentation ](<https://docs.google.com/presentation/d/e/2PACX-1vTTZM0yDEa6DlIb65063ioabxzOi1lKXs-Hojly4tC_Np0861CgP-hP8pfwdr9UBVupMxTvy-vc5UAM/pub?start=false&loop=false&delayms=3000>)

When it is time to use the PVS‑Studio analyzer 

For a developer

You make occasional mistakes during development

Debugging when searching for errors is time consuming

Errors get into the version control system

Once an error is found by QA specialists, it’s difficult to debug that code

[ For a manager Frequent returns to old tasks due to bugs Users report errors in your products You hire more developers but notice a code quality decline With the increasing amount of code, it is difficult to assess its quality and reliability ](<https://pvs-studio.com/en/pvs-studio/for-managers/>)

[ For a security professional Difficulties with external code audit Potential customers require the use of such tools Clients require to use security and safety standards in development ](<https://pvs-studio.com/en/pvs-studio/security/>)

How PVS-Studio finds potential vulnerabilities 

![cwe diagram](/static/images/backgrounds/cwe_diagram_small.svg)

PVS-Studio detects various errors – typos, dead code, and potential vulnerabilities (Static Application Security Testing, SAST).

The analyzer matches warnings to the Common Weakness Enumeration, SEI CERT Coding Standards, and supports the MISRA standard.

Click the links below to see PVS-Studio warning classifications for various standards:

[CWE](<https://pvs-studio.com/en/pvs-studio/sast/cwe/>)

[Sei Cert](<https://pvs-studio.com/en/pvs-studio/sast/cert/>)

[Misra](<https://pvs-studio.com/en/pvs-studio/sast/misra/>)

[OWASP](<https://pvs-studio.com/en/pvs-studio/sast/owasp/>)

[AUTOSAR](<https://pvs-studio.com/en/pvs-studio/sast/autosar/>)

[More details...](<https://pvs-studio.com/en/pvs-studio/sast/>)

Where does PVS-Studio integrate into? 

IDE 

![Visual Studio](/static/images/integrated/Visual_Studio_Icon_2026.svg)

[Visual Studio](<https://pvs-studio.com/en/docs/manual/6522/>)

![Visual Studio Code](/static/images/integrated/vcstuido.svg)

[Visual Studio Code](<https://pvs-studio.com/en/docs/manual/6646/>)

![WebStorm](/static/images/integrated/webstorm.svg)

[WebStorm](<https://pvs-studio.com/en/docs/manual/7189/>)

![PhpStorm](/static/images/integrated/phpstorm.svg)

[PhpStorm](<https://pvs-studio.com/en/docs/manual/7189/>)

![GoLand](/static/images/integrated/goland.svg)

[GoLand](<https://pvs-studio.com/en/docs/manual/7190/>)

![IntelliJ IDEA](/static/images/integrated/icon-intellij-idea.svg)

[IntelliJ IDEA](<https://pvs-studio.com/en/docs/manual/6704/>)

![Rider](/static/images/integrated/icon-rider.svg)

[Rider](<https://pvs-studio.com/en/docs/manual/0052/>)

![CLion](/static/images/integrated/clion.svg)

[CLion](<https://pvs-studio.com/en/docs/manual/0052/>)

![Qt Creator](/static/images/integrated/QtProject-qtcreator.png)

[Qt Creator](<https://pvs-studio.com/en/docs/manual/6648/>)

Game engines 

![Unreal Engine](/static/images/integrated/Unreal_Engine_Logo.svg)

[Unreal Engine](<https://pvs-studio.com/en/docs/manual/0043/>)

![Unity](/static/images/integrated/unity_logo.svg)

[Unity](<https://pvs-studio.com/en/docs/manual/6607/>)

Code quality 

![SonarQube](/static/images/integrated/SonarQube-icon.png)

[SonarQube](<https://pvs-studio.com/en/docs/manual/0037/>)

![DefectDojo](/static/images/integrated/DefectDojo-3.png)

[DefectDojo](<https://pvs-studio.com/en/docs/manual/6686/>)

![CodeChecker](/static/images/integrated/logo_codechecker.png)

[CodeChecker](<https://pvs-studio.com/en/docs/manual/6819/>)

Embedded 

![Keil µVision, DS-MDK](/static/images/integrated/keil_icon.svg)

Keil µVision, DS-MDK 

![IAR Embedded Workbench](/static/images/integrated/iar_icon.svg)

IAR Embedded Workbench 

![QNX Momentics](/static/images/integrated/qnx_2026.svg)

QNX Momentics 

![TI ARM Code Generation](/static/images/integrated/ti_arm_icon.svg)

TI ARM Code Generation 

Build system 

![MSBuild](/static/images/integrated/MSBuild-Logo.svg)

[MSBuild](<https://pvs-studio.com/en/docs/manual/0035/>)

![CMake](/static/images/integrated/make_icon.svg)

[CMake](<https://pvs-studio.com/en/docs/manual/6591/>)

![Make](/static/images/integrated/Official_gnu.svg)

Make 

![Ninja](/static/images/integrated/Ninja_icon.svg)

[Ninja](<https://pvs-studio.com/en/docs/manual/0036/>)

![Gradle](/static/images/integrated/gradle-elephant-icon-dark-green-secondary.svg)

[Gradle](<https://pvs-studio.com/en/docs/manual/6706/>)

![Maven](/static/images/integrated/file_type_maven_icon_130397.svg)

[Maven](<https://pvs-studio.com/en/docs/manual/6705/>)

![JSON Compilation Database](/static/images/logo/dragon_medium.png)

[JSON Compilation Database](<https://pvs-studio.com/en/docs/manual/6557/>)

Virtualization 

![Docker](/static/images/integrated/docker-tile.svg)

[Docker](<https://pvs-studio.com/en/docs/manual/0047/>)

![WSL](/static/images/integrated/wsl_new.png)

WSL 

Distributed build 

![Incredibuild](/static/images/integrated/incdibuild_logo_high101.svg)

[Incredibuild](<https://pvs-studio.com/en/docs/manual/0041/>)

CI 

![Jenkins](/static/images/integrated/jenkins-icon.svg)

[Jenkins](<https://pvs-studio.com/en/docs/manual/0048/>)

![TeamCity](/static/images/integrated/icon-teamcity.svg)

[TeamCity](<https://pvs-studio.com/en/docs/manual/0049/>)

Cloud CI 

![CircleCI](/static/images/integrated/icons8-circleci.svg)

[CircleCI](<https://pvs-studio.com/en/docs/manual/0054/>)

![Travis CI](/static/images/integrated/Travis_icon.svg)

[Travis CI](<https://pvs-studio.com/en/docs/manual/0057/>)

![GitLab](/static/images/integrated/wm_web.svg)

[GitLab](<https://pvs-studio.com/en/docs/manual/0056/>)

![Azure DevOps](/static/images/integrated/Azure_icon.svg)

[Azure DevOps](<https://pvs-studio.com/en/docs/manual/0053/>)

![GitHub Actions](/static/images/integrated/github_actions.svg)

[GitHub Actions](<https://pvs-studio.com/en/docs/manual/6579/>)

## Work from your browser

Review PVS‑Studio results directly in your browser: mark false positives and assign team members for fixing issues.

  * [How to work with CodeChecker](<https://pvs-studio.com/en/docs/manual/6819/>)
  * [How to work with SonarQube](<https://pvs-studio.com/en/docs/manual/0037/>)

Supported languages and compilers 

**Windows**

Visual Studio C, C++, C++/CLI, C++/CX (WinRT)

MinGW C, C++

Texas Instruments Code Composer Studio, C6000-CGT, C, C++

**Windows/Linux/macOS**

GNU Arm Embedded Toolchain, Arm Embedded  
GCC compiler, C, C++

GNU toolchain for RISC-V, C, C++

CLion, Qt Creator, VS Code, GCC, Clang C, C++

IntelliJ IDEA, Android Studio, VS Code Java

Visual Studio, JetBrains Rider, VS Code, .NET Framework, .NET C#

WebStorm, PhpStorm, VS Code JavaScript, TypeScript

GoLand, VS Code Go

Texas Instruments C2000-CGT, C, C++

**Windows/Linux**

IAR Embedded Workbench, C/C++ Compiler for ARM C, C++

QNX Momentics, QCC C, C++

Keil µVision, DS-MDK, ARM Compiler 5/6 C, C++

Texas Instruments Code Composer Studio, ARM Code  
Generation Tools C, C++

MPLAB XC8 C

Getting started with PVS‑Studio is easy

### Trying for the first time? Check the most interesting warnings

A special filter chooses those warnings that most likely indicate an error.

[More details...](<https://pvs-studio.com/en/docs/manual/6532/>)

### Integrating PVS‑Studio into the project?  
Hide the warnings on the legacy code

This way you will only work with warnings issued on the newly written code. If necessary, you can return the hidden warnings later

[More details...](<https://pvs-studio.com/en/docs/manual/0032/>)

Problem types that PVS-Studio detects

Quality 

Typos

Null pointer/reference dereference

Array index out of bounds

Incorrect shift operations

and others.

Security 

[CWE](<https://pvs-studio.com/en/pvs-studio/sast/cwe/>)

[SEI CERT](<https://pvs-studio.com/en/pvs-studio/sast/cert/>)

[OWASP](<https://pvs-studio.com/en/pvs-studio/sast/owasp/>)

[Vulnerable components (SCA)](<https://pvs-studio.com/en/pvs-studio/sca/>)

Safety 

[MISRA](<https://pvs-studio.com/en/pvs-studio/sast/misra/>)

[AUTOSAR](<https://pvs-studio.com/en/pvs-studio/sast/autosar/>)

[See all types of errors](<https://pvs-studio.com/en/docs/warnings/>)

Customers choose PVS-Studio for...

Expert technical support

Over the years, we have built a team of proven code analysis experts. Clients get support directly from our analyzer developers.

Offline use availability

You can use our analyzer offline. This includes the installation, activation, launch, source code analysis, and all other use case scenarios. This is a perfect solution for companies that employ isolated development environments and develop software for finance or government sectors.

Ease of use

To take a quick peek at the analyzer, use the compilation monitoring system. It is designed for Windows and Linux and does not require you to integrate PVS-Studio into a project.

Diagnostic abilities

We have developed more than 1100 diagnostic rules and add new ones every month.

Cross-platform integration

Many apps are created for several platforms to meet the current market's demand. Our cross-platform analyzer provides such clients with full code coverage.

Easy-to-use analyzer reports

The analyzer reports are available in Html, Xml, Csv, Txt, Json, CompileError, TaskList, TeamCity formats. The report generator itself is posted on GitHub for custom modifications.

Convenient CLI

You can choose one of the three easy approaches: run the analyzer from the command line, integrate it into a build script or CI.

Plugins

To enhance interaction with the analyzer, we provide plugins for Visual Studio, IntelliJ IDEA, Rider, SonarQube, Jenkins, and other similar products.

Mode for checking Legacy code

Some clients are uncertain about introducing an analyzer into their development process because of the large code base. PVS-Studio accommodates these clients by introducing Legacy code checking mode. You can install PVS-Studio, hide warnings for old (Legacy) code until later, and use the analyzer to check new code.

Dealing with false alarms

Static analysis implies you’ll get false warnings. In addition to contacting our support, users have many ways to deal with false positives. This makes the work with the analyzer very convenient.

![](/static/images/logo/pvs_logo.png) ![](/static/images/logo/pvs_logo_2.png)

[Download](</en/pvs-studio/download/>)

The number of diagnostics   
in PVS-Studio increases each year 

Number of diagnostics

Number of diagnostics

Years 

How does PVS-Studio do all this?

![Based on compilation parameters icon](/static/images/preprocessing.png)

**Preprocessing of C and C++ source files** (based on compilation parameters) allows to expand preprocessor directives, i.e. to include header files and to substitute macros. The analyzer uses this feature to build the most complete semantic model of the analyzed code. 

![The pattern-based analysis icon](/static/images/icons/abstract/1.png)

**The pattern-based analysis** that is based on an abstract syntax tree searches for fragments in the source code that are similar to the known code patterns with an error. 

![Method annotations icon](/static/images/icons/abstract/2.png)

**Method annotations** provide more information about the used methods than one can obtain by analyzing only their signatures. 

![Data-flow analysis icon](/static/images/icons/abstract/3.png)

**Data-flow analysis** is used to evaluate limitations that are imposed on variable values when processing various language constructs. For example, data-flow analysis helps evaluate values that a variable can take inside if/else blocks. 

![Type inference icon](/static/images/icons/abstract/4.png)

**Type inference** that is based on a program semantic model provides the analyzer with full information about all variables and statements in the code. 

![Symbolic execution icon](/static/images/icons/abstract/5.png)

**Symbolic execution** evaluates variables' values that can lead to errors, performs checks of values' range. 

![Tainted data analysis icon](/static/images/icons/abstract/taint.png)

**Tainted data analysis** detects cases when an application uses unverified user data. Trusting such data excessively may cause vulnerabilities (for example, SQLI, XSS, path traversal). 

![Intermodular analysis icon](/static/images/icons/abstract/intermodular.png)

**Intermodular analysis** enables the diagnostics to account for functions declared in other translation units. 

![Software composition analysis icon](/static/images/icons/abstract/sca_icon.png)

**Software composition analysis** (SCA) looks for the application dependencies on components that contain vulnerabilities.