PMD
Github Repo: https://github.com/pmd/pmd
Homepage: https://pmd.github.io/
Orizon
OWASP Orizon Project: https://www.owasp.org/index.php/Category:OWASP_Orizon_Project
SourceForge / Orizon: http://orizon.sourceforge.net/download.shtml
Github Repo: https://github.com/thesp0nge/owasp-orizon
LapsePlus
OWASP LAPSE Project: https://www.owasp.org/index.php/OWASP_LAPSE_Project
OWASP / Download: https://www.owasp.org/index.php/Projects/OWASP_LAPSE_Project/Releases/LapsePlus_2.8.1
http://www.securityinternal.com/2016/03/static-source-code-analysis-with-owasp.html
http://blog.7-a.org/2013/01/installing-and-using-lapse-plus-in.html
Code Google: https://code.google.com/archive/p/lapse-plus/downloads
Imagix 4D
https://www.imagix.com/download/info/README_UNIX
Homepage: https://www.imagix.com/index.html
FindBugs
Homepage: http://findbugs.sourceforge.net/
参考文献
OWASP / Static Code Analysis
Wikipedia / List of tools for static code analysis
NIST / Source Code Security Analyzers