Best SonarQube MCP Servers
SonarQube is an open-source platform developed by SonarSource for continuous inspection of code quality to perform automatic reviews with static analysis of code to detect bugs, code smells, and security vulnerabilities.
Why this server?
Provides read-only access to the SonarQube Web API, enabling issue retrieval, quality gate status checks, rule details, component measures, and source code context for project analysis.
AlicenseBqualityDmaintenanceRead-only MCP server that exposes SonarQube Web API tools for issue retrieval, quality gate status, and source context, enabling coding agents to fix code issues.896 npm1MITWhy this server?
Provides tools for interacting with SonarQube to list projects, retrieve project metrics, manage code quality issues, analyze security vulnerabilities, check quality gates, and view historical analysis trends.
AlicenseAqualityDmaintenanceA Model Context Protocol (MCP) server that provides AI assistants with access to SonarQube code quality, security, and project analytics data.738 npmMITWhy this server?
Reads SonarQube (or SonarCloud) analysis results for a configured project key and token, feeding static-analysis findings into the review workflow via the review_sonar tool. Read-only: no Sonar issue-status mutation is exposed.
AlicenseAqualityBmaintenanceEnables an MCP-capable assistant to review GitLab merge requests, GitHub pull requests, and pre-push local branches against ticket requirements, domain rubrics, compiler/lint pre-passes, blast-radius analysis, and SonarQube findings, and to draft inline comments or follow-up tasks in the user's chosen language. Nothing reaches a remote host until a human approves the exact content in an interactive terminal.3MITWhy this server?
Optionally integrates with SonarQube for IDE to enhance code quality analysis, with automatic merging and deduplication of findings from JetBrains inspections.
AlicenseAqualityAmaintenanceConnects AI coding assistants to PyCharm's code quality inspections and optionally SonarQube for IDE, providing unified, de-duplicated code analysis results without uploading source code.82MITWhy this server?
Integrates with SonarQube for static application security testing (SAST), enabling automated code analysis and vulnerability detection.
AlicenseBqualityCmaintenanceAn MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.6MITWhy this server?
Provides tools to manage SonarQube projects, search issues, check quality gate status, and handle security hotspots via configurable base URL.
AlicenseAqualityCmaintenanceEnables interaction with SonarCloud projects, issues, quality gates, and security hotspots through natural language.15MITWhy this server?
Provides tools to check for code quality issues in a branch and automatically fix common SonarQube issues.
AlicenseBqualityDmaintenanceIntegrates Zoho Projects, Git, and SonarQube to automate task management, branch creation, code quality checks, and reporting for React developers.134 npmMITWhy this server?
Provides tools to query SonarQube for code quality metrics, issues, and duplication reports on pull requests and files.
AlicenseAqualityDmaintenanceEnables Cursor AI to query SonarQube for pull request metrics, issues, file issues, and duplication reports directly, without manual data export.438 npmMITWhy this server?
Provides read-only access to a SonarQube instance via its web-api, allowing AI agents to list projects and components, fetch issues and security hotspots, retrieve rule details and source-code snippets, and view project summaries, branches, and pull request analyses.
AlicenseAqualityAmaintenanceRead-only MCP server for self-hosted SonarQube Community Build 26.4+: lets AI agents (Claude Code, Cursor, Copilot) read issues, security hotspots, rules and code snippets to fix findings locally13MIT