Best SonarQube MCP Servers
SonarQube is an open-source platform developed by SonarSource for continuous inspection of code quality to perform automatic reviews with static analysis of code to detect bugs, code smells, and security vulnerabilities.
Why this server?
Provides read-only tools for interacting with SonarQube instances, enabling discovery of projects, retrieval of quality metrics, Quality Gate status checks, issue search with filtering, and cross-project ranking by worst metric values.
AlicenseAqualityBmaintenanceAn MCP server for SonarQube that enables LLM agents to discover projects, analyze code quality metrics, check Quality Gate status, search issues with filters, and rank projects by worst-performing metrics. It provides read-only, safe access to SonarQube instances with structured outputs and error handling.Last updated5MITWhy this server?
Offers specialized AI agent security analysis that complements traditional code quality tools like SonarQube with AI-specific vulnerability detection.
Why this server?
Integrates with SonarQube for static application security testing (SAST), enabling automated code analysis and vulnerability detection.
AlicenseBqualityCmaintenanceAn MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.Last updated6MITWhy this server?
Provides read-only access to SonarQube projects, metrics, and rules, allowing users to search for issues, retrieve quality dashboards, and access detailed information about code bugs, vulnerabilities, and security hotspots.
FlicenseAqualityCmaintenanceA read-only MCP server that provides AI assistants with structured access to SonarQube projects, issues, metrics, and rules. It enables safe analysis of code quality and security findings through a set of validated, safety-first tools.Last updated6Why this server?
Provides tools for accessing code quality and security analysis data from SonarQube instances, including project listing, issue searching (bugs, vulnerabilities, code smells), quality gate status checks, and retrieval of code metrics.
Alicense-qualityCmaintenanceServer for SonarQube Give AI assistants direct access to your code quality, security & analysis dataLast updated1MITWhy this server?
Integrates with SonarQube servers for an optional secondary phase of deep code analysis and security auditing.
Alicense-qualityBmaintenance🚀 Kill the Junior AI Era. 🤖 Level up your AI code to Principal standards. No more sloppy lines or junior mistakes. Automated ESLint ✨ TypeScript 🔧 Prettier 🎨 SonarQube 🛡️ Security 🔒 Complexity 📊 in seconds. High-stakes quality, forced to ship only the best. ⚡🏆 Goodbye, bad code. Hello, Principal Engineer. 🚀✨Last updated2944MITWhy this server?
Provides tools for retrieving metrics, historical data, and component tree metrics from SonarQube projects. Enables querying project status, listing projects, fetching code quality metrics (bugs, vulnerabilities, code smells, coverage, duplication density), and retrieving project issues with filtering options.
Alicense-qualityBmaintenanceA server that provides tools for retrieving SonarQube project metrics and quality data through a simplified message-based approach, allowing users to programmatically access metrics, historical data, and component-level information from SonarQube.Last updated12Apache 2.0Why this server?
Provides output formats compatible with SonarQube for static code analysis integration
MITWhy this server?
Provides tools for interacting with SonarQube APIs, enabling token-based authentication, project listing and details retrieval, and metrics collection from SonarQube instances.
Alicense-qualityCmaintenanceA lightweight MCP for SonarQube reportsLast updated1MIT