‹ The Index

Sonarqube

plugin

Integrate SonarQube code quality and security analysis into Claude Code: this includes namespaced slash commands, a guided skill to setup the SonarQube CLI, and a startup check for the CLI and wiring. MCP server registration and secrets-scanning hooks are installed on your machine by the SonarQube CLI as part of the setup.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code

Category: Productivity — see all ranked ›

Work: Code review · Security review

Who it is for: Software engineer · Security engineer

solid

“Slash commands shown with real rule ids and flags; body is seven install matrices”

Security audit

Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.

source ↗  ·  plugin:sonarsource/sonarqube-agent-plugins/sonarqube

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›