On this page
Overview
PMD is an extensible multi-language static code analyzer. It provides more than 400 built-in rules, supports custom rules in Java or XPath, and includes CPD for duplicate-code detection.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Run more than 400 built-in rules over parsed source ASTs
The README lists findings such as unused variables, empty catch blocks, and unnecessary object creation and supports Java, Apex, Kotlin, JavaScript, Swift, PL/SQL, and other languages.
Sources: [2]
Extend analysis with Java or XPath rules and copy-paste detection
PMD parses source into ASTs and allows custom rules in Java or XPath. CPD detects duplicated code across Java and many other languages.
Sources: [2]
Best fit
Fits Java projects enforcing bug, design, and code-smell rules in CI
It is useful when teams want configurable best-practice, error-prone, design, and other analysis beyond source-format conventions, with Maven, Gradle, and IDE integrations.
Sources: [2]
Before adoption
Review rule changes and type-resolution requirements during upgrades
Version 7.28.0 adds Java rules and expands Kotlin XPath/type information. Some rule properties are deprecated, and type-aware analysis may require auxClasspath configuration.
Sources: [4]
Official sources
- [1]pmd/pmd — GitHub repository(2026-10-06)
- [2]PMD — README(2026-10-06)
- [3]PMD — License(2026-10-06)
- [4]PMD 7.28.0 release(2026-10-06)
Supplemental curator note
PMD fits teams that want rule-based analysis for bugs, design, performance, and other code smells beyond style. Introduce rule upgrades gradually because new findings and deprecated properties can affect CI.
Try it in 3 steps
- 1
Get the source
git clone --depth 1 https://github.com/pmd/pmd.git - 2
Enter the repository
cd pmd - 3
Check the official steps
Continue with the commands in the README Installation, Quick Start, or Getting Started section.
find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Growth
Growth trends · Last 30 days
5,494 Stars
Trend data is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- apex
- code-analysis
- code-quality
- hacktoberfest
- java
- linter
- plsql
- static-analysis
- static-code-analysis
- swift
- Stars
- 5,494
- Forks
- 1,598
- Watchers
- 5,494
- Open issues
- 600
- Contributors
- 316
- Owner type
- Organization
- Primary language
- Java
- License
- Not determined
- Repository last updated
- Oct 4, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Apache Maven5,369 Stars
1 shared tag(s) · 2 shared category(s) · Same language
Standardize Java/JVM builds by sharing dependencies, plugins, and lifecycle rules in a POM
Java - Grype12,979 Stars
1 shared tag(s) · 2 shared category(s)
scan container images, filesystems, and SBOMs against vulnerability data and prioritize findings with EPSS, KEV, and VEX
Go - Syft9,642 Stars
1 shared tag(s) · 2 shared category(s)
generate SBOMs from container images, filesystems, and archives in CycloneDX, SPDX, and other formats
Go - GitHub Actions Runner6,311 Stars
1 shared tag(s) · 2 shared category(s)
run GitHub Actions jobs on self-hosted machines with control over operating system, hardware, and network access
C# - Allure Report5,549 Stars
1 shared tag(s) · 2 shared category(s)
turn results from multiple languages and test frameworks into unified reports with history, steps, and attachments
HTML - DBeaver51,964 Stars
1 shared tag(s) · 1 shared category(s) · Same language
operate many database systems from one desktop SQL workspace
Java
Report incorrect information
Tell us if any listing information is incorrect or outdated.