
PC-lint Plus
PC-lint Plus is a static analysis tool for C and C++ that detects defects, vulnerabilities, and coding standard violations directly in source code. It runs on developer workstations and in CI pipelines, with no internet connection required and no code leaving your environment.
Built for embedded and safety-critical software development, PC-lint Plus is certified for ISO 26262, IEC 61508, IEC 62304, and EN 50716. It supports MISRA C:2025, MISRA C:2023, MISRA C++:2023, AUTOSAR C++, CERT C, and CWE, giving teams a single tool to address multiple compliance requirements across automotive, medical, industrial, aerospace, and railway domains.
Advantages
Find bugs before they reach hardware
Deep static analysis catches logic errors, suspicious constructs, and root causes with precise location reporting, so developers spend less time debugging on target.
Stay compliant across multiple standards
A single tool covers MISRA C:2025, MISRA C:2023, MISRA C++:2023, AUTOSAR C++, CERT C, and CWE, reducing tool qualification overhead and evidence gathering effort.
Fast analysis at any scale
Parallel execution keeps run times short on large codebases, so static analysis fits into the development cycle rather than slowing it down, whether on a workstation or in an automated pipeline.
Audit every suppression
Diagnostic Accounting tracks all emitted and suppressed messages with tagged justifications, giving you a complete, auditable record for safety case documentation.
Keep code quality visible over time
PC-lint Plus View provides a graphical interface to monitor diagnostic trends, track regressions, and share findings with review teams, without custom scripting.
Expert Support and Documentation
Vector's dedicated technical support team is on hand to help with configuration, compiler integration, and standard-specific questions.
Where PC-lint Plus is Used
PC-lint Plus is used across a wide range of C and C++ development contexts, from safety-critical systems with formal compliance requirements to commercial software teams focused on code quality and maintainability. Typical application areas include:
Automotive
Automotive ECU software developed under ISO 26262, with MISRA C/C++ enforcement and ASIL D tool qualification
Aerospace & Defense
Aerospace and defense embedded software requiring CERT C compliance and CWE vulnerability screening
Medical
Medical device firmware subject to IEC 62304, where suppression traceability supports design history files and audits
Industrial
Industrial control systems under IEC 61508, including SIL 3 and SIL 4 applications
Railway
Railway embedded software developed under EN 50716, where static analysis supports software integrity level requirements and coding standard compliance.
General C and C++ Development
General C and C++ development teams using PC-lint Plus to enforce consistent coding standards, reduce bug rates, and keep codebases maintainable over time, independent of any regulatory requirement
Key Features
Catch Bugs and Issues Early
PC-lint Plus analysis runs in seconds on a developer workstation. PC-lint Plus analyzes C and C++ source files without executing code, so defects surface at edit time, well before they reach integration, target hardware, or a safety review. The earlier an issue is found, the cheaper it is to fix.
- Detects logic errors, null pointer dereferences, out-of-bounds access, uninitialized variables, and hundreds of other defect classes across C and C++ source
- Each diagnostic includes the precise source location, a clear description, and a value trace showing how the problem originated, so developers act on results without guesswork
- Parallel execution keeps analysis time practical on large codebases, whether running on a workstation or in a CI pipeline
- All analysis runs locally with no internet connection required and no code leaving your environment
Custom Checks: Metrics and Queries
PC-lint Plus ships with over 100 built-in code metrics and a query engine that lets teams define their own checks. You can enforce project-specific coding rules and track quality thresholds that go beyond any predefined standard, with no external scripts or post-processing tools required.
- Over 100 built-in metrics covering cyclomatic complexity, coupling, maintainability index, and design quality, each with configurable pass/fail thresholds
- Custom Queries let teams define diagnostic messages and checks tailored to their own coding standards, architecture rules, or safety requirements
- Results from metrics and custom queries both feed into Diagnostic Accounting, so findings from built-in rules and team-defined checks alike are tracked and auditable
Compliance and Standards Support
- MISRA C:2023 and MISRA C:2025: diagnostic coverage mapped directly to guideline rules - full rule mapping is documented in the online manual
- MISRA C++:2023: over 90% guideline coverage in the 2025 SP1 release
- AUTOSAR C++: full enforcement support
- CERT C and CWE: certified detection of common vulnerability patterns
- ISO 26262 (ASIL D), IEC 61508 (SIL 4), IEC 62304: tool qualification certificates available
Diagnostic Accounting & Suppression Traceability
- Every emitted and suppressed diagnostic is recorded with full context
- Tagged suppressions link deviations to documented coding guideline justifications
- Unused suppression rules are flagged automatically, keeping configurations clean
- Output feeds directly into compliance documentation and audit records
PC-lint Plus View
- Graphical interface for exploring and filtering diagnostic results by severity, rule, file, or message type
- Version-based trend tracking shows regressions and improvements over time
- Results include rule IDs, coding standard references, and full source context
- Export in SARIF format for integration with supported IDEs and CI systems
- Available as an online demo or self-hosted via Docker
Language and Compiler Support
- Supports C11, C17, C23, C++03, C++11, C++14, C++17, C++20, and C++23
- Compatible compilers include GCC, Clang, MSVC, IAR, Green Hills, TI, and Microchip
- Runs natively on Windows, Linux, and macOS
IDE and Pipeline Integration
- IDE integrations for Visual Studio, Eclipse, CLion, Sublime Text, and Code Composer Studio
- Parallel execution scales analysis across large codebases
- SARIF export enables integration with CI platforms and supported IDEs
- Team Enterprise License covers developer workstations, build servers, multi-user systems, and virtualized or cloud environments under a single license
Call Graph Export
- Generate project-level function call graphs in DOT Language format, readable by Graphviz and compatible tools
- Useful for architecture reviews, test coverage planning, and impact analysis
Safety and Security Certifications
PC-lint Plus holds independent tool qualification certificates for the following standards:
| Certification | Scope |
| ISO 26262:2018 (ASIL D) | Automotive functional safety, highest integrity level |
| IEC 61508:2010 (SIL 4) | Functional safety for E/E/PE safety-related systems |
| IEC 62304 | Software lifecycle processes for medical device software |
| EN 50716 | Railway software development for safety-related systems, supporting Software Integrity Levels SIL 0 to SIL 4 |
| CWE Compatible | Certified for detection of Common Weakness Enumeration vulnerabilities |
Licensing
PC-lint Plus is licensed as a Team Enterprise License on an annual subscription. A single license covers developer workstations, build servers, and virtualized or cloud environments. Pricing scales with your team size.
Try PC-lint Plus
14-Day Evaluation License
Contact us for full-featured trial with access to technical support.
PC-lint Plus Downloads
Latest releases and documentation available at the Vector Download Center.
Online Demo
Run PC-lint Plus in your browser with a real-time code example.
Online Manual
Setup guidance, usage examples, and advanced configuration.
Support
Frequently Asked Questions


Related Pages


VectorCAST


Squore

