Static Code Analysis with latest SonarQube, vulnerabilities and code quality remediation recommendations would be provided in generated reports, preliminary false-posites analysis and estimates will be presented in free 30-min consultation.
Sample SonarQube report of the WebGoat project (Training Web application with 12K lines codebase) you can find at https://github.com/WebGoat/WebGoat/issues/1847#issuecomment-2278770550
also there demo video of working SonarQube analysis - fixed SQLInjection by following provided in report remediation recommendations:
https://www.youtube.com/watch?v=yBeJr38DAFE