Codacy

Code quality and security platform aggregating third-party analyzers across 40+ languages, with SAST, SCA, secrets, coverage and a free IDE extension.

$18/dev/moLast verified 2026-09-06

Deployment

Cloud

Languages

50+

Pricing model

Per developer seat, Quote-based / Enterprise

Free tier

Yes

Workflow coverage

Where in the development lifecycle Codacy operates.

Real-Time IDE FeedbackYes

Guardrails extension for VS Code, Cursor, Windsurf, JetBrains; scans offline, syncs org config.

AI Agent Guardrail (MCP)Yes

MCP integration scans AI-generated code for Copilot, Cursor, Windsurf, Claude; AI can auto-remediate.

Local CLI / Pre-CommitYes

Codacy Analysis CLI runs static analysis fully locally, no API round-trip; pre-commit hook not confirmed.

PR Inline ReviewYesTeam

Inline PR comments and status checks on GitHub, GitLab merge requests, Bitbucket PRs.

Merge Gate BlockingYesTeam

Merge gates enforce quality, coverage and security thresholds via branch protection.

Full Repo ScanYesTeam

Unlimited cloud scans with no pipeline integration required; full scan within minutes of signup.

Scheduled / Continuous RescanYesBusiness

Daily proactive SCA and malicious-package re-scans without new commits; Business plan only.

Runtime / Production MonitoringYesBusiness

DAST scans deployed web apps and APIs on a schedule; Business plan only.

Analysis & detection

Every detection and code-analysis capability tracked for Codacy.

SASTYesTeam

Bandit, Checkov, Clang-Tidy, Gosec, Opengrep, SpotBugs across 20+ security categories.

Taint / Data-Flow AnalysisNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Secrets DetectionYesTeam

Opengrep and Trivy detect 50+ secret patterns in code, IaC and config files.

Secrets ValidationNo

Not offered in vendor documentation reviewed as of 2026-09-05.

SCA (Dependencies)YesTeam

Trivy scans 12+ package ecosystems with dependency-chain visualization and CVE/GHSA/CVSS metadata.

Reachability AnalysisYesTeam

Affected-functions analysis AI-checks whether vulnerable dependency code is actually used.

Malicious Package DetectionYesTeam

Cross-references OpenSSF database for typosquatting and supply-chain compromise; daily rescans Business only.

License ComplianceYesTeam

SPDX identification with allowlists, blocklists, category policies and license inventory reporting.

SBOM GenerationYesBusiness

SBOM exports available as a compliance feature; Business plan only.

IaC ScanningYesTeam

Checkov, Hadolint, Spectral cover Terraform, CloudFormation, Kubernetes, Dockerfile, Helm, GitHub Actions, Ansible.

Container ScanningYesBusiness

Container image scanning included; Business plan only, scanner and scope not named.

Cloud Posture (CSPM)No

Not offered in vendor documentation reviewed as of 2026-09-05.

DAST / API ScanningYesBusiness

OWASP ZAP integration scans web apps, OpenAPI, GraphQL, REST APIs; Business plan only.

Code Smells & MaintainabilityYesTeam

Ten issue categories including code style, comprehensibility, documentation, best practice, unused code.

Complexity MetricsYesTeam

Cyclomatic complexity via Lizard and detekt; feeds the repository A-F grade.

Duplication DetectionYesTeam

PMD CPD, jscpd, PHPCPD and Flay with cloning reports; feeds the grade.

Dead / Unused CodeYesTeam

Dedicated unused-code issue category; deadcode and aligncheck analyzers.

Test Coverage TrackingYesTeam

Coverage Reporter CLI ingests Cobertura, JaCoCo, lcov, Clover, Istanbul and 8 more formats.

Diff / New-Code CoverageYesTeam

Diff coverage of newly added or modified lines on PRs, commits and dashboard.

Architecture GovernanceNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Technical Debt QuantificationPartialTeam

Grade A-F and issues-per-kLoC trending only; no remediation-time or cost debt model described.

Behavioral Delivery AnalyticsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

AI Logic Bug DetectionPartialTeam

AI Reviewer adds Gemini contextual review; logic-error claims appear only in the flagged Verity section.

PR Summaries & WalkthroughsPartialTeam

AI-generated issue summaries and remediation suggestions on PRs; no change-by-change walkthrough described.

Custom Rule AuthoringYesTeam

Custom scan rules, patterns and org-wide coding standards via UI or .codacy.yml.

Autofix SuggestionsYes

One-click and batch fixes for ESLint, Opengrep, markdownlint; free IDE autofix for four languages.

Autofix via Agentic PRsPartial

MCP lets AI assistants auto-remediate flagged code; no autofix pull-request creation described.

AI Triage / False-Positive FilteringYesTeam

AI scores false-positive likelihood with reasoning; opt-in, enabled via support request.

Monorepo SupportNo

Not supported. Direct confirmation from Codacy that monorepos are not supported.

AI capabilities

AI Review EngineYesTeam

AI Reviewer (GitHub) combines static analysis with Gemini contextual review using PR, Jira, history context.

BYO Model / BYOKNo

Not offered in vendor documentation reviewed as of 2026-09-05.

MCP ServerYes

MCP integration for Copilot, Cursor, Windsurf, Claude Code and Claude.ai; included free.

AI Usage GovernanceYesBusiness

AI Inventory, AI Risk Hub and org-wide AI Coding Policies govern AI-generated code; Business plan.

Chat With ReviewerYesTeam

Codacy findings surfaced in the IDE AI chat panel for context-aware discussion; Team and Business.

Learns From FeedbackNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Code Excluded From TrainingYesTeam

AI Reviewer uses enterprise Gemini instances; code not used for training, secrets redacted, prompts not stored.

Models used

OpenAI GPT (AI-enhanced PR comments on GitLab/Bitbucket)Google Gemini (AI Reviewer for GitHub, enterprise-grade instances)

Compliance & governance

Audit LogsYesBusiness

Org-wide event audit logs with CSV/JSON/API export and 90+ day retention; Business plan only.

SSO / SAMLYesBusiness

SAML 2.0 with Okta, Azure AD, Google Workspace and JIT provisioning; Business plan only.

Role-Based Access ControlYesTeam

Owner, Admin, Manager, Developer, Read-only roles; 'advanced RBAC' listed as Business.

Compliance Reporting ExportsYesBusiness

Compliance-ready SBOM and audit-trail exports on Business; CSV/JSON finding exports available on Team.

Certifications

SOC 2 Type 2GDPRCCPAISO 27001 (claimed only in the marketing differentiators list, not in the compliance sections)

Standards mapping

OWASP Top 10 (DAST scan profile)SPDX License ListCVE/GHSA identifiers with CVSS scores

Integrations

GitHubYes
GitHub Enterprise ServerYes
GitLabYes
GitLab Self-ManagedYes
BitbucketYes
Bitbucket Data CenterYes
Azure DevOpsNo
REST APIYes
CLIYes
WebhooksYes

CI/CD systems

GitHub ActionsGitLab CI/CDCircleCIJenkinsAzure PipelinesTravis CIBitbucket PipelinesDrone CIGoCDBambooTeamCityAppVeyorCirrus CIBuildkiteany HTTP/webhook-compatible systemcustom pipelines via REST API

IDEs

Visual Studio CodeCursorWindsurfIntelliJ IDEAPyCharmWebStormGoLandCLionRiderRubyMineDataGripPhpStormAppCodeAndroid StudioVim/Neovim (plugin)Emacs (plugin)GitHub Codespaces

Issue trackers

Jira CloudJira Server (8.0+)

Chat & notifications

Slack (public, private channels and DMs; immediate, daily or weekly digest)Mattermost (webhooks)Email (daily/weekly digests, critical alerts)Generic webhooks

Pricing & plans

$18/dev/month billed annually ($216/dev/year) ($21/dev/month if billed monthly)

Minimum seats: None — no minimum seats; Team plan capped at 30 developers (Business required above that)

Trial: 14 days, no credit card required, full access to Team plan features (extended trial offered on Business)

Developer$0 (free forever)Individual developers, open-source maintainers, students, hobby projects
  • Guardrails IDE extension, unlimited, with real-time SAST, secrets, dependency, complexity and duplication scanning
  • Works offline with periodic org config sync
  • Auto-fix on demand for JavaScript, TypeScript, Python, Java
  • MCP integration with Copilot, Cursor and Claude
  • Free forever for open-source projects
  • IDE-only: no cloud platform access
  • No PR analysis, merge gates, dashboards or API/CLI
  • Language coverage for this IDE-only plan is not separately documented and may be narrower than the platform's
Team$18/dev/month annual ($216/dev/year) or $21/dev/month monthlyModern teams up to 30 developers; growing teams, startups, mid-size companies
  • Full cloud platform with unlimited pipeline-less scans, 54 tools and 12,000+ scan rules
  • SAST, secrets, IaC, SCA of new code, malicious package detection, license scanning
  • AI Reviewer (GitHub), AI PR comments (GitLab/Bitbucket), smart false-positive triage
  • Merge gates for quality, coverage and security; test coverage tracking
  • GitHub/GitLab/Bitbucket, 2-way Jira, Slack; REST API v2/v3 and CLI
  • Org-wide Security & Risk Management Dashboard and shared coding standards
  • Maximum 30 developers (Business plan required above that)
  • Up to 100 private repos (unlimited LOC); unlimited public repos
  • No DAST, container scanning, audit logs, SSO/SAML, SBOM export or data residency
  • Standard email and in-app chat support only
BusinessCustom pricing (contact sales)Large enterprises and regulated industries (FinTech, HealthTech, Defense) with 100+ developers
  • DAST (web, API, GraphQL), container image scanning, penetration testing integration
  • Daily proactive SCA and malicious-package re-scans
  • Audit logs, SBOM exports, GitHub Enterprise Cloud data residency (EU/US)
  • AI Inventory, AI Risk Hub and org-wide AI Coding Policies
  • SSO/SAML 2.0, advanced RBAC, static IP allowlisting, session management
  • Dedicated CSM and Solutions Engineer, priority screen-share support, AI-generated custom reports
  • Quote-only, no published price
  • Custom Business agreements may carry longer-term contracts
  • Everything in this tier is unavailable on Team, including SSO/SAML and audit logs

Who it's for

Team plan positioned for teams up to 30 developers; Business plan for enterprise scale of 100+ developers

Notable strengths

  • Aggregates a broad set of third-party analyzers (54 claimed by the vendor) across 40+ languages, so quality, security, IaC, duplication and complexity come from one configuration surface
  • Free, unlimited Guardrails IDE extension works offline across VS Code, Cursor, Windsurf and 12 JetBrains IDEs, with MCP guardrails for AI agents included at no cost
  • Pipeline-less cloud scanning: analysis needs no CI integration, and pricing is flat per developer with no scan, finding or LOC quotas
  • Coverage is first-class: Coverage Reporter handles 13+ report formats, plus diff coverage, coverage goals, badges and enforceable coverage gates
  • Multi-region SaaS (EU/US) on AWS and Google Cloud with a 99.9% uptime SLA and automatic updates
  • Local analysis without a cloud round-trip: the Codacy Analysis CLI runs static analysis on the developer's machine, alongside the offline-capable Guardrails IDE extension

Notable limitations

  • Cloud-only for new customers: self-hosted and air-gapped deployment are deprecated and closed to new onboarding, which disqualifies Codacy outright for buyers with a must-self-host or air-gap requirement
  • The free tier is IDE-only; every cloud capability (PR analysis, merge gates, dashboards, API, CLI) starts at the $18/dev/month Team plan, which is capped at 30 developers (Business required above that)
  • SSO/SAML, audit logs, SBOM export, DAST, container scanning, data residency and AI governance are all Business-plan-only, and Business is quote-only
  • Azure DevOps is supported as a CI system (Azure Pipelines) but is absent from the Git provider list, unlike GitHub, GitLab and Bitbucket
  • No taint/data-flow analysis, architecture governance, monorepo handling, or secret validation is described anywhere in Codacy's documentation
  • Language counts conflict across the document (38 vs 44 vs 49) and auto-fix reaches only four languages, so headline breadth overstates depth

Similar tools

Other Quality Platform tools in the directory.

FAQ

When should you choose Codacy?

Codacy best fits Indie developers, Startups, Mid-market teams, Enterprise, Regulated industries, Team plan positioned for teams up to 30 developers; Business plan for enterprise scale of 100+ developers. Aggregates a broad set of third-party analyzers (54 claimed by the vendor) across 40+ languages, so quality, security, IaC, duplication and complexity come from one configuration surface

What languages does Codacy support?

Codacy supports 50+ languages and frameworks, including Apex, AsyncAPI, AWS CloudFormation, Azure Resource Manager Templates, C, C++, C#, CoffeeScript, Crystal, CSS, and 40 more.

What does Codacy integrate with?

Codacy integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center for source control, CI systems including GitHub Actions, GitLab CI/CD, CircleCI, Jenkins, Azure Pipelines, and 11 more, and IDEs including Visual Studio Code, Cursor, Windsurf, IntelliJ IDEA, PyCharm, and 12 more.

What tools are similar to Codacy?

Similar Quality Platform tools tracked here include CodeScene, DeepSource, Qlty, SonarQube.

What are Codacy's plans and pricing?

Codacy offers a free tier, with paid plans starting around $18/dev/mo; enterprise pricing is quote-only.