Quality Platform
Codacy
Code quality and security platform aggregating third-party analyzers across 40+ languages, with SAST, SCA, secrets, coverage and a free IDE extension.
Deployment
Cloud
Languages
50+
Pricing model
Per developer seat, Quote-based / Enterprise
Free tier
Yes
Workflow coverage
Where in the development lifecycle Codacy operates.
Guardrails extension for VS Code, Cursor, Windsurf, JetBrains; scans offline, syncs org config.
MCP integration scans AI-generated code for Copilot, Cursor, Windsurf, Claude; AI can auto-remediate.
Codacy Analysis CLI runs static analysis fully locally, no API round-trip; pre-commit hook not confirmed.
Inline PR comments and status checks on GitHub, GitLab merge requests, Bitbucket PRs.
Merge gates enforce quality, coverage and security thresholds via branch protection.
Unlimited cloud scans with no pipeline integration required; full scan within minutes of signup.
Daily proactive SCA and malicious-package re-scans without new commits; Business plan only.
DAST scans deployed web apps and APIs on a schedule; Business plan only.
Analysis & detection
Every detection and code-analysis capability tracked for Codacy.
Bandit, Checkov, Clang-Tidy, Gosec, Opengrep, SpotBugs across 20+ security categories.
Not offered in vendor documentation reviewed as of 2026-09-05.
Opengrep and Trivy detect 50+ secret patterns in code, IaC and config files.
Not offered in vendor documentation reviewed as of 2026-09-05.
Trivy scans 12+ package ecosystems with dependency-chain visualization and CVE/GHSA/CVSS metadata.
Affected-functions analysis AI-checks whether vulnerable dependency code is actually used.
Cross-references OpenSSF database for typosquatting and supply-chain compromise; daily rescans Business only.
SPDX identification with allowlists, blocklists, category policies and license inventory reporting.
SBOM exports available as a compliance feature; Business plan only.
Checkov, Hadolint, Spectral cover Terraform, CloudFormation, Kubernetes, Dockerfile, Helm, GitHub Actions, Ansible.
Container image scanning included; Business plan only, scanner and scope not named.
Not offered in vendor documentation reviewed as of 2026-09-05.
OWASP ZAP integration scans web apps, OpenAPI, GraphQL, REST APIs; Business plan only.
Ten issue categories including code style, comprehensibility, documentation, best practice, unused code.
Cyclomatic complexity via Lizard and detekt; feeds the repository A-F grade.
PMD CPD, jscpd, PHPCPD and Flay with cloning reports; feeds the grade.
Dedicated unused-code issue category; deadcode and aligncheck analyzers.
Coverage Reporter CLI ingests Cobertura, JaCoCo, lcov, Clover, Istanbul and 8 more formats.
Diff coverage of newly added or modified lines on PRs, commits and dashboard.
Not offered in vendor documentation reviewed as of 2026-09-05.
Grade A-F and issues-per-kLoC trending only; no remediation-time or cost debt model described.
Not offered in vendor documentation reviewed as of 2026-09-05.
AI Reviewer adds Gemini contextual review; logic-error claims appear only in the flagged Verity section.
AI-generated issue summaries and remediation suggestions on PRs; no change-by-change walkthrough described.
Custom scan rules, patterns and org-wide coding standards via UI or .codacy.yml.
One-click and batch fixes for ESLint, Opengrep, markdownlint; free IDE autofix for four languages.
MCP lets AI assistants auto-remediate flagged code; no autofix pull-request creation described.
AI scores false-positive likelihood with reasoning; opt-in, enabled via support request.
Not supported. Direct confirmation from Codacy that monorepos are not supported.
AI capabilities
AI Reviewer (GitHub) combines static analysis with Gemini contextual review using PR, Jira, history context.
Not offered in vendor documentation reviewed as of 2026-09-05.
MCP integration for Copilot, Cursor, Windsurf, Claude Code and Claude.ai; included free.
AI Inventory, AI Risk Hub and org-wide AI Coding Policies govern AI-generated code; Business plan.
Codacy findings surfaced in the IDE AI chat panel for context-aware discussion; Team and Business.
Not offered in vendor documentation reviewed as of 2026-09-05.
AI Reviewer uses enterprise Gemini instances; code not used for training, secrets redacted, prompts not stored.
Models used
Compliance & governance
Org-wide event audit logs with CSV/JSON/API export and 90+ day retention; Business plan only.
SAML 2.0 with Okta, Azure AD, Google Workspace and JIT provisioning; Business plan only.
Owner, Admin, Manager, Developer, Read-only roles; 'advanced RBAC' listed as Business.
Compliance-ready SBOM and audit-trail exports on Business; CSV/JSON finding exports available on Team.
Certifications
Standards mapping
Integrations
CI/CD systems
IDEs
Issue trackers
Chat & notifications
Pricing & plans
$18/dev/month billed annually ($216/dev/year) ($21/dev/month if billed monthly)
Minimum seats: None — no minimum seats; Team plan capped at 30 developers (Business required above that)
Trial: 14 days, no credit card required, full access to Team plan features (extended trial offered on Business)
- Guardrails IDE extension, unlimited, with real-time SAST, secrets, dependency, complexity and duplication scanning
- Works offline with periodic org config sync
- Auto-fix on demand for JavaScript, TypeScript, Python, Java
- MCP integration with Copilot, Cursor and Claude
- Free forever for open-source projects
- IDE-only: no cloud platform access
- No PR analysis, merge gates, dashboards or API/CLI
- Language coverage for this IDE-only plan is not separately documented and may be narrower than the platform's
- Full cloud platform with unlimited pipeline-less scans, 54 tools and 12,000+ scan rules
- SAST, secrets, IaC, SCA of new code, malicious package detection, license scanning
- AI Reviewer (GitHub), AI PR comments (GitLab/Bitbucket), smart false-positive triage
- Merge gates for quality, coverage and security; test coverage tracking
- GitHub/GitLab/Bitbucket, 2-way Jira, Slack; REST API v2/v3 and CLI
- Org-wide Security & Risk Management Dashboard and shared coding standards
- Maximum 30 developers (Business plan required above that)
- Up to 100 private repos (unlimited LOC); unlimited public repos
- No DAST, container scanning, audit logs, SSO/SAML, SBOM export or data residency
- Standard email and in-app chat support only
- DAST (web, API, GraphQL), container image scanning, penetration testing integration
- Daily proactive SCA and malicious-package re-scans
- Audit logs, SBOM exports, GitHub Enterprise Cloud data residency (EU/US)
- AI Inventory, AI Risk Hub and org-wide AI Coding Policies
- SSO/SAML 2.0, advanced RBAC, static IP allowlisting, session management
- Dedicated CSM and Solutions Engineer, priority screen-share support, AI-generated custom reports
- Quote-only, no published price
- Custom Business agreements may carry longer-term contracts
- Everything in this tier is unavailable on Team, including SSO/SAML and audit logs
Who it's for
Team plan positioned for teams up to 30 developers; Business plan for enterprise scale of 100+ developers
Notable strengths
- Aggregates a broad set of third-party analyzers (54 claimed by the vendor) across 40+ languages, so quality, security, IaC, duplication and complexity come from one configuration surface
- Free, unlimited Guardrails IDE extension works offline across VS Code, Cursor, Windsurf and 12 JetBrains IDEs, with MCP guardrails for AI agents included at no cost
- Pipeline-less cloud scanning: analysis needs no CI integration, and pricing is flat per developer with no scan, finding or LOC quotas
- Coverage is first-class: Coverage Reporter handles 13+ report formats, plus diff coverage, coverage goals, badges and enforceable coverage gates
- Multi-region SaaS (EU/US) on AWS and Google Cloud with a 99.9% uptime SLA and automatic updates
- Local analysis without a cloud round-trip: the Codacy Analysis CLI runs static analysis on the developer's machine, alongside the offline-capable Guardrails IDE extension
Notable limitations
- Cloud-only for new customers: self-hosted and air-gapped deployment are deprecated and closed to new onboarding, which disqualifies Codacy outright for buyers with a must-self-host or air-gap requirement
- The free tier is IDE-only; every cloud capability (PR analysis, merge gates, dashboards, API, CLI) starts at the $18/dev/month Team plan, which is capped at 30 developers (Business required above that)
- SSO/SAML, audit logs, SBOM export, DAST, container scanning, data residency and AI governance are all Business-plan-only, and Business is quote-only
- Azure DevOps is supported as a CI system (Azure Pipelines) but is absent from the Git provider list, unlike GitHub, GitLab and Bitbucket
- No taint/data-flow analysis, architecture governance, monorepo handling, or secret validation is described anywhere in Codacy's documentation
- Language counts conflict across the document (38 vs 44 vs 49) and auto-fix reaches only four languages, so headline breadth overstates depth
Similar tools
Other Quality Platform tools in the directory.
FAQ
When should you choose Codacy?
Codacy best fits Indie developers, Startups, Mid-market teams, Enterprise, Regulated industries, Team plan positioned for teams up to 30 developers; Business plan for enterprise scale of 100+ developers. Aggregates a broad set of third-party analyzers (54 claimed by the vendor) across 40+ languages, so quality, security, IaC, duplication and complexity come from one configuration surface
What languages does Codacy support?
Codacy supports 50+ languages and frameworks, including Apex, AsyncAPI, AWS CloudFormation, Azure Resource Manager Templates, C, C++, C#, CoffeeScript, Crystal, CSS, and 40 more.
What does Codacy integrate with?
Codacy integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center for source control, CI systems including GitHub Actions, GitLab CI/CD, CircleCI, Jenkins, Azure Pipelines, and 11 more, and IDEs including Visual Studio Code, Cursor, Windsurf, IntelliJ IDEA, PyCharm, and 12 more.
What tools are similar to Codacy?
Similar Quality Platform tools tracked here include CodeScene, DeepSource, Qlty, SonarQube.
What are Codacy's plans and pricing?
Codacy offers a free tier, with paid plans starting around $18/dev/mo; enterprise pricing is quote-only.
Opens www.codacy.com in a new tab. Review Radar is affiliated with Codacy.