CodeScene

Behavioural code analysis platform scoring Code Health, hotspots, knowledge distribution and delivery risk from version-control history.

Contact for pricingLast verified 2026-08-19

Deployment

Cloud · Self-Hosted · Air-Gapped

Languages

28+

Pricing model

Per contributing developer, Quote-based / Enterprise

Free tier

Partial

Workflow coverage

Where in the development lifecycle CodeScene operates.

Real-Time IDE FeedbackYesStandard

CodeHealth Monitor flags God Functions, complex methods, low cohesion, Bumpy Road live in the editor

AI Agent Guardrail (MCP)Yes

CodeHealth MCP server runs locally, model-agnostic, exposes code_health_review plus pre/post-commit checks

Local CLI / Pre-CommitYesStandard

CLI runs local analysis, goal supervision and batch analysis with script-friendly output

PR Inline ReviewYesStandard

Automated review of new and modified code with virtual code review, delta analysis, exact contributing lines

Merge Gate BlockingYesStandard

Custom quality gates plus goal-violation and code-health-decline detection via GitHub Checks API and CI

Full Repo ScanYesStandard

Whole-repository hotspot, code health and architectural analysis, with X-Ray function-level drill-down

Scheduled / Continuous RescanYesStandard

Dashboard analyses run on a schedule; the CLI supports batch analysis of repositories.

Runtime / Production MonitoringNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Analysis & detection

Every detection and code-analysis capability tracked for CodeScene.

SASTNo
Taint / Data-Flow AnalysisNo
Secrets DetectionNo
Secrets ValidationNo
SCA (Dependencies)No
Reachability AnalysisNo
Malicious Package DetectionNo
License ComplianceNo
SBOM GenerationNo
IaC ScanningNo
Container ScanningNo
Cloud Posture (CSPM)No
DAST / API ScanningNo
Code Smells & MaintainabilityYesStandard

20+ code health issues: God Class/Function, Bumpy Road, low cohesion, deep nesting, excess conditionals, feature entanglement

Complexity MetricsYesStandard

Code Health combines 25+ factors including nesting depth; cyclomatic complexity weighted low for poor predictive value

Duplication DetectionNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Dead / Unused CodeNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Test Coverage TrackingYesPro

Code coverage measurement alongside Code Health, added as a 2025-2026 platform improvement

Diff / New-Code CoverageNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Architecture GovernanceYesStandard

Auto-generated architectural definitions, subsystem health, cross-service coupling, distributed-monolith detection

Technical Debt QuantificationYesStandard (advanced cost metrics require Pro)

Debt prioritized by cost: per-hotspot maintenance cost trends, unplanned-work correlation, refactoring ROI in velocity and defect terms

Behavioral Delivery AnalyticsYesStandard (team and delivery insights require Pro)

Hotspots, change coupling, knowledge distribution, Conway's Law, bus-factor simulation, branch lead time, ML delivery-risk prediction

AI Logic Bug DetectionNo
PR Summaries & WalkthroughsPartialStandard

Virtual code review breaks down Code Health issues and improvements per PR; no AI narrative summary of the change

Custom Rule AuthoringPartialFree (open source) / standard

Customizable Code Health rules, custom quality gates and thresholds; no rule-authoring language or custom checks documented

Autofix SuggestionsYes

CodeScene ACE proposes AI refactorings in the IDE, validated by a secondary fact-checking AI

Autofix via Agentic PRsYes

PR Refactoring Agent runs in CI and commits Code Health fixes back to GitHub and GitLab PRs

AI Triage / False-Positive FilteringPartialStandard

Prioritizes by organizational impact to avoid treating all issues equally; ML ranks review risk. Not false-positive filtering

Monorepo SupportPartialStandard

Architectural definitions give subsystem, component and service-level analysis; monorepos never named explicitly

AI capabilities

AI Review EngineYesStandard

AI-powered PR analysis plus CodeScene ACE refactoring with deterministic Code Health fact-checking

BYO Model / BYOKYes

User controls LLM provider and model for the PR Refactoring Agent; CodeHealth MCP is model-agnostic

MCP ServerYes

CodeHealth MCP server executes locally on-machine, exposes code_health_review and a review-plan-refactor-remeasure loop

AI Usage GovernanceYesStandard

Quality Gates for AI Code govern AI-generated changes in real time across repositories.

Chat With ReviewerNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Learns From FeedbackPartialPro

Delivery-risk ML self-adjusts thresholds as developers gain experience; no learning from review feedback

Code Excluded From TrainingYesStandard

Vendor states source code is never used to train or enhance the AI

Compliance & governance

Audit LogsYesEnterprise

Audit trail with full logging for compliance; audit and logging listed as a recent enterprise improvement

SSO / SAMLYesEnterprise

SSO on enterprise plans, plus LDAP and OAuth2; SAML is not named specifically

Role-Based Access ControlYesEnterprise

Role-based access control with fine-grained permission management, listed as an Enterprise inclusion

Compliance Reporting ExportsYesStandard

PDF reports for technical debt, code health trends, key-personnel risk, knowledge distribution, goal violations

Certifications

ISO 27001GDPR

Integrations

GitHubYes
GitHub Enterprise ServerYes
GitLabYes
GitLab Self-ManagedYes
BitbucketYes
Bitbucket Data CenterYes
Azure DevOpsYes
REST APIYes
CLIYes
WebhooksPartial

CI/CD systems

JenkinsGitHub ActionsGitLab CI/CDAzure PipelinesBitbucket PipelinesCustom CI/CD scripts via REST API and CLI

IDEs

Visual Studio CodeJetBrains IDEs (IntelliJ, WebStorm, PyCharm)Visual Studio

Issue trackers

Jira (cloud and on-premise)Azure DevOps work itemsTrelloGitHub IssuesClickUp

Chat & notifications

Slack

Pricing & plans

$19/active author/month billed yearly ($21/active author/month if billed monthly)

Minimum seats: 1

Trial: Free trial for commercial projects, limited-time; the deployment section states the trial requires a credit card

Open Source Community EditionFreeMaintainers of publicly available repositories
  • Pull request integration and automated code review
  • Hotspot management
  • Code health measurement
  • Knowledge distribution visualization
  • Virtual code review and PDF reports
  • Customizable Code Health rules
  • Repository must be publicly available
  • No private repositories
StandardEUR 18/active author/month billed yearly (EUR 20 monthly)Teams wanting code health and technical-debt management on private repos
  • Unlimited private repositories and unlimited analyses
  • CodeHealth analysis and technical debt management
  • Hotspot and architectural analysis
  • Knowledge distribution and team dynamics visualization
  • PR integration, virtual code review, quality gates for AI coding
  • IDE extensions, CLI, REST API, PDF reports
  • No software portfolio overview or team insights dashboard
  • No delivery insights (branch analysis, lead times)
  • No code coverage measurement
  • No advanced cost metrics or planned vs. unplanned work tracking
  • No SSO, RBAC or on-premise support
ProEUR 27/active author/month billed yearly (EUR 30 monthly)Multi-project engineering organizations tracking delivery as well as code
  • Everything in Standard
  • Software Portfolio overview across projects
  • Team insights dashboard
  • Delivery insights: branch analysis and lead times
  • Code coverage measurement
  • Advanced cost metrics and planned vs. unplanned work tracking
  • No SSO, RBAC, custom integrations or on-premise support
  • No dedicated infrastructure or success manager
EnterpriseCustom (contact sales); typically large annual contractsLarge or regulated organizations with data-residency and access-control requirements
  • Everything in Pro
  • Single Sign-On and role-based access control
  • On-premise deployment support and dedicated infrastructure option
  • Custom integrations and priority support
  • Dedicated workshops, onboarding and success manager
  • Compliance and audit support
  • Quote-only pricing
  • Typically large annual commitment

Who it's for

Notable strengths

  • Behavioural analytics no code-only scanner offers: hotspots weighted by change frequency, change coupling, knowledge distribution, Conway's Law alignment, bus-factor simulation
  • Technical debt quantified in business terms: per-hotspot maintenance cost trends, planned vs. unplanned work, refactoring ROI, three-metric Code Health profile that avoids averaging away risk
  • X-Ray drills hotspots down to function level to give a concrete refactoring starting point in very large files
  • CodeHealth MCP server runs locally and model-agnostically, giving AI agents an objective maintainability target plus pre/post-commit checks
  • PR Refactoring Agent runs in CI and commits Code Health fixes back to GitHub and GitLab PRs with the customer's own LLM
  • Published per-active-author pricing with unlimited repos and analyses, plus free open-source edition and Docker/JAR on-premise option

Notable limitations

  • No security scanning of any kind — SAST, SCA, secrets, IaC, container and cloud posture are absent from the entire 15,000-word source
  • Requires substantial Git history to be accurate, and onboarding complexity is listed as a risk in CodeScene's own documentation
  • Code Health quality varies by language because the metric must be implemented per language
  • Delivery insights, team insights, code coverage and advanced cost metrics are gated to the Pro plan; SSO, RBAC, on-premise and audit support to Enterprise
  • Duplication detection is never mentioned, an unusual omission for a maintainability platform
  • AI features (ACE, MCP server, PR Refactoring Agent) are described as new and maturing; Azure DevOps refactoring agent is not yet available

Similar tools

Other Quality Platform tools in the directory.

FAQ

When should you choose CodeScene?

CodeScene best fits Startups, Mid-market teams, Enterprise, Regulated industries. Behavioural analytics no code-only scanner offers: hotspots weighted by change frequency, change coupling, knowledge distribution, Conway's Law alignment, bus-factor simulation

What languages does CodeScene support?

CodeScene supports 28+ languages and frameworks, including Java, C#, C++, Python, JavaScript, Go, Rust, Kotlin, TypeScript, Scala, and 18 more.

What does CodeScene integrate with?

CodeScene integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center, Azure DevOps for source control, CI systems including Jenkins, GitHub Actions, GitLab CI/CD, Azure Pipelines, Bitbucket Pipelines, and 1 more, and IDEs including Visual Studio Code, JetBrains IDEs (IntelliJ, WebStorm, PyCharm), Visual Studio.

What tools are similar to CodeScene?

Similar Quality Platform tools tracked here include Codacy, DeepSource, Qlty, SonarQube.

What are CodeScene's plans and pricing?

CodeScene has paid plans available by contacting the vendor; enterprise pricing is quote-only.