SonarQube

Code quality and security analysis platform for 40+ languages, delivered as SonarQube Cloud SaaS or self-managed SonarQube Server.

Free tier availableLast verified 2026-08-18

Deployment

Cloud · Self-Hosted · Air-Gapped

Languages

41+

Pricing model

Per lines of code, Quote-based / Enterprise

Free tier

Yes

Workflow coverage

Where in the development lifecycle SonarQube operates.

Real-Time IDE FeedbackYes

SonarQube for IDE gives real-time analysis with quick fixes; 25 languages, connected mode.

AI Agent Guardrail (MCP)Yesadd-on

MCP server plus Sonar Vortex context augmentation; Vortex needs Sonar Agent Essentials subscription.

Local CLI / Pre-CommitYes

SonarQube CLI analyses local changes and staged files and runs 'sonar analyze secrets'.

PR Inline ReviewYes

PR decoration in GitHub, GitLab, Bitbucket, Azure DevOps; Free limits PRs to main target branch.

Merge Gate BlockingYes

Quality gates block PRs and branches via status checks; custom gates require Team or Enterprise.

Full Repo ScanYes

Full codebase analysis in CI/CD via SonarScanner CLI, Maven, Gradle, Python, .NET scanners.

Scheduled / Continuous RescanPartial

Automatic Analysis re-runs on repository changes for GitHub and Azure DevOps; no scheduled rescan documented.

Runtime / Production MonitoringNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Analysis & detection

Every detection and code-analysis capability tracked for SonarQube.

SASTYes

Injection, arbitrary file read/write, access control, authentication, and cryptography rules.

Taint / Data-Flow AnalysisYes

Tracks data flow from untrusted sources to dangerous sinks; Advanced SAST sold separately.

Secrets DetectionYes

Hardcoded credentials, API keys, tokens via SonarQube CLI and Cloud staged-file scanning.

Secrets ValidationNo

Not offered in vendor documentation reviewed as of 2026-09-05.

SCA (Dependencies)Yesadd-on

SCA is a separate product subscription, available only to Team and Enterprise plans.

Reachability AnalysisNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Malicious Package DetectionNo

Not offered in vendor documentation reviewed as of 2026-09-05.

License ComplianceYesadd-on

License policy management and enforcement ships inside the separately subscribed SCA product.

SBOM GenerationYesadd-on

SBOM export in standard formats is part of the separately subscribed SCA product.

IaC ScanningYes

Ansible, Azure Resource Manager, CloudFormation, Docker, Kubernetes/Helm, Terraform misconfiguration rules.

Container ScanningPartial

Dockerfile analysis only; no container image or layer scanning documented.

Cloud Posture (CSPM)No

Not offered in vendor documentation reviewed as of 2026-09-05.

DAST / API ScanningNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Code Smells & MaintainabilityYes

5,000+ rules covering maintenance issues, poor practices, and suboptimal patterns.

Complexity MetricsYes

Complexity metrics reported alongside issue density and distribution measures.

Duplication DetectionYes

Duplication detection and tracking reported as a first-class metric.

Dead / Unused CodeNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Test Coverage TrackingYes

Coverage import for C/C++/Objective-C, Dart, .NET, Go, Java, JavaScript/TypeScript, PHP, Python.

Diff / New-Code CoveragePartial

Configurable new-code definition drives gates on new code; coverage-on-new-code not explicitly documented.

Architecture GovernanceYesTeam

Derived vs intended architecture, tangles, oversized components, wrong dependency and location issues.

Technical Debt QuantificationYes

Technical debt calculation plus structural technical debt tracking from architecture analysis.

Behavioral Delivery AnalyticsPartial

Velocity and burndown tracking in metrics; no code-hotspot or behavioural analytics documented.

AI Logic Bug DetectionYesadd-on

Gitar AI pull-request review is a separate Sonar product; bug classes it detects are unspecified.

PR Summaries & WalkthroughsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Custom Rule AuthoringPartialTeam

Custom quality profiles configure language rule sets on Team and Enterprise; authoring new rules not documented.

Autofix SuggestionsYesTeam

AI CodeFix proposes LLM fixes for CRITICAL, HIGH, MEDIUM issues; Cloud Team/Enterprise, Server Enterprise/Data Center.

Autofix via Agentic PRsYesadd-on

Remediation Agent fixes backlog issues on GitHub and Azure DevOps; requires Sonar Agent Essentials.

AI Triage / False-Positive FilteringNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Monorepo SupportYes

Multi-project repository analysis with monorepo branch, PR, and scoped analysis.

AI capabilities

AI Review EngineYesTeam

AI CodeFix is LLM-powered on Team and Enterprise; Gitar AI PR review sold as a separate product.

BYO Model / BYOKYesEnterprise

Azure OpenAI/AWS Bedrock/self-hosted gateway BYOK on Server Enterprise/Data Center only; Cloud has no BYOK option

MCP ServerYes

SonarQube MCP Server for agent context; Vortex MCP integration tied to Sonar Agent Essentials.

AI Usage GovernanceYesEnterprise

Enterprise quality gate and quality profiles specifically govern agentic AI-generated code.

Chat With ReviewerYesadd-on

Gitar (separate Sonar product) takes natural-language PR replies, e.g. 'gitar why was this file changed?'

Learns From FeedbackYesadd-on

Gitar persists dismissed and resolved findings across review iterations, learning from developer replies.

Code Excluded From TrainingYesEnterprise

Third-party LLM providers contractually barred from training on input data across all tiers; SonarSource excludes Enterprise/Server data.

Compliance & governance

Audit LogsYes

Organization activity, change history, and access/permission modification logs.

SSO / SAMLYesEnterprise

Multiple SSO providers and LDAP/Active Directory options, but Enterprise SSO is Enterprise-only.

Role-Based Access ControlYes

Role-based access control and project-level permissions; permission templates need Team or Enterprise.

Compliance Reporting ExportsYesTeam

PDF and interactive project/portfolio security reports, CRA reports, audit evidence export; portfolios are Team+.

Certifications

SOC 2 (stated as 'SOC 2 compliance', type not specified)GDPR

Standards mapping

Cyber Resilience Act (CRA)MISRA (Enterprise quality profiles)

Integrations

GitHubYes
GitHub Enterprise ServerYes
GitLabYes
GitLab Self-ManagedYes
BitbucketYes
Bitbucket Data CenterYes
Azure DevOpsYes
REST APIYes
CLIYes
WebhooksYes

CI/CD systems

GitHub ActionsGitLab CI/CDBitbucket PipelinesCircleCIAmazon CodeCatalystAzure DevOps (Azure DevOps Extension)Any other CI via SonarScanner CLI, SonarScanner for Maven, Gradle, Python, or .NET

IDEs

IntelliJ IDEACLionWebStormPhpStormPyCharmRiderAndroid StudioRubyMineVisual StudioVS CodeEclipse

Issue trackers

JiraServiceNow

Chat & notifications

SlackEmail

Pricing & plans

$24/month for the entry lines-of-code tier (Team plan); price scales with the LOC tier chosen

Minimum seats: none

Trial: 14 days for new Team plan customers

Free (SonarQube Cloud)$0 perpetualSmall teams and open-source projects
  • Basic code analysis
  • Unlimited public project analysis
  • IDE integration
  • Built-in 'Sonar way' quality gate
  • Webhooks
  • 50,000 LOC for private projects
  • Up to 5 organization members
  • Pull request analysis only when the target branch is main
  • No custom quality gates or profiles, no architecture analysis, no AI CodeFix
  • No email or Slack notifications
Team (SonarQube Cloud)$24/month at the entry LOC tier, rising with the chosen tierGrowing teams with advanced analysis needs
  • All Free features plus unlimited pull request analysis
  • Custom quality profiles and custom quality gates
  • Architecture analysis
  • AI CodeFix
  • Portfolio management and advanced management reporting
  • Permission templates, groups, org-wide project configuration, email and Slack notifications
  • LOC ceiling of 1,900,000; exceeding the limit is blocked with an error
  • SCA and Advanced SAST require separate subscriptions
  • Sonar Agent Essentials is annual-subscription only on Team
  • No Enterprise languages, MISRA profiles, Enterprise SSO, IP allow lists, or code encryption
  • Credit-card auto-renewal; suspension on payment failure (data preserved)
Enterprise (SonarQube Cloud)Contact for custom pricingLarge organizations with extensive governance needs; described as ideal from 5M LOC
  • All Team features
  • Enterprise languages: Apex, ABAP, COBOL, JCL, PL/I, RPG
  • MISRA compliance quality profiles
  • Enterprise organization hierarchy with shared or individual LOC allocation
  • Sonar Agent Essentials included
  • GitHub advanced security integration, IP allow lists, Enterprise SSO, code encryption, custom SLA
  • No published price; enterprise sales motion required
  • SCA and Advanced SAST still require separate subscriptions
OSS (SonarQube Cloud)$0Open-source projects
  • Full analysis of public repositories with unlimited LOC
  • Unlimited pull request analysis
  • Advanced analysis features including architecture and custom quality gates/profiles
  • Portfolio management, groups, webhooks
  • GitHub member synchronization
  • No private project analysis
  • No AI CodeFix, Remediation Agent, or Sonar Vortex
  • No permission templates, org-wide configurations, or email/Slack notifications
SonarQube Community Build (self-hosted)$0Teams wanting a free self-managed install
  • Free, open-source version of SonarQube Server
  • Source does not enumerate which analysis features Community Build includes or excludes
SonarQube Server Developer (self-hosted)Not published — contact sales; priced per instance, per year, by lines of codeSmall teams self-hosting; recommended for 100K+ LOC
  • 34 languages & frameworks
  • Autodetect AI-generated code
  • AI Code Assurance
  • Advanced bug detection
  • Secrets detection
  • Architecture management
  • No published price; quote via sales
  • No AI CodeFix, MISRA C++:2023 compliance, or commercial support tiers (Enterprise+ only)
  • No high-availability or distributed architecture (Data Center only)
SonarQube Server Enterprise (self-hosted)Not published — contact sales; priced per instance, per year, by lines of codeLarger self-hosted teams; recommended for 1M+ LOC
  • Developer edition, plus:
  • 40 total languages & frameworks (incl. Apex, ABAP, COBOL, JCL, PL/I, RPG)
  • AI CodeFix
  • MISRA C++:2023 compliance
  • Commercial support, and 24/7 white-glove support available
  • Detailed project health insights
  • No published price; quote via sales
  • No autoscaling or distributed high-availability architecture (Data Center only)
SonarQube Server Data Center (self-hosted)Not published — contact sales; priced per instance, per year, by lines of codeLarge enterprises needing self-managed high availability; recommended for 20M+ LOC
  • Enterprise edition, plus:
  • Autoscaling based on demand
  • High performance for distributed teams
  • Distributed architecture for horizontal scaling and high availability
  • No published price; quote via sales

Who it's for

Notable strengths

  • 40+ languages and 5,000+ rules, including legacy/mainframe languages (ABAP, COBOL, JCL, PL/I, RPG) on Enterprise
  • Both SaaS (EU and US regions) and self-managed Server, plus a free open-source Community Build
  • Architecture governance: derived vs intended architecture, tangle and oversized-component detection, structural debt tracking
  • Cyber Resilience Act mapping with SBOM export, audit logs, and evidence generation for compliance processes
  • IDE plugins for JetBrains IDEs, Visual Studio, VS Code, and Eclipse with connected mode to Cloud or Server

Notable limitations

  • SCA and Advanced SAST are separate subscriptions, not included in Team or Enterprise base plans
  • Sonar Agent Essentials (Remediation Agent, Sonar Vortex) is a separate subscription and annual-only on Team
  • Free plan caps private code at 50,000 LOC and 5 members and restricts PR analysis to the main target branch
  • Six languages, MISRA profiles, Enterprise SSO, IP allow lists, and code encryption are Enterprise-only
  • No published price for Team or Enterprise; both require a quote, and LOC overage is hard-blocked with an error

Similar tools

Other Quality Platform tools in the directory.

FAQ

When should you choose SonarQube?

SonarQube best fits Startups, Mid-market teams, Enterprise, Regulated industries. 40+ languages and 5,000+ rules, including legacy/mainframe languages (ABAP, COBOL, JCL, PL/I, RPG) on Enterprise

What languages does SonarQube support?

SonarQube supports 41+ languages and frameworks, including Apex, ABAP, Ansible, Azure Resource Manager, C, C++, C#, COBOL, CloudFormation, Dart, and 31 more.

What does SonarQube integrate with?

SonarQube integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center, Azure DevOps for source control, CI systems including GitHub Actions, GitLab CI/CD, Bitbucket Pipelines, CircleCI, Amazon CodeCatalyst, and 2 more, and IDEs including IntelliJ IDEA, CLion, WebStorm, PhpStorm, PyCharm, and 6 more.

What tools are similar to SonarQube?

Similar Quality Platform tools tracked here include Codacy, CodeScene, DeepSource, Qlty.

What are SonarQube's plans and pricing?

SonarQube offers a free tier, with paid plans starting around Free tier available; enterprise pricing is quote-only.