Quality Platform
SonarQube
Code quality and security analysis platform for 40+ languages, delivered as SonarQube Cloud SaaS or self-managed SonarQube Server.
Deployment
Cloud · Self-Hosted · Air-Gapped
Languages
41+
Pricing model
Per lines of code, Quote-based / Enterprise
Free tier
Yes
Workflow coverage
Where in the development lifecycle SonarQube operates.
SonarQube for IDE gives real-time analysis with quick fixes; 25 languages, connected mode.
MCP server plus Sonar Vortex context augmentation; Vortex needs Sonar Agent Essentials subscription.
SonarQube CLI analyses local changes and staged files and runs 'sonar analyze secrets'.
PR decoration in GitHub, GitLab, Bitbucket, Azure DevOps; Free limits PRs to main target branch.
Quality gates block PRs and branches via status checks; custom gates require Team or Enterprise.
Full codebase analysis in CI/CD via SonarScanner CLI, Maven, Gradle, Python, .NET scanners.
Automatic Analysis re-runs on repository changes for GitHub and Azure DevOps; no scheduled rescan documented.
Not offered in vendor documentation reviewed as of 2026-09-05.
Analysis & detection
Every detection and code-analysis capability tracked for SonarQube.
Injection, arbitrary file read/write, access control, authentication, and cryptography rules.
Tracks data flow from untrusted sources to dangerous sinks; Advanced SAST sold separately.
Hardcoded credentials, API keys, tokens via SonarQube CLI and Cloud staged-file scanning.
Not offered in vendor documentation reviewed as of 2026-09-05.
SCA is a separate product subscription, available only to Team and Enterprise plans.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
License policy management and enforcement ships inside the separately subscribed SCA product.
SBOM export in standard formats is part of the separately subscribed SCA product.
Ansible, Azure Resource Manager, CloudFormation, Docker, Kubernetes/Helm, Terraform misconfiguration rules.
Dockerfile analysis only; no container image or layer scanning documented.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
5,000+ rules covering maintenance issues, poor practices, and suboptimal patterns.
Complexity metrics reported alongside issue density and distribution measures.
Duplication detection and tracking reported as a first-class metric.
Not offered in vendor documentation reviewed as of 2026-09-05.
Coverage import for C/C++/Objective-C, Dart, .NET, Go, Java, JavaScript/TypeScript, PHP, Python.
Configurable new-code definition drives gates on new code; coverage-on-new-code not explicitly documented.
Derived vs intended architecture, tangles, oversized components, wrong dependency and location issues.
Technical debt calculation plus structural technical debt tracking from architecture analysis.
Velocity and burndown tracking in metrics; no code-hotspot or behavioural analytics documented.
Gitar AI pull-request review is a separate Sonar product; bug classes it detects are unspecified.
Not offered in vendor documentation reviewed as of 2026-09-05.
Custom quality profiles configure language rule sets on Team and Enterprise; authoring new rules not documented.
AI CodeFix proposes LLM fixes for CRITICAL, HIGH, MEDIUM issues; Cloud Team/Enterprise, Server Enterprise/Data Center.
Remediation Agent fixes backlog issues on GitHub and Azure DevOps; requires Sonar Agent Essentials.
Not offered in vendor documentation reviewed as of 2026-09-05.
Multi-project repository analysis with monorepo branch, PR, and scoped analysis.
AI capabilities
AI CodeFix is LLM-powered on Team and Enterprise; Gitar AI PR review sold as a separate product.
Azure OpenAI/AWS Bedrock/self-hosted gateway BYOK on Server Enterprise/Data Center only; Cloud has no BYOK option
SonarQube MCP Server for agent context; Vortex MCP integration tied to Sonar Agent Essentials.
Enterprise quality gate and quality profiles specifically govern agentic AI-generated code.
Gitar (separate Sonar product) takes natural-language PR replies, e.g. 'gitar why was this file changed?'
Gitar persists dismissed and resolved findings across review iterations, learning from developer replies.
Third-party LLM providers contractually barred from training on input data across all tiers; SonarSource excludes Enterprise/Server data.
Compliance & governance
Organization activity, change history, and access/permission modification logs.
Multiple SSO providers and LDAP/Active Directory options, but Enterprise SSO is Enterprise-only.
Role-based access control and project-level permissions; permission templates need Team or Enterprise.
PDF and interactive project/portfolio security reports, CRA reports, audit evidence export; portfolios are Team+.
Certifications
Standards mapping
Integrations
CI/CD systems
IDEs
Issue trackers
Chat & notifications
Pricing & plans
$24/month for the entry lines-of-code tier (Team plan); price scales with the LOC tier chosen
Minimum seats: none
Trial: 14 days for new Team plan customers
- Basic code analysis
- Unlimited public project analysis
- IDE integration
- Built-in 'Sonar way' quality gate
- Webhooks
- 50,000 LOC for private projects
- Up to 5 organization members
- Pull request analysis only when the target branch is main
- No custom quality gates or profiles, no architecture analysis, no AI CodeFix
- No email or Slack notifications
- All Free features plus unlimited pull request analysis
- Custom quality profiles and custom quality gates
- Architecture analysis
- AI CodeFix
- Portfolio management and advanced management reporting
- Permission templates, groups, org-wide project configuration, email and Slack notifications
- LOC ceiling of 1,900,000; exceeding the limit is blocked with an error
- SCA and Advanced SAST require separate subscriptions
- Sonar Agent Essentials is annual-subscription only on Team
- No Enterprise languages, MISRA profiles, Enterprise SSO, IP allow lists, or code encryption
- Credit-card auto-renewal; suspension on payment failure (data preserved)
- All Team features
- Enterprise languages: Apex, ABAP, COBOL, JCL, PL/I, RPG
- MISRA compliance quality profiles
- Enterprise organization hierarchy with shared or individual LOC allocation
- Sonar Agent Essentials included
- GitHub advanced security integration, IP allow lists, Enterprise SSO, code encryption, custom SLA
- No published price; enterprise sales motion required
- SCA and Advanced SAST still require separate subscriptions
- Full analysis of public repositories with unlimited LOC
- Unlimited pull request analysis
- Advanced analysis features including architecture and custom quality gates/profiles
- Portfolio management, groups, webhooks
- GitHub member synchronization
- No private project analysis
- No AI CodeFix, Remediation Agent, or Sonar Vortex
- No permission templates, org-wide configurations, or email/Slack notifications
- Free, open-source version of SonarQube Server
- Source does not enumerate which analysis features Community Build includes or excludes
- 34 languages & frameworks
- Autodetect AI-generated code
- AI Code Assurance
- Advanced bug detection
- Secrets detection
- Architecture management
- No published price; quote via sales
- No AI CodeFix, MISRA C++:2023 compliance, or commercial support tiers (Enterprise+ only)
- No high-availability or distributed architecture (Data Center only)
- Developer edition, plus:
- 40 total languages & frameworks (incl. Apex, ABAP, COBOL, JCL, PL/I, RPG)
- AI CodeFix
- MISRA C++:2023 compliance
- Commercial support, and 24/7 white-glove support available
- Detailed project health insights
- No published price; quote via sales
- No autoscaling or distributed high-availability architecture (Data Center only)
- Enterprise edition, plus:
- Autoscaling based on demand
- High performance for distributed teams
- Distributed architecture for horizontal scaling and high availability
- No published price; quote via sales
Who it's for
Notable strengths
- 40+ languages and 5,000+ rules, including legacy/mainframe languages (ABAP, COBOL, JCL, PL/I, RPG) on Enterprise
- Both SaaS (EU and US regions) and self-managed Server, plus a free open-source Community Build
- Architecture governance: derived vs intended architecture, tangle and oversized-component detection, structural debt tracking
- Cyber Resilience Act mapping with SBOM export, audit logs, and evidence generation for compliance processes
- IDE plugins for JetBrains IDEs, Visual Studio, VS Code, and Eclipse with connected mode to Cloud or Server
Notable limitations
- SCA and Advanced SAST are separate subscriptions, not included in Team or Enterprise base plans
- Sonar Agent Essentials (Remediation Agent, Sonar Vortex) is a separate subscription and annual-only on Team
- Free plan caps private code at 50,000 LOC and 5 members and restricts PR analysis to the main target branch
- Six languages, MISRA profiles, Enterprise SSO, IP allow lists, and code encryption are Enterprise-only
- No published price for Team or Enterprise; both require a quote, and LOC overage is hard-blocked with an error
Similar tools
Other Quality Platform tools in the directory.
FAQ
When should you choose SonarQube?
SonarQube best fits Startups, Mid-market teams, Enterprise, Regulated industries. 40+ languages and 5,000+ rules, including legacy/mainframe languages (ABAP, COBOL, JCL, PL/I, RPG) on Enterprise
What languages does SonarQube support?
SonarQube supports 41+ languages and frameworks, including Apex, ABAP, Ansible, Azure Resource Manager, C, C++, C#, COBOL, CloudFormation, Dart, and 31 more.
What does SonarQube integrate with?
SonarQube integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center, Azure DevOps for source control, CI systems including GitHub Actions, GitLab CI/CD, Bitbucket Pipelines, CircleCI, Amazon CodeCatalyst, and 2 more, and IDEs including IntelliJ IDEA, CLion, WebStorm, PhpStorm, PyCharm, and 6 more.
What tools are similar to SonarQube?
Similar Quality Platform tools tracked here include Codacy, CodeScene, DeepSource, Qlty.
What are SonarQube's plans and pricing?
SonarQube offers a free tier, with paid plans starting around Free tier available; enterprise pricing is quote-only.
Opens www.sonarsource.com in a new tab. Review Radar is not affiliated with Sonar.