Codacy Platform Plans & Pricing

Plug and play. Predictable cost. No usage limits.

Developer

For Al-driven engineers shipping faster without sacrificing security, quality and good vibes

Free forever

$0

Per dev/mth, billed

Guardrails for AI-generated code

  • Make every line of AI code clean, secure and compliant as it is being generated
  • One-click integration with VSCode, Cursor and Windsurf
  • Works with any MCP-ready LLM (Copilot, Claude, etc.)
  • Supports TypeScript, JavaScript, Python & Java

Security and quality scans embedded in your IDE

  • SAST vulnerabilities
  • Hardcoded secrets
  • Insecure dependencies
  • Complex code and duplications
  • Error-prone code
  • Code performance issues

Team

For modern teams up to 30 devs protecting their apps from inception to product

Yearly starting at

$18

Per dev/mth

Monthly starting at

$21

Per dev/mth

Start free trial

Free forever for open-source projects

Everything in Developer, plus:

AI Guardrails across teams and projects

  • Sharable security and coding standards enforced in every developer’s IDE
  • Fix critical issues and write missing unit tests at scale from your AI chat panel
  • Query your security and quality data without leaving your IDE

AI-powered Pull Request feedback

  • Scan unlimited lines of code in up to 100 private repos – no pipeline steps needed
  • AI-powered, context-aware PR feedback
  • Maintain secure, healthy code and high test coverage across 49 languages
  • SAST, secret and dependency scans for application and infrastructure-as-code
  • Flag Malicious Packages introduced in Pull Requests

Triage and fix findings at scale

  • Smart False Positive Triage
  • Security and Risk Management monitor with SLA tracking
  • Explore findings by team, repo, issue category and severity
  • Track issues on Jira and Slack

Business

For leading organizations with enterprise-level security and reporting requirements

Free forever

Custom

Per dev/mth, billed

Chat with us

Anonymously

Everything in Team, plus:

360° DevSecOps from code to runtime

  • Unlimited private projects
  • Daily SCA and Malicious Package re-scans across all repositories
  • AI Risk Hub: Enforce and track org-wide AI coding policies
  • DAST (pipeline-less runtime scans)
  • License scanning 
  • Smart False Positive Triage
  • Penetration testing (billed separately)

Enterprise-ready deployment

  • Priority queue for fastest scan results
  • Custom API scripts for configuration and reporting at scale
  • Audit log for usage tracking
  • Session timeout

White-glove customer excellence

  • Dedicated Customer Success Manager (depending on contract value)
  • Premium technical support with screen sharing and video chat
  • Extended proof-of-value (trial) with dedicated support

Get Codacy on AWS Marketplace

Organizations purchasing through the AWS Marketplace can receive 2% of their contract value back in AWS credits. Contact us for more details.

Purchase through AWS

Features included

AI Guardrails (IDE Extension)

Developer

Team

Business

Guardrails for clean, secure and compliant AI code enforced during code generation
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
One-click integration with VSCode, Cursor and Windsurf
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Support for all MCP-ready LLMs (Copilot, Claude, etc.)
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Local, real-time security scans for SAST issues, hardcoded secrets and insecure dependencies, embedded in the IDE
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Local, real-time quality scans for complex and error-prone code, duplications and performance issues, embedded in the IDE
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Customize scan rules locally via configuration files
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Customize scan rules globally in the Codacy Cloud Platform UI
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Sharable AI security and coding standards enforced in every developer’s IDE
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Query, report, prioritize and fix security and quality findings at scale from your AI chat panel
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
AI-generate missing unit tests for files with low test coverage
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.

Integration

Developer

Team

Business

Unlimited public repositories
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Unlimited private repositories
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
GitHub, Bitbucket and GitLab integration (Cloud-hosted only)
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Enforceable security and quality gates for Pull Requests
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
AI-powered Pull Request feedback
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
AI-powered fix suggestions in Pull Requests
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Test coverage tracker and merge gates
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Two-way Jira integration
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Slack integration for critical security alerts
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.

Code Scanning

Developer

Team

Business

49 languages and frameworks supported
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Real-time Commit & Pull Request scans
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Pull Request merge gates
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Smart False Positive Triage
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
One-click fix suggestions
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Smart configuration with over 12k scan rules
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Custom scan rules
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Prioritized PR analysis for faster results
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.

Application Security

Developer

Team

Business

SAST vulnerability scanning
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Hardcoded secrets & password detection
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Infrastructure-as-code (IaC) misconfiguration detection
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Dependency / SCA scanning of new code
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Malicious package detection in new code
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Org-wide AI Coding Policies
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Daily SCA and Malicious Package re-scans across all repositories
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
SBOM exports
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
License scanning
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
DAST (pipeline-less runtime scans)
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Penetration testing (billed separately)
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.

Vulnerability Management and Reporting

Developer

Team

Business

Customizable management reports across teams and projects
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Organization-wide Security and Risk Management Dashboard
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Configurable SLA remediation due date tracking
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Create and track Jira tickets from findings in Codacy
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Import external security findings via Jira
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Live critical security alerts via Slack
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
AI Risk Hub
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Export SBOM files
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Report automation and custom integrations via Codacy API
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.

Enterprise Compliance

Developer

Team

Business

SOC2 Type 2-certified cloud infrastructure
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Single sign-on (SSO) via GitHub, Bitbucket or GitLab
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Static IP for allowlisting Codacy
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Audit logs (via API)
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Session timeout
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Access control checks
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Service Level Agreement (SLA)
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.

Customer Experience

Developer

Team

Business

Standard support via email & in-app chat
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Priority support via screen sharing and video chat
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Dedicated Customer Success Manager and Solutions Engineer
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Personalized training for users and administrators
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Custom configuration and API scripting support
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.
Extended proof-of-value (trial)
Automated code quality analysis detecting error-prone patterns, code complexity, duplications, best practice violations and more, across 49 languages.

Ready to make the switch?

Start free trial
Book a demo

Full scan within minutes  |  Free trial for 14 days  |  No credit card required

Frequently asked questions

Codacy is the easiest way for engineering teams to maintain a clean and secure codebase without any pipeline integrations, ready to go with a few clicks:

  1. Log in with your GitHub, Bitbucket or GitLab account to add your organization or workspace (requires org admin permissions)
  2. Add your repositories with the click of a button. Codacy scans the entire codebase for quality and security violations within minutes. Easily browse all findings, and tackle the most critical risks before they cause damage.
  3. As the codebase evolves, every new Pull/Merge Request is scanned in real time, catching new quality and security violations before they get merged, built and released.

On top of code scanning, Codacy tracks test coverage results across files and Pull Requests, preventing untested critical code from being merged.

Codacy's code scanning as-a-service allows businesses to reduce hosting and maintaining complex, dynamic and costly pipeline integrations while ensuring full quality and security coverage across all projects and languages.

As a 100% cloud-based GitHub, Bitbucket and GitLab app, Codacy uses webhooks to keep track of all code changes in real time, and performs all scans on its own AWS infrastructure, while seamlessly updating the latest coding conventions and scan rules for you to keep up with industry trends and evolving programming languages.

For more details on how Codacy keeps your source code safe, see here.

Codacy scans source code in 49 languages across a range of common violations, including error prone code, performance problems, complex code, duplications and code style deviations. Learn more about issue categories here.

All Codacy subscriptions include responsive, high-quality technical support. Our team of experts is ready to assist you with any questions, from initial setup and onboarding to advanced configuration and troubleshooting.

We are committed to ensuring your team is successful with Codacy, providing the reliable assistance you need to keep your development workflow running smoothly.Codacy detects a wide range of security vulnerability types through a curated collection of analysis tools built into the Codacy platform:

  • Static Application Security Testing (SAST)
  • Hardcoded Secrets and Passwords
  • Infrastructure-as-code (IaC scanning)
  • Software Composition Analysis (SCA) / Dependency checks
  • Dynamic Application Security Testing (DAST)
  • Penetration Testing (manual testing via Bulletproof)
  • License scanning (coming soon)

Learn more about security categories here.

No, Codacy currently does not support projects hosted on any on-premise Git deployments.

The supported Git providers are GitHub Cloud, Bitbucket Cloud, and GitLab Cloud.

Codacy currently does not support Azure Repos, but you can now join our waitlist to get notified once we do.

The supported Git providers are GitHub Cloud, Bitbucket Cloud, and GitLab Cloud.

Codacy supports 49 popular programming languages and frameworks across back-end, front-end, infrastructure-as-code, mobile code, and everything in between. See a full list of supported languages here.

Yes, Codacy provides plugins for Jetbrains IDEs and VSCode (requires GitHub, Bitbucket or GitLab integration on codacy.com)

The Codacy plugin shows all scan results and fix suggestions for every open Pull Request right inside the IDE for more seamless code reviews, faster remediation, and to help avoid context switching.

While real-time scanning within the IDE (outside the Pull Request flow) is not supported yet, make sure to stay tuned for a major update to our IDE plugin in 2025! 🤫

As we provide cloud solutions for leading enterprises around the world, keeping our customers' data protected at all times is the highest of all priorities. Codacy has implemented bulletproof cloud security measures in accordance with the latest industry standards, and certified by SOC2.

For details on Codacy's security measures, visit https://security.codacy.com.

Codacy is compliant with the General Data Protection Regulation (GDPR). The purpose of GDPR is to protect the private information of EU citizens and give them more control over their personal data.

For any further questions about personal data privacy, contact us at [email protected].

Open Source (free): For individuals and teams working exclusively on public projects.

Pro: For individuals and teams of up to 30 contributors working on up to 100 private projects.

Business: For engineering organizations with more than 30 contributors or more than 100 private projects, as well as teams with advanced security, reporting, and support requirements (see comparison table above)

Codacy requires a seat for every Git contributor who commits code changes to a private repo added to Codacy. Typically, the required number of seats reflects the total size of the development team.

Simply sign up with your Git provider (no credit card required), and enjoy full access to the Codacy platform for 14 days, free of charge.

After the trial period, you can upgrade to a paid plan to continue using Codacy with private repositories, or keep scanning your public repositories for free on the Open Source plan.

Codacy accepts credit cards by Visa, Mastercard, American Express, and Discover. Wire transfers and ACH are accepted only for annual Pro and Business plans.

If your preferred payment method is not supported, please contact us at [email protected].

Yes, you can change or cancel your plan at any time. If you choose to cancel your annual subscription before the conclusion of the 12 months, your account will continue to work for the remainder of the annual billing period.