Comparison

Endor Labs vs SonarQube

On the evidence we track, SonarQube leads this comparison with a composite score of 71/100. Scores are only directly comparable because these tools share a category; the full breakdown and every source is below.

Machine formatsJSONMarkdownGraphQLor send Accept: application/json
Endor Labs65
SonarQube71
Score
Vioscale score
Endor Labs65 / 100medium · 71%
SonarQube71 / 100high · 75%
Pricing
Free tier
Endor Labs
SonarQube
Model
Endor Labsfreemium
SonarQubefreemium
Price level
Endor Labslow
SonarQubemid
Transparent
Endor Labs
SonarQube
Integrations
Count
Endor Labs10
SonarQube20
Security
Disclosure policy
Endor Labs
SonarQube
Fedramp
Endor Labs
SonarQube
Gdpr
Endor Labs
SonarQube
Iso27001
Endor Labs
SonarQube
Pci
Endor Labs
SonarQube
Scorecard
Endor Labs
SonarQube4.9
Soc2
Endor Labs
SonarQube
Reliability
Sla pct
Endor Labs99.9
SonarQube99.9
Status page
Endor Labs
SonarQube
Adoption
Dependent repos
Endor Labs
SonarQube497
Github stars
Endor Labs
SonarQube10,928
Activity
Commits last 30d
Endor Labs
SonarQube100
Release
Cadence days
Endor Labs
SonarQube28
History
Endor Labs
SonarQube20 items
License
Spdx
Endor Labs
SonarQubeLGPL-3.0
Language
Primary
Endor Labs
SonarQubeJava

Capabilities

Feature-by-feature on the axes that matter for devsecops tools. “-” means undocumented, not absent.

Scan types
SAST (static analysis)
Endor Labs
SonarQube
DAST (dynamic analysis)
Endor Labs
SonarQube
SCA / dependency scanning
Endor Labs
SonarQube
Secret scanning
Endor Labs
SonarQube
Container / image scanning
Endor Labs
SonarQube
IaC misconfiguration scanning
Endor Labs
SonarQube
Governance
OSS licence compliance
Endor Labs
SonarQube
SBOM generation (SPDX/CycloneDX)
Endor Labs
SonarQube
Remediation
Automated fix / upgrade PRs
Endor Labs
SonarQube
Prioritisation
Reachability / exploitability prioritisation
Endor Labs
SonarQube
Deployment
Hosting
Endor LabsCloud + self-hosted
SonarQubeCloud + self-hosted
Integration
First-class CI / pipeline integration
Endor Labs
SonarQube
In-editor / IDE scanning
Endor Labs
SonarQube
Licensing
OSS engine available
Endor Labs
SonarQube

What each one is

The product in its own terms, so the numbers below have context.

Endor Labs

An AI-powered application security platform combining static analysis, dependency scanning, and container image scanning with reachability-based prioritization to reduce false positives and enable automated vulnerability remediation across the development lifecycle.

Independently observed

SonarQube

Leader

A code verification system that scans source code repositories for bugs, security flaws, and quality problems, supporting both human-written and AI-generated code. It integrates directly into development workflows and CI/CD pipelines to provide real-time feedback and automated fix suggestions.

Independently observed

Pricing

List pricing as published by each vendor, with the date we read it. Always verify at the source before you buy.

Endor Labs

SubscriptionFree tier

Seat-based subscription pricing with free Developer tier; specific pricing available on request

  • DeveloperFree
    • Local scanning
    • Read-only vulnerability data
  • Core-
  • Pro-
as of verify ↗

SonarQube

Leader
from $34/moSubscriptionFree tier14-day trial

From $34/month. Free tier for open source projects. 14-day free trial.

  • Team$34/month
    • 30+ languages
    • code quality standards
    • bug and vulnerability detection
    • secret scanning
    • AI-powered code fixes
    • +2 more
  • EnterpriseContact sales
    • 40+ languages including ABAP, COBOL, Apex
    • all Team features plus
    • advanced security reports and audit logs
    • OWASP, CWE, PCI DSS, MISRA C++:2023 compliance
    • unlimited users and projects
    • +5 more
as of verify ↗

Platform & deployment

Where each product runs and how it can be hosted. A dash means undocumented, not unsupported.

Platforms
Web
Endor Labs
SonarQube
CLI
Endor Labs
SonarQube
Deployment
Cloud / SaaS
Endor Labs
SonarQube
Self-hosted
Endor Labs
SonarQube
On-premise
Endor Labs
SonarQube
Hybrid
Endor Labs
SonarQube
Air-gapped
Endor Labs
SonarQube

Integrations

What each product connects to. Counts come from the vendor's own integration directory where one exists.

In common (4)
  • GitHub
  • GitLab
  • BitBucket
  • Azure DevOps

Endor Labs

10 total - 6 not shared
  • AWS Marketplace
  • Microsoft Azure
  • Google Cloud Marketplace
  • Wiz
  • Cursor AI
  • Microsoft Defender for Cloud
Independently observed

SonarQube

Leader
19 total - 15 not shared
  • CodeCatalyst
  • CircleCI
  • TravisCI
  • GitHub Actions
  • Jenkins
  • Codemagic
  • Slack
  • Jira
  • Linear
  • GitHub Advanced Security
  • Backstage
  • Compass
  • Cortex
  • Harness
  • Port
Independently observed

Comparison generated from independently-sourced facts. Every value links to its source and retrieval date. See the method.