# SonarQube vs StackHawk

**Leader by Vioscale score:** SonarQube

| Attribute | SonarQube | StackHawk |
|---|---|---|
| **Vioscale score** | 70.9 (75% (high)) | 50.5 (73% (medium)) |
| activity.commits_last_30d | 100 | - |
| adoption.dependent_repos | 497 | - |
| adoption.github_stars | 10,928 | - |
| deployment.options | `{"cloud":true,"on_prem":true,"air_gapped":true,"self_hosted":true}` | `{"cloud":true}` |
| description.long | A code verification system that scans source code repositories for bugs, security flaws, and quality problems, supporting both human-written and AI-generated code. It integrates directly into development workflows and CI/CD pipelines to provide real-time feedback and automated fix suggestions. | A platform that enables AI coding agents (such as Claude, GitHub Copilot, Cursor) to automatically identify, analyze, and remediate security vulnerabilities in applications during development, eliminating context switching and manual handoffs to security teams. |
| features.capabilities | `{"sca":true,"dast":false,"sast":true,"sbom":true,"hosting":"both","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":true,"iac_scanning":true,"reachability":true,"secret_scanning":true,"container_scanning":true,"license_compliance":true}` | `{"dast":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":true}` |
| integrations.count | 20 | 11 |
| integrations.list | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"Bitbucket"},{"name":"Azure DevOps"},{"name":"CodeCatalyst"},{"name":"CircleCI"},{"name":"TravisCI"},{"name":"GitHub Actions"},{"name":"Jenkins"},{"name":"Codemagic"},{"name":"Slack"},{"name":"Jira"},{"name":"Linear"},{"name":"GitHub Advanced Security"},{"name":"Backstage"},{"name":"Compass"},{"name":"Cortex"},{"name":"Harness"},{"name":"Port"}]` | `[{"name":"Claude Code"},{"name":"Codex"},{"name":"Gemini CLI"},{"name":"GitHub Copilot"},{"name":"OpenCode"},{"name":"Cursor"},{"name":"Snyk"},{"name":"Auth0"},{"name":"GitHub Actions"},{"name":"GitLab"},{"name":"Jenkins"},{"name":"CircleCI"}]` |
| language.primary | Java | - |
| license.spdx | LGPL-3.0 | - |
| market.availability | `{"hqCountry":"CH","primaryMarkets":["US","EU"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"subscription","plans":[{"free":false,"name":"Team","summary":"$34/month","features":["30+ languages","code quality standards","bug and vulnerability detection","secret scanning","AI-powered code fixes","PR analysis","commercial support available"],"commitment":"monthly","components":[{"kind":"fixed","amount":34,"period":"month","currency":"USD"}],"description":"For small teams analyzing up to 100k lines of code","contactSales":false,"includedLimits":{"private_loc":"up to 100k"}},{"free":false,"name":"Enterprise","summary":"Custom pricing","features":["40+ languages including ABAP, COBOL, Apex","all Team features plus","advanced security reports and audit logs","OWASP, CWE, PCI DSS, MISRA C++:2023 compliance","unlimited users and projects","SSO, SCIM, CMK/BYOK, IP allowlist","enterprise hierarchy and portfolios","GitHub Advanced Security integration","enterprise SLA","premium support"],"description":"For large organizations with advanced security and compliance needs","contactSales":true}],"addOns":[{"name":"Advanced Security"},{"name":"Sonar Agent Essentials"}],"summary":"From $34/month. Free tier for open source projects. 14-day free trial.","currency":"USD","freeTier":true,"sourceUrl":"https://www.sonarsource.com/jp/plans-and-pricing/","retrievedAt":"2026-08-14T15:24:06.893Z","freeTrialDays":14,"startingPrice":{"amount":34,"period":"month","currency":"USD"},"billingPeriods":["month","year"]}` | `{"type":"subscription","plans":[{"free":false,"name":"Wingman","summary":"$10/user/month","features":["Works inside Claude Code, Cursor, GitHub Copilot","Auto-configures and boots app","Runtime testing against running app","Finds and fixes vulnerabilities in same session","Auto-rescanning to verify fix","Pre-PR security attestation","Unlimited apps","50 scans/user/month"],"commitment":"monthly","components":[{"kind":"per_unit","unit":"user","amount":10,"period":"month","currency":"USD"}],"description":"For individuals and teams shipping with AI coding agents","contactSales":false,"includedLimits":{"apps":"unlimited","scans":"50/user/month"}},{"free":false,"name":"Scale","summary":"Custom pricing. Contact sales.","features":["Everything in Wingman","Attack surface discovery","Sensitive data detection","Deeper, broader scan coverage","Program reporting (coverage, fix rates by team)","Teams, roles, and enterprise support","Unlimited agentic scans"],"description":"For security teams needing attack surface discovery, coverage, and proof across every app","contactSales":true,"includedLimits":{"apps":"unlimited","scans":"unlimited"}}],"summary":"From $10/user/month (Wingman). 14-day free trial. Scale plan available via sales consultation.","currency":"USD","freeTier":true,"sourceUrl":"https://www.stackhawk.com","retrievedAt":"2026-08-03T22:45:21.019Z","freeTrialDays":14,"startingPrice":{"amount":10,"period":"month","currency":"USD"},"billingPeriods":["month"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | freemium |
| pricing.price_level | mid | low |
| pricing.transparent | yes | no |
| release.cadence_days | 28 | - |
| release.history | `[{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.8.0.126808","date":"2026-08-05T07:17:56Z","type":"stable","version":"26.8.0.126808"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.7.0.124771","date":"2026-07-08T13:48:56Z","type":"stable","version":"26.7.0.124771"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.6.0.123539","date":"2026-06-03T09:56:25Z","type":"stable","version":"26.6.0.123539"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.5.0.122743b","date":"2026-05-19T12:59:25Z","type":"stable","version":"26.5.0.122743b"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.4.0.121862","date":"2026-04-10T13:17:33Z","type":"stable","version":"26.4.0.121862"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.3.0.120487","date":"2026-03-03T09:53:50Z","type":"stable","version":"26.3.0.120487"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.2.0.119303","date":"2026-02-04T10:07:42Z","type":"stable","version":"26.2.0.119303"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.1.0.118079","date":"2026-01-06T14:46:07Z","type":"stable","version":"26.1.0.118079"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.12.0.117093","date":"2025-12-23T15:00:10Z","type":"stable","version":"25.12.0.117093"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.11.0.114957","date":"2025-11-05T10:26:59Z","type":"stable","version":"25.11.0.114957"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.10.0.114319","date":"2025-10-03T13:33:44Z","type":"stable","version":"25.10.0.114319"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.9.0.112764","date":"2025-09-01T15:33:36Z","type":"stable","version":"25.9.0.112764"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.8.0.112029","date":"2025-08-06T13:33:07Z","type":"stable","version":"25.8.0.112029"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.7.0.110598","date":"2025-07-07T09:39:23Z","type":"stable","version":"25.7.0.110598"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.6.0.109173","date":"2025-06-02T14:19:56Z","type":"stable","version":"25.6.0.109173"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.5.0.107428","date":"2025-05-06T08:12:43Z","type":"stable","version":"25.5.0.107428"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.4.0.105899","date":"2025-04-07T13:22:08Z","type":"stable","version":"25.4.0.105899"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.3.0.104237","date":"2025-03-04T14:08:50Z","type":"stable","version":"25.3.0.104237"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.2.0.102705","date":"2025-02-03T16:06:10Z","type":"stable","version":"25.2.0.102705"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.1.0.102122","date":"2025-01-07T15:44:51Z","type":"stable","version":"25.1.0.102122"}]` | - |
| reliability.sla_pct | 99.9 | - |
| reliability.status_page | yes | yes |
| security.disclosure_policy | - | yes |
| security.gdpr | yes | - |
| security.iso27001 | yes | - |
| security.scorecard | 4.9 | - |
| security.soc2 | yes | yes |
| security.vulnerabilities | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.sonarsource.sonarqube%3Asonar-plugin-api&per_page=100","last_12m":0,"max_severity":"MODERATE"}` | - |

## Capabilities (DevSecOps Tools)

| Capability | SonarQube | StackHawk |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | ✓ | - |
| DAST (dynamic analysis) | ✗ | ✓ |
| SCA / dependency scanning | ✓ | - |
| Secret scanning | ✓ | - |
| Container / image scanning | ✓ | - |
| IaC misconfiguration scanning | ✓ | - |
| **Governance** |  |  |
| OSS licence compliance | ✓ | - |
| SBOM generation (SPDX/CycloneDX) | ✓ | - |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | ✓ | ✓ |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | ✓ | - |
| **Deployment** |  |  |
| Hosting | Cloud + self-hosted | Cloud only |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | ✓ | ✓ |
| **Licensing** |  |  |
| OSS engine available | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T14:32:42.824Z. "-" = undocumented, not absent.*
