What is Checkov?

Checkov scans infrastructure-as-code configurations across Terraform, Kubernetes, CloudFormation, Dockerfile, and other IaC formats to detect security vulnerabilities and compliance violations before deployment.

Independently observed

Checkov pricing

We don't have Checkov's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

What Checkov does

The capabilities that matter for cloud security software, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Posture
CSPM (posture / misconfig)
KSPM (Kubernetes posture)
Workload
CWPP (workload protection)
-
Entitlements
CIEM (entitlements)
-
Data
DSPM (data posture)
-
Pipeline
IaC / pipeline scanning
Architecture
Agentless scanning
Runtime
Runtime protection
-
Coverage
Cloud coverage
AWS, Google Cloud, Azure
Compliance
Compliance frameworks assessed
-
Licensing
Open-core scanner available
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
Deployment
  • Cloud / SaaS
  • Self-hosted

Integrations (13)

Independently observed
  • AWS
  • Google Cloud
  • Azure
  • Docker
  • Terraform
  • Kubernetes
  • CloudFormation
  • Dockerfile
  • Git
  • GitHub
  • Helm
  • Kustomize
  • Serverless

Security & compliance

Known vulnerabilities: 0 (0 in the last 12 months) sourcea count reflects scale & disclosure, not quality

Checkov FAQ

Common questions about Checkov, answered from independent, dated evidence.

What is Checkov?

Checkov scans infrastructure-as-code configurations across Terraform, Kubernetes, CloudFormation, Dockerfile, and other IaC formats to detect security vulnerabilities and compliance violations before deployment. It is indexed under Cloud Security Software.

Source: https://www.checkov.io

Is Checkov free to use?

Checkov is open source, so it can be self-hosted and used at no licence cost. It is released under the Apache-2.0 licence. Pricing changes often, so verify at source before relying on it.

Source: https://www.checkov.io

What platforms does Checkov support?

Checkov supports a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.

Source: https://www.checkov.io

Can Checkov be self-hosted?

Yes. Checkov can be deployed cloud / SaaS and self-hosted, so it does not have to run on the vendor's infrastructure.

Source: https://www.checkov.io

What does Checkov integrate with?

We have confirmed 11 integrations for Checkov, including AWS, Google Cloud, Azure, Docker, Terraform, Kubernetes, CloudFormation and Git, plus 3 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.

Source: https://www.checkov.io

Is Checkov open source?

Yes. Checkov is published under the Apache-2.0 licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.

Source: https://github.com/bridgecrewio/checkov

Checkov alternatives

Other cloud security software we track, ranked by the same independent score.

All Checkov alternatives, ranked →

Compare Checkov

Side by side against other cloud security software, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Checkov, not the verdict.

Balanced composite 60 / 100
low · 47%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Package downloads870.1411.8
Release cadence980.055.1
Capabilities750.064.7
Development activity400.093.8
Security score700.042.9
Dependent projects360.062.3
Integrations330.062.1
Stars750.031.9
Security posture00.210.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d18mediumsource · 2026-09-10 · 65%

Adoption

AttributeValueEvidence
Github stars8,996highsource · 2026-09-10 · 90%
Dependent repos138highsource · 2026-08-26 · 85%
Package downloads weekly4,830,339highsource · 2026-08-26 · 85%

Content

AttributeValueEvidence
Faq6 itemsmediumsource · 2026-09-10 · 61%

Features

AttributeValueEvidence
CapabilitiesCspm: Yes · Kspm: Yes · Iac scanning: Yes · Cloud coverage: AWS, Google Cloud, Azure · Open core scanner: Yes · Agentless scanning: Yesmediumsource · 2026-08-14 · 60%

Integrations

AttributeValueEvidence
Count13mediumsource · 2026-08-14 · 60%

Language

AttributeValueEvidence
PrimaryPythonhighsource · 2026-09-10 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-09-10 · 95%

Pricing

AttributeValueEvidence
Modelopen_sourcemediumsource · 2026-08-14 · 60%
Price levelfreemediumsource · 2026-08-14 · 60%
Free tierYesmediumsource · 2026-08-14 · 60%

Release

AttributeValueEvidence
Cadence days4mediumsource · 2026-09-10 · 70%
History20 itemsmediumsource · 2026-09-10 · 70%

Security

AttributeValueEvidence
Scorecard7highsource · 2026-09-10 · 90%
VulnerabilitiesCount: 0 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=checkov&per_page=100 · Last 12m: 0highsource · 2026-08-26 · 90%
Still deciding?

Is Checkov the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank Checkov against the rest of the cloud security software we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of Checkov

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Checkov up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows Checkov's independent score and links back to this profile.

Checkov, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/checkov" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/checkov.svg" alt="Checkov, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![Checkov, verified on vioscaleAI](https://www.vioscale.ai/badge/software/checkov.svg)](https://www.vioscale.ai/software/checkov)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Checkov. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim Checkov

Not the owner? How vendor profiles work