# Checkov

- **Canonical URI:** https://www.vioscale.ai/software/checkov
- **Category:** Cloud Security Software
- **Homepage:** https://www.checkov.io
- **Also known as:** checkov
- **Profile claimed by vendor:** no
- **Last updated:** 2026-08-05T14:15:45.450Z

## Vioscale score

**66.5 / 100**, confidence 32% (low).

Composite of weighted, independently-sourced signals (no user reviews, no vendor payment).

| Signal | Score | Weight | Contribution | Evidence present |
|---|--:|--:|--:|:--:|
| capabilities | 74.7 | 0.07 | 5.2 | ✓ |
| github_stars | 74.5 | 0.029 | 2.2 | ✓ |
| integrations | 41.2 | 0.07 | 2.9 | ✓ |
| github_activity | 26.6 | 0.105 | 2.8 | ✓ |
| release_cadence | 98.9 | 0.058 | 5.7 | ✓ |
| security_posture | 0 | 0.234 | 0 | - |
| package_downloads | 88 | 0.152 | 13.4 | ✓ |
| stackoverflow_activity | 0 | 0.07 | 0 | - |

## Pricing

_As of 2026-08-05, [verify at source](https://www.checkov.io). Independently observed._

Open source

## About

Infrastructure-as-code scanner that identifies misconfigurations across cloud platforms before deployment using policy-as-code framework.

_Independently observed._

## Platform & deployment

- **Platforms:** CLI
- **Deployment:** Self-hosted

## Integrations (26)

_Independently observed._

- Terraform
- Terraform Plan
- CloudFormation
- Kubernetes
- Helm
- AWS CDK
- Serverless
- Bicep
- ARM Templates
- Ansible
- Argo Workflows
- Kustomize
- AWS SAM
- GitHub Actions
- GitLab CI
- GitHub
- GitLab
- Bitbucket Cloud Pipelines
- Bitbucket
- Jenkins
- CircleCI
- Azure Pipelines
- Docker
- Dockerfile
- OpenAPI
- Pre-Commit Hooks

## Capabilities

_The capabilities that matter for Cloud Security Software. "-" = undocumented, not absent._

| Capability | Supported |
|---|:--:|
| **Posture** | |
| CSPM (posture / misconfig) | ✓ |
| KSPM (Kubernetes posture) | ✓ |
| **Workload** | |
| CWPP (workload protection) | - |
| **Entitlements** | |
| CIEM (entitlements) | - |
| **Data** | |
| DSPM (data posture) | - |
| **Pipeline** | |
| IaC / pipeline scanning | ✓ |
| **Architecture** | |
| Agentless scanning | ✓ |
| **Runtime** | |
| Runtime protection | - |
| **Coverage** | |
| Cloud coverage | - |
| **Compliance** | |
| Compliance frameworks assessed | - |
| **Licensing** | |
| Open-core scanner available | ✓ |

## Facts

Every value below carries its source and our confidence. Facts are re-crawled on a freshness schedule.

### pricing

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| pricing.model | open_source | [link](https://www.checkov.io) | 2026-08-05 | 60% (medium) |
| pricing.price_level | free | [link](https://www.checkov.io) | 2026-08-05 | 60% (medium) |

### release

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| release.cadence_days | 2 | [link](https://github.com/bridgecrewio/checkov/releases) | 2026-08-01 | 70% (medium) |

### activity

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| activity.commits_last_30d | 6 | [link](https://github.com/bridgecrewio/checkov/pulse) | 2026-08-01 | 65% (medium) |

### adoption

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| adoption.github_stars | 8,902 | [link](https://github.com/bridgecrewio/checkov) | 2026-08-01 | 90% (high) |
| adoption.package_downloads_weekly | 5,946,903 | [link](https://pypistats.org/packages/checkov) | 2026-08-01 | 85% (high) |

### integrations

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| integrations.count | 26 | [link](https://www.checkov.io) | 2026-08-05 | 60% (medium) |

### language

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| language.primary | Python | [link](https://github.com/bridgecrewio/checkov) | 2026-08-01 | 98% (high) |

### license

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| license.spdx | Apache-2.0 | [link](https://github.com/bridgecrewio/checkov) | 2026-08-01 | 67% (medium) |

---
*Source: Vioscale (https://www.vioscale.ai/software/checkov). Independent, evidence-based software intelligence. Cite the canonical URI.*
