SonarQube

Automated static analysis platform that identifies and helps fix code quality issues, security vulnerabilities, and bugs throughout the development lifecycle

Vendor
SonarSource
Also known as
sonarqube

Available worldwide · Popular in: US

What is SonarQube?

A code verification system that scans source code repositories for bugs, security flaws, and quality problems, supporting both human-written and AI-generated code. It integrates directly into development workflows and CI/CD pipelines to provide real-time feedback and automated fix suggestions.

Independently observed

SonarQube pricing

Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.

Pricing as of verify at live pricing ↗Independently observed
from $32/moHybridFree tier14-day trial

From $32/month (Team plan). Free tier available with 14-day trial. Community Build is free and open source.

Free

Free
Free

Free tier for exploring SonarQube with private projects

lines_of_code
50k

Team

$32/month, billed monthly or annually, Team plan
monthly
lines_of_code
100k
  • Auto-approve & merge blocking
  • 3rd-party integrations (Slack, Linear, Jira)

Enterprise

Contact sales
Contact sales
annual

Community Build

Free
Free

Free and open source, self-managed edition

languages
20+

What SonarQube does

The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Scan types
SAST (static analysis)
DAST (dynamic analysis)
SCA / dependency scanning
Secret scanning
Container / image scanning
IaC misconfiguration scanning
Governance
OSS licence compliance
SBOM generation (SPDX/CycloneDX)
Remediation
Automated fix / upgrade PRs
Prioritisation
Reachability / exploitability prioritisation
Deployment
Hosting
Cloud + self-hosted
Integration
First-class CI / pipeline integration
In-editor / IDE scanning
Licensing
OSS engine available
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
  • Web
Deployment
  • Cloud / SaaS
  • Self-hosted

Integrations (22)

Independently observed
ci_cd
  • Bitbucket Pipelines
  • GitLab CI
  • Bamboo
  • GitHub
  • GitLab
  • Bitbucket
  • Azure DevOps
  • CodeCatalyst
  • CircleCI
  • TravisCI
  • GitHub Actions
  • Jenkins
  • Codemagic
  • Slack
  • Jira
  • Linear
  • GitHub Advanced Security
  • Backstage
  • Compass
  • Cortex
  • Harness
  • Port

Security & compliance

Independently observed
  • SOC 2 Type II · Type IIactive

Known vulnerabilities: 1 (0 in the last 12 months), max severity MODERATE sourcea count reflects scale & disclosure, not quality

SonarQube FAQ

Common questions about SonarQube, answered from independent, dated evidence.

What is SonarQube?

A code verification system that scans source code repositories for bugs, security flaws, and quality problems, supporting both human-written and AI-generated code. It integrates directly into development workflows and CI/CD pipelines to provide real-time feedback and automated fix suggestions. It is indexed under DevSecOps Tools.

Source: https://www.sonarsource.com/jp/plans-and-pricing/

Is SonarQube free?

SonarQube offers a free tier, so you can start without paying. Paid plans start at $34 per month. Prices are published openly on the vendor's own pricing page. Pricing changes often, so verify at source before relying on it.

Source: https://www.sonarsource.com/jp/plans-and-pricing/

What platforms does SonarQube support?

SonarQube supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.

Source: https://www.sonarsource.com/jp/plans-and-pricing/

Can SonarQube be self-hosted?

Yes. SonarQube can be deployed cloud / SaaS, on-premise, air-gapped and self-hosted, so it does not have to run on the vendor's infrastructure.

Source: https://www.sonarsource.com/jp/plans-and-pricing/

What does SonarQube integrate with?

We have confirmed 17 integrations for SonarQube, including GitHub, GitLab, Bitbucket, Azure DevOps, CodeCatalyst, CircleCI, TravisCI and Jenkins, plus 9 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.

Source: https://www.sonarsource.com/jp/plans-and-pricing/

What security certifications does SonarQube have?

We have independently confirmed SOC 2, ISO 27001 and GDPR for SonarQube. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as SonarQube not holding them. Always confirm compliance directly before you rely on it.

Source: https://www.sonarsource.com/products/sonarqube/

Is SonarQube open source?

Yes. SonarQube is published under the LGPL-3.0 licence, a copyleft licence, so check its terms before embedding it in a closed-source product. Licence terms can change between releases, so verify against the repository for the version you intend to use.

Source: https://github.com/SonarSource/sonarqube

Where is SonarQube available?

SonarQube is available worldwide. Its primary markets are the United States and the EU. The vendor is headquartered in Switzerland.

Source: https://www.sonarsource.com/jp/plans-and-pricing/

SonarQube alternatives

Other devsecops tools we track, ranked by the same independent score.

All SonarQube alternatives, ranked →

Compare SonarQube

Side by side against other devsecops tools, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for SonarQube, not the verdict.

Balanced composite 71 / 100
high · 76%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Security posture700.2114.6
Reliability950.098.9
Capabilities1000.066.3
Development activity630.095.9
Pricing transparency1000.055.2
Release cadence840.054.4
Dependent projects450.062.8
Integrations380.062.4
Price level500.042.1
Security score490.042.1
Stars760.032.0
Package downloads00.140.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d100mediumsource · 2026-09-10 · 65%

Adoption

AttributeValueEvidence
Dependent repos497highsource · 2026-09-10 · 85%
Github stars10,969highsource · 2026-09-10 · 90%

Content

AttributeValueEvidence
Faq8 itemsmediumsource · 2026-09-10 · 65%

Features

AttributeValueEvidence
CapabilitiesSca: Yes · Dast: No · Sast: Yes · Sbom: Yes · Hosting: both · Ci native: Yesmediumsource · 2026-09-10 · 60%

Integrations

AttributeValueEvidence
Count20mediumsource · 2026-08-14 · 60%

Language

AttributeValueEvidence
PrimaryJavahighsource · 2026-09-10 · 90%

License

AttributeValueEvidence
SpdxLGPL-3.0highsource · 2026-09-10 · 95%

Market

AttributeValueEvidence
AvailabilityPrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …mediumsource · 2026-09-10 · 50%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-09-10 · 60%
Modelfreemiummediumsource · 2026-09-10 · 60%
Price levelmidmediumsource · 2026-09-10 · 60%
TransparentYesmediumsource · 2026-09-10 · 60%
Starting priceAmount: 32 · Currency: USDmediumsource · 2026-09-10 · 60%

Release

AttributeValueEvidence
Cadence days28mediumsource · 2026-09-10 · 70%
History20 itemsmediumsource · 2026-09-10 · 70%

Reliability

AttributeValueEvidence
Sla pct99.9mediumsource · 2026-09-10 · 60%
Status pageYesmediumsource · 2026-08-14 · 60%

Security

AttributeValueEvidence
Soc2Yesmediumsource · 2026-09-10 · 60%
GdprYeshighsource · 2026-08-14 · 75%
Iso27001Yeshighsource · 2026-08-14 · 75%
Scorecard4.9highsource · 2026-09-10 · 90%
VulnerabilitiesCount: 1 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.sonarsource.sonarqube%3Asonar-plugin-api&per_page=100 · Last 12m: 0 · Max severity: MODERATEhighsource · 2026-09-10 · 90%
CertificationsSOC 2 Type IImediumsource · 2026-09-10 · 60%
Still deciding?

Is SonarQube the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank SonarQube against the rest of the devsecops tools we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of SonarQube

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves SonarQube up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows SonarQube's independent score and links back to this profile.

SonarQube, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/sonarqube" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/sonarqube.svg" alt="SonarQube, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![SonarQube, verified on vioscaleAI](https://www.vioscale.ai/badge/software/sonarqube.svg)](https://www.vioscale.ai/software/sonarqube)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing SonarQube. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim SonarQube

Not the owner? How vendor profiles work