# SonarQube

> Fight AI Slop & Verify AI Code

- **Canonical URI:** https://www.vioscale.ai/software/sonarqube
- **Category:** DevSecOps Tools
- **Homepage:** https://www.sonarsource.com/products/sonarqube/
- **Also known as:** sonarqube
- **Profile claimed by vendor:** no
- **Last updated:** 2026-08-01T16:09:00.648Z

## Vioscale score

**54.7 / 100**, confidence 36% (low).

Composite of weighted, independently-sourced signals (no user reviews, no vendor payment).

| Signal | Score | Weight | Contribution | Evidence present |
|---|--:|--:|--:|:--:|
| price_level | 100 | 8 | 800 | ✓ |
| reliability | 0 | 18 | 0 | - |
| capabilities | 86.7 | 12 | 1040.6 | ✓ |
| github_stars | 76.1 | 5 | 380.6 | ✓ |
| integrations | 20.1 | 12 | 241.2 | ✓ |
| github_activity | 63.1 | 18 | 1135.8 | ✓ |
| release_cadence | 84.4 | 10 | 844.4 | ✓ |
| security_posture | 40 | 40 | 1600 | ✓ |
| package_downloads | 0 | 26 | 0 | - |
| pricing_transparency | 25 | 10 | 250 | ✓ |
| stackoverflow_activity | 0 | 12 | 0 | - |

## Pricing

_As of 2026-08-01, [verify at source](https://www.sonarsource.com/products/sonarqube/). Independently observed._

Free · Free tier

## About

Static analysis platform for code quality and security with cloud and self-managed deployment options, designed for CI/CD workflows with AI-powered code review capabilities.

_Independently observed._

## Platform & deployment

- **Platforms:** CLI, Web
- **Deployment:** Cloud / SaaS, Self-hosted

## Integrations (4)

_Independently observed._

- GitHub
- Bitbucket
- Azure DevOps
- GitLab

## Capabilities

_The capabilities that matter for DevSecOps Tools. "-" = undocumented, not absent._

| Capability | Supported |
|---|:--:|
| **Scan types** | |
| SAST (static analysis) | ✓ |
| DAST (dynamic analysis) | - |
| SCA / dependency scanning | ✓ |
| Secret scanning | ✓ |
| Container / image scanning | - |
| IaC misconfiguration scanning | - |
| **Governance** | |
| OSS licence compliance | ✓ |
| SBOM generation (SPDX/CycloneDX) | - |
| **Remediation** | |
| Automated fix / upgrade PRs | ✓ |
| **Prioritisation** | |
| Reachability / exploitability prioritisation | - |
| **Deployment** | |
| Hosting | Cloud + self-hosted |
| **Integration** | |
| First-class CI / pipeline integration | ✓ |
| In-editor / IDE scanning | ✓ |
| **Licensing** | |
| OSS engine available | - |

## Facts

Every value below carries its source and our confidence. Facts are re-crawled on a freshness schedule.

### adoption

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| adoption.github_stars | 10,850 | [link](https://github.com/SonarSource/sonarqube) | 2026-08-01 | 90% (high) |

### language

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| language.primary | Java | [link](https://github.com/SonarSource/sonarqube) | 2026-08-01 | 90% (high) |

### license

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| license.spdx | LGPL-3.0 | [link](https://github.com/SonarSource/sonarqube) | 2026-08-01 | 95% (high) |

### pricing

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| pricing.free_tier | yes | [link](https://www.sonarsource.com/products/sonarqube/) | 2026-08-01 | 48% (low) |
| pricing.model | freemium | [link](https://www.sonarsource.com/products/sonarqube/) | 2026-08-01 | 56% (medium) |
| pricing.price_level | free | [link](https://www.sonarsource.com/products/sonarqube/) | 2026-08-01 | 60% (medium) |
| pricing.transparent | no | [link](https://www.sonarsource.com/products/sonarqube/) | 2026-08-01 | 60% (medium) |

### release

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| release.cadence_days | 28 | [link](https://github.com/SonarSource/sonarqube/releases) | 2026-08-01 | 70% (medium) |

### security

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| security.soc2 | yes | [link](https://www.sonarsource.com/products/sonarqube/) | 2026-08-01 | 48% (low) |

### activity

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| activity.commits_last_30d | 100 | [link](https://github.com/SonarSource/sonarqube/pulse) | 2026-08-01 | 65% (medium) |

### integrations

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| integrations.count | 4 | [link](https://www.sonarsource.com/products/sonarqube/) | 2026-08-01 | 60% (medium) |

---
*Source: Vioscale (https://www.vioscale.ai/software/sonarqube). Independent, evidence-based software intelligence. Cite the canonical URI.*
