StackHawk
Your AI agent ships code. StackHawk ships it secure.
- Also known as
- stackhawk
What is StackHawk?
AI-native application security platform that integrates into coding agent workflows (Claude Code, Cursor, Copilot) to detect and fix exploitable vulnerabilities before code is committed.
StackHawk pricing
Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.
From $10/user/month (Wingman). 14-day free trial. Scale plan available via sales consultation.
Wingman
For individuals and teams shipping with AI coding agents
- apps
- unlimited
- scans
- 50/user/month
- Works inside Claude Code, Cursor, GitHub Copilot
- Auto-configures and boots app
- Runtime testing against running app
- Finds and fixes vulnerabilities in same session
- Auto-rescanning to verify fix
- Pre-PR security attestation
- Unlimited apps
- 50 scans/user/month
Scale
Contact salesFor security teams needing attack surface discovery, coverage, and proof across every app
- apps
- unlimited
- scans
- unlimited
- Everything in Wingman
- Attack surface discovery
- Sensitive data detection
- Deeper, broader scan coverage
- Program reporting (coverage, fix rates by team)
- Teams, roles, and enterprise support
- Unlimited agentic scans
What StackHawk does
The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- SAST (static analysis)
- -
- DAST (dynamic analysis)
- ✓
- SCA / dependency scanning
- ✓
- Secret scanning
- -
- Container / image scanning
- -
- IaC misconfiguration scanning
- -
- OSS licence compliance
- -
- SBOM generation (SPDX/CycloneDX)
- -
- Automated fix / upgrade PRs
- ✓
- Reachability / exploitability prioritisation
- ✓
- Hosting
- Cloud only
- First-class CI / pipeline integration
- ✓
- In-editor / IDE scanning
- ✓
- OSS engine available
- -
Platform & deployment
Independently observed- CLI
- Web
- Cloud / SaaS
Integrations (5)
Independently observed- Claude Code
- Cursor
- GitHub Copilot
- Codex
- Antigravity
StackHawk alternatives
Other devsecops tools we track, ranked by the same independent score.
- Endor LabsSpeed or security. The best teams code without compromise.low · 36%
- SemgrepAI-assisted SAST, SCA and Secrets Detectionmedium · 51%
- SnykAI Security Fabricmedium · 60%
- OWASP ZAPThe world's most widely used web app scanner. Free and open source.low · 13%
- MendSecure code, AI, and every interaction between themmedium · 53%
- GitGuardianFind every credential. Stop the next breach.medium · 60%
The Vioscale score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for StackHawk, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Security Posture | 45 | 40.00 | 1800.0 | ✓ |
| Pricing Transparency | 100 | 10.00 | 1000.0 | ✓ |
| Capabilities | 81 | 12.00 | 973.8 | ✓ |
| Reliability | 50 | 18.00 | 900.0 | ✓ |
| Price Level | 80 | 8.00 | 640.0 | ✓ |
| Integrations | 22 | 12.00 | 268.5 | ✓ |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | {"sca":true,"dast":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"reachability":true} | mediumsource · 2026-08-03 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 5 | mediumsource · 2026-08-03 · 60% |
Pricing
Reliability
| Attribute | Value | Evidence |
|---|---|---|
| Status page | Yes | mediumsource · 2026-08-03 · 60% |