Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

CodeQL for Visual Studio Code

Free#18 of 21 in IDE Code Security Plugins

Write, run, and test CodeQL queries in Visual Studio Code.

—Not yet scored
CodeQL for Visual Studio Code— Visit GitHub

At a glance

  • Editor score
    Not yet scored
  • Pricing
    Free plan
  • Best for
    CodeQL specialists building custom security queries
  • Free plan
    Yes
  • Paid from
    None
  • IDE coverage
    Single
  • Facts checked
    26 Sep 2026
  • Where it wins

    • Write and test custom queries, libraries, and query packs in VS Code
    • Inspect data-flow paths and run queries against CodeQL databases
    • Run variant analysis across multiple repositories
  • Where it doesn't

    • Works in Visual Studio Code rather than across multiple IDEs
    • The extension supports CodeQL/QL, a single language
    • Some private or organization-owned repositories may require GitHub Code Security licensing

Our verdict on CodeQL for Visual Studio Code

CodeQL for Visual Studio Code is GitHub’s editor extension for developers who write, run, and test CodeQL queries against databases. It is aimed at CodeQL specialists building custom security queries, rather than developers seeking general code-quality checks or fixes inside the editor. The extension is free, open source, and available for Visual Studio Code on Windows, macOS, and Linux. Its focus is the CodeQL/QL language, with query and library authoring supported by IntelliSense, autocomplete, and Go To Definition.

The main draw is the query workflow. Users can run queries against one or more CodeQL databases, inspect data-flow paths in results, and browse and run queries from the open-source CodeQL security query repository. The extension also supports creating and editing query, library, and model packs, running unit tests for queries, and viewing variant analysis across multiple repositories. Those tools make it suited to teams that need to develop and validate CodeQL queries, though its single-language and single-IDE scope is a poor fit for broader multi-language security work or teams using another editor.

The extension connects with the CodeQL CLI and GitHub repositories, while access to CodeQL capabilities depends on repository type and GitHub Code Security licensing. Although the extension itself is free and MIT-licensed, according to the vendor, use with certain private or organization-owned repositories may require a Code Security license. Published support is through documentation. Choose it if your work centers on authoring CodeQL queries in VS Code and you can meet any applicable licensing requirements; consider another tool if you need broader language coverage, in-editor fixes, or support beyond documentation.

CodeQL for Visual Studio Code pricing

Plans Free planFree Free to use — no paid tier required for the core job.
See plans on github.com

CodeQL for Visual Studio Code fact sheet

Free planYes
Paid fromNone
IDE coverageSingle
Security analysisYes
Taint analysisYes
Code quality checksNo
In-IDE fixesNo
Languages supported1
DeploymentDesktop
PlatformsWindows, macOS, Linux
SupportDocs
Built forSolo, Small business, Mid-market, Enterprise (editorial estimate)
Integrations3 integrations: Visual Studio Code, CodeQL CLI, GitHub repositories
PricingFree plan
Websitegithub.com
Facts checked26 Sep 2026

CodeQL for Visual Studio Code integrations

CodeQL for Visual Studio Code lists 3 integrations on its own site.

  • Visual Studio Code
  • CodeQL CLI
  • GitHub repositories

Alternatives to CodeQL for Visual Studio Code

See all CodeQL for Visual Studio Code alternatives →

Used CodeQL for Visual Studio Code? Be the first to review it

The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used CodeQL for Visual Studio Code for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.

Write a reviewTwo minutes · verified accounts only · read by an editor before it appears

Reviews come only from verified accounts. Sign in or create an account first — your e-mail is never shown.

Your rating

0 characters · at least 80, up to 3,000

Posted from your verified account. Reviews appear after an editor reads them, usually within two working days.

Featured on iTechGuides

Featured on iTechGuides — CodeQL for Visual Studio Code —/10

CodeQL for Visual Studio Code is listed in our IDE Code Security Plugins directory. Add the badge to your site — it links back to this page.

<a href="https://www.itechguides.com/products/codeql-for-visual-studio-code/"><img src="https://www.itechguides.com/best/badge/codeql-for-visual-studio-code.svg" alt="Featured on iTechGuides" width="230" height="46"></a>

Reviewed by iTechGuides Editors · Editorial team · Updated Sep 2026

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. It never changes a score or a verdict. How we rank.