CodeThreat
AI-assisted code security scanning for development teams.
At a glance
- Editor score8.0 / 10
- PricingFree plan · paid from $39/mo
- Best forSmall teams wanting a broad free AppSec starter
- Free planYes
- Facts checked24 Sep 2026
Where it wins
- Free Plan includes SAST and SCA scanning.
- Scans can cover IaC, secrets, repositories, and pull requests.
- Integrates with GitHub, GitLab, Azure DevOps, and CI/CD tools.
Where it doesn't
- Free Plan limits agentic PR review and false-positive elimination.
- Pro pricing is $39 per contributor per month.
- On-premises deployment and dedicated support are Enterprise features.
Our verdict on CodeThreat
CodeThreat brings static application security testing together with software composition analysis, infrastructure-as-code checks, and secret scanning. It is aimed at development teams that want security findings in repository and pull-request workflows, rather than a standalone SAST tool. AI-assisted project-wide code review, repository mapping, and false-positive review add analysis around the findings. Small teams can start with the Free Plan; teams needing broader controls can consider Pro or Enterprise.
Workflow fit is one of CodeThreat’s clearest strengths. It integrates with GitHub, GitLab, Azure DevOps, Bitbucket Cloud, and Bitbucket Server, and supports CI/CD tools including GitHub Actions, Jenkins, and Bamboo. Pull-request scanning and security feedback connect checks to code changes, while custom pattern-based and semantic rules allow teams to define additional security checks. The product is available through web and API access, with cloud and self-hosted deployment options. This breadth may suit teams consolidating several code-security checks in their development workflow; teams seeking only SAST may find the range broader than they need.
The Free Plan includes SAST and SCA scanning, but limits agentic PR review and false-positive elimination. Pro is priced at $39 per contributor per month and adds role-based access control, secret scanning, infrastructure security, Jira integration, and vulnerability reports and exports. Enterprise adds on-premises deployment, SLA and dedicated support, advanced compliance reporting, and private LLM hosting options. The per-contributor Pro model is worth weighing as a team grows. CodeThreat fits teams that value a free starting tier and multiple security checks; buyers who need the Enterprise deployment or support options should assess that tier, while teams focused on a narrower SAST workflow may prefer a more specialized product.
CodeThreat pricing
All 3 CodeThreat plans and prices →
CodeThreat fact sheet
| Free plan | Yes |
|---|---|
| Paid from | Not verified |
| Languages supported | Not verified |
| IDE integration | Not verified |
| CI/CD integration | Yes |
| Deployment | Both |
| Custom rules | Yes |
| Pull request scanning | Yes |
| Deployment | Cloud, Self-hosted |
| Platforms | Web |
| Compliance & security | GDPR, ISO 27001 |
| Support | Email, Community |
| Built for | Small business, Mid-market, Enterprise (editorial estimate) |
| Integrations | 9 integrations: GitHub, GitLab, Azure DevOps, Bitbucket Cloud, Bitbucket Server, GitHub Actions … |
| Pricing | Free plan · paid from $39/mo (source) |
| Website | codethreat.com |
| Facts checked | 24 Sep 2026 |
CodeThreat integrations
CodeThreat lists 9 integrations on its own site.
- GitHub
- GitLab
- Azure DevOps
- Bitbucket Cloud
- Bitbucket Server
- GitHub Actions
- Jenkins
- Bamboo
- Jira
Alternatives to CodeThreat
- Checkmarx SASTBroad source analysis with custom queries and remediation guidance for enterprise teams.—
- Snyk CodeSource-code scanning across IDEs, pull requests and CI/CD, with a free entry tier.7.0
- OpenText Fortify SASTBroad SAST coverage with pull-request scans, custom rules, and AI-assisted fixes.—
See all CodeThreat alternatives →
Used CodeThreat? Be the first to review it
The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used CodeThreat for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.
Write a reviewTwo minutes · verified accounts only · read by an editor before it appears
Featured on iTechGuides
CodeThreat is listed in our Static Application Security Testing Sast directory. Add the badge to your site — it links back to this page.
<a href="https://www.itechguides.com/products/codethreat/"><img src="https://www.itechguides.com/best/badge/codethreat.svg" alt="Featured on iTechGuides" width="230" height="46"></a>
Reviewed by iTechGuides Editors · Editorial team · Updated Sep 2026
Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. It never changes a score or a verdict. How we rank.

