EveryDev.ai
Sign inSubscribe
Explore AI Tools
  • AI Coding Assistants
  • Agent Frameworks
  • MCP Servers
  • AI Prompt Tools
  • Vibe Coding Tools
  • AI Design Tools
  • AI Database Tools
  • AI Website Builders
  • AI Testing Tools
  • LLM Evaluations
Follow Us
  • X / Twitter
  • LinkedIn
  • Reddit
  • Discord
  • Threads
  • Bluesky
  • Mastodon
  • YouTube
  • GitHub
  • Instagram
Get Started
  • About
  • Editorial Standards
  • Corrections & Disclosures
  • Community Guidelines
  • Advertise
  • Contact Us
  • Newsletter
  • Submit a Tool
  • Start a Discussion
  • Write A Blog
  • Share A Build
  • Terms of Service
  • Privacy Policy
Explore with AI
  • ChatGPT
  • Gemini
  • Claude
  • Grok
  • Perplexity
Agent Experience
  • llms.txt
Theme
With AI, Everyone is a Dev. EveryDev.ai © 2026
Main Menu
  • Tools
  • Developers
  • Topics
  • Discussions
  • Communities
  • News
  • Podcasts
  • Blogs
  • Builds
  • Contests
  • Compare
  • Arena
Create
    Home
    Tools

    2,407+ AI tools

    • New
    • Trending
    • Featured
    • Compare
    • Arena
    Categories
    • Agents1565
    • Coding1169
    • Infrastructure524
    • Marketing445
    • Design418
    • Projects381
    • Research353
    • Analytics328
    • Testing219
    • MCP207
    • Data203
    • Security189
    • Integration168
    • Learning154
    • Communication144
    • Prompts138
    • Extensions133
    • Commerce123
    • Voice122
    • DevOps97
    • Web75
    • Finance21
    1. Home
    2. Tools
    3. Codacy
    Codacy icon

    Codacy

    Code Review

    Codacy is a code quality and security platform that automates code reviews, enforces coding standards, and governs AI-generated code across the entire software development lifecycle.

    Visit Website

    At a Glance

    Pricing
    Free tier available

    Free forever for open-source projects and public repositories.

    Pro: Custom/contact
    Business: Custom/contact

    Engagement

    Available On

    Web
    API
    VS Code
    JetBrains

    Resources

    WebsiteDocsGitHubllms.txt

    Topics

    Code ReviewApplication Security3D and Animation

    Alternatives

    SonarQubeHackerOne CodeGuardix
    Developer
    CodacyLisbon, PortugalEst. 2012$32.5M raised

    Listed May 2026

    About Codacy

    Codacy is a cloud-based code quality and security platform built for engineering teams working with AI-assisted development. It integrates with GitHub, GitLab, and Bitbucket to scan repositories, pull requests, and IDE sessions for quality violations, security vulnerabilities, and AI coding policy breaches. The platform is actively developed by a 57-person team across 6 countries, with the company reporting over 15,000 organizations onboarded according to its About page.

    What It Is

    Codacy sits in the code quality and application security category, functioning as a unified platform that replaces multiple point tools for static analysis, dependency scanning, secret detection, and AI governance. It operates as a 100% cloud-hosted service — no CI/CD pipeline integration is required — using webhooks to trigger scans on every commit and pull request. The platform covers 49 programming languages and frameworks, and extends into the IDE via plugins for VS Code, JetBrains, and Cursor.

    Core Scanning Capabilities

    Codacy bundles several distinct scan types into a single platform:

    • SAST — static application security testing for vulnerabilities like SQL injection
    • SCA / Dependency scanning — detects insecure or malicious packages, with daily CVE database re-scans
    • Secret scanning — finds hardcoded credentials and passwords
    • Infrastructure-as-Code (IaC) scanning — detects misconfigurations in infrastructure definitions
    • DAST — dynamic application security testing for runtime vulnerabilities
    • Container image scanning — CVE detection in container images
    • Code quality analysis — error-prone patterns, complexity, duplications, unused code, and style violations across 49 languages
    • Test coverage tracking — monitors coverage per file and enforces merge gates

    AI Governance Layer

    A distinguishing feature of Codacy is its AI-specific governance tooling, which the product page describes as "AI Guardrails," "AI Inventory," and "AI Risk Hub." These modules enforce organization-defined AI coding policies — blocking unapproved model calls, detecting prompt injection risks, and flagging vulnerable libraries inherited from outdated AI training data. The Guardrails component scans AI-generated code as it is being written inside the IDE, enabling agents to auto-fix issues before a developer sees the output. This positions Codacy as a governance layer for agentic coding workflows using tools like GitHub Copilot, Claude, Cursor, and Windsurf.

    Where It Fits in the Stack

    Codacy integrates at multiple points in the development workflow:

    • IDE — VS Code, JetBrains, and Cursor plugins provide real-time local scanning
    • Git — GitHub Cloud, Bitbucket Cloud, and GitLab Cloud (self-hosted Git providers are not supported)
    • Pull Requests — automated AI reviewer with fix suggestions, PR summaries, and false positive detection
    • Containers — JFrog, Amazon ECR, and Docker registries
    • Issue tracking — two-way Jira integration
    • Alerts — Slack integration for critical security notifications
    • AWS Marketplace — available for purchase through AWS

    Compliance and Reporting

    The platform generates audit-ready outputs including SBOM exports, SLA remediation tracking, and real-time security and risk dashboards. The company states its cloud infrastructure is SOC2 Type 2 certified. Compliance-relevant scan reports are described as supporting SOC2 and ISO27001 requirements. The pricing page notes that open-source projects can use the platform for free indefinitely, while private repository access requires a paid subscription.

    Current Status

    Codacy is actively developed and commercially available. The About page lists 57 employees with 51% in product and engineering roles. The platform recently launched AI Inventory as a new module, noted in a site-wide banner. IDE plugin support for VS Code and JetBrains is live, with Cursor also listed as a supported environment. The company publishes a public roadmap at roadmap.codacy.com and maintains documentation at docs.codacy.com.

    Codacy - 1

    Community Discussions

    Be the first to start a conversation about Codacy

    Share your experience with Codacy, ask questions, or help others learn from your insights.

    Pricing

    FREE

    Open Source

    Free forever for open-source projects and public repositories.

    • Unlimited public repositories
    • GitHub, Bitbucket & GitLab integration
    • Cloud-hosted code quality & security scans
    • AI Reviewer & merge gates for pull requests
    • Shared coding standards across 49 languages
    FREE

    IDE Plugin

    Free IDE plugin for VS Code, JetBrains, and Cursor with local real-time scanning.

    • Auto-fix AI code before it reaches the editor
    • Scan-as-you-type
    • Security scans (SAST, SCA, Secrets)
    • Code quality scans
    • Agent handoff for auto-fixing issues

    Pro

    For individuals and teams of up to 30 contributors working on up to 100 private projects.

    Custom
    contact sales
    • Up to 100 private repos & unlimited LOC
    • GitHub, Bitbucket & GitLab integration
    • Cloud-hosted code quality & security scans
    • AI Reviewer & merge gates for pull requests
    • Shared coding standards across 49 languages
    • Trends across teams & projects
    • Coverage reports & merge policies
    • Malicious package detection
    • Jira + Slack integration

    Business

    For engineering organizations with more than 30 contributors or more than 100 private projects, with advanced security, reporting, and support.

    Custom
    contact sales
    • Unlimited private projects
    • Priority scan queue
    • Daily re-scans against new CVEs
    • AI Inventory + AI Risk Hub
    • DAST
    • Container image scanning
    • False positive detection
    • Custom rules
    • SSO/SAML + audit logs
    • Dedicated CSM + premium support
    View official pricing

    Capabilities

    Key Features

    • Automated code quality analysis across 49 languages
    • SAST vulnerability scanning
    • Software Composition Analysis (SCA) / dependency scanning
    • Hardcoded secrets and password detection
    • Infrastructure-as-Code (IaC) misconfiguration detection
    • DAST (pipeline-less runtime scans)
    • Container image scanning
    • AI Guardrails for agentic workflows
    • AI Inventory and AI Risk Hub
    • AI coding policy enforcement
    • AI-powered pull request reviewer with fix suggestions
    • False positive detection
    • Test coverage tracking and merge gates
    • Daily CVE and malicious package re-scans
    • SBOM exports
    • License scanning
    • Two-way Jira integration
    • Slack integration for critical security alerts
    • Org-wide coding standards across 49 languages
    • Real-time commit and pull request scans
    • Pull request merge gates
    • Custom scan rules
    • SOC2 Type 2-certified cloud infrastructure
    • SSO/SAML and audit logs
    • Configurable SLA remediation due date tracking
    • Organization-wide security and risk management dashboard
    • IDE plugins for VS Code, JetBrains, and Cursor

    Integrations

    GitHub Cloud
    GitLab Cloud
    Bitbucket Cloud
    VS Code
    JetBrains
    Cursor
    Windsurf
    GitHub Copilot
    Claude
    Gemini
    Jira
    Slack
    JFrog
    Amazon ECR
    Docker
    AWS Marketplace
    API Available
    View Docs

    Reviews & Ratings

    No ratings yet

    Be the first to rate Codacy and help others make informed decisions.

    Developer

    Codacy Team

    Codacy builds a unified code quality and security platform for engineering teams shipping AI-assisted software. The platform automates code reviews, enforces coding standards across 49 languages, and governs AI-generated code from prompt to production. Led by CEO Jaime Jorge and CTO Kendrick Curtis, the 57-person team operates across 6 countries with over 15,000 organizations onboarded. Codacy differentiates through its AI Guardrails and AI Risk Hub modules, which enforce organization-defined AI coding policies inside IDEs and agentic workflows.

    Founded 2012
    Lisbon, Portugal
    $32.5M raised
    66 employees

    Used by

    Panasonic
    Delivery Hero
    Harvey Nichols
    Schneider Electric
    +1 more
    Read more about Codacy Team
    WebsiteGitHubLinkedInX / Twitter
    1 tool in directory

    Similar Tools

    SonarQube icon

    SonarQube

    SonarQube is a static code analysis platform that detects bugs, security vulnerabilities, code smells, and secrets across 40+ programming languages to ensure code quality and security.

    HackerOne Code icon

    HackerOne Code

    Expert code review and security guidance platform that catches vulnerabilities earlier in development with AI and human expert review.

    Guardix icon

    Guardix

    AI-powered Solidity smart contract audit platform with multi-model analysis, architecture mapping, and exploit verification on forked chains.

    Browse all tools

    Related Topics

    Code Review

    Tools that help review, analyze, and improve code quality.

    73 tools

    Application Security

    AI tools for securing software applications and identifying vulnerabilities.

    66 tools

    3D and Animation

    AI-powered tools for creating, manipulating, and animating 3D models, characters, and environments with intelligent rigging, texturing, and motion synthesis.

    21 tools
    Browse all topics
    Back to all tools
    Discussions