Pricing

Plans and pricing

Try enterprise-grade code verification without the surprise usage bills. 14-day trial on paid plans, and a free tier that never expires.

SonarQube plans

Code verification and governance for the AI era

Cloud-hosted analysis for your CI/CD workflows. Priced per instance per year, based on your lines of code.

Team

Team

Essential capabilities for small teams

Starts at
$34monthly
Includes:
  • Recommended for teams <50 developers
  • 30+ languages
  • Code quality standards
  • Detecting bugs and vulnerabilities
  • Secrets detection
  • AI-driven code fixes
  • Pull request analysis
  • Architecture management
  • Commercial support available
Need SonarQube for an OSS project?
Gitar plans

AI code review that turns your PRs green

Fixes validated against your CI pipeline. Try the full platform free for 14 days.

Best for getting started

Core

Unlimited public & private repos · Up to 50 users

$20/ user / mo
$25/ user / mo
Billed annually · 14-day free trial Billed monthly · 14-day free trial
Get started
Includes:
  • Fully customizable code reviews
  • Automatic PR summaries
  • CI failure analysis (GitHub Actions, GitLab Pipelines)
  • Fixes via comments (Ask Gitar to fix issues on your PRs)
  • Interactive agent on your PRs
  • Developer insights
Comprehensive platform engineering

Enterprise

Unlimited public & private repos · Unlimited users

Contact us
Custom pricing & agreements
Book a demo
Everything in Pro, plus:
  • Self-hosted Code Hosting
  • Bring your own LLM API key
  • SSO / SAML
  • Custom deployment options
  • Audit logs
  • Dedicated support
  • Custom agreements
  • Custom integrations
  • API access
New

Free for Open Source

Open source projects get Gitar at no cost. Includes all the same features as the Pro plan.

Public repository

On GitHub or GitLab

OSI-approved license

MIT, Apache-2.0, GPL, and more

Also available

For your agent-centric development

Add Sonar Agent essentials, SonarQube Advanced Security, and SonarQube Hunter Agent to extend SonarQube across the agent-centric development cycle. Built on your SonarQube plan, not beside it.

Agentic package · Team and Enterprise

Sonar Agent Essentials

Context and verification for AI agents

Custom pricing
Usage based
Includes:
  • Sonar Vortex: Guide agents with your architecture and standards before they write, then verify every output in real time inside the inner loop.
    • Inject context and constraints
    • Verify code in the agent loop
  • Remediation Agent: Opens verified-fix PRs automatically. Build must pass before merge.
  • Integrated with agents using:
    • SonarQube CLI: Unified CLI for agentic workflows. Run analysis from any terminal, CI pipeline, or coding agent.
    • SonarQube MCP Server: Bring code quality and security into your AI workflow. Open source and free.
    • SonarQube agent plugins: Slash commands and quality gates for Claude Code, Gemini, and Kiro.
For Team and Enterprise

Advanced Security

Advanced SAST and supply-chain security

Custom pricing
Custom pricing
Includes:
  • CVE detection
    Identify known vulnerabilities in open source dependencies, prioritized by severity and exploitability.
  • Malicious package detection
    Block compromised and malicious libraries from entering your supply chain in real time.
  • Dependency-aware taint analysis
    Traces data flow across code boundaries into third-party libraries — uncovering complex vulnerabilities that cross-file analysis alone misses.
  • SBOM Enterprise
    Generate and export a complete software bill of materials for every project.
  • License policy management Enterprise
    Define and enforce open source license policies across all projects and dependencies.
For Enterprise

SonarQube Hunter Agent

AI agent for logic-based vulnerabilities

Custom pricing
Custom pricing
Includes:
  • Finds logic-based vulnerabilities
    Uncovers broken access control, business logic abuse, and authentication and session issues, the vulnerabilities that depend on intent, not a code pattern
  • Reasons like a security researcher
    Runs structured playbooks that trace code, data, and identity flows across the whole codebase, rather than matching patterns.
  • Runs in the background
    Scan on demand or on schedule, with no pull request or CI slowdown.
  • Native to your workflow
    Findings arrive as SonarQube issues, auto-tagged and CWE-severity mapped, ready to triage and fix. Nothing to install.
  • Complements SAST and SCA
    Adds a reasoning layer to SonarQube's deterministic analysis, for coverage no single method delivers.
Feature comparison

Compare SonarQube plans

Capability
Team$34 monthly
★ Most teams choose thisEnterpriseCustom pricing
SonarQube MCP Server
SonarQube CLI
AI Code Assurance
AI-driven code fixes
Detect issues in AI-generated code
Languages and frameworks supported30+40+
Quality gates and profiles
Architecture management
Technical debt management
Enforce custom coding standards
Test coverage
Pull request and branch analysis
SAST
Taint analysis
Secrets detection
IaC scanning
SCA and Advanced SASTIncluded in Advanced Security
OWASP Top 10, CWE, PCI DSS, STIG, CASA
MISRA C++:2023 compliance
Cyber Resilience Act (CRA) compliance
GitHub Advanced Security integration
Security reports and audit logs
Unlimited users and projects
SSO, SCIM, CMK/BYOK
IP allowlist
Enterprise hierarchy and portfolios
Customizable dashboards
Enterprise SLA
Premium supportAdd-onAdd-on

Frequently asked questions

How does pricing work for private projects?

Do you offer pricing for a self-hosted solution?

What payment options are available?

What is a Line of Code (LOC) on SonarQube?

How are Lines of Code (LOCs) counted towards billing?

When will I be invoiced?

Which programming languages does SonarQube Cloud support?

Is support available for SonarQube?

Can I try a private project on SonarQube for free?

Can I cancel my subscription?

Can I try the enterprise features?

How can I get SCA?

Is SonarQube Free?

How much does SonarQube cost?