Skip to content
Z Zendikt
C

Codacy review and pricing

Modern developer-first code quality and security.

By Codacy · Founded 2012 · Lisbon, Portugal · private

Codacy is the modern developer-first code-quality platform, founded 2012 in Lisbon and last raising a Series B (reported around $15M) in 2020 led by Bright Pixel Capital. The product covers code quality, code coverage, and security (Codacy Security launched 2022 with Trivy and Semgrep under the hood). Strengths: cleaner UX than SonarQube, faster onboarding, transparent per-developer SaaS pricing, and PR-time feedback that engineering teams adopt without security-team pressure. Best fit for engineering-led teams under roughly 500 engineers that want a single tool for code quality plus a competent security signal. Trade-offs: narrower language depth than SonarQube, security analysis depth lags Snyk Code and CodeQL, the self-hosted option is functional but less mature than SonarQube self-managed, and the vendor footprint is small enough that procurement teams sometimes push back on it.

Best for

Engineering-led teams (20 to 500 engineers) that want one tool for code quality, code coverage, and a competent security signal without security-team-led procurement. Particularly strong for EU-headquartered organizations needing GDPR-native data residency.

Worst for

Very large enterprises (1,000+ engineers) where SonarQube Enterprise scales further, AppSec-led organizations wanting deepest SAST (Snyk Code, CodeQL, Semgrep better), or buyers needing 30+ language coverage (SonarQube better).

Vendor Trust Score

Is Codacy a trustworthy vendor?

7.8/10
Mixed
Pricing transparency
Published rates; no hidden fees
8.5
Contract fairness
Reasonable terms; no auto-renew traps
8.0
Incident response
How they handle outages and breaches
7.5
Post-acquisition behavior
Customer treatment after M&A or PE
8.0
Executive stability
Leadership churn over 24 months
7.5
Roadmap honesty
Public commitments held
7.5
Trust signal log
  • 2020-06-15
    Series B led by Bright Pixel Capital
    Reported around $15M; funded the Codacy Security expansion delivered in 2022.
  • 2022-09-22
    Codacy Security launched
    Bundled SAST, SCA, secret detection under one product; Trivy plus Semgrep rule sets under the hood.
  • 2024-04-15
    Roadmap velocity slower after 2022 reorganization
    Customer reports of slower feature delivery through 2023-2024; some feature parity gaps with SonarQube widened.
Vendor Trust is scored independently of product quality. A great product from an unfair vendor still earns a low trust score.
Review Intelligence

What 380 reviews actually say

Synthesized from G2, Capterra, Reddit, Trustpilot. Patterns >15% prevalence shown.

Last synthesized
2026-04-29

Praise patterns

  • Cleaner UX than SonarQube; faster time-to-value
    87%
  • Transparent per-developer pricing
    78%
  • PR decoration across all major Git platforms
    71%
  • EU-headquartered GDPR-native data residency
    51%

Complaint patterns

  • Narrower language depth than SonarQube on niche languages
    47%
  • Security analysis depth lags Snyk Code and CodeQL
    41%
  • Roadmap velocity slower since 2022 reorganization
    38%
  • Self-hosted less mature than SonarQube self-managed
    31%
Sentiment trend (6 months)
79/100 0 pts
12
01
02
03
04
05
Patterns are extracted from review corpus and human-verified. We surface trends, not anecdotes.
Verified Pricing

What buyers actually pay

214 anonymized deal disclosures · last updated 2026-05-01

Contribute your deal price
Company size Median annual
10 to 50 engineers (Pro) $216
50 to 500 engineers (Business) $324
500+ engineers (Self-hosted) $84,000
Verified pricing is crowdsourced from buyers under anonymity guarantees. Vendor-listed prices are validated against actual deals quarterly.
Compliance & Security

Auto-verified certifications

Verified 2026-05-01
SOC 2 Type II
ISO 27001
HIPAA
GDPR
CCPA
PCI DSS
FedRAMP

Editorial: Strengths

  • Cleaner UX than SonarQube; faster time-to-value
  • Transparent per-developer SaaS pricing (no LOC surprises)
  • PR decoration on GitHub, GitLab, Bitbucket out of the box
  • Code coverage plus quality plus security in one product
  • Codacy Security (2022) bundles Trivy, Semgrep, Trufflehog rule sets
  • EU-headquartered (Lisbon); GDPR-native data residency
  • Open-source Codacy Analysis CLI keeps the developer trust signal honest

Editorial: Weaknesses

  • Narrower language depth than SonarQube on niche languages (Apex, COBOL, ABAP)
  • Security analysis depth lags Snyk Code and CodeQL on semantic findings
  • Self-hosted (Codacy Self-hosted) less mature than SonarQube self-managed
  • Procurement pushback on vendor size in Fortune 500 buyers
  • False-positive rate on security findings reported around 20 percent in buyer disclosures
  • Roadmap velocity slower since the 2022 reorganization

Key features & integrations

  • +Static analysis across 40+ languages
  • +PR decoration on GitHub, GitLab, Bitbucket
  • +Code coverage with merge-time quality gates
  • +Codacy Security (Trivy, Semgrep, Trufflehog under the hood)
  • +Issue auto-fix suggestions
  • +Custom coding standards plus reusable patterns
  • +Self-hosted air-gap deployment option
  • +SAML SSO, SCIM, audit logging at Business
  • +REST API plus webhooks
  • +Codacy Analysis CLI (open-source)
80+ integrations
GitHubGitLabBitbucketAzure DevOpsSlackJiraVS CodeIntelliJ
Geography supported
Global; strongest in EU, US, UK
Best fit
10 to 1,000 employees · Engineering-led teams wanting code quality plus a security signal
Editorial deep-dive

Read our full ranking of Code Quality and Static Analysis

Codacy ranks #2 in our editorial review of 10 code quality and static analysis platforms. The deep-dive covers methodology, comparison tables, decision matrix, migration scoring, and FAQs.

Read the full ranking

Closest alternatives in Code Quality and Static Analysis

Help the next buyer

Contribute your verified deal price

Pricing in B2B software is opaque because vendors want it that way. Verified buyer prices fix that, anonymously. Share what you actually paid for Codacy; we’ll add it to the verified pricing dataset on this page (with company size band only, no identifying details).

Submit anonymously