SonarQube Server plans and pricing

Self-hosted editions for automated code review

Priced per instance, per year, based on your lines of code.

Developer

Essential capabilities for small teams

Includes:

  • Recommended for 100K+ lines of code
  • 34 languages & frameworks
  • Autodetect AI-generated code
  • AI Code Assurance
  • Advanced bug detection
  • Secrets detection
  • Architecture management

Data Center

Performance, high availability & scalability

Enterprise Edition, plus:

  • Recommended for 20M+ lines of code
  • Autoscaling based on demand
  • High performance for distributed teams

Feature comparison

Compare SonarQube Server plans

Capability
Developer
RecommendedEnterprise
Data Center
Contact
Recommended lines of code100K or above1M or above20M or above
DevOps platform integrationSupports one integration each for the following DevOps platforms• GitHub
• GitLab
• Bitbucket
• Azure DevOps
IDE synchronization with SonarQube for IDESupports the following IDEs• VS Code
• Visual Studio
• IntelliJ
• Eclipse
• Cursor
• Windsurf
Detect issues in AI generated code
Combine third-party tool results with SARIF reports
AutoConfig for C and C++ projects
Autoprovision users and groups from GitHub and GitLab
Automatically sync permissions with GitHub and GitLab
Integrate with unlimited numbers of DevOps platformsSupports the following• GitHub Actions
• GitLab CI/CD
• Bitbucket Pipelines
• Azure Pipelines
• Jenkins
• Codemagic
Consolidate projects into a central instance
Pull request decoration and guided setup for monorepos
Configure testing and staging environments with additional licenses
Automatically provision users and groups through SCIM with Okta and Azure AD
Set rule priority to uphold your coding standards
Component redundancy
Data resiliency
Horizontal scalability
High performance under extreme load
Autoscale in a Kubernetes cluster
Languages and frameworksDeveloper EditionJava · C# · JavaScript · TypeScript · Kotlin · CloudFormation · Terraform · Docker · Kubernetes/Helm · Ruby · Go · Scala · Flex · Python · PHP · Rust · HTML · Shell · CSS · XML · VB.NET · Azure Resource Manager/Bicep · Ansible · C · C++ · Dart/Flutter · Obj-C · Swift · ABAP · T-SQL · PL/SQL · JSON · YAML · GitHub ActionsEnterprise & Data Center EditionsAll Developer Edition languages plus APEX · COBOL · JCL · PL/I · RPG · VB6344040
Detect security, reliability, and maintainability issues
Detect issues in AI generated code
Auto-trigger code reviews and block substandard code in CI/CD pipelinesSupports the following• GitHub Actions
• GitLab CI/CD
• Bitbucket Pipelines
• Azure Pipelines
• Jenkins
• Codemagic
Automatically analyze feature and maintenance branches and pull requests
Display quality gate pass/fail status in DevOps pull request commentsVisible in• GitHub pull request
• GitLab merge request
• Bitbucket pull request
• Azure DevOps pull request
Analyze with parallel processing to improve performance for large teams
Quality profiles
Quality gates
Discover issues in code that cause bugs
Track and resolve technical debt
Find advanced dataflow bugs
Show percentage of test case coverage for improved code quality
Architecture management
MISRA C++:2023 compliance
Discover issues in code that cause hotspots and security vulnerabilities
Industry leading secrets detectionDetects 400+ secrets patterns with 340+ rules, including coverage of 248 public, private, commercial, and enterprise cloud services.
Taint analysis with cross-function and cross-file trackingSupported languages• Java
• C#
• JavaScript
• TypeScript
• Python
• PHP
• Kotlin
• Go
• VB.NET
Display security vulnerabilities in GitHub and GitLab
Custom configure the security engine for more powerful taint analysis
Create custom rules to detect private secret patterns
SCA and Advanced SAST with Advanced Security*Additional subscription*Additional subscription
Monitor code quality metrics and history of activity
Collect multiple projects together as an application for a single view
Create custom rules to detect private secret patterns
Aggregate projects and applications into a portfolio
Project, application, and executive portfolio reports
Security reports for common security standardsSupported standards• PCI DSS
• OWASP Top 10
• OWASP ASVS
• OWASP Mobile Top 10
• CWE Top 25
• STIG
• CASA
• OWASP Top 10 for LLM Application
• OWASP MASVS
Regulatory reports and audit logs
AI CodeFix
AI Code AssuranceEnsures AI generated code is fully understood and verified before reaching production.
MCP Server
Standard commercial support availableFor detailed pricing, contact sales.
24/7 premium commercial support availableFor detailed pricing, contact sales.

Frequently asked questions

How are the plans licensed?

Is support included in my SonarQube Server plan?

How are my Lines of Code (LOC) calculated?

What happens if my instance gets close to or reaches the limit of LOCs?

Which programming languages does SonarQube Server analyze?

How do I get an evaluation license and do I need to pay now?

Why upgrade from the Community Build to SonarQube Server Enterprise Edition?

What if my question hasn't been answered?