SonarQube Server plans and pricing

Self-hosted editions for automated code review

Priced per instance, per year, based on your lines of code.

Developer

Essential capabilities for small teams

Includes:

  • Recommended for 100K+ lines of code
  • 34 languages & frameworks
  • Autodetect AI-generated code
  • AI Code Assurance
  • Advanced bug detection
  • Secrets detection

Data Center

Performance, high availability & scalability

Enterprise Edition, plus:

  • Recommended for 20M+ lines of code
  • Autoscaling based on demand
  • High performance for distributed teams

Feature comparison

Compare SonarQube Server plans

Capability
Developer
RecommendedEnterprise
Data Center
Contact
Recommended lines of code100K or above1M or above20M or above
DevOps platform integrationSupports one integration each for the following DevOps platforms• GitHub
• GitLab
• Bitbucket
• Azure DevOps
IDE synchronization with SonarQube for IDESupports the following IDEs• VS Code
• Visual Studio
• IntelliJ
• Eclipse
• Cursor
• Windsurf
Detect issues in AI generated code
Combine third-party tool results with SARIF reports
AutoConfig for C and C++ projects
Autoprovision users and groups from GitHub and GitLab
Automatically sync permissions with GitHub and GitLab
Integrate with unlimited numbers of DevOps platformsSupports the following• GitHub Actions
• GitLab CI/CD
• Bitbucket Pipelines
• Azure Pipelines
• Jenkins
• Codemagic
Consolidate projects into a central instance
Pull request decoration and guided setup for monorepos
Configure testing and staging environments with additional licenses
Automatically provision users and groups through SCIM with Okta and Azure AD
Set rule priority to uphold your coding standards
Component redundancy
Data resiliency
Horizontal scalability
High performance under extreme load
Autoscale in a Kubernetes cluster
Languages and frameworksDeveloper EditionJava · C# · JavaScript · TypeScript · Kotlin · CloudFormation · Terraform · Docker · Kubernetes/Helm · Ruby · Go · Scala · Flex · Python · PHP · Rust · HTML · Shell · CSS · XML · VB.NET · Azure Resource Manager/Bicep · Ansible · C · C++ · Dart/Flutter · Obj-C · Swift · ABAP · T-SQL · PL/SQL · JSON · YAML · GitHub ActionsEnterprise & Data Center EditionsAll Developer Edition languages plus APEX · COBOL · JCL · PL/I · RPG · VB6344040
Detect security, reliability, and maintainability issues
Detect issues in AI generated code
Auto-trigger code reviews and block substandard code in CI/CD pipelinesSupports the following• GitHub Actions
• GitLab CI/CD
• Bitbucket Pipelines
• Azure Pipelines
• Jenkins
• Codemagic
Automatically analyze feature and maintenance branches and pull requests
Display quality gate pass/fail status in DevOps pull request commentsVisible in• GitHub pull request
• GitLab merge request
• Bitbucket pull request
• Azure DevOps pull request
Analyze with parallel processing to improve performance for large teams
Quality profiles
Quality gates
Discover issues in code that cause bugs
Track and resolve technical debt
Find advanced dataflow bugs
Show percentage of test case coverage for improved code quality
MISRA C++:2023 compliance
Discover issues in code that cause hotspots and security vulnerabilities
Industry leading secrets detectionDetects 400+ secrets patterns with 340+ rules, including coverage of 248 public, private, commercial, and enterprise cloud services.
Taint analysis with cross-function and cross-file trackingSupported languages• Java
• C#
• JavaScript
• TypeScript
• Python
• PHP
• Kotlin
• Go
• VB.NET
Display security vulnerabilities in GitHub and GitLab
Custom configure the security engine for more powerful taint analysis
Create custom rules to detect private secret patterns
SCA and Advanced SAST with Advanced Security*Additional subscription*Additional subscription
Monitor code quality metrics and history of activity
Collect multiple projects together as an application for a single view
Create custom rules to detect private secret patterns
Aggregate projects and applications into a portfolio
Project, application, and executive portfolio reports
Security reports for common security standardsSupported standards• PCI DSS
• OWASP Top 10
• OWASP ASVS
• OWASP Mobile Top 10
• CWE Top 25
• STIG
• CASA
• OWASP Top 10 for LLM Application
• OWASP MASVS
Regulatory reports and audit logs
AI CodeFix
AI Code AssuranceEnsures AI generated code is fully understood and verified before reaching production.
MCP Server
Standard commercial support availableFor detailed pricing, contact sales.
24/7 premium commercial support availableFor detailed pricing, contact sales.

Frequently asked questions

How are the plans licensed?

Developer Edition, Enterprise Edition, and Data Center Edition are priced per instance per year and based on your lines of code (LOC). An instance is an installation of SonarQube Server. You pay per instance for a maximum number of LOC to be analyzed.

Get in touch with sales for pricing specific to your needs.

Is support included in my SonarQube Server plan?

Standard commercial support is included in your Enterprise Edition or Data Center Edition plan starting at 30M lines of code and above. For other plans, standard commercial support is available for an additional cost. See the benefits of commercial support, including details on how to purchase. You are also always welcome to ask questions in our vibrant and active Sonar Community.

How are my Lines of Code (LOC) calculated?

LOC is calculated by summing up the LOC of each project analyzed in your SonarQube Server instance. Blank lines, comments, and lines of test code are never included in the count. The LOC of a project is counted as the lines in the largest branch of the project. If you have set up branch analysis for your project, the LOC used for a project are the ones found during the most recent analysis of the project with the largest branch or pull request. More details can be found on the Lines of Code page in our docs.

What happens if my instance gets close to or reaches the limit of LOCs?

If you are getting close to the threshold, you will be notified to either upgrade your plan or reduce the number of LOCs in your projects. If you reach your limit, you will receive an error message and the SonarQube Server instance will reject any new analysis whose total lines of code exceed the limit defined by your license. However, SonarQube Server will retain basic functionality such as saving configuration changes and allowing project browsing.

Which programming languages does SonarQube Server analyze?

SonarQube Server Developer Edition covers the following languages and frameworks: Java, C#, C, C++, Objective-C, Dart/Flutter, Python, JavaScript, TypeScript, Kotlin, CloudFormation, Terraform, Azure Resource Manager, Docker, Kubernetes/Helm Charts, Ruby, Go, Scala, Flex, PHP, HTML, CSS, XML, VB.NET, Swift, ABAP, T-SQL, and PL/SQL.


Enterprise Edition and Data Center Edition additionally cover the following languages: Apex, COBOL, JCL, PL/I, RPG, and VB6.

How do I get an evaluation license and do I need to pay now?

You can request an evaluation license by clicking on any of the trial buttons above for the edition you are interested in. Once you submit your request, our sales representative will contact you to activate the trial and discuss options once your trial is complete. No payment is required to request or activate a free trial license.

Why upgrade from the Community Build to SonarQube Server Enterprise Edition?

SonarQube Community Build is a powerful, free, and open-source tool. However, upgrading to Enterprise Edition unlocks exclusive support, more powerful security, efficiency, and scalability, along with advanced features that will take your code quality to the next level. Read more about the benefits of upgrading.

What if my question hasn't been answered?

You can contact our team