the dev-tools map/security scanning/2026
FIG. 20 — DETAIL

Security scanning, in detail

SAST, dependency and supply-chain scanning, mostly billed per contributing developer. Two 2024–25 events reshaped the category: GitHub unbundled Advanced Security into two cheaper SKUs, and Semgrep's license shift spawned the Opengrep fork. The free OSS scanner row is the baseline every per-dev quote should beat.

7 tools compared · compiled July 2026 · every tool links to its official site

ToolFree tierEntry priceBilling unitWatch out forBest for
Snyk100–300 tests/mo per productTeam from $25/dev/moPer contributing dev'Contributing developer' counting surprises on renewalsDev-first SCA + SAST with automatic fix PRs
SonarQube CloudPublic repos free; private ≤50k LOCTeam $34/mo per 100k LOCPer lines of codeLOC-based billing punishes monoreposQuality gates + maintainability in the PR flow
GitHub Advanced SecurityDependabot free; all free on public repos$19 + $30 per committer/moPer active committerTwo SKUs since Apr 2025 — buy only what you needCodeQL + secret scanning without leaving GitHub
SemgrepOSS CLI + platform ≤10 devsTeams ~$40/contributor/moPer contributorDec 2024 license shift → Opengrep fork (Jan 2025)Fast SAST with rules you write yourself
SocketFree for OSS/small teamsPer-dev plansPer devNewer; npm-first heritage (now multi-ecosystem)Catching malicious packages, not just CVEs
TrivyUnlimited — OSS (Apache-2.0)$0FreeCLI/CI tool — no management platformFree container/IaC/dependency scanning in CI
AikidoFree tierFlat plansFlat, per repo/dev bandsAggregates OSS engines — depth vs specialists variesOne dashboard bundling SCA/SAST/secrets/IaC

Pricing models and free tiers change often — check each vendor for current terms. Compiled July 2026; the most volatile figures verified on official pricing pages.

Official pages: Snyk · SonarQube Cloud · GitHub Advanced Security · Semgrep · Socket · Trivy · Aikido

Entry price at a glance

Cheapest paid plan, USD per month — per-user plans shown for a single seat. Hatched bars are usage-based or quote-only; values marked ~ are approximate.

Trivy
$0 OSS
GHAS Secret Protection
$19/committer
Snyk
$25/dev
GHAS Code Security
$30/committer
SonarQube Cloud
$34 per 100k LOC
Semgrep
~$40/contributor
Socket
per-dev plans
Aikido
flat plans

Notes & recent changes

Which one should you pick?

← Back to the full dev-tools map