--- title: CodeScan Reviews meta\_title: 'CodeScan Reviews 2026: Details, Pricing, & Features | G2' meta\_description: Filter 34 reviews by the users' company size, role or industry to find out how CodeScan works for a business like yours. aggregate\_rating: rating\_value: 4.6 review\_count: 34 scale: '5' date\_modified: '2026-08-07' parent\_category: name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t" url: https://www.g2.com/categories/devsecops ---

# CodeScan Reviews & Product Details

Claimed

###### Profile Status

This profile is currently managed by CodeScan but has limited features.  
  
Are you part of the CodeScan team? [Upgrade your plan](https://sell.g2.com) to enhance your branding and engage with visitors to your profile!

CodeScan Shield addresses code quality, security, and compliance liabilities with two automated modules: CodeScan and OrgScan. CodeScan provides static code analysis for total visibility into code health from the moment it’s written through production. OrgScan governs organizational policies by enforcing the security and compliance rules mandated for your Salesforce environment. Together, they ensure the code that makes up your Salesforce environment and the way the environment is being utilized will always meet high standards. The result is strengthened data security, streamlined DevSecOps processes, and an assurance of meeting compliance standards—avoiding potentially thousands of dollars in fines and lost opportunities. CodeScan Shield protects your Salesforce org from both the inside and outside. CodeScan provides dashboards and reports for consistent code visibility, while also alerting developers the moment new errors are introduced. OrgScan analyzes Salesforce policies to ensure the organization remains compliant with client-mandated specifications and guidelines. Violations are flagged and recorded in an interactive dashboard. Progress is tracked for policy reviews. Collectively, these features ensure admins maintain governance control within their organization. CodeScan Shield is part of AutoRABIT’s complete DevSecOps platform. Enabling Salesforce DevOps teams with CodeScan Shield’s powerful technology produces high-quality, secure applications and updates at speed.

* * *

Seller
[AutoRABIT](https://www.g2.com/sellers/autorabit)
Discussions
[CodeScan Community](https://www.g2.com/products/codescan/discuss)
Languages Supported

English

Solution Type

Best-of-Breed

Overview by
Kris Gabert (Vice President Marketing at AutoRABIT)

Show More

## Value at a Glance

Averages based on real user reviews.

### Perceived Cost

$$$$$

[
View More Pricing Information
](https://www.g2.com/products/codescan/pricing)

## Top-Rated Alternatives

[

 ![SonarQube](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "SonarQube")

SonarQube

4.4/5(155)

](https://www.g2.com/products/sonarqube/reviews)

[

 ![Checkmarx](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Checkmarx")

Checkmarx

4.2/5(48)

](https://www.g2.com/products/checkmarx/reviews)

[

 ![GitLab](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "GitLab")

GitLab

4.5/5(901)

](https://www.g2.com/products/gitlab/reviews)

[
View All Alternatives
](https://www.g2.com/products/codescan/competitors/alternatives)

## User Insights

Average based on 34 real user reviews.

Perceived Cost

$$$$$

[Log in to unlock pricing and user insights](/login)

 ![Ramkumar N.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Ramkumar N.")
RN

Ramkumar N.

Salesforce Developer

Information Technology and Services

Enterprise (\> 1000 emp.)

9/22/2022

"CodeScan effectively helps mitigating Salesforce metadata risks thanks to its splendid scan engines"

4/5

What do you like best about CodeScan?

We prioritize Salesforce code quality as it's integral to our retail organization. We work with sensitive customer data and encode security roles, permissions & access control definitions & overviewing them is made convenient with CodeScan. As we incorporate our metadata, the possibility of errors is high, resulting in poor code quality. CodeScan provides a sophisticated platform to overcome these challenges and keep our code security intact & compliant. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

In my opinion, its pricing model seems to be costly. Each pricing block is evaluated based on scanning 40,000 lines of code & your expenditure can be calculated with this. For small retail businesses, their framework & codes would mostly have fewer lines of code & they would be paying for a standard pricing block. It would be great to have granularity in its pricing block so that any organization would opt CodeScan's pricing model that fits their requirements without paying additional charges. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

CodeScan offers our retail organization with excellent static code analysis platform. We obtain superb visibility about our code quality, reliability in code analysis & also ensure proper Salesforce development provisions. Regarding the Salesforce platform, a few regulatory metrics need to be upheld & CodeScan governs these metrics through its well-structured rule policies. Before carrying out the production deployments, we need to validate our Salesforce codes & metadata to avoid exposure of sensitive client data & poor release quality. CodeScan platform is excellent for handling these commitments, and we provide satisfactory deliverables to our customers. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite

 ![Tyronica O.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Tyronica O.")
TO

Tyronica O.

Data quality and clean up consultant

Mid-Market (51-1000 emp.)

6/16/2022

"CodeScan"

5/5

What do you like best about CodeScan?

CodeScan is the most awesome with the tools that help in writing the most secure and quality codes on the salesforce platform. It's the best in the market Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

The only downside is if the code in unrecognised or has errors, it sometimes misses where the error is. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

With CodeScan you know you are providing quality and secure codes. Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: G2 invite

 ![Santosh T.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Santosh T.")
ST

Santosh T.

Tech Lead

Enterprise (\> 1000 emp.)

3/4/2022

"Codescan : for better code quality"

4.5/5

What do you like best about CodeScan?

Vs code plugin and

Autorabit integration Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

No dislikes as such .great product indeed. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Code best practices

Avoided Salesforce governor limit related issues. Review collected by and hosted on G2.com.

Show More

3/4/2024
Validated ReviewerIncentivizedSource: G2 invite

 ![Verified User in Computer Software](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Computer Software")
UC

Verified User in Computer Software

Small-Business (50 or fewer emp.)

11/12/2021

"Code Standard"

5/5

What do you like best about CodeScan?

Through this we can code efficient and learn standard coding techniques. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

It takes few minutes to run or to finish the execution. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Code refactoring, removing vulnerability, bug, code smell, Duplicate lines of code can be identified and can be resolved. Review collected by and hosted on G2.com.

Show More

5/13/2022
Current UserValidated ReviewerIncentivizedSource: G2 invite

 ![Verified User in Management Consulting](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Management Consulting")
UM

Verified User in Management Consulting

Enterprise (\> 1000 emp.)

10/19/2021

"Best static code review tool"

5/5

What do you like best about CodeScan?

Easy to use and aldo suggestions it offer for each violations Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

It shows a lot of false positives and there's no option to mark a bug as false positive Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Static review of code and it helps maintain code quality Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite

OU

Ogaga U.

Mid-Market (51-1000 emp.)

11/17/2020

"Helps to facilitate SAST scan and secure code reviews"

3.5/5

What do you like best about CodeScan?

It's specific to Salesforce Apex. There aren't many tools out there for this language. And it does it well with SonarCloud integration so you have the ability to see what aspect of OWASP Top 10 the vulnerability falls under. Recently, they included security hotspots, to give you more insight to areas your organisation's code needs more security improvement.

CodeScan is very understanding about your business needs, and try to fit into your budget as much as they can. They also value customer loyalty and they listen to their customers. They provide hands-on help as needed and do not leave you hanging.

The pricing for CodeScan eliminates any general SonarCloud languages. It only includes programming languages specific to Salesforce - i.e. lightning pages, aura component, apex classes, visualforce pages (excluding js files which is included with SonarCloud]. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

There isn't much to dislike about the product, although it does not integrate with a ticketing system, it does the job. It will be helpful if it integrated with a ticketing system, to create a ticket for security or quality bugs. It also results in a lot of false positives but you may modify this as you please in the administrative part of SonarCloud.

You cannot get a specific report for newer codes in your repository or Salesforce org. The security report generated is for collated code from your org or repository.

I would also appreciate more help with working in SonarCloud for those who are not versatile with the application. Although, CodeScan provides hands- on help. The team needs to consider writing up a manual for specific operations in SonarCloud that organisations might be interested in. Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

CodeScan does the job for security vulnerabilities and quality assessment more than most high-end commercial tools. It is just as good as the very expensive tools and integrates well with your CI/CD process.

The company ensures their clients are satisfied and always check in with their customers. They do not leave you hanging like some other organisations do.

Lots of opportunities to ask for help if you are stuck. Overall, for secure code reviews, it is brilliant! We do not currently use if for SAST but it does a great job with overall reporting of your code-base - projects. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

We currently use CodeScan to facilitate in our internal secure code reviews and it does well with in-depth information regarding new and existing code security.

It also provides more than Security vulnerabilities or hotspots, it is very beneficial for Quality bugs relating to Salesforce Apex. We do not currently use this aspect of CodeScan.

We have used it to improve our deployment process by 50%, and SonarCloud is easily integrated with our CI/CD process, which automates CodeScan scans for our teams. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Alex B.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Alex B.")
AB

Alex B.

Senior IT Solutions Architect for People & Culture

Tobacco

Enterprise (\> 1000 emp.)

11/19/2020

"Must-have for those running several solutions within Salesforce"

5/5

What do you like best about CodeScan?

First of all, CodeScan is just great to deal with: they are extremely flexible, helpful, and do respect customers' internal procedures (even if they are overcomplicated for sometimes small purchases).

We're using it with SonarQube, it's quite straightforward to install and use by the DevOps Engineers. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

I can't actually find anything that I dislike, sorry... Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

As I have mentioned above CodeScan team is great so it's a plus already.

If you are using it with SonarQube make sure it's not a Sonar used globally and somehow you get your own "space". You're paying here for lines of the code and you don't want to run out of the nr of lines you've purchased (of you can if you have a budget)

Ask your developers which tools they prefer in the majority fo the cases it will be CodeScan Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Before going live with our Project that mainly was developed by the third-party it was important for me to understand the code complexity and its impact on dev-ops processes we've envisioned here. We had a couple of less than a pleasant conversation with our implementation partner since they hold that they deliver a product of the highest quality...and then came CodeScan. The result was something we had a feeling about - poor coding standards, a lot of loops, etc.

Ok, CodeScan is not a real human so don't expect that there's nothing to do for you after you have it. Sometimes it does overuse "code smell" and so on but you can mark it once and just re-check with the next deployments.

If you are in a similar position where you are in the dark how your code looks like or you want something that easily will identify if one developer is not destroying the work of the other one I can't recommend CodeScan more Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Dino K.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Dino K.")
DK

Dino K.

Salesforce Developer

Mid-Market (51-1000 emp.)

8/11/2020

Business partner of the seller or seller's competitor, not included in G2 scores.

"The best static code analysis tool for Salesforce"

5/5

What do you like best about CodeScan?

The ability to set different Quality Gates for different projects combined with different Quality Profiles. Out-of-the-box ruleset is just huge and the option to customize the ruleset is useful. The setup is really easy.

You can use an IDE plugin combined with the cloud solution (IntelliJ or VS Code) so it acts like a lint tool and that is really useful for development. Works with JavaScript (LWC) as well as other languages (out-of-the-box).

CI/CD is also supported which is brilliant. Copado, Jenkins, GitLab it's all there. In addition to CI/CD, you can also configure a webhook and send it to Slack :)

From the reporting point of view, Leak Period gives an overview of arising issues which is really useful as well as the Technical Debt. Another pro is the option to send the reports periodically.

Overall a fantastic tool every Salesforce developer should use. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

Wish there was a bit more documentation available and a custom report option for an individual member of the project. Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

Neatly fits into the Agile methodology. It helps in speeding up the development process and greatly contributes to overall code quality. Additionally, it saves a lot of time and effort on setup and maintenance.

UI is simple to use and the configuration is simple. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Developers on the projects follow the enforced standards hence overall code quality improved. Enforced test coverage significantly increased = fewer bugs. Code reviews take less time as the obvious mistakes are pointed out during development. Saves a lot of time (and stress!) during the two-week sprints :). CI/CD integration is a must-have and codescan integrates nicely into it. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

SK

Sheshant K.

Enterprise (\> 1000 emp.)

11/24/2020

"One awesome code scanner!"

5/5

What do you like best about CodeScan?

CodeScan really has saved us a lot of time in doing code reviews. We had the opportunity to let our developers install it in the VS Code IDE and codeScan did everything else.

The prompt warnings with the mention of lines, and the best way to correct it is what eased it all for us. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

Nothing really as of now. CodeScan infact has been so much flexible in integrating with Copado. So our CI/CD process was actually well streamlined. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

The user interface of CodeScan.

The flexibility of integrating it with Copado.

Ease of installation with VS Code. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

JH

Justin H.

Small-Business (50 or fewer emp.)

8/4/2020

"Fantastic static code analyzer"

4.5/5

What do you like best about CodeScan?

Its biggest pro is the centralized analysis for multiple different languages.

Typically you'd need to set up and configure a linter for JS, Java, Python, etc separately, per repo but codescan works out of the box on all the major languages and provides a single UI for managing the rules.

It also is simple to set up and integrate into CI/CD and takes away the pain of having to do that integration for each language pipeline.

Another pro is that it works at the project level so you can have multiple repos, each of different languages (or mixed) which all have their own coverage and health grade.

You can also customize each ruleset (self hosted) for each language to suit the teams needs. Some people enjoy trailing commas and the others are just wrong. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

There are a few quirks that, though provide rare frustrations, are by no means large deterrents.

One such rarity is a rule being flagged as incorrect due to a misinterpreted context.

Of course, you can just mark it as ignored but then the real frustration comes from the email notification sent out that a rule was ignored. Typically this is a useful feature as people shouldn't be bypassing rules, but in this case it's a bit frustrating to hold off on a deploy while you explain why the rule was ignored.

Also, during CI/CD, if an upstream branch was merged to master, a branch of that branch will fail. Of course, the simple solution is to point the branch at master now and rerun but sometimes you just want things to unrealistically work.

No VIM plugin :( Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

If your team has multiple different languages, repos, etc or constantly generating new microservices, CodeScan is going to dramatically decrease setup time.

Also, as the rules become standards for the team the dev iterations speeds up due to less PR churn and yak shaving. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

As mentioned above, it solves the critical problem of maintaining multiple different linter and ci/cd integration pipelines.

It runs against most languages and has a single integration pattern.

The UI allows a single source of truth for the rules so each new project automatically has them applied without any additional configurations or boilerplate 3rd party library setups. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: Seller invite

## Questions about CodeScan? Ask real users or explore answers from the community

Get practical answers, real workflows, and honest pros and cons from the G2 community or share your insights.

[
Ask about CodeScan
](https://www.g2.com/products/codescan/discussions/new)

GU

Guest User

What is CodeScan used for?

0 Upvotes

0

[
Join the conversation
](https://www.g2.com/discussions/what-is-codescan-used-for)

[
View all Discussions
](https://www.g2.com/products/codescan/discuss)

## Pricing Options

Pricing provided by CodeScan.

### Cloud

Contact for Pricing

### Self Hosted

Contact for Pricing

### Editor Plugin

Contact for Pricing

[
View More Pricing Information
](https://www.g2.com/products/codescan/pricing)

CodeScan Comparisons

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_a4dc620644f85fd7e4f00b0a2267d09c/sonarqube.png "Product Avatar Image")

SonarQube

4.4/5(155)

[
Compare Now
](https://www.g2.com/compare/codescan-vs-sonarqube)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_9c1730ad68b323f13e6809169d249245/checkmarx%282%29.png "Product Avatar Image")

Checkmarx

4.2/5(48)

[
Compare Now
](https://www.g2.com/compare/checkmarx-vs-codescan)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_eba7b910de9a9aac0b4f1b82545d0832/black-duck-coverity-static.jpg "Product Avatar Image")

Black Duck Coverity Static

4.3/5(65)

[
Compare Now
](https://www.g2.com/compare/black-duck-coverity-static-vs-codescan)

##### Categories on G2

[Static Application Security Testing (SAST)](https://www.g2.com/categories/static-application-security-testing-sast)[Static Code Analysis](https://www.g2.com/categories/static-code-analysis)

##### Explore More

[Which freelance platforms have the strongest talent pool with high user adoption, based on reviews?](https://www.g2.com/discussions/which-freelance-platforms-have-the-strongest-talent-pool-with-high-user-adoption-based-on-reviews)[What employee recognition software works for a mid-size company that needs peer-to-peer recognition across multiple departments?](https://www.g2.com/discussions/what-employee-recognition-software-works-for-a-mid-size-company-that-needs-peer-to-peer-recognition-across-multiple-departments)[Best enterprise risk management software in 2025](https://www.g2.com/discussions/what-are-the-best-enterprise-risk-management-erm-software-for-businesses-in-2025)

[Which affiliate marketing tools make it easy for publishers and partners to track their own performance without constantly pinging your team?](https://www.g2.com/discussions/which-affiliate-marketing-tools-make-it-easy-for-publishers-and-partners-to-track-their-own-performance-without-constantly-pinging-your-team)[Which technology review platforms have the best verified user reviews and detailed feature comparison tools?](https://www.g2.com/discussions/which-technology-review-platforms-have-the-best-verified-user-reviews-and-detailed-feature-comparison-tools)[Which revenue management platforms are best suited for concert halls and performing arts venues?](https://www.g2.com/discussions/which-revenue-management-platforms-are-best-suited-for-concert-halls-and-performing-arts-venues)

[Show MoreShow Less](javascript:void(0);)