--- title: CodeScan Reviews meta\_title: 'CodeScan Reviews 2026: Details, Pricing, & Features | G2' meta\_description: Filter 34 reviews by the users' company size, role or industry to find out how CodeScan works for a business like yours. aggregate\_rating: rating\_value: 4.6 review\_count: 34 scale: '5' date\_modified: '2026-08-07' parent\_category: name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t" url: https://www.g2.com/categories/devsecops ---

# CodeScan Reviews & Product Details

Claimed

###### Profile Status

This profile is currently managed by CodeScan but has limited features.  
  
Are you part of the CodeScan team? [Upgrade your plan](https://sell.g2.com) to enhance your branding and engage with visitors to your profile!

CodeScan Shield addresses code quality, security, and compliance liabilities with two automated modules: CodeScan and OrgScan. CodeScan provides static code analysis for total visibility into code health from the moment it’s written through production. OrgScan governs organizational policies by enforcing the security and compliance rules mandated for your Salesforce environment. Together, they ensure the code that makes up your Salesforce environment and the way the environment is being utilized will always meet high standards. The result is strengthened data security, streamlined DevSecOps processes, and an assurance of meeting compliance standards—avoiding potentially thousands of dollars in fines and lost opportunities. CodeScan Shield protects your Salesforce org from both the inside and outside. CodeScan provides dashboards and reports for consistent code visibility, while also alerting developers the moment new errors are introduced. OrgScan analyzes Salesforce policies to ensure the organization remains compliant with client-mandated specifications and guidelines. Violations are flagged and recorded in an interactive dashboard. Progress is tracked for policy reviews. Collectively, these features ensure admins maintain governance control within their organization. CodeScan Shield is part of AutoRABIT’s complete DevSecOps platform. Enabling Salesforce DevOps teams with CodeScan Shield’s powerful technology produces high-quality, secure applications and updates at speed.

* * *

Seller
[AutoRABIT](https://www.g2.com/sellers/autorabit)
Discussions
[CodeScan Community](https://www.g2.com/products/codescan/discuss)
Languages Supported

English

Solution Type

Best-of-Breed

Overview by
Kris Gabert (Vice President Marketing at AutoRABIT)

Show More

## Value at a Glance

Averages based on real user reviews.

### Perceived Cost

$$$$$

[
View More Pricing Information
](https://www.g2.com/products/codescan/pricing)

## Top-Rated Alternatives

[

 ![SonarQube](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "SonarQube")

SonarQube

4.4/5(155)

](https://www.g2.com/products/sonarqube/reviews)

[

 ![Checkmarx](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Checkmarx")

Checkmarx

4.2/5(48)

](https://www.g2.com/products/checkmarx/reviews)

[

 ![GitLab](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "GitLab")

GitLab

4.5/5(901)

](https://www.g2.com/products/gitlab/reviews)

[
View All Alternatives
](https://www.g2.com/products/codescan/competitors/alternatives)

## User Insights

Average based on 34 real user reviews.

Perceived Cost

$$$$$

[Log in to unlock pricing and user insights](/login)

 ![Ramkumar N.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Ramkumar N.")
RN

Ramkumar N.

Salesforce Developer

Information Technology and Services

Enterprise (\> 1000 emp.)

9/22/2022

"CodeScan effectively helps mitigating Salesforce metadata risks thanks to its splendid scan engines"

4/5

What do you like best about CodeScan?

We prioritize Salesforce code quality as it's integral to our retail organization. We work with sensitive customer data and encode security roles, permissions & access control definitions & overviewing them is made convenient with CodeScan. As we incorporate our metadata, the possibility of errors is high, resulting in poor code quality. CodeScan provides a sophisticated platform to overcome these challenges and keep our code security intact & compliant. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

In my opinion, its pricing model seems to be costly. Each pricing block is evaluated based on scanning 40,000 lines of code & your expenditure can be calculated with this. For small retail businesses, their framework & codes would mostly have fewer lines of code & they would be paying for a standard pricing block. It would be great to have granularity in its pricing block so that any organization would opt CodeScan's pricing model that fits their requirements without paying additional charges. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

CodeScan offers our retail organization with excellent static code analysis platform. We obtain superb visibility about our code quality, reliability in code analysis & also ensure proper Salesforce development provisions. Regarding the Salesforce platform, a few regulatory metrics need to be upheld & CodeScan governs these metrics through its well-structured rule policies. Before carrying out the production deployments, we need to validate our Salesforce codes & metadata to avoid exposure of sensitive client data & poor release quality. CodeScan platform is excellent for handling these commitments, and we provide satisfactory deliverables to our customers. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite

OU

Ogaga U.

Mid-Market (51-1000 emp.)

11/17/2020

"Helps to facilitate SAST scan and secure code reviews"

3.5/5

What do you like best about CodeScan?

It's specific to Salesforce Apex. There aren't many tools out there for this language. And it does it well with SonarCloud integration so you have the ability to see what aspect of OWASP Top 10 the vulnerability falls under. Recently, they included security hotspots, to give you more insight to areas your organisation's code needs more security improvement.

CodeScan is very understanding about your business needs, and try to fit into your budget as much as they can. They also value customer loyalty and they listen to their customers. They provide hands-on help as needed and do not leave you hanging.

The pricing for CodeScan eliminates any general SonarCloud languages. It only includes programming languages specific to Salesforce - i.e. lightning pages, aura component, apex classes, visualforce pages (excluding js files which is included with SonarCloud]. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

There isn't much to dislike about the product, although it does not integrate with a ticketing system, it does the job. It will be helpful if it integrated with a ticketing system, to create a ticket for security or quality bugs. It also results in a lot of false positives but you may modify this as you please in the administrative part of SonarCloud.

You cannot get a specific report for newer codes in your repository or Salesforce org. The security report generated is for collated code from your org or repository.

I would also appreciate more help with working in SonarCloud for those who are not versatile with the application. Although, CodeScan provides hands- on help. The team needs to consider writing up a manual for specific operations in SonarCloud that organisations might be interested in. Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

CodeScan does the job for security vulnerabilities and quality assessment more than most high-end commercial tools. It is just as good as the very expensive tools and integrates well with your CI/CD process.

The company ensures their clients are satisfied and always check in with their customers. They do not leave you hanging like some other organisations do.

Lots of opportunities to ask for help if you are stuck. Overall, for secure code reviews, it is brilliant! We do not currently use if for SAST but it does a great job with overall reporting of your code-base - projects. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

We currently use CodeScan to facilitate in our internal secure code reviews and it does well with in-depth information regarding new and existing code security.

It also provides more than Security vulnerabilities or hotspots, it is very beneficial for Quality bugs relating to Salesforce Apex. We do not currently use this aspect of CodeScan.

We have used it to improve our deployment process by 50%, and SonarCloud is easily integrated with our CI/CD process, which automates CodeScan scans for our teams. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Verified User in Information Technology and Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Information Technology and Services")
AI

Verified User in Information Technology and Services

Mid-Market (51-1000 emp.)

8/12/2020

Business partner of the seller or seller's competitor, not included in G2 scores.

"Better than alternatives"

4/5

What do you like best about CodeScan?

CodeScan provides a much deeper set of rules compared to the alternatives currently available.

The rule thresholds can be configured in the UI and you can save your changes to the rule severity & thresholds as a profile that can be applied to projects.

Issues identified often provide pretty good examples of how to address the issue right in the tool.

Plugin available for the most popular IDEs (VS Code, IntelliJ).

The documentation has become much better, especially for the Cloud/Hosted version. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

It is difficult to configure CodeScan to only scan my changes. Thankfully they provide multiple options (scan only files with a specific regex, compare to a date snapshot, branches). However, some investment could be made to make this easier and more powerful.

The integration with CI/CD tools (especially Copado) needs to be better. CodeScan intends you to use it as a code review tool, but often I already have a Pipeline tool (e.g. Gitlab/BitBucket Pipeline, Jenkins, Copado) and all I want to use CodeScan for is to scan code.

Unit testing often times out. There needs to be greater control over how unit tests are executed and to avoid hitting the timeout limit.

The daily reports could be more helpful if you could specify that they run against a branch rather than "master".

The documentation is getting better every day. That said, I would like to see CodeScan invest in more walkthroughs. Also, rather than just explain what a feature does, explain how you might make a decision how to use that functionality. Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

Expect challenges integrating it into your CI/CD/Pipeline tool. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

CodeScan is helping us to enforce parts of our coding standard, and using the tool is helping us to coach our developers and improve their skill.

I don't know that we have data to quantify this, but we do believe the tool is helping us identify larger architectural and scalability issues earlier in the cycle. Thus far there has not been vulnerabilities identified in code delivered that was scanned using CodeScan. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Adam O.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam O.")
AO

Adam O.

Salesforce Developer

Enterprise (\> 1000 emp.)

8/11/2020

"Easy to integrate and maintain, sometimes hard to use during daily development"

4/5

What do you like best about CodeScan?

A lot of rules, easy integration with IDE and CI Processes Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

There is no option to run static analysis with command (like You can do with esLint or other tools or only at save, big consumption of CPU. Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

There are a lot of rules which could be use. You need to pick the ones which suits You, because there will be a lot of issues in Your initial scan, and not everything will make sense for You. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Our code review process is faster and it is much easier to maintain code standards. We have a lot of objective rules to follow so I don't need to spend my time on fixing common bugs. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Verified User in Telecommunications](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Telecommunications")
UT

Verified User in Telecommunications

Mid-Market (51-1000 emp.)

12/17/2020

"Good tool but rules can be improved for Apex"

4/5

What do you like best about CodeScan?

Configurable rules for each language are good to use. Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

Time it takes to run the scan is too much. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

We avoid building up of technical debt, leading to better code quality Review collected by and hosted on G2.com.

Show More

Validated ReviewerSource: Seller invite

 ![Verified User in Computer Software](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Computer Software")
UC

Verified User in Computer Software

Enterprise (\> 1000 emp.)

8/11/2020

"CodeScan is Great"

4/5

What do you like best about CodeScan?

The way it provides all the reports without vconfiguring anything on-prem Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

We cannot modify the already created rules or we cannot add up any new scanning rules Review collected by and hosted on G2.com.

Recommendations to others considering CodeScan:

Use it to make your work easy and save time. Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Was scanning the code for code coverage, duplicity of code etc.

Benefit is that we don't need to configure anything like installation and all is not required. Everything is available by just a single login Review collected by and hosted on G2.com.

Show More

8/12/2020
Validated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Verified User in Hospital & Health Care](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Hospital & Health Care")
CH

Verified User in Hospital & Health Care

Mid-Market (51-1000 emp.)

8/11/2020

"Helps to improve code quality and follow best code practices as we code."

4/5

What do you like best about CodeScan?

we can follow good code practices as we code so we do not have to worry about code quality later Review collected by and hosted on G2.com.

What do you dislike about CodeScan?

Some errors are not helpful like gives exception handling error even if we catch exception Review collected by and hosted on G2.com.

What problems is CodeScan solving and how is that benefiting you?

Checking accessibility before making any DML statements or SOQL queries.

declaring variables final. Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: G2 invite on behalf of seller

## Questions about CodeScan? Ask real users or explore answers from the community

Get practical answers, real workflows, and honest pros and cons from the G2 community or share your insights.

[
Ask about CodeScan
](https://www.g2.com/products/codescan/discussions/new)

GU

Guest User

What is CodeScan used for?

0 Upvotes

0

[
Join the conversation
](https://www.g2.com/discussions/what-is-codescan-used-for)

[
View all Discussions
](https://www.g2.com/products/codescan/discuss)

## Pricing Options

Pricing provided by CodeScan.

### Cloud

Contact for Pricing

### Self Hosted

Contact for Pricing

### Editor Plugin

Contact for Pricing

[
View More Pricing Information
](https://www.g2.com/products/codescan/pricing)

CodeScan Comparisons

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_a4dc620644f85fd7e4f00b0a2267d09c/sonarqube.png "Product Avatar Image")

SonarQube

4.4/5(155)

[
Compare Now
](https://www.g2.com/compare/codescan-vs-sonarqube)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_9c1730ad68b323f13e6809169d249245/checkmarx%282%29.png "Product Avatar Image")

Checkmarx

4.2/5(48)

[
Compare Now
](https://www.g2.com/compare/checkmarx-vs-codescan)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_eba7b910de9a9aac0b4f1b82545d0832/black-duck-coverity-static.jpg "Product Avatar Image")

Black Duck Coverity Static

4.3/5(65)

[
Compare Now
](https://www.g2.com/compare/black-duck-coverity-static-vs-codescan)

##### Categories on G2

[Static Application Security Testing (SAST)](https://www.g2.com/categories/static-application-security-testing-sast)[Static Code Analysis](https://www.g2.com/categories/static-code-analysis)

##### Explore More

[Best VDR software for mergers and acquisitions](https://www.g2.com/discussions/what-s-the-best-vdr-software-for-mergers-and-acquisitions)[What are the best practices for evaluating and selecting UKG Marketplace solutions to support growing teams with complex HR and payroll requirements?](https://www.g2.com/discussions/what-are-the-best-practices-for-evaluating-and-selecting-ukg-marketplace-solutions-to-support-growing-teams-with-complex-hr-and-payroll-requirements)[best crm for ecommerce platforms](https://www.g2.com/discussions/what-crm-is-the-best-for-e-commerce-platforms)

[Best tools for managing data consent and preferences](https://www.g2.com/discussions/what-are-the-best-tools-for-managing-data-consent-and-preferences)[What lead retrieval solutions work well for a sales team attending multiple events and needing to centralize all captured leads in one view regardless of which event they came from?](https://www.g2.com/discussions/what-lead-retrieval-solutions-work-well-for-a-sales-team-attending-multiple-events-and-needing-to-centralize-all-captured-leads-in-one-view-regardless-of-which-event-they-came-from)[What platform integrates work management with collaboration tools?](https://www.g2.com/discussions/what-platform-integrates-work-management-with-collaboration-tools)

[Show MoreShow Less](javascript:void(0);)