Feature checklists rarely decide anything. What decides it is the pricing metric, who has to write the tests, and which limitation you can live with.
Entry price
From $30 per committer/month (GitHub Advanced Security, indicative)
Free tierFrom $475 per user/year (Professional)
PaidWhat drives the bill
The metric that actually scales your invoice.
Free on public repos. Private repositories require GitHub Advanced Security, priced per active committer.
Professional is inexpensive for what it does; Enterprise is quote-based by scanning agents and applications.
Free tier
Free for public repositories on GitHub.
Community Edition is free but omits the scanner and rate-limits key tools.
Open source
MIT (queries)
Self-hostable
No-code authoring
Languages
Platforms
Fits teams
Adoption
Widely used
GitHub (Microsoft) · since 2019
Category standard
PortSwigger · since 2003
Strengths
Limitations
Best for
GitHub-hosted projects wanting deep static security analysis, free if the repo is public.
Security teams and penetration testers, plus enterprises needing scheduled authenticated scanning.
All of these integrate with: GitHub Actions, Jenkins.
Pricing last reviewed August 2026 and is indicative only — confirm on each vendor’s own page.