aicoolies logo
CodeThreat logo
CodeThreat logo

CodeThreat

AI-powered SAST for PR-time security analysis

freemiumupdated Apr 21, 2026

CodeThreat provides pull request-time security analysis covering SAST, dependency vulnerability checks, and infrastructure-as-code risk review. Highly rated for its seamless GitHub integration, it catches security issues introduced by both human and AI-generated code before they reach production, with particular strength in identifying vulnerabilities from rapid vibe coding workflows.

CodeThreat integrates security analysis directly into the pull request workflow, scanning code changes for vulnerabilities at the moment they are proposed rather than after deployment. The platform covers static application security testing, dependency vulnerability scanning to identify known CVEs in third-party packages, and infrastructure-as-code review for configuration security issues in Terraform, Kubernetes manifests, and cloud templates.

The tool has gained particular relevance as AI-generated code volumes increase. CodeThreat is designed to catch the types of security mistakes that AI coding assistants commonly make, including hardcoded credentials, SQL injection patterns, insecure API configurations, and missing input validation. The platform provides actionable remediation guidance alongside each finding, helping developers fix issues quickly without deep security expertise.

CodeThreat integrates natively with GitHub and has received strong ratings on Product Hunt for its developer experience. The platform supports multiple programming languages and frameworks, providing consistent security coverage across polyglot codebases. Paid plans include team management features, compliance reporting, and priority support for enterprise security requirements.

Pricing

Paid plans; free trial available

Platforms

GitHub, CI/CD, multi-language

Categories

Tags

Use Cases

Related Tools

computed discovery: shared active categories · kept separate from editor-verified Alternatives

ToolHive mascot logo

ToolHive

Run and govern MCP servers across desktop, CLI and Kubernetes

Open-source MCP runtime and governance platform that runs servers in isolated containers, curates registries, enforces access policies, and operates gateways across desktop, CLI, and Kubernetes.

Open Source
Anamorpher parent Trail of Bits mark

Anamorpher

Craft image-scaling prompt-injection payloads to red-team multimodal AI systems

Open-source red-team toolkit from Trail of Bits that generates image-scaling attack payloads — images that look benign at full resolution but reveal a hidden prompt injection after a multimodal system downsamples them.

freeOpen Source
cai

CAI (Cybersecurity AI)

AI agent framework for offensive security and penetration testing

Alias Robotics' agent framework for building AI-driven offensive-security workflows — reconnaissance, exploitation, privilege escalation, and lateral movement — with multi-agent handoffs and human-in-the-loop control. Source-available, but the core is licensed for non-commercial research use only.

freemiumTelemetry
MEDUSA logo

MEDUSA

AI-first security scanner for LLM, agent, MCP, and RAG codebases

MEDUSA is an AGPL-3.0 AI-first security scanner from Pantheon Security that checks AI and machine-learning applications, LLM agents, MCP workflows, RAG pipelines, repository-poisoning risks, secrets, and agent-specific compromise patterns.

Open Source
iFixAi logo

iFixAi

Open-source diagnostic for AI operational misalignment

iFixAi is an Apache-2.0 diagnostic tool for scoring AI agents and models against operational-misalignment risks such as hallucination, manipulation, sabotage, sandbagging, and oversight evasion.

Open Source
Inspect AI parent UK AISI mark

Inspect AI

UK AI Security Institute framework for LLM safety evaluations

Inspect AI is an MIT-licensed framework from the UK AI Security Institute for running large language model evaluations, including tool use, multi-turn dialogue, model-graded scoring, and reusable evaluation tasks.

Open Source

FAQ

What is CodeThreat?

CodeThreat provides pull request-time security analysis covering SAST, dependency vulnerability checks, and infrastructure-as-code risk review. Highly rated for its seamless GitHub integration, it catches security issues introduced by both human and AI-generated code before they reach production, with particular strength in identifying vulnerabilities from rapid vibe coding workflows.

Is CodeThreat free?

CodeThreat offers a free tier alongside paid plans. Paid plans; free trial available

What are the best CodeThreat alternatives?

The top editor-verified CodeThreat alternatives are Semgrep, Checkmarx, SonarQube.