
CodeQL
CodeQL is the industry-standard semantic code analysis engine by GitHub.
Free + paidWebCLIAPI
Visit websitecodeql.github.com
Compare with book-to-skillExplore CodeQL alternativesOverview
CodeQL is the industry-standard semantic code analysis engine by GitHub. It treats code as data, allowing users to query it to find complex security vulnerabilities and logical errors that simple pattern matching might miss. It leverages a vast library of queries shared by security researchers worldwide and has recently integrated AI to assist in query writing and improve detection accuracy.
Key features
- Semantic Code Analysis
- Data Flow Analysis
- Taint Analysis
- Custom Query Writing
- GitHub Actions Integration
- Multi-language Support
- Automated Vulnerability Detection
Pricing
Free + paidStarting price: Free (public repos) / $30/active committer/mo (private)
Verified on:
Use cases
- Zero-day vulnerability discovery
- Variant analysis of security flaws
- CI/CD security automation
- Searching for logical errors in codebases
Who it is for
Security ResearchersSecurity EngineersOpen Source MaintainersEnterprise Dev Teams
Integrations
GitHub ActionsVS CodeAzure DevOps
Tags
SASTGitHub
How we verified this
Company, pricing, and feature details come from the primary sources below and our latest verification pass. When sources disagree, the official source and the most recent check win.
Last verified 08/30/2026Verified sources: 1
Alternatives
Tools you can use instead

book-to-skill
Converts technical books and document collections into structured, on-demand skills for AI coding agents.
★ 28.8KOpen source
Developer Tools

GPT-6 Astra
OpenAI frontier model for difficult end-to-end reasoning and professional work.
API
Developer Tools

