CodeQL

CodeQL

CodeQL is the industry-standard semantic code analysis engine by GitHub.

Free + paidWebCLIAPI
Visit websitecodeql.github.com
Compare with book-to-skillExplore CodeQL alternatives

Overview

CodeQL is the industry-standard semantic code analysis engine by GitHub. It treats code as data, allowing users to query it to find complex security vulnerabilities and logical errors that simple pattern matching might miss. It leverages a vast library of queries shared by security researchers worldwide and has recently integrated AI to assist in query writing and improve detection accuracy.

Key features

  • Semantic Code Analysis
  • Data Flow Analysis
  • Taint Analysis
  • Custom Query Writing
  • GitHub Actions Integration
  • Multi-language Support
  • Automated Vulnerability Detection

Pricing

Free + paidStarting price: Free (public repos) / $30/active committer/mo (private)

Verified on:

Use cases

  • Zero-day vulnerability discovery
  • Variant analysis of security flaws
  • CI/CD security automation
  • Searching for logical errors in codebases

Who it is for

Security ResearchersSecurity EngineersOpen Source MaintainersEnterprise Dev Teams

Integrations

GitHub ActionsVS CodeAzure DevOps

Tags

SASTGitHub

How we verified this

Company, pricing, and feature details come from the primary sources below and our latest verification pass. When sources disagree, the official source and the most recent check win.

Last verified 08/30/2026Verified sources: 1

Alternatives

Tools you can use instead