Where Corgea's free tier stops
Corgea Corgea's free tier covers AI SAST, logic and auth scanning, dependency scanning, secrets detection, container scanning, and IaC scanning, but only for up to 2 team members and 10 repositories. That is the main ceiling for builders who want to keep scanning real codebases without moving to paid plans. The free tier text does not list higher quotas for PR scans or auto-fixes, and the pricing summary says the broader free offer is capped at 10 PR scans per month and 10 SAST auto-fixes, so the free plan is best for small teams and a few repos.
Switch table
| Corgea | Codacy | DeepSource | Coverity Scan | Meterian | Zeet | HostedScan | |
|---|---|---|---|---|---|---|---|
| team members | 2 | Unknown | Unlimited team members on Open Source plan | Approval-based project access | Unknown | Up to 7 team members | Up to 5 targets during trial |
| repositories | 10 | Up to 100 private repositories for open source projects | Unlimited public repositories on Open Source plan | Registration-based projects | Unlimited open source projects, 1 closed source project | 3 free projects | Not applicable |
| PR scans per month | 10 | Unlimited for open source Team features, otherwise not stated | 1,000 pull requests reviewed per month on Open Source plan | Up to 28 build submissions per week for projects under 100K LOC | Not stated | Not stated | Unlimited scans of included targets during the 14-day trial |
| automation or AI fixes | 10 SAST auto-fixes | Developer plan includes auto-fix AI code before it reaches the editor | Open Source plan includes pay-as-you-go Autofix™ | Not stated | Not stated | Not stated | Not stated |
| open source allowance | Not stated in free tier items | Open source projects free forever | Open source plan only for public repositories | Registered open source projects at no charge | Unlimited open source projects | Not applicable | Not applicable |
| analysis or scan volume | Core scanning included, no higher free quota stated | Not stated as a single cross-product quota | 1,000 formatting runs per month on Open Source plan | Up to 28, 21, 14, or 7 build submissions per week depending on size | 10 analyses per day | Not stated | Unlimited scans of 5 included targets during the 14-day trial |
| Card required | - | No | No | Yes | Yes | Yes | Yes |
| First paid tier | - | Developer free; Team starts at $18 per dev/month | Team, $24 per user/month billed yearly | Varies by usage | Bootstrap, £2300/year | Pro, $699 per month* | Basic, $39 / month |
The alternatives
Codacy
FTV 44 / 100Codacy's free offering is strongest if your work centers on open source or individual IDE use. Open source projects can use Team plan features at no cost, including cloud-hosted code quality and security scans, GitHub, Bitbucket, and GitLab integrations, AI Reviewer, merge gates, Jira and Slack integration, and up to 100 private repositories with unlimited LOC. The free Developer plan also stays free forever and includes IDE plugin access, scan-as-you-type feedback, security scans for SAST, SCA, and secrets, code quality scans, and auto-fix workflows in VSCode, JetBrains, and Cursor. It goes farther than Corgea on collaboration and repository scale, but it is less focused on Corgea's IaC, container, and logic/auth bundle. Switch if you want broader code review workflow features or open source coverage at no cost.
- Beats Corgea: More free repository capacity and team-oriented workflow features.
- Falls short: Less direct coverage of Corgea's IaC, container, and logic/auth scanning bundle.
- Who should switch: Switch if you are an open source maintainer or an individual developer who wants free IDE and PR workflow scanning.
DeepSource
FTV 43 / 100DeepSource gives you two free paths: a 14-day trial with up to $50 in bundled AI Review credits, and an open source plan that stays free for unlimited public repositories and unlimited team members. The open source plan includes 1,000 pull request reviews per month, 1,000 automated formatting runs per month, Static Analysis, SAST, IaC, Code Coverage, and Secrets Detection, plus pay-as-you-go AI Review and Autofix. That makes it useful for teams that want an ongoing free baseline rather than a tiny permanent cap. Compared with Corgea, it offers much more room for public projects and more automation around review workflows, but it excludes private repositories in the open source plan. Switch if your code is public and you want generous ongoing limits.
- Beats Corgea: Unlimited team members and much higher ongoing review volume for public repositories.
- Falls short: Private repositories are excluded from the open source free plan.
- Who should switch: Switch if you maintain public codebases and want free SAST, IaC, and review automation at scale.
Coverity Scan
FTV 48 / 100Coverity Scan is a free static analysis service for registered open source projects. You can submit builds for analysis, download the submission software after registration, and access analysis results at no charge once approved. The service also supports responsible disclosure, with detailed findings visible only to approved project members until issues are resolved. Its free tier is built around open source governance rather than self-serve product usage, and it allows up to 28 build submissions per week for projects under 100K lines of code, with lower weekly limits for larger projects. It is narrower than Corgea in scan types, but it can be a fit for maintainers who mainly want defect and vulnerability analysis on approved open source code. Switch if your project is open source and you care most about static analysis results and disclosure workflow.
- Beats Corgea: Higher weekly build submission capacity for approved open source projects.
- Falls short: No self-serve free coverage for Corgea's broader multi-signal scanning set.
- Who should switch: Switch if you are an approved open source maintainer focused on static analysis and vulnerability findings.
Meterian
FTV 52 / 100Meterian's free plan is simple and long-lived for small-scale security scanning. It includes unlimited open source projects, one closed source project, 10 analyses per day, and HTML reports. That is a clear fit for builders who want to keep a single private project under continuous monitoring without paying, or who mainly work on open source and need room to scan many repositories. Against Corgea, Meterian gives you more room on open source usage and a defined closed-source allowance, but it is much more limited on reporting and daily analysis volume. It is also not a broad application security bundle in the same way Corgea is. Switch if you want basic vulnerability and license scanning with very low ongoing cost pressure.
- Beats Corgea: Unlimited open source projects and a small closed-source allowance.
- Falls short: Much narrower reporting and scan cadence than Corgea's multi-signal security bundle.
- Who should switch: Switch if you run one private project or many open source projects and can live with simple reports.
Zeet
FTV 59 / 100Zeet's free plan is for deploying and operating infrastructure rather than scanning code. It includes 3 free projects, 1 cluster, 1 cloud region, 1 custom blueprint, up to 7 team members, and up to 10 linked cloud accounts, plus unlimited Zeet-official blueprints. For builders whose main need is Terraform and Kubernetes workflow management, the free tier gives a real starting point without a card. Compared with Corgea, it is much more generous on infrastructure collaboration and deployment structure, but it does not replace application security scanning at all. Use it only if your free-tier decision is really about infrastructure operations, not code security. Switch if your problem is managing clusters and blueprints, not scanning repositories.
- Beats Corgea: More free room for infrastructure projects, clusters, regions, and team members.
- Falls short: It does not provide Corgea-style code and dependency security scanning.
- Who should switch: Switch if you need free Kubernetes and Terraform operations management instead of app security scanning.
HostedScan
FTV 34 / 100HostedScan's free offer is a 14-day trial of Basic with 5 targets and unlimited scanning of those included targets during the trial. It is best when you need to scan websites, servers, networks, or APIs rather than source code, dependencies, or IaC. The trial lets you test the service with the same target limit as the paid plans, and the product includes scanners such as OpenVAS, Nessus, OWASP ZAP, Nmap, Nuclei, and SSLyze. Compared with Corgea, HostedScan is broader on external vulnerability scanning targets but far less suited to repository-centric application security workflows. The main drawback is that it is only a trial, not a permanent free tier. Switch if you need external asset scanning and are evaluating the tool before paying.
- Beats Corgea: Broader target coverage for websites, servers, networks, and APIs.
- Falls short: It is only a 14-day trial, not a permanent free tier.
- Who should switch: Switch if you are scanning live assets and want to trial a hosted vulnerability scanner first.
Two quick picks
Codacy
Codacy is the closest fit for teams that want free security scanning plus code quality workflows in a Git-based product. Its free options cover both individual and open source usage, with integrations and review features that are easy to adopt without changing how developers work.
DeepSource
DeepSource gives the most free room for ongoing use because the open source plan allows unlimited team members, unlimited public repositories, and 1,000 pull request reviews per month, which is the widest free operating envelope in this set.
Frequently asked questions
Which alternative is best if I need free scanning for public repositories only?
DeepSource and Codacy are the strongest fits. DeepSource gives unlimited public repositories on its open source plan, while Codacy gives open source projects free access to Team plan features and up to 100 private repositories for open source projects.
Which alternative is closest if I want a Git-based workflow like Corgea?
Codacy is the closest drop-in because it stays centered on Git repositories, pull requests, and developer workflow, while still covering security and code quality scanning.
Which alternative has the most generous ongoing free limits?
DeepSource has the most headroom for open source use because it allows unlimited team members, unlimited public repositories, and 1,000 pull request reviews per month on the free open source plan.
Which alternative is best if I only need infrastructure or asset scanning, not code scanning?
Zeet is the infrastructure option if you need Kubernetes and Terraform operations, while HostedScan is the better choice for scanning websites, servers, networks, and APIs.
Bottom line
For most builders leaving Corgea's free tier, Codacy is the best first stop. It stays closest to a code-security workflow, adds stronger Git and PR collaboration, and gives open source projects a very generous free path. If your work is public code and you want the most free headroom, DeepSource is the better pick. If you need infrastructure operations or external asset scanning instead of repository security, Zeet or HostedScan are better matches, but they are not true replacements for Corgea's scanning bundle.
Read the full listing for Corgea. Scores use the FTV methodology at /ftv. Browse more alternatives on /alternatives, or head-to-head comparisons on /compare.