logo Code Review

AI Code Review & Security

Tools focused on reviewing, securing, and validating code — not generating it.

14 tools · 14 with full reviews · 5 free or open source · Updated
CodeRabbit Freemium
CodeRabbit CodeRabbit is an AI-powered code review platform that automatically analyzes pull requests to provide summaries, line-by-line feedback, and suggested fixes. By integrating directly into Git platforms like GitHub, GitLab, Bitbucket, and Azure DevOps, it acts as a first-pass reviewer to catch bugs, security issues, and style inconsistencies before human engineers begin their review.
Qodo Freemium
Qodo Qodo is an AI-powered code quality and governance platform that provides multi-agent pull request reviews, cross-repository context, and automated coding standard enforcement. It operates as a verification layer to identify logic gaps, bugs, and compliance issues in both human and AI-generated code.
Snyk Code Freemium
Snyk Snyk Code is a developer-first static application security testing (SAST) tool that uses a proprietary machine learning engine called DeepCode AI to identify vulnerabilities in real-time. It integrates directly into IDEs, repositories, and CI/CD pipelines to provide rapid, context-aware security insights and automated remediation suggestions.
cubic Freemium
Cubic Cubic is an AI-native code review platform that provides semantic, context-aware analysis across your entire codebase rather than just reviewing PR diffs. It helps teams ship faster by detecting cross-file logic bugs, enforcing custom team standards, and automating fixes directly within GitHub pull requests.
Kodus Freemium
Kodus Kodus is an open-source, model-agnostic AI code review platform that integrates directly into your Git workflow. It utilizes a Bring Your Own Key (BYOK) model, ensuring transparent, markup-free AI costs while allowing teams to use any LLM for context-aware code analysis and policy enforcement.
Gito Open Source
Vitalii Stepanenko Gito is an open-source, vendor-agnostic AI code review tool that integrates with GitHub and GitLab to detect security vulnerabilities, bugs, and maintainability issues. It operates as a stateless, client-side tool, ensuring that source code is sent directly to the user's chosen LLM without intermediaries.
Bubo Free
MountainOwl Bubo is an agentic, self-hosted AI code review tool that watches GitHub and GitLab repositories to provide inline, actionable feedback on pull requests and merge requests. By using the LLM of the user's choice, it focuses on high-signal findings while suppressing noise and maintaining strict data privacy on the user's own infrastructure.
heygrc Freemium
ISMS Copilot / Better ISMS heygrc is a compliance-focused pull request reviewer that scans code changes against selected regulatory frameworks like SOC 2 and ISO 27001. It integrates as a GitHub App to provide control-grounded feedback and check statuses, ensuring that code updates comply with specific audit requirements before merging.
Mydentify AI Crawler Access Checker Free
Mydentify / Timothy Allard Mydentify AI Crawler Access Checker is a diagnostic tool that identifies whether public web pages are accessible to specific AI crawlers from OpenAI and Anthropic. It evaluates robots.txt files, page-level meta directives, and HTTP responses to help website owners troubleshoot visibility issues for search, retrieval, and training bots.
Vercel Agent Freemium
Vercel Vercel Agent is an AI-powered development assistant integrated directly into the Vercel platform. It leverages deep context from your project's codebase, deployments, logs, and infrastructure to perform tasks like code reviews, production investigations, and automated remediations.
Graphite Freemium
Graphite Graphite is an AI-powered code review platform and workflow tool designed to help engineering teams ship code faster through stacked pull requests. It integrates directly with GitHub to provide a seamless experience featuring a powerful CLI, an automated merge queue, and an AI agent for real-time code analysis and collaboration.
Bito Freemium
Bito Bito is an AI development platform that provides a codebase-aware knowledge graph (AI Architect) to ground coding agents and development workflows. It integrates with IDEs, CLI, and Git providers to automate technical design, grounded code generation, and codebase-aware pull request reviews.
security-audit Open Source
Cloudflare security-audit is the coding-agent skill that seeded Cloudflare's fleet-wide vulnerability discovery harness (described in the Cloudflare blog post "Build your own vulnerability harness"), released as a single-repo starting point. It orchestrates isolated agents through six phases: reconnaissance that maps architecture, trust boundaries, and input surfaces into `architecture.md` and a `coverage-ledger.json`; coverage-led hunting where isolated hunters attack ledger units and coverage critics look for gaps; candidate validation where a fresh verifier tries to disprove each finding; structured output of `confirmed`, `needs_validation`, and `rejected` records into a schema-validated `findings.json`; independent record verification of every source claim; and target-neutral `REPORT.md`, `FINDINGS-DETAIL.md`, and `NEEDS-VALIDATION.md` reports. Attack-class playbooks cover web protocol and auth, client-side, supply chain and release, cloud and deployment, RPC and messaging, resource exhaustion, data isolation, desktop/mobile/local IPC, memory safety and binaries, and prompt-injection and tool-use classes for LLM-backed targets. Repeat runs are additive, reusing prior ledgers and findings to target gaps and revalidate changed code.
Open Code Review Open Source
Alibaba Open Code Review is an AI-powered CLI tool that uses a hybrid architecture combining deterministic engineering with LLM agents to provide precise, line-level code reviews. Originally built as Alibaba's internal review assistant, it optimizes for high precision and efficiency by using rule-based file filtering and bundling to reduce token consumption and improve reliability.
FAQ
What are the best Code Review tools?

The most complete Code Review listings on ai.dosa.dev include CodeRabbit, Qodo, Snyk Code. Every tool has a detail page with pricing, key features, and a verdict - see the full list of 14 tools below.

Are Code Review tools free?

5 of the 14 Code Review tools listed here are free or open source. Others offer freemium or paid plans - check each tool's detail page for current pricing.

How is this list curated?

ai.dosa.dev is manually curated from community submissions and editorial review. Entries are enriched with pricing, features, and reviewer notes, and the directory is updated continuously.