Vital signs
Why it's on the table
On the table, Code Review (Cq) is seat 7 of 58, in the Build family. It is an emerging element — the job is real and here to stay, but the leaderboard still changes quarterly. Choose for this quarter, hold loosely, and watch the changelog. It is optional: plenty of companies run without it — until a specific trigger (scale, regulation, cost, or customers) makes it essential for them. It sits in the lowest paid band — lunch money against the hours it returns.
Code Review: the top 5 — v2026.Q3
Edition v2026.Q3 · ranking, pricing and status verified 2026-08-06.
1CodeRabbitCodeRabbit Inc.
Free tier (PR summaries, IDE/CLI reviews) · Pro $24/user/mo · Pro Plus $48 · Enterprise custom (self-host)Best for Teams shipping AI-speed code who want line-by-line PR review with linters, security checks, and chat — installed in minutes on GitHub/GitLab/Azure/Bitbucket.
The standalone-category leader by every measure: ~$40M ARR in April 2026, up 700% from ~$5M a year earlier (Sacra est.); 15,000+ customers, 6M repositories, 75M defects found; most-installed AI app on GitHub and GitLab. The $60M Series B (Sep 2025, $550M valuation) was pitched explicitly on vibe-coding cleanup demand — the same 2.7x-vulnerability wave this element exists to tax.
Watch Comment volume is the perennial complaint — tuning is required before it feels like a colleague rather than a lint firehose. ARR figures are Sacra estimates, not audited. Bundled reviewers (Copilot, Bugbot, Claude Code Review) are commoditizing baseline review from above.
2Copilot code reviewMicrosoft / GitHub
Included in all paid Copilot plans (Pro $10/mo → Enterprise $39/user) · consumes AI credits per review · not on Copilot FreeBest for Teams already paying for Copilot who want a reliable first-pass review on every PR with zero new vendors, contracts, or apps.
Distribution nobody can answer: 60M reviews since the April 2025 launch, 10x usage growth, and more than 1 in 5 of all code reviews on GitHub by March 2026, with 12,000+ orgs auto-reviewing every PR. Quality is climbing — 71% of reviews surface actionable feedback, and agent skills + MCP context went GA July 29, 2026.
Watch Depth trails the specialists in most independent roundups — it reviews the diff well but reads the codebase less deeply than Greptile or CodeRabbit. GitHub-only. The 2026 shift to AI-credit billing makes per-review cost opaque, and reviews are blocked when credit budgets run out.
3GraphiteGraphite → Cursor/Anysphere (Dec 2025; → SpaceX pending)
Hobby free · Starter $20/user/mo · Team $40 (unlimited AI reviews, merge queue) · Enterprise customBest for Teams who want to fix the review process, not just add a bot — stacked PRs, merge queue, and the Diamond AI reviewer in one flow.
The only top-5 pick that re-architects review itself: stacked PRs plus merge queue plus AI review (Diamond, launched with the $52M Accel-led Series B in March 2025 — Anthropic's Anthology Fund participated). Used by hundreds of thousands of engineers, and now the code-review arm of the Cursor empire after the December 19, 2025 acquisition — the strongest possible signal that review and generation are converging.
Watch Ownership churn squared: acquired by Cursor, which is itself being acquired by SpaceX ($60B, close expected Q3 2026). Stacked-PR workflow has a real adoption cost for teams happy with plain PRs, and unlimited AI review requires the $40 Team tier.
4GreptileGreptile (YC W24)
Free 50 credits/mo · Pro $30/seat incl. 50 reviews, $1/extra review · Enterprise custom (self-host, SSO)Best for Complex codebases and monorepos — it indexes the whole repository graph so reviews catch cross-file breakage a diff-reader can't see.
The context-depth play: full-codebase indexing rather than diff-only review, a v3 rewrite the company says catches 3x more critical bugs than v2, and a learning system that absorbs your engineers' review comments. Benchmark led the $25M Series A (Sep 23, 2025); customers include Brex, Substack, and PostHog, with 500M+ lines reviewed and 180k+ bugs prevented at announcement.
Watch Per-credit pricing stacks up fast on high-throughput repos ($1/review beyond the included 50). Headline bug-catch numbers are self-published, not independently benchmarked. Smallest vendor in the top 5 — procurement-sensitive orgs will notice.
5BugbotCursor/Anysphere (→ SpaceX pending)
Usage-based $1.00–1.50/review since Jun 8, 2026 (was $40/seat/mo) · individuals draw from Cursor plan usageBest for Cursor-native teams who want a pure bug-hunter on every PR — logic errors and edge cases, not style commentary — with one-click fixes back in the editor.
Rides the largest AI-coding install base on earth (Cursor: 1M+ paying users, $3B ARR by May 2026) and stays deliberately narrow: hard bugs only, with a claimed 80% resolution rate on flagged issues and a high-effort mode that finds 35% more bugs at the same precision (May 2026). The June 2026 move to $1–1.50 per review made it the cheapest credible entry point in the category.
Watch Not a full reviewer — no summaries, style, or architectural feedback; you still need review process elsewhere. Pricing model changed twice inside a year, and the SpaceX acquisition adds the same ownership uncertainty as Graphite. GitHub-focused.
Code Review: the top 8 compared
Edition v2026.Q3 · ranking, pricing and status verified 2026-08-06.
| Tool | Pricing model | Free tier | Context depth | Learns your rules | Platforms | Autofix | Self-host |
|---|---|---|---|---|---|---|---|
| CodeRabbit | Seat $24–48 | Yes (+ OSS free) | Repo + linked repos + 40 linters | Yes (chat, learnings) | GitHub · GitLab · Azure · Bitbucket | 1-click fixes | Enterprise |
| Copilot code review | AI credits on paid plans | No (paid Copilot only) | Diff + agentic context | Instructions + skills + MCP | GitHub only | Suggested edits | No |
| Graphite | Seat $20–40 | Hobby free | PR + stack context | Customizations, automations | GitHub (GHES on Ent.) | Limited | No (GHES support) |
| Greptile | Seat $30 + $1/review | 50 reviews/mo | Full codebase graph | Yes (learns from comments) | GitHub · GitLab | Agent-ready fix prompts | Enterprise |
| Bugbot | $1–1.50/review | Via Cursor plans | Diff-focused, bug-only | Rules + effort levels | GitHub | Fix in Cursor | No |
| Qodo | Credits $0.012 ea | 14-day trial + OSS free | Repo-aware | Rules; self-learning (Ent.) | GitHub · GitLab · Bitbucket · Azure | Yes | On-prem / single-tenant |
| Claude Code Review | $15–25/review (usage credits) | No (Team/Ent preview) | Full codebase, multi-agent + verification | CLAUDE.md + REVIEW.md | GitHub (GitLab via CI) | Via Claude Code /code-review --fix | Run in own CI |
| PR-Agent (community) | Free + your tokens | Yes (Apache-2.0) | Diff-focused | Config files | GitHub · GitLab · Bitbucket · Gitea | Suggestions | Yes |
How to choose your code review
- If coding agents are writing most of your code and PRs pile up faster than humans can read them
- CodeRabbit — the fastest install-to-value in the category, then spend a week tuning its noise down. Review is the tax on AI velocity; this automates the tax.
- If you already pay for Copilot and procurement hates new vendors
- Turn on Copilot code review org-wide — a 71%-actionable first pass for AI credits you already budget, with the honest caveat that it reads the diff, not your architecture.
- If review latency is the bottleneck — big PRs rotting for days
- Graphite — stacked PRs plus merge queue attacks the process, and Diamond handles the first pass. Accept the Cursor→SpaceX ownership uncertainty.
- If you run a monorepo or a gnarly legacy codebase where diff-only review misses cross-file breakage
- Greptile — full-codebase indexing is the whole product; budget ~$1/review beyond the included 50.
- If you expect AI review to catch security holes
- Don't — AI code stalls at a 56% security pass rate (Veracode, Jul 2026) and general reviewers are not SAST. Pair any pick with a real scanner (Snyk/Semgrep class) and, if on Claude, the free claude-code-security-review action.
Code Review: the whole field
23 more tools tracked in this category, including 6 dead, renamed, or sunsetting — a reference that hides the graveyard isn't one. Verified 2026-08-06.
| Tool | Maker | What it is | Entry | Status |
|---|---|---|---|---|
| Qodo (Qodo Merge) | Qodo (ex-CodiumAI) | Enterprise agentic review platform (credits at $0.012, BYOK, on-prem); expanded to Azure DevOps Feb 2026; handed its open-source PR-Agent to the community Apr 2026 — the strongest enterprise near-miss for the top 5 | credits $0.012 · Ent. 30+ seats | active |
| Claude Code Review | Anthropic | Multi-agent review with a false-positive verification pass, on Anthropic infra; research preview for Team/Enterprise at $15–25/review; /code-review runs free-of-setup locally on any plan; deepest verification story, narrowest availability | $15–25/review (usage credits) | active |
| PR-Agent | community (Apache-2.0, ex-Qodo) | The original open-source PR reviewer — re-licensed AGPL→Apache-2.0 and moved to community governance Apr 23, 2026; the default free self-hosted answer | free + tokens | active |
| claude-code-security-review | Anthropic (open source) | Free GitHub Action doing security-focused diff review with Claude; a June 2026 prompt-injection flaw in the broader claude-code-action was patched — audit your workflow permissions | free + API tokens | active |
| Gemini Code Assist on GitHub | The free consumer review agent was shut down Jul 17, 2026 (deprecated Jun 18) — enterprise version via Google Cloud continues; same retreat pattern as Gemini CLI | enterprise only | sunsetting | |
| Ellipsis | Ellipsis (YC W24) | Early AI reviewer that expanded upward — launched 'Agent Cloud' (managed coding agents) Jul 28, 2026; review remains but is no longer the whole company; 400+ teams | ~$20/dev/mo | active |
| Sourcery | Sourcery AI | Veteran review + refactoring bot for GitHub/GitLab, Python roots; steady but out-momentumed by the funded pack | free OSS · ~$12/mo | active |
| Bito AI Code Review Agent | Bito | Repo-aware review agent with static-analysis/security tool fusion; free plan plus ~$15/user teams tier | free · ~$15/user/mo | active |
| Baz | Baz (Guy Eisenkot) | AI-native review platform pitching governance/specs for AI-generated code; seed-stage, enterprise-leaning | unverified | active |
| cubic | cubic (YC X25) | 'Cursor for code review' — review UI + AI reviewer aimed at AI-generated-code failure modes | free tier | active |
| Macroscope | Macroscope | Code review + codebase-understanding layer; markets itself against Bugbot | unverified | active |
| Entelligence | Entelligence AI | Review bot + engineering-intelligence dashboards (aggregator-sourced; verify before buying) | free tier | active |
| CodeAnt AI | CodeAnt (YC W24) | Review + SAST hybrid — one of the few pitching security and review in one bot | ~$10/dev/mo | active |
| Panto AI | Panto | Context-aware PR review agent, India-based, undercuts on price (aggregator-sourced) | free tier | active |
| Korbit AI | Korbit | Mentor-style PR reviews with quality scoring; quiet through 2026 roundups | ~$9/dev/mo | fading |
| DeepSource | DeepSource (YC W20) | Static analysis platform with AI Autofix — code-quality adjacent rather than conversational review | free · ~$24/seat | active |
| Codacy | Codacy | Classic code-quality platform bolting on AI guardrails for AI-generated code | free · ~$15/seat | active |
| SonarQube AI Code Assurance | Sonar | The 400k-org static-analysis incumbent's answer: detect/assure AI-written code; complements rather than replaces agentic reviewers | free community · paid tiers | active |
| CodeScene | CodeScene | Behavioral code analysis + ACE auto-refactoring; technical-debt lens on review | free trial · per-seat | active |
| Sweep | Sweep AI (YC S23) | Left the review/PR-bot business — pivoted to a JetBrains autocomplete/coding assistant | — | fading |
| What The Diff | Beyond Code | Early AI PR-summary tool (2022 wave); superseded by full review agents | free tier | fading |
| Codeball | Sturdy (YC) | 2022 deep-learning PR reviewer; repo dormant for years — the category's first graveyard entry | — | dead |
| PullRequest | → HackerOne | Human code-review-as-a-service marketplace, acquired by HackerOne (2022) and absorbed into its security offering | — | acquired |
Code Review: the category in numbers
Edition v2026.Q3 · ranking, pricing and status verified 2026-08-06.
- AI now authors ~half of committed code, but its security pass rate stalled at 56% (55% in 2025) — ~44% of AI code-generation tasks introduce vulnerabilities; top model (GPT-5.5) only 68% (Veracode 2026 GenAI Code Security Report, Jul 28, 2026, 100+ models) [src]
- Copilot code review passed 60M reviews and >1 in 5 of all code reviews on GitHub (Mar 2026) — bundled review is now the category's biggest player by volume [src]
- CodeRabbit: ~$5M → ~$40M ARR Apr 2025 → Apr 2026 (+700%, Sacra est.); $60M Series B at $550M (Sep 2025) raised explicitly on vibe-coding cleanup demand [src]
- Consolidation into codegen platforms: Cursor acquired Graphite Dec 19, 2025, then agreed to be acquired by SpaceX for $60B (Jun 2026) — putting two of the top five reviewers (Graphite, Bugbot) under one pending owner [src]
- Pricing is shifting seat → usage across the category in 2026: Bugbot $40/seat → $1–1.50/review (Jun 8), Qodo credits at $0.012, Claude Code Review $15–25/review, Copilot per-review AI credits [src]
- Free/community tiers in flux: Google shut its consumer Gemini Code Assist review agent Jul 17, 2026 (enterprise-only now); Qodo handed PR-Agent to community governance under Apache-2.0 (Apr 23, 2026) [src]
Code Review: method & sources
Ranking criteria: verified adoption/revenue, review depth (codebase context, false-positive control), platform breadth, and momentum — no affiliate consideration. On the tile's '2.7x vulnerability rate': we could not trace 2.7x to a primary study (it circulates via SEO aggregators like SQ Magazine without citation); the defensible anchor is Veracode's Jul 2026 finding that ~44% of AI code-generation tasks introduce vulnerabilities and the pass rate has stalled at 56% — treat 2.7x as directionally right, not citable. Conflicts resolved: CodeRabbit and Qodo ARR figures are Sacra/aggregator estimates, not audited — we cite them as estimates; ideaplan.io's '$420M category ARR / 140k paid users' market-share numbers are aggregator-only and excluded from signals; Greptile's '3x more bugs' and Bugbot's '80% resolution' are vendor-published. Claude Code Review sits in the field, not the top 5, because it is a research preview restricted to Team/Enterprise plans at $15–25/review — technically the most rigorous verification pipeline in the category, but not yet broadly buyable; revisit next quarter. Adjacent elements: coding agents that also review (Claude Code, Cursor, Copilot as assistants) → Ca; SAST/security scanners proper (Snyk, Semgrep, Veracode, Checkmarx) are security tooling, not this element — only review/SAST hybrids (CodeAnt, Sonar) get field entries; LLM-app evals → Ev. Graphite ownership stated as Cursor/Anysphere with SpaceX close pending Q3 2026. Ranking criteria: verified commercial traction, independent satisfaction surveys, agent benchmarks, and founder-fit (price floor, lock-in, surfaces). Editorial, never paid — the charter. Machine-readable twin: cq.json.
All sources (21)
- https://sacra.com/c/coderabbit/
- https://www.coderabbit.ai/pricing
- https://markets.financialcontent.com/observerreporter/article/bizwire-2025-9-16-coderabbit-raises-60m-series-b-following-unprecedented-growth-as-vibe-coding-triggers-a-need-for-new-code-quality-standards
- https://github.blog/ai-and-ml/github-copilot/60-million-copilot-code-reviews-and-counting/
- https://github.blog/changelog/2026-07-29-copilot-code-review-agent-skills-and-mcp-now-generally-available/
- https://docs.github.com/en/copilot/concepts/agents/code-review
- https://cursor.com/blog/graphite
- https://techcrunch.com/2025/12/19/cursor-continues-acquisition-spree-with-graphite-deal
- https://graphite.com/pricing
- https://thesaasnews.com/news/graphite-raises-52-million-in-series-b
- https://cursor.com/blog/may-2026-bugbot-changes
- https://www.greptile.com/blog/series-a
- https://www.greptile.com/pricing
- https://www.qodo.ai/pricing/
- https://www.qodo.ai/blog/qodo-is-handing-pr-agent-over-to-the-community/
- https://code.claude.com/docs/en/code-review
- https://www.veracode.com/blog/2026-genai-code-security-report-ai-risk/
- https://www.businesswire.com/news/home/20260728207685/en/LLMs-Are-Getting-Smarter-But-Not-Safer-Veracode-2026-GenAI-Code-Security-Report-Finds-AI-Generated-Code-Security-Has-Stalled-at-56-Pass-Rate
- https://developers.google.com/gemini-code-assist/docs/deprecations/consumer-code-review
- https://github.com/The-PR-Agent/pr-agent
- https://en.wikipedia.org/wiki/Cursor_(company)
Our take
AI code carries a 2.7x vulnerability rate. Review is the tax you pay for velocity — automate the tax.
Combines with
This is element 7 of 58. The table is versioned quarterly — when a tool loses its seat, the changelog records the succession.
Explore the full table →