Cubic
AI PR Review · Proprietary
AI code review for GitHub PRs plus scheduled whole-codebase bug scans, with local CLI review, custom agents, and issue checks.
The AI Code Review Directory · Updated 2026-08-11
No star ratings and no affiliate rankings. 27 tools mapped against 9 engineering standards — pricing, licence, self-hosting, model control — each with the source it came from and the date we checked it.
One pick per dimension, each the highest-scoring tool that qualifies. The ranked list below is pure arithmetic — this strip is where we choose which dimension leads.
Ranked by documented coverage of the 9 standards. Filter it, then open any tool for the sourced matrix behind its score.
Showing all 27 tools
AI PR Review · Proprietary
AI code review for GitHub PRs plus scheduled whole-codebase bug scans, with local CLI review, custom agents, and issue checks.
AI PR Review · Proprietary
Code review agent in the Cosmos platform: risk-triaged inline PR comments with full-codebase context; GitHub-native, others via CLI.
AI PR Review · Proprietary
Review platform running specialized agents (code, spec, security, merge) on GitHub, GitLab, and Azure DevOps PRs with sandbox execution.
AI PR Review · AGPL-3.0
Open-source AI code review built to run where the organization controls: self-hosted or cloud, models under your keys, org-wide Kody Rules.
AI PR Review · Proprietary
PR reviewer with severity-ranked comments and one-click fixes across GitHub, GitLab, Bitbucket, and Azure DevOps, plus SAST scanning.
AI PR Review · Proprietary
Reviews PRs on GitHub, GitLab, and Bitbucket with codebase and team context, plus CLI pre-PR review and engineering metrics.
AI PR Review · Proprietary
Hosted AI PR reviewer with summaries, linter/SAST integration, and agentic chat across GitHub, GitLab, Azure DevOps, and Bitbucket.
Security · LGPL-2.1
Open-source static analysis engine with a commercial AppSec Platform adding cross-file analysis and an AI assistant for triage.
AI PR Review · Proprietary
AI code reviewer that indexes the whole codebase into a graph; its TREX agent writes and runs tests for PRs in a sandbox.
AI PR Review · Proprietary
Enterprise AI dev platform whose Code Review Agent checks PRs against plain-language team rules on GitHub, GitLab, and Bitbucket.
Code Quality · LGPL-3.0
Deterministic static analysis platform (Server and Cloud) with PR decoration and LLM-generated AI CodeFix suggestions.
Code Quality · Proprietary
Code-quality platform covering 49 languages and 12,000+ static rules, SAST, secrets, SCA, and IaC, with an AI review layer on top.
Static Analysis · Proprietary
JetBrains' static analysis for CI, running IDE inspections in pipelines with quality gates, baselines, and cloud reports.
AI PR Review · Proprietary
AI platform spanning IDE assistant, CLI, and Qodo Merge PR review with test generation; enterprise on-prem and air-gapped options.
AI PR Review · Proprietary
Google's coding assistant whose GitHub app auto-reviews pull requests with severity-ranked comments and committable fixes.
AI PR Review · Proprietary
Vercel Labs' self-hosted GitHub review bot: mention @openreview for Claude-powered inline suggestions; dormant beta since March 2026.
Security · Proprietary
Developer-focused SAST built on Snyk's DeepCode AI engine, with PR checks and AI fix suggestions across major git platforms.
Security · Proprietary
All-in-one AppSec platform (SAST, SCA, secrets, cloud) with AI autotriage and autofix PRs, built on tuned open-source scanners.
AI PR Review · Proprietary
Cursor's PR reviewer scoped to bugs, security issues, and rule violations, billed per run (avg $1.00-1.50) since June 2026.
AI PR Review · MIT
Community-maintained, MIT-licensed PR reviewer with /review, /describe, and /improve commands, self-hosted with your own model keys.
AI PR Review · Proprietary
AI Code Review Agent for GitHub, GitLab, and Bitbucket with repo-aware reviews, custom guidelines, Jira integration, and analytics.
AI PR Review · Proprietary
Pull request review bundled into paid GitHub Copilot plans; reviews the diff with instructions-file customization, metered by AI credits.
AI PR Review · Proprietary
AI reviewer for GitHub and GitLab with line-by-line reviews, summaries and diagrams, custom rules, and BYO-LLM on its Team tier.
Code Quality · Proprietary
Static-analysis platform (quality, coverage, secrets) with Autofix and a metered AI Review add-on; free for open-source repos.
AI PR Review · Proprietary
AI code reviewer with 30,000+ security checks, IaC and secrets scanning, and business context pulled from Jira and Confluence.
AI PR Review · Proprietary
Writes PR descriptions from the diff, sends changelog notifications to stakeholders, and does small /wtd refactors on GitHub and GitLab.
AI PR Review · Proprietary
Code review platform built around stacked PRs, with an AI reviewer (formerly Diamond), merge queue, and review automation for GitHub.
Nothing matches those filters.
The same data as the cards above, in one scannable table. Coverage is capability documented by the vendor, not review quality — read the methodology before treating it as a verdict.
| # | Tool | Coverage | Self-hosting | Licence | Free tier | From |
|---|---|---|---|---|---|---|
| 1 | Cubic AI PR Review | 7.5/9 Coverage score 7.5 out of 9 | Unknown | Proprietary | Limited free tier | $30/dev/mo |
| =2 | Augment Code AI PR Review | 6.5/9 Coverage score 6.5 out of 9 | Cloud only | Proprietary | Unknown | $100/mo flat |
| =2 | Baz AI PR Review | 6.5/9 Coverage score 6.5 out of 9 | Enterprise only | Proprietary | Unknown | $30/dev/mo |
| =2 | Kodus AI PR Review | 6.5/9 Coverage score 6.5 out of 9 | Self-hostable | Open source | Limited free tier | $10/dev/mo |
| =2 | CodeAnt AI AI PR Review | 6.5/9 Coverage score 6.5 out of 9 | Enterprise only | Proprietary | Trial only | $24/user/mo |
| =2 | Entelligence AI AI PR Review | 6.5/9 Coverage score 6.5 out of 9 | Self-hostable | Proprietary | Unknown | See pricing |
| 7 | CodeRabbit AI PR Review | 6/9 Coverage score 6 out of 9 | Enterprise only | Proprietary | Limited free tier | $24/dev/mo |
| =8 | Semgrep Security | 4.5/9 Coverage score 4.5 out of 9 | Self-hostable | Open source | Limited free tier | $30/contributor/mo |
| =8 | Greptile AI PR Review | 4.5/9 Coverage score 4.5 out of 9 | Enterprise only | Proprietary | Limited free tier | $30/seat/mo |
| =8 | Tabnine AI PR Review | 4.5/9 Coverage score 4.5 out of 9 | Self-hostable | Proprietary | No free tier | $39/user/mo |
| =11 | SonarQube Code Quality | 4/9 Coverage score 4 out of 9 | Self-hostable | Open source | Limited free tier | $34/mo |
| =11 | Codacy Code Quality | 4/9 Coverage score 4 out of 9 | Cloud only | Proprietary | Limited free tier | $18/dev/mo |
Tools whose main job is reviewing a pull request and leaving findings on the diff.
Cubic · Augment Code · Baz · Kodus
Scanners built around vulnerability classes, dependencies, and secrets rather than general review.
Semgrep · Snyk Code · Aikido Security
Platforms that track maintainability, duplication, and coverage across a whole codebase over time.
SonarQube · Codacy · DeepSource
Rule- and pattern-based analyzers that run without an LLM in the loop.
Qodana
Reviewers that run inside your own network, for teams whose code cannot leave it.
Which tools actually support GitHub, GitLab, Bitbucket, Azure DevOps and self-hosted forges — the shortest path to ruling candidates out.
GitHub · GitLab · Bitbucket · Azure DevOps
Tools whose source you can read, audit and fork before you trust them with your codebase.
A hands-on look at what "free" really means across AI code review tools — metered credits, trials, BYO-LLM, and how to evaluate them.
Most AI reviewers catch generic bugs. Whether one will follow your team's own coding rules is a separate question. Here's how to evaluate custom-standards support before you buy.
Pullfrog is a BYOK harness over Claude Code and Codex, not a first-party reviewer like CodeRabbit. Review quality is model-attributed, not harness-attributed. Here's what actually separates them.
An eval-grounded look at Pullfrog vs CodeRabbit: when a reviewer wraps Claude Code or Codex, review quality is model-attributed, not harness-attributed. The real difference is the credential boundary.
9 standards every AI code reviewer should meet, and why each one exists. This is what the scores are measured against.
LearnLong-form guides on running code review well — process, metrics, security, scale — independent of which tool you buy.
ReferencePlain definitions for the vocabulary vendors use — from cyclomatic complexity to BYOK — with what it means when you are buying.
There is no single best one — it depends on which of the 9 standards your team actually needs. This directory ranks 27 tools by how much of that baseline each vendor's own documentation backs up, and shows the full matrix so you can re-rank on the pillars that matter to you. As of 2026-08-11, Cubic leads on documented coverage at 7.5/9.
Each tool is mapped against 9 standards with four values: documented (1 point), partial (0.5), not offered (0) and undocumented (0). The sum is the score out of 9. Undocumented counts as zero on purpose — a capability nobody can find in the docs is one a buyer cannot rely on. The full formula and the sources are public.
8 of the 27 tools in this directory document full self-hosting on their standard plans; several more offer it only on an enterprise contract. If code cannot leave your network, filter the directory by self-hosting before you compare anything else.
Yes — 4 of the 27 tools here publish their source. Open source and self-hostable are not the same thing, and the licence matters: some are permissive, some copyleft, some dual-licensed with commercial-only files.
Every tool carries the date its facts were last checked against the vendor's own documentation — currently 2026-08-11 across the directory. Pricing and plan changes are the most common corrections; the dataset is public, so a stale row can be reported and fixed directly.
Score your own setup, not just the vendors'
The same 9 standards, turned into a 10-minute readiness assessment.