Stack Cost AI

Application Securityhobby stack.

For each requirement below, pick the option that fits your build — recommended first, then free and cheaper alternatives — or skip what your project doesn't need. Tap the info icon next to any requirement to see why it matters.

SAST Platform (Static Application Security Testing)

Pricing & free-tier limitsFree: SonarQube CE $0 self-host unlimited LOC, CodeQL $0 public repos unlimited | SonarCloud Team $150/mo for 100k LOC + $50 per extra 100k, Free tier 50k LOC | Snyk Code Free 200 scans/mo, Team $25/dev/mo ($300/yr) unlimited | Semgrep Pro Team $40/dev/mo | Checkmarx One Enterprise $50k/yr (~$4167/mo) for 25 devs, overage $2k per 5 devs

SCA Dependency Scanning (Software Composition Analysis)

Pricing & free-tier limitsFree: Dependabot $0 unlimited alerts/PRs, npm audit $0, OSV-Scanner $0 | Snyk Free 200 tests/mo 1 org, Team $25/dev/mo unlimited tests + fix PRs | Socket Free 100 repos 50k installs/mo, Pro $20/mo org + $5/dev/mo up to 500 repos, Team $20/dev/mo | Mend $30k/yr base (~$2500/mo), overage $50 per extra dev

Secrets Scanning & Detection

Pricing & free-tier limitsFree: TruffleHog OSS $0 unlimited repos, Gitleaks OSS $0, GitHub Secret Scanning $0 public + private | GitGuardian Free 25 devs/history scan, $20/dev/mo after ($500/mo for 25 devs), Business $40/dev/mo ($1000/mo for 25), overage $25 per 1000 extra secrets | Doppler Free 250 secrets 25 devs

DAST Scanning (Dynamic Application Security Testing)

Pricing & free-tier limitsFree: ZAP $0 unlimited scans, self-hosted | StackHawk Free 1 app 1 scan/mo, Pro $99/mo 5 apps 5 scans/mo, $399/mo Team 20 apps | Burp Suite Pro $449/yr per user (~$37/mo) one-time license, Enterprise $6,999/yr (~$583/mo) for 10 scan slots + 1 agent $0.10 per extra scan hour | Invicti $25k/yr

Web Application Firewall (WAF) for App Protection

Pricing & free-tier limitsFree: Cloudflare Free 1 custom rule + unmetered DDoS $0 | Cloudflare Pro $20/mo 20 rules + $5/mo managed ruleset, Business $200/mo 100 rules + managed, Enterprise $5000/mo custom ruleset unlimited | AWS WAF $5/mo per WebACL + $1/mo per rule + $1 per 1M req, overage $0.60 per M after 10M | Imperva $1200/mo avg 10M req, Fastly NGWAF $2000/mo base + $0.10 per 1000 reqs over

Container Image Vulnerability Scanning

Pricing & free-tier limitsFree: Trivy OSS $0 unlimited images, Grype OSS $0, Docker Scout Free 3 repos | Snyk Container Free 200 tests/mo, Team $25/dev/mo unlimited | Docker Scout Pro $20/mo 25 repos $0.50 per extra repo | Anchore Enterprise $35k/yr (~$2916/mo) 100 hosts, Wiz $30k/yr base

Infrastructure-as-Code (IaC) Security Scanning

Pricing & free-tier limitsFree: Checkov OSS $0 unlimited IaC, tfsec OSS $0, KICS OSS $0 1000 scans/mo | Snyk IaC Free 200 tests/mo, Team $25/dev/mo | Prisma Cloud Code Security $24k/yr (~$2000/mo) 100 IaC repos $100 per extra repo, Wiz IaC included in $30k/yr

CI/CD Pipeline Security & Supply Chain Hardening

Pricing & free-tier limitsFree: Scorecard $0 unlimited, Dependabot Review $0, StepSecurity Free 1 repo | GitHub Advanced Security $3.67/user/mo ($44/user/yr) minimum 10 users $36.70/mo, Enterprise $6.50/user/mo | StepSecurity Pro $50/mo 10 repos $100/mo Team, Enterprise $500/mo 100 repos | GitLab Ultimate $99/user/mo

Software Bill of Materials (SBOM) Generation Platform

Pricing & free-tier limitsFree: Syft OSS $0 unlimited artifacts, CycloneDX $0, Trivy $0 unlimited SBOM gen | Anchore Cloud Free 50 SBOMs/mo $0, Pro $50/mo 500 SBOMs $0.10 per extra SBOM | Mend SBOM module $15k/yr ($1250/mo) | Chainguard SBOM $0 with images

Static Secrets Management & Vault

Pricing & free-tier limitsFree: Vault OSS $0 self-host unlimited secrets, Infisical OSS $0 self-host, Doppler Free 25 devs 250 secrets | Infisical Cloud Free 1000 secrets $12/mo Starter, Doppler Pro $20/dev/mo | HCP Vault $1.58/hr dev cluster ~$1150/mo + $0.03/secret/mo $0.05 per 10k API calls | AWS Secrets Manager $0.40/secret/mo + $0.05 per 10k calls, overage same

Code Security Linting / Pre-commit Security Hooks

Pricing & free-tier limitsFree: Semgrep OSS $0 unlimited scans, pre-commit.com $0, Gitleaks hook $0 | Semgrep Pro Team $40/dev/mo ($30 annual) includes 1000 Pro scans, Business $60/dev/mo | Snyk Code $25/dev/mo unlimited includes pre-commit hook

Options and prices come straight from our research sheets for a hobby application security project. Prices are estimates and change often — always confirm on the provider's page before committing.

How this hobby application security checklist works.

Each requirement below is something a hobby application security build typically needs. Pick one of the four researched options — recommended, free, cheaper or paid — add your own with "Other", or skip the requirement if your project doesn't need it. Nothing is mandatory; the plan on the right tracks what you've decided so nothing gets forgotten.

Your picks are saved in this browser automatically, so you can come back anytime. Options are researched per build level and refreshed as vendors change their plans — always verify details on the provider's page before committing.