Application Security — hobby stack.
For each requirement below, pick the option that fits your build — recommended first, then free and cheaper alternatives — or skip what your project doesn't need. Tap the info icon next to any requirement to see why it matters.
SAST Platform (Static Application Security Testing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: SonarQube CE $0 self-host unlimited LOC, CodeQL $0 public repos unlimited | SonarCloud Team $150/mo for 100k LOC + $50 per extra 100k, Free tier 50k LOC | Snyk Code Free 200 scans/mo, Team $25/dev/mo ($300/yr) unlimited | Semgrep Pro Team $40/dev/mo | Checkmarx One Enterprise $50k/yr (~$4167/mo) for 25 devs, overage $2k per 5 devs
SCA Dependency Scanning (Software Composition Analysis)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Dependabot $0 unlimited alerts/PRs, npm audit $0, OSV-Scanner $0 | Snyk Free 200 tests/mo 1 org, Team $25/dev/mo unlimited tests + fix PRs | Socket Free 100 repos 50k installs/mo, Pro $20/mo org + $5/dev/mo up to 500 repos, Team $20/dev/mo | Mend $30k/yr base (~$2500/mo), overage $50 per extra dev
Secrets Scanning & Detection
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: TruffleHog OSS $0 unlimited repos, Gitleaks OSS $0, GitHub Secret Scanning $0 public + private | GitGuardian Free 25 devs/history scan, $20/dev/mo after ($500/mo for 25 devs), Business $40/dev/mo ($1000/mo for 25), overage $25 per 1000 extra secrets | Doppler Free 250 secrets 25 devs
DAST Scanning (Dynamic Application Security Testing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: ZAP $0 unlimited scans, self-hosted | StackHawk Free 1 app 1 scan/mo, Pro $99/mo 5 apps 5 scans/mo, $399/mo Team 20 apps | Burp Suite Pro $449/yr per user (~$37/mo) one-time license, Enterprise $6,999/yr (~$583/mo) for 10 scan slots + 1 agent $0.10 per extra scan hour | Invicti $25k/yr
Web Application Firewall (WAF) for App Protection
Controls and protects your APIs — quotas, abuse prevention, and firewalls. Important once you have real traffic or many clients.Pricing & free-tier limitsFree: Cloudflare Free 1 custom rule + unmetered DDoS $0 | Cloudflare Pro $20/mo 20 rules + $5/mo managed ruleset, Business $200/mo 100 rules + managed, Enterprise $5000/mo custom ruleset unlimited | AWS WAF $5/mo per WebACL + $1/mo per rule + $1 per 1M req, overage $0.60 per M after 10M | Imperva $1200/mo avg 10M req, Fastly NGWAF $2000/mo base + $0.10 per 1000 reqs over
Container Image Vulnerability Scanning
Where you keep files users upload or you serve — images, videos, documents — and how fast they reach visitors around the world.Pricing & free-tier limitsFree: Trivy OSS $0 unlimited images, Grype OSS $0, Docker Scout Free 3 repos | Snyk Container Free 200 tests/mo, Team $25/dev/mo unlimited | Docker Scout Pro $20/mo 25 repos $0.50 per extra repo | Anchore Enterprise $35k/yr (~$2916/mo) 100 hosts, Wiz $30k/yr base
Infrastructure-as-Code (IaC) Security Scanning
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Checkov OSS $0 unlimited IaC, tfsec OSS $0, KICS OSS $0 1000 scans/mo | Snyk IaC Free 200 tests/mo, Team $25/dev/mo | Prisma Cloud Code Security $24k/yr (~$2000/mo) 100 IaC repos $100 per extra repo, Wiz IaC included in $30k/yr
CI/CD Pipeline Security & Supply Chain Hardening
Automates testing and deploying your code. Saves enormous time and prevents “works on my machine” releases.Pricing & free-tier limitsFree: Scorecard $0 unlimited, Dependabot Review $0, StepSecurity Free 1 repo | GitHub Advanced Security $3.67/user/mo ($44/user/yr) minimum 10 users $36.70/mo, Enterprise $6.50/user/mo | StepSecurity Pro $50/mo 10 repos $100/mo Team, Enterprise $500/mo 100 repos | GitLab Ultimate $99/user/mo
Software Bill of Materials (SBOM) Generation Platform
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Syft OSS $0 unlimited artifacts, CycloneDX $0, Trivy $0 unlimited SBOM gen | Anchore Cloud Free 50 SBOMs/mo $0, Pro $50/mo 500 SBOMs $0.10 per extra SBOM | Mend SBOM module $15k/yr ($1250/mo) | Chainguard SBOM $0 with images
Static Secrets Management & Vault
Stores API keys and credentials safely, separate from your code. Leaking secrets is one of the most common breaches.Pricing & free-tier limitsFree: Vault OSS $0 self-host unlimited secrets, Infisical OSS $0 self-host, Doppler Free 25 devs 250 secrets | Infisical Cloud Free 1000 secrets $12/mo Starter, Doppler Pro $20/dev/mo | HCP Vault $1.58/hr dev cluster ~$1150/mo + $0.03/secret/mo $0.05 per 10k API calls | AWS Secrets Manager $0.40/secret/mo + $0.05 per 10k calls, overage same
Code Security Linting / Pre-commit Security Hooks
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Semgrep OSS $0 unlimited scans, pre-commit.com $0, Gitleaks hook $0 | Semgrep Pro Team $40/dev/mo ($30 annual) includes 1000 Pro scans, Business $60/dev/mo | Snyk Code $25/dev/mo unlimited includes pre-commit hook
How this hobby application security checklist works.
Each requirement below is something a hobby application security build typically needs. Pick one of the four researched options — recommended, free, cheaper or paid — add your own with "Other", or skip the requirement if your project doesn't need it. Nothing is mandatory; the plan on the right tracks what you've decided so nothing gets forgotten.
Your picks are saved in this browser automatically, so you can come back anytime. Options are researched per build level and refreshed as vendors change their plans — always verify details on the provider's page before committing.