Application Security — small scale stack.
For each requirement below, pick the option that fits your build — recommended first, then free and cheaper alternatives — or skip what your project doesn't need. Tap the info icon next to any requirement to see why it matters.
SAST Platform (Static Application Security Testing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: SonarQube CE $0 self-host unlimited LOC, CodeQL $0 public repos unlimited | SonarCloud Team $150/mo for 100k LOC + $50 per extra 100k, Free tier 50k LOC | Snyk Code Free 200 scans/mo, Team $25/dev/mo ($300/yr) unlimited | Semgrep Pro Team $40/dev/mo | Checkmarx One Enterprise $50k/yr (~$4167/mo) for 25 devs, overage $2k per 5 devs
SCA Dependency Scanning (Software Composition Analysis)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Dependabot $0 unlimited alerts/PRs, npm audit $0, OSV-Scanner $0 | Snyk Free 200 tests/mo 1 org, Team $25/dev/mo unlimited tests + fix PRs | Socket Free 100 repos 50k installs/mo, Pro $20/mo org + $5/dev/mo up to 500 repos, Team $20/dev/mo | Mend $30k/yr base (~$2500/mo), overage $50 per extra dev
Secrets Scanning & Detection
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: TruffleHog OSS $0 unlimited repos, Gitleaks OSS $0, GitHub Secret Scanning $0 public + private | GitGuardian Free 25 devs/history scan, $20/dev/mo after ($500/mo for 25 devs), Business $40/dev/mo ($1000/mo for 25), overage $25 per 1000 extra secrets | Doppler Free 250 secrets 25 devs
DAST Scanning (Dynamic Application Security Testing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: ZAP $0 unlimited scans, self-hosted | StackHawk Free 1 app 1 scan/mo, Pro $99/mo 5 apps 5 scans/mo, $399/mo Team 20 apps | Burp Suite Pro $449/yr per user (~$37/mo) one-time license, Enterprise $6,999/yr (~$583/mo) for 10 scan slots + 1 agent $0.10 per extra scan hour | Invicti $25k/yr
Web Application Firewall (WAF) for App Protection
Controls and protects your APIs — quotas, abuse prevention, and firewalls. Important once you have real traffic or many clients.Pricing & free-tier limitsFree: Cloudflare Free 1 custom rule + unmetered DDoS $0 | Cloudflare Pro $20/mo 20 rules + $5/mo managed ruleset, Business $200/mo 100 rules + managed, Enterprise $5000/mo custom ruleset unlimited | AWS WAF $5/mo per WebACL + $1/mo per rule + $1 per 1M req, overage $0.60 per M after 10M | Imperva $1200/mo avg 10M req, Fastly NGWAF $2000/mo base + $0.10 per 1000 reqs over
Container Image Vulnerability Scanning
Where you keep files users upload or you serve — images, videos, documents — and how fast they reach visitors around the world.Pricing & free-tier limitsFree: Trivy OSS $0 unlimited images, Grype OSS $0, Docker Scout Free 3 repos | Snyk Container Free 200 tests/mo, Team $25/dev/mo unlimited | Docker Scout Pro $20/mo 25 repos $0.50 per extra repo | Anchore Enterprise $35k/yr (~$2916/mo) 100 hosts, Wiz $30k/yr base
Infrastructure-as-Code (IaC) Security Scanning
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Checkov OSS $0 unlimited IaC, tfsec OSS $0, KICS OSS $0 1000 scans/mo | Snyk IaC Free 200 tests/mo, Team $25/dev/mo | Prisma Cloud Code Security $24k/yr (~$2000/mo) 100 IaC repos $100 per extra repo, Wiz IaC included in $30k/yr
CI/CD Pipeline Security & Supply Chain Hardening
Automates testing and deploying your code. Saves enormous time and prevents “works on my machine” releases.Pricing & free-tier limitsFree: Scorecard $0 unlimited, Dependabot Review $0, StepSecurity Free 1 repo | GitHub Advanced Security $3.67/user/mo ($44/user/yr) minimum 10 users $36.70/mo, Enterprise $6.50/user/mo | StepSecurity Pro $50/mo 10 repos $100/mo Team, Enterprise $500/mo 100 repos | GitLab Ultimate $99/user/mo
Software Bill of Materials (SBOM) Generation Platform
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Syft OSS $0 unlimited artifacts, CycloneDX $0, Trivy $0 unlimited SBOM gen | Anchore Cloud Free 50 SBOMs/mo $0, Pro $50/mo 500 SBOMs $0.10 per extra SBOM | Mend SBOM module $15k/yr ($1250/mo) | Chainguard SBOM $0 with images
Static Secrets Management & Vault
Stores API keys and credentials safely, separate from your code. Leaking secrets is one of the most common breaches.Pricing & free-tier limitsFree: Vault OSS $0 self-host unlimited secrets, Infisical OSS $0 self-host, Doppler Free 25 devs 250 secrets | Infisical Cloud Free 1000 secrets $12/mo Starter, Doppler Pro $20/dev/mo | HCP Vault $1.58/hr dev cluster ~$1150/mo + $0.03/secret/mo $0.05 per 10k API calls | AWS Secrets Manager $0.40/secret/mo + $0.05 per 10k calls, overage same
Code Security Linting / Pre-commit Security Hooks
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Semgrep OSS $0 unlimited scans, pre-commit.com $0, Gitleaks hook $0 | Semgrep Pro Team $40/dev/mo ($30 annual) includes 1000 Pro scans, Business $60/dev/mo | Snyk Code $25/dev/mo unlimited includes pre-commit hook
Dependency Firewall / Malicious Package Detection (Supply Chain Firewall)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Socket Free 100 repos 50k package installs/mo $0, npm audit $0 | Socket Pro $20/mo org + $5/dev/mo up to 500 repos, Team $20/dev/mo unlimited installs, Enterprise $50k/yr (~$4167/mo) unlimited | Sonatype Firewall $40k/yr, Mend Defender $30k/yr | overage $0.01 per extra install after 500k
Open Source License Compliance Scanning
Keeps you secure and compliant with regulations. Required for enterprise customers and handling sensitive data.Pricing & free-tier limitsFree: ScanCode $0 OSS unlimited files, FOSSology $0, ORT $0 | FOSSA Free 1 project 1000 deps $0, Team $100/mo 5 projects + $0.10 per dep over 2k, Enterprise $30k/yr | Snyk License included in $25/dev/mo, Mend License $20k/yr base
API Security Platform & Discovery
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Akto OSS $0 self-host 1000 endpoints, Amass $0 | Wallarm Free 1 app 50 endpoints $0, Pro $500/mo 5 apps 500 endpoints, $1500/mo Team 20 apps 2000 endpoints | Salt Security $50k/yr base (~$4167/mo) up to 1000 APIs $50 per extra API/mo | Noname $100k/yr (~$8333/mo)
API Fuzzing & Schema Validation Testing
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Schemathesis OSS $0 unlimited tests, RESTler OSS $0, APIFuzzer OSS $0 | Akto Fuzz Free 1 API 100 tests/mo, Pro $150/mo 10 APIs 10k tests | 42Crunch $300/mo per API unlimited tests, Platform $900/mo 5 APIs | Burp Enterprise API $6999/yr
Software Supply Chain Attestation (SLSA / Sigstore)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Sigstore Public Instance $0 unlimited signing/verifying, Cosign $0, Fulcio $0, Rekor $0 | Chainguard Enforce Free 25 images $0, Team $350/mo 100 images + $3 per extra image, Enterprise $1500/mo 1000 images | in-toto $0 OSS
Penetration Testing as a Service (PTaaS) Platform
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: HackerOne Community platform fee $0 (Bounties $500-$5000 per bug typical), Open Bug Bounty $0 | Cobalt Starter $5000/test 1-week test (one-time), $15k/mo for 3 tests/mo ($5000/test avg) | HackerOne Pentest $25k/test one-time, $100k/yr program fee, Synack $120k/yr ($10k/mo) 4 tests/yr + crowdsourced | Intigriti $2000/test
API Gateway with Security Policy Enforcement
Controls and protects your APIs — quotas, abuse prevention, and firewalls. Important once you have real traffic or many clients.Pricing & free-tier limitsFree: Kong OSS $0 unlimited routes, APISIX OSS $0, KrakenD CE $0 | Kong Konnect Free 1M gateway calls/mo $0, Team $250/mo 10M calls + $0.02 per 10k over | AWS API Gateway Free 1M calls/mo first 12 mo then $3.50 per M HTTP + WAF $5/mo per ACL $1/rule | Apigee $500/mo base 1M + $40 per M over | Azure APIM $150/mo Developer
Secure Code Review / PR Security Automation
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: CodeQL OSS $0 public repos, SonarQube CE $0 PR decoration, Semgrep OSS $0 unlimited PR comments | GitHub Advanced Security $3.67/user/mo, SonarQube Cloud Team $150/mo | Semgrep Pro PR $40/dev/mo | Snyk $25/dev/mo PR checks, Checkmarx $50k/yr PR flow
How this small scale application security checklist works.
Each requirement below is something a small scale application security build typically needs. Pick one of the four researched options — recommended, free, cheaper or paid — add your own with "Other", or skip the requirement if your project doesn't need it. Nothing is mandatory; the plan on the right tracks what you've decided so nothing gets forgotten.
Your picks are saved in this browser automatically, so you can come back anytime. Options are researched per build level and refreshed as vendors change their plans — always verify details on the provider's page before committing.