Stack Cost AI

Application Securitysmall scale stack.

For each requirement below, pick the option that fits your build — recommended first, then free and cheaper alternatives — or skip what your project doesn't need. Tap the info icon next to any requirement to see why it matters.

SAST Platform (Static Application Security Testing)

Pricing & free-tier limitsFree: SonarQube CE $0 self-host unlimited LOC, CodeQL $0 public repos unlimited | SonarCloud Team $150/mo for 100k LOC + $50 per extra 100k, Free tier 50k LOC | Snyk Code Free 200 scans/mo, Team $25/dev/mo ($300/yr) unlimited | Semgrep Pro Team $40/dev/mo | Checkmarx One Enterprise $50k/yr (~$4167/mo) for 25 devs, overage $2k per 5 devs

SCA Dependency Scanning (Software Composition Analysis)

Pricing & free-tier limitsFree: Dependabot $0 unlimited alerts/PRs, npm audit $0, OSV-Scanner $0 | Snyk Free 200 tests/mo 1 org, Team $25/dev/mo unlimited tests + fix PRs | Socket Free 100 repos 50k installs/mo, Pro $20/mo org + $5/dev/mo up to 500 repos, Team $20/dev/mo | Mend $30k/yr base (~$2500/mo), overage $50 per extra dev

Secrets Scanning & Detection

Pricing & free-tier limitsFree: TruffleHog OSS $0 unlimited repos, Gitleaks OSS $0, GitHub Secret Scanning $0 public + private | GitGuardian Free 25 devs/history scan, $20/dev/mo after ($500/mo for 25 devs), Business $40/dev/mo ($1000/mo for 25), overage $25 per 1000 extra secrets | Doppler Free 250 secrets 25 devs

DAST Scanning (Dynamic Application Security Testing)

Pricing & free-tier limitsFree: ZAP $0 unlimited scans, self-hosted | StackHawk Free 1 app 1 scan/mo, Pro $99/mo 5 apps 5 scans/mo, $399/mo Team 20 apps | Burp Suite Pro $449/yr per user (~$37/mo) one-time license, Enterprise $6,999/yr (~$583/mo) for 10 scan slots + 1 agent $0.10 per extra scan hour | Invicti $25k/yr

Web Application Firewall (WAF) for App Protection

Pricing & free-tier limitsFree: Cloudflare Free 1 custom rule + unmetered DDoS $0 | Cloudflare Pro $20/mo 20 rules + $5/mo managed ruleset, Business $200/mo 100 rules + managed, Enterprise $5000/mo custom ruleset unlimited | AWS WAF $5/mo per WebACL + $1/mo per rule + $1 per 1M req, overage $0.60 per M after 10M | Imperva $1200/mo avg 10M req, Fastly NGWAF $2000/mo base + $0.10 per 1000 reqs over

Container Image Vulnerability Scanning

Pricing & free-tier limitsFree: Trivy OSS $0 unlimited images, Grype OSS $0, Docker Scout Free 3 repos | Snyk Container Free 200 tests/mo, Team $25/dev/mo unlimited | Docker Scout Pro $20/mo 25 repos $0.50 per extra repo | Anchore Enterprise $35k/yr (~$2916/mo) 100 hosts, Wiz $30k/yr base

Infrastructure-as-Code (IaC) Security Scanning

Pricing & free-tier limitsFree: Checkov OSS $0 unlimited IaC, tfsec OSS $0, KICS OSS $0 1000 scans/mo | Snyk IaC Free 200 tests/mo, Team $25/dev/mo | Prisma Cloud Code Security $24k/yr (~$2000/mo) 100 IaC repos $100 per extra repo, Wiz IaC included in $30k/yr

CI/CD Pipeline Security & Supply Chain Hardening

Pricing & free-tier limitsFree: Scorecard $0 unlimited, Dependabot Review $0, StepSecurity Free 1 repo | GitHub Advanced Security $3.67/user/mo ($44/user/yr) minimum 10 users $36.70/mo, Enterprise $6.50/user/mo | StepSecurity Pro $50/mo 10 repos $100/mo Team, Enterprise $500/mo 100 repos | GitLab Ultimate $99/user/mo

Software Bill of Materials (SBOM) Generation Platform

Pricing & free-tier limitsFree: Syft OSS $0 unlimited artifacts, CycloneDX $0, Trivy $0 unlimited SBOM gen | Anchore Cloud Free 50 SBOMs/mo $0, Pro $50/mo 500 SBOMs $0.10 per extra SBOM | Mend SBOM module $15k/yr ($1250/mo) | Chainguard SBOM $0 with images

Static Secrets Management & Vault

Pricing & free-tier limitsFree: Vault OSS $0 self-host unlimited secrets, Infisical OSS $0 self-host, Doppler Free 25 devs 250 secrets | Infisical Cloud Free 1000 secrets $12/mo Starter, Doppler Pro $20/dev/mo | HCP Vault $1.58/hr dev cluster ~$1150/mo + $0.03/secret/mo $0.05 per 10k API calls | AWS Secrets Manager $0.40/secret/mo + $0.05 per 10k calls, overage same

Code Security Linting / Pre-commit Security Hooks

Pricing & free-tier limitsFree: Semgrep OSS $0 unlimited scans, pre-commit.com $0, Gitleaks hook $0 | Semgrep Pro Team $40/dev/mo ($30 annual) includes 1000 Pro scans, Business $60/dev/mo | Snyk Code $25/dev/mo unlimited includes pre-commit hook

Dependency Firewall / Malicious Package Detection (Supply Chain Firewall)

Pricing & free-tier limitsFree: Socket Free 100 repos 50k package installs/mo $0, npm audit $0 | Socket Pro $20/mo org + $5/dev/mo up to 500 repos, Team $20/dev/mo unlimited installs, Enterprise $50k/yr (~$4167/mo) unlimited | Sonatype Firewall $40k/yr, Mend Defender $30k/yr | overage $0.01 per extra install after 500k

Open Source License Compliance Scanning

Pricing & free-tier limitsFree: ScanCode $0 OSS unlimited files, FOSSology $0, ORT $0 | FOSSA Free 1 project 1000 deps $0, Team $100/mo 5 projects + $0.10 per dep over 2k, Enterprise $30k/yr | Snyk License included in $25/dev/mo, Mend License $20k/yr base

API Security Platform & Discovery

Pricing & free-tier limitsFree: Akto OSS $0 self-host 1000 endpoints, Amass $0 | Wallarm Free 1 app 50 endpoints $0, Pro $500/mo 5 apps 500 endpoints, $1500/mo Team 20 apps 2000 endpoints | Salt Security $50k/yr base (~$4167/mo) up to 1000 APIs $50 per extra API/mo | Noname $100k/yr (~$8333/mo)

API Fuzzing & Schema Validation Testing

Pricing & free-tier limitsFree: Schemathesis OSS $0 unlimited tests, RESTler OSS $0, APIFuzzer OSS $0 | Akto Fuzz Free 1 API 100 tests/mo, Pro $150/mo 10 APIs 10k tests | 42Crunch $300/mo per API unlimited tests, Platform $900/mo 5 APIs | Burp Enterprise API $6999/yr

Software Supply Chain Attestation (SLSA / Sigstore)

Pricing & free-tier limitsFree: Sigstore Public Instance $0 unlimited signing/verifying, Cosign $0, Fulcio $0, Rekor $0 | Chainguard Enforce Free 25 images $0, Team $350/mo 100 images + $3 per extra image, Enterprise $1500/mo 1000 images | in-toto $0 OSS

Penetration Testing as a Service (PTaaS) Platform

Pricing & free-tier limitsFree: HackerOne Community platform fee $0 (Bounties $500-$5000 per bug typical), Open Bug Bounty $0 | Cobalt Starter $5000/test 1-week test (one-time), $15k/mo for 3 tests/mo ($5000/test avg) | HackerOne Pentest $25k/test one-time, $100k/yr program fee, Synack $120k/yr ($10k/mo) 4 tests/yr + crowdsourced | Intigriti $2000/test

API Gateway with Security Policy Enforcement

Pricing & free-tier limitsFree: Kong OSS $0 unlimited routes, APISIX OSS $0, KrakenD CE $0 | Kong Konnect Free 1M gateway calls/mo $0, Team $250/mo 10M calls + $0.02 per 10k over | AWS API Gateway Free 1M calls/mo first 12 mo then $3.50 per M HTTP + WAF $5/mo per ACL $1/rule | Apigee $500/mo base 1M + $40 per M over | Azure APIM $150/mo Developer

Secure Code Review / PR Security Automation

Pricing & free-tier limitsFree: CodeQL OSS $0 public repos, SonarQube CE $0 PR decoration, Semgrep OSS $0 unlimited PR comments | GitHub Advanced Security $3.67/user/mo, SonarQube Cloud Team $150/mo | Semgrep Pro PR $40/dev/mo | Snyk $25/dev/mo PR checks, Checkmarx $50k/yr PR flow

Options and prices come straight from our research sheets for a small scale application security project. Prices are estimates and change often — always confirm on the provider's page before committing.

How this small scale application security checklist works.

Each requirement below is something a small scale application security build typically needs. Pick one of the four researched options — recommended, free, cheaper or paid — add your own with "Other", or skip the requirement if your project doesn't need it. Nothing is mandatory; the plan on the right tracks what you've decided so nothing gets forgotten.

Your picks are saved in this browser automatically, so you can come back anytime. Options are researched per build level and refreshed as vendors change their plans — always verify details on the provider's page before committing.