The core engine targets high-impact classes such as SQL injection, cross-site scripting, CSRF, path traversal, SSRF-style patterns, weak cryptography, and risky uses of eval and similar constructs.
Higher tiers add deeper capabilities including dedicated secret detection, dependency and license signals, infrastructure-as-code checks, and custom rules so you can encode org-specific policies.
Free, Pro, and Premier each unlock additional rule sets and features. Upgrade when you need PR gating, trends, exports, or Premier-only engines without changing how your team runs scans.