BenchRank
#2 in Code ReviewUpdated 2026-08

HackerOne Code

by PullRequest · AI-filtered, human-validated security review in your pull requests

BenchRank score

52 — BenchRank score out of 100

Screenshots of HackerOne Code

Homepage · HackerOne Code

Homepage of HackerOne Code

Overview

HackerOne Code, formerly PullRequest, reviews code changes for security problems inside the source control tools a team already uses. Its AI, Hai, flags high-risk changes and filters out low-risk ones, and contracted expert engineers manually validate each finding before it is surfaced to developers. It integrates with GitHub, GitLab, Bitbucket and Azure DevOps.

Best for
Development teams wanting expert human security review of pull requests inside their existing SCM.
Pricing
One published plan, TEAM at $129 per developer per month billed annually with a two-week trial; Enterprise is custom priced through sales.
Runs on
WebSelf-hosted

Strengths and trade-offs

Strengths

  • Findings validated by human reviewers before developers see them
  • Integrates with GitHub, GitLab, Bitbucket and Azure DevOps
  • All major languages and frameworks supported out of the box
  • Enterprise option to keep code on your own network

Trade-offs

  • Smart Review Selection covers only ~30-40% of pull requests
  • Reviews run in US business hours; turnaround varies by size
  • No free tier or self-serve sign-up; both plans go via sales
  • SSO, API access and on-premise require the Enterprise plan

How HackerOne Code markets itself

A structured read of the promise, proof and page design on HackerOne Code’s captured homepage.

Homepage capture

“Ship Secure Code”

  • Angle: Security / trust-led
  • Hero: Product screenshot

Pricing

Published plans and prices from HackerOne Code’s own pricing page.

How this score is made up

Each dimension is scored out of 100 and combined into the headline score using fixed weights.

  • MCP support

    Whether an agent can drive the product through the Model Context Protocol, and how much setup that takes.

  • Documentation

    Publicly reachable docs — coverage, freshness, code samples and machine readability.

  • Agent friendliness

    How readable the site is to an automated client: llms.txt, structured data, server-rendered content, crawler access.

  • Pricing transparency

    Whether real prices are published, self-serve signup exists, and usage costs are knowable without a sales call.

  • Changelog

    A public, dated record of what shipped and when — the clearest signal that a product is still alive.

  • Marketing site structure

    Whether the site answers a buyer's questions: clear positioning, the pages that matter, and accessibility.

  • Page speed

    How fast the site loads for real visitors: Chrome UX Report 75th-percentile LCP, INP and CLS, with a Lighthouse mobile run standing in where a site has too little traffic for field data.

  • Operational trust

    Status page and incident history, security disclosure, compliance and data-processing documentation.

Measured, but not part of the score

Useful to know, but not a mark for or against the product — so these do not affect the ranking.

  • Openness

    Source availability, self-hosting, data export and open standards. Scored and shown, but not part of the composite — paid SaaS is not worse for being paid SaaS.

  • Maintenance

    Release cadence and repository activity. Scored and shown, but not part of the composite — it is only measurable for open repositories.

This doesn’t look right — report a problem with HackerOne Code’s score

Where this comes from

The HackerOne Code pages BenchRank reads when it scores the product — its documentation, release notes, status and security pages, and its repository where there is one.

Alternatives in Code Review

  • Ranked 1

    59.3 — BenchRank score out of 100

    Gogs

    Gogs · Self-hosted Git service that runs from a single Go binary

    Best for: Small teams or individuals self-hosting Git on modest hardware, including ARM boxes

  • Ranked 3

    51.3 — BenchRank score out of 100

    Gitea

    Gitea · Self-hosted Git, CI/CD and package hosting under the MIT licence

    Best for: Teams that want to self-host Git, CI/CD and package registries on their own infrastructure.

  • Ranked 4

    24 — BenchRank score out of 100

    Opengrep

    Opengrep · Open-source static analysis engine forked from Semgrep CE

    Best for: Security teams wanting an open-source SAST engine with no features locked behind a licence.

Is this your product?

Claim PullRequest to manage its profile. Claiming lets you suggest edits to the descriptive fields — it never changes scores or rankings.

Claim this business

Report a problem with this page

Report an issue with HackerOne Code