
HackerOne Code
by PullRequest · AI-filtered, human-validated security review in your pull requests
BenchRank score
Screenshots of HackerOne Code
Homepage
Overview
HackerOne Code, formerly PullRequest, reviews code changes for security problems inside the source control tools a team already uses. Its AI, Hai, flags high-risk changes and filters out low-risk ones, and contracted expert engineers manually validate each finding before it is surfaced to developers. It integrates with GitHub, GitLab, Bitbucket and Azure DevOps.
- Best for
- Development teams wanting expert human security review of pull requests inside their existing SCM.
- Pricing
- One published plan, TEAM at $129 per developer per month billed annually with a two-week trial; Enterprise is custom priced through sales.
- Runs on
- WebSelf-hosted
Strengths and trade-offs
Strengths
- Findings validated by human reviewers before developers see them
- Integrates with GitHub, GitLab, Bitbucket and Azure DevOps
- All major languages and frameworks supported out of the box
- Enterprise option to keep code on your own network
Trade-offs
- Smart Review Selection covers only ~30-40% of pull requests
- Reviews run in US business hours; turnaround varies by size
- No free tier or self-serve sign-up; both plans go via sales
- SSO, API access and on-premise require the Enterprise plan
How HackerOne Code markets itself
A structured read of the promise, proof and page design on HackerOne Code’s captured homepage.
Homepage capture
“Ship Secure Code”
- Angle: Security / trust-led
- Hero: Product screenshot
Pricing
Published plans and prices from HackerOne Code’s own pricing page.
How this score is made up
Each dimension is scored out of 100 and combined into the headline score using fixed weights.
MCP support
Whether an agent can drive the product through the Model Context Protocol, and how much setup that takes.
Documentation
Publicly reachable docs — coverage, freshness, code samples and machine readability.
Agent friendliness
How readable the site is to an automated client: llms.txt, structured data, server-rendered content, crawler access.
Pricing transparency
Whether real prices are published, self-serve signup exists, and usage costs are knowable without a sales call.
Changelog
A public, dated record of what shipped and when — the clearest signal that a product is still alive.
Marketing site structure
Whether the site answers a buyer's questions: clear positioning, the pages that matter, and accessibility.
Page speed
How fast the site loads for real visitors: Chrome UX Report 75th-percentile LCP, INP and CLS, with a Lighthouse mobile run standing in where a site has too little traffic for field data.
Operational trust
Status page and incident history, security disclosure, compliance and data-processing documentation.
Measured, but not part of the score
Useful to know, but not a mark for or against the product — so these do not affect the ranking.
Openness
Source availability, self-hosting, data export and open standards. Scored and shown, but not part of the composite — paid SaaS is not worse for being paid SaaS.
Maintenance
Release cadence and repository activity. Scored and shown, but not part of the composite — it is only measurable for open repositories.
This doesn’t look right — report a problem with HackerOne Code’s score
Where this comes from
The HackerOne Code pages BenchRank reads when it scores the product — its documentation, release notes, status and security pages, and its repository where there is one.
Alternatives in Code Review
Ranked 1
59.3 — BenchRank score out of 100Gogs
Gogs · Self-hosted Git service that runs from a single Go binary
Best for: Small teams or individuals self-hosting Git on modest hardware, including ARM boxes
Ranked 3
51.3 — BenchRank score out of 100Gitea
Gitea · Self-hosted Git, CI/CD and package hosting under the MIT licence
Best for: Teams that want to self-host Git, CI/CD and package registries on their own infrastructure.
Ranked 4
24 — BenchRank score out of 100Opengrep
Opengrep · Open-source static analysis engine forked from Semgrep CE
Best for: Security teams wanting an open-source SAST engine with no features locked behind a licence.
Is this your product?
Claim PullRequest to manage its profile. Claiming lets you suggest edits to the descriptive fields — it never changes scores or rankings.

