122 checks, one CI gate.
Fails on the diff, not the backlog.
Deterministic static analysis on every push, scored against a baseline file you commit, so the job fails only on new findings. Every report lists what was not checked. Precision is measured nightly on 19 pinned third-party repositories and published, misses included.
npx -p @gatetest/cli gatetest --suite quickThree artifacts. Nothing to log in to.
Every push sets a commit status
The App or the Action runs the deterministic checks on the diff, scores them against the committed baseline, and writes one status. A blocking finding means exit 1 and a red check. Nothing else in your pipeline changes.
POST /repos/your-org/your-repo/statuses/9f2c1a7
{
"state": "failure",
"context": "GateTest Quality Gate",
"description": "2 blocking findings in this diff · 5 checks not run",
"target_url": "https://gatetest.io/scan/scn_4b1e…"
}One comment names the findings and what was not run
Line-attributed, with the exact ignore reply beside each finding. Checks that could not run are listed, never silently counted as passed. Baselined findings stay visible and stay out of the verdict.
## 2 blocking findings in this diff | File | Finding | Reply to ignore | | --- | --- | --- | | src/handler.js:12 | `q` from request input reaches a `sql-query` sink | `@gatetest ignore crossFileTaint@src/handler.js` | | src/handler.js:20 | `result` from request input reaches a `sql-query` sink | same | **Not checked:** lint (no ESLint config), dependencies (no lockfile). Baseline: .gatetest/baseline.json @ 3 findings — none of them counted here.
On the fix tiers, a pull request with the patch and its test
A model writes the patch; the gate re-runs on it; a regression test is added; a second model reviews the diff. You review and merge, or reply to reject. Pricing is per run, not per seat.
## fix: parameterise the SQL in handler.js - src/handler.js: two queries rewritten with placeholders - tests/handler.sql.test.js: regression test for both sinks (added) - Gate re-run on this patch: 0 blocking · 3 warnings - Second-model review: approved, no scope creep Cost of this fix: 38 s · ~$0.02 API
A gate that blocks clean code gets uninstalled. So the numbers are public.
Every push runs the full suite on 19 pinned commits of repositories we do not control. Each has a ceiling that only goes down. Hover a row for what that repository taught the rules.
Where it runs
| Where | Identifier | Cost | Output |
|---|---|---|---|
| GitHub App | github.com/apps/gatetest-hq | free gate on every push | commit status, PR comment |
| GitHub Action | uses: crclabs-hq/GateTest@v1 | free, public and private | gate, SARIF, JUnit, baseline |
| Terminal | npx -p @gatetest/cli gatetest --suite quick | free, offline, MIT | verdict, exit code, JSON |
| VS Code / Open VSX | GateTestHQ.gatetest | free, nothing leaves the machine | findings in the Problems panel |
| AI agent (MCP) | npx @gatetest/mcp-server | free on your own keys | 24 tools: scan, explain, fix, run tests, verify |
| GitLab / CircleCI | gatetest --ci-init gitlab | circleci | free | a complete pipeline file |
| Any live site | gatetest --crawl https://example.com | free preview, no repo | headers, TLS, links, a11y, SEO per page |
Pricing
| Tier | Price | Billing | Scope | What you get |
|---|---|---|---|---|
| Quick Scan | $29 | one-time · repository | syntax, lint, secrets, codeQuality | 4 modules — syntax, linting, secrets, code quality |
| Full Scan | $99 | one-time · repository | all-applicable | The full engine — every module that applies to a repository: security, supply chain, auth, CI hardening, structure, AI review, and more. (Live-URL and WordPress modules need a deployed site; mutation + chaos ship via the GitHub Action.) Scan-only (no auto-fix — that ships at Scan + Fix $199 and above). |
| Scan + Fix | $199 | one-time · repository | all-applicable+pair-review+architecture | Everything in Full Scan, plus a second-agent pair-review critique on every fix (correctness/completeness/readability/test-coverage rubric) and a separate architecture-annotator report on codebase-shape design observations. Same PR, deeper deliverable. |
| Forensic Scan | $399 | one-time · repository | all-applicable+forensic-stack | Everything in Scan + Fix, PLUS: real AI diagnosis on every finding (no templated snippets), cross-finding attack-chain correlation (textbook session-forgery / supply-chain vectors no per-finding scanner can see), board-ready CISO report (findings mapped to OWASP Top 10 and CIS Controls v8, with a 30/60/90-day remediation plan), and a CTO-readable executive summary report. Mutation testing and chaos / fuzz pass are also available via the GitHub Action (mutation: true / chaos: true) — they need a CI runner so they ship wherever your CI runs. |
| Website Scan — Full Report | $29 | one-time · live site | web-suite | Unlocks every finding on the website scanner: full issue list, plain-English fix instructions, and the complete health-score breakdown for your site. |
| WordPress Health Check — Full Report | $19 | one-time · live site | wp-suite | Unlocks the full WordPress health report: every finding, plugin/theme risk detail, and plain-English fix instructions for your site. |
| Continuous | $49/mo | subscription | subscription-continuous | Scan every push across EVERY repo in your org — one flat $49/mo, no per-seat, no per-repo (org-flat since 2026-07-23). Unlimited deterministic push scans, plus a monthly AI-review allowance shared across the org that escalates pushes to the deeper full-suite scan while budget remains. Fix PRs are a per-scan upsell. Cancel anytime. |
| GateTest MCP | $29/mo | subscription | subscription-mcp | Hosted MCP access — use GateTest from web and mobile AI clients and locked-down machines with no local install, plus hosted scan history. The LOCAL MCP server is free with every tool ungated (2026-07-23) — this tier is for when you can't run npx. API key delivered by email when checkout completes. Cancel anytime. |
| Enterprise | contact | invoiced | same engine | custom scan volume, raised AI-review budget, priority support, invoicing on your terms |
Charged at checkout, no seats, no minimum. The engine is open source and free to run yourself; hosted runs are what is billed.
The questions engineers ask first
- Will it block my whole backlog on day one?
- No. `gatetest --baseline` snapshots every current finding into .gatetest/baseline.json, you commit it, and the gate fails only on findings not in it. Baselined findings stay visible in every report and are counted per file, so a new one cannot hide behind an old one.
- How do I know the rules are not over-firing?
- The corpus above. Every push scans 20 pinned commits of repositories we do not control; each has a ceiling that only ratchets down, and the numbers are published including the bad ones. A rule that starts over-firing on express or Django turns our CI red before yours.
- What does the model actually do?
- Nothing in the default scan; that is deterministic and reproducible. On the fix tiers a model writes a patch for a located finding, the gate re-runs on the patch, a regression test is added, and a second model reviews the diff. The CLI and local MCP server run on your own key.
- What is reported when something could not run?
- It says so, in the terminal, the PR comment and the JSON: 'not checked' with the reason. A pass from silence is treated as the worst bug in this codebase.
- Where does my code go?
- The CLI, the Action, the editor extension and the local MCP server run where you run them; nothing is uploaded. Hosted scans read the repository over HTTPS on our box and keep the report for the share window. The GitHub App uses scoped permissions and short-lived installation tokens; every webhook is HMAC-verified and fails closed.