🚀 TG4G
DirectorySecuritySast Rasp Iast Dast Scacodepecker.com.cn
🛡 Security Sast Rasp Iast Dast Sca 📍 HQ: China
C

codepecker.com.cn

Overall Rating
★★★⯨☆ 7.0/10
China Access
★★★ China direct-connect friendly
Quick Check
Data source
ai_crawl · Last updated 2026-06-08

⚡ Score breakdown

5-dim weighted · /10
Performance25% 7.0
Value20% 7.0
China access20% 10.0
Reputation20% 6.0
Support15% 6.5

Dimension scores are derived from public data and fields; weighted into the composite. Reference only.

Editorial Highlights

A domestic DevSecOps product suite with a complete lineup, covering multiple types of security testing.

In-Depth Review TG4G Review ·2026-06-08 · For reference only

What It Is

CodePecker is a software secure development and software supply chain security product suite from Beijing CodePecker Information Technology Co., Ltd. Its official website primarily highlights “Buque,” a SAST source-code defect analysis system, while also listing products such as RASP, IAST, SCA, DAST, FUZZ, source-code traceability, a continuous application development platform, source-code management, and static analysis for data security. Overall, it is positioned not as a standalone scanning tool, but as a DevSecOps-oriented secure development platform solution.

Core Capabilities

In terms of protection coverage, CodePecker spans white-box testing, black-box testing, interactive testing, runtime protection, open-source component analysis, and fuzz testing, making it suitable for continuous risk management from coding and testing through post-release operations. Its SAST product emphasizes source-code static analysis combined with artificial intelligence, detecting more than 1,000 defect types and supporting international coding standards such as CWE, OWASP, and CERT. On the SCA side, it claims coverage of public vulnerability database data and can be used to detect vulnerabilities in open-source code. For management, the system can integrate with DevSecOps workflows and present requirement analysis, threat models, protection bypass strategies, detection progress, and vulnerability details by project, helping R&D leaders gain an overall view of code security status.

Pricing and Deployment

The official website does not disclose pricing, licensing models, trial availability, or whether fees are based on projects, code volume, or user count, so buyers will need to contact the vendor before procurement. Deployment options are also not clearly stated, making it unclear whether the product is offered as on-premises software, private cloud, SaaS, or a hybrid deployment. However, given its stated focus on finance, government, defense, and large state-owned enterprises, real-world projects are likely to involve private deployment and customized delivery, though this cannot be confirmed from the website content alone.

Pros and Cons

Its strengths include a complete product line covering multiple key areas of software supply chain security; an early start in SAST; an emphasis on fully self-owned intellectual property; and customer case references such as Sinopec, State Grid, China Sports Lottery, ICBC, and Tsinghua University. Its industry coverage includes finance, government, defense, telecommunications, intelligent manufacturing, and high tech, making it suitable for organizations with demanding compliance requirements. The main limitation is the lack of key information on the official website: it does not specify supported programming languages, CI/CD and code repository integration details, alerting channels, reporting capabilities, false-positive handling mechanisms, specific compliance certifications, or pricing.

Who It’s For and Access from China

CodePecker is better suited to medium and large enterprises with in-house development teams that need to build secure coding standards, perform source-code audits, govern open-source components, and establish DevSecOps processes—especially customers in finance, government/enterprise, and critical industries. For small teams that only need lightweight code quality scanning, it may be necessary to compare cost and implementation complexity against solutions such as SonarQube, Snyk, Checkmarx, Fortify, Qi An Xin CodeSafe, and Xmirror Lingmai. Its domain is .com.cn, with complete ICP filing and public security registration information, and it targets the Chinese market; access from mainland China is expected to work directly. Payment methods are not disclosed and will likely need to be confirmed through business procurement.

⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on codepecker.com.cn official site.

About this entry

codepecker.com.cn is an China Security (Sast Rasp Iast Dast Sca) provider. TG4G tracks its product information, an overall rating of 7.0/10, and a China-accessibility score of China direct-connect friendly. Click "Visit Official Site" to reach codepecker.com.cn directly.

Get Started

Price not disclosed
Visit codepecker.com.cn official site →
External link · prices subject to vendor site

Frequently Asked Questions

What is codepecker.com.cn?
codepecker.com.cn is a China-based Security (Sast Rasp Iast Dast Sca) provider. A domestic DevSecOps product suite with a complete lineup, covering multiple types of security testing.
Is codepecker.com.cn good? Is it worth it?
codepecker.com.cn scores 7.0/10 on TG4G — a solid rating, based in 中国. See the in-depth review below for pros, cons and China accessibility.
Is codepecker.com.cn usable in China?
codepecker.com.cn offers good direct-connect performance in mainland China and works in most regions without a proxy. The provider is headquartered in China and primarily serves overseas markets.
How do I sign up for codepecker.com.cn?
Visit the codepecker.com.cn official site to complete sign-up. Registration typically requires an email (Gmail/Outlook recommended) and a payment method. Most overseas services accept credit card / PayPal / crypto. See the "Visit Official Site" button on this page for the direct link.

Browse Other Categories

View the full directory →