Skip to content
CodeDD Logo

Code quality

Is this code maintainable — or expensive to own?

Every file in the estate — every repository in scope — is scored and benchmarked against other audits. You see whether the code will slow the plan down, how it compares to peers, and what it takes to bring it up to standard.

Start for FreeBook a Demo

Trusted by

Beyond a vendor score

A single score is not diligence.

You need to know where the score comes from, whether it is normal for the market, and what it costs to change.

  1. Every file, not a sample

    Each source file is reviewed against production-ready standards across seven categories — so weak spots show up where they are, not averaged away.

  2. One health number, with its drivers

    Code quality, verified security, and test coverage in one score — with the driver pulling it down in plain view.

  3. Benchmarked against peers

    Each category sits next to the average of other CodeDD audits, so you can tell a company-specific problem from a market norm.

The health score

See which driver pulls health down.

Solid code with weak tests is a testing gap. Weak code throughout is a maintainability problem. The breakdown tells you which one you are buying — and who to staff.

The work

What it takes to reach your standard.

The gap to your quality and coverage target, sized in days — with security findings alongside, so the total is the real work.

See the full cost

Against peers

A problem, or just the market?

Seven category scores against the global average of CodeDD audits. Here, documentation is far ahead of peers and security is weak — but no weaker than the norm. That changes the conversation from a red flag to a planned improvement.

Across the investment cycle

Where the score gets used

  1. Pre-deal tech DD

    Know whether the codebase is an asset or a rebuild before the price assumes one or the other.

  2. Hold period

    Set a quality target in the value-creation plan and re-audit to show the gap closing.

  3. Pre-sale preparation

    Raise the categories a buyer will benchmark first, and show the trend, not just the score.

FAQ

Questions

How is a file scored?

Each source file is reviewed against production-ready standards across seven categories: quality, functionality, performance, security posture, compatibility, documentation, and standards. Ratings use fixed scales. Very small files and non-code — lockfiles, data, generated blobs — are skipped rather than scored.

What goes into the health score?

Code quality counts for 50%, verified security for 30%, and test coverage for 20%. Verified security is built from confirmed findings and known package vulnerabilities; test coverage is measured against your target.

Why is the security score on the peer chart different from the one in health?

The peer chart uses the file-level security posture score, so every audit is compared on the same seven axes. The health score uses verified security — confirmed findings and known CVEs — which is the stronger evidence. Both are shown so neither is mistaken for the other.

How precise is the peer comparison?

It is indicative. The scores use the same form on every audit, so a gap of twenty points is meaningful; a gap of three is not a ranking. Use it to decide where to look closer.

How is this different from a linter or SonarQube?

Linters and SonarQube catch known patterns and style issues line by line. This reviews each file for maintainability, completeness, and design, and puts the result next to peers — a view built for a decision rather than a code review.

What happens to our source code?

In a cloud audit, scoped source is analysed and then overwritten; CodeDD keeps structured scores, not source. The audit can also run in your own environment.

See how a codebase you are evaluating compares

Run it on a repository yourself, or book a walkthrough of the scores, the peer comparison, and the cost to reach your standard.