Technical debt
What it costs to fix this codebase
The work to bring the estate — every repository in scope — up to your standard, in hours and dollars: security, tests, code quality, and packages. One number for the memo, and the mix behind it.
$106k
Cost at $150/h
706h
Engineering hours
88 days
Of work
65%
From security findings
Verified security findings
Largest driver278 confirmed in the code
65%
57.6d · 461h
- Critical (15)4.4d
- High (263)53.2d
Missing tests
Coverage to the 80% target
16%
14.1d · 113h
- 451 files need tests14.1d
Below-standard code
Quality to the 80 target
13%
11.2d · 90h
- 342 files · repository 110.7d
- 16 files · repository 20.5d
Vulnerable packages
Known CVEs in declared packages
6%
5.3d · 42h
- Critical (1)1d
- High (3)1.5d
- Medium (11)2.8d
Trusted by




Beyond a debt score
A days number is not a plan.
To use it in a price discussion or a 100-day plan, you need to know what it is measured against, what drives it, and what it costs.
Measured against your standard
Quality and test coverage are measured against your target — 80 by default, not a perfect 100. Move it and the hours follow.
Broken down by driver
Security, tests, code quality, and packages — so you know whether you are buying a security problem or a testing gap.
Priced at your rate
Hours convert to cost at your hourly rate — a number for the memo, the budget, or the SPA discussion.
Across the investment cycle
Where the number gets used
Pre-deal tech DD
Quantify the remediation the buyer inherits, before signing — in hours and cost, not adjectives.
Hold period
Budget the 100-day plan from the mix, then re-audit to show the number coming down.
Pre-sale preparation
Close the largest drivers before a buyer's technical DD prices them in.
Close the work
The team closes it where they already work.
Security findings and package CVEs go straight to an AI coding assistant: the CodeDD CLI serves them one at a time with the evidence and records each fix against the audit. Tests and code quality stay in the plan as scheduled work.
One prompt starts the loop.
Works with any AI coding assistant that can run terminal commands.
Claude Code
Use codedd in your terminal to fix security issues. Start with “codedd ai-docs” to learn the CLI. The audit is already selected. Fix the next 5 Critical findings.
› codedd ai-docs
CODEDD-CLI · docs for AI agents
› codedd fix flags next --auto
[+] Critical · checkout URL schemepip install codedd-cli
12%
Security findings
20%
Package CVEs
Resolved so far
36 of 293
33 findings · 3 CVEs · recorded against the audit
CodeDD Advisor
Ask whether it is getting better
The Advisor compares this audit with earlier ones, so progress in the hold period is a number — not an impression.
FAQ
Questions
How are the hours calculated?
They are the work to reach your targets — quality 80 and test coverage 80 by default. Below-standard code is sized per file or per thousand lines, whichever is larger. Missing tests are sized by the files still needed to reach the coverage target. Security findings and package CVEs use a per-finding estimate by severity.
How is the cost calculated?
Hours multiplied by your organisation's hourly rate — $150 by default. Change the rate or the targets and the cost updates. It is an engineering estimate, not a vendor quote.
Which security findings are counted?
Only verified findings: each one is re-checked against the code before it enters the estimate, so the hours are not inflated by false alarms. Package CVEs are matched to the exact versions the estate ships.
How is this different from Code quality?
Code quality scores how maintainable the code is and how it compares to peers. Technical debt turns the gap to your standard into hours and cost, across security, tests, code quality, and packages — and gives the team a way to close it.
Does CodeDD change our code?
No. The CLI hands each finding to the engineer or their coding assistant with the evidence, and records the fix once it is marked done. The change itself is written and reviewed by your team.
What happens to our source code?
In a cloud audit, scoped source is analysed and then overwritten; CodeDD keeps structured results, not source. The audit can also run in your own environment.
See the cost to fix a codebase you are evaluating
Run it on a repository yourself, or book a walkthrough of the total, the drivers, and how the team would close them.