The ScanCode Toolkit homepage

ScanCode Toolkit

Score7.1
Rank#3 of 28
PriceFree
Free planYes
Runs onAPI, Linux, macOS, Self-hosted, Windows

Summary

ScanCode Toolkit is a free software tool for examining codebases for code origin, copyrights, licenses, vulnerabilities, packages, and dependencies. It can run from the command line or be used as a library in an application. For license detection, it checks extracted file text against an index of license texts and matching rules. It can unpack archives recursively and extract text from binary files when needed, and it recognizes many package manifests, lockfiles, and package datafiles. Scan results can be saved as JSON, YAML, JSON Lines, HTML, SPDX, Debian copyright, or CycloneDX; CSV is deprecated. JSON results can be used with ScanCode Workbench and applications that accept ScanCode result data. Plugins extend processing stages, and external plugins can add license data. Installation options include release archives, Docker, source, pip, and Fedora's repository. The documentation lists Linux, macOS, and Windows as tested platforms, with 64-bit operating system and Python requirements. The project points users to community Slack and GitHub discussions for help. Scan output is provided as-is, without warranties, and is not legal advice.

Who it is for

It suits developers and organizations that need to inspect codebases for licensing, provenance, vulnerabilities, and dependency details. Its command-line and library options support both direct scanning and use within applications.

What is good

  • Scans for code origin, licenses, vulnerabilities, and dependencies.
  • Runs from the command line or as an application library.
  • Reads archives recursively and can extract binary-file text.
  • Exports to JSON, SPDX, HTML, and other formats.
  • Free software with plugin extension options.

What to know first

  • CSV output is deprecated.
  • Documentation specifies 64-bit operating systems and Python requirements.
  • Scan output is not legal advice and carries no warranty.

Verdict

ScanCode Toolkit offers a broad set of codebase scanning and reporting functions in a free package. Check its documented platform requirements and treat results as technical information, not legal advice.

ScanCode Toolkit plans and pricing

All plans
ScanCode Toolkit Free Free software code scanning tool scancode-toolkit.readthedocs.io · 2 Oct 2026

Compared on open source license compliance software

Free plan
Yesscancode-toolkit.readthedocs.io
Policy enforcement
advisoryscancode-toolkit.readthedocs.io
Attribution reports
Yesscancode-toolkit.readthedocs.io
Deployment options
on-premisescancode-toolkit.readthedocs.io
Source scan methods
multiplescancode-toolkit.readthedocs.io

Facts

Purpose
ScanCode Toolkit scans codebases to detect code origin, copyrights, licenses, vulnerabilities, packages and dependencies.scancode-toolkit.readthedocs.io · 2 Oct 2026
Use modes
It can be used as a command-line tool or as a library in an application.scancode-toolkit.readthedocs.io · 2 Oct 2026
License detection
License detection searches an index of license texts and rules for matches in extracted file text.scancode-toolkit.readthedocs.io · 2 Oct 2026
Archive scanning
The scanning process extracts files recursively from archives and extracts text from binary files when needed.scancode-toolkit.readthedocs.io · 2 Oct 2026
Package support
It supports a wide variety of package manifests, lockfiles and package datafiles containing package and dependency information.scancode-toolkit.readthedocs.io · 2 Oct 2026
Output formats
Scan results can be written as JSON, YAML, JSON Lines, HTML, SPDX, Debian copyright, or CycloneDX; CSV is marked deprecated.scancode-toolkit.readthedocs.io · 2 Oct 2026
Integration
JSON scan results can be consumed by ScanCode Workbench and other applications that accept ScanCode result data.scancode-toolkit.readthedocs.io · 2 Oct 2026
Extensibility
Plugins can extend ScanCode at different stages, and users can add license data through external plugins.scancode-toolkit.readthedocs.io · 2 Oct 2026
Installation
Installation options include release archives, Docker, source, pip, and Fedora’s repository.scancode-toolkit.readthedocs.io · 2 Oct 2026
Platform requirements
The documentation lists Linux, macOS and Windows as tested platforms and specifies 64-bit operating systems and Python requirements.scancode-toolkit.readthedocs.io · 2 Oct 2026
Support
The project directs users to its community Slack and GitHub discussions for questions and challenges.scancode-toolkit.readthedocs.io · 2 Oct 2026
Legal limitation
The scan output says ScanCode is provided as-is without warranties and that its content should not be used as legal advice.scancode-toolkit.readthedocs.io · 2 Oct 2026
Maker history
nexB says it was founded in 2003 by Michael J. Herzog, Philippe Ombrédanne and François Granade.nexb.com · 2 Oct 2026

Company

Founded
2003scancode-toolkit.readthedocs.io · 28 Sept 2026
Headquarters
Los Altos, California, United Statesscancode-toolkit.readthedocs.io · 28 Sept 2026

Best ScanCode Toolkit alternatives

See all 12

Where it ranks on Everything Xiaomi

Is ScanCode Toolkit yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources