
ScanCode Toolkit
Summary
ScanCode Toolkit is a free software tool for examining codebases for code origin, copyrights, licenses, vulnerabilities, packages, and dependencies. It can run from the command line or be used as a library in an application. For license detection, it checks extracted file text against an index of license texts and matching rules. It can unpack archives recursively and extract text from binary files when needed, and it recognizes many package manifests, lockfiles, and package datafiles. Scan results can be saved as JSON, YAML, JSON Lines, HTML, SPDX, Debian copyright, or CycloneDX; CSV is deprecated. JSON results can be used with ScanCode Workbench and applications that accept ScanCode result data. Plugins extend processing stages, and external plugins can add license data. Installation options include release archives, Docker, source, pip, and Fedora's repository. The documentation lists Linux, macOS, and Windows as tested platforms, with 64-bit operating system and Python requirements. The project points users to community Slack and GitHub discussions for help. Scan output is provided as-is, without warranties, and is not legal advice.
Who it is for
It suits developers and organizations that need to inspect codebases for licensing, provenance, vulnerabilities, and dependency details. Its command-line and library options support both direct scanning and use within applications.
What is good
- Scans for code origin, licenses, vulnerabilities, and dependencies.
- Runs from the command line or as an application library.
- Reads archives recursively and can extract binary-file text.
- Exports to JSON, SPDX, HTML, and other formats.
- Free software with plugin extension options.
What to know first
- CSV output is deprecated.
- Documentation specifies 64-bit operating systems and Python requirements.
- Scan output is not legal advice and carries no warranty.
Verdict
ScanCode Toolkit offers a broad set of codebase scanning and reporting functions in a free package. Check its documented platform requirements and treat results as technical information, not legal advice.
ScanCode Toolkit plans and pricing
All plansCompared on open source license compliance software
- Free plan
- Yesscancode-toolkit.readthedocs.io
- Policy enforcement
- advisoryscancode-toolkit.readthedocs.io
- Attribution reports
- Yesscancode-toolkit.readthedocs.io
- Deployment options
- on-premisescancode-toolkit.readthedocs.io
- Source scan methods
- multiplescancode-toolkit.readthedocs.io
Facts
- Purpose
- ScanCode Toolkit scans codebases to detect code origin, copyrights, licenses, vulnerabilities, packages and dependencies.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Use modes
- It can be used as a command-line tool or as a library in an application.scancode-toolkit.readthedocs.io · 2 Oct 2026
- License detection
- License detection searches an index of license texts and rules for matches in extracted file text.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Archive scanning
- The scanning process extracts files recursively from archives and extracts text from binary files when needed.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Package support
- It supports a wide variety of package manifests, lockfiles and package datafiles containing package and dependency information.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Output formats
- Scan results can be written as JSON, YAML, JSON Lines, HTML, SPDX, Debian copyright, or CycloneDX; CSV is marked deprecated.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Integration
- JSON scan results can be consumed by ScanCode Workbench and other applications that accept ScanCode result data.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Extensibility
- Plugins can extend ScanCode at different stages, and users can add license data through external plugins.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Installation
- Installation options include release archives, Docker, source, pip, and Fedora’s repository.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Platform requirements
- The documentation lists Linux, macOS and Windows as tested platforms and specifies 64-bit operating systems and Python requirements.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Support
- The project directs users to its community Slack and GitHub discussions for questions and challenges.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Legal limitation
- The scan output says ScanCode is provided as-is without warranties and that its content should not be used as legal advice.scancode-toolkit.readthedocs.io · 2 Oct 2026
- Maker history
- nexB says it was founded in 2003 by Michael J. Herzog, Philippe Ombrédanne and François Granade.nexb.com · 2 Oct 2026
Company
- Founded
- 2003scancode-toolkit.readthedocs.io · 28 Sept 2026
- Headquarters
- Los Altos, California, United Statesscancode-toolkit.readthedocs.io · 28 Sept 2026
Best ScanCode Toolkit alternatives
See all 12Where it ranks on Everything Xiaomi
Is ScanCode Toolkit yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- scancode-toolkit.readthedocs.io/en/latest/· checked 2 Oct 2026
- scancode-toolkit.readthedocs.io/en/latest/explanation/scancode-license-· checked 2 Oct 2026
- scancode-toolkit.readthedocs.io/en/latest/reference/scancode-supported-· checked 2 Oct 2026
- scancode-toolkit.readthedocs.io/en/latest/reference/scancode-cli/cli-ou· checked 2 Oct 2026
- scancode-toolkit.readthedocs.io/en/latest/getting-started/installation/· checked 2 Oct 2026
- nexb.com/about/· checked 2 Oct 2026
- scancode-toolkit.readthedocs.io· checked 28 Sept 2026


