Arbor
Deterministic dependency-graph analysis that shows exactly what a pull request can reach before you merge it
If your problem is "what could this diff break?" rather than "is this code good?", Arbor's graph walk is the more honest primitive — it is explicit about unknown edges instead of hallucinating confidence. It won't find logic bugs and it says so plainly. Today the only thing you can actually buy and run is the MIT-licensed engine, whose v3.0.3 release adds Rust call resolution, per-symbol blast radii, and inheritance edges. The catch: hosted Arbor Cloud has no announced launch date, the previous dashboard and account flows closed on 2026-09-23, and signup is a waitlist. Start with the open-source engine and treat Cloud as a wait-and-see. Pair it with a model-based reviewer like CodeRabbit if
Verified 6d ago · liveness 71/100 · cite: rightaichoice.com/tools/arbor
- Solo developers who want a structural risk read on their own AI-generated PRs before merging
- Tiny teams that need automated breakage context without a heavyweight code review process
- AI agent workflows that need a compact, grounded handoff before the agent edits code
- Engineers assessing downstream risk when a diff touches billing, auth, or data layers
- Teams expecting full static analysis or symbolic execution
- Codebases heavy on dynamic metaprogramming, eval, or generated code where indexing leaves gaps
- Buyers wanting an LLM code review assistant with inline style and refactor suggestions
We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.
- Honest verdict, not marketing
- Real pros & cons from real users
- Attributed quotes with receipts
3 free scans · no card needed
Skip Arbor if you need an LLM reviewer that comments on code style, suggests refactors, or catches logical bugs — Arbor maps structural reach only and will report unknown edges rather than guess at them.
Running the free MIT engine on your own infrastructure means you pay for compute and any model-provider charges separately — Arbor does not cover those.
Arbor's only currently purchasable product is the MIT-licensed engine at $0 — you self-host it and carry your own compute and model-provider costs. For a solo dev or tiny team willing to run a CLI in CI, the cost floor is effectively zero; teams that need a managed hosted service should budget for an unknown number and
In short
Arbor — Deterministic dependency-graph analysis that shows exactly what a pull request can reach before you merge it. Best for Solo developers who want a structural risk read on their own AI-generated PRs before merging, Tiny teams that need automated breakage context without a heavyweight code review process, AI agent workflows that need a compact, grounded handoff before the agent edits code. Free to use.
What's new in Arbor
Checked 6 days agoAcross the latest 5 updates: 3 feature updates, 1 launch and 1 news mention.
Arbor publishes privacy notice, terms, and receipts guide ahead of Cloud
New privacy notice and terms cover future Cloud accounts: GitHub sign-in, repo access, report retention, and account deletion. No Cloud launch date was announced.
Arbor v3.0.3 Linux binaries require glibc 2.39
Linux binaries for engine v3.0.3 need glibc 2.39; the installation guide documents workarounds for older systems.
Arbor engine v3.0.3: Rust call resolution, per-symbol diffs, graph refresh
v3.0.3 resolves calls through Rust paths and macros, gives each modified symbol its own blast radius, refreshes stale graphs, and adds inheritance edges. Published on GitHub, npm, and crates.io.
Arbor launches new public site; Cloud dashboard and account flows closed
New docs, FAQ, product, pricing, and security pages went live with email signup. The previous Cloud dashboard and account flows closed while Arbor rebuilds; the open-source engine stays available.
Arbor engine v3.0.0 lands with import-aware call resolution
v3.0.0 matches calls by considering imports before nearby declarations. GitHub release binaries shipped v3.0.0; npm and crates.io stayed at v2.6.0 until v3.0.3.
What people actually say about Arbor — is it worth it?
We scanned public community sources for Arbor on Jul 26, 2026 and could not establish that the discussion we found is about this tool rather than something else sharing its name. Our own analysis of that scan says the posts were off-subject. Rather than publish a sentiment score built on the wrong subject, we publish nothing here and re-run the scan.
Viability Score
How well maintained and how widely used is Arbor? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this
Last calculated: October 2026
How we score →Key Features
- Deterministic blast-radius tracing from a diff to routes, jobs, webhooks, and data writes
- PR comment listing changed scope, reachable paths, likely breakage, unknown edges, and first check
- Per-symbol diffs so each modified symbol gets its own blast radius (engine v3.0.3)
- Import-aware call resolution that considers imports before nearby declarations
- Rust call resolution through paths and macros (engine v3.0.3)
- Inheritance edges included in the call graph (engine v3.0.3)
- Stale graph refresh so results reflect recent commits
- Agent handoff JSON export for Codex, Claude Code, and Cursor
- Framework-aware entrypoint detection for Next.js, Express, FastAPI, Axum, and Spring
- Tree-sitter parsing across 14 languages
- Classifier heuristics for 10 surface categories including billing, auth, data, and migrations
- Sensitive path configuration via .arbor/security.yml and .arbor/security.json
- Unknown edge listing for dynamic imports, generated code, and incomplete resolution
- Smallest useful regression test suggestion attached to each walk
- CLI graph queries such as arbor callers to inspect direct callers
About Arbor
Arbor is a code intelligence engine that parses your repository into a call graph and traces the reachable paths from whatever a diff changes — routes, jobs, webhooks, billing flows, and data writes. It answers one pre-merge question: what does this change actually touch downstream? The walk comes from the graph, not a language model, so the same commit yields the same answer every time, making the output reproducible and auditable. Arbor posts a single PR comment covering changed scope, reachable paths, likely breakage, unknown edges, and the smallest useful regression test to write next. Framework-aware entrypoint detection covers Next.js, Express, FastAPI, Axum, and Spring, and tree-sitter parsing handles 14 languages. Classifier heuristics flag ten surface categories including billing, auth, data, and migrations, with sensitive paths configurable via .arbor/security.yml and .arbor/security.json. For agent workflows, Arbor exports a handoff JSON payload that Codex, Claude Code, or Cursor can consume as a scoped repair prompt instead of letting the model wander the repo. The engine is open source under MIT — the newest release, engine v3.0.3 (2026-09-29), adds Rust call resolution through paths and macros, per-symbol blast radii, inheritance edges, and stale-graph refresh, and ships on GitHub, npm, and crates.io. Arbor Cloud, the hosted change-analysis product, is still in development; the prior dashboard and account flows were closed on 2026-09-23 while it is rebuilt, and the public site now takes waitlist email signups only. It is built for solo developers, tiny teams, and AI coding agents that want a grounded structural brief rather than a model's opinion.
Behind the Verdict
Arbor occupies a narrow, defensible niche: structural risk surfacing rather than code commentary. Its core loop is a deterministic graph walk. Arbor parses your repository, builds a call graph, detects framework entrypoints (Next.js, Express, FastAPI, Axum, Spring), and traces upstream and downstream from the changed symbols to routes, jobs, webhooks, billing flows, and data writes. Because the result is computed rather than generated, the same commit produces the same map — which is exactly what makes it useful as an audit artifact or a merge gate rather than a suggestion box. Strengths. The PR comment is unusually honest for this category: it lists changed scope, reachable paths, likely breakage, unknown edges, and the smallest useful regression test to write next. The unknown-edge section matters — dynamic imports, generated code, and unresolved references are reported as gaps instead of being silently resolved, so you can see where the map stops. Classifier heuristics flag ten surface categories including billing, auth, data, and migrations, and you can extend sensitivity with .arbor/security.yml or .arbor/security.json. For agent workflows, the handoff JSON export is the sharpest idea here: instead of giving Codex, Claude Code, or Cursor an open-ended prompt, you give it a scoped repair brief derived from the graph. The CLI exposes direct queries like arbor callers to inspect what calls a symbol, and the MCP bridge connects the same engine to MCP-compatible assistants. Slack alerts and merge gates let you block risky PRs when a change reaches cross-team blast radius. Engineering velocity has been real. Engine v3.0.0 (2026-08-10) introduced import-aware call resolution — matching calls by considering imports before nearby declarations. v3.0.3 (2026-09-29) extended that to Rust paths and macros, gave every modified symbol its own blast radius instead of one repo-wide list, added inheritance edges, and refreshes stale graphs. It is published on GitHub, npm, and crates.io, though note the release lag: npm and crates.io sat at v2.6.0 through the v3.0.0 window and only caught up at v3.0.3. Linux binaries for v3.0.3 require glibc 2.39, and the installation guide covers older systems — worth checking before you point CI at it. Weaknesses and where it doesn't fit. Arbor does not execute code, so it cannot detect runtime errors or logical bugs — it maps source structure only. Codebases heavy on dynamic metaprogramming, eval, or generated code will produce a lot of unknown edges, which is honest but limits how much the map can be trusted. It does not score code quality, suggest refactors, or review style, so teams that want a conventional AI reviewer should look elsewhere. The commercial picture is the important caveat. Arbor Cloud — hosted change analysis and review context — is in development with no launch date. On 2026-09-23 the company launched a new public site with docs, FAQ, product, pricing, and security pages, and closed the previous
Researching Arbor? Get your full AI stack in 60 seconds.
Free, no signup — tell us your goal and get tools matched to your budget & existing stack.
Real-world workflow fit
Concrete scenarios for the personas Arbor actually fits — and what changes day-one when you adopt it.
You prompt Cursor to add a discount code to the checkout flow, review the diff, and open a PR. Arbor walks the graph and posts one comment listing the billing and data-write paths that diff reaches plus the smallest regression test to write.
Outcome: You merge with a concrete list of downstream paths to check instead of re-reading the whole checkout module, and you write one targeted test rather than a broad smoke suite.
A refactor touches a shared helper. You run Arbor in CI with a merge gate on high-risk paths and Slack alerts, so a PR that reaches auth tokens or payment writes blocks until someone reviews the reachable path list.
Outcome: Cross-team blast radius gets caught at the gate instead of after deploy, and the Slack alert points the reviewer at the exact reachable paths.
Before asking Claude Code to continue, you export the Arbor handoff JSON for the changed symbols and paste it as a scoped repair prompt covering the symbols, their reachable paths, and the unknown edges.
Outcome: The agent edits within a bounded scope derived from the call graph rather than wandering the repository, and the unknown edges tell you where its edits can't be verified structurally.
Use Cases
- Catch duplicate side effects in billing paths before merging a pricing PR
- Give an AI coding agent a scoped repair brief instead of letting it wander the repo
- Identify all routes, jobs, and webhooks touched by a refactor in a Node.js backend
- Flag changes that touch auth tokens, database writes, or payment flows automatically
- Accelerate code review by focusing human attention on the high-risk paths Arbor surfaces
- Block merges when a PR reaches cross-team blast radius using merge gates and Slack alerts
- Use the PR note as a pre-edit brief before asking Claude Code or Cursor to continue
- Query the call graph directly with CLI commands like arbor callers to see what a symbol reaches
Limitations
- Arbor walks the dependency graph deterministically to map PR blast radius and does not execute code; the worker parses and walks source structure only, so runtime behavior isn't analyzed.
- Maps can be incomplete — dynamic imports, generated files, and unresolved edges are surfaced as 'unknown edges' rather than resolved.
- Arbor Cloud is still in development with no announced launch date, and the previous Cloud dashboard and account flows were closed on 2026-09-23 while it is rebuilt.
- Linux binaries for engine v3.0.3 require glibc 2.39.
- Release lag means npm and crates.io sat at v2.6.0 through the v3.0.0 window and only caught up at v3.0.3, so verify the version you actually install.
- Output is structural and should be paired with human or agent review.
as of 2026-10-03
Verification history
We have re-verified Arbor 8 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-checked, vendor evidence unchanged
Showing the 6 most recent of 8 verification passes.
Free to cite with attribution — this page re-verifies continuously.
12-month cost
Project the real annual outlay, including the implied monthly cost when only an annual tier is published.
Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.
Plans compared
For each published Arbor tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.
Arbor Engine
$0
Ideal for
Solo developers and tiny teams willing to run a CLI in their own CI on their own infrastructure, including Rust and Node/Python backends.
What this tier adds
Starting tier — MIT-licensed open-source engine you download and self-host, at $0, with your own compute and model-provider costs billed separately.
Arbor Cloud
Custom
Ideal for
Teams that want hosted change analysis without running the engine themselves — but no launch date is announced, so this is a waitlist, not a purchase.
What this tier adds
Adds hosted change analysis and review context over the self-hosted engine; access invitations are sent by email and earlier published plans are no longer available for purchase.
Where the pricing makes sense
The company stage and team size where Arbor's pricing actually pencils out — and where peers do it cheaper.
Arbor's only currently purchasable product is the MIT-licensed engine at $0 — you self-host it and carry your own compute and model-provider costs. For a solo dev or tiny team willing to run a CLI in CI, the cost floor is effectively zero; teams that need a managed hosted service should budget for an unknown number and
Setup time & first value
How long it actually takes to get something useful out of Arbor — broken out by persona, not the marketing-page minute.
Solo developer: minutes to first PR comment if you install the CLI and run it locally on a repo you already have checked out. Tiny team in CI: roughly an hour to wire the action, set a merge gate, and confirm the entrypoint detection matches your framework — plus extra time if your CI image needs glibc 2.39 for the v3.0.3 binaries. Agent workflow: near-instant once the CLI runs, since the handoff
Switching to or from Arbor
How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.
- →From CodeRabbit: keep CodeRabbit for style and refactor commentary, and add Arbor as a second PR check for structural reach and merge gates.
- →From PullRequest: run Arbor alongside it on the same repos to compare a graph-derived blast radius against model-based review commentary.
- →From a manual reviewer checklist: replace ad-hoc 'what else calls this?' greps with Arbor's arbor callers CLI queries and the PR reachable-path list.
- →From a homegrown dependency script: point Arbor at the same repo and use .arbor/security.yml to mark the sensitive paths your script already treated as high risk.
- ↗To CodeRabbit: if you decide you want inline style suggestions and refactor commentary more than structural reach, standard AI reviewers cover that ground.
- ↗To SonarQube or a full static analyzer: if you need rule-based bug and quality findings across languages, a static analysis platform goes further than a graph walk.
- ↗To Semgrep: if your priority shifts to security pattern matching rather than downstream call reachability, rule-based scanning is a better fit.
Integrations
Resources & Guides
Tutorials & Learning
YouTube returned 6 videos for “Arbor”, and we withheld 6: 6 could not be judged, because “Arbor” is a single word that other videos use for other things. We are showing none, because we could not prove any of them are about Arbor.
Official links
Tools that pair well with Arbor
Common stack mates teams adopt alongside Arbor, with the specific reason each pairing earns its keep.
Greptile
AI code review agent that tests every pull request against a full graph index of your codebase before it ships.
Command Center
Desktop app that turns AI-generated pull requests into guided code walkthroughs and cleans up the mess before merge
SonarQube
SonarQube is code verification and governance software that statically analyzes every pull request across 30+ languages and blocks merges that fail your
Featured Head-to-Head Comparisons
Arbor vs Spider Cloud
Arbor and Spider Cloud solve completely different problems — Arbor is a deterministic code analysis tool for PR risk assessment, while Spider Cloud is a web data extraction API for AI pipelines. Your choice depends on whether you need to prevent breakage in your codebase (Arbor) or feed fresh web content into your AI agents (Spider Cloud). They are not competitors.
Arbor vs Temporal Ai
Arbor is unmatched for solo devs wanting a deterministic, low-overview risk map before merging AI-written PRs. Temporal AI is essential for teams building reliable, long-running AI agents that must survive crashes. Choose Arbor if your pain point is auditability and speed in code review; choose Temporal if your pain point is failure recovery and orchestration of multi-step agents. They solve different problems — pick the one that matches your bottleneck.
Arbor vs Voyage Ai
Arbor and Voyage AI solve entirely different problems. Arbor is for developers who need deterministic, LLM-free PR breakage maps to catch structural bugs in AI-written code. Voyage serves enterprises needing high-accuracy, domain-specific embeddings for RAG. Choose Arbor if you want grounded risk assessment per commit; choose Voyage if you need state-of-the-art retrieval. They are not direct competitors.
Alternatives to Arbor
View allGreptile
AI code review agent that tests every pull request against a full graph index of your codebase before it ships.
Command Center
Desktop app that turns AI-generated pull requests into guided code walkthroughs and cleans up the mess before merge
Frequently Asked Questions
Categories
Used Arbor? Help shape our editorial sentiment research.