Arbor

Arbor

Deterministic dependency-graph analysis that shows exactly what a pull request can reach before you merge it

71/100Safe BetFree planFreemium

If your problem is "what could this diff break?" rather than "is this code good?", Arbor's graph walk is the more honest primitive — it is explicit about unknown edges instead of hallucinating confidence. It won't find logic bugs and it says so plainly. Today the only thing you can actually buy and run is the MIT-licensed engine, whose v3.0.3 release adds Rust call resolution, per-symbol blast radii, and inheritance edges. The catch: hosted Arbor Cloud has no announced launch date, the previous dashboard and account flows closed on 2026-09-23, and signup is a waitlist. Start with the open-source engine and treat Cloud as a wait-and-see. Pair it with a model-based reviewer like CodeRabbit if

Verified 6d ago · liveness 71/100 · cite: rightaichoice.com/tools/arbor

Best for
  • Solo developers who want a structural risk read on their own AI-generated PRs before merging
  • Tiny teams that need automated breakage context without a heavyweight code review process
  • AI agent workflows that need a compact, grounded handoff before the agent edits code
  • Engineers assessing downstream risk when a diff touches billing, auth, or data layers
Not ideal for
  • Teams expecting full static analysis or symbolic execution
  • Codebases heavy on dynamic metaprogramming, eval, or generated code where indexing leaves gaps
  • Buyers wanting an LLM code review assistant with inline style and refactor suggestions
Visit Website

IntermediateSolo developer: minutes to first PR comment if you install the CLI and run it locally on a repo you already have checked out. Tiny team in CI: roughly an hour to wire the action, set a merge gate, and confirm the entrypoint detection matches your framework — plus extra time if your CI image needs glibc 2.39 for the v3.0.3 binaries. Agent workflow: near-instant once the CLI runs, since the handoffWeb · Plugin · APIAPI availableVerified 6d ago
Pricing
Free plan
FreemiumFree tier2 plans3 hidden costs
Learning curve
Intermediate
Solo developer: minutes to first PR comment if you install the CLI and run it locally on a repo you already have checked out. Tiny team in CI: roughly an hour to wire the action, set a merge gate, and confirm the entrypoint detection matches your framework — plus extra time if your CI image needs glibc 2.39 for the v3.0.3 binaries. Agent workflow: near-instant once the CLI runs, since the handoff
Runs on
WebPluginAPI
API available · 2 integrations
Who it's for
Solo developer shipping AI-generated PRsTwo-person backend team on a Node.js serviceDeveloper driving a coding agent on a Rust service
Live sentiment
Is Arbor actually worth it?

We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.

  • Honest verdict, not marketing
  • Real pros & cons from real users
  • Attributed quotes with receipts
Run a free scan

3 free scans · no card needed

Skip it if

Skip Arbor if you need an LLM reviewer that comments on code style, suggests refactors, or catches logical bugs — Arbor maps structural reach only and will report unknown edges rather than guess at them.

The 30-second take
Biggest gripe

Running the free MIT engine on your own infrastructure means you pay for compute and any model-provider charges separately — Arbor does not cover those.

Price reality

Arbor's only currently purchasable product is the MIT-licensed engine at $0 — you self-host it and carry your own compute and model-provider costs. For a solo dev or tiny team willing to run a CLI in CI, the cost floor is effectively zero; teams that need a managed hosted service should budget for an unknown number and

In short

Arbor — Deterministic dependency-graph analysis that shows exactly what a pull request can reach before you merge it. Best for Solo developers who want a structural risk read on their own AI-generated PRs before merging, Tiny teams that need automated breakage context without a heavyweight code review process, AI agent workflows that need a compact, grounded handoff before the agent edits code. Free to use.

What's new in Arbor

Checked 6 days ago

Across the latest 5 updates: 3 feature updates, 1 launch and 1 news mention.

What people actually say about Arbor — is it worth it?

We scanned public community sources for Arbor on Jul 26, 2026 and could not establish that the discussion we found is about this tool rather than something else sharing its name. Our own analysis of that scan says the posts were off-subject. Rather than publish a sentiment score built on the wrong subject, we publish nothing here and re-run the scan.

Viability Score

71/100
Safe Bet

How well maintained and how widely used is Arbor? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this

Recent activity
90
Traction
100
Site health
95
User sentiment
12
What the vendor publishes
40

Last calculated: October 2026

How we score →

Key Features

  • Deterministic blast-radius tracing from a diff to routes, jobs, webhooks, and data writes
  • PR comment listing changed scope, reachable paths, likely breakage, unknown edges, and first check
  • Per-symbol diffs so each modified symbol gets its own blast radius (engine v3.0.3)
  • Import-aware call resolution that considers imports before nearby declarations
  • Rust call resolution through paths and macros (engine v3.0.3)
  • Inheritance edges included in the call graph (engine v3.0.3)
  • Stale graph refresh so results reflect recent commits
  • Agent handoff JSON export for Codex, Claude Code, and Cursor
  • Framework-aware entrypoint detection for Next.js, Express, FastAPI, Axum, and Spring
  • Tree-sitter parsing across 14 languages
  • Classifier heuristics for 10 surface categories including billing, auth, data, and migrations
  • Sensitive path configuration via .arbor/security.yml and .arbor/security.json
  • Unknown edge listing for dynamic imports, generated code, and incomplete resolution
  • Smallest useful regression test suggestion attached to each walk
  • CLI graph queries such as arbor callers to inspect direct callers

About Arbor

FreemiumIntermediateAPI availableWeb · Plugin · API

Arbor is a code intelligence engine that parses your repository into a call graph and traces the reachable paths from whatever a diff changes — routes, jobs, webhooks, billing flows, and data writes. It answers one pre-merge question: what does this change actually touch downstream? The walk comes from the graph, not a language model, so the same commit yields the same answer every time, making the output reproducible and auditable. Arbor posts a single PR comment covering changed scope, reachable paths, likely breakage, unknown edges, and the smallest useful regression test to write next. Framework-aware entrypoint detection covers Next.js, Express, FastAPI, Axum, and Spring, and tree-sitter parsing handles 14 languages. Classifier heuristics flag ten surface categories including billing, auth, data, and migrations, with sensitive paths configurable via .arbor/security.yml and .arbor/security.json. For agent workflows, Arbor exports a handoff JSON payload that Codex, Claude Code, or Cursor can consume as a scoped repair prompt instead of letting the model wander the repo. The engine is open source under MIT — the newest release, engine v3.0.3 (2026-09-29), adds Rust call resolution through paths and macros, per-symbol blast radii, inheritance edges, and stale-graph refresh, and ships on GitHub, npm, and crates.io. Arbor Cloud, the hosted change-analysis product, is still in development; the prior dashboard and account flows were closed on 2026-09-23 while it is rebuilt, and the public site now takes waitlist email signups only. It is built for solo developers, tiny teams, and AI coding agents that want a grounded structural brief rather than a model's opinion.

Behind the Verdict

Arbor occupies a narrow, defensible niche: structural risk surfacing rather than code commentary. Its core loop is a deterministic graph walk. Arbor parses your repository, builds a call graph, detects framework entrypoints (Next.js, Express, FastAPI, Axum, Spring), and traces upstream and downstream from the changed symbols to routes, jobs, webhooks, billing flows, and data writes. Because the result is computed rather than generated, the same commit produces the same map — which is exactly what makes it useful as an audit artifact or a merge gate rather than a suggestion box. Strengths. The PR comment is unusually honest for this category: it lists changed scope, reachable paths, likely breakage, unknown edges, and the smallest useful regression test to write next. The unknown-edge section matters — dynamic imports, generated code, and unresolved references are reported as gaps instead of being silently resolved, so you can see where the map stops. Classifier heuristics flag ten surface categories including billing, auth, data, and migrations, and you can extend sensitivity with .arbor/security.yml or .arbor/security.json. For agent workflows, the handoff JSON export is the sharpest idea here: instead of giving Codex, Claude Code, or Cursor an open-ended prompt, you give it a scoped repair brief derived from the graph. The CLI exposes direct queries like arbor callers to inspect what calls a symbol, and the MCP bridge connects the same engine to MCP-compatible assistants. Slack alerts and merge gates let you block risky PRs when a change reaches cross-team blast radius. Engineering velocity has been real. Engine v3.0.0 (2026-08-10) introduced import-aware call resolution — matching calls by considering imports before nearby declarations. v3.0.3 (2026-09-29) extended that to Rust paths and macros, gave every modified symbol its own blast radius instead of one repo-wide list, added inheritance edges, and refreshes stale graphs. It is published on GitHub, npm, and crates.io, though note the release lag: npm and crates.io sat at v2.6.0 through the v3.0.0 window and only caught up at v3.0.3. Linux binaries for v3.0.3 require glibc 2.39, and the installation guide covers older systems — worth checking before you point CI at it. Weaknesses and where it doesn't fit. Arbor does not execute code, so it cannot detect runtime errors or logical bugs — it maps source structure only. Codebases heavy on dynamic metaprogramming, eval, or generated code will produce a lot of unknown edges, which is honest but limits how much the map can be trusted. It does not score code quality, suggest refactors, or review style, so teams that want a conventional AI reviewer should look elsewhere. The commercial picture is the important caveat. Arbor Cloud — hosted change analysis and review context — is in development with no launch date. On 2026-09-23 the company launched a new public site with docs, FAQ, product, pricing, and security pages, and closed the previous

Researching Arbor? Get your full AI stack in 60 seconds.

Free, no signup — tell us your goal and get tools matched to your budget & existing stack.

Real-world workflow fit

Concrete scenarios for the personas Arbor actually fits — and what changes day-one when you adopt it.

Solo developer shipping AI-generated PRs

You prompt Cursor to add a discount code to the checkout flow, review the diff, and open a PR. Arbor walks the graph and posts one comment listing the billing and data-write paths that diff reaches plus the smallest regression test to write.

Outcome: You merge with a concrete list of downstream paths to check instead of re-reading the whole checkout module, and you write one targeted test rather than a broad smoke suite.

Two-person backend team on a Node.js service

A refactor touches a shared helper. You run Arbor in CI with a merge gate on high-risk paths and Slack alerts, so a PR that reaches auth tokens or payment writes blocks until someone reviews the reachable path list.

Outcome: Cross-team blast radius gets caught at the gate instead of after deploy, and the Slack alert points the reviewer at the exact reachable paths.

Developer driving a coding agent on a Rust service

Before asking Claude Code to continue, you export the Arbor handoff JSON for the changed symbols and paste it as a scoped repair prompt covering the symbols, their reachable paths, and the unknown edges.

Outcome: The agent edits within a bounded scope derived from the call graph rather than wandering the repository, and the unknown edges tell you where its edits can't be verified structurally.

Use Cases

Limitations

  • Arbor walks the dependency graph deterministically to map PR blast radius and does not execute code; the worker parses and walks source structure only, so runtime behavior isn't analyzed.
  • Maps can be incomplete — dynamic imports, generated files, and unresolved edges are surfaced as 'unknown edges' rather than resolved.
  • Arbor Cloud is still in development with no announced launch date, and the previous Cloud dashboard and account flows were closed on 2026-09-23 while it is rebuilt.
  • Linux binaries for engine v3.0.3 require glibc 2.39.
  • Release lag means npm and crates.io sat at v2.6.0 through the v3.0.0 window and only caught up at v3.0.3, so verify the version you actually install.
  • Output is structural and should be paired with human or agent review.

as of 2026-10-03

Verification history

We have re-verified Arbor 8 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.

  1. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  2. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  3. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  4. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  5. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  6. — re-checked, vendor evidence unchanged

Showing the 6 most recent of 8 verification passes.

Free to cite with attribution — this page re-verifies continuously.

12-month cost

Project the real annual outlay, including the implied monthly cost when only an annual tier is published.

Annual total
Free
Over 12 months
Effective monthly
—
—

Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.

Plans compared

For each published Arbor tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.

Arbor Engine

$0

Ideal for

Solo developers and tiny teams willing to run a CLI in their own CI on their own infrastructure, including Rust and Node/Python backends.

What this tier adds

Starting tier — MIT-licensed open-source engine you download and self-host, at $0, with your own compute and model-provider costs billed separately.

Arbor Cloud

Custom

Ideal for

Teams that want hosted change analysis without running the engine themselves — but no launch date is announced, so this is a waitlist, not a purchase.

What this tier adds

Adds hosted change analysis and review context over the self-hosted engine; access invitations are sent by email and earlier published plans are no longer available for purchase.

Hidden costs & gotchas

What the public pricing page doesn't put in bold. Captured from pricing-page footnotes, contract terms, and recurring complaints.

  • Running the free MIT engine on your own infrastructure means you pay for compute and any model-provider charges separately — Arbor does not cover those.
  • Arbor Cloud has no announced launch date and no published tier prices, so any budget you set for the hosted product is an estimate until it opens.
  • Engine v3.0.3 Linux binaries require glibc 2.39, so older CI images may need an OS upgrade before Arbor runs at all.

Where the pricing makes sense

The company stage and team size where Arbor's pricing actually pencils out — and where peers do it cheaper.

Arbor's only currently purchasable product is the MIT-licensed engine at $0 — you self-host it and carry your own compute and model-provider costs. For a solo dev or tiny team willing to run a CLI in CI, the cost floor is effectively zero; teams that need a managed hosted service should budget for an unknown number and

Setup time & first value

How long it actually takes to get something useful out of Arbor — broken out by persona, not the marketing-page minute.

Solo developer: minutes to first PR comment if you install the CLI and run it locally on a repo you already have checked out. Tiny team in CI: roughly an hour to wire the action, set a merge gate, and confirm the entrypoint detection matches your framework — plus extra time if your CI image needs glibc 2.39 for the v3.0.3 binaries. Agent workflow: near-instant once the CLI runs, since the handoff

Switching to or from Arbor

How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.

Migrating in
  • →From CodeRabbit: keep CodeRabbit for style and refactor commentary, and add Arbor as a second PR check for structural reach and merge gates.
  • →From PullRequest: run Arbor alongside it on the same repos to compare a graph-derived blast radius against model-based review commentary.
  • →From a manual reviewer checklist: replace ad-hoc 'what else calls this?' greps with Arbor's arbor callers CLI queries and the PR reachable-path list.
  • →From a homegrown dependency script: point Arbor at the same repo and use .arbor/security.yml to mark the sensitive paths your script already treated as high risk.
Migrating out
  • ↗To CodeRabbit: if you decide you want inline style suggestions and refactor commentary more than structural reach, standard AI reviewers cover that ground.
  • ↗To SonarQube or a full static analyzer: if you need rule-based bug and quality findings across languages, a static analysis platform goes further than a graph walk.
  • ↗To Semgrep: if your priority shifts to security pattern matching rather than downstream call reachability, rule-based scanning is a better fit.

Integrations

GitHubSlack

Resources & Guides

Tutorials & Learning

YouTube returned 6 videos for “Arbor”, and we withheld 6: 6 could not be judged, because “Arbor” is a single word that other videos use for other things. We are showing none, because we could not prove any of them are about Arbor.

Tools that pair well with Arbor

Common stack mates teams adopt alongside Arbor, with the specific reason each pairing earns its keep.

Featured Head-to-Head Comparisons

Alternatives to Arbor

View all
Greptile

Greptile

AI code review agent that tests every pull request against a full graph index of your codebase before it ships.

FreemiumTry
Command Center

Command Center

Desktop app that turns AI-generated pull requests into guided code walkthroughs and cleans up the mess before merge

FreemiumTry
SonarQube

SonarQube

SonarQube is code verification and governance software that statically analyzes every pull request across 30+ languages and blocks merges that fail your

FreemiumTry

Frequently Asked Questions

Used Arbor? Help shape our editorial sentiment research.