Blog

Cursor Bugbot review: pricing, setup and how it compares

Is Cursor Bugbot free? After a 14-day trial it bills per run. What a run costs, how to enable it, and how it scores against other AI reviewers.

Alex Mercer

Cursor Bugbot is Cursor's pull request reviewer: it flags likely bugs in each PR and can send a Cursor agent to push the fix. Since May 2026 you pay per run instead of $40 a seat, and at Cursor's average of $1.00 to $1.50 a run, that's cheap for a quiet repo and hard to budget for a busy one.

Our verdict: Bugbot is the easy pick if your team already works in Cursor, and a real option on GitLab, Bitbucket or Azure DevOps. On GitHub, if catching the most bugs matters more than staying inside Cursor, several reviewers beat it on the benchmark below.

This blog belongs to cubic (cubic.dev), an AI code review tool that competes with Bugbot, so weigh our opinions accordingly. The Bugbot facts here come from Cursor's docs, blog and changelog, read on October 4, 2026.

What is Cursor Bugbot?

Bugbot is the bug bot in Cursor: an AI reviewer for pull requests on GitHub, GitLab, Bitbucket and Azure DevOps. On each new PR or push in the repos you enable, it reviews the diff, comments on problems with a suggested fix, and writes a PR summary. It reads existing PR comments so it doesn't repeat your reviewers.

Findings link to Fix in Cursor (the editor) and Fix in Web (cursor.com/agents). SpaceX acquired Cursor in August 2026; Bugbot is still part of Cursor's plans.

Cursor Bugbot pricing: is Bugbot free?

No. Cursor's Bugbot page offers a 14-day free trial on all plans, and after that each review is a paid run, drawn from your plan's included usage or from on-demand spend. Cursor puts the average run at $1.00 to $1.50, depending on PR size and complexity.

Cursor announced the switch from seats to runs on May 11, 2026. Old seat plans run to their first renewal after June 8, 2026, so an annual plan bought in May 2026 keeps seat pricing until May 2027 unless you switch earlier from the dashboard. Cursor's pricing page lists no per-review rate.

As of October 2026, each Cursor plan pays for Bugbot like this:

Cursor plan

Plan price

How Bugbot bills

Pro, Pro Plus, Ultra

$20, $60 or $200 a month

The plan's included usage first, then on-demand spend

Teams

$40 (Standard) or $120 (Premium) per user a month, for Cursor itself

On-demand spend, on top of the seat price

Old Bugbot subscription

$40 per seat a month

Ends at your first renewal after June 8, 2026

Three settings move the bill:

  • Trigger. Every push is a run by default, even though later runs cover only what changed since the last review.

  • Effort. High reviews cost more and Low reviews less, per Cursor's docs.

  • Autofix. Fixes bill as Cloud Agent usage at your plan's rates.

A rough example, with our arithmetic: 200 pull requests a month with one review each comes to about $200 to $300 at Cursor's average, before Autofix and extra pushes. Our AI code review pricing comparison sets that against per-seat tools.

Does Bugbot work with GitLab, Bitbucket or Azure DevOps?

Yes. Cursor's docs list GitHub, GitLab, Bitbucket and Azure DevOps, though its Bugbot page shows only GitHub. Away from GitHub, support thins out: Bitbucket Cloud and Azure DevOps are public betas, self-hosted GitLab and Bitbucket Data Center need Cursor Teams or Enterprise, and Azure DevOps has no Autofix.

Host

What Cursor's docs say (October 2026)

GitHub and GitHub Enterprise Server

The most complete support, including both Autofix modes

GitLab.com and self-hosted GitLab

Needs a paid GitLab plan (Premium or Ultimate). Self-hosted needs Cursor Teams or Enterprise

Bitbucket Cloud

Public beta

Bitbucket Data Center

Cursor Teams or Enterprise. Supports Bugbot but not Cloud Agents, and comment commands don't run

Azure DevOps Services

Public beta, dev.azure.com only (Azure DevOps Server isn't supported). No Autofix, no automatic rule learning, no personal settings, no Security Review. Comment commands work only for people whose sign-in address matches a Cursor account on the team that owns the repository. If you require the cursor-bugbot/review status, set it to reset when new changes land, or an old pass keeps satisfying the policy

How to enable Cursor Bugbot

Connect GitHub under Integrations in the Cursor dashboard, turn Bugbot on for each repository in Automations, then open a pull request or comment bugbot run on one. You need Cursor admin access, admin rights on the GitHub organization, and billing set up in account settings (individuals) or the team dashboard (teams).

  1. In the Cursor dashboard, open Integrations and click Connect next to GitHub. Choose All repositories or Selected repositories.

  2. Open Bugbot in Automations and turn it on for each repository you want reviewed.

  3. Choose when it runs: on every push (the default), or Run only once per PR or Run only when mentioned in personal settings. Teams and Enterprise can also review draft PRs.

  4. Open a pull request, or comment bugbot run on an open one, and check the comments and the Cursor Bugbot check.

On an individual plan, Bugbot reviews only your own PRs. On Teams, it reviews every contributor's PRs on enabled repositories, on your Cursor team or not, and each review is a run. Admins can narrow that with allow and deny lists.

Where Bugbot fits in your workflow

You can use Bugbot at three points: before you push, on the pull request, and as a merge check.

Before you push

In Cursor 3.7 or later, /review or /review-bugbot runs a Bugbot review before you push, and the same review works at cursor.com/agents and in the Cursor CLI. If you then open a PR with the same diff, Bugbot skips it and leaves a comment saying so.

Our take: if your team lives in Cursor, make the pre-push review the habit. You fix what it finds before a teammate reads the diff.

On the pull request

These PR comments control Bugbot:

Comment on the PR

What happens

bugbot run or cursor review

Starts a review

bugbot run verbose=true

Starts a review and lists the rules it loaded, plus a request ID for support

@cursor remember [fact]

Saves the fact as a learned rule for future reviews

Does Bugbot block merges?

Not by default. On GitHub, the Cursor Bugbot check concludes neutral when Bugbot finds issues, so requiring it in branch protection proves Bugbot ran but doesn't stop a merge with findings open. To block, turn on the setting that fails the check on unresolved issues, if your organization has it.

Neutral is a sensible default for an AI reviewer, since it can be wrong.

BUGBOT.md rules, Autofix and effort levels

Rules in .cursor/BUGBOT.md

Bugbot loads .cursor/BUGBOT.md from the repo root plus any it finds walking up from each changed file, so backend/.cursor/BUGBOT.md applies only when backend code changes. A short example:

# Review rules

- Money is stored as integer cents. Flag floats used for amounts in billing/.
- Handlers in api/ must check auth before reading the request body.
- Flag database calls inside loops in services/ and suggest a batched query

# Review rules

- Money is stored as integer cents. Flag floats used for amounts in billing/.
- Handlers in api/ must check auth before reading the request body.
- Flag database calls inside loops in services/ and suggest a batched query

# Review rules

- Money is stored as integer cents. Flag floats used for amounts in billing/.
- Handlers in api/ must check auth before reading the request body.
- Flag database calls inside loops in services/ and suggest a batched query

The dashboard adds Team Rules for every repository and manual rules for one. Limits worth knowing:

  • Bugbot cuts each rule at 30,000 characters and caps all rules together at 100,000 characters per review, dropping the overflow but keeping required team rules. bugbot run verbose=true shows what it cut.

  • Cursor's editor rules in .cursor/rules/*.mdc don't apply to Bugbot. Copy the conventions that matter for review into BUGBOT.md.

Learned rules

Since April 8, 2026, Bugbot can write its own rules. According to Cursor's changelog, it learns from reactions and replies to its comments and from human reviewers' comments, keeps the rules that collect signal and switches off the rest. You turn learning on per organization and repository.

Autofix

Autofix spawns a Cloud Agent to fix what Bugbot found. The modes are off, Create New Branch (Cursor's recommendation) and Commit to Existing Branch, which stops after 3 attempts per PR to avoid loops. GitLab and Bitbucket support only the existing-branch mode. Autofix needs on-demand usage and storage turned on, so it doesn't run in Legacy Privacy Mode.

Autofix left beta on February 26, 2026, and Cursor said then that over 35% of its changes get merged.

One cost trap: under the default every-push trigger, each Autofix commit to the PR branch is a new push, so one fix can set off another review and another billed run.

Effort levels

Since the May 2026 change, usage-based plans can set how hard Bugbot works:

  • Low: cheaper and slower; Cursor says quality is close to Default.

  • Default: tuned for efficiency and speed.

  • High: more reasoning, longer reviews and higher cost; it may find more bugs.

  • Smart: you describe when Bugbot should use Low, Default or High.

In Cursor's internal runs, High found 35% more bugs than Default at the same 80% resolution rate. If you pick High, mind the trigger. High on every push costs the most, and once per PR costs less but leaves later pushes unreviewed unless someone comments bugbot run.

Settings as code: bugbot.yaml

This repo file asks for one high-effort review per PR and posts the summary as a comment:

# .cursor/config/bugbot.yaml
version: 1
triggers:
  frequency: oncePerPr   # or everyPush
review:
  effort: high           # low | default | high | smart
prSummary:
  mode: comment          # disabled | description | comment
# .cursor/config/bugbot.yaml
version: 1
triggers:
  frequency: oncePerPr   # or everyPush
review:
  effort: high           # low | default | high | smart
prSummary:
  mode: comment          # disabled | description | comment
# .cursor/config/bugbot.yaml
version: 1
triggers:
  frequency: oncePerPr   # or everyPush
review:
  effort: high           # low | default | high | smart
prSummary:
  mode: comment          # disabled | description | comment

Bugbot reads this file from the PR's base branch, so a pull request can't change how it gets reviewed. It ignores files over 64 KB, and the file can lower the dashboard's Autofix mode but not raise it.

Bugbot's 2026 updates

June 10: faster and cheaper, Cursor says

On June 10, 2026, Cursor said Bugbot now runs over 3x faster, costs 22% less and finds 10% more bugs per review, and that 90% of runs finish in under three minutes. It credits Composer 2.5, the Cursor-trained model that now powers Bugbot, plus changes to the system around the model. The same release added the pre-push /review and incremental reviews.

These are Cursor's numbers, and the post gives no resolution rate, so it doesn't say how many of the extra bugs get fixed. If your organization blocks Composer 2.5, Bugbot falls back to another model, and Cursor notes that speed and performance depend on your configuration.

September 23: Security Review is a separate bot

Cursor launched Security Review for Teams and Enterprise. It reads each pull request with the codebase as context and posts one comment listing exploitable bugs, such as injection, auth bypasses, committed secrets, SSRF and vulnerable dependency changes. The announcement leaves style and code quality to Bugbot, though Bugbot's docs still list security issues among what it finds. If you want Cursor's dedicated security pass on Teams, it's a second bot to turn on.

Is Bugbot any good?

It's precise, but it misses more bugs than the leading reviewers. On Martian's Code Review Bench online tracker (last-month view, checked October 4, 2026), developers acted on 72.5% of Bugbot's comments, in line with the top four tools (67.0% to 79.0%). But it caught 47.1% of the fixes developers made, below all four (50.8% to 59.7%).

Martian, which describes itself as a research lab that doesn't sell coding tools, scores review bots on real open-source pull requests. Precision is the share of a reviewer's comments developers acted on, recall is the share of real fixes it caught, and F1 balances the two. The last-month view (September 4 to October 4, 2026), ranked by F1, lists Bugbot as "Cursor":

Rank

Tool

F1

Precision

Recall

1

cubic

65.3%

72.0%

59.7%

2

Greptile

61.9%

79.0%

50.8%

3

CodeRabbit

61.8%

70.0%

55.3%

4

GitHub Copilot

61.0%

67.0%

56.0%

10

Cursor (Bugbot)

57.1%

72.5%

47.1%

Cursor's product page says Bugbot "optimizes for bugs that get fixed", and the resolution rates Cursor reports (the share of flagged bugs fixed before merge) rose from 76% in February 2026 to 78% in April and 80% at Default effort in May. We read the low recall as the price of that focus.

Martian's offline benchmark runs every tool on the same 50 PRs with hard-to-find bugs and ranks them by F2, which weights recall more. On the board labeled September 8, 2026, "Cursor Bugbot" is #13 of 21 at 48.6% F2. Qodo's Deep configuration is #1 at 65.1%, 0.2 points ahead of cubic at 64.9%.

Two cautions. The board moves daily, and several vendors, cubic included, have each claimed #1 at different dates and in different modes. Martian also warns that its online data can't settle head-to-head comparisons, because bots see each other's comments and different kinds of repos adopt different tools.

How Bugbot compares with cubic

This is where our bias matters most, so we'll stick to what each product documents. Prices are as of October 2026, from Cursor's pricing page and cubic's pricing page.


Cursor Bugbot

cubic

Git hosts

GitHub, GitLab, Bitbucket, Azure DevOps (some in beta)

GitHub only

How you pay

Per run, average $1.00-1.50 (Cursor's figure), through a Cursor plan

Per developer: Team $30, Pro $79, Max $160 a month billed yearly ($40, $99, $200 monthly), each with a pooled allowance of reviewed lines

Free options

14-day trial

7-day trial with no card, a free plan with 20 PR reviews a month, free for public repos within fair-use limits

Review rules

.cursor/BUGBOT.md, Team Rules, manual rules

Plain-English custom agents with path filters, cubic.yaml, and context files such as AGENTS.md, CLAUDE.md and .cursorrules

Learning

Reactions, replies, reviewer comments and a backfill from repo history; @cursor remember

Replies, thumbs up and down, and the past PR comments of up to five senior reviewers you choose

Fixes

Autofix through Cloud Agents (not on Azure DevOps)

Fix with cubic, on Pro and Max

Deeper reviews

Low, Default, High and Smart effort

Ultrareview, about 9 minutes, counts 3x against the allowance

Martian online tracker F1 (last month, checked Oct 4, 2026)

57.1% (#10)

65.3% (#1)

In practice, cubic differs in four places:

  • GitHub only. On GitLab, Bitbucket or Azure DevOps, Bugbot can review your code and cubic can't. That settles it.

  • Seat pricing. The seat price is fixed, but if a busy month uses up the pooled allowance, reviews pause until the reset unless you add flex capacity at $20 per 10,000 lines, which you can cap.

  • Approvals and repo scans. cubic can auto-approve PRs that meet your policy, starting in shadow mode (Team, Pro and Max), and codebase scans audit the whole repository (Pro and Max, beta, by request).

  • It works alongside Cursor. cubic's CLI and MCP server run from Cursor's agent, and Fix with cubic can use Cursor cloud agents instead of cubic's own.

For the full side-by-side, see cubic vs Cursor Bugbot.

Who should use Bugbot

Bugbot fits if:

  • Your team already pays for Cursor and works in it. Setup happens in a dashboard you already use, and fixes flow back into the editor.

  • Your code lives on GitLab, Bitbucket or Azure DevOps.

  • Your PR volume is low or uneven. With no review seat to buy, a quiet month costs little.

Look elsewhere if you're on GitHub and recall matters most, or if you need a monthly bill you can forecast. Our roundup of Cursor Bugbot alternatives covers more options. If you're on GitHub without Cursor, start with our guide to GitHub Copilot code review.

Test any reviewer on your own pull requests before you trust anyone's ranking, ours included.

If you're on GitHub, try cubic's AI code reviewer next to Bugbot on the same PRs. The trial lasts 7 days and needs no card.

Table of contents