Best Static Application Security Testing (SAST) Software for Small Business

How Many Static Application Security Testing (SAST) Software Products Does G2 Track?

Total Products under this Category: 117

Category Stats (Sep 2026)

  • Average Rating: 4.54/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Static Application Security Testing (SAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,500+ Authentic Reviews
  • 117+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Application Security Testing (SAST) Software

G2 Grid® for Static Application Security Testing (SAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, GitHub, GitGuardian, SonarQube, GitLab, Checkmarx, Snyk, and HCL AppScan.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-application-security-testing-sast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=github&focus%5B%5D=gitguardian&focus%5B%5D=sonarqube&focus%5B%5D=gitlab&focus%5B%5D=checkmarx&focus%5B%5D=snyk&focus%5B%5D=hcl-appscan&segment=small-business)

Aikido Security

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

Average Rating: 4.6/5.0

Total Reviews: 263

How Do G2 Users Rate Aikido Security?

  • Test Automation: 8.6/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.1/10)
  • Quality of Support: 9.3/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Aikido Security?

  • Seller: Aikido Security
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Ghent, Belgium
  • Twitter: @AikidoSecurity
    11,770 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    320 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Founder, CTO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 79% Small, 14% Medium

What Do G2 Reviewers Say About Aikido Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Aikido Security, thanks to its clear insights and seamless integration.
  • Users appreciate Aikido Security's robust security capabilities, providing a comprehensive and seamless integration in their workflow.
  • Users value the intuitive dashboard of Aikido Security, which simplifies security issue identification and management.
  • Users value the easy integrations of Aikido Security, enhancing workflows with seamless connections to existing GitLab repositories.
  • Users find Aikido's easy setup highly efficient, enabling quick implementation and immediate usability for security assessments.
Cons
  • Users note the lack of advanced features in Aikido Security, such as dark mode and in-depth analysis options.
  • Users find the pricing structure expensive for micro businesses, making upgrades difficult to justify.
  • Users note the limited features of Aikido Security, wishing for more customization and advanced options.
  • Users find the pricing issues challenging, especially for micro businesses, due to the steep upgrade costs.
  • Users feel Aikido Security is lacking features like advanced reporting and deeper compliance analysis compared to competitors.

What Are Recent G2 Reviews of Aikido Security?

GitHub

GitHub is where the world builds software. Millions of individuals, organizations and businesses around the world use GitHub to discover, share, and contribute software. Developers at startups to Fortune 50 companies use GitHub, every step of the way.

Average Rating: 4.7/5.0

Total Reviews: 2,340

How Do G2 Users Rate GitHub?

  • Test Automation: 8.5/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.1/10)
  • Quality of Support: 8.7/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.3/10 (Category avg: 8.4/10)

Who Is the Company Behind GitHub?

  • Seller: GitHub
  • Year Founded: 2008
  • HQ Location: San Francisco, CA
  • Twitter: @github
    2,673,925 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6,653 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 47% Small, 31% Medium

What Do G2 Reviewers Say About GitHub?

AI-generated summary from verified user reviews

Pros
  • Users value GitHub's seamless collaboration and powerful version control, enhancing project transparency and workflow management.
  • Users appreciate the ease of use of GitHub, enabling seamless collaboration and efficient version control.
  • Users value the seamless team collaboration on GitHub, enhancing code sharing and workflow management effectively.
  • Users value the seamless collaboration offered by GitHub, enhancing project transparency and team workflow management.
  • Users value GitHub for its seamless version control, enhancing collaboration and streamlining the development process.
Cons
  • Users find the complexity in advanced features of GitHub challenging, particularly for newcomers and managing large repositories.
  • Users find the learning curve challenging, especially when designing workflows and managing permissions effectively.
  • Users find learning GitHub challenging due to overwhelming settings and complexities, making navigation difficult for newcomers.
  • Users find the complexity for beginners challenging, especially with CI/CD workflows and permission management.
  • Users find the steep learning curve of GitHub challenging, especially in mastering workflows and managing permissions.

What Are Recent G2 Reviews of GitHub?

What Are G2 Users Discussing About GitHub?

GitGuardian

GitGuardian is an end-to-end Secrets and Non-Human Identity (NHI) Security platform designed to help organizations eliminate secrets sprawl, govern machine identities, and meet compliance requirements under PCI-DSS v4.0, DORA, NYDFS Part 500, and NIS 2. As attackers increasingly target NHIs like service accounts, service principals, AI agents, and applications, protecting the credentials they rely on has become critical. GitGuardian's platform is built on three pillars: Secrets Security, NHI Governance, and Developer Endpoint Protection. **Secrets Security** eliminates leaks across every environment. Internal Secrets Monitoring detects hardcoded credentials in source code, CI/CD pipelines, container images, and collaboration tools like Slack, Jira, and Confluence with 500+ purpose-built detectors and a false positive rate under 10%. Public Secrets Monitoring scans 1B+ public GitHub commits daily, alerting teams the moment a secret is exposed externally. Honeytokens deploy decoy credentials that trigger immediate alerts on unauthorized access attempts. **NHI Governance** provides a centralized inventory of machine identities, including those outside vaults, with ownership attribution, risk scoring, and compliance evidence to support access reviews and rotation policy configuration. **Developer Endpoint Protection** extends coverage to the credential layer that repo and CI scanning can't reach: developer laptops. GitGuardian scans project directories, .env files, cloud credential stores, AI agent configs, and shell history across the entire fleet, delivering a prioritized inventory of exposed secrets by machine and severity. Trusted by Snowflake, ING, BASF, Datadog, Webflow, Bouygues Telecom, and more, and the #1 most-installed security app on the GitHub Marketplace.

Average Rating: 4.8/5.0

Total Reviews: 282

How Do G2 Users Rate GitGuardian?

  • Test Automation: 8.4/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 9.1/10)
  • Quality of Support: 9.1/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 9.0/10 (Category avg: 8.4/10)

Who Is the Company Behind GitGuardian?

  • Seller: GitGuardian
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Paris, Île-de-France
  • Twitter: @GitGuardian
    6,055 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    208 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Software Developer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 85% Small, 12% Medium

What Do G2 Reviewers Say About GitGuardian?

AI-generated summary from verified user reviews

Pros
  • Users value the real-time alert notifications from GitGuardian, ensuring quick detection of key leaks and issues.
  • Users value the automated security features of GitGuardian, ensuring quick detection of secrets throughout the development process.
  • Users love the automated vulnerability detection of GitGuardian, ensuring fast and efficient secret management after code pushes.
  • Users value the accuracy of GitGuardian, noting its swift detection of issues with precise actionable feedback.
  • Users value the immediate detection speed of GitGuardian, ensuring quick resolutions and minimal workflow interruptions.
Cons
  • Users face challenges with false positives, requiring time to adjust settings and improve user experience.
  • Users find the inefficient notifications overwhelming, leading to increased review time and a cluttered interface when managing alerts.
  • Users find limited customization in GitGuardian, hindering the adjustment of alerts and specific security policies.
  • Users find the confusing interface of GitGuardian complicates navigation and slows down incident resolution despite helpful alerting.
  • Users report feeling overwhelmed by the excessive notifications from GitGuardian, complicating workflow and alert management.

What Are Recent G2 Reviews of GitGuardian?

What Are G2 Users Discussing About GitGuardian?

SonarQube

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

Average Rating: 4.4/5.0

Total Reviews: 152

How Do G2 Users Rate SonarQube?

  • Test Automation: 6.4/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.1/10)
  • Quality of Support: 8.1/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 6.8/10 (Category avg: 8.4/10)

Who Is the Company Behind SonarQube?

  • Seller: SonarSource Sàrl
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Geneva, Switzerland
  • Twitter: @SonarSource
    10,913 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    973 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, DevOps Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 42% Large, 40% Medium

What Do G2 Reviewers Say About SonarQube?

AI-generated summary from verified user reviews

Pros
  • Users value SonarQube for its ability to quickly flag code quality and security issues, ensuring a reliable codebase.
  • Users value the flexible issue filtering and prioritization features of SonarQube, enhancing team productivity and focus.
  • Users appreciate how SonarQube quickly flags code quality and security issues, ensuring a clean and reliable codebase.
  • Users appreciate the ease of use of SonarQube, finding integration and actionable feedback simple and effective.
  • Users appreciate the easy integrations with CI/CD tools, enhancing their workflow and improving code quality effectively.
Cons
  • Users face software bugs that lead to false positives, complicating the experience and requiring significant knowledge to manage.
  • Users find the complex configuration of SonarQube challenging, especially for beginners needing extensive knowledge.
  • Users encounter false positives that complicate usage, despite helpful tools for review and customization of analysis.
  • Users find SonarQube's complexity in configuration and excessive warnings can make it cumbersome to use.
  • Users find the complex setup of SonarQube time-consuming, requiring significant effort to configure and tune effectively.

What Are Recent G2 Reviews of SonarQube?

What Are G2 Users Discussing About SonarQube?

GitLab

GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab, teams can create, deliver, and manage code quickly and continuously instead of managing disparate tools and scripts. GitLab helps your teams across the complete DevSecOps lifecycle, from developing, securing, and deploying software. What makes us truly different? - Flexibility: Consume as a service or manage your own deployment - Cloud-Agnostic: Deploy anywhere with no vendor lock-in - No rip and replace: Scale to a platform approach at your own pace

Average Rating: 4.5/5.0

Total Reviews: 885

How Do G2 Users Rate GitLab?

  • Test Automation: 9.2/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.8/10 (Category avg: 9.1/10)
  • Quality of Support: 8.5/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.9/10 (Category avg: 8.4/10)

Who Is the Company Behind GitLab?

  • Seller: GitLab Inc.
  • Year Founded: 2014
  • HQ Location: San Francisco, California
  • Twitter: @gitlab
    171,534 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,431 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 37% Medium, 37% Small

What Do G2 Reviewers Say About GitLab?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use in GitLab, enjoying its all-in-one DevOps capabilities and intuitive interface.
  • Users value the all-encompassing features of GitLab, which enhance collaboration and streamline the DevOps workflow.
  • Users love the seamless CI/CD integration of GitLab, simplifying automation and collaboration in DevOps workflows.
  • Users value the seamless integrations in GitLab, resulting in efficient workflows and streamlined management across multiple functions.
  • Users praise the seamless CI/CD integration in GitLab, enhancing automation and collaboration within their DevOps workflow.
Cons
  • Users find the complexity of GitLab's setup and management to be a significant barrier to efficient use.
  • Users find the difficult learning curve of GitLab challenging due to its complex interface and YAML syntax.
  • Users find the interface confusing due to clutter and slow performance with large repositories, complicating their navigation.
  • Users find the complex user interface challenging, especially with slow performance and difficulties in navigation and management.
  • Users find the learning curve steep, particularly for those new to DevOps and managing extensive features.

What Are Recent G2 Reviews of GitLab?

What Are G2 Users Discussing About GitLab?

Snyk

Snyk (pronounced sneak) is a developer security platform for securing custom code, open source dependencies, containers, and cloud infrastructure all from a single platform. Snyk’s developer security solutions enable modern applications to be built securely, empowering developers to own and build security for the whole application, from code & open source to containers & cloud infrastructure. Secure while you code in your IDE: find issues quickly using the scanner, fix issues easily with remediation advice, verify the updated code. Integrate your source code repositories to secure applications: integrate a repository to find issues, prioritize with context, fix & merge. Secure your containers as you build, throughout the SDLC: start fixing containers as soon as your write a Dockerfile, continuously monitor container images throughout their lifecycle, and prioritize with context. Secure build and deployment pipelines: Integrate natively with your CI/CD tool, configure your rules, find & fix issues in your application, and monitor your applications. Secure your apps quickly with Snyk’s vulnerability scanning and automated fixes - Try for Free!

Average Rating: 4.5/5.0

Total Reviews: 136

How Do G2 Users Rate Snyk?

  • Test Automation: 7.8/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.7/10 (Category avg: 9.1/10)
  • Quality of Support: 8.6/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 6.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Snyk?

  • Seller: Snyk
  • HQ Location: Boston, Massachusetts
  • Twitter: @snyksec
    21,057 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,764 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 45% Medium, 35% Small

What Do G2 Reviewers Say About Snyk?

AI-generated summary from verified user reviews

Pros
  • Users value Snyk's quick vulnerability detection, significantly improving efficiency in code security and remediation processes.
  • Users appreciate Snyk for its efficient vulnerability identification, significantly aiding in maintaining secure code and streamlining DevOps processes.
  • Users value the easy integration setup of Snyk, enhancing vulnerability detection in their development workflows.
  • Users appreciate the easy setup of Snyk, seamlessly integrating with GitHub for efficient vulnerability management.
  • Users benefit from Snyk's intuitive GUI and customizable features, facilitating effective vulnerability management and developer organization.
Cons
  • Users experience false positives in Snyk, which can hinder efficiency and slow down the scanning process.
  • Users find the poor interface design of Snyk cumbersome, impacting their overall experience with the product.
  • Users note that pricing issues can arise, especially when accessing all features of Snyk, impacting affordability.
  • Users report experiencing false positives and slow scan times, affecting their efficiency and integration within the Snyk product.
  • Users experience false positives and slow scans, complicating overall use and requiring additional tools for code quality.

What Are Recent G2 Reviews of Snyk?

What Are G2 Users Discussing About Snyk?

Checkmarx

Checkmarx offers leading application security solutions that help organizations safeguard software development while enhancing efficiency and reducing costs. At the center is Checkmarx Fusion, the highest-fidelity scanning architecture in the industry. Most scanners force a choice: catch more, or get buried in noise and miss what matters. Fusion ends that trade-off — deterministic precision and frontier AI coverage fused into one verified result, with the Findings Analysis Engine validating and deduplicating every finding before a developer sees it. The result is an F1 score of 0.64 today by using the Checkmarx NG SAST vs. an industry average of ~0.20, and an astonishing market leading F1 score of 0.74 with Checkmarx Fusion. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as NG SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

Average Rating: 4.2/5.0

Total Reviews: 45

How Do G2 Users Rate Checkmarx?

  • Test Automation: 8.9/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 9.1/10)
  • Quality of Support: 8.4/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 6.7/10 (Category avg: 8.4/10)

Who Is the Company Behind Checkmarx?

  • Seller: Checkmarx
  • Company Website:
  • Year Founded: 2006
  • HQ Location: Paramus, NJ
  • Twitter: @Checkmarx
    7,284 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    997 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 57% Large, 22% Medium

What Do G2 Reviewers Say About Checkmarx?

AI-generated summary from verified user reviews

Pros
  • Users value the easy implementation of Checkmarx into existing repositories, enhancing their security review processes effortlessly.
  • Users praise the intuitive user interface of Checkmarx, making security reviews and integrations straightforward and user-friendly.
  • Users value the accuracy of results in Checkmarx, finding it effective for automated security reviews.
  • Users appreciate the automation testing capabilities of Checkmarx, making security reviews efficient and user-friendly.
  • Users praise the responsive customer support of Checkmarx, consistently providing help when challenges arise.
Cons
  • Users experience a significant number of false positives with Checkmarx, particularly for Kotlin projects, leading to frustration.
  • Users face challenges with limited support for Kotlin, experiencing many false positives compared to other languages like Java or Javascript.
  • Users experience missing features in Checkmarx, particularly with Kotlin support, leading to numerous false positives.
  • Users find the navigation poor in Checkmarx, citing issues with dashboard layout and display clarity.

What Are Recent G2 Reviews of Checkmarx?

What Are G2 Users Discussing About Checkmarx?

HCL AppScan

HCL AppScan is a comprehensive suite of market-leading application security testing solutions (SAST, DAST, IAST, SCA, API), available on-premises and on-cloud. These powerful DevSecOps tools pinpoint application vulnerabilities, allowing for quick remediation in every phase of the software development lifecycle. Fast and Accurate Scanning for Secure DevOps Developers and DevOps teams can quickly and accurately scan code, applications, and APIs for security vulnerabilities while applications are being developed. This allows companies to fix issues at the earliest stages of the software development lifecycle, when it is least costly to the business. Focus on the Fix Continuous monitoring with IAST, along with auto issue correlation with DAST and SAST scan results allows DevOps teams to group and prioritize findings for faster, more streamlined remediation. Enterprise Management for Security Teams Centralized, easy-to-use dashboards provide visibility and oversight of all security scanning and remediation, and allow users to set scan parameters and compliance policies.

Average Rating: 4.1/5.0

Total Reviews: 86

How Do G2 Users Rate HCL AppScan?

  • Test Automation: 8.5/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 9.1/10)
  • Quality of Support: 8.5/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.4/10 (Category avg: 8.4/10)

Who Is the Company Behind HCL AppScan?

  • Seller: HCL Technologies
  • Company Website:
  • Year Founded: 1999
  • HQ Location: Noida, Uttar Pradesh
  • Twitter: @hcltech
    425,043 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    258,955 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 53% Large, 28% Small

What Are Recent G2 Reviews of HCL AppScan?

What Are G2 Users Discussing About HCL AppScan?

Codacy

Codacy is the code quality and security platform for AI-assisted engineering teams. AI is now embedded through the engineering workflow, which has made teams faster, but also adds risk to everything they ship. Codacy helps AI-assisted teams ship high-quality, secure code across the full software development lifecycle, starting in the agent and editor, through pull requests in Git, and into containers and runtime security. At each stage we check for quality issues, security vulnerabilities and AI coding risk introduced into the codebase, and help devs and agent fix them effortlessly. A team's standards become automated guardrails that apply across every IDE, AI coding agent, and Pull Request. More than 250,000 developers rely on Codacy to keep quality and security stable as AI changes how software gets built. Add your repo and get your free scan report in minutes: https://codacy.com

Average Rating: 4.6/5.0

Total Reviews: 29

How Do G2 Users Rate Codacy?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.1/10)
  • Quality of Support: 9.1/10 (Category avg: 9.2/10)

Who Is the Company Behind Codacy?

  • Seller: Codacy
  • Year Founded: 2012
  • HQ Location: Lisbon, Lisboa
  • Twitter: @codacy
    5,002 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    62 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 59% Small, 24% Medium

What Do G2 Reviewers Say About Codacy?

AI-generated summary from verified user reviews

Pros
  • Users value the enhanced security features of Codacy, benefiting from integrated automation and insightful vulnerability management.
  • Users appreciate the integrated automation of Codacy, finding it easy to use and helpful for maintaining code quality.
  • Users find the out-of-the-box automation in Codacy to be user-friendly and effective for maintaining code quality.
  • Users value the high code quality provided by Codacy's integrated automation and effective static code analyses.
  • Users value the helpful customer support of Codacy, appreciating their immediate assistance during integration and security management.
Cons
  • Users find Codacy expensive at $19/month, which can be a barrier for smaller organizations.

What Are Recent G2 Reviews of Codacy?

DeepSource

DeepSource is an all-in-one code health platform that equips organizations with everything they need to build maintainable and secure software while elevating the velocity of their software development cycle. - Guaranteed below 5% false-positive rate with highly accurate and fast static analyzers - Automated issue remediation with Autofix™️ - Code Issue and security reporting: OWASP Top 10, SANS Top 25, Code Coverage, and more - Self-hosted option with one-click installation and upgrades

Average Rating: 4.6/5.0

Total Reviews: 22

How Do G2 Users Rate DeepSource?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.1/10)
  • Quality of Support: 9.5/10 (Category avg: 9.2/10)

Who Is the Company Behind DeepSource?

  • Seller: DeepSource
  • Year Founded: 2018
  • HQ Location: San Francisco, California
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 82% Small, 9% Large

What Are Recent G2 Reviews of DeepSource?

What Are G2 Users Discussing About DeepSource?

Mend.io

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

Average Rating: 4.3/5.0

Total Reviews: 117

How Do G2 Users Rate Mend.io?

  • Test Automation: 7.2/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.1/10)
  • Quality of Support: 8.7/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.3/10 (Category avg: 8.4/10)

Who Is the Company Behind Mend.io?

  • Seller: Mend
  • Company Website:
  • Year Founded: 2011
  • HQ Location: Boston, Massachusetts
  • Twitter: @Mend_io
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    259 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 36% Small, 33% Large

What Do G2 Reviewers Say About Mend.io?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the scanning efficiency of Mend.io, enabling quick and accurate scans across multiple repositories seamlessly.
  • Users appreciate the ease of use of Mend.io, made simpler by effective integrations and an attractive interface.
  • Users value the easy integrations of Mend.io, allowing seamless scanning across multiple repositories and CI/CD platforms.
  • Users appreciate the quick and accurate scanning capabilities of Mend.io, benefiting from a range of integrations.
  • Users value the automated vulnerability detection of Mend.io, enhancing efficiency in identifying and addressing issues seamlessly.
Cons
  • Users face integration issues with Mend.io, finding it difficult to connect on-premise tools and features like Jira.
  • Users express concern over limited features in Mend.io, necessitating workarounds for optimal functionality and integration.
  • Users find the missing features in Mend.io cumbersome, often resorting to workarounds for integration and functionality.
  • Users face complex implementation, with challenging integration and frequent false positives affecting their experience.
  • Users find the confusing interface challenging due to the awkward transitions between different portals.

What Are Recent G2 Reviews of Mend.io?

What Are G2 Users Discussing About Mend.io?

Appknox

Appknox is an on-demand mobile application security platform that helps businesses detect and fix security vulnerabilities using an Automated Security Testing suite. We have been successfully reducing delivery timelines, manpower costs & mitigating security threats for Global Banks and Enterprises in 10 + countries.

Average Rating: 4.4/5.0

Total Reviews: 41

How Do G2 Users Rate Appknox?

  • Test Automation: 8.6/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.1/10)
  • Quality of Support: 8.9/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 9.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Appknox?

  • Seller: Appknox
  • Year Founded: 2014
  • HQ Location: Singapore, Singapore
  • Twitter: @appknox
    3,055 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    84 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 41% Small, 36% Medium

What Are Recent G2 Reviews of Appknox?

What Are G2 Users Discussing About Appknox?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated