Best Static Application Security Testing (SAST) Software

How Many Static Application Security Testing (SAST) Software Products Does G2 Track?

Total Products under this Category: 117

Category Stats (Sep 2026)

  • Average Rating: 4.54/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Static Application Security Testing (SAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,500+ Authentic Reviews
  • 117+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Application Security Testing (SAST) Software

G2 Grid® for Static Application Security Testing (SAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, GitHub, GitGuardian, GitLab, SonarQube, Semgrep, Snyk, and Checkmarx.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-application-security-testing-sast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=github&focus%5B%5D=gitguardian&focus%5B%5D=gitlab&focus%5B%5D=sonarqube&focus%5B%5D=semgrep&focus%5B%5D=snyk&focus%5B%5D=checkmarx)

Aikido Security

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

Average Rating: 4.6/5.0

Total Reviews: 263

How Do G2 Users Rate Aikido Security?

  • Test Automation: 8.6/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.1/10)
  • Quality of Support: 9.3/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Aikido Security?

  • Seller: Aikido Security
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Ghent, Belgium
  • Twitter: @AikidoSecurity
    11,770 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    320 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Founder, CTO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 79% Small, 14% Medium

What Do G2 Reviewers Say About Aikido Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Aikido Security, thanks to its clear insights and seamless integration.
  • Users appreciate Aikido Security's robust security capabilities, providing a comprehensive and seamless integration in their workflow.
  • Users value the intuitive dashboard of Aikido Security, which simplifies security issue identification and management.
  • Users value the easy integrations of Aikido Security, enhancing workflows with seamless connections to existing GitLab repositories.
  • Users find Aikido's easy setup highly efficient, enabling quick implementation and immediate usability for security assessments.
Cons
  • Users note the lack of advanced features in Aikido Security, such as dark mode and in-depth analysis options.
  • Users find the pricing structure expensive for micro businesses, making upgrades difficult to justify.
  • Users note the limited features of Aikido Security, wishing for more customization and advanced options.
  • Users find the pricing issues challenging, especially for micro businesses, due to the steep upgrade costs.
  • Users feel Aikido Security is lacking features like advanced reporting and deeper compliance analysis compared to competitors.

What Are Recent G2 Reviews of Aikido Security?

GitHub

GitHub is where the world builds software. Millions of individuals, organizations and businesses around the world use GitHub to discover, share, and contribute software. Developers at startups to Fortune 50 companies use GitHub, every step of the way.

Average Rating: 4.7/5.0

Total Reviews: 2,340

How Do G2 Users Rate GitHub?

  • Test Automation: 8.5/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.1/10)
  • Quality of Support: 8.7/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.3/10 (Category avg: 8.4/10)

Who Is the Company Behind GitHub?

  • Seller: GitHub
  • Year Founded: 2008
  • HQ Location: San Francisco, CA
  • Twitter: @github
    2,673,925 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6,653 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 47% Small, 31% Medium

What Do G2 Reviewers Say About GitHub?

AI-generated summary from verified user reviews

Pros
  • Users value GitHub's seamless collaboration and powerful version control, enhancing project transparency and workflow management.
  • Users appreciate the ease of use of GitHub, enabling seamless collaboration and efficient version control.
  • Users value the seamless team collaboration on GitHub, enhancing code sharing and workflow management effectively.
  • Users value the seamless collaboration offered by GitHub, enhancing project transparency and team workflow management.
  • Users value GitHub for its seamless version control, enhancing collaboration and streamlining the development process.
Cons
  • Users find the complexity in advanced features of GitHub challenging, particularly for newcomers and managing large repositories.
  • Users find the learning curve challenging, especially when designing workflows and managing permissions effectively.
  • Users find learning GitHub challenging due to overwhelming settings and complexities, making navigation difficult for newcomers.
  • Users find the complexity for beginners challenging, especially with CI/CD workflows and permission management.
  • Users find the steep learning curve of GitHub challenging, especially in mastering workflows and managing permissions.

What Are Recent G2 Reviews of GitHub?

What Are G2 Users Discussing About GitHub?

GitGuardian

GitGuardian is an end-to-end Secrets and Non-Human Identity (NHI) Security platform designed to help organizations eliminate secrets sprawl, govern machine identities, and meet compliance requirements under PCI-DSS v4.0, DORA, NYDFS Part 500, and NIS 2. As attackers increasingly target NHIs like service accounts, service principals, AI agents, and applications, protecting the credentials they rely on has become critical. GitGuardian's platform is built on three pillars: Secrets Security, NHI Governance, and Developer Endpoint Protection. **Secrets Security** eliminates leaks across every environment. Internal Secrets Monitoring detects hardcoded credentials in source code, CI/CD pipelines, container images, and collaboration tools like Slack, Jira, and Confluence with 500+ purpose-built detectors and a false positive rate under 10%. Public Secrets Monitoring scans 1B+ public GitHub commits daily, alerting teams the moment a secret is exposed externally. Honeytokens deploy decoy credentials that trigger immediate alerts on unauthorized access attempts. **NHI Governance** provides a centralized inventory of machine identities, including those outside vaults, with ownership attribution, risk scoring, and compliance evidence to support access reviews and rotation policy configuration. **Developer Endpoint Protection** extends coverage to the credential layer that repo and CI scanning can't reach: developer laptops. GitGuardian scans project directories, .env files, cloud credential stores, AI agent configs, and shell history across the entire fleet, delivering a prioritized inventory of exposed secrets by machine and severity. Trusted by Snowflake, ING, BASF, Datadog, Webflow, Bouygues Telecom, and more, and the #1 most-installed security app on the GitHub Marketplace.

Average Rating: 4.8/5.0

Total Reviews: 282

How Do G2 Users Rate GitGuardian?

  • Test Automation: 8.4/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 9.1/10)
  • Quality of Support: 9.1/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 9.0/10 (Category avg: 8.4/10)

Who Is the Company Behind GitGuardian?

  • Seller: GitGuardian
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Paris, Île-de-France
  • Twitter: @GitGuardian
    6,055 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    208 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Software Developer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 85% Small, 12% Medium

What Do G2 Reviewers Say About GitGuardian?

AI-generated summary from verified user reviews

Pros
  • Users value the real-time alert notifications from GitGuardian, ensuring quick detection of key leaks and issues.
  • Users value the automated security features of GitGuardian, ensuring quick detection of secrets throughout the development process.
  • Users love the automated vulnerability detection of GitGuardian, ensuring fast and efficient secret management after code pushes.
  • Users value the accuracy of GitGuardian, noting its swift detection of issues with precise actionable feedback.
  • Users value the immediate detection speed of GitGuardian, ensuring quick resolutions and minimal workflow interruptions.
Cons
  • Users face challenges with false positives, requiring time to adjust settings and improve user experience.
  • Users find the inefficient notifications overwhelming, leading to increased review time and a cluttered interface when managing alerts.
  • Users find limited customization in GitGuardian, hindering the adjustment of alerts and specific security policies.
  • Users find the confusing interface of GitGuardian complicates navigation and slows down incident resolution despite helpful alerting.
  • Users report feeling overwhelmed by the excessive notifications from GitGuardian, complicating workflow and alert management.

What Are Recent G2 Reviews of GitGuardian?

What Are G2 Users Discussing About GitGuardian?

GitLab

GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab, teams can create, deliver, and manage code quickly and continuously instead of managing disparate tools and scripts. GitLab helps your teams across the complete DevSecOps lifecycle, from developing, securing, and deploying software. What makes us truly different? - Flexibility: Consume as a service or manage your own deployment - Cloud-Agnostic: Deploy anywhere with no vendor lock-in - No rip and replace: Scale to a platform approach at your own pace

Average Rating: 4.5/5.0

Total Reviews: 885

How Do G2 Users Rate GitLab?

  • Test Automation: 9.2/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.8/10 (Category avg: 9.1/10)
  • Quality of Support: 8.5/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.9/10 (Category avg: 8.4/10)

Who Is the Company Behind GitLab?

  • Seller: GitLab Inc.
  • Year Founded: 2014
  • HQ Location: San Francisco, California
  • Twitter: @gitlab
    171,534 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,431 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 37% Medium, 37% Small

What Do G2 Reviewers Say About GitLab?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use in GitLab, enjoying its all-in-one DevOps capabilities and intuitive interface.
  • Users value the all-encompassing features of GitLab, which enhance collaboration and streamline the DevOps workflow.
  • Users love the seamless CI/CD integration of GitLab, simplifying automation and collaboration in DevOps workflows.
  • Users value the seamless integrations in GitLab, resulting in efficient workflows and streamlined management across multiple functions.
  • Users praise the seamless CI/CD integration in GitLab, enhancing automation and collaboration within their DevOps workflow.
Cons
  • Users find the complexity of GitLab's setup and management to be a significant barrier to efficient use.
  • Users find the difficult learning curve of GitLab challenging due to its complex interface and YAML syntax.
  • Users find the interface confusing due to clutter and slow performance with large repositories, complicating their navigation.
  • Users find the complex user interface challenging, especially with slow performance and difficulties in navigation and management.
  • Users find the learning curve steep, particularly for those new to DevOps and managing extensive features.

What Are Recent G2 Reviews of GitLab?

What Are G2 Users Discussing About GitLab?

SonarQube

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

Average Rating: 4.4/5.0

Total Reviews: 152

How Do G2 Users Rate SonarQube?

  • Test Automation: 6.4/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.1/10)
  • Quality of Support: 8.1/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 6.8/10 (Category avg: 8.4/10)

Who Is the Company Behind SonarQube?

  • Seller: SonarSource Sàrl
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Geneva, Switzerland
  • Twitter: @SonarSource
    10,913 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    973 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, DevOps Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 42% Large, 40% Medium

What Do G2 Reviewers Say About SonarQube?

AI-generated summary from verified user reviews

Pros
  • Users value SonarQube for its ability to quickly flag code quality and security issues, ensuring a reliable codebase.
  • Users value the flexible issue filtering and prioritization features of SonarQube, enhancing team productivity and focus.
  • Users appreciate how SonarQube quickly flags code quality and security issues, ensuring a clean and reliable codebase.
  • Users appreciate the ease of use of SonarQube, finding integration and actionable feedback simple and effective.
  • Users appreciate the easy integrations with CI/CD tools, enhancing their workflow and improving code quality effectively.
Cons
  • Users face software bugs that lead to false positives, complicating the experience and requiring significant knowledge to manage.
  • Users find the complex configuration of SonarQube challenging, especially for beginners needing extensive knowledge.
  • Users encounter false positives that complicate usage, despite helpful tools for review and customization of analysis.
  • Users find SonarQube's complexity in configuration and excessive warnings can make it cumbersome to use.
  • Users find the complex setup of SonarQube time-consuming, requiring significant effort to configure and tune effectively.

What Are Recent G2 Reviews of SonarQube?

What Are G2 Users Discussing About SonarQube?

Snyk

Snyk (pronounced sneak) is a developer security platform for securing custom code, open source dependencies, containers, and cloud infrastructure all from a single platform. Snyk’s developer security solutions enable modern applications to be built securely, empowering developers to own and build security for the whole application, from code & open source to containers & cloud infrastructure. Secure while you code in your IDE: find issues quickly using the scanner, fix issues easily with remediation advice, verify the updated code. Integrate your source code repositories to secure applications: integrate a repository to find issues, prioritize with context, fix & merge. Secure your containers as you build, throughout the SDLC: start fixing containers as soon as your write a Dockerfile, continuously monitor container images throughout their lifecycle, and prioritize with context. Secure build and deployment pipelines: Integrate natively with your CI/CD tool, configure your rules, find & fix issues in your application, and monitor your applications. Secure your apps quickly with Snyk’s vulnerability scanning and automated fixes - Try for Free!

Average Rating: 4.5/5.0

Total Reviews: 136

How Do G2 Users Rate Snyk?

  • Test Automation: 7.8/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.7/10 (Category avg: 9.1/10)
  • Quality of Support: 8.6/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 6.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Snyk?

  • Seller: Snyk
  • HQ Location: Boston, Massachusetts
  • Twitter: @snyksec
    21,057 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,764 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 45% Medium, 35% Small

What Do G2 Reviewers Say About Snyk?

AI-generated summary from verified user reviews

Pros
  • Users value Snyk's quick vulnerability detection, significantly improving efficiency in code security and remediation processes.
  • Users appreciate Snyk for its efficient vulnerability identification, significantly aiding in maintaining secure code and streamlining DevOps processes.
  • Users value the easy integration setup of Snyk, enhancing vulnerability detection in their development workflows.
  • Users appreciate the easy setup of Snyk, seamlessly integrating with GitHub for efficient vulnerability management.
  • Users benefit from Snyk's intuitive GUI and customizable features, facilitating effective vulnerability management and developer organization.
Cons
  • Users experience false positives in Snyk, which can hinder efficiency and slow down the scanning process.
  • Users find the poor interface design of Snyk cumbersome, impacting their overall experience with the product.
  • Users note that pricing issues can arise, especially when accessing all features of Snyk, impacting affordability.
  • Users report experiencing false positives and slow scan times, affecting their efficiency and integration within the Snyk product.
  • Users experience false positives and slow scans, complicating overall use and requiring additional tools for code quality.

What Are Recent G2 Reviews of Snyk?

What Are G2 Users Discussing About Snyk?

Semgrep

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

Average Rating: 4.6/5.0

Total Reviews: 56

How Do G2 Users Rate Semgrep?

  • Test Automation: 9.2/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.1/10)
  • Quality of Support: 8.8/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 7.5/10 (Category avg: 8.4/10)

Who Is the Company Behind Semgrep?

  • Seller: Semgrep
  • Year Founded: 2017
  • HQ Location: San Francisco, US
  • Twitter: @semgrep
    4,433 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    268 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 45% Large, 43% Medium

What Do G2 Reviewers Say About Semgrep?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Semgrep, enabled by its intuitive syntax and smooth integration with CI/CD.
  • Users appreciate the flexibility and speed of Semgrep in enforcing coding standards and catching vulnerabilities effectively.
  • Users appreciate the effective vulnerability detection of Semgrep, facilitating quick identification and resolution of security issues.
  • Users appreciate the scanning efficiency of Semgrep, benefiting from rapid scans and streamlined CI/CD integration.
  • Users value Semgrep for its effective security vulnerability detection, enabling quick resolutions without hindering development speed.
Cons
  • Users find Semgrep not user-friendly due to a steep learning curve and complex initial setup requirements.
  • Users find the limited features of Semgrep restrict its usability and complicate effective vulnerability management.
  • Users find the difficult learning curve for Semgrep daunting, especially for creating advanced rules and setups.
  • Users express concerns about the lack of guidance in creating custom rules, complicating effective use of Semgrep.
  • Users note a steep learning curve for Semgrep's rule syntax, making it challenging for newcomers to master.

What Are Recent G2 Reviews of Semgrep?

Checkmarx

Checkmarx offers leading application security solutions that help organizations safeguard software development while enhancing efficiency and reducing costs. At the center is Checkmarx Fusion, the highest-fidelity scanning architecture in the industry. Most scanners force a choice: catch more, or get buried in noise and miss what matters. Fusion ends that trade-off — deterministic precision and frontier AI coverage fused into one verified result, with the Findings Analysis Engine validating and deduplicating every finding before a developer sees it. The result is an F1 score of 0.64 today by using the Checkmarx NG SAST vs. an industry average of ~0.20, and an astonishing market leading F1 score of 0.74 with Checkmarx Fusion. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as NG SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

Average Rating: 4.2/5.0

Total Reviews: 45

How Do G2 Users Rate Checkmarx?

  • Test Automation: 8.9/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 9.1/10)
  • Quality of Support: 8.4/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 6.7/10 (Category avg: 8.4/10)

Who Is the Company Behind Checkmarx?

  • Seller: Checkmarx
  • Company Website:
  • Year Founded: 2006
  • HQ Location: Paramus, NJ
  • Twitter: @Checkmarx
    7,284 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    997 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 57% Large, 22% Medium

What Do G2 Reviewers Say About Checkmarx?

AI-generated summary from verified user reviews

Pros
  • Users value the easy implementation of Checkmarx into existing repositories, enhancing their security review processes effortlessly.
  • Users praise the intuitive user interface of Checkmarx, making security reviews and integrations straightforward and user-friendly.
  • Users value the accuracy of results in Checkmarx, finding it effective for automated security reviews.
  • Users appreciate the automation testing capabilities of Checkmarx, making security reviews efficient and user-friendly.
  • Users praise the responsive customer support of Checkmarx, consistently providing help when challenges arise.
Cons
  • Users experience a significant number of false positives with Checkmarx, particularly for Kotlin projects, leading to frustration.
  • Users face challenges with limited support for Kotlin, experiencing many false positives compared to other languages like Java or Javascript.
  • Users experience missing features in Checkmarx, particularly with Kotlin support, leading to numerous false positives.
  • Users find the navigation poor in Checkmarx, citing issues with dashboard layout and display clarity.

What Are Recent G2 Reviews of Checkmarx?

What Are G2 Users Discussing About Checkmarx?

OX Security

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

Average Rating: 4.8/5.0

Total Reviews: 51

How Do G2 Users Rate OX Security?

  • Test Automation: 7.3/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.1/10)
  • Quality of Support: 9.6/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 7.7/10 (Category avg: 8.4/10)

Who Is the Company Behind OX Security?

Who Uses This Product?

  • Who Uses This: Security Engineer
  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 63% Medium, 25% Large

What Do G2 Reviewers Say About OX Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the intuitive dashboard of OX Security, enhancing issue management and streamlining security processes effectively.
  • Users find OX Security highly user-friendly, benefiting from an intuitive dashboard and responsive support for seamless operations.
  • Users value the responsive and professional customer support of OX Security, enhancing their overall experience and efficiency.
  • Users value the seamless integration support from OX Security, enhancing their workflow with fast and user-friendly solutions.
  • Users appreciate the comprehensive security capabilities of OX Security, ensuring a streamlined and effective security management experience.
Cons
  • Users report integration issues with OX Security's limited documentation and insufficient support for various tools.
  • Users note some missing features in OX Security, which can affect its overall usability and integration capabilities.
  • Users find the complexity of OX Security daunting, with inadequate documentation and a steep learning curve for new users.
  • Users find OX Security's inadequate reporting limits their ability to effectively showcase security progress to management.
  • Users find the limited cloud integration with certain tools frustrating, impacting overall connectivity and functionality.

What Are Recent G2 Reviews of OX Security?

OpenText Static Application Security Testing

OpenText™ Static Application Security Testing (SAST) is a comprehensive solution designed to identify and remediate security vulnerabilities within an application's source code during the early stages of development. By analyzing code from the "inside out," SAST provides immediate feedback to developers, enabling them to address security issues promptly and effectively. Key Features and Functionality: - Extensive Language Support: Supports over 33 programming languages and more than 1,400 vulnerability categories, ensuring broad applicability across various development environments. - Integration with Development Tools: Seamlessly integrates with popular Integrated Development Environments (IDEs) such as Eclipse, Visual Studio, and JetBrains, as well as Continuous Integration/Continuous Deployment (CI/CD) tools like Jenkins and Bamboo, facilitating a smooth incorporation into existing workflows. - Scalable Deployment Options: Offers flexible deployment models, including on-premises, cloud-based, and Software as a Service (SaaS) solutions, allowing organizations to choose the setup that best fits their needs. - Advanced Analysis Capabilities: Utilizes multiple algorithms and an expansive knowledge base of secure coding rules to perform thorough code analysis, pinpointing the root causes of vulnerabilities and providing detailed remediation guidance. Primary Value and Problem Solved: OpenText SAST empowers organizations to proactively manage application security by detecting and addressing vulnerabilities early in the Software Development Life Cycle (SDLC). This proactive approach reduces the risk of security breaches, minimizes the cost and effort associated with late-stage remediation, and enhances the overall security posture of applications. By integrating security testing into the development process, OpenText SAST helps developers create more secure code, leading to robust and reliable software products.

Average Rating: 4.5/5.0

Total Reviews: 21

How Do G2 Users Rate OpenText Static Application Security Testing?

  • Test Automation: 8.7/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 9.1/10)
  • Quality of Support: 8.7/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 7.0/10 (Category avg: 8.4/10)

Who Is the Company Behind OpenText Static Application Security Testing?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Who Uses This Product?

  • Top Industries: Banking, Financial Services
  • Company Size: 50% Large, 29% Small

What Do G2 Reviewers Say About OpenText Static Application Security Testing?

AI-generated summary from verified user reviews

Pros
  • Users value the easy integrations of OpenText Static Application Security Testing, enhancing their workflow with multiple tools.
  • Users value the extensive integration capabilities of OpenText Static Application Security Testing with various third-party tools.
  • Users value the extensive integration support for various technologies and third-party tools offered by OpenText Static Application Security Testing.
Cons
  • Users are disappointed by the false positives, but appreciate the ability to ignore issues in future scans.

What Are Recent G2 Reviews of OpenText Static Application Security Testing?

What Are G2 Users Discussing About OpenText Static Application Security Testing?

DryRun Security

Security leaders face a paradox: ship faster and enable agentic development while staying secure and keeping developers productive. DryRun Security resolves this by securing every pull request and repo with a high-precision, automated security engineer review right where developers and their agents build. DryRun Security is the industry’s most accurate agentic code security intelligence platform. Powered by its proprietary Contextual Security Analysis (CSA) engine, DryRun Security delivers the AI moment for security teams in an AI-native developer world. Traditional static application security testing (SAST) floods teams with alerts, misses higher-order risk, and burns time in triage. DryRun Security goes beyond SAST with contextual analysis that prioritizes what is exploitable and impactful in your codebase, then helps engineers remediate fast. Instead of “find everything and hope someone sorts it out,” DryRun Security delivers code security intelligence that is ready to act on. DryRun Security puts a security engineer directly into developer workflows. In pull requests, the Code Review Agent reviews changes in context, explains risk in plain language, and guides fixes where developers already work. In repos, the DeepScan Agent produces focused, human-grade findings for the issues that actually matter, without weeks of manual review before major milestones. The Custom Policy Agent enforces guardrails with Natural Language Code Policies, so you can standardize security and compliance requirements across teams without brittle rule sets. Codebase Insights allows leaders to ask questions of their entire codebase like "Are we exposed to this new vulnerability" and have confidence in minutes. DryRun Security also integrates with AI coding workflows, so remediation happens with the precision of a security engineer working at machine speed. Teams connect DryRun Security insights and guidance into Claude, Cursor, OpenAI Codex, and Windsurf, helping developers and their agents fix issues with contextual, security-engineered direction tied to the PR and codebase. What DryRun Security delivers (beyond SAST) • Automated secure code review in every pull request with high-signal findings and low noise • Contextual Security Analysis that catches common vulnerabilities and deeper multi-dependency and logic risks • Automated remediation guidance that helps engineers fix faster, with explanations and next steps • Secrets analysis identifies genuine hardcoded secrets and suppresses the usual false alarms • Policy enforcement in PRs using Natural Language Code Policies for consistent guardrails across repos • Codebase intelligence and reporting for AppSec visibility, prioritization, and audit-ready evidence DryRun Security supports most code environments, languages, and frameworks, including: • GitHub, GitLab • C#, Golang, Elixir, JavaScript, TypeScript, Python, Ruby, Java, Kotlin, PHP, Swift, HTML • Infrastructure as Code (Terraform, YAML) • And more

Average Rating: 4.9/5.0

Total Reviews: 20

How Do G2 Users Rate DryRun Security?

  • Test Automation: 10.0/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.1/10)
  • Quality of Support: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind DryRun Security?

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 40% Small, 30% Medium

What Do G2 Reviewers Say About DryRun Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the context-aware security feedback from DryRun Security, enabling efficient vulnerability mitigation in real-time.
  • Users appreciate the quick and context-aware vulnerability detection of DryRun Security, enhancing code security during development.
  • Users commend DryRun Security for its seamless integration and effective detections, enhancing code security and development efficiency.
  • Users appreciate the accuracy of DryRun Security, effectively identifying vulnerabilities in AI-generated code and traditional applications.
  • Users commend the easy setup of DryRun Security, providing seamless integration and efficient workflow for code scanning.
Cons
  • Users experience slow performance in the management portal, affecting usability and efficiency with linked repositories.
  • Users find the slow speed of the management portal frustrating, though improvements to the UI have been noted.
  • Users note a need for improved UX investment in DryRun Security to enhance the developer experience and engagement.
  • Users desire more customization options for tuning analyzers, indicating limited flexibility in current features.
  • Users feel that greater focus on workflow issues could enhance DryRun Security's adoption among developers.

What Are Recent G2 Reviews of DryRun Security?

Black Duck Polaris Platform

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it, development and DevSecOps teams to automate testing within development pipelines without compromising velocity, and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Average Rating: 4.2/5.0

Total Reviews: 103

How Do G2 Users Rate Black Duck Polaris Platform?

  • Test Automation: 8.1/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.4/10 (Category avg: 9.1/10)
  • Quality of Support: 8.5/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.6/10 (Category avg: 8.4/10)

Who Is the Company Behind Black Duck Polaris Platform?

  • Seller: Black Duck
  • Year Founded: 2024
  • HQ Location: Burlington, US
  • LinkedIn® Page: www.linkedin.com
    1,317 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 53% Large, 32% Medium

What Do G2 Reviewers Say About Black Duck Polaris Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the accuracy of findings from Black Duck SCA, highlighting its powerful engine and extensive knowledge base.
  • Users value the powerful identification of open source issues by Black Duck SCA, aided by extensive knowledge resources.
Cons
  • Users find that Black Duck SCA requires huge resources to deploy on-prem, which can be a significant drawback.

What Are Recent G2 Reviews of Black Duck Polaris Platform?

What Are G2 Users Discussing About Black Duck Polaris Platform?

Kiuwan Code Security & Insights

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

Average Rating: 4.5/5.0

Total Reviews: 29

How Do G2 Users Rate Kiuwan Code Security & Insights?

  • Test Automation: 9.4/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.1/10)
  • Quality of Support: 8.9/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.3/10 (Category avg: 8.4/10)

Who Is the Company Behind Kiuwan Code Security & Insights?

  • Seller: Sembi
  • Company Website:
  • Year Founded: 2023
  • HQ Location: Austin, US
  • LinkedIn® Page: www.linkedin.com
    114 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Banking
  • Company Size: 41% Large, 35% Medium

What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the accuracy of the results from Kiuwan Code Security & Insights, enhancing their overall experience.
  • Users value the accuracy of findings from Kiuwan, enhancing their satisfaction with code security and reporting.
  • Users commend the efficient customer support of Kiuwan, ensuring timely assistance and strong satisfaction overall.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, making it very easy to navigate.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, enhancing ease of use for dashboards.

What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

Jit

Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empowers organizations to proactively manage security risks across the entire software development lifecycle.​ AI-Powered Agents Jit's AI Agents, such as SERA (Security Evaluation and Remediation Agent) and COTA (Communication, Ops, and Ticketing Agent), collaborate with your teams to automate vulnerability triage, risk assessment, and remediation processes, significantly reducing manual workloads. ​ Comprehensive Security Scanning Achieve full-stack security coverage with integrated scanners for SAST, DAST, SCA, IaC, CSPM, and more. Jit's platform ensures continuous monitoring and immediate feedback on code changes, facilitating rapid identification and resolution of security issues. ​ Developer-Centric Experience With integrations into popular IDEs and CI/CD pipelines, Jit provides developers with contextual security insights directly within their workflows, promoting a shift-left approach without disrupting productivity. ​ Agentic AI for AppSec Teams Risk-Based Prioritization Utilizing the Model Context Protocol (MCP), Jit evaluates vulnerabilities in the context of runtime environments, business impact, and compliance requirements, enabling teams to focus on the most critical risks. ​ Seamless Integrations Jit integrates with a wide array of tools, including GitHub, GitLab, AWS, Azure, GCP, Jira, Slack, and more, ensuring that security processes are embedded within your existing technology stack. ​

Average Rating: 4.5/5.0

Total Reviews: 43

How Do G2 Users Rate Jit?

  • Test Automation: 8.7/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.1/10)
  • Quality of Support: 9.3/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.2/10 (Category avg: 8.4/10)

Who Is the Company Behind Jit?

  • Seller: jit
  • Year Founded: 2021
  • HQ Location: Boston, MA
  • Twitter: @jit_io
    522 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    161 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Financial Services
  • Company Size: 44% Medium, 42% Small

What Do G2 Reviewers Say About Jit?

AI-generated summary from verified user reviews

Pros
  • Users value the seamless integration of security in Jit, enhancing efficiency without overwhelming the development process.
  • Users value the easy integrations of Jit, streamlining security into development without overwhelming workflows.
  • Users appreciate the ease of use of Jit, as it simplifies integration and enhances productivity without added complexity.
  • Users value the efficiency of Jit, noting significant waste reduction and streamlined processes that enhance overall productivity.
  • Users praise the easy integration support of Jit, streamlining security practices in the development workflow.
Cons
  • Users note integration issues, as Jit may not support all enterprise environments and requires extra manual setup.
  • Users find the product has limited features, especially in customization and advanced analytics for complex environments.
  • Users express concerns about limited integration with enterprise environments and third-party tools, hindering overall usability.
  • Users find the documentation lacking for advanced configurations, making it difficult to fully utilize Jit.
  • Users find the complexity of Jit's advanced integrations and features overwhelming for beginners and experienced developers alike.

What Are Recent G2 Reviews of Jit?

Invicti

Invicti (formerly known as Netsparker) is an enterprise application and API security testing platform that helps organizations secure thousands of web applications and APIs at scale while dramatically reducing the risk of attack. Combining advanced DAST and IAST capabilities in a single platform, Invicti enables security teams to continuously identify, prioritize, and remediate vulnerabilities across complex modern environments with confidence and automation. With Invicti, security teams can: - Automate application security testing workflows and save hundreds of hours every month - Discover and secure all web applications and APIs, including forgotten, unmanaged, and shadow assets - Deliver actionable, developer-friendly feedback that helps teams remediate vulnerabilities faster and build more secure code over time - Reduce false positives with proof-based scanning technology that validates exploitable vulnerabilities - Scale application security programs across large enterprises without slowing development teams - Integrate security seamlessly into existing DevSecOps and CI/CD workflows Built for organizations with the most demanding security requirements, Invicti empowers teams to confidently secure their entire attack surface with accuracy, scalability, and automation.

Average Rating: 4.5/5.0

Total Reviews: 69

How Do G2 Users Rate Invicti?

  • Test Automation: 10.0/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.1/10)
  • Quality of Support: 8.9/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 10.0/10 (Category avg: 8.4/10)

Who Is the Company Behind Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    326 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 46% Large, 29% Medium

What Do G2 Reviewers Say About Invicti?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Invicti, facilitating quick setup and effective vulnerability scanning in their workflow.
  • Users value the quick and easy scanning technology of Invicti, enhancing workflow efficiency and accuracy in vulnerability detection.
  • Users value the simplicity and integration of Invicti, enhancing security measures through user-friendly report generation and detailed views.
  • Users value the easy-to-read and well-formatted reports from Invicti, enhancing efficiency and supporting ISO certification needs.
  • Users value the high accuracy and ease of use in Invicti's vulnerability detection, effectively identifying true issues.
Cons
  • Users find the customer support lacking, often experiencing slow responses and inadequate technical assistance.
  • Users experience slow performance during scans and setups, impacting overall efficiency and satisfaction.
  • Users experience slow scanning issues with Invicti, often leading to frustrating delays during the scanning process.
  • Users face API scanning issues with Invicti, limiting its effectiveness for their specific needs despite decent support.
  • Users find the complex setup of Invicti challenging initially, hindering their ability to quickly navigate configurations.

What Are Recent G2 Reviews of Invicti?

What Are G2 Users Discussing About Invicti?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024