Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Claimed
Claimed

Top Rated DerScanner Alternatives

DerScanner Reviews & Product Details

DerScanner Overview

What is DerScanner?

DerScanner is a complete application security testing solution to eliminate known and unknown code threats across Software Development Lifecycle. DerScanner static code analysis offers developers the support for 43 programming languages ensuring thorough security coverage for almost any application. DerScanner's SAST uniquely analyzes both source and binary files, revealing hidden vulnerabilities that are often missed in standard scans. This is especially crucial for legacy applications or when source code access is limited. DerScanner’s DAST feature mimics an external attacker, similar to penetration testing. This is vital for finding vulnerabilities that only appear when the application is operational. DAST in DerScanner enriches SAST findings by cross-checking and correlating vulnerabilities detected by both methods. With DerScanner Software Composition Analysis you can gain critical insights into open-source components and dependencies in your projects. It helps identify vulnerabilities early and ensures compliance with licensing terms, reducing legal risks. DerScanner's Supply Chain Security continuously monitors public repositories, evaluating the security posture of each package. This allows you to make informed decisions about using open-source components in your applications.

DerScanner Details
Languages Supported
English
Show LessShow More
Product Description

DerScanner is a comprehensive application security tool. Its capabilities make it possible to effectively identify vulnerabilities and backdoors using various analysis methods (SAST, DAST, SCA) and integrate with other tools for embedding in SSDLC. DerScanner supports static analysis that can check apps written in 36 programing languages. One of the distinctive features of the DerScanner SAST module is the ability to perform static analysis not only of the source code, but also of executable files (binary code). In addition to the static analysis module, DerScanner includes a dynamic analysis module that can analyze web applications for vulnerabilities by simulating malicious external attacks and exploiting common vulnerabilities. The DerScanner solution also provides correlation of static and dynamic analysis results, so that the vulnerabilities, found using the static method, can be dynamically validated. Therefore, correlation of the results obtained during the SAST and DAST analysis is one of the key advantages of using this solution.


Seller Details
Seller
DerSecur
Year Founded
2019
HQ Location
Dubai, United Arab Emirates
LinkedIn® Page
www.linkedin.com
1 employees on LinkedIn®

Andy D.
AD
Overview Provided by:

Recent DerScanner Reviews

Timothy S.
TS
Timothy S.Small-Business (50 or fewer emp.)
5.0 out of 5
"Setting a Baseline for Identifying True Threats"
One common challenge with SAST solutions is the overwhelming number of issues they detect, making it difficult to distinguish crucial problems from...
Yury S.
YS
Yury S.Mid-Market (51-1000 emp.)
5.0 out of 5
"Great resource that helps my platform stay up to date with needed security measures"
DerScanner allows us to improve the collaboration between our application security and development teams. By using this platform, we can include se...
JC
Jason C.Small-Business (50 or fewer emp.)
5.0 out of 5
"Making hidden issues visible - real eyes opener"
When we first got our hands on DerScanner for our company's financial application, we were in for quite a journey. The initial phase was a deep div...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

DerScanner Media

DerScanner Demo - Main Dashboard
SAST, DAST, SCA
DerScanner Demo - Projects Dashboard
Manage your projects
DerScanner Demo - Scan Result
See details
Answer a few questions to help the DerScanner community
Have you used DerScanner before?
Yes

12 DerScanner Reviews

5.0 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
12 DerScanner Reviews
5.0 out of 5
12 DerScanner Reviews
5.0 out of 5

DerScanner Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons
G2 reviews are authentic and verified.
JC
Marketing Manager
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about DerScanner?

When we first got our hands on DerScanner for our company's financial application, we were in for quite a journey. The initial phase was a deep dive into the source code, a daunting 30,000 lines that seemed like a mountain to climb. Surprisingly, DerScanner made quick work of it, detecting only a handful of vulnerabilities. Review collected by and hosted on G2.com.

What do you dislike about DerScanner?

Actually we considered a cloud version at first. However after a discussion with DerScanner team we were recommended to stick with on-prem implementation. Review collected by and hosted on G2.com.

What problems is DerScanner solving and how is that benefiting you?

When DerScanner analyzed the compiled executable files, it was like peeling back layers of an onion. The analysis revealed a staggering 500,000 lines of code, uncovering a myriad of vulnerabilities, several hundred to be precise. It turned out that most of our app was stitched together with third-party components — a patchwork of freeware, internet-sourced codes, modules, and libraries, all used to cut down on development time.

This was something we didn't expect to see. DerScanner didn't just scan our application; it uncovered a hidden world within our code, highlighting the risks we didn't even know were there. This level of thoroughness and the insights it provided have been invaluable to our team. Review collected by and hosted on G2.com.

Timothy  R.
TR
Manager
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about DerScanner?

Our primary need was to scan the source code and executables of an in-house Pascal application that requires regular maintenance. We were particularly concerned about potential vulnerabilities, as the system is outdated, poorly documented, and has undergone heavy modifications over the years. DerScanner, with its proficiency in handling legacy systems, stood out in our search. It efficiently scans both source files and executables, providing clear instructions on mitigating risks specific to our situation. Additionally, we were pleased with its on-premise deployment option, which allows for local scanning without the need to upload code to the cloud. Review collected by and hosted on G2.com.

What do you dislike about DerScanner?

So far, our experience with DerScanner has been entirely positive. Review collected by and hosted on G2.com.

What problems is DerScanner solving and how is that benefiting you?

DerScanner plays a crucial role in our security strategy for the Pascal application. We regularly analyze the security of both the code and executables to identify vulnerabilities. Upon detection, we swiftly reconfigure our WAF and instruct developers to correct the code, thereby eliminating vulnerabilities and undocumented features. This proactive approach minimizes incidents related to application code vulnerabilities. Review collected by and hosted on G2.com.

William D.
WD
CEO
Individual & Family Services
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about DerScanner?

Security is a big deal when I'm developing mobile apps. The stakes are high and the risks are unique. When it shifts to mobile apps, DerScanner really shows its strength. It has a special focus on mobile Application Security Testing, which means it looks at security with the particular characteristics of mobile platforms like Android or iOS in mind. This matters a lot because making apps for phones and tablets comes with its own set of security challenges.

Another technology in DerScanner like IAST catches problems that other types of security testing might miss. For example, a typical external scanner might not notice an issue that doesn’t affect how the app looks or functions on the surface. But with IAST, DerScanner can detect issues deep within the internal data processes of the app, like when something’s wrong in the logs. Review collected by and hosted on G2.com.

What do you dislike about DerScanner?

Adding Huawei app gallery support would be a great benefit for us. Review collected by and hosted on G2.com.

What problems is DerScanner solving and how is that benefiting you?

As for the problems DerScanner is solving for me, they're pretty critical. When building mobile apps, you have to get them to market quickly, but you can’t afford to cut corners on security. DerScanner helps me spot security risks early on. Finding a security flaw late in the game, like during production or after the app has gone live, can be a disaster. It’s expensive to fix, and it can hurt my reputation. So, DerScanner's early warnings are a big help. Review collected by and hosted on G2.com.

Timothy S.
TS
Marketing Manager
Restaurants
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about DerScanner?

One common challenge with SAST solutions is the overwhelming number of issues they detect, making it difficult to distinguish crucial problems from less significant ones. This is often referred to as the problem of false positives. DerScanner addresses this effectively with its threshold capability, allowing users to set a criticality baseline. This feature enables us to focus on the most important code flaws, thereby understanding our true positive vulnerabilities more clearly. Review collected by and hosted on G2.com.

What do you dislike about DerScanner?

Looking ahead, an ideal enhancement would be an AI-driven assistant to aid in prioritizing findings more intelligently. While DerScanner is effective in its current form, this addition could further streamline the vulnerability management process. Review collected by and hosted on G2.com.

What problems is DerScanner solving and how is that benefiting you?

Our primary objective in choosing DerScanner, after evaluating several other static scanners, was to reduce both false positives and false negatives, particularly in terms of vulnerabilities and undocumented features. DerScanner demonstrates a clear advantage in this area, enhancing our ability to identify and address genuine security concerns more effectively. Review collected by and hosted on G2.com.

Yury S.
YS
Senior Consultant - Human Capital Practice
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about DerScanner?

DerScanner allows us to improve the collaboration between our application security and development teams. By using this platform, we can include security measures at early stage in the development process. This makes it easier for developers to integrate security practices while they are coding, avoiding the need to go back and fix things later on, which can save time and reduce frustration.

Regarding collaboration with DerScanner I would mention the quality of customer service: DerScanner has genuinely changed the way I view security scanning tools. In an era where automated responses are the norm, it’s refreshing to have real people on the other end of the line, ready to help. You can tell that the team behind DerScanner values their clients and strives to provide a customer service experience that stands out from the crowd. Review collected by and hosted on G2.com.

What do you dislike about DerScanner?

Some of our developers at first found it difficult to adapt to the new workflow. However, over time and with adequate training and support, this challenge has been resolved. Review collected by and hosted on G2.com.

What problems is DerScanner solving and how is that benefiting you?

DerScanner tackles a crucial problem in software development and security: the lack of coordination between AppSec and development teams. By integrating security from the start, it ensures safer final products and a smoother development process. Early identification of security issues means developers can stay creative, and AppSec knows security is a priority throughout. This results in better products, happier teams, and overall business success Review collected by and hosted on G2.com.

Charles Y.
CY
Owner
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about DerScanner?

Here is the thing, every single vendor is now a SaaS company. Everyone is rushing to the public cloud and it can be challenging for companies looking for privacy and confidentiality to get an on-premises deployment. At this stage of our business we don't feel comfortable with a 100% SaaS installation. That's why Derscanner has become a fit to offer a private cloud package for us. Review collected by and hosted on G2.com.

What do you dislike about DerScanner?

DAST can be a bit tricky to configure at that first time. It's not like a drag and drop experience. But after some training we're good to go. Review collected by and hosted on G2.com.

What problems is DerScanner solving and how is that benefiting you?

When it comes to relying on SaaS and cloud applications, updating software can become a cumbersome process that involves tweaking network policies. This is something we simply cannot afford to do due to our stringent security policies. While having an on-premise installation can allow us to get updates with no Internet access at all. The process is seamless: download the update, run a manual script, and you’re up to date. This not only adheres to our strict security protocols but also ensures that our systems are always running the latest and greatest. As for the capabilities of the scanner, we are satisfied in general. It offers a traditional bundle for static analysis and throws in open-source security for good measure, striking just the right balance for our needs. Review collected by and hosted on G2.com.

April  C.
AC
Project Manager
Manufacturing
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about DerScanner?

DerScanner has been instrumental in helping us track down and fix vulnerabilities across our platform. Its ability to quickly pinpoint issues and provide detailed guidance on how to secure our applications has been a game changer. The tool is incredibly user-friendly. Even if you’re not a hardcore developer, you can get the hang of it pretty quickly and start making your applications safer. This was a big win for us, considering the pace at which we operate and the majority of security folks in our team. Review collected by and hosted on G2.com.

What do you dislike about DerScanner?

To be completely honest, DerScanner has fit so well into our workflow and has proven so useful that I'm hard-pressed to find something I don't like about it. Maybe as we continue to use it more extensively, we might come across areas that could be improved. Review collected by and hosted on G2.com.

What problems is DerScanner solving and how is that benefiting you?

DerScanner’s speed and efficiency, along with its low rate of false positives, mean that our security checks don’t slow us down. This was a crucial factor in our decision to go with DerScanner. In our fast-paced environment, we need to be able to roll out new features quickly without compromising on security. DerScanner enables us to do just that, ensuring that our speedy development process doesn’t leave vulnerabilities in there. Review collected by and hosted on G2.com.

Martha F.
MF
Front End Developer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about DerScanner?

Honestly, I never thought I'd find something as comprehensive as DerScanner. It does static, dynamic, and open source analysis all in one place. For someone like me working at a training company, where we are constantly developing new training software, this is a game changer.

And whenever I got stuck, the support team was there, ready to help. Review collected by and hosted on G2.com.

What do you dislike about DerScanner?

When I first started using it, the amount of information it gave me was a lot to take in. It took a bit to figure out what’s what and not get lost in all the details. Review collected by and hosted on G2.com.

What problems is DerScanner solving and how is that benefiting you?

With all the stories you hear about hacks and data breaches, knowing that DerScanner is there to find any sneaky backdoors or vulnerabilities before the bad guys do is a huge relief.

We’re in the business of education, and our users trust us with their data. DerScanner helps us keep that trust by making sure our apps are as secure. Review collected by and hosted on G2.com.

Peter J.
PJ
Project Manager
Information Technology and Services
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about DerScanner?

OK, so I have to admit, DerScanner is pretty good when it comes to understanding Delphi code. It checks everything – the whole source code, libraries, and even resource files. I mean, it's like having a super-smart buddy checking your work for any possible mistakes. Keeping in mind I had some hard times finding a solution that does support Delphi — not the most popular framework these days. DerScanner has been a great find. Review collected by and hosted on G2.com.

What do you dislike about DerScanner?

There are occasional false positives, but they were less often than in other solutions we have used. I assume it takes some time for a system to adapt to the type of code you have usually in your environment. With time the results are getting better. Review collected by and hosted on G2.com.

What problems is DerScanner solving and how is that benefiting you?

What I really appreciate about DerScanner is that it finds the hidden, sneaky stuff in your code. Things like backdoors that someone might have left intentionally. That’s pretty crucial for our security. I also found it kind of educational. It opened my eyes to see how certain ways of coding, that seem totally fine at first, can actually be potential security risks. Review collected by and hosted on G2.com.

CD
Owner
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about DerScanner?

I've had some previous experience with the scanners that's been built purely for developers and sometimes it's difficult to understand their language. DerScanner doesn’t just throw error codes or complex jargon at you, it shows you exactly where things went wrong and walks you through how to fix it. And that's all explained in the language that a security guy can understand. And for someone who isn’t exactly a coding hero, this makes a difference. As your security practice gets more mature you can benefit from Fuzzy Logic Engine technology. It doesn’t go off the rails sending false alarms every time there’s a minor issue. It knows how to tell the difference between a real vulnerability and a false alarm. Review collected by and hosted on G2.com.

What do you dislike about DerScanner?

As we prefer the on-prem deployment the hardware requirements can be a bit resource consuming like the RAM it needs. But as long as it does the job, I'm fine with that. Review collected by and hosted on G2.com.

What problems is DerScanner solving and how is that benefiting you?

We started with a couple of ad-hoc scans and then expanded the installation to our whole coding process. The scanner now integrates with all sorts of our CI/CD pipeline tools like Jenkins, GitHub and others. Review collected by and hosted on G2.com.