Best AI AppSec Assistants

How Many AI AppSec Assistants Products Does G2 Track?

Total Products under this Category: 50

Category Stats (Oct 2026)

  • Average Rating: 4.53/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Appdome (+0.61%) - Among all products in this category, Appdome recorded the largest rating increase compared to last month

Last updated: October 01, 2026

How Does G2 Rank AI AppSec Assistants Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 1,900+ Authentic Reviews
  • 50+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for AI AppSec Assistants

G2 Grid® for AI AppSec Assistants plotting products by satisfaction and market presence

Highlighted products: Aikido Security, GitHub Copilot, SonarQube, Replit, Snyk, OX Security, and DryRun Security.

Underlying data: [Grid® JSON](https://www.g2.com/categories/ai-appsec-assistants/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=github-copilot&focus%5B%5D=sonarqube&focus%5B%5D=replit&focus%5B%5D=snyk&focus%5B%5D=ox-security&focus%5B%5D=dryrun-security)

Aikido Security

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

Average Rating: 4.6/5.0

Total Reviews: 266

Who Is the Company Behind Aikido Security?

  • Seller: Aikido Security
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Ghent, Belgium
  • Twitter: @AikidoSecurity
    11,770 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    320 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Founder, CTO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 78% Small, 15% Medium

What Do G2 Reviewers Say About Aikido Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Aikido Security, thanks to its clear insights and seamless integration.
  • Users appreciate Aikido Security's robust security capabilities, providing a comprehensive and seamless integration in their workflow.
  • Users value the intuitive dashboard of Aikido Security, which simplifies security issue identification and management.
  • Users value the easy integrations of Aikido Security, enhancing workflows with seamless connections to existing GitLab repositories.
  • Users find Aikido's easy setup highly efficient, enabling quick implementation and immediate usability for security assessments.
Cons
  • Users note the lack of advanced features in Aikido Security, such as dark mode and in-depth analysis options.
  • Users find the pricing structure expensive for micro businesses, making upgrades difficult to justify.
  • Users note the limited features of Aikido Security, wishing for more customization and advanced options.
  • Users find the pricing issues challenging, especially for micro businesses, due to the steep upgrade costs.
  • Users feel Aikido Security is lacking features like advanced reporting and deeper compliance analysis compared to competitors.

What Are Recent G2 Reviews of Aikido Security?

GitHub Copilot

GitHub Copilot helps more than 1 million developers and over 20,000 businesses push what’s possible in software development. Based on powerful LLMs, including OpenAI’s GPT models, this AI pair programmer helps developers write code faster and with less work by drawing context from comments and code to suggest individual lines and whole functions instantly. All languages are supported, however the more common a language, the better represented it will be in the training data and the more robust suggestions will be.

Average Rating: 4.4/5.0

Total Reviews: 387

Who Is the Company Behind GitHub Copilot?

  • Seller: GitHub
  • Year Founded: 2008
  • HQ Location: San Francisco, CA
  • Twitter: @github
    2,673,925 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6,653 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 37% Small, 32% Medium

What Do G2 Reviewers Say About GitHub Copilot?

AI-generated summary from verified user reviews

Pros
  • Users find GitHub Copilot's ease of use enhances their coding workflow, boosting productivity without interruptions.
  • Users value the seamless coding assistance of GitHub Copilot, enhancing productivity and confidence in their programming tasks.
  • Users appreciate the productivity improvement from GitHub Copilot, enhancing development speed and code consistency throughout projects.
  • Users find GitHub Copilot's effective problem-solving capabilities invaluable, providing timely coding suggestions and solutions directly.
  • Users appreciate the efficiency of GitHub Copilot, enhancing coding with intelligent suggestions and error reduction.
Cons
  • Users find the poor coding accuracy of GitHub Copilot can lead to ineffective and lazy coding practices.
  • Users find poor suggestions from GitHub Copilot frustrating, as they often require careful review and aren't always suitable.
  • Users find the subscription cost expensive, making it a barrier for students and new developers.
  • Users note the inaccuracy of GitHub Copilot, often leading to complications and potential bugs in their code.
  • Users find that GitHub Copilot has context understanding issues, leading to confusion and inaccurate code suggestions.

What Are Recent G2 Reviews of GitHub Copilot?

SonarQube

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

Average Rating: 4.4/5.0

Total Reviews: 153

Who Is the Company Behind SonarQube?

  • Seller: SonarSource Sàrl
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Geneva, Switzerland
  • Twitter: @SonarSource
    10,913 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    973 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: DevOps Engineer, Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 41% Large, 41% Medium

What Do G2 Reviewers Say About SonarQube?

AI-generated summary from verified user reviews

Pros
  • Users value SonarQube for its ability to quickly flag code quality and security issues, ensuring a reliable codebase.
  • Users value the flexible issue filtering and prioritization features of SonarQube, enhancing team productivity and focus.
  • Users appreciate how SonarQube quickly flags code quality and security issues, ensuring a clean and reliable codebase.
  • Users appreciate the ease of use of SonarQube, finding integration and actionable feedback simple and effective.
  • Users appreciate the easy integrations with CI/CD tools, enhancing their workflow and improving code quality effectively.
Cons
  • Users face software bugs that lead to false positives, complicating the experience and requiring significant knowledge to manage.
  • Users find the complex configuration of SonarQube challenging, especially for beginners needing extensive knowledge.
  • Users encounter false positives that complicate usage, despite helpful tools for review and customization of analysis.
  • Users find SonarQube's complexity in configuration and excessive warnings can make it cumbersome to use.
  • Users find the complex setup of SonarQube time-consuming, requiring significant effort to configure and tune effectively.

What Are Recent G2 Reviews of SonarQube?

What Are G2 Users Discussing About SonarQube?

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

Replit

Replit turns your ideas into apps, fast. With Replit, anyone—technical or non-technical—can build and deploy fully-functional, full-stack apps directly from their browser, without any installation, setup, or configuration. Replit's Agent and Assistant enables you to create entire applications from natural language, turning bullet points into working apps in minutes. Its built-in tools, including databases and deployment features, allow you to launch with a single click. Replit bridges the gap between non-technical and technical users, driving collaboration for everything from product roadmaps and prototypes to custom APIs and internal tools. Replit empowers everyone to not just consume software but to create it, transforming app development into an accessible, instant, and impactful process. Go from 'why doesn't this app exist?' to building it for yourself.

Average Rating: 4.4/5.0

Total Reviews: 411

Who Is the Company Behind Replit?

  • Seller: Replit
  • Year Founded: 2016
  • HQ Location: San Francisco, US
  • Twitter: @Replit
    234,474 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    693 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Founder, CEO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 66% Small, 12% Medium

What Do G2 Reviewers Say About Replit?

AI-generated summary from verified user reviews

Pros
  • Users find Replit's ease of use remarkable, enabling even non-coders to build and deploy complex applications effortlessly.
  • Users value Replit for its instant browser-based coding, enhancing collaboration and speeding up prototyping and testing processes.
  • Users find Replit's implementation ease exceptional, enabling efficient app creation and management without coding knowledge.
  • Users value the time-saving capabilities of Replit, allowing for quick development and deployment of projects.
  • Users appreciate the coding assistance of Replit, facilitating an easy and enjoyable development experience for all skill levels.
Cons
  • Users find Replit expensive due to confusing pricing and hidden fees that complicate budget management.
  • Users are frustrated by the high cost of credit usage, making budgeting for queries a significant challenge.
  • Users experience poor coding as the agent struggles with complex tasks, leading to errors and wasted resources.
  • Users experience system unreliability with Replit, often facing endless loops and errors affecting project development.
  • Users experience slow performance with Replit, causing frustration during project edits and page refreshes.

What Are Recent G2 Reviews of Replit?

What Are G2 Users Discussing About Replit?

FAQs About AI AppSec Assistants

Generated using AI

Last updated: June 3, 2026

Which AI AppSec platforms avoid high false positive rates that waste security and developer time

Based on G2 reviews, these products are most often praised for reducing noisy findings and helping teams focus on real issues.

  • Aikido Security — low-noise findings with fast remediation.
  • DryRun Security — contextual PR feedback with high signal.
  • SonarQube — early code checks with quality gates.
  • Snyk — reachability-based triage for dependencies.

AI AppSec Assistants with accurate detection of OWASP Top 10 vulnerabilities and supply chain risks

According to verified users, strong AI AppSec Assistants are valued for surfacing meaningful vulnerabilities across code, dependencies, containers, secrets, and cloud environments without overwhelming teams with noise. Reviews repeatedly highlight the importance of clear remediation guidance, contextual findings, and prioritization that helps developers act quickly. Recent G2 feedback also points to demand for coverage of common web application risks such as injection flaws, authorization issues, leaked secrets, and insecure dependencies. Buyers evaluating this category should look for products that combine code scanning with software composition analysis, explain why an issue matters, and fit naturally into pull requests, CI pipelines, or repository-based workflows so fixes happen before release.

Which AI AppSec solutions integrate into IDEs and provide real-time guidance during code development

Based on G2 reviews, these products stand out for developer-facing workflows, in-editor feedback, or fast guidance during coding and review.

What are AI AppSec Assistants

AI AppSec Assistants are tools that help teams find, prioritize, and remediate application security issues within software development workflows. Recent G2 reviews describe them as products that scan code, dependencies, containers, secrets, and related environments while giving developers actionable guidance instead of long lists of raw alerts. They are commonly used in pull requests, repositories, CI pipelines, and dashboards so teams can catch vulnerabilities earlier and reduce manual review effort. Across the category, buyers consistently value fast setup, clear explanations, lower false-positive rates, and remediation support that helps engineering and security teams work from the same findings without slowing delivery.

How does AI AppSec Assistants integrate with GitHub

G2 reviewers mention GitHub integration as one of the most practical workflows in this category. Recent reviews describe teams connecting repositories quickly, scanning pull requests or merged code, and receiving findings directly where developers already work. Common benefits include PR comments, automatic repository onboarding, alerts on new issues, and remediation guidance that reduces context switching. Buyers also appear to value tools that support continuous monitoring after code changes, help prioritize what should be fixed first, and make security review easier for both developers and AppSec teams. In the latest G2 feedback, GitHub-connected workflows are especially associated with faster reviews, earlier detection, and better trust in findings.

Snyk

Snyk (pronounced sneak) is a developer security platform for securing custom code, open source dependencies, containers, and cloud infrastructure all from a single platform. Snyk’s developer security solutions enable modern applications to be built securely, empowering developers to own and build security for the whole application, from code & open source to containers & cloud infrastructure. Secure while you code in your IDE: find issues quickly using the scanner, fix issues easily with remediation advice, verify the updated code. Integrate your source code repositories to secure applications: integrate a repository to find issues, prioritize with context, fix & merge. Secure your containers as you build, throughout the SDLC: start fixing containers as soon as your write a Dockerfile, continuously monitor container images throughout their lifecycle, and prioritize with context. Secure build and deployment pipelines: Integrate natively with your CI/CD tool, configure your rules, find & fix issues in your application, and monitor your applications. Secure your apps quickly with Snyk’s vulnerability scanning and automated fixes - Try for Free!

Average Rating: 4.5/5.0

Total Reviews: 136

Who Is the Company Behind Snyk?

  • Seller: Snyk
  • HQ Location: Boston, Massachusetts
  • Twitter: @snyksec
    21,057 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,764 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 45% Medium, 35% Small

What Do G2 Reviewers Say About Snyk?

AI-generated summary from verified user reviews

Pros
  • Users value Snyk's quick vulnerability detection, significantly improving efficiency in code security and remediation processes.
  • Users appreciate Snyk for its efficient vulnerability identification, significantly aiding in maintaining secure code and streamlining DevOps processes.
  • Users value the easy integration setup of Snyk, enhancing vulnerability detection in their development workflows.
  • Users appreciate the easy setup of Snyk, seamlessly integrating with GitHub for efficient vulnerability management.
  • Users benefit from Snyk's intuitive GUI and customizable features, facilitating effective vulnerability management and developer organization.
Cons
  • Users experience false positives in Snyk, which can hinder efficiency and slow down the scanning process.
  • Users find the poor interface design of Snyk cumbersome, impacting their overall experience with the product.
  • Users note that pricing issues can arise, especially when accessing all features of Snyk, impacting affordability.
  • Users report experiencing false positives and slow scan times, affecting their efficiency and integration within the Snyk product.
  • Users experience false positives and slow scans, complicating overall use and requiring additional tools for code quality.

What Are Recent G2 Reviews of Snyk?

What Are G2 Users Discussing About Snyk?

OX Security

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

Average Rating: 4.8/5.0

Total Reviews: 51

Who Is the Company Behind OX Security?

Who Uses This Product?

  • Who Uses This: Security Engineer
  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 63% Medium, 25% Large

What Do G2 Reviewers Say About OX Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the intuitive dashboard of OX Security, enhancing issue management and streamlining security processes effectively.
  • Users find OX Security highly user-friendly, benefiting from an intuitive dashboard and responsive support for seamless operations.
  • Users value the responsive and professional customer support of OX Security, enhancing their overall experience and efficiency.
  • Users value the seamless integration support from OX Security, enhancing their workflow with fast and user-friendly solutions.
  • Users appreciate the comprehensive security capabilities of OX Security, ensuring a streamlined and effective security management experience.
Cons
  • Users report integration issues with OX Security's limited documentation and insufficient support for various tools.
  • Users note some missing features in OX Security, which can affect its overall usability and integration capabilities.
  • Users find the complexity of OX Security daunting, with inadequate documentation and a steep learning curve for new users.
  • Users find OX Security's inadequate reporting limits their ability to effectively showcase security progress to management.
  • Users find the limited cloud integration with certain tools frustrating, impacting overall connectivity and functionality.

What Are Recent G2 Reviews of OX Security?

DryRun Security

Security leaders face a paradox: ship faster and enable agentic development while staying secure and keeping developers productive. DryRun Security resolves this by securing every pull request and repo with a high-precision, automated security engineer review right where developers and their agents build. DryRun Security is the industry’s most accurate agentic code security intelligence platform. Powered by its proprietary Contextual Security Analysis (CSA) engine, DryRun Security delivers the AI moment for security teams in an AI-native developer world. Traditional static application security testing (SAST) floods teams with alerts, misses higher-order risk, and burns time in triage. DryRun Security goes beyond SAST with contextual analysis that prioritizes what is exploitable and impactful in your codebase, then helps engineers remediate fast. Instead of “find everything and hope someone sorts it out,” DryRun Security delivers code security intelligence that is ready to act on. DryRun Security puts a security engineer directly into developer workflows. In pull requests, the Code Review Agent reviews changes in context, explains risk in plain language, and guides fixes where developers already work. In repos, the DeepScan Agent produces focused, human-grade findings for the issues that actually matter, without weeks of manual review before major milestones. The Custom Policy Agent enforces guardrails with Natural Language Code Policies, so you can standardize security and compliance requirements across teams without brittle rule sets. Codebase Insights allows leaders to ask questions of their entire codebase like "Are we exposed to this new vulnerability" and have confidence in minutes. DryRun Security also integrates with AI coding workflows, so remediation happens with the precision of a security engineer working at machine speed. Teams connect DryRun Security insights and guidance into Claude, Cursor, OpenAI Codex, and Windsurf, helping developers and their agents fix issues with contextual, security-engineered direction tied to the PR and codebase. What DryRun Security delivers (beyond SAST) • Automated secure code review in every pull request with high-signal findings and low noise • Contextual Security Analysis that catches common vulnerabilities and deeper multi-dependency and logic risks • Automated remediation guidance that helps engineers fix faster, with explanations and next steps • Secrets analysis identifies genuine hardcoded secrets and suppresses the usual false alarms • Policy enforcement in PRs using Natural Language Code Policies for consistent guardrails across repos • Codebase intelligence and reporting for AppSec visibility, prioritization, and audit-ready evidence DryRun Security supports most code environments, languages, and frameworks, including: • GitHub, GitLab • C#, Golang, Elixir, JavaScript, TypeScript, Python, Ruby, Java, Kotlin, PHP, Swift, HTML • Infrastructure as Code (Terraform, YAML) • And more

Average Rating: 4.9/5.0

Total Reviews: 20

Who Is the Company Behind DryRun Security?

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 40% Small, 30% Medium

What Do G2 Reviewers Say About DryRun Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the context-aware security feedback from DryRun Security, enabling efficient vulnerability mitigation in real-time.
  • Users appreciate the quick and context-aware vulnerability detection of DryRun Security, enhancing code security during development.
  • Users commend DryRun Security for its seamless integration and effective detections, enhancing code security and development efficiency.
  • Users appreciate the accuracy of DryRun Security, effectively identifying vulnerabilities in AI-generated code and traditional applications.
  • Users commend the easy setup of DryRun Security, providing seamless integration and efficient workflow for code scanning.
Cons
  • Users experience slow performance in the management portal, affecting usability and efficiency with linked repositories.
  • Users find the slow speed of the management portal frustrating, though improvements to the UI have been noted.
  • Users note a need for improved UX investment in DryRun Security to enhance the developer experience and engagement.
  • Users desire more customization options for tuning analyzers, indicating limited flexibility in current features.
  • Users feel that greater focus on workflow issues could enhance DryRun Security's adoption among developers.

What Are Recent G2 Reviews of DryRun Security?

Amazon Q Developer

Amazon Q Developer is a generative AI-powered assistant designed to enhance the entire software development lifecycle. It integrates seamlessly into various development environments, offering real-time code suggestions, automating routine tasks, and providing expert guidance on AWS services. By leveraging advanced AI capabilities, Amazon Q Developer aims to boost developer productivity, improve code quality, and streamline operations. Key Features and Functionality: - Real-Time Code Suggestions: Generates code snippets and full functions based on comments and existing code, supporting multiple programming languages. - Inline Chat and CLI Support: Offers inline chat within code editors and command-line interface (CLI) completions, including natural language-to-bash translation. - Security and Reliability Enhancements: Scans code for vulnerabilities, suggests remediations, and assists in writing unit tests to optimize code performance. - Agentic Capabilities: Autonomously performs tasks such as implementing features, documenting, testing, reviewing, refactoring code, and executing software upgrades. - AWS Integration: Provides expert assistance on AWS services, helping to optimize cloud resources, analyze costs, and adhere to architectural best practices. - Multi-Platform Availability: Compatible with popular integrated development environments (IDEs) like JetBrains, Visual Studio Code, Eclipse, and Visual Studio, as well as command-line interfaces and chat applications like Microsoft Teams and Slack. Primary Value and User Solutions: Amazon Q Developer addresses common challenges in software development by automating time-consuming tasks, reducing the cognitive load on developers, and enhancing code quality. Its integration with AWS services ensures that applications are built following best practices, leading to more efficient and secure cloud operations. By providing real-time assistance and automating routine processes, Amazon Q Developer enables developers to focus on innovation and delivering value to their users.

Average Rating: 4.6/5.0

Total Reviews: 51

Who Is the Company Behind Amazon Q Developer?

  • Seller: Amazon Web Services (AWS)
  • Year Founded: 2006
  • HQ Location: Seattle, WA
  • Twitter: @awscloud
    2,232,483 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    147,094 employees on LinkedIn®
  • Ownership: NASDAQ: AMZN

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 41% Small, 31% Large

What Do G2 Reviewers Say About Amazon Q Developer?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Amazon Q Developer, enabling faster coding, understanding, and debugging.
  • Users value the coding assistance provided by Amazon Q Developer, enhancing learning and speeding up development processes.
  • Users appreciate the easy integrations of Amazon Q Developer, enhancing their coding and troubleshooting efficiency with AWS.
  • Users appreciate the context-aware code suggestions of Amazon Q Developer, enhancing their coding speed and understanding.
  • Users appreciate the seamless integration and automation features of Amazon Q Developer, enhancing productivity and learning experiences.
Cons
  • Users report poor suggestions from Amazon Q Developer, causing confusion and hindering the overall coding experience.
  • Users experience inaccurate suggestions from Amazon Q Developer, leading to confusion and inefficiency during coding tasks.
  • Users experience irrelevant responses that can be generic or repetitive, impacting the effectiveness of Amazon Q Developer.
  • Users find poor integration with other tools complicates the experience and makes it challenging for beginners to utilize effectively.
  • Users report slow performance and latency issues, especially when handling large files or complex code structures.

What Are Recent G2 Reviews of Amazon Q Developer?

Appdome

Appdome is an agentic platform that protects mobile apps and the mobile business at scale. Trusted by enterprises worldwide, Appdome automates mobile app security, fraud prevention, bot defense, and threat detection and response across Android and iOS applications. Unlike legacy SDK-based approaches that require manual implementation and ongoing maintenance, Appdome uses AI agents to embed protections directly into mobile apps, analyze threats in real time, and continuously adapt defenses without code or complex integration. Organizations use Appdome to protect mobile apps, APIs, identities, accounts, transactions, and users from fraud, bots, malware, account takeover, deepfakes, and other cyber threats. Appdome’s agentic mobile defense platform includes: Identity and reputation protection Fraud and account takeover (ATO) prevention Bot and API defense Mobile app security (RASP and app shielding) DevSecOps and CI/CD integration Threat management and response (including ThreatScope™ Mobile XDR, ThreatEvents™, and Threat Resolution Center™)

Average Rating: 4.8/5.0

Total Reviews: 96

Who Is the Company Behind Appdome?

  • Seller: Appdome
  • Company Website:
  • Year Founded: 2012
  • HQ Location: Redwood City, California, United States
  • Twitter: @appdome
    2,107 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    184 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Banking
  • Company Size: 48% Large, 34% Medium

What Do G2 Reviewers Say About Appdome?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the excellent customer support from Appdome, highlighting their responsiveness and helpfulness throughout the process.
  • Users value the extensive security features of Appdome, enhancing mobile app protection effectively and efficiently.
  • Users value the ease of use with Appdome, praising its intuitive GUI for securing mobile applications effortlessly.
  • Users value the runtime application protection of Appdome, appreciating its ease and comprehensive security without coding.
  • Users appreciate the ease of implementation with Appdome, enabling fast and efficient integration without coding.
Cons
  • Users note that the licensing costs can be prohibitive, making it challenging for smaller companies to afford Appdome.
  • Users find the complexity of features in Appdome overwhelming, requiring time to understand proper integration and configuration.
  • Users find the initial learning curve challenging due to the extensive features, requiring time to understand configurations.
  • Users face a challenging learning difficulty due to the complexity of configurations and initial integration guidance required.
  • Users often struggle with poor documentation, leading to confusion during integration and configuration of Appdome.

What Are Recent G2 Reviews of Appdome?

Codeant AI Code Reviewer

CodeAnt AI reviews every pull request against the full codebase and the business logic behind it, not just the changed lines. Inline review comments land on the exact lines that need attention, covering logic errors, edge cases, anti-patterns, security vulnerabilities, hardcoded secrets, and infrastructure-as-code misconfigurations. IDE fixes apply CodeAnt's suggestions directly in the editor, so remediation happens where the code is written rather than in the pull request interface. Sequence diagrams are generated automatically for every pull request, showing how the changed code moves through services and functions. PR summaries describe what changed and what it affects, written for technical and non-technical reviewers. Quality gates enforce merge criteria deterministically. The same code returns the same verdict on every run. AI chat answers questions about the change inside the pull request, with full codebase context. Continuous AI learning adapts to what your team accepts, rejects, and debates. Custom rules are written in plain English and enforced from the next pull request onward. Results: zero false positives, 70% fix acceptance, 80% reduction in review time, 4x fewer production bugs. CodeAnt reviews more than 5 million pull requests monthly across more than 1 billion lines of codebase history.

Average Rating: 4.7/5.0

Total Reviews: 7

Who Is the Company Behind Codeant AI Code Reviewer?

  • Seller: CodeAnt AI
  • Year Founded: 2023
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    22 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 57% Small, 43% Medium

What Do G2 Reviewers Say About Codeant AI Code Reviewer?

AI-generated summary from verified user reviews

Pros
  • Users value the exceptional code quality from Codeant AI Code Reviewer, benefiting from smart suggestions and custom rules.
  • Users appreciate the comprehensive all-in-one features of Codeant AI Code Reviewer, simplifying code reviews and security analysis.
  • Users appreciate the comprehensive coverage of Codeant AI Code Reviewer, simplifying code review and security processes.
  • Users value the custom rules feature for its tailored context and enhanced code review efficiency.
  • Users value the ease of use of Codeant AI Code Reviewer, appreciating its simple interface for comprehensive reviews.
Cons
  • Users find the difficult learning curve with Codeant AI Code Reviewer due to cautious suggestions and slow onboarding.
  • Users find the false positives from Codeant AI Code Reviewer often overly cautious, requiring manual adjustments during onboarding.
  • Users find the improvement needed as suggestions can be overly cautious and onboarding requires significant time.
  • Users find the inefficient notifications sometimes overly cautious and require manual adjustments, complicating the onboarding process.
  • Users find the lack of guidance frustrating, as suggestions may be overly cautious and require manual adjustments.

What Are Recent G2 Reviews of Codeant AI Code Reviewer?

Tabnine

Tabnine provides the world’s most contextually-aware AI software development agents, autonomously completing the broadest variety of tasks across the SDLC without sacrificing privacy. Tabnine boosts engineering velocity and software quality through AI tools customized to each unique organization’s coding patterns, standards, and expectations. Many AI tools can write software, but only Tabnine generates and validates software like your best engineers.Unlike generic coding assistants, Tabnine is the AI software development platform tailored to you and your team: - Personalized — Tabnine delivers an optimized experience for each development team; it is highly context-aware, integrates with the widest variety of IT systems to gain understanding and to act, and learns and applies your unique approach and policies,. - Private — You choose where and how to deploy Tabnine (SaaS, VPC, or on-premises) to maximize control over your IP, and you choose both the underlying LLM and how it is applied (including private endpoints and fully private deployment). - Protected — Tabnine has the most comprehensive approach to assuring license and copyright compliance. Tabnine evaluates all AI-generated code (flagging any matches with publicly visible code) and also offers a proprietary model exclusively trained on permissively licensed code to support the strictest teams and use cases. Tabnine pioneered AI-enabled software development and now supports more than a million developers across thousands of teams, making it one of the most widely used AI applications in the world. Tabnine is privately held and backed by top-tier investors. We support all the popular IDEs namely - VS Code - JetBrains IDEs - Eclipse - Visual Studio 2022 We support all the major programming languages. Refer here for more details (https://docs.tabnine.com/main/welcome/readme/supported-languages) - JavaScript - TypeScript - Python - Java - C - C++ - C# - Go - Php - Ruby - Kotlin / Dart - Rust - React / Vue - HTML 5 - CSS - Lua - Cuda - Perl - SQL - Scala - Shell (bash) - Swift - R - Julia - VB - Groovy - Matlab - Terraform - ABAP

Average Rating: 4.2/5.0

Total Reviews: 69

Who Is the Company Behind Tabnine?

  • Seller: Tricentis
  • Company Website:
  • Year Founded: 2007
  • HQ Location: Austin, Texas
  • Twitter: @Tricentis
    12,931 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,679 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 71% Small, 22% Medium

What Do G2 Reviewers Say About Tabnine?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use with Tabnine for quick task completion and AI-driven code insights.
  • Users value the coding assistance from Tabnine, enhancing productivity with quick, reliable AI-driven code suggestions.
  • Users value the speed and security of Tabnine, enhancing productivity with intelligent code suggestions and team collaboration.
  • Users appreciate the reliable auto-suggestions from Tabnine, enhancing coding speed and productivity during development tasks.
  • Users value the speed and efficiency of Tabnine, enhancing productivity with accurate code suggestions and insights.
Cons
  • Users criticize Tabnine for its poor coding performance, falling short of expectations and alternatives like ChatGPT Plus.
  • Users often face poor suggestions with Tabnine, especially when working with UI frameworks like Vue.js.
  • Users find the AI integration lacking, with limited context and performance compared to direct alternatives like ChatGPT.
  • Users face compatibility issues, as Tabnine struggles with UI frameworks and requires good connectivity for accuracy.
  • Users experience irrelevant responses from Tabnine, leading to frustration and ineffective code completion suggestions.

What Are Recent G2 Reviews of Tabnine?

What Are G2 Users Discussing About Tabnine?

CybeDefend

CybeDefend is the application security platform built for the AI coding era. Traditional shift-left security detects vulnerabilities after the code is written. But with Claude Code, Cursor, Copilot and Codex generating thousands of lines per developer per day, human review can no longer keep pace and the pull request is no longer the right control point. CybeDefend operates at shift-zero, directly inside the AI coding agent loop. Our flagship product VibeDefend is the MCP-native security layer that injects your business rules and compliance policies straight into the agent's context, before the first line of code is written. The agent ships safe code by default, on every developer's machine, without slowing the team down. Our AI-BOM scanner discovers every AI asset in your code (models, datasets, prompts, agents, MCP servers, guardrails) and produces the EU AI Act Annex IV evidence dossier plus NIST AI RMF mapping directly in your CI pipeline. No questionnaire, no consultant. Built-in build gate on prohibited and ungoverned high-risk components. The complete AppSec stack comes unified on top: SAST, SCA, IaC, CI/CD, Secrets and Container scanning, powered by a knowledge graph of business-logic rules auto-mined from your repository. Sovereign cloud (SecNumCloud-certified) or US cloud at your choice, on-premise deployment available for regulated industries. Code never leaves the machine, only metadata.

Average Rating: 5.0/5.0

Total Reviews: 4

Who Is the Company Behind CybeDefend?

Who Uses This Product?

  • Company Size: 75% Small, 25% Medium

What Are Recent G2 Reviews of CybeDefend?

Arnica

Arnica is a comprehensive application security posture management (ASPM) platform that protects developers, source code, and products throughout the software development lifecycle. The platform provides real-time application security scanning with 100% coverage across the software supply chain, addressing risks in Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC), hardcoded secrets detection, and more. At its core, Arnica offers AI-native security governance that takes control of AI-generated code through advanced AI SAST scanning and agentic rules enforcement. The platform automatically injects centrally-controlled security requirements into AI coding agents like Copilot, Cursor, and Claude at the point of code generation, ensuring every line of AI-written code is secure by default before vulnerabilities reach production. This approach addresses 92% of risks before they ever reach production environments. Arnica's pipelineless architecture provides automatic coverage for every repository without requiring CI/CD pipeline integrations or IDE deployments. The platform scans every code change at the feature branch level, delivering developer-native workflows that keep teams focused on building features rather than chasing security issues. Risk prioritization is enhanced through OWASP Top 10, CVSS, EPSS, and KEV scoring, combined with organizational context to surface the most critical vulnerabilities. The platform excels in developer experience by delivering security findings directly within existing workflows through Slack, Microsoft Teams, pull request comments, and automated ticket management in Jira and Azure DevOps Boards. AI-powered mitigation suggestions provide context-aware, automated fixes that align with organizational coding standards, significantly reducing mean-time-to-remediation. Key security capabilities include real-time secrets detection with automatic validation and mitigation, comprehensive container scanning that maps vulnerabilities directly to source code, and intelligent dependency management with automated SCA upgrades. The platform maintains SOC 2 Type 2 compliance and ISO 27001 certification, ensuring enterprise-grade security standards. Arnica's unique value proposition lies in its ability to scale security across entire organizations while maintaining development velocity, providing complete visibility into code risks, and enabling proactive security measures that prevent vulnerabilities from reaching production environments.

Average Rating: 4.8/5.0

Total Reviews: 9

Who Is the Company Behind Arnica?

  • Seller: Arnica
  • Company Website:
  • Year Founded: 2021
  • HQ Location: Alpharetta, Georgia
  • Twitter: @arnicaio
    124 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    60 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 56% Large, 33% Small

What Do G2 Reviewers Say About Arnica?

AI-generated summary from verified user reviews

Pros
  • Users value the accuracy of findings from Arnica, enhancing security through effective management of privileges.
  • Users value Arnica for its actionable recommendations, simplifying the management of elevated privileges in source code repositories.
  • Users appreciate the easy setup and administration of Arnica, which saves valuable time and effort.
  • Users love the easy setup of Arnica, making administration a quick and efficient process.
  • Users value Arnica for its ability to reduce attack surface by identifying and rectifying excessive privileged access efficiently.
Cons
  • Users find the paid features limited for smaller teams, restricting access to crucial protections in Arnica.

What Are Recent G2 Reviews of Arnica?

What Are G2 Users Discussing About Arnica?

Checkmarx

Checkmarx offers leading application security solutions that help organizations safeguard software development while enhancing efficiency and reducing costs. At the center is Checkmarx Fusion, the highest-fidelity scanning architecture in the industry. Most scanners force a choice: catch more, or get buried in noise and miss what matters. Fusion ends that trade-off — deterministic precision and frontier AI coverage fused into one verified result, with the Findings Analysis Engine validating and deduplicating every finding before a developer sees it. The result is an F1 score of 0.64 today by using the Checkmarx NG SAST vs. an industry average of ~0.20, and an astonishing market leading F1 score of 0.74 with Checkmarx Fusion. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as NG SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

Average Rating: 4.2/5.0

Total Reviews: 45

Who Is the Company Behind Checkmarx?

  • Seller: Checkmarx
  • Company Website:
  • Year Founded: 2006
  • HQ Location: Paramus, NJ
  • Twitter: @Checkmarx
    7,284 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    997 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 57% Large, 22% Small

What Do G2 Reviewers Say About Checkmarx?

AI-generated summary from verified user reviews

Pros
  • Users value the easy implementation of Checkmarx into existing repositories, enhancing their security review processes effortlessly.
  • Users praise the intuitive user interface of Checkmarx, making security reviews and integrations straightforward and user-friendly.
  • Users value the accuracy of results in Checkmarx, finding it effective for automated security reviews.
  • Users appreciate the automation testing capabilities of Checkmarx, making security reviews efficient and user-friendly.
  • Users praise the responsive customer support of Checkmarx, consistently providing help when challenges arise.
Cons
  • Users experience a significant number of false positives with Checkmarx, particularly for Kotlin projects, leading to frustration.
  • Users face challenges with limited support for Kotlin, experiencing many false positives compared to other languages like Java or Javascript.
  • Users experience missing features in Checkmarx, particularly with Kotlin support, leading to numerous false positives.
  • Users find the navigation poor in Checkmarx, citing issues with dashboard layout and display clarity.

What Are Recent G2 Reviews of Checkmarx?

What Are G2 Users Discussing About Checkmarx?

Black Duck Polaris Platform

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it, development and DevSecOps teams to automate testing within development pipelines without compromising velocity, and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Average Rating: 4.2/5.0

Total Reviews: 103

Who Is the Company Behind Black Duck Polaris Platform?

  • Seller: Black Duck
  • Year Founded: 2024
  • HQ Location: Burlington, US
  • LinkedIn® Page: www.linkedin.com
    1,317 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 53% Large, 32% Medium

What Do G2 Reviewers Say About Black Duck Polaris Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the accuracy of findings from Black Duck SCA, highlighting its powerful engine and extensive knowledge base.
  • Users value the powerful identification of open source issues by Black Duck SCA, aided by extensive knowledge resources.
Cons
  • Users find that Black Duck SCA requires huge resources to deploy on-prem, which can be a significant drawback.

What Are Recent G2 Reviews of Black Duck Polaris Platform?

What Are G2 Users Discussing About Black Duck Polaris Platform?

Adam Crivello
AC
Researched and written by Adam Crivello
Updated April 9, 2026