Best Dynamic Application Security Testing (DAST) Software - Page 5

How Many Dynamic Application Security Testing (DAST) Software Products Does G2 Track?

Total Products under this Category: 98

Category Stats (Sep 2026)

  • Average Rating: 4.58/5 (↑0.02 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: TASKING Test & Verification Tools (+10.99%) - Among all products in this category, TASKING Test & Verification Tools recorded the largest rating increase compared to last month

Last updated: September 05, 2026

How Does G2 Rank Dynamic Application Security Testing (DAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 4,200+ Authentic Reviews
  • 98+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Dynamic Application Security Testing (DAST) Software

G2 Grid® for Dynamic Application Security Testing (DAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, Astra Pentest, Burp Suite, Invicti, Qodex.ai, Tenable Nessus, GitLab, and Harness Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/dynamic-application-security-testing-dast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=astra-pentest&focus%5B%5D=burp-suite&focus%5B%5D=invicti&focus%5B%5D=qodex-ai&focus%5B%5D=tenable-nessus&focus%5B%5D=gitlab&focus%5B%5D=harness-platform)

Fluid Attacks

Implement Fluid Attacks' comprehensive, AI-powered solution into your SDLC and develop secure software without delays. As an all-in-one solution, Fluid Attacks accurately finds and helps you remediate vulnerabilities throughout the SDLC and ensures secure software development. The solution integrates its AI, automated tool, and team of pentesters to perform SAST, SCA, DAST, CSPM, SCR, PtaaS and RE to help you improve your security posture. This way, Fluid Attacks delivers accurate knowledge of the security status of your application. This means security goes alongside innovation without hindering your speed. Fluid Attacks provides you with expert knowledge about vulnerabilities and support options that enable you to remediate the security issues in your application.

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate Fluid Attacks?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)
  • API / Integrations: 10.0/10 (Category avg: 8.7/10)
  • Test Automation: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Fluid Attacks?

  • Seller: Fluid Attacks
  • Year Founded: 2001
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    136 employees on LinkedIn®
  • Phone: +14154042154

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Fluid Attacks?

HackZero

HackZero is a security and compliance platform in the same category as Vanta, Drata and Secureframe, with the two things they leave you to buy separately already in the package: a real, continuous penetration test, and an independent CPA who issues the attestation. The usual path to SOC 2 Type 2 is three vendors. A compliance platform for the paperwork, a separate firm for the pentest, and an auditor at the end, wired together by you. HackZero runs all three as one motion. The platform collects and maps your evidence to the SOC 2 Trust Services Criteria itself, so you do not need Vanta, Drata or Secureframe alongside it. If you already run one, our pentest report drops straight in as evidence there. The penetration test is not a separate purchase: we test your live app continuously with AI agents, and hackers in the loop confirm every finding actually exploits, with each one pre-mapped to the control it satisfies. The same evidence is formatted for HIPAA, PCI DSS 4.0 and ISO 27001:2022 when you need those. We do not sell the audit. An independent AICPA-member CPA issues the SOC 2 opinion and you pay them directly, which is what keeps the attestation independent and keeps us out of the audit-mill category. A first SOC 2 Type 2 lands around $6,000 all-in, against the $30,000 to $45,000 a separate platform, pentest and auditor cost. Our pricing is public, our benchmark results are public, and our vulnerability research is public and credited, including a critical RCE in velocity.js (CVSS 9.8) and a Function-constructor escape in JSONPath-Plus, so our claim of real security depth is one you can verify.

Average Rating: 4.8/5.0

Total Reviews: 2

How Do G2 Users Rate HackZero?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind HackZero?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of HackZero?

Nexora Cyber

Nexora is an automated Dynamic Application Security Testing platform designed to help you find web vulnerabilities before they become real incidents. You scan your web applications and APIs continuously. Nexora identifies security risks based on OWASP Top 10, assigns clear risk scores, and shows you what needs to be fixed first.

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate Nexora Cyber?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Test Automation: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Nexora Cyber?

Who Uses This Product?

  • Company Size: 100% Small

What Do G2 Reviewers Say About Nexora Cyber?

AI-generated summary from verified user reviews

Pros
  • Users find the easy setup of Nexora Cyber ideal for teams managing web apps without extensive resources.

What Are Recent G2 Reviews of Nexora Cyber?

ProjectDiscovery

Software ships daily. Security testing happens quarterly, or once a year. Everything in between goes untested, and the gap widens as AI agents write a growing share of the code. From the founders of popular open source tools like Nuclei, httpx, subfinder and more, Neo is ProjectDiscovery's unified offensive testing and regression platform for vulnerability management. One engine pentests code, web apps, APIs, networks, and cloud on every PR and release, validates what is exploitable, and enforces every fix as a permanent regression test. In a head-to-head benchmark against DAST scanners and AI security tools, Neo found 24 exploitable vulnerabilities no other tool caught, with the lowest false positive rate of anything tested. Security compounds release over release.

Average Rating: 5.0/5.0

Total Reviews: 4

How Do G2 Users Rate ProjectDiscovery?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • API / Integrations: 10.0/10 (Category avg: 8.7/10)
  • Detection Rate: 10.0/10 (Category avg: 8.8/10)
  • Test Automation: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind ProjectDiscovery?

  • Seller: ProjectDiscovery
  • Company Website:
  • Year Founded: 2020
  • HQ Location: San Francisco, US
  • Twitter: @pdiscoveryio
    41,738 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    45 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 75% Large, 25% Medium

What Do G2 Reviewers Say About ProjectDiscovery?

AI-generated summary from verified user reviews

Pros
  • Users commend the excellent customer support from ProjectDiscovery, ensuring swift assistance and attentiveness to feedback.
  • Users find ProjectDiscovery's platform remarkably easy to use, enabling quick integration and immediate value in vulnerability management.
  • Users find the onboarding process incredibly simple, enabling quick integration and immediate value in vulnerability management.
  • Users value the accuracy of results from ProjectDiscovery, which enhances threat detection and overall security posture.
  • Users value the seamless cloud integration of ProjectDiscovery, enhancing vulnerability management and asset discovery effortlessly.
Cons
  • Users feel the dashboard issues limit functionality, especially for complex security ecosystems needing broader feature sets.
  • Users express concerns about inadequate analytics in ProjectDiscovery, limiting insights within complex security environments.
  • Users note integration issues with ProjectDiscovery, especially within complex security environments, limiting its overall effectiveness.
  • Users note the limited features of ProjectDiscovery, particularly compared to larger enterprise solutions, impacting overall utility.
  • Users feel the limited features of ProjectDiscovery may not meet the needs of complex security environments.

What Are Recent G2 Reviews of ProjectDiscovery?

SAMI

Assisted by AI, SAMI (Security Automated by Machine Intelligence) simplifies cyber related financial and operational risk management. Demonstrably reducing risk, saving cost, enhancing ROI, streamlining process and increasing revenue for our customers.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind SAMI?

  • Seller: Autnhive
  • Year Founded: 2018
  • HQ Location: West Bloomfeild, US
  • LinkedIn® Page: www.linkedin.com
    26 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of SAMI?

SmartScanner

SmartScanner is an AI-powered web vulnerability scanner designed to enhance the security of websites and applications. It offers features such as comprehensive vulnerability detection, support for various technologies, and a user-friendly interface that automates dynamic application security testing (DAST). Targeting a wide range of clients needing web security, SmartScanner provides detailed reports and flexible pricing options, making it a budget-friendly choice for organizations of all sizes. With its adaptive intelligence, it ensures optimal results tailored to the unique characteristics of each website.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind SmartScanner?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of SmartScanner?

VulnSign

VulnSign is help to organizations enhance their cybersecurity posture and protect their web applications from potential threats. Our intuitive, user-friendly platform allows users to quickly and easily scan their web applications for vulnerabilities that could be exploited by cybercriminals. VulnSign is designed to easy to use, yet powerful enough to identify potential vulnerabilities in your web-based systems. Our team of security experts is constantly working to improve and update our DAST application, ensuring that it stays at the forefront of the cybersecurity industry.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind VulnSign?

  • Seller: VulnSign
  • Year Founded: 2022
  • HQ Location: West Hollywood, US
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of VulnSign?

Appvigil

Appvigil is a completely automated Mobile Reputation Protection Suite for Mobile Apps.Powered by patent pending technology, Appvigil employs intensive static, dynamic & stringent network analysis.

Who Is the Company Behind Appvigil?

  • Seller: Appvigil
  • HQ Location: Seattle, US
  • Twitter: @appvigil_co
    438 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Bugsmirror MASST (Mobile Application Security Suite & Tools)

Bugsmirror Mobile Application Security Suite & Tools (MASST) is designed specifically for your business, providing scalable, end-to-end security for your mobile app. From detection to protection, MASST ensures your app is safeguarded against evolving security threats. With MASST, you can focus on growing your business, knowing your app is fully protected at every stage.

Who Is the Company Behind Bugsmirror MASST (Mobile Application Security Suite & Tools)?

Conviso

The Conviso Platform is a complete Application Security Posture Management (ASPM) solution that centralizes visibility, correlation, and prioritization of vulnerabilities across the software development lifecycle. It integrates with your existing SAST, DAST, SCA, IaC, and CI/CD tools, automates triage, and provides a unified view of risk — helping security and development teams work together to reduce complexity and strengthen AppSec maturity.

Who Is the Company Behind Conviso?

Enso Security

Enso Application Security Posture is a platform for AppSec teams to manage their day-to-day work, implement their security strategy into an AppSec organizational program, enforce it and automate it. And all of that in a scalable rapidly changing environment. AppSec teams struggle with prioritization - they may have a vision and concept of how to handle AppSec, but they don’t know where to invest and what actions to take. To keep up with R&D velocity and scale, Enso provides full visibility on the application inventory, focuses the AppSec teams on the most important tasks and insights, and takes a policy-based “call to action” approach so that the AppSec professionals won’t waste their time looking for application changes, prioritizing, or doing manual work.

Who Is the Company Behind Enso Security?

MeshaSec

Product Overview: The Autonomous Evolution of DAST MeshaSec is an autonomous DAST (Dynamic Application Security Testing) tool that scans web applications, APIs, and SPAs behind MFA, SSO, and TOTP authentication — without manual configuration. Built for DevSecOps teams and security engineers who need authenticated coverage with zero false positives. In 2026, security is no longer about just "finding bugs"—it’s about established Protocol Truth. MeshaSec orchestrates the identity handshake natively, treating your complex React/Vue/Angular applications as dynamic state machines rather than static pages. The result? 99.9% noise reduction, 100% authenticated coverage, and deterministic evidence fragments that your developers can act on instantly. Core Value Proposition: Why MeshaSec? 1. Identity-Aware Orchestration (Bypassing the Moat) Legacy scanners bounce off the entrance. MeshaSec natively orchestrates complex identity sessions, including: Enterprise SSO: Microsoft Entra ID (Azure AD), Okta, PingFederate, and Google Workspace. Adaptive MFA: Native TOTP/MFA fulfillment during scan execution. Session Continuity: Protocol-level heartbeats that detect 401/403 errors and silently re-authenticate to maintain continuous discovery. 2. Autonomous Discovery Nodes (Thinking Like an Attacker) Our discovery engine doesn't just crawl links; it understands application states. SPA Mastery: Native navigation of JS-rich environments (React, Vue, etc.). Shadow API Discovery: Uncovering private, undocumented endpoints hidden within client-side state transitions. Deep Business Logic Paths: Mapping every potential user journey to ensure no attack vector is left unverified. 3. Deterministic Protocol Truth (Ending the Triage War) Security teams are drowning in "Possible XSS" alerts. MeshaSec delivers Deterministic Verification: Raw Evidence Fragments: Every finding includes the raw HTTP Request and Response that triggered the flaw. 99.9% Deduplication: We correlate thousands of vectors into a single, irrefutable source of truth. Zero-Guessing Triage: If MeshaSec reports it, it exists. No probability scores—just proof. Technical Specifications & Standards Alignment MeshaSec is engineered to align with global security frameworks, making it the preferred choice for compliance-driven enterprises: OWASP Top 10 Mapping: Every vulnerability is automatically categorized under current OWASP standards. MITRE ATT&CK Integration: Specifically mapped to initial access and credential access techniques. Federal & Global Compliance: Native reporting for NIST 800-53, WASC v2.0, and SOC2 Readiness. Intelligence Isolation: AES-256 encryption-at-rest with total environment separation between scans. Use Cases: Industry Focus FinTech & Banking Secure portals protected by strict MFA and rotating session tokens. MeshaSec fulfills the identity handshake and audits deep behind the boundary without manual intervention. Enterprise SaaS Continuously map and secure multi-tenant dashboards and complex API surfaces that change daily. Our autonomous nodes scale with your deployment frequency About MeshaSec Headquartered in the global technology hub of Bengaluru, India. MeshaSec is committed to engineering the future of autonomous, identity-aware AppSec. We believe that security should be as agile as your code, and as deterministic as your logic. MeshaSec: Precision DAST for the Global Elite

Who Is the Company Behind MeshaSec?

  • Seller: MeshaSec
  • HQ Location: Bengaluru, Karnataka, India
  • LinkedIn® Page: linkedin.com
    1 employees on LinkedIn®

Mobix

Mobix is a SaaS mobile application testing platform that reduces application analysis costs and time, making tests creation and finding vulnerabilities effortless. Mobix's unique characteristics include: - Non-invasive tool, which augments existing SDLC (Software Development Life Cycle) - Automates 90% of the entire test coverage for dynamic and static analysis - No code, plug and play analysis - Automated recording of tests - Machine Learning to automatically adapt auto-tests - Scalable multithread testing, custom scan rules - Compliance to all major mobile security standards

Who Is the Company Behind Mobix?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024