Best Dynamic Application Security Testing (DAST) Software - Page 6

How Many Dynamic Application Security Testing (DAST) Software Products Does G2 Track?

Total Products under this Category: 98

Category Stats (Sep 2026)

  • Average Rating: 4.58/5 (↑0.02 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: TASKING Test & Verification Tools (+10.99%) - Among all products in this category, TASKING Test & Verification Tools recorded the largest rating increase compared to last month

Last updated: September 05, 2026

How Does G2 Rank Dynamic Application Security Testing (DAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 4,200+ Authentic Reviews
  • 98+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Dynamic Application Security Testing (DAST) Software

G2 Grid® for Dynamic Application Security Testing (DAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, Astra Pentest, Burp Suite, Invicti, Qodex.ai, Tenable Nessus, GitLab, and Harness Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/dynamic-application-security-testing-dast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=astra-pentest&focus%5B%5D=burp-suite&focus%5B%5D=invicti&focus%5B%5D=qodex-ai&focus%5B%5D=tenable-nessus&focus%5B%5D=gitlab&focus%5B%5D=harness-platform)

Nullify

The post-human product security program. Nullify continuously allocates AI capacity toward the highest-impact product security work, maximizing outcomes from every engineer hour and every token spent.

Who Is the Company Behind Nullify?

  • Seller: Nullify
  • Company Website:
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    27 employees on LinkedIn®

Outpost24 Application Security

Dynamic Application Security Testing for DevOps Frequent changes to applications, whether built by in-house DevOps teams or outsourced from commercial suppliers, means risk evaluation must shift towards continuous testing. Our Dynamic Application Security Testing (DAST) solution, provides critical assessments during the SDLC rapidly and efficiently with quick-and-easy configuration assessments. With an accessible REST API, Selenium integration, and automated reporting, Scale is designed to deliver the high-quality vulnerability findings needed to enable each iteration of the SDLC to confidently address issues before they are released to the next phase. 

Who Is the Company Behind Outpost24 Application Security?

Oversecured

Enterprise vulnerability scanner for Android and iOS apps. It offers app owners and developers the ability to secure each new version of a mobile app by integrating Oversecured into the development process.

Who Is the Company Behind Oversecured?

OWASP ZAP

Who Is the Company Behind OWASP ZAP?

  • Seller: OWASP
  • Year Founded: 2001
  • HQ Location: Wakefield, US
  • Twitter: @DependencyTrack
    1,436 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    686 employees on LinkedIn®

Panoptic Scans - Network and Application Vulnerability Scans

Panoptic Scans is a hosted vulnerability scanning platform designed to bolster cybersecurity for businesses by offering automated, comprehensive network and application vulnerability scans. Our platform empowers users to schedule vulnerability scans - daily, weekly, monthly, or annually - to ensure compliance with stringent regulations like SOC 2, HIPAA, ISO 27001, NIST 800-53, CMMC, and GDPR. Leveraging powerful tools such as OpenVAS for network vulnerabilities, OWASP ZAP for application security, and Nmap for port scanning, Panoptic Scans identifies weaknesses like unpatched software, misconfigurations, and open ports that could be exploited by cyber threats. With features like email notifications, detailed scan reports, and a user-friendly API, it simplifies vulnerability management, making it ideal for SaaS companies, security teams, and agile development environments aiming to safeguard sensitive data and maintain robust compliance effortlessly.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Panoptic Scans - Network and Application Vulnerability Scans?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • API / Integrations: 10.0/10 (Category avg: 8.7/10)
  • Detection Rate: 8.3/10 (Category avg: 8.8/10)
  • Test Automation: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Panoptic Scans - Network and Application Vulnerability Scans?

Who Uses This Product?

  • Company Size: 100% Medium

What Do G2 Reviewers Say About Panoptic Scans - Network and Application Vulnerability Scans?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the easy automation of scans with Panoptic Scans, enabling efficient SOC2 Vulnerability scanning and reporting.
  • Users value the automation capabilities of Panoptic Scans, simplifying SOC2 vulnerability scans and enhancing dashboard creation.
  • Users appreciate the easy automation of scans with Panoptic Scans, simplifying SOC2 Vulnerability management and reporting.
  • Users value the dashboard usability of Panoptic Scans, enhancing the ease of managing vulnerability assessments effectively.
  • Users appreciate the ease of use of Panoptic Scans, enabling effortless automation and actionable insights for security assessments.

What Are Recent G2 Reviews of Panoptic Scans - Network and Application Vulnerability Scans?

Proscan

Proscan is a unified application security platform designed to help organizations streamline the management of their security tools. By integrating multiple standalone solutions into a single cohesive experience, Proscan provides comprehensive security visibility across the entire software stack. This platform replaces the complexity of managing various tools for static analysis, dynamic testing, and dependency scanning, allowing teams to focus on building secure applications without the hassle of juggling disparate systems. The platform is particularly beneficial for security teams, developers, and engineering leaders who require a consolidated view of application security risks. Proscan combines nine specialized security scanners, including Static Application Security Testing (SAST), which analyzes source code in over 30 programming languages using advanced detection methods. Dynamic Application Security Testing (DAST) further enhances security by testing live applications, identifying vulnerabilities that may only become apparent during runtime. Additionally, Software Composition Analysis (SCA) evaluates open-source dependencies across 196 package ecosystems, helping organizations detect known vulnerabilities before they can impact production environments. Proscan's capabilities extend beyond code analysis. It includes scanning for hardcoded secrets, misconfigurations in Infrastructure-as-Code, and vulnerabilities in container images. The platform also offers API security testing that validates endpoints against the OWASP API Security Top 10, ensuring robust protection for applications that leverage APIs. For organizations developing AI-powered applications, Proscan features a dedicated AI and LLM security scanner that identifies potential risks associated with prompt injections and other vulnerabilities, utilizing over 4,600 techniques mapped to the OWASP LLM Top 10. Artificial intelligence plays a crucial role in enhancing Proscan's efficiency and accuracy. The platform employs machine-learning algorithms to reduce false positives and prioritize vulnerabilities based on their potential impact. This intelligent approach allows teams to focus on the most critical security issues while providing clear explanations and actionable remediation guidance. Proscan integrates seamlessly into existing development workflows, offering IDE plugins and native CI/CD integrations that ensure security checks are part of the development process without causing disruptions. Compliance readiness is another key feature of Proscan, as it generates audit-ready reports aligned with major security standards, including OWASP Top 10, PCI DSS, HIPAA, and GDPR. This automated evidence collection simplifies the compliance process, providing organizations with the necessary documentation in various formats. Proscan is designed for security teams looking to consolidate fragmented toolchains, developers needing quick feedback, and managed security service providers managing multiple client environments, making it a versatile solution for modern application security challenges.

Who Is the Company Behind Proscan?

ProtoCrawler

ProtoCrawler is an intelligent fuzz testing solution, used to identify security weaknesses and implementation bugs.

Who Is the Company Behind ProtoCrawler?

  • Seller: Cytal
  • Year Founded: 2020
  • HQ Location: Peterborough, GB
  • Twitter: @CyTAL_UK
    36 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    13 employees on LinkedIn®

PT Application Inspector

PT Application Inspector™ (PT AI™) is a comprehensive source code analysis tool that offers protection for web applications of any scale. Its holistic approach combines the advantages of static, dynamic, and interactive analysis to maintain application security throughout every stage of development—from the very first line of code to the go-live.

Average Rating: 5.0/5.0

Total Reviews: 2

How Do G2 Users Rate PT Application Inspector?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind PT Application Inspector?

Who Uses This Product?

  • Company Size: 67% Large, 33% Small

What Are Recent G2 Reviews of PT Application Inspector?

What Are G2 Users Discussing About PT Application Inspector?

Quokka Q-mast

Designed for app development, Q-mast embeds security directly into your workflow to identify security, privacy, and compliance risks before the mobile app is released. With a design tailored for DevSecOps workflows, Q-mast supports continuous, automated security testing that aligns with tools like Jenkins, GitLab, and GitHub. Q-mast capabilities: • Automated scanning in minutes, no source code needed • Analysis of compiled app binary, regardless of in-app or run-time obfuscations • Precise SBOM generation and analysis for vulnerability reporting to specific library version, including embedded libraries • Comprehensive static (SAST), dynamic (DAST), interactive (IAST), and forced-path execution app analysis • Malicious behavior profiling, including app collusion • Checks against privacy & security standards: NIAP, NIST, MASVS

Who Is the Company Behind Quokka Q-mast?

Red Cloud

With prooV Red Cloud, you can assess how technologies will react in the case of a cyberattack before you implement them It is a tailored, cloud-based environment that gives you the flexibility to carry out complex cybersecurity attacks on any type of software you are testing. You can use Red Cloud with the PoC Platform to include red team testing in your initial software testing and evaluation process, or you can use it on its own.

Who Is the Company Behind Red Cloud?

  • Seller: prooV
  • HQ Location: Herzaliya Pituach, IL
  • Twitter: @prooV_inc
    839 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    9 employees on LinkedIn®

SECURITY by HTTPCS

Detect security flaws in your website or web application and avoid being hacked. HTTPCS Security puts Machine Learning at the service of your cyber security to protect your site against hacking and data leaks.

Who Is the Company Behind SECURITY by HTTPCS?

  • Seller: HTTPCS by Ziwit
  • Year Founded: 2011
  • HQ Location: Montpellier, FR
  • Twitter: @httpcs
    2,812 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    27 employees on LinkedIn®

Sn1per Professional

Sn1per Professional is an all-in-one offensive security platform that provides a comprehensive view of your internal and external attack surface and offers an asset risk scoring system to prioritize, reduce, and manage risk. With Sn1per Professional, you can discover the attack surface and continuously monitor it for changes. It integrates with the leading open source and commercial security testing tools for a unified view of your data.

Average Rating: 4.5/5.0

Total Reviews: 1

Who Is the Company Behind Sn1per Professional?

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Sn1per Professional?

Sparrow DAST

Sparrow DAST is a dynamic application security testing solution designed to identify and address security vulnerabilities in web applications. By automatically crawling subdirectories from a web application's URL, it detects potential security flaws, ensuring comprehensive coverage. The solution adheres to global security compliance standards such as OWASP Top 10 and CWE, enhancing software security and quality. Through event-based attack process simulations, Sparrow DAST enables users to quickly understand and mitigate web hacking processes, thereby preventing potential breaches. Key Features: - Automated Vulnerability Detection: Automatically crawls web application URLs to detect security vulnerabilities. - Comprehensive Coverage: Ensures compliance with global security standards like OWASP Top 10 and CWE. - Attack Process Simulation: Reproduces vulnerability attack processes through events, aiding in quick identification and understanding of web hacking methods. - Web-Based User Interface: Eliminates the need for installation, offering easy access via a web browser and centralized management of analysis results. - Powerful Analysis: Utilizes browser event replay technology to detect security vulnerabilities and analyzes open-source web libraries for potential issues. - Integration Support: Overcomes limitations of dynamic analysis through interaction with Sparrow SAST and RASP, providing IAST capability via the TrueScan function. - Detailed Analysis Reports: Provides clear vulnerability information, trends, and detailed reports with analysis methods, results, and solutions for each vulnerability. - Support for Latest Web Technologies: Analyzes web applications using technologies like HTML5 and AJAX, detecting vulnerabilities by reproducing various browser events. - Multi-User Optimization: Allows setting permissions and roles per user, with centralized management and sharing of analysis results among users. Primary Value and User Solutions: Sparrow DAST offers continuous protection of web applications from external attacks by thoroughly analyzing and identifying security vulnerabilities. Its automated detection and comprehensive coverage ensure that applications comply with global security standards, enhancing both security and quality. The solution's user-friendly interface and detailed reporting facilitate quick understanding and remediation of vulnerabilities, empowering organizations to maintain robust and secure web applications.

Who Is the Company Behind Sparrow DAST?

Topscan

Topscan is a continuous security monitoring platform for the DevOps engineer or CTO who owns security among other things. It covers the whole delivery pipeline in one subscription — static analysis in your code, dynamic scanning of live applications and infrastructure, and continuous monitoring of everything you expose to the internet — instead of three separate vendors for SAST, DAST and attack surface management. Perimeter. External infrastructure scanning reports open ports, service versions and known server vulnerabilities matched against CVE databases, with unlimited scheduled rescans. Asset discovery maps the subdomains and hosts you forgot about — the Grafana, the Sentry, the staging box nobody remembers deploying — and new hosts arrive with a review prompt: you confirm ownership before anything is scanned. Attack surface monitoring keeps every exposed service inventoried, and certificate watch catches TLS/SSL expiry weeks early instead of on the Friday night it happens. Applications and code. Web application scanning runs OWASP-class checks against live apps: SQL injection, XSS, exposed admin panels, default credentials, missing headers. Static application security testing covers three kinds of risk in one scan — vulnerable code patterns, committed secrets and keys, and known CVEs in dependencies (software composition analysis) — on every commit, pointing at the exact file and line. Pipeline and cloud. A CI/CD webhook gives you a unique event link to call from the last step of your deploy script: no API keys, no agent, nothing installed on your servers. AWS connects with keys you issue to discover EC2 and Route 53 resources, which are added to monitoring and rescanned when they change. Workflow. Findings are deduplicated and carry severity in your context, CVSS, a first-seen date and an SLA clock with overdue flags. Snooze what you accept, mark false positives and they stop resurfacing, and work through a large backlog in triage mode. Informational findings stay out of the feed and never touch your score. One security score tracks the whole estate over time — the number you show yourself, your CEO or an auditor. Alerts reach the team in Slack or Microsoft Teams and turn into Jira tickets; chat and tracker routing starts on the Advanced plan. Audit and compliance. Auditors ask for evidence of regular scanning and an inventory of what is exposed: scan history with downloadable reports and an exportable asset inventory answer both, which is what most teams use Topscan for ahead of SOC 2, ISO 27001 or a customer security review. Auditor seats are free and read-only, and users are unlimited on every plan. Pricing starts at $129 per month and is published on the site — no demo call required to see it — with a 14-day free trial of the full plan and no credit card. Add a domain and the first map of your perimeter arrives in five to ten minutes.

Who Is the Company Behind Topscan?

  • Seller: Topscan
  • Year Founded: 2024
  • HQ Location: Dubai, AE
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Topscan?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024