Best Dynamic Application Security Testing (DAST) Software - Page 7

How Many Dynamic Application Security Testing (DAST) Software Products Does G2 Track?

Total Products under this Category: 98

Category Stats (Sep 2026)

  • Average Rating: 4.58/5 (↑0.02 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: TASKING Test & Verification Tools (+10.99%) - Among all products in this category, TASKING Test & Verification Tools recorded the largest rating increase compared to last month

Last updated: September 05, 2026

How Does G2 Rank Dynamic Application Security Testing (DAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 4,200+ Authentic Reviews
  • 98+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Dynamic Application Security Testing (DAST) Software

G2 Grid® for Dynamic Application Security Testing (DAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, Astra Pentest, Burp Suite, Invicti, Qodex.ai, Tenable Nessus, GitLab, and Harness Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/dynamic-application-security-testing-dast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=astra-pentest&focus%5B%5D=burp-suite&focus%5B%5D=invicti&focus%5B%5D=qodex-ai&focus%5B%5D=tenable-nessus&focus%5B%5D=gitlab&focus%5B%5D=harness-platform)

Traceable AI

Traceable is the industry’s leading API Security company that helps organizations protect their digital systems and assets in a cloud-first world where everything is interconnected. Traceable is the only intelligent and context-aware platform that powers complete API security. Security Posture Management: Traceable helps organizations dramatically improve their security posture with a real time, risk ranked catalog of all APIs in their ecosystem, conformance analysis, identification of shadow and orphaned APIs, and visibility of sensitive data flows. RunTime Threat Protection: Traceable observes user level transactions and applies mature machine learning algorithms to discover anomalous transactions, alert the security team, and block attacks at the user level. Threat management and analytics: Traceable helps organizations analyze attacks and incidents with its API data lake, which provides rich historical data of nominal and malicious traffic. API Security Testing throughout the SDLC: Traceable connects the security lifecycle together with the DevOps lifecycle providing automated API Security tests to be run within the CI pipeline. Digital Fraud Prevention: Traceable brings together its broad and deep data collection over time and cutting edge machine learning to identify fraud across all API transactions

Who Is the Company Behind Traceable AI?

  • Seller: Harness
  • Year Founded: 2018
  • HQ Location: San Francisco
  • Twitter: @HarnessWealth
    1,389 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,832 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services
  • Company Size: 5% Large

What Do G2 Reviewers Say About Traceable AI?

AI-generated summary from verified user reviews

Pros
  • Users find the customer support of Traceable AI exceptional, providing quick and helpful guidance for their inquiries.
  • Users value the exceptional security features of Traceable AI, effectively guarding API endpoints from vulnerabilities.
  • Users find Traceable AI's setup ease impressive, enabling quick deployment and immediate insights into API vulnerabilities.
  • Users appreciate the robust API management features of Traceable AI, enabling effective monitoring and protection of APIs.
  • Users value the flexibility and customization of Traceable AI, enhancing their API security experience significantly.
Cons
  • Users express a desire for more features and functionalities in Traceable AI, highlighting limitations in usability and customization.
  • Users find it challenging to manage false positives in Traceable AI, requiring more effort than expected.
  • Users experience inefficiency in the update process, incurring unnecessary costs and facing challenges with data handling and scaling.
  • Users find the poor documentation of Traceable AI challenging, hindering effective use and requiring additional support.
  • Users highlight the need for improved reporting capabilities, especially for historical data and larger scales.

Trickest Platform

Trickest provides an innovative approach to offensive cybersecurity automation, assets, and vulnerability discovery. The platform combines extensive adversary tactics and techniques with full transparency, hypercustomization, and hyperscalability, making it the go-to platform for offensive security operations. The Trickest platform comes with comprehensive tooling, scripting, managed infrastructure, scaling, ready-to-go solutions, and analytics, serving as a collaborative command center for Offensive Security, Penetration testing, Red teams, Security Analysts, and Security Service providers (MSSPs). What makes us different? Easy customization of logic, inputs, outputs, and integrations, making them adaptable to specific needs and thus producing superior-quality data compared to others. Some of the automation workflows and solutions that our customers deploy and execute: - Attack Surface Discovery - Vulnerability Scanning - Dynamic Application Security Testing (DAST) - Recon/Information Gathering (Passive & Active) - Organization OSINT - CVE scanning - Cloud Scanning - DNS recon & research - Subdomain Enumeration - Subdomain Takeover - Custom Security Automation and Orchestration Main components of the Trickest platform include: Solutions & Analytics - Ready-to-go and transparent solutions for Attack Surface Discovery, Vulnerability Scanning, Dynamic Application Security Testing (DAST), and Open-source intelligence OSINT, offering insight into every step of the process, easy customization, and Analytics on the top. The Builder - Access to 90+ workflow templates, 300+ open-source tools, Bash & Python scripting, CLI for building custom workflows to discover asset, vulnerabilities, scan network & apps, crawl, spider, enumerate, fuzz, bruteforce and much more. Hyperscalability - Whether scanning regional infrastructures with 100s of 1000s of assets or smaller organizational scopes, Trickest supports it all without per-asset costs.

Who Is the Company Behind Trickest Platform?

  • Seller: Trickest
  • Year Founded: 2020
  • HQ Location: Dover, US
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

TruStacks

TruStacks is a software delivery engine that offers standardized, efficient DevOps workflows to help teams ship products faster and more frequently.

Who Is the Company Behind TruStacks?

Vector

Vector is an AI-powered black-box vulnerability scanner. Point it at any web application and it autonomously discovers attack surfaces, tests for vulnerabilities across multiple categories, and generates detailed security reports with proof-of-concept exploits.

Who Is the Company Behind Vector?

we45

AppSec Testing(AST) - Whatever your motivation, a proactive security push or a compliance compulsion, our AST service can help keep your application secure against external threats. Security Automation - Secure your agile Software Development Life Cycle(SDLC) without compromising on quality or time. AppSec Training - Our numerous/variegated training offerings help product teams gain the security understanding necessary to keep their deployments secure. Orchestron - Make Application Security efficient with one of the most integral parts of a modern DevSecOps toolchain - An AVC engine. Threat PlayBook - A (relatively) Unopinionated framework that faciliates Threat Modeling as Code married with Application Security Automation on a single Fabric. Perform Iterative Threat Modeling in an Agile Environment with Threat Playbook.

Who Is the Company Behind we45?

  • Seller: we45
  • Year Founded: 2019
  • HQ Location: San Jose, US
  • LinkedIn® Page: www.linkedin.com
    37 employees on LinkedIn®

Web Application Scanning

A Key Part of Fortra (the new face of HelpSystems) Digital Defense is proud to be part of Fortra’s comprehensive cybersecurity portfolio. Fortra simplifies today’s complex cybersecurity landscape by bringing complementary products together to solve problems in innovative ways. These integrated, scalable solutions address the fast-changing challenges you face in safeguarding your organization. With the help of the powerful protection from Frontline Web Application Scanning and others, Fortra is your relentless ally, here for you every step of the way throughout your cybersecurity journey.

Who Is the Company Behind Web Application Scanning?

  • Seller: Fortra
  • Year Founded: 1982
  • HQ Location: Eden Prairie, Minnesota
  • Twitter: @fortraofficial
    2,773 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,784 employees on LinkedIn®

Web Application Security Testing

Ostorlab is an agentic security testing platform for web applications and APIs. Its AI agents authenticate, navigate multi-step workflows, observe application behavior, and adapt their testing based on what they discover. They follow attack paths across web interfaces and APIs to validate injection vulnerabilities, broken access controls, exposed secrets, insecure configurations, vulnerable dependencies, and business logic flaws—with reproducible evidence. Ostorlab supports APIs defined with OpenAPI and GraphQL, including authenticated and multi-step workflows. Beyond detection, teams can aggregate findings, route them through ticketing integrations, generate fixes with AI Autofix, monitor applications continuously, and validate remediation through retesting.

Who Is the Company Behind Web Application Security Testing?

  • Seller: Ostorlab
  • Year Founded: 2021
  • HQ Location: Middletown, US
  • Twitter: @OstorlabSec
  • LinkedIn® Page: www.linkedin.com
    31 employees on LinkedIn®

ZeroNorth

Continuous security delivery fabric for modern enterprise infrastructure.

Who Is the Company Behind ZeroNorth?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024