Top Free Penetration Testing Tools - Page 2

How Many Penetration Testing Tools Products Does G2 Track?

Total Products under this Category: 172

Category Stats (Oct 2026)

  • Average Rating: 4.64/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: CybaOps (+0.97%) - Among all products in this category, CybaOps recorded the largest rating increase compared to last month

Last updated: October 01, 2026

How Does G2 Rank Penetration Testing Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,800+ Authentic Reviews
  • 172+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Penetration Testing Tools

G2 Grid® for Penetration Testing Tools plotting products by satisfaction and market presence

Highlighted products: vPenTest, Cobalt, Astra Pentest, Oneleet, Pentera, NodeZero from Horizon3.ai, H1 Platform, and Bugcrowd.

Underlying data: [Grid® JSON](https://www.g2.com/categories/penetration-testing-tools/grids.json?focus%5B%5D=vpentest&focus%5B%5D=cobalt-io-cobalt&focus%5B%5D=astra-pentest&focus%5B%5D=oneleet&focus%5B%5D=pentera&focus%5B%5D=nodezero-from-horizon3-ai&focus%5B%5D=h1-platform&focus%5B%5D=bugcrowd)

Beagle Security

Beagle Security helps you identify vulnerabilities in your web applications, APIs, GraphQL and remediate them with actionable insights before hackers harm you in any manner. With Beagle Security, you can integrate automated penetration testing into your CI/CD pipeline to identify security issues earlier in your development lifecycle and ship safer web applications. Major features: - Checks your web apps & APIs for 3000+ test cases to find security loopholes - OWASP & SANS standards - Recommendations to address security issues - Security test complex web apps with login - Compliance reports (GDPR, HIPAA & PCI DSS) - Test scheduling - DevSecOps integrations - API integration - Team access - Integrations with popular tools like Slack, Jira, Asana, Trello & 100+ other tools

Average Rating: 4.7/5.0

Total Reviews: 85

How Do G2 Users Rate Beagle Security?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.7/10 (Category avg: 9.2/10)
  • Extensibility: 6.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Beagle Security?

  • Seller: Beagle Security
  • Year Founded: 2020
  • HQ Location: San Francisco, US
  • Twitter: @beaglesecure
    206 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    55 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO, Director
  • Top Industries: Marketing and Advertising, Information Technology and Services
  • Company Size: 91% Small, 7% Medium

What Do G2 Reviewers Say About Beagle Security?

AI-generated summary from verified user reviews

Pros
  • Users commend the attractive reporting of Beagle Security, finding it easy to configure and comprehensive.
  • Users appreciate the easy setup of Beagle Security, finding it efficient for quick and effective implementation.

What Are Recent G2 Reviews of Beagle Security?

What Are G2 Users Discussing About Beagle Security?

StackHawk

StackHawk is reimagining AppSec for AI-driven development, where applications are built faster than traditional AppSec tools can keep up. Our AppSec Intelligence Platform combines scalable runtime testing with complete attack surface discovery from source code. We integrate directly into development workflows and provide context-aware remediations to developers, enabling teams to find and fix exploitable vulnerabilities before they reach production. With real-time visibility and centralized program intelligence, AppSec teams can prioritize testing and fixing what matters. Companies like British Airways, ITV, and Norstella trust StackHawk to evaluate application risk, prove program value, and scale testing coverage to match development velocity.

Average Rating: 4.6/5.0

Total Reviews: 67

How Do G2 Users Rate StackHawk?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.2/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.2/10)
  • Extensibility: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind StackHawk?

  • Seller: StackHawk
  • Year Founded: 2019
  • HQ Location: Denver, CO
  • Twitter: @StackHawk
    1,137 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    28 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 46% Small, 35% Medium

What Do G2 Reviewers Say About StackHawk?

AI-generated summary from verified user reviews

Pros
  • Users value the easy integrations of StackHawk, facilitating seamless setups with major CI tools and configurations.
  • Users praise the excellent customer support from StackHawk, highlighting their responsiveness and helpfulness in addressing queries.
  • Users value the customizability of StackHawk, appreciating its flexibility and integration options for unique workflows.
  • Users find that StackHawk greatly enhances efficiency, enabling quicker identification and resolution of security vulnerabilities.
  • Users commend StackHawk for its scanning efficiency, enabling quick identification of vulnerabilities and seamless CI/CD integration.
Cons
  • Users find the complex setup challenging, particularly with the YAML configurations and onboarding processes for applications.
  • Users find the high learning curve of StackHawk challenging due to its complex scripting and setup process.
  • Users find StackHawk lacking features, specifically in API management and vulnerability reproducibility, hindering its usability.
  • Users find the limited scope of StackHawk restricts functionality and automation in vulnerability management.
  • Users find the setup complexity of StackHawk frustrating due to YAML configuration and onboarding challenges.

What Are Recent G2 Reviews of StackHawk?

What Are G2 Users Discussing About StackHawk?

Qodex.ai

Qodex is a continuous testing platform built for teams shipping software at AI speed. It runs real tests across APIs, browser UIs, and security workflows, and reviews pull requests with execution evidence instead of model guesses. Teams can create reusable HTTP and Playwright scenarios from plain-language briefs, OpenAPI or Swagger specifications, Postman collections, spreadsheets, and existing tests. Scenarios can run on demand, on schedules, in CI/CD, through webhooks, and on pull requests. Findings include failing requests and responses, browser screenshots, and the context needed to distinguish a product defect from a stale test or environment issue. Qodex helps engineering teams catch breaking changes earlier while keeping tests readable, editable, and owned by the team.

Average Rating: 4.9/5.0

Total Reviews: 60

How Do G2 Users Rate Qodex.ai?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)

Who Is the Company Behind Qodex.ai?

  • Seller: QodexAI
  • Year Founded: 2023
  • HQ Location: San Francisco, California
  • LinkedIn® Page: linkedin.com
    13 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 75% Small, 20% Medium

What Do G2 Reviewers Say About Qodex.ai?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Qodex.ai, enabling quick learning and efficient API testing for all skill levels.
  • Users appreciate the automation of testing in Qodex.ai, greatly reducing testing time and enhancing reliability.
  • Users value the easy interface for writing test cases, streamlining the testing process and enhancing efficiency.
  • Users appreciate the testing efficiency of Qodex.ai, streamlining the testing process and reducing shipment time significantly.
  • Users appreciate the effortless automation of Qodex.ai, which streamlines API testing and enhances team productivity.
Cons
  • Users note that the slow loading of the UI can hinder their experience and requires improvement.
  • Users find the poor documentation hampers their ability to fully utilize Qodex.ai's advanced features effectively.
  • Users report slow performance with Qodex.ai, noting delays in UI loading and chatbot response times.
  • Users report bug issues including repeated test cases, and suggest improvements in bug classification and accuracy.
  • Users report bugs related to test cases and suggest improvements for prioritizing and flagging issues effectively.

What Are Recent G2 Reviews of Qodex.ai?

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

Detectify

Detectify sets a new standard for advanced application security testing, challenging traditional DAST by providing evolving coverage of each and every exposed asset across the changing attack surface. AppSec teams trust Detectify to expose how attackers will exploit their Internet-facing applications. The Detectify platform automates continuous real-world, payload-based attacks fuelled by its global community of elite ethical hackers into its own expert-built engines, exposing critical weaknesses before it's too late. The Detectify solution includes: - Automated discovery of known and unknown digital assets via domain & cloud connectors - Continuous coverage (24/7) of every corner of the attack surface with dynamic testing. Not just predefined targets - 100% payload-based testing fuelled by elite ethical hackers for a high signal-to-noise ratio - Distributed coverage across an unmatched array of relevant technologies - Actionable remediation tips for software development teams - Team functionality to easily share reports - Powerful integrations platform to prioritize and triage vulnerability findings onward to development teams -Advanced API functionality -Capabilities to set custom attack surface security policies

Average Rating: 4.5/5.0

Total Reviews: 49

How Do G2 Users Rate Detectify?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.5/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.2/10)
  • Extensibility: 7.2/10 (Category avg: 8.8/10)

Who Is the Company Behind Detectify?

  • Seller: Detectify
  • Year Founded: 2013
  • HQ Location: Stockholm, Sweden
  • Twitter: @detectify
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    96 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 47% Small, 35% Medium

What Do G2 Reviewers Say About Detectify?

AI-generated summary from verified user reviews

Pros
  • Users praise Detectify for its automation capabilities, making security testing seamless and adaptable to existing workflows.
  • Users appreciate Detectify's automation testing capabilities, making security assessments easier and more efficient to manage.
  • Users appreciate the customizability of Detectify, enjoying its easy integration and tailored security testing options.
  • Users praise Detectify for its easy integration and comprehensive dynamic application security testing, enhancing security without complex setups.
  • Users value Detectify for its effective dynamic application security testing and seamless integration into existing workflows.
Cons
  • Users find the initial setup complex, which can create challenges in getting started with Detectify.
  • Users struggle with the complex queries in Detectify, which hinder understanding of the spidering outcomes and assessments.
  • Users find the complex setup of Detectify challenging, making initial use more difficult than expected.
  • Users find Detectify expensive when testing multiple sites, affecting its accessibility for wider use.
  • Users face inaccuracies in Detectify's spidering results, leading to uncertainty in thorough application assessments.

What Are Recent G2 Reviews of Detectify?

What Are G2 Users Discussing About Detectify?

Core Impact

Core Impact is an easy-to-use penetration testing tool with commercially developed and tested exploits that enables security teams to exploit security weaknesses, increase productivity, and improve efficiencies. With guided automation and certified exploits , this powerful penetration testing software enables you to safely test your environment using the same techniques as today's attackers. Core Impact gives you visibility into the effectiveness of your defenses and reveals where your most pressing risks exist in your environment. This enables you to assess your organization’s ability to detect, prevent, and respond to real-world, multi-staged threats against your infrastructure, applications, and people. Organizations can rely on Core Impact to measure their ability to identify attacks, track, and validate their effectiveness through a variety of approaches, including: - Demonstrating what vulnerabilities surfaced from scanners are truly exploitable, revealing how chains of exploitable vulnerabilities open paths to your organization’s mission-critical systems and assets. - Re-testing exploited systems to verify that remediation measures or compensating controls are effective and working. - Simplifying testing for new users by providing intuitive, step-by-step wizards and rapid penetration tests so they can automatically gather the information they need. - Deploying phishing campaigns for social engineering tests to discover which users are susceptible and what credentials can be harvested. Core Impact’s Key Features Include: · Guide Automation and Patented Agents · Certified Exploits · Reporting and Visibility · Programmable Self-Destruct & Error Prevention · Teaming, Automated Retesting, and Validation Core Impact is also interoperable with Vuln Scanners, like Fortra VM, and Red Team Tools such as Cobalt Strike and Outflank OST. View our product bundles https://www.coresecurity.com/products/bundles. Learn more at https://www.coresecurity.com/products/core-impact

Average Rating: 4.1/5.0

Total Reviews: 29

How Do G2 Users Rate Core Impact?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.1/10 (Category avg: 9.2/10)
  • Extensibility: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind Core Impact?

  • Seller: Fortra
  • Company Website:
  • Year Founded: 1982
  • HQ Location: Eden Prairie, Minnesota
  • Twitter: @fortraofficial
    2,773 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,784 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 37% Small, 33% Large

What Are Recent G2 Reviews of Core Impact?

What Are G2 Users Discussing About Core Impact?

Defendify All-In-One Cybersecurity Solution

Founded in 2017, Defendify is pioneering All-In-One Cybersecurity® for organizations with growing security needs, backed by experts offering ongoing guidance and support. Delivering multiple layers of protection, Defendify provides an all-in-one, easy-to-use platform designed to strengthen cybersecurity across people, process, and technology, continuously. With Defendify, organizations streamline cybersecurity assessments, testing, policies, training, detection, response & containment in one consolidated and cost-effective cybersecurity solution. 3 layers, 13 solutions, 1 platform, including: • Managed Detection & Response • Cyber Incident Response Plan • Cybersecurity Threat Alerts • Phishing Simulations • Cybersecurity Awareness Training • Cybersecurity Awareness Videos • Cybersecurity Awareness Posters & Graphics • Technology Acceptable Use Policy • Cybersecurity Risk Assessments • Penetration Testing • Vulnerability Scanning • Compromised Password Scanning • Website Security Scanning See Defendify in action at www.defendify.com.

Average Rating: 4.7/5.0

Total Reviews: 57

How Do G2 Users Rate Defendify All-In-One Cybersecurity Solution?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.8/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.7/10 (Category avg: 9.2/10)
  • Extensibility: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Defendify All-In-One Cybersecurity Solution?

  • Seller: Defendify
  • Year Founded: 2017
  • HQ Location: Portland, Maine
  • Twitter: @defendify
    305 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    36 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 65% Small, 35% Medium

What Do G2 Reviewers Say About Defendify All-In-One Cybersecurity Solution?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Defendify, streamlining cybersecurity management for small and medium-sized businesses.
  • Users praise Defendify for its comprehensive and cost-effective cybersecurity features, streamlining management for small to medium-sized businesses.
  • Users appreciate the easy setup of Defendify, finding it quick and simple for effective cybersecurity management.
  • Users value the ease of use of Defendify, appreciating quick setup and actionable insights for cybersecurity management.
  • Users value the continuous monitoring features of Defendify, easing the burden of network security management significantly.
Cons
  • Users note that inadequate reporting hinders effective communication, calling for improvements in clarity and detail.
  • Users feel that the poor reporting features hinder effective communication and internal analysis of cybersecurity efforts.
  • Users express frustration over the lack of concise information in reports, preferring clearer and more detailed summaries.
  • Users find the limited customization options restrictive, wishing for more personalized reporting and branding capabilities.
  • Users desire custom reporting options and co-branding features to enhance the personalization of their experience.

What Are Recent G2 Reviews of Defendify All-In-One Cybersecurity Solution?

What Are G2 Users Discussing About Defendify All-In-One Cybersecurity Solution?

Appknox

Appknox is an on-demand mobile application security platform that helps businesses detect and fix security vulnerabilities using an Automated Security Testing suite. We have been successfully reducing delivery timelines, manpower costs & mitigating security threats for Global Banks and Enterprises in 10 + countries.

Average Rating: 4.4/5.0

Total Reviews: 41

How Do G2 Users Rate Appknox?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.7/10 (Category avg: 9.2/10)
  • Extensibility: 9.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Appknox?

  • Seller: Appknox
  • Year Founded: 2014
  • HQ Location: Singapore, Singapore
  • Twitter: @appknox
    3,055 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    84 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 41% Small, 36% Medium

What Are Recent G2 Reviews of Appknox?

What Are G2 Users Discussing About Appknox?

ZAP by Checkmarx

ZAP by Checkmarx, formerly known as Zed Attack Proxy , is a leading open-source web application security scanner designed to help developers, testers, and security professionals identify vulnerabilities in web applications. Actively maintained by a global community, ZAP offers both automated and manual testing capabilities, making it suitable for users with varying levels of security expertise. Key Features and Functionality: - Automated Security Scanning: ZAP provides simple, single-click automated scanning, enabling users to identify security flaws with ease. - Active and Passive Scanning: Utilizes both passive and active scanning techniques to uncover a wide range of security vulnerabilities. - Advanced User Controls: Offers tools like manual interception, fuzzing, and forced browsing for thorough penetration testing. - CI/CD Integration: Seamlessly integrates with Continuous Integration/Continuous Deployment pipelines, automating security testing within development workflows. - Cross-Platform Support: Compatible with Linux, Windows, and macOS operating systems. Primary Value and Problem Solved: ZAP by Checkmarx addresses the critical need for accessible and effective web application security testing. By offering a free, open-source solution with both automated and manual testing capabilities, ZAP empowers organizations to identify and remediate vulnerabilities early in the development lifecycle. Its integration with CI/CD pipelines ensures that security becomes an integral part of the development process, reducing the risk of security breaches and enhancing overall application security.

Average Rating: 4.7/5.0

Total Reviews: 13

How Do G2 Users Rate ZAP by Checkmarx?

  • Performance and Reliability: 8.9/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.4/10 (Category avg: 9.2/10)
  • Extensibility: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind ZAP by Checkmarx?

  • Seller: Checkmarx
  • Year Founded: 2006
  • HQ Location: Paramus, NJ
  • Twitter: @Checkmarx
    7,284 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    997 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 71% Small, 14% Large

What Do G2 Reviewers Say About ZAP by Checkmarx?

AI-generated summary from verified user reviews

Pros
  • Users find ZAP's ease of use exceptional, making it perfect for both beginners and experienced security researchers.
  • Users appreciate the advanced automation features of ZAP, making web application security scanning efficient and user-friendly.
  • Users praise ZAP's exceptional automated testing features, highlighting its effectiveness in vulnerability assessments and integrations.
  • Users highlight the easy integrations with CI/CD tools, enhancing automation and usability for seamless development workflows.
  • Users find ZAP by Checkmarx enhances pentesting efficiency with its user-friendly interface and comprehensive automation features.
Cons
  • Users experience false positives that require manual intervention, complicating the review process for findings.
  • Users find the poor documentation for ZAP by Checkmarx lacking, especially during error troubleshooting.
  • Users note the limited automation scope in ZAP, lacking new features compared to other web pen testing tools.
  • Users often face navigation problems due to insufficient documentation and support, complicating their experience with ZAP.
  • Users express frustration over poor customer support and lack of documentation for ZAP by Checkmarx.

What Are Recent G2 Reviews of ZAP by Checkmarx?

ZeroThreat

ZeroThreat Inc. is an AI-driven cybersecurity innovator dedicated to transforming how modern enterprises protect their web applications and APIs through its advanced platform. We empower organizations, from fast-growing startups to global enterprises, to stay ahead of evolving threats by delivering continuous, attacker-style penetration testing at the speed of modern development. Our mission is to eliminate the noise and complexity of traditional application security. By pioneering an Agentic AI engine and automated penetration testing platform, ZeroThreat.ai enables security teams to automate complex manual processes, reducing manual pentesting effort by 90% while achieving a 99.9% accuracy rate. It doesn't just scan for vulnerabilities. It validates real-world attack paths and provides audit-ready evidence, ensuring that organizations in highly regulated sectors such as Fintech, Healthcare, and Government can scale securely and maintain compliance. ZeroThreat.ai bridges the gap between developers and security teams by providing proof-based findings and actionable remediation guidance. We are committed to restoring developer trust through non-destructive, intelligent validation that focuses exclusively on exploitable risks, allowing businesses to ship software up to 10x faster without compromising security.

Average Rating: 4.8/5.0

Total Reviews: 10

How Do G2 Users Rate ZeroThreat?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.2/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.2/10)
  • Extensibility: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind ZeroThreat?

Who Uses This Product?

  • Company Size: 50% Large, 30% Small

What Do G2 Reviewers Say About ZeroThreat?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of ZeroThreat, enjoying smooth integration and a user-friendly interface for security management.
  • Users value the real-time vulnerability detection of ZeroThreat, enhancing security without disrupting workflow and reducing false positives.
  • Users commend the accuracy of results from ZeroThreat, significantly reducing false positives and enhancing security efficiency.
  • Users appreciate the setup ease of ZeroThreat, enabling quick integration into existing workflows without complications.
  • Users appreciate the easy setup of ZeroThreat, allowing quick integration and immediate security scanning in their workflow.
Cons
  • Users find the inefficient filtering in ZeroThreat's reporting section makes locating specific results unnecessarily time-consuming.
  • Users experience integration issues with ZeroThreat, finding it challenging to connect with DevOps tools and proprietary software.
  • Users feel that the limited integrations with other tools hinder a more seamless experience with ZeroThreat.
  • Users report slow performance in ZeroThreat, with lagging features and longer loading times affecting productivity.
  • Users note that the UX improvement in ZeroThreat is needed for better navigation, filtering, and faster loading times.

What Are Recent G2 Reviews of ZeroThreat?

Reflectiz

Reflectiz is the AI-powered web exposure company trusted by hundreds of global organizations, including DAZN, Cox Communications, Village Roadshow, and Leeds United, to continuously monitor everything that executes on their live websites. Rather than scanning code or configuration, Reflectiz watches real browser execution, the actual scripts, pixels, and third and fourth-party tools running in front of your users, and applies AI to flag malicious behavior, unauthorized data flows, and compliance gaps the moment they appear. Reflectiz is built around four hubs that all run on this same engine. Security Hub continuously monitors every script and library executing on your site, catching Magecart-style skimming, supply chain attacks, and AI-generated threats that firewalls and perimeter tools were never built to see. Privacy Hub verifies that user data is only collected and shared the way your consent banner promises, supporting GDPR, CCPA, HIPAA, and PIPEDA. Offensive Hub runs continuous, agentic penetration testing, using AI agents to map applications and validate exploitable risks at up to 10x the capacity of manual pentesting. PCI Module automates PCI DSS 4.0.1 Requirements 6.4.3 and 11.6.1 with audit-ready evidence. Together, the four hubs give Security, Privacy, Compliance, and Digital teams one 360-degree view of web risk instead of four disconnected tools and reports. Reflectiz operates entirely remotely through its proprietary sandbox browser, with zero code changes, zero agents, and no access to sensitive data, typically going live within one business day. Its Exposure Rating draws on an intelligence database built from monitoring millions of websites, and the platform has been recognized with a 2026 Fortress Cyber Security Award, a 2025 Top InfoSec Innovator award, and G2 High Performer status. Customers frequently cite fast, hands-off onboarding and responsive support alongside a growing library of published case studies across e-commerce, financial services, and entertainment.

Average Rating: 4.7/5.0

Total Reviews: 32

How Do G2 Users Rate Reflectiz?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.4/10)

Who Is the Company Behind Reflectiz?

  • Seller: Reflectiz
  • Company Website:
  • Year Founded: 2016
  • HQ Location: Ramat Gan, IL
  • Twitter: @_Reflectiz_
    2,192 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    62 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Large, 34% Medium

What Do G2 Reviewers Say About Reflectiz?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the powerful vulnerability management tools of Reflectiz, enhancing security awareness and risk mitigation.
  • Users value the ongoing alerts from Reflectiz, ensuring efficient compliance and enhanced security management.
  • Users commend the ease of use of Reflectiz, highlighting its simple deployment and efficient risk management capabilities.
  • Users value Reflectiz for its instant visibility and intuitive monitoring, significantly enhancing security management and compliance.
  • Users value the real-time monitoring capabilities of Reflectiz, enhancing security and quickly identifying web threats.
Cons
  • Users find Reflectiz expensive, as training costs and higher prices limit affordability for smaller enterprises.
  • Users find the product complexity necessitates training, restricting affordability for smaller businesses and startups.
  • Users find that insufficient training increases costs, limiting Reflectiz's affordability for smaller businesses.
  • Users find a lack of clarity in script approval processes, complicating the integration with end-user delivery systems.
  • Users find that the learning difficulty of Reflectiz adds extra costs, limiting affordability for smaller companies.

What Are Recent G2 Reviews of Reflectiz?

What Are G2 Users Discussing About Reflectiz?

ImmuniWeb AI Platform

The ImmuniWeb AI Platform helps over 1,000 enterprise customers from more than 50 countries to test, secure and protect their web and mobile applications, APIs and microservices, cloud and networks, to prevent data breaches and reduce third-party risk, and to comply with regulatory requirements. ImmuniWeb’s products available on the Platform include Continuous Threat Exposure Management (CTEM), External Attack Surface Management (EASM), Dark Web Monitoring and phishing websites takedown, as well as vulnerability scanning and penetration testing for web and mobile apps, cloud and network infrastructure, and LLM models. Headquartered in Geneva, Switzerland, ImmuniWeb has offices in Washington, London and Dubai to provide an uninterrupted service to all global customers and partners.

Average Rating: 4.7/5.0

Total Reviews: 12

How Do G2 Users Rate ImmuniWeb AI Platform?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.4/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)
  • Extensibility: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind ImmuniWeb AI Platform?

  • Seller: ImmuniWeb
  • Year Founded: 2019
  • HQ Location: Geneva, CH
  • Twitter: @immuniweb
    8,473 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    32 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 92% Medium, 8% Small

What Do G2 Reviewers Say About ImmuniWeb AI Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the effective vulnerability detection of ImmuniWeb AI Platform, significantly improving security and compliance efforts.
  • Users commend the responsive customer support, which offers prompt assistance and enhances the overall scanning experience.
  • Users value the continuous monitoring of the attack surface, ensuring proactive awareness of critical security issues.
  • Users value the continuous monitoring efficiency of ImmuniWeb AI Platform, ensuring proactive security and reducing potential losses.
  • Users value the alert notifications for keeping them informed about critical security issues and protecting their assets.
Cons
  • Users find the complexity of target scans leads to uncertain scanning times, complicating the overall experience.
  • Users face integration issues as ImmuniWeb AI Platform lacks connections with tools like Slack and PagerDuty.
  • Users find the lack of integration with Slack and PagerDuty complicates on-call support and accessibility after hours.
  • Users find the Excel export limited, which affects their data handling capabilities compared to the full JSON export.
  • Users note the limited flexibility in the algorithm for cost calculation, though improvements have been made.

What Are Recent G2 Reviews of ImmuniWeb AI Platform?

What Are G2 Users Discussing About ImmuniWeb AI Platform?

PentestPad

PentestPad is a penetration testing reporting platform used by offensive security consultancies, managed security service providers, and in-house red teams to manage engagements end-to-end and deliver client-ready reports. Testers create projects, capture findings with evidence and CVSS scoring, and collaborate in a shared editor where an AI assistant drafts finding descriptions, impact statements, and remediation guidance based on the vulnerability context already entered. Existing DOCX report templates can be imported and rebuilt inside PentestPad at no additional cost, so consultancies retain their established report style rather than adopt a vendor template. Scanner output from Nessus, Burp Suite, Nuclei, and custom feeds can be imported directly into a project, and finished reports export to DOCX, PDF, and XLSX. It consolidates project planning, collaborative finding management, AI-assisted report writing, and client delivery into a single web application. PentestPad is available as a managed EU-hosted cloud service and as a fully self-hosted installation for air-gapped and regulated environments. The AI assistant can be configured to use a self-hosted language model so client data never leaves the customer's infrastructure. PentestPad is ISO 27001 certified, GDPR compliant, EU-hosted by default, and priced publicly per seat.

Average Rating: 5.0/5.0

Total Reviews: 7

How Do G2 Users Rate PentestPad?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)
  • Extensibility: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind PentestPad?

Who Uses This Product?

  • Company Size: 86% Small, 14% Medium

What Are Recent G2 Reviews of PentestPad?

PlexTrac

PlexTrac is the leading AI-powered platform for pentest reporting and threat exposure management, trusted by Fortune 500 companies and top security providers. Built to help cybersecurity teams continuously manage and reduce threat exposure, PlexTrac centralizes security data, streamlines reporting, prioritizes risk, and automates remediation workflows—empowering teams to drive measurable risk reduction. The platform is ideal for enterprises & service providers looking to deliver a Continuous Threat Exposure Management (CTEM) framework across their business. With our suite of solutions, you can consolidate security data from tools and manual testing, automatically prioritize risks based on business impact, and automate remediation and retesting workflows for ongoing, more effective threat management.

Average Rating: 4.8/5.0

Total Reviews: 15

How Do G2 Users Rate PlexTrac?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 0.0/10 (Category avg: 9.2/10)
  • Extensibility: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind PlexTrac?

  • Seller: PlexTrac
  • Company Website:
  • Year Founded: 2016
  • HQ Location: Boise, Idaho
  • Twitter: @plextrac
    1,648 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    84 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Consulting
  • Company Size: 40% Large, 40% Small

What Do G2 Reviewers Say About PlexTrac?

AI-generated summary from verified user reviews

Pros
  • Users praise the intuitive and customizable platform of PlexTrac, enhancing efficiency in security reporting and collaboration.
  • Users praise the exceptional customer support from PlexTrac, noting their responsiveness and willingness to assist with inquiries.
  • Users find PlexTrac's ease of use beneficial, thanks to its intuitive UI and seamless integration features.
  • Users appreciate the reporting efficiency of PlexTrac, enabling streamlined processes and enhanced organization in their workflow.
  • Users value the seamless integrations of PlexTrac, significantly enhancing efficiency in reporting and security assessments.
Cons
  • Users face missing features in PlexTrac's on-premise version compared to the SaaS offering, affecting overall functionality.
  • Users note that complexity in report formatting can be finicky, requiring extra effort for optimal results.
  • Users find the complex setup of PlexTrac challenging initially, requiring time to adapt before reaping its benefits.
  • Users find the difficult learning curve of PlexTrac challenging, despite the team's supporting availability.
  • Users seek improved reporting capabilities for Threat Hunting and Incident Response within PlexTrac to enhance usability.

What Are Recent G2 Reviews of PlexTrac?

Cytix

Cytix is the security decision layer for a world where software development never stops. It reads the context behind every ticket, pull request and release, and helps security, engineering and risk teams decide which software changes carry real risk, what response is proportionate, and what evidence to keep. Cytix already powers KPMG and NCC Group's continuous testing programme, turning software change into security decisions the business can stand behind.

Average Rating: 4.7/5.0

Total Reviews: 11

How Do G2 Users Rate Cytix?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.7/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.4/10 (Category avg: 9.2/10)
  • Extensibility: 9.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Cytix?

  • Seller: Cytix
  • Year Founded: 2022
  • HQ Location: Manchester
  • LinkedIn® Page: www.linkedin.com
    25 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 55% Small, 36% Medium

What Do G2 Reviewers Say About Cytix?

AI-generated summary from verified user reviews

Pros
  • Users value the effortless automation of Cytix, enhancing triage efficiency and real-time code security analysis.
  • Users value the automated testing of Cytix, which enhances security through continuous real-time code analysis.
  • Users value the clear and actionable insights from Cytix, enhancing efficiency in addressing security issues seamlessly.
  • Users value the clear and actionable insights of Cytix, which enhance efficiency and integration in workflows.
  • Users praise the fantastic customer support of Cytix, highlighting their expertise and assistance during and after rollout.
Cons
  • Users find the confusing interface challenging initially, though it ultimately functions well.
  • Users find the difficult learning curve of Cytix challenging, especially for those unfamiliar with software navigation.
  • Users find Cytix to be expensive compared to traditional options, impacting budget considerations for security testing.
  • Users find that Cytix can generate false positives, causing extra work and frustration for developers.
  • Users find the limited customization of Cytix's workflows and templates restrictive for their specific needs.

What Are Recent G2 Reviews of Cytix?

Hexway Hive

Hexway is a full-cycle pentest reporting, automation, collaboration, and management platform. Simplify reporting by integrating tools, aggregating data during the project, collaborating with teammates, reducing time, and providing better pentest services with Hexway Pentest Suite.

Average Rating: 4.6/5.0

Total Reviews: 4

How Do G2 Users Rate Hexway Hive?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.6/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 7.5/10 (Category avg: 9.2/10)
  • Extensibility: 7.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Hexway Hive?

Who Uses This Product?

  • Company Size: 50% Medium, 50% Small

What Are Recent G2 Reviews of Hexway Hive?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated March 5, 2025