Best Penetration Testing Tools - Page 3

How Many Penetration Testing Tools Products Does G2 Track?

Total Products under this Category: 136

Category Stats (Aug 2026)

  • Average Rating: 4.64/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Cyver Core (+1.26%) - Among all products in this category, Cyver Core recorded the largest rating increase compared to last month

Last updated: August 05, 2026

How Does G2 Rank Penetration Testing Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,600+ Authentic Reviews
  • 136+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Penetration Testing Tools

G2 Grid® for Penetration Testing Tools plotting products by satisfaction and market presence

Highlighted products: Cobalt, vPenTest, Astra Pentest, Oneleet, NodeZero from Horizon3.ai, Bugcrowd, Verizon Penetration Testing, and H1 Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/penetration-testing-tools/grids.json?focus%5B%5D=cobalt-io-cobalt&focus%5B%5D=vpentest&focus%5B%5D=astra-pentest&focus%5B%5D=oneleet&focus%5B%5D=nodezero-from-horizon3-ai&focus%5B%5D=bugcrowd&focus%5B%5D=verizon-penetration-testing&focus%5B%5D=h1-platform)

Sponsored

Sprocket Security

By combining automation with expert-driven human testing, Sprocket Security delivers Continuous Penetration Testing to help businesses continuously validate their security posture and resilience. This innovative solution is tailored for organizations seeking to enhance their cybersecurity measures by proactively identifying vulnerabilities and assessing their defenses against potential threats. By employing a year-round testing methodology, Sprocket Security ensures that businesses remain vigilant and prepared in the ever-evolving landscape of cyber threats. The platform primarily targets organizations of all sizes that are committed to improving their security frameworks. Sprocket Security is particularly beneficial for IT and security teams that need to stay ahead of emerging attack techniques and adapt to changes in their IT structures. With features such as Attack Surface Management, Continuous Penetration Testing, and Adversary Simulation, Sprocket Security provides a comprehensive suite of tools that empower businesses to prioritize offensive security measures effectively. One of the key features of Sprocket Security is its Attack Surface Management, which allows organizations to gain visibility into their digital assets and potential vulnerabilities. By continuously monitoring and analyzing the attack surface, businesses can identify weak points before they are exploited by malicious actors. Additionally, the platform offers Continuous Penetration Testing, which simulates real-world attack scenarios to evaluate the effectiveness of existing security controls. This ongoing testing approach ensures that organizations can adapt their defenses in response to new threats and vulnerabilities. Another significant aspect of Sprocket Security is its commitment to retesting. Whenever a new attack technique emerges, a change occurs in the IT infrastructure, or a finding is patched, Sprocket Security provides unlimited retests at no additional cost. This feature not only enhances the overall security posture of an organization but also fosters a culture of continuous improvement and vigilance. By prioritizing offensive security, businesses can reduce their IT risk and enhance their resilience against cyber threats. Overall, Sprocket Security stands out in the cybersecurity landscape by offering a robust and flexible solution that integrates both automated and human-driven testing methodologies. This unique combination allows organizations to maintain a proactive stance against cyber threats, ensuring that their security measures evolve in tandem with the dynamic nature of the digital landscape.

Visit website

APPCHECK

AppCheck is a Dynamic Application Security Testing (DAST) and network vulnerability testing solution, developed and supported by experienced penetration testers. We approach security testing as a hacker would, leveraging multiple proprietary crawling engines to analyse target behaviour across both modern and traditional technologies, including Single Page Applications (SPAs), APIs, and complex authentication flows such as SSO, 2FA, and TOTP. Organisations can conduct unlimited security assessments across Web Applications, SPAs, APIs, cloud services, networks, across internal or external assets. Supporting production and UAT testing, AppCheck also helps organisations ‘shift left’ by integrating with CI/CD pipelines and build servers, including ADO, GitHub, Jenkins, TeamCity, CircleCI, TravisCI, Bamboo, and GitLab CI/CD. Allowing automated security testing throughout development, identifying risks as soon as changes are introduced. AppCheck are proud to be part of the CVE Numbering Authority (CNA), contributing to global security research

Average Rating: 4.6/5.0

Total Reviews: 67

How Do G2 Users Rate APPCHECK?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.3/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.5/10 (Category avg: 9.1/10)
  • Extensibility: 8.3/10 (Category avg: 8.7/10)

Who Is the Company Behind APPCHECK?

  • Seller: APPCHECK
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Leeds, GB
  • Twitter: @AppcheckNG
    649 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    106 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 49% Medium, 30% Small

What Do G2 Reviewers Say About APPCHECK?

AI-generated summary from verified user reviews

Pros
  • Users highlight the effective vulnerability detection of AppCheck, which outshines competitors in thoroughness and ease of use.
  • Users find the ease of use of AppCheck invaluable, simplifying complex security processes effectively and efficiently.
  • Users appreciate the excellent pricing and functionality of AppCheck, enhancing their vulnerability management and reporting capabilities.
  • Users commend AppCheck for its exceptional pentesting efficiency, significantly enhancing vulnerability detection and streamlining security processes.
  • Users appreciate the automated scanning of AppCheck, benefiting from detailed reports and seamless integration with CI/CD pipelines.
Cons
  • Users find the poor customer support frustrating, as they must submit tickets for simple changes.
  • Users feel that UX improvement is necessary, particularly in scoring systems, customization, and starting points for scans.
  • Users find the API endpoint changes cumbersome, relying on service requests instead of having direct control.
  • Users find difficult customization options in AppCheck, limiting the ability to tailor reports and vulnerability scoring.
  • Users note a significant difficult learning curve with Appcheck, which can hinder initial usability and efficiency.

What Are Recent G2 Reviews of APPCHECK?

Pynt - API Security Testing

Pynt is an innovative API Security Testing platform exposing verified API threats through simulated attacks. Hundreds of companies rely on Pynt to continuously monitor, classify and attack poorly secured APIs, before hackers do.

Average Rating: 4.8/5.0

Total Reviews: 44

How Do G2 Users Rate Pynt - API Security Testing?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.2/10 (Category avg: 9.1/10)
  • Extensibility: 8.8/10 (Category avg: 8.7/10)

Who Is the Company Behind Pynt - API Security Testing?

  • Seller: Pynt
  • Year Founded: 2022
  • HQ Location: Tel Aviv, IL
  • Twitter: @pynt_io
    361 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    16 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Computer & Network Security
  • Company Size: 57% Small, 23% Large

What Do G2 Reviewers Say About Pynt - API Security Testing?

AI-generated summary from verified user reviews

Pros
  • Users commend Pynt for its auto-generation of security tests, making vulnerability detection accessible for all development teams.
  • Users commend Pynt for its impressive security engine that effectively identifies critical API vulnerabilities quickly.
  • Users value the seamless integration of Pynt into CI/CD pipelines for automated API security testing and vulnerability identification.
  • Users appreciate the easy integration of Pynt with their SDLC, enhancing automated API security without disrupting workflows.
  • Users highlight the automation capabilities of Pynt, streamlining API security tasks and enhancing efficiency in development workflows.
Cons
  • Users find the complex setup of Pynt challenging, often requiring support which complicates the initial experience.
  • Users find the setup complexity challenging, often needing support and seeking a more user-friendly interface.
  • Users experience limited features in Pynt, particularly in reporting, dashboard options, and onboarding processes for complex APIs.
  • Users find the user interface challenging, especially beginners who struggle with navigation and setup.
  • Users find the user interface challenging, suggesting improvements for a more user-friendly experience in Pynt.

What Are Recent G2 Reviews of Pynt - API Security Testing?

Breachlock

BreachLock is a global leader in Continuous Attack Surface Discovery and Penetration Testing. Continuously discover, prioritize, and mitigate exposures with evidence-backed Attack Surface Management, Penetration Testing and Red Teaming. Elevate your defense strategy with an attacker’s view that goes beyond common vulnerabilities and exposures. Each risk we uncover is backed by validated evidence. We test your entire attack surface and help you mitigate your next cyber breach before it occurs. Know your risk. Contact BreachLock today!

Average Rating: 4.6/5.0

Total Reviews: 38

How Do G2 Users Rate Breachlock?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.7/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.9/10 (Category avg: 9.1/10)
  • Extensibility: 7.6/10 (Category avg: 8.7/10)

Who Is the Company Behind Breachlock?

  • Seller: Breachlock
  • Company Website:
  • Year Founded: 2019
  • HQ Location: New York, NY
  • Twitter: @BreachLock
    274 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    125 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 53% Small, 39% Medium

What Do G2 Reviewers Say About Breachlock?

AI-generated summary from verified user reviews

Pros
  • Users commend Breachlock for their excellent customer support, noting quick responses and helpful interactions during testing.
  • Users appreciate the excellent communication from Breachlock, making the penetration testing process smooth and efficient.
  • Users appreciate the ease of use of Breachlock, making compliance and security testing straightforward and efficient.
  • Users value the detailed vulnerability information from Breachlock, enabling proactive security measures and clear remediation paths.
  • Users value the efficiency of Breachlock's penetration testing, appreciating their thoroughness and ease of collaboration throughout the process.
Cons
  • Users face challenges with high false positives, complicating the accuracy of vulnerability tracking and resolution efforts.
  • Users find the poor interface design of Breachlock hinders effective tracking and increases frustration due to false positives.
  • Users feel Breachlock is expensive, as prices remain high even with discounts, impacting overall value perception.
  • Users feel that the inadequate reporting lacks polish, affecting the presentation of information to customers.
  • Users find the lack of detail in Breachlock's reports leads to confusion and extensive back-and-forth support.

What Are Recent G2 Reviews of Breachlock?

Qodex.ai

Qodex is a continuous testing platform that runs your test scenarios against your real app on every pull request and deploy, then shows you exactly what broke with the failing request, response, and screenshot.

Average Rating: 4.9/5.0

Total Reviews: 60

How Do G2 Users Rate Qodex.ai?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)

Who Is the Company Behind Qodex.ai?

  • Seller: QodexAI
  • Company Website:
  • Year Founded: 2023
  • HQ Location: San Francisco, California
  • LinkedIn® Page: linkedin.com
    13 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 75% Small, 20% Medium

What Do G2 Reviewers Say About Qodex.ai?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Qodex.ai, making it accessible for both technical and non-technical teams.
  • Users value the automation capabilities of Qodex.ai, significantly enhancing efficiency in managing API testing processes.
  • Users value the ease of test case writing with Qodex.ai, enhancing efficiency for developers and product managers.
  • Users value the high testing efficiency of Qodex.ai, achieving 90% code coverage with minimal manual effort.
  • Users find Qodex.ai incredibly helpful for quick integration and effective scenario analysis, boosting efficiency significantly.
Cons
  • Users experience slow loading times with the chatbot and reports, affecting overall efficiency and responsiveness.
  • Users find the poor documentation a barrier to fully leverage Qodex.ai’s capabilities in advanced testing scenarios.
  • Users experience slow performance with delayed chatbot responses and longer load times for reports on larger projects.
  • Users report bug issues including repeated test cases and suggest improvements for bug reporting and flagging accuracy.
  • Users report bug reporting issues, suggesting improvements for tagging and accuracy of critical and non-critical bugs.

What Are Recent G2 Reviews of Qodex.ai?

Core Impact

Core Impact is an easy-to-use penetration testing tool with commercially developed and tested exploits that enables security teams to exploit security weaknesses, increase productivity, and improve efficiencies. With guided automation and certified exploits , this powerful penetration testing software enables you to safely test your environment using the same techniques as today's attackers. Core Impact gives you visibility into the effectiveness of your defenses and reveals where your most pressing risks exist in your environment. This enables you to assess your organization’s ability to detect, prevent, and respond to real-world, multi-staged threats against your infrastructure, applications, and people. Organizations can rely on Core Impact to measure their ability to identify attacks, track, and validate their effectiveness through a variety of approaches, including: - Demonstrating what vulnerabilities surfaced from scanners are truly exploitable, revealing how chains of exploitable vulnerabilities open paths to your organization’s mission-critical systems and assets. - Re-testing exploited systems to verify that remediation measures or compensating controls are effective and working. - Simplifying testing for new users by providing intuitive, step-by-step wizards and rapid penetration tests so they can automatically gather the information they need. - Deploying phishing campaigns for social engineering tests to discover which users are susceptible and what credentials can be harvested. Core Impact’s Key Features Include: · Guide Automation and Patented Agents · Certified Exploits · Reporting and Visibility · Programmable Self-Destruct & Error Prevention · Teaming, Automated Retesting, and Validation Core Impact is also interoperable with Vuln Scanners, like Fortra VM, and Red Team Tools such as Cobalt Strike and Outflank OST. View our product bundles https://www.coresecurity.com/products/bundles. Learn more at https://www.coresecurity.com/products/core-impact

Average Rating: 4.1/5.0

Total Reviews: 29

How Do G2 Users Rate Core Impact?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.1/10 (Category avg: 9.1/10)
  • Extensibility: 8.6/10 (Category avg: 8.7/10)

Who Is the Company Behind Core Impact?

  • Seller: Fortra
  • Company Website:
  • Year Founded: 1982
  • HQ Location: Eden Prairie, Minnesota
  • Twitter: @fortraofficial
    2,773 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,755 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 37% Small, 33% Large

What Are Recent G2 Reviews of Core Impact?

What Are G2 Users Discussing About Core Impact?

Beagle Security

Beagle Security helps you identify vulnerabilities in your web applications, APIs, GraphQL and remediate them with actionable insights before hackers harm you in any manner. With Beagle Security, you can integrate automated penetration testing into your CI/CD pipeline to identify security issues earlier in your development lifecycle and ship safer web applications. Major features: - Checks your web apps & APIs for 3000+ test cases to find security loopholes - OWASP & SANS standards - Recommendations to address security issues - Security test complex web apps with login - Compliance reports (GDPR, HIPAA & PCI DSS) - Test scheduling - DevSecOps integrations - API integration - Team access - Integrations with popular tools like Slack, Jira, Asana, Trello & 100+ other tools

Average Rating: 4.7/5.0

Total Reviews: 85

How Do G2 Users Rate Beagle Security?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.7/10 (Category avg: 9.1/10)
  • Extensibility: 6.7/10 (Category avg: 8.7/10)

Who Is the Company Behind Beagle Security?

  • Seller: Beagle Security
  • Year Founded: 2020
  • HQ Location: San Francisco, US
  • Twitter: @beaglesecure
    206 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    50 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO, Director
  • Top Industries: Marketing and Advertising, Information Technology and Services
  • Company Size: 91% Small, 7% Medium

What Do G2 Reviewers Say About Beagle Security?

AI-generated summary from verified user reviews

Pros
  • Users praise the attractive reporting of Beagle Security, finding it easy to configure and comprehensive.
  • Users value the setup ease of Beagle Security, finding it straightforward and efficient to configure.

What Are Recent G2 Reviews of Beagle Security?

What Are G2 Users Discussing About Beagle Security?

StackHawk

StackHawk is reimagining AppSec for AI-driven development, where applications are built faster than traditional AppSec tools can keep up. Our AppSec Intelligence Platform combines scalable runtime testing with complete attack surface discovery from source code. We integrate directly into development workflows and provide context-aware remediations to developers, enabling teams to find and fix exploitable vulnerabilities before they reach production. With real-time visibility and centralized program intelligence, AppSec teams can prioritize testing and fixing what matters. Companies like British Airways, ITV, and Norstella trust StackHawk to evaluate application risk, prove program value, and scale testing coverage to match development velocity.

Average Rating: 4.6/5.0

Total Reviews: 67

How Do G2 Users Rate StackHawk?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.2/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.1/10)
  • Extensibility: 9.2/10 (Category avg: 8.7/10)

Who Is the Company Behind StackHawk?

  • Seller: StackHawk
  • Year Founded: 2019
  • HQ Location: Denver, CO
  • Twitter: @StackHawk
    1,137 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    30 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 46% Small, 35% Medium

What Do G2 Reviewers Say About StackHawk?

AI-generated summary from verified user reviews

Pros
  • Users value the easy integrations of StackHawk, enhancing CI/CD pipelines and streamlining the onboarding process.
  • Users commend StackHawk for its exceptional customer support, providing expert assistance and enhancing the overall user experience.
  • Users value the customizability of StackHawk, appreciating its flexibility and integration options for unique workflows.
  • Users find that StackHawk greatly enhances efficiency, enabling quicker identification and resolution of security vulnerabilities.
  • Users value the scanning efficiency of StackHawk, enabling faster and more effective security scanning processes.
Cons
  • Users find the complex setup process frustrating due to the lack of simplified documentation and time-consuming configurations.
  • Users face a high learning curve with StackHawk due to its complex setup and scripting requirements.
  • Users find StackHawk lacking features, especially in API management and intuitive setup, hindering vulnerability management.
  • Users note the limited scope of StackHawk, particularly regarding on-prem usage and automation capabilities.
  • Users find setup complexity frustrating, as extensive YAML config trials are necessary for effective onboarding and scans.

What Are Recent G2 Reviews of StackHawk?

What Are G2 Users Discussing About StackHawk?

Detectify

Detectify sets a new standard for advanced application security testing, challenging traditional DAST by providing evolving coverage of each and every exposed asset across the changing attack surface. AppSec teams trust Detectify to expose how attackers will exploit their Internet-facing applications. The Detectify platform automates continuous real-world, payload-based attacks fuelled by its global community of elite ethical hackers into its own expert-built engines, exposing critical weaknesses before it's too late. The Detectify solution includes: - Automated discovery of known and unknown digital assets via domain & cloud connectors - Continuous coverage (24/7) of every corner of the attack surface with dynamic testing. Not just predefined targets - 100% payload-based testing fuelled by elite ethical hackers for a high signal-to-noise ratio - Distributed coverage across an unmatched array of relevant technologies - Actionable remediation tips for software development teams - Team functionality to easily share reports - Powerful integrations platform to prioritize and triage vulnerability findings onward to development teams -Advanced API functionality -Capabilities to set custom attack surface security policies

Average Rating: 4.5/5.0

Total Reviews: 49

How Do G2 Users Rate Detectify?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.5/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.1/10)
  • Extensibility: 7.2/10 (Category avg: 8.7/10)

Who Is the Company Behind Detectify?

  • Seller: Detectify
  • Year Founded: 2013
  • HQ Location: Stockholm, Sweden
  • Twitter: @detectify
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    94 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 47% Small, 35% Medium

What Do G2 Reviewers Say About Detectify?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the automation capabilities of Detectify, enjoying seamless integration and tailored security testing processes.
  • Users value the easy automation and integration features of Detectify that enhance security testing efficiently.
  • Users value the customizability of Detectify, enabling easy integration and tailored security testing to fit diverse needs.
  • Users appreciate the easy integration and comprehensive features of Detectify for efficient security testing.
  • Users appreciate Detectify for its effective dynamic application security testing, ensuring comprehensive security without complex setups.
Cons
  • Users find the initial complexity of setting up Detectify to be a challenging aspect of the product.
  • Users find the complex queries in Detectify challenging, impacting clarity on spidering results and app assessment.
  • Users find the complex setup of Detectify to be a challenging start, impacting its usability for newcomers.
  • Users find Detectify to be expensive when testing multiple sites, impacting its affordability for small operations.
  • Users find inaccuracy in outcomes from Detectify's spidering, lacking clarity on app assessment completeness.

What Are Recent G2 Reviews of Detectify?

What Are G2 Users Discussing About Detectify?

OnSecurity

OnSecurity is a leading CREST-accredited penetration testing vendor based in the UK, dedicated to delivering high-impact, high-intelligence penetration testing services to businesses of all sizes. By simplifying the management and delivery of pentesting, we make it easier for organisations to enhance their security posture and mitigate risks, contributing to a safer, more secure digital environment for everyone. Pentesting, Vulnerability Scanning and Threat Intelligence all in one platform. Start your offensive cyber security journey today: https://www.onsecurity.io/

Average Rating: 4.9/5.0

Total Reviews: 36

How Do G2 Users Rate OnSecurity?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.8/10 (Category avg: 9.1/10)
  • Extensibility: 9.3/10 (Category avg: 8.7/10)

Who Is the Company Behind OnSecurity?

  • Seller: On Security
  • Year Founded: 2018
  • HQ Location: Bristol, GB
  • Twitter: @weareonsecurity
    1,338 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    56 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 64% Small, 31% Medium

What Are Recent G2 Reviews of OnSecurity?

What Are G2 Users Discussing About OnSecurity?

Appknox

Appknox is an on-demand mobile application security platform that helps businesses detect and fix security vulnerabilities using an Automated Security Testing suite. We have been successfully reducing delivery timelines, manpower costs & mitigating security threats for Global Banks and Enterprises in 10 + countries.

Average Rating: 4.5/5.0

Total Reviews: 40

How Do G2 Users Rate Appknox?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.7/10 (Category avg: 9.1/10)
  • Extensibility: 9.3/10 (Category avg: 8.7/10)

Who Is the Company Behind Appknox?

  • Seller: Appknox
  • Year Founded: 2014
  • HQ Location: Singapore, Singapore
  • Twitter: @appknox
    3,055 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    85 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 40% Small, 37% Medium

What Are Recent G2 Reviews of Appknox?

What Are G2 Users Discussing About Appknox?

BugBase

BugBase is a Continuous Vulnerability Assessment Platform that conducts comprehensive security operations such as bug bounty programs and next-gen pentesting (VAPT) to assist startups and enterprises in effectively identifying, managing and mitigating vulnerabilities.

Average Rating: 4.5/5.0

Total Reviews: 46

How Do G2 Users Rate BugBase?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.7/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.1/10 (Category avg: 9.1/10)
  • Extensibility: 8.2/10 (Category avg: 8.7/10)

Who Is the Company Behind BugBase?

  • Seller: BugBase
  • Year Founded: 2021
  • HQ Location: Singapore, US
  • Twitter: @BugBase
    1,673 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    45 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Computer Software
  • Company Size: 58% Small, 23% Large

What Do G2 Reviewers Say About BugBase?

AI-generated summary from verified user reviews

Pros
  • Users praise the ease of use of BugBase, making it ideal for new bug bounty hunters.
  • Users highlight the simple and user-friendly interface of BugBase, making it ideal for new bug bounty hunters.
  • Users value the strong cybersecurity measures of BugBase, enhancing data confidentiality and minimizing competition for rewards.
  • Users appreciate the user-friendly interface of BugBase, enabling seamless integration and effective security threat detection.
  • Users value the easy integrations of BugBase, facilitating seamless collaboration within diverse tools and technologies.
Cons
  • Users experience slow performance on BugBase, with freezing and lag hindering bug hunting and overall satisfaction.
  • Users find the pricing of BugBase to be expensive, lacking incentives compared to other bug bounty platforms.
  • Users find the difficult setup of BugBase challenging, particularly those lacking technical expertise and experience with bug bounty programs.
  • Users find the steep learning curve of BugBase challenging, especially those unfamiliar with bug bounty programs.
  • Users report poor customer support from BugBase, leading to slow responses and a frustrating experience during bug hunting.

What Are Recent G2 Reviews of BugBase?

Defendify All-In-One Cybersecurity Solution

Founded in 2017, Defendify is pioneering All-In-One Cybersecurity® for organizations with growing security needs, backed by experts offering ongoing guidance and support. Delivering multiple layers of protection, Defendify provides an all-in-one, easy-to-use platform designed to strengthen cybersecurity across people, process, and technology, continuously. With Defendify, organizations streamline cybersecurity assessments, testing, policies, training, detection, response & containment in one consolidated and cost-effective cybersecurity solution. 3 layers, 13 solutions, 1 platform, including: • Managed Detection & Response • Cyber Incident Response Plan • Cybersecurity Threat Alerts • Phishing Simulations • Cybersecurity Awareness Training • Cybersecurity Awareness Videos • Cybersecurity Awareness Posters & Graphics • Technology Acceptable Use Policy • Cybersecurity Risk Assessments • Penetration Testing • Vulnerability Scanning • Compromised Password Scanning • Website Security Scanning See Defendify in action at www.defendify.com.

Average Rating: 4.7/5.0

Total Reviews: 57

How Do G2 Users Rate Defendify All-In-One Cybersecurity Solution?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.8/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.7/10 (Category avg: 9.1/10)
  • Extensibility: 8.8/10 (Category avg: 8.7/10)

Who Is the Company Behind Defendify All-In-One Cybersecurity Solution?

  • Seller: Defendify
  • Year Founded: 2017
  • HQ Location: Portland, Maine
  • Twitter: @defendify
    305 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    37 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 65% Small, 35% Medium

What Do G2 Reviewers Say About Defendify All-In-One Cybersecurity Solution?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Defendify, streamlining cybersecurity management for organizations with limited resources.
  • Users praise Defendify for its comprehensive and cost-effective cybersecurity features, streamlining management for small and medium-sized businesses.
  • Users appreciate the easy setup of Defendify, making configuration and onboarding quick and efficient.
  • Users value the ease of use of Defendify, enabling quick setup and clear insights into cybersecurity posture.
  • Users value the continuous monitoring and ease of use of Defendify, enhancing their network security significantly.
Cons
  • Users note that the reporting is inadequate, desiring improvements like concise summaries and detailed penetration testing results.
  • Users feel the reporting could be improved, expressing a need for more concise and detailed reports.
  • Users feel the lack of information in reports diminishes clarity and thoroughness of penetration testing insights.
  • Users find the limited customization options restrictive, desiring more flexibility in reports and branding features.
  • Users find the lack of custom reporting options limits their ability to tailor insights for future needs.

What Are Recent G2 Reviews of Defendify All-In-One Cybersecurity Solution?

What Are G2 Users Discussing About Defendify All-In-One Cybersecurity Solution?

Hackrate Ethical Hacking Platform

Hackrate Ethical Hacking Platform is a crowdsourced security testing solution designed to connect businesses with ethical hackers in order to identify and remediate security vulnerabilities. By leveraging the expertise of a diverse pool of ethical hackers, Hackrate enables organizations to enhance their cybersecurity posture efficiently and effectively. The platform is tailored for businesses of all sizes, from startups to large enterprises, seeking to bolster their security measures. With the increasing frequency of cyber threats, organizations are recognizing the importance of proactive security testing. Hackrate facilitates this by allowing companies to tap into a global network of skilled ethical hackers who can provide insights and solutions to potential vulnerabilities. This collaborative approach not only accelerates the testing process but also enriches the quality of security assessments through varied perspectives and methodologies. One of the key features of Hackrate is its user-friendly interface, which simplifies the onboarding process for both businesses and ethical hackers. Companies can initiate security testing within hours, streamlining the process of vulnerability identification. This rapid deployment is critical for organizations that need to address security concerns promptly, especially in a fast-paced digital landscape. Furthermore, Hackrate offers flexible pricing plans, making it accessible for businesses with varying budgets and security needs. Security and confidentiality are paramount in the realm of cybersecurity, and Hackrate prioritizes these aspects by implementing robust encryption and adhering to industry-standard security protocols. This commitment ensures that sensitive data remains protected throughout the testing process, fostering trust between businesses and ethical hackers. By utilizing Hackrate, organizations can confidently engage in security testing without compromising their data integrity. Overall, Hackrate Ethical Hacking Platform stands out as a comprehensive solution for businesses aiming to enhance their security frameworks. By combining the expertise of ethical hackers with an efficient, secure platform, Hackrate offers a practical approach to identifying and addressing security vulnerabilities, ultimately contributing to a safer digital environment.

Average Rating: 4.9/5.0

Total Reviews: 35

How Do G2 Users Rate Hackrate Ethical Hacking Platform?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.7/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.9/10 (Category avg: 9.1/10)
  • Extensibility: 9.6/10 (Category avg: 8.7/10)

Who Is the Company Behind Hackrate Ethical Hacking Platform?

  • Seller: Hackrate
  • Year Founded: 2020
  • HQ Location: Budapest, HU
  • Twitter: @hackrate
    363 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    10 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 83% Small, 11% Large

What Do G2 Reviewers Say About Hackrate Ethical Hacking Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the supportive and knowledgeable communication from Hackrate, enhancing the collaborative atmosphere of the platform.
  • Users praise the highly motivated and skilled support team for their exceptional assistance and responsiveness.
  • Users appreciate the ease of use of Hackrate, enjoying its straightforward rules and responsive support team.
  • Users appreciate the expertise of Hackrate's founders, benefiting from their profound understanding of real-world ethical hacking.
  • Users value the guidance and expertise of Hackrate's skilled team, enhancing their cybersecurity project outcomes.
Cons
  • Users note the poor customer support during busy periods, leading to delays in assistance when needed most.
  • Users find the poor interface design of Hackrate challenging, as it lacks intuitive navigation and clear structure.

What Are Recent G2 Reviews of Hackrate Ethical Hacking Platform?

What Are G2 Users Discussing About Hackrate Ethical Hacking Platform?

ZAP by Checkmarx

ZAP by Checkmarx, formerly known as Zed Attack Proxy , is a leading open-source web application security scanner designed to help developers, testers, and security professionals identify vulnerabilities in web applications. Actively maintained by a global community, ZAP offers both automated and manual testing capabilities, making it suitable for users with varying levels of security expertise. Key Features and Functionality: - Automated Security Scanning: ZAP provides simple, single-click automated scanning, enabling users to identify security flaws with ease. - Active and Passive Scanning: Utilizes both passive and active scanning techniques to uncover a wide range of security vulnerabilities. - Advanced User Controls: Offers tools like manual interception, fuzzing, and forced browsing for thorough penetration testing. - CI/CD Integration: Seamlessly integrates with Continuous Integration/Continuous Deployment pipelines, automating security testing within development workflows. - Cross-Platform Support: Compatible with Linux, Windows, and macOS operating systems. Primary Value and Problem Solved: ZAP by Checkmarx addresses the critical need for accessible and effective web application security testing. By offering a free, open-source solution with both automated and manual testing capabilities, ZAP empowers organizations to identify and remediate vulnerabilities early in the development lifecycle. Its integration with CI/CD pipelines ensures that security becomes an integral part of the development process, reducing the risk of security breaches and enhancing overall application security.

Average Rating: 4.7/5.0

Total Reviews: 13

How Do G2 Users Rate ZAP by Checkmarx?

  • Performance and Reliability: 8.9/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.4/10 (Category avg: 9.1/10)
  • Extensibility: 8.8/10 (Category avg: 8.7/10)

Who Is the Company Behind ZAP by Checkmarx?

  • Seller: Checkmarx
  • Year Founded: 2006
  • HQ Location: Paramus, NJ
  • Twitter: @Checkmarx
    7,284 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,019 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 71% Small, 14% Medium

What Do G2 Reviewers Say About ZAP by Checkmarx?

AI-generated summary from verified user reviews

Pros
  • Users enjoy the easy integrations with CI/CD tools, enhancing automation and streamlining their workflows effectively.
  • Users find ZAP by Checkmarx enhances pentesting efficiency with its ease of use and comprehensive testing capabilities.
  • Users appreciate the customizable dashboards in ZAP, enhancing user experience and meeting specific testing needs.
  • Users appreciate the easy integration with CI/CD pipelines, enhancing workflow efficiency and automation in development processes.
  • Users love the customizable and user-friendly interface of ZAP, making penetration testing accessible to all.
Cons
  • Users report frequent false positives that require manual verification, complicating the effectiveness of ZAP by Checkmarx.
  • Users find the poor documentation frustrating, as it lacks support for troubleshooting errors effectively.
  • Users note the limited automated tasks in ZAP, lacking many features found in other web pen testing applications.
  • Users report facing navigation problems due to insufficient documentation and support for ZAP by Checkmarx.
  • Users report a lack of documentation and support, leading to frustrations and challenges while using ZAP by Checkmarx.

What Are Recent G2 Reviews of ZAP by Checkmarx?

AppSec Labs eLearning

AppSec Labs is an application security company that does one thing: penetration testing of software-based systems — web applications, REST and GraphQL APIs, mobile apps, and the AI features increasingly built into them. We are software engineers who specialise in attacking software, which is why we find the flaws that require understanding a system rather than scanning it: broken authorization, multi-tenant isolation failures, business logic and workflow abuse. Testing is human-led, accelerated by our own platform, CybeRapid. Reports are written for the engineers who have to fix the problem — reproduction steps, real impact and concrete remediation — and every reported finding is retested after the fix, as part of the engagement.

Average Rating: 4.4/5.0

Total Reviews: 46

How Do G2 Users Rate AppSec Labs eLearning?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.4/10)

Who Is the Company Behind AppSec Labs eLearning?

  • Seller: AppSec Labs
  • Year Founded: 2010
  • HQ Location: Kfar Saba, Israel
  • Twitter: @AppSecLabs
    219 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 48% Small, 33% Medium

What Are Recent G2 Reviews of AppSec Labs eLearning?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated March 5, 2025