Best Penetration Testing Tools - Page 4

How Many Penetration Testing Tools Products Does G2 Track?

Total Products under this Category: 172

Category Stats (Sep 2026)

  • Average Rating: 4.64/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 26, 2026

How Does G2 Rank Penetration Testing Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,800+ Authentic Reviews
  • 172+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Penetration Testing Tools

G2 Grid® for Penetration Testing Tools plotting products by satisfaction and market presence

Highlighted products: vPenTest, Cobalt, Astra Pentest, Oneleet, Pentera, NodeZero from Horizon3.ai, H1 Platform, and Bugcrowd.

Underlying data: [Grid® JSON](https://www.g2.com/categories/penetration-testing-tools/grids.json?focus%5B%5D=vpentest&focus%5B%5D=cobalt-io-cobalt&focus%5B%5D=astra-pentest&focus%5B%5D=oneleet&focus%5B%5D=pentera&focus%5B%5D=nodezero-from-horizon3-ai&focus%5B%5D=h1-platform&focus%5B%5D=bugcrowd)

ZAP by Checkmarx

ZAP by Checkmarx, formerly known as Zed Attack Proxy , is a leading open-source web application security scanner designed to help developers, testers, and security professionals identify vulnerabilities in web applications. Actively maintained by a global community, ZAP offers both automated and manual testing capabilities, making it suitable for users with varying levels of security expertise. Key Features and Functionality: - Automated Security Scanning: ZAP provides simple, single-click automated scanning, enabling users to identify security flaws with ease. - Active and Passive Scanning: Utilizes both passive and active scanning techniques to uncover a wide range of security vulnerabilities. - Advanced User Controls: Offers tools like manual interception, fuzzing, and forced browsing for thorough penetration testing. - CI/CD Integration: Seamlessly integrates with Continuous Integration/Continuous Deployment pipelines, automating security testing within development workflows. - Cross-Platform Support: Compatible with Linux, Windows, and macOS operating systems. Primary Value and Problem Solved: ZAP by Checkmarx addresses the critical need for accessible and effective web application security testing. By offering a free, open-source solution with both automated and manual testing capabilities, ZAP empowers organizations to identify and remediate vulnerabilities early in the development lifecycle. Its integration with CI/CD pipelines ensures that security becomes an integral part of the development process, reducing the risk of security breaches and enhancing overall application security.

Average Rating: 4.7/5.0

Total Reviews: 13

How Do G2 Users Rate ZAP by Checkmarx?

  • Performance and Reliability: 8.9/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.4/10 (Category avg: 9.2/10)
  • Extensibility: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind ZAP by Checkmarx?

  • Seller: Checkmarx
  • Year Founded: 2006
  • HQ Location: Paramus, NJ
  • Twitter: @Checkmarx
    7,284 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    997 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 71% Small, 14% Medium

What Do G2 Reviewers Say About ZAP by Checkmarx?

AI-generated summary from verified user reviews

Pros
  • Users find ZAP's ease of use exceptional, making it perfect for both beginners and experienced security researchers.
  • Users appreciate the advanced automation features of ZAP, making web application security scanning efficient and user-friendly.
  • Users praise ZAP's exceptional automated testing features, highlighting its effectiveness in vulnerability assessments and integrations.
  • Users highlight the easy integrations with CI/CD tools, enhancing automation and usability for seamless development workflows.
  • Users find ZAP by Checkmarx enhances pentesting efficiency with its user-friendly interface and comprehensive automation features.
Cons
  • Users experience false positives that require manual intervention, complicating the review process for findings.
  • Users find the poor documentation for ZAP by Checkmarx lacking, especially during error troubleshooting.
  • Users note the limited automation scope in ZAP, lacking new features compared to other web pen testing tools.
  • Users often face navigation problems due to insufficient documentation and support, complicating their experience with ZAP.
  • Users express frustration over poor customer support and lack of documentation for ZAP by Checkmarx.

What Are Recent G2 Reviews of ZAP by Checkmarx?

AppSec Labs

AppSec Labs is an application security company that does one thing: penetration testing of software-based systems — web applications, REST and GraphQL APIs, mobile apps, and the AI features increasingly built into them. We are software engineers who specialise in attacking software, which is why we find the flaws that require understanding a system rather than scanning it: broken authorization, multi-tenant isolation failures, business logic and workflow abuse. Testing is human-led, accelerated by our own platform, CybeRapid. Reports are written for the engineers who have to fix the problem — reproduction steps, real impact and concrete remediation — and every reported finding is retested after the fix, as part of the engagement.

Average Rating: 4.4/5.0

Total Reviews: 46

How Do G2 Users Rate AppSec Labs?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.4/10)

Who Is the Company Behind AppSec Labs?

  • Seller: AppSec Labs
  • Year Founded: 2010
  • HQ Location: Kfar Saba, Israel
  • Twitter: @AppSecLabs
    219 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    15 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 48% Small, 33% Medium

What Are Recent G2 Reviews of AppSec Labs?

Veracode Application Security Platform

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

Average Rating: 3.8/5.0

Total Reviews: 25

How Do G2 Users Rate Veracode Application Security Platform?

  • Has the product been a good partner in doing business?: 7.9/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.8/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.8/10 (Category avg: 9.2/10)
  • Extensibility: 7.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Veracode Application Security Platform?

  • Seller: VERACODE
  • Year Founded: 2006
  • HQ Location: Burlington, MA
  • Twitter: @Veracode
    21,950 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    500 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 69% Large, 31% Medium

What Do G2 Reviewers Say About Veracode Application Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the effective security vulnerability identification offered by Veracode, enhancing overall application safety and code integrity.
  • Users find Veracode's vulnerability detection excellent for identifying security issues and ensuring high application security standards.
  • Users value the automated scanning of Veracode, streamlining security checks and enhancing code quality effortlessly.
  • Users value the effective detection of security vulnerabilities, enabling robust protection and streamlined development processes.
  • Users appreciate the ease of integration with GitHub and CI/CD pipelines, streamlining their development process effectively.
Cons
  • Users find Veracode to be expensive, with high costs, complex licensing, and unfulfilled feature delivery.
  • Users face a lack of information due to mismatches in documentation and delayed notifications during uploads.
  • Users express concerns over licensing issues, including rising costs, complex models, and unequal feature availability.
  • Users report poor customer support with pushy account executives and difficulties in resolving issues efficiently.
  • Users express concerns about pricing issues, with rising costs and a complex licensing model affecting value perception.

What Are Recent G2 Reviews of Veracode Application Security Platform?

What Are G2 Users Discussing About Veracode Application Security Platform?

sql map

sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers.

Average Rating: 4.0/5.0

Total Reviews: 12

How Do G2 Users Rate sql map?

  • Has the product been a good partner in doing business?: 5.0/10 (Category avg: 9.4/10)

Who Is the Company Behind sql map?

  • Seller: sql map
  • HQ Location: N/A
  • Twitter: @pypi
    23,230 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 71% Medium, 29% Large

What Are Recent G2 Reviews of sql map?

What Are G2 Users Discussing About sql map?

NowSecure

NowSecure Inc., based in Oak Park, Illinois, was formed in 2009 with a mission to advance mobile security worldwide. We help secure mobile devices, enterprises and mobile apps.

Average Rating: 4.6/5.0

Total Reviews: 27

How Do G2 Users Rate NowSecure?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.4/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)
  • Extensibility: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind NowSecure?

  • Seller: NowSecure
  • Year Founded: 2009
  • HQ Location: Chicago, Illinois
  • Twitter: @nowsecuremobile
    6,372 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    101 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 41% Medium, 37% Large

What Are Recent G2 Reviews of NowSecure?

What Are G2 Users Discussing About NowSecure?

ZeroThreat

ZeroThreat Inc. is an AI-driven cybersecurity innovator dedicated to transforming how modern enterprises protect their web applications and APIs through its advanced platform. We empower organizations, from fast-growing startups to global enterprises, to stay ahead of evolving threats by delivering continuous, attacker-style penetration testing at the speed of modern development. Our mission is to eliminate the noise and complexity of traditional application security. By pioneering an Agentic AI engine and automated penetration testing platform, ZeroThreat.ai enables security teams to automate complex manual processes, reducing manual pentesting effort by 90% while achieving a 99.9% accuracy rate. It doesn't just scan for vulnerabilities. It validates real-world attack paths and provides audit-ready evidence, ensuring that organizations in highly regulated sectors such as Fintech, Healthcare, and Government can scale securely and maintain compliance. ZeroThreat.ai bridges the gap between developers and security teams by providing proof-based findings and actionable remediation guidance. We are committed to restoring developer trust through non-destructive, intelligent validation that focuses exclusively on exploitable risks, allowing businesses to ship software up to 10x faster without compromising security.

Average Rating: 4.8/5.0

Total Reviews: 10

How Do G2 Users Rate ZeroThreat?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.2/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.2/10)
  • Extensibility: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind ZeroThreat?

Who Uses This Product?

  • Company Size: 50% Large, 30% Medium

What Do G2 Reviewers Say About ZeroThreat?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of ZeroThreat, enjoying smooth integration and a user-friendly interface for security management.
  • Users value the real-time vulnerability detection of ZeroThreat, enhancing security without disrupting workflow and reducing false positives.
  • Users commend the accuracy of results from ZeroThreat, significantly reducing false positives and enhancing security efficiency.
  • Users appreciate the setup ease of ZeroThreat, enabling quick integration into existing workflows without complications.
  • Users appreciate the easy setup of ZeroThreat, allowing quick integration and immediate security scanning in their workflow.
Cons
  • Users find the inefficient filtering in ZeroThreat's reporting section makes locating specific results unnecessarily time-consuming.
  • Users experience integration issues with ZeroThreat, finding it challenging to connect with DevOps tools and proprietary software.
  • Users feel that the limited integrations with other tools hinder a more seamless experience with ZeroThreat.
  • Users report slow performance in ZeroThreat, with lagging features and longer loading times affecting productivity.
  • Users note that the UX improvement in ZeroThreat is needed for better navigation, filtering, and faster loading times.

What Are Recent G2 Reviews of ZeroThreat?

Reflectiz

Reflectiz is the AI-powered web exposure company trusted by hundreds of global organizations, including DAZN, Cox Communications, Village Roadshow, and Leeds United, to continuously monitor everything that executes on their live websites. Rather than scanning code or configuration, Reflectiz watches real browser execution, the actual scripts, pixels, and third and fourth-party tools running in front of your users, and applies AI to flag malicious behavior, unauthorized data flows, and compliance gaps the moment they appear. Reflectiz is built around four hubs that all run on this same engine. Security Hub continuously monitors every script and library executing on your site, catching Magecart-style skimming, supply chain attacks, and AI-generated threats that firewalls and perimeter tools were never built to see. Privacy Hub verifies that user data is only collected and shared the way your consent banner promises, supporting GDPR, CCPA, HIPAA, and PIPEDA. Offensive Hub runs continuous, agentic penetration testing, using AI agents to map applications and validate exploitable risks at up to 10x the capacity of manual pentesting. PCI Module automates PCI DSS 4.0.1 Requirements 6.4.3 and 11.6.1 with audit-ready evidence. Together, the four hubs give Security, Privacy, Compliance, and Digital teams one 360-degree view of web risk instead of four disconnected tools and reports. Reflectiz operates entirely remotely through its proprietary sandbox browser, with zero code changes, zero agents, and no access to sensitive data, typically going live within one business day. Its Exposure Rating draws on an intelligence database built from monitoring millions of websites, and the platform has been recognized with a 2026 Fortress Cyber Security Award, a 2025 Top InfoSec Innovator award, and G2 High Performer status. Customers frequently cite fast, hands-off onboarding and responsive support alongside a growing library of published case studies across e-commerce, financial services, and entertainment.

Average Rating: 4.7/5.0

Total Reviews: 32

How Do G2 Users Rate Reflectiz?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.4/10)

Who Is the Company Behind Reflectiz?

  • Seller: Reflectiz
  • Company Website:
  • Year Founded: 2016
  • HQ Location: Ramat Gan, IL
  • Twitter: @_Reflectiz_
    2,192 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    62 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Large, 34% Medium

What Do G2 Reviewers Say About Reflectiz?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the powerful vulnerability management tools of Reflectiz, enhancing security awareness and risk mitigation.
  • Users value the ongoing alerts from Reflectiz, ensuring efficient compliance and enhanced security management.
  • Users commend the ease of use of Reflectiz, highlighting its simple deployment and efficient risk management capabilities.
  • Users value Reflectiz for its instant visibility and intuitive monitoring, significantly enhancing security management and compliance.
  • Users value the real-time monitoring capabilities of Reflectiz, enhancing security and quickly identifying web threats.
Cons
  • Users find Reflectiz expensive, as training costs and higher prices limit affordability for smaller enterprises.
  • Users find the product complexity necessitates training, restricting affordability for smaller businesses and startups.
  • Users find that insufficient training increases costs, limiting Reflectiz's affordability for smaller businesses.
  • Users find a lack of clarity in script approval processes, complicating the integration with end-user delivery systems.
  • Users find that the learning difficulty of Reflectiz adds extra costs, limiting affordability for smaller companies.

What Are Recent G2 Reviews of Reflectiz?

What Are G2 Users Discussing About Reflectiz?

AppSecure Security

AppSecure Security is a CREST-accredited offensive security company specializing in Red Teaming, Penetration Testing (Pentesting), and Vulnerability Assessment and Penetration Testing (VAPT). We deliver hacker-focused security assessments to help businesses understand their security posture and protect against real-world cyber threats. Our expert team employs cutting-edge, real-world hacking techniques to evaluate your organization’s security posture, identify critical security vulnerabilities, and work with your team to remediate them effectively. Backed by elite security researchers with proven expertise in leading bug bounty programs like PayPal, Reddit, LinkedIn, Instacart, and more, AppSecure Security is your trusted partner in safeguarding your business from evolving cyber threats.

Average Rating: 4.9/5.0

Total Reviews: 7

How Do G2 Users Rate AppSecure Security?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.3/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.2/10)
  • Extensibility: 8.7/10 (Category avg: 8.8/10)

Who Is the Company Behind AppSecure Security?

  • Seller: AppSecure
  • Year Founded: 2015
  • HQ Location: Bengaluru, India
  • Twitter: @AppSecure
    347 Twitter followers
  • LinkedIn® Page: in.linkedin.com
    14 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 63% Medium, 38% Small

What Do G2 Reviewers Say About AppSecure Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the clear interface of AppSecure Security, making it easy to manage and track security issues.
  • Users value the comprehensive solutions offered by AppSecure Security, effectively addressing diverse security challenges in digital environments.
  • Users appreciate the customizable security options of AppSecure Security, allowing tailored solutions for diverse security needs.
  • Users value the real-time monitoring of AppSecure Security, which effectively enhances protection against emerging threats.
  • Users appreciate the detailed reporting of AppSecure Security, which provides actionable insights for effective security management.
Cons
  • Users find the initial setup complex, particularly challenging for smaller teams without cybersecurity expertise.
  • Users find the initial setup complex, making it challenging for beginners and smaller teams without cybersecurity expertise.
  • Users find the high learning curve of AppSecure Security challenging, especially for teams lacking cybersecurity expertise.
  • Users find the initial setup complex, making it challenging for smaller teams without cybersecurity expertise.

What Are Recent G2 Reviews of AppSecure Security?

ImmuniWeb AI Platform

The ImmuniWeb AI Platform helps over 1,000 enterprise customers from more than 50 countries to test, secure and protect their web and mobile applications, APIs and microservices, cloud and networks, to prevent data breaches and reduce third-party risk, and to comply with regulatory requirements. ImmuniWeb’s products available on the Platform include Continuous Threat Exposure Management (CTEM), External Attack Surface Management (EASM), Dark Web Monitoring and phishing websites takedown, as well as vulnerability scanning and penetration testing for web and mobile apps, cloud and network infrastructure, and LLM models. Headquartered in Geneva, Switzerland, ImmuniWeb has offices in Washington, London and Dubai to provide an uninterrupted service to all global customers and partners.

Average Rating: 4.7/5.0

Total Reviews: 12

How Do G2 Users Rate ImmuniWeb AI Platform?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.4/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)
  • Extensibility: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind ImmuniWeb AI Platform?

  • Seller: ImmuniWeb
  • Year Founded: 2019
  • HQ Location: Geneva, CH
  • Twitter: @immuniweb
    8,473 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    32 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 92% Medium, 8% Small

What Do G2 Reviewers Say About ImmuniWeb AI Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the effective vulnerability detection of ImmuniWeb AI Platform, significantly improving security and compliance efforts.
  • Users commend the responsive customer support, which offers prompt assistance and enhances the overall scanning experience.
  • Users value the continuous monitoring of the attack surface, ensuring proactive awareness of critical security issues.
  • Users value the continuous monitoring efficiency of ImmuniWeb AI Platform, ensuring proactive security and reducing potential losses.
  • Users value the alert notifications for keeping them informed about critical security issues and protecting their assets.
Cons
  • Users find the complexity of target scans leads to uncertain scanning times, complicating the overall experience.
  • Users face integration issues as ImmuniWeb AI Platform lacks connections with tools like Slack and PagerDuty.
  • Users find the lack of integration with Slack and PagerDuty complicates on-call support and accessibility after hours.
  • Users find the Excel export limited, which affects their data handling capabilities compared to the full JSON export.
  • Users note the limited flexibility in the algorithm for cost calculation, though improvements have been made.

What Are Recent G2 Reviews of ImmuniWeb AI Platform?

What Are G2 Users Discussing About ImmuniWeb AI Platform?

PentestPad

PentestPad is a penetration testing reporting platform used by offensive security consultancies, managed security service providers, and in-house red teams to manage engagements end-to-end and deliver client-ready reports. Testers create projects, capture findings with evidence and CVSS scoring, and collaborate in a shared editor where an AI assistant drafts finding descriptions, impact statements, and remediation guidance based on the vulnerability context already entered. Existing DOCX report templates can be imported and rebuilt inside PentestPad at no additional cost, so consultancies retain their established report style rather than adopt a vendor template. Scanner output from Nessus, Burp Suite, Nuclei, and custom feeds can be imported directly into a project, and finished reports export to DOCX, PDF, and XLSX. It consolidates project planning, collaborative finding management, AI-assisted report writing, and client delivery into a single web application. PentestPad is available as a managed EU-hosted cloud service and as a fully self-hosted installation for air-gapped and regulated environments. The AI assistant can be configured to use a self-hosted language model so client data never leaves the customer's infrastructure. PentestPad is ISO 27001 certified, GDPR compliant, EU-hosted by default, and priced publicly per seat.

Average Rating: 5.0/5.0

Total Reviews: 7

How Do G2 Users Rate PentestPad?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)
  • Extensibility: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind PentestPad?

Who Uses This Product?

  • Company Size: 86% Small, 14% Medium

What Are Recent G2 Reviews of PentestPad?

PlexTrac

PlexTrac is the leading AI-powered platform for pentest reporting and threat exposure management, trusted by Fortune 500 companies and top security providers. Built to help cybersecurity teams continuously manage and reduce threat exposure, PlexTrac centralizes security data, streamlines reporting, prioritizes risk, and automates remediation workflows—empowering teams to drive measurable risk reduction. The platform is ideal for enterprises & service providers looking to deliver a Continuous Threat Exposure Management (CTEM) framework across their business. With our suite of solutions, you can consolidate security data from tools and manual testing, automatically prioritize risks based on business impact, and automate remediation and retesting workflows for ongoing, more effective threat management.

Average Rating: 4.8/5.0

Total Reviews: 15

How Do G2 Users Rate PlexTrac?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 0.0/10 (Category avg: 9.2/10)
  • Extensibility: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind PlexTrac?

  • Seller: PlexTrac
  • Company Website:
  • Year Founded: 2016
  • HQ Location: Boise, Idaho
  • Twitter: @plextrac
    1,648 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    84 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Consulting
  • Company Size: 40% Small, 40% Large

What Do G2 Reviewers Say About PlexTrac?

AI-generated summary from verified user reviews

Pros
  • Users praise the intuitive and customizable platform of PlexTrac, enhancing efficiency in security reporting and collaboration.
  • Users praise the exceptional customer support from PlexTrac, noting their responsiveness and willingness to assist with inquiries.
  • Users find PlexTrac's ease of use beneficial, thanks to its intuitive UI and seamless integration features.
  • Users appreciate the reporting efficiency of PlexTrac, enabling streamlined processes and enhanced organization in their workflow.
  • Users value the seamless integrations of PlexTrac, significantly enhancing efficiency in reporting and security assessments.
Cons
  • Users face missing features in PlexTrac's on-premise version compared to the SaaS offering, affecting overall functionality.
  • Users note that complexity in report formatting can be finicky, requiring extra effort for optimal results.
  • Users find the complex setup of PlexTrac challenging initially, requiring time to adapt before reaping its benefits.
  • Users find the difficult learning curve of PlexTrac challenging, despite the team's supporting availability.
  • Users seek improved reporting capabilities for Threat Hunting and Incident Response within PlexTrac to enhance usability.

What Are Recent G2 Reviews of PlexTrac?

AppSentinels

AppSentinels protects your APIs by securing the business logic that drives your operations. Continuous discovery, automated API pen testing, and real-time defense stop hidden threats before they disrupt your business, ensuring seamless, risk-free innovation without slowing development.

Average Rating: 4.9/5.0

Total Reviews: 10

How Do G2 Users Rate AppSentinels?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind AppSentinels?

  • Seller: AppSentinels
  • Year Founded: 2021
  • HQ Location: Boston , US
  • Twitter: @appsentinelsai
    122 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    49 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 60% Medium, 20% Small

What Do G2 Reviewers Say About AppSentinels?

AI-generated summary from verified user reviews

Pros
  • Users value the automated discovery of shadow and undocumented APIs, enhancing their API testing efficiency.
  • Users commend the responsive and knowledgeable support team behind AppSentinels, enhancing their overall user experience.
  • Users value the automated vulnerability detection, enhancing security through smart API management and robust support.

What Are Recent G2 Reviews of AppSentinels?

Cytix

Cytix is the security decision layer for a world where software development never stops. It reads the context behind every ticket, pull request and release, and helps security, engineering and risk teams decide which software changes carry real risk, what response is proportionate, and what evidence to keep. Cytix already powers KPMG and NCC Group's continuous testing programme, turning software change into security decisions the business can stand behind.

Average Rating: 4.7/5.0

Total Reviews: 11

How Do G2 Users Rate Cytix?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.7/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.4/10 (Category avg: 9.2/10)
  • Extensibility: 9.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Cytix?

  • Seller: Cytix
  • Year Founded: 2022
  • HQ Location: Manchester
  • LinkedIn® Page: www.linkedin.com
    25 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 55% Small, 36% Medium

What Do G2 Reviewers Say About Cytix?

AI-generated summary from verified user reviews

Pros
  • Users value the effortless automation of Cytix, enhancing triage efficiency and real-time code security analysis.
  • Users value the automated testing of Cytix, which enhances security through continuous real-time code analysis.
  • Users value the clear and actionable insights from Cytix, enhancing efficiency in addressing security issues seamlessly.
  • Users value the clear and actionable insights of Cytix, which enhance efficiency and integration in workflows.
  • Users praise the fantastic customer support of Cytix, highlighting their expertise and assistance during and after rollout.
Cons
  • Users find the confusing interface challenging initially, though it ultimately functions well.
  • Users find the difficult learning curve of Cytix challenging, especially for those unfamiliar with software navigation.
  • Users find Cytix to be expensive compared to traditional options, impacting budget considerations for security testing.
  • Users find that Cytix can generate false positives, causing extra work and frustration for developers.
  • Users find the limited customization of Cytix's workflows and templates restrictive for their specific needs.

What Are Recent G2 Reviews of Cytix?

Penti

Penti addresses the complex and costly problem of cybersecurity for SMEs with its AI-enhanced penetration testing platform. By blending cutting-edge AI with expert human oversight, Securily provides thorough, efficient, and affordable security assessments. This unique approach not only detects vulnerabilities but also guides remediation, helping businesses strengthen their defenses and comply with industry standards effortlessly.

Average Rating: 5.0/5.0

Total Reviews: 6

How Do G2 Users Rate Penti?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.2/10)
  • Extensibility: 8.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Penti?

  • Seller: Penti
  • Year Founded: 2025
  • HQ Location: Boca Raton, US
  • LinkedIn® Page: www.linkedin.com
    16 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Penti?

Escape

Escape automates the full offensive security lifecycle, multiplying the impact of every security engineer tenfold. Our key products: 1. Attack Surface Management: Discover and validate exposure of modern applications, APIs, and infrastructure from code to cloud. 2. Business-logic-aware DAST: Replace legacy DAST with business-logic-aware testing that improves over time and helps your team remediate real, exploitable vulnerabilities. 3. AI Pentesting: Replace manual pentest and bug bounty programs with a solution that scales. Escape is a customer-centric company, supporting more than 2000+ security teams worldwide, and we have the privilege of working with exceptional companies like Schibsted (Media), HealthEquity (Healthcare), Applied (InsurTech), Visma, Miro (Tech), DoubleVerify (AdTech), Thinkific (EdTech), and many others.

Average Rating: 4.9/5.0

Total Reviews: 10

How Do G2 Users Rate Escape?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)

Who Is the Company Behind Escape?

  • Seller: Escape
  • Company Website:
  • Year Founded: 2020
  • HQ Location: Paris, France
  • Twitter: @escapetechHQ
    345 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    76 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Small, 40% Medium

What Do G2 Reviewers Say About Escape?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Escape, praising its simple setup and seamless CI/CD integration.
  • Users love the easy integrations with Escape, facilitating smooth workflows and secure GraphQL endpoint checks.
  • Users appreciate the effective scanning technology of Escape, enhancing API security management and vulnerability detection.
  • Users value the strong API security features of Escape, ensuring effective management and detection of vulnerabilities.
  • Users commend Escape for its effective API security management, adeptly identifying various vulnerabilities, including overlooked business logic flaws.
Cons
  • Users find the complex setup of Escape can be a challenge, requiring adjustment to keep up with updates.
  • Users find difficult upgrades sometimes challenging, but appreciate the continuous improvements and security enhancements of the platform.
  • Users note the limited features currently offered, though improvements are promised based on active feedback and updates.
  • Users note missing features in Escape, yet appreciate the roadmap for updates and responsiveness to feedback.
  • Users find update issues occasionally challenging, though the overall tool benefits outweigh these minor inconveniences.

What Are Recent G2 Reviews of Escape?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated March 5, 2025