Best Static Application Security Testing (SAST) Software - Page 5

How Many Static Application Security Testing (SAST) Software Products Does G2 Track?

Total Products under this Category: 123

Category Stats (Oct 2026)

  • Average Rating: 4.54/5 (↓0.01 vs Sep 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: HCL AppScan (+0.7%) - Among all products in this category, HCL AppScan recorded the largest rating increase compared to last month

Last updated: October 01, 2026

How Does G2 Rank Static Application Security Testing (SAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,600+ Authentic Reviews
  • 123+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Application Security Testing (SAST) Software

G2 Grid® for Static Application Security Testing (SAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, GitGuardian, GitHub, GitLab, SonarQube, Snyk, Semgrep, and Checkmarx.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-application-security-testing-sast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=gitguardian&focus%5B%5D=github&focus%5B%5D=gitlab&focus%5B%5D=sonarqube&focus%5B%5D=snyk&focus%5B%5D=semgrep&focus%5B%5D=checkmarx)

Xanitizer

Xanitizer is the essential tool for security auditors. It specializes in security analysis of web applications and also considers the behavior of the applied web frameworks. Xanitizer investigates the code of an application for security vulnerabilities and also checks the server configuration files for misconfigurations. Xanitizer can easily be integrated into the CI/CD process, automatically and regularly checking the application code to prevent that security vulnerabilities are introduced into the production code.

Average Rating: 5.0/5.0

Total Reviews: 2

How Do G2 Users Rate Xanitizer?

  • Test Automation: 8.3/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.1/10)
  • Quality of Support: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind Xanitizer?

Who Uses This Product?

  • Company Size: 50% Medium, 50% Small

What Are Recent G2 Reviews of Xanitizer?

What Are G2 Users Discussing About Xanitizer?

AppSonar

AppSonar is a application security testing software created by CyberTest. It's main feature is static source code analyzer but also can analyze windows executable files for security and quality bugs.

Average Rating: 3.5/5.0

Total Reviews: 1

Who Is the Company Behind AppSonar?

Who Uses This Product?

  • Company Size: 100% Small

BlueClosure

The latest Minded Security Labs project regards JavaScript Security. We have released a tool called BlueClosure which helps security testers to analyze and discover Client Side security issues.

Average Rating: 3.5/5.0

Total Reviews: 1

How Do G2 Users Rate BlueClosure?

  • Test Automation: 8.3/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.1/10)
  • Source-Code Scanning: 10.0/10 (Category avg: 8.4/10)

Who Is the Company Behind BlueClosure?

Who Uses This Product?

  • Company Size: 100% Small

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

Bluesentinel

BlueSentinel develops secure code analysis technology that helps engineering teams identify vulnerabilities early and remediate them efficiently. The platform combines static application security testing, AI-assisted remediation, data-flow analysis, and developer-focused reporting to improve software security throughout the development lifecycle. Our goal is to make secure software development faster, more accurate, and more actionable for development and security teams.

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate Bluesentinel?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.1/10)
  • Quality of Support: 8.3/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 10.0/10 (Category avg: 8.4/10)

Who Is the Company Behind Bluesentinel?

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Bluesentinel?

Corgea

Corgea is the AI-native application security platform that finds the vulnerabilities your scanners miss, and ships verified fix PRs your developers actually merge. Full coverage across SAST, SCA, secrets, IaC, and containers, with 2x more true positives and 3x fewer false positives than legacy tools. Trusted by Zapier, epilot, Yageo, and and many others.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Corgea?

  • Seller: Corgea
  • Company Website:
  • Year Founded: 2023
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    8 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Corgea?

Cycode

Cycode’s AI-Native Application Security Platform unites security and development teams with actionable context from code to runtime to identify, prioritize, and fix the software risks that matter. Powered by proprietary scanners, third-party integrations, and the Context Intelligence Graph (CIG), Cycode delivers unified, correlated insight across the Software Factory. Its unique ability to sense, reason, and act with context in the AI-Era comes from its foundational convergence of AST, ASPM, and Software Supply Chain Security—purpose-built to secure both AI- and human-generated code.

Average Rating: 4.0/5.0

Total Reviews: 2

How Do G2 Users Rate Cycode?

  • Test Automation: 8.3/10 (Category avg: 8.8/10)
  • Quality of Support: 10.0/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 8.3/10 (Category avg: 8.4/10)

Who Is the Company Behind Cycode?

  • Seller: Cycode
  • Year Founded: 2019
  • HQ Location: New York, New York, United States
  • LinkedIn® Page: www.linkedin.com
    149 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 67% Medium, 33% Large

What Are Recent G2 Reviews of Cycode?

Data Theorem

RamQuest’s solutions include our fully integrated closing, escrow accounting, imaging, transaction management, esigning, and digital marketplace solutions and are available on-premise or in a hosted environment

Average Rating: 4.0/5.0

Total Reviews: 1

Who Is the Company Behind Data Theorem?

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Data Theorem?

Fluid Attacks

Implement Fluid Attacks' comprehensive, AI-powered solution into your SDLC and develop secure software without delays. As an all-in-one solution, Fluid Attacks accurately finds and helps you remediate vulnerabilities throughout the SDLC and ensures secure software development. The solution integrates its AI, automated tool, and team of pentesters to perform SAST, SCA, DAST, CSPM, SCR, PtaaS and RE to help you improve your security posture. This way, Fluid Attacks delivers accurate knowledge of the security status of your application. This means security goes alongside innovation without hindering your speed. Fluid Attacks provides you with expert knowledge about vulnerabilities and support options that enable you to remediate the security issues in your application.

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate Fluid Attacks?

  • Test Automation: 10.0/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.1/10)
  • Quality of Support: 10.0/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 10.0/10 (Category avg: 8.4/10)

Who Is the Company Behind Fluid Attacks?

  • Seller: Fluid Attacks
  • Year Founded: 2001
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    181 employees on LinkedIn®
  • Phone: +14154042154

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Fluid Attacks?

Osto

Osto is the complete cybersecurity platform for startups. One platform that runs your full security stack, automates compliance directly from the security stack itself, delivers VAPT by OSCP-certified engineers, and answers security questionnaire in 5 minutes. Most startups today end up paying for a compliance tool (Vanta, Drata, Sprinto), a separate stack of security tools that does not connect to it (WAF, endpoint protection, ZTNA, cloud posture management), an annual VAPT firm, and weeks of engineering time burned on security questionnaires.. An auditor who cannot tell the difference between configured and operational. Osto replaces all of that. CLOUD SECURITY - Cloud Posture (CSPM): Scan AWS, Azure, GCP for misconfigs and drift - Web API Protection: Shadow API discovery, schema enforcement, malicious traffic blocking - Web App Protection: OWASP Top 10, DDoS, bot blocking, virtual patching APPLICATION SECURITY - Mobile App Scanner: Assess mobile app builds for weaknesses before release - SAST / SBOM: Static analysis and software bill of materials - Web App Scanner: Continuously scan internet-facing applications for exploitable issues - SCA (Software Composition Analysis): Detect known vulnerabilities in open-source dependencies and third-party libraries used by your application - License Compliance: Surface and track open-source licenses in your codebase to avoid legal and IP exposure NETWORK SECURITY - Domain Filtering: Block malicious domains, enforce browsing policies - ZTNA Secure Access: Zero Trust with 2FA, time-based permissions, instant blocking ENDPOINT SECURITY - App Control: Control application behavior to reduce unauthorized execution risk - Device Control: Control USB peripherals and removable media access on company devices - Disk Encryption: Protect startup devices and sensitive data at rest - Endpoint Antimalware: Real-time malware detection, ransomware prevention - File Access DLP: Protect sensitive files with access controls and data-loss prevention - Screen Lock: Enforce automatic device lock and idle-session protection - Swipe Clean: Remote wipe and cleanup actions for managed startup devices COMPLIANCE - AI Security Q&A: Pre-fill questionnaires in 5 minutes at 99% precision - Compliance Automation: Continuously mapped controls, evidence collection, and audit workflows (SOC 2, ISO 27001, HIPAA, PCI-DSS) - Security Awareness Training: Train employees continuously and keep participation evidence audit-ready AUDITS - Logs Analyzer: Centralized logs and audit-ready posture across every module ASSESSMENT - VAPT: OSCP-certified engineers, 2 weeks+ delivery, covering web applications, APIs, networks, mobile, and source code This is what we call TrulyOne: Osto's vision of one cybersecurity platform for startups, where everything you build, protect, and prove runs as a single system. Compliance evidence flows directly from the security stack, audit readiness becomes continuous rather than quarterly, and one dashboard replaces 5-7 separate vendors plus the annual VAPT firm plus manual GRC work. Built for startup founders going from first enterprise deal to Series B and beyond, where compliance is no longer optional and the cost of fragmented security tools adds up fast. Backed by PointOne Capital, GSF, and India Accelerator.

Average Rating: 4.7/5.0

Total Reviews: 14

How Do G2 Users Rate Osto?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.1/10)
  • Quality of Support: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind Osto?

  • Seller: Osto
  • Year Founded: 2025
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    29 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 93% Small, 7% Medium

What Are Recent G2 Reviews of Osto?

PrivJs Safe

PrivJs Safe blocks the installation of malicious npm packages and provides with an ESLint plugin to detect vulnerable dependencies in a project.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate PrivJs Safe?

  • Test Automation: 10.0/10 (Category avg: 8.8/10)
  • Quality of Support: 10.0/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 10.0/10 (Category avg: 8.4/10)

Who Is the Company Behind PrivJs Safe?

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of PrivJs Safe?

Sigrid

Sigrid® - The Software Assurance Platform Sigrid, the software assurance platform from Software Improvement Group (SIG), provides actionable insights into your software portfolio and empowers your organization to make fact-based decisions that cut costs and reduce risks, boost productivity up to 30%, keep technical debt in check, speed up time to market and build a foundation for future innovation. Sigrid illuminates the risks and opportunities in your source code and architecture and provides actionable advice to navigate the pitfalls. Sigrid continuously measures and monitors the build quality of your enterprise software, including architecture, maintainability, security, and productivity – a single solution that reduces expensive tool spread and provides a central overview of software health. Join our community - // Getting software right for a healthier digital world.

Average Rating: 4.8/5.0

Total Reviews: 2

Who Is the Company Behind Sigrid?

Who Uses This Product?

  • Company Size: 50% Medium, 50% Small

What Are Recent G2 Reviews of Sigrid?

Sparrow SAST

Sparrow SAST is designed to detect security weaknesses in source code with its semantic based static program analysis engine.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Sparrow SAST?

  • Test Automation: 8.3/10 (Category avg: 8.8/10)
  • Quality of Support: 8.3/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 6.7/10 (Category avg: 8.4/10)

Who Is the Company Behind Sparrow SAST?

Who Uses This Product?

  • Company Size: 100% Small

What Do G2 Reviewers Say About Sparrow SAST?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the excellent customer support from Sparrow SAST, making implementation and compliance seamless and efficient.
  • Users find Sparrow SAST to be easy to use and well-integrated with CI/CD pipelines for compliance.
  • Users find Sparrow SAST to have easy implementation, especially with CI/CD integration and compliance with regulations.
  • Users value the effective vulnerability detection capabilities of Sparrow SAST, ensuring compliance with coding regulations effortlessly.
Cons
  • Users experience slow performance when analyzing large C or C++ codes, impacting their efficiency with Sparrow SAST.

What Are Recent G2 Reviews of Sparrow SAST?

Virtual Forge Security Suite

Using the Virtual Forge Security Suite, customers will improve their security and compliance by automating tasks involved in securing their SAP systems.

Average Rating: 4.0/5.0

Total Reviews: 1

How Do G2 Users Rate Virtual Forge Security Suite?

  • Test Automation: 8.3/10 (Category avg: 8.8/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.1/10)
  • Quality of Support: 10.0/10 (Category avg: 9.2/10)
  • Source-Code Scanning: 6.7/10 (Category avg: 8.4/10)

Who Is the Company Behind Virtual Forge Security Suite?

  • Seller: Virtual Forge
  • Year Founded: 2009
  • HQ Location: Boston, Massachusetts, United States
  • LinkedIn® Page: www.linkedin.com
    343 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Virtual Forge Security Suite?

Axivion

Axivion Static Code Analysis helps developers check standard compliance, security vulnerabilities, and code quality issues for C and C++ code. It performs automated analysis to identify violations of coding guidelines like MISRA C and detect clones, dead code, and security vulnerabilities. Key features include coding standards compliance checking, metric monitoring, defect analysis, and certification for safety-critical software development.

Who Is the Company Behind Axivion?

  • Seller: Qt Group
  • Year Founded: 1995
  • HQ Location: Espoo, Finland
  • Twitter: @qtproject
    21,456 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

Bearer

Bearer helps modern teams ship trustworthy products with the help of our code security SAST solution built for security, privacy and engineering teams. We combine sensitive data context with static code analysis to make security and privacy engineering simpler and smarter to maximize the ROI for your DevSecOps and central security team driven programs.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Bearer?

  • Quality of Support: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind Bearer?

  • Seller: Bearer
  • Year Founded: 2019
  • HQ Location: Cambridge, US
  • Twitter: @BearerSH
    16 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    25 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Bearer?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024