Best Static Application Security Testing (SAST) Software - Page 6

How Many Static Application Security Testing (SAST) Software Products Does G2 Track?

Total Products under this Category: 113

Category Stats (Aug 2026)

  • Average Rating: 4.54/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Coverity Static (+0.61%) - Among all products in this category, Black Duck Coverity Static recorded the largest rating increase compared to last month

Last updated: August 12, 2026

How Does G2 Rank Static Application Security Testing (SAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 113+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Application Security Testing (SAST) Software

G2 Grid® for Static Application Security Testing (SAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, GitHub, GitGuardian, GitLab, SonarQube, Semgrep, Snyk, and OX Security.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-application-security-testing-sast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=github&focus%5B%5D=gitguardian&focus%5B%5D=gitlab&focus%5B%5D=sonarqube&focus%5B%5D=semgrep&focus%5B%5D=snyk&focus%5B%5D=ox-security)

Sponsored

Zensai

Zensai is the Human Success company. We believe every employee should have the skills, feedback, and support they need to perform at their best. Our platform delivers that through agentic AI coaching for learning, performance, and engagement, fully built inside Microsoft 365, where your people already work. 💡 Learning management that goes beyond the LMS: compliance, onboarding, AI-coached skills development, and course creation, all inside Teams, SharePoint, and Outlook. AI coaches every employee along a personalized development path, with the AI Tutor answering questions from your own content in the flow of work. 🎯 Performance management built into everyday routines: continuous check-ins, OKRs, 360 feedback, and manager coaching workflows that make performance a habit, not an annual event. AI coaches every manager through every conversation, every goal, and every piece of feedback. 🙂 Employee engagement that shows you how your people are really doing: real-time sentiment, recognition, pulse surveys, and a continuously updated signal on how every employee, every team, and the whole organization is learning, performing, and engaging. Don't just track people progress. Coach it.

Visit website

CodeAnt AI Code Security Platform

CodeAnt AI secures your codebase with automated detection of vulnerabilities, secrets, and misconfigurations across every pull request. It runs SAST, IaC scans, and secret scanning with inline remediation, all built into your dev workflow. Get security findings mapped to OWASP and CWE standards — no setup required, no extra tools to manage.

Who Is the Company Behind CodeAnt AI Code Security Platform?

  • Seller: CodeAnt AI
  • Year Founded: 2023
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    22 employees on LinkedIn®

Code Dx Enterprise

Code Dx Enterprise takes the results of all of your scans, processes them, and gives you a short list with no duplicates. It even points out which vulnerabilities were found by more than one tool, and provides an easy interface to prioritize each one based on severity. This can cut your testing time down, and get your application secured without falling behind schedule.

Who Is the Company Behind Code Dx Enterprise?

  • Seller: Code Dx
  • Year Founded: 2002
  • HQ Location: Burlington, Massachusetts, United States
  • LinkedIn® Page: www.linkedin.com
    1,250 employees on LinkedIn®

CodePatrol

CodePatrol performs powerful SAST scans on your project source code and identifies security flaws early. Powered by Claranet and Checkmarx

Who Is the Company Behind CodePatrol?

CodeThreat

Prevent the software flaws as early as possible in SDLC with CodeThreat SAST Platform. CodeThreat statically tests your code and helps you locate, prioritize and mitigate security weaknesses without pre-compilation. Self-Hosted Scan Center will help you to mitigate issues faster with real-time actions in your software development pipelines.

Who Is the Company Behind CodeThreat?

Conviso

The Conviso Platform is a complete Application Security Posture Management (ASPM) solution that centralizes visibility, correlation, and prioritization of vulnerabilities across the software development lifecycle. It integrates with your existing SAST, DAST, SCA, IaC, and CI/CD tools, automates triage, and provides a unified view of risk — helping security and development teams work together to reduce complexity and strengthen AppSec maturity.

Who Is the Company Behind Conviso?

Devknox

Devknox is a security plugin for the Android Studio IDE that detects and corrects security issues as you write code, real-time. Simply install the plugin and let Devknox detect, suggest and remediate all your security threats while you code and build your app.

Who Is the Company Behind Devknox?

  • Seller: Appknox
  • Year Founded: 2014
  • HQ Location: Singapore, Singapore
  • Twitter: @appknox
    3,055 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    85 employees on LinkedIn®

Enso Security

Enso Application Security Posture is a platform for AppSec teams to manage their day-to-day work, implement their security strategy into an AppSec organizational program, enforce it and automate it. And all of that in a scalable rapidly changing environment. AppSec teams struggle with prioritization - they may have a vision and concept of how to handle AppSec, but they don’t know where to invest and what actions to take. To keep up with R&D velocity and scale, Enso provides full visibility on the application inventory, focuses the AppSec teams on the most important tasks and insights, and takes a policy-based “call to action” approach so that the AppSec professionals won’t waste their time looking for application changes, prioritizing, or doing manual work.

Who Is the Company Behind Enso Security?

ForAllSecure

Mayhem Security, formerly known as ForAllSecure, is a provider of autonomous application security solutions designed to identify and remediate vulnerabilities in software applications and APIs. Leveraging advanced artificial intelligence and dynamic analysis techniques, Mayhem Security offers a comprehensive platform that integrates seamlessly into development workflows, enabling organizations to enhance their security posture without compromising development speed. Key Features and Functionality: - Code Security: Mayhem tests applications by simulating real-world attack scenarios, pinpointing vulnerabilities, and guiding rapid remediation efforts. - API Security: The platform provides continuous validation and verification of APIs, ensuring they are robust against potential threats. - Dynamic Software Bill of Materials (SBOM: Mayhem's Dynamic SBOM reduces security alert noise by up to 80% by analyzing an application's runtime behavior to identify only exploitable vulnerabilities, thereby minimizing false positives. - Advanced Fuzz Testing: Utilizing AI-powered, network-aware fuzzing combined with symbolic execution, Mayhem conducts intelligent triage to uncover defects that might otherwise go unnoticed. - Seamless Integration: Mayhem integrates with popular development tools and platforms, including GitHub, Jenkins, GitLab, Jira, Slack, and more, facilitating easy adoption into existing workflows. Primary Value and Problem Solved: Mayhem Security addresses the critical challenge of securing software applications in an era of rapid development and deployment. By automating the process of vulnerability detection and remediation, Mayhem enables development teams to focus on innovation while ensuring their applications are secure. The platform's ability to reduce false positives and provide actionable insights accelerates the development lifecycle, enhances software reliability, and protects organizations from potential cyber threats.

Who Is the Company Behind ForAllSecure?

FuzzLabs

FuzzLabs is the most comprehensive fuzzer for finding bugs and zero-day vulnerabilities in custom/proprietary products, protocols, and complex environments.

Who Is the Company Behind FuzzLabs?

  • Seller: Guardara
  • Year Founded: 2018
  • HQ Location: London, GB
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Hexway ASOC

Universal DevSecOps platform to simplify vulnerability management. Assess, analyze, and assign vulnerabilities, ensuring a secure and controlled environment.

Who Is the Company Behind Hexway ASOC?

IDA Pro

IDA Pro is a state-of-the-art, multi-processor disassembler and debugger developed by Hex-Rays. It is widely recognized as the gold standard for reverse engineering and binary analysis, enabling professionals to dissect and understand complex software executables across various platforms. With over thirty years of development, IDA Pro combines powerful static and dynamic analysis tools, offering unparalleled support for a vast array of processor architectures and file formats. Its interactive and programmable environment allows users to navigate through disassembled code efficiently, making it an indispensable tool for malware analysis, vulnerability research, and software debugging. Key Features and Functionality: - Multitarget Disassembler: Supports disassembly for over 60 processor families, allowing analysis of diverse binary files. - Integrated Debugger: Facilitates dynamic analysis with support for local and remote debugging across multiple platforms. - Decompilers: Generates high-level, readable pseudocode from machine code, enhancing code comprehension. - Extensibility: Offers APIs, SDKs, and scripting capabilities (including IDAPython for automation and customization. - Interactive Interface: Allows users to edit and redefine disassembly outputs, providing an intuitive analysis experience. - Security and Reliability: Undergoes continuous improvement with regular updates, rigorous testing, and secure coding practices. Primary Value and User Solutions: IDA Pro addresses the critical need for in-depth binary code analysis by providing a comprehensive suite of tools that transform complex machine code into human-readable formats. This capability is essential for cybersecurity professionals, malware analysts, and software developers who require a deep understanding of software behavior, vulnerabilities, and potential threats. By offering both static and dynamic analysis features, along with extensive customization options, IDA Pro empowers users to efficiently reverse-engineer software, identify security flaws, and develop robust solutions to mitigate risks.

Who Is the Company Behind IDA Pro?

  • Seller: Hex-Rays
  • Year Founded: 2005
  • HQ Location: Liège, BE
  • LinkedIn® Page: www.linkedin.com
    31 employees on LinkedIn®

IMCA.AI Code Vulnerability Scanner

IMCA.AI helps organizations 𝗱𝗲𝘁𝗲𝗰𝘁 𝗺𝗮𝗹𝗶𝗰𝗶𝗼𝘂𝘀 𝗮𝗻𝗱 𝗶𝗻𝘁𝗲𝗻𝘁𝗶𝗼𝗻𝗮𝗹𝗹𝘆 𝗵𝗶𝗱𝗱𝗲𝗻 𝗰𝗼𝗱𝗲 that traditional security scanners miss. Using agentic AI workflows and RAG, IMCA analyzes source code contextually to 𝘂𝗻𝗰𝗼𝘃𝗲𝗿 𝗯𝗮𝗰𝗸𝗱𝗼𝗼𝗿𝘀, 𝗶𝗻𝘀𝗶𝗱𝗲𝗿 𝘁𝗵𝗿𝗲𝗮𝘁𝘀, 𝘀𝘂𝗽𝗽𝗹𝘆-𝗰𝗵𝗮𝗶𝗻 𝗿𝗶𝘀𝗸𝘀, 𝗮𝗻𝗱 𝗼𝗯𝗳𝘂𝘀𝗰𝗮𝘁𝗲𝗱 𝗮𝘁𝘁𝗮𝗰𝗸 𝗽𝗮𝘁𝘁𝗲𝗿𝗻𝘀 — across proprietary and open-source codebases. Our platform 𝗿𝗲𝗱𝘂𝗰𝗲𝘀 𝗺𝗮𝗻𝘂𝗮𝗹 𝗿𝗲𝘃𝗶𝗲𝘄 𝗲𝗳𝗳𝗼𝗿𝘁 𝗯𝘆 𝘂𝗽 𝘁𝗼 𝟵𝟬%, integrates into CI/CD pipelines, and supports secure deployment in SaaS, private cloud, or Swiss-hosted environments. IMCA.AI extends existing SAST tools — so security teams can see what others don’t.

Who Is the Company Behind IMCA.AI Code Vulnerability Scanner?

IRIS

CodeEye's IRIS is a next-generation application security posture management (ASPM) platform, offers an all-in-one solution with real-time, AI-powered vulnerability and threat detection, correlation, prioritization, and remediation, easing the tension between time-to-market and risk mitigation. How it Works? Unlike traditional ASPM Solutions, IRIS detects vulnerabilities within the product development lifecycle and application infrastructure, while simultaneously providing continuous penetration testing and attack surface management to production environments. IRIS detects, correlates, provides risk-based analysis, and prioritizes application security findings in real time with automated workflows for remediation – all within one platform. IRIS seamlessly integrates with your tools, pipelines, and workflows, and supports your favourite languages. Unlock the Benefits: 1) Centralize detection, prioritization, and remediation of application threats and vulnerabilities. 2) Real-time actionable insights. 3) Establish resilient DevSecOps processes based on risk management. 4) Implement automated workflows to accelerate the identification and resolution of application risks. 5) Adopt a straightforward licensing model. 6) Ability to measure the effectiveness of your application security program. 7) Deploy within 24 hours with simplicity and ease of operation. 8) Built-in policy compliance measures. Next-Gen ASPM Managed Service In today's digital landscape, organizations grapple with deciphering and prioritizing the criticality of code and application related threats and vulnerabilities. The scarcity and expense of specialized talent capable of bridging the gap between DevOps and SecOps exacerbates this challenge. CodeEye's expertise in Application Security provides a Continuous AppSec Partner, accelerating program maturity with expert guidance and advanced technology. Our IRIS Managed Service centralizes application risk management, helping you define compliance measures and policies for prioritization and remediation, ensuring you grasp and address program risk in real-time. Key Features - Static Application Security Testing (SAST): Scans your source code for security risks before an issue goes to production. - Software Composition Analysis (SCA): Continuously monitors your code for known vulnerabilities and other security risks. - Container Scanning: Scans your container in real time for packages that contain security threats and vulnerabilities. - Dynamic Application Security Testing (DAST): Dynamically tests your production applications for vulnerabilities through simulated attacks. - Attack Surface Management (ASM): Continuously identifies, monitors, and manages external internet-connected assets for potential attack vectors and exposures. - Risk and Compliance: Continuously evaluates regulatory and internal security policy compliance using real-time and historical reporting. Vendor of Record Award CodeEye's IRIS is recognized as a Vendor of Record by the Ministry of Government and Consumer Services for IT Security Products In 2024, NIST updated its Cyber Security Framework (CSF) with significant implications for security by design and secure SDLC. Our Risk and Compliance module supports compliance with NIST CSF 2.0 throughout the software development lifecycle. Gain a comprehensive view of various scanning modules aligned with the CSF's five core functions: Identify, Protect, Detect, Respond, and Recover. Our Difference: An all-in-one platform with straight forward licensing and seamless integration. Your Results: A tool that works with your existing tools and workflows, providing security without hidden costs or complexities. Our Difference: Continuous penetration testing and attack surface management. Your Results: Identify and close gaps before an attacker exploits them across your ever-changing attack surface. Our Difference: Quick and Easy Deployment Your Results: Security monitoring and testing within 24 hours, without extensive setup or training. Our difference: Built-in risk and compliance policy module Your Results: Ensure regulatory and internal compliance with built-in policy measures aligned with industry standards like NIST CSF 2.0. Our Difference: Automated Workflows for remediation. Your Results: Rapid risk mitigation, reducing the time, effort and cost of finding and fixing vulnerabilities to ensure continuous protection. Our Difference: Real-Time, AI-powered vulnerability Your Results: Immediately identify and address security threats with precise, actionable intelligence. Our Difference: Threat and vulnerability detection, correlation, and risk-based analysis. Your Results: Simplified security operations where critical vulnerabilities are addressed first.

Who Is the Company Behind IRIS?

  • Seller: CodeEye
  • Year Founded: 2015
  • HQ Location: Toronto, CA
  • Twitter: @CodeEyeAI
    6 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

IronSCAN

Quick and reliable security assessment platform that scans your mobile application for vulnerabilities without the need for high-profile penetration testing's. IronSCAN assessment platform provides quick and easy vulnerability identification and remediation, without the need for custom plugins or programming. Scan across multiple platforms and applications with ease using integrated scanners. Audit your entire infrastructure in minutes, not days!

Who Is the Company Behind IronSCAN?

  • Seller: SecIron
  • Year Founded: 2017
  • HQ Location: Tokyo, JP
  • LinkedIn® Page: www.linkedin.com
    15 employees on LinkedIn®

Mobix

Mobix is a SaaS mobile application testing platform that reduces application analysis costs and time, making tests creation and finding vulnerabilities effortless. Mobix's unique characteristics include: - Non-invasive tool, which augments existing SDLC (Software Development Life Cycle) - Automates 90% of the entire test coverage for dynamic and static analysis - No code, plug and play analysis - Automated recording of tests - Machine Learning to automatically adapt auto-tests - Scalable multithread testing, custom scan rules - Compliance to all major mobile security standards

Who Is the Company Behind Mobix?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024