Best Static Application Security Testing (SAST) Software - Page 6

How Many Static Application Security Testing (SAST) Software Products Does G2 Track?

Total Products under this Category: 123

Category Stats (Oct 2026)

  • Average Rating: 4.54/5 (↓0.01 vs Sep 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: HCL AppScan (+0.7%) - Among all products in this category, HCL AppScan recorded the largest rating increase compared to last month

Last updated: October 01, 2026

How Does G2 Rank Static Application Security Testing (SAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,600+ Authentic Reviews
  • 123+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Application Security Testing (SAST) Software

G2 Grid® for Static Application Security Testing (SAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, GitGuardian, GitHub, GitLab, SonarQube, Snyk, Semgrep, and Checkmarx.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-application-security-testing-sast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=gitguardian&focus%5B%5D=github&focus%5B%5D=gitlab&focus%5B%5D=sonarqube&focus%5B%5D=snyk&focus%5B%5D=semgrep&focus%5B%5D=checkmarx)

Black Duck Coverity Static Analysis

Built for developers and backed by security teams, Coverity® Static Analysis provides unparalleled code scanning to help you deliver high-quality software that meets security, functional safety, and industry standards.

Who Is the Company Behind Black Duck Coverity Static Analysis?

  • Seller: Black Duck
  • Year Founded: 2024
  • HQ Location: Burlington, US
  • LinkedIn® Page: www.linkedin.com
    1,317 employees on LinkedIn®

BoringSec

BoringSec is an application security platform that helps developers, founders, product teams, and agencies identify, understand, fix, and verify security issues across code and production environments. It combines code review, live application scanning, evidence-backed findings, AI-ready remediation, re-testing, continuous monitoring, alerts, professional reporting, and compliance evidence mapping in one workflow. BoringSec also supports REST API, MCP, CLI, GitHub, Slack, and webhook integrations, making it easier to embed security into modern development processes without the complexity of traditional enterprise security tooling.

Who Is the Company Behind BoringSec?

Bugsmirror MASST (Mobile Application Security Suite & Tools)

Bugsmirror Mobile Application Security Suite & Tools (MASST) is designed specifically for your business, providing scalable, end-to-end security for your mobile app. From detection to protection, MASST ensures your app is safeguarded against evolving security threats. With MASST, you can focus on growing your business, knowing your app is fully protected at every stage.

Who Is the Company Behind Bugsmirror MASST (Mobile Application Security Suite & Tools)?

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

CodeAnt AI Code Security Platform

CodeAnt AI covers code, cloud, and runtime security in one platform. Code security: AI SAST detects vulnerabilities during development and establishes which are reachable before surfacing them, with 95% fewer false positives than pattern-matching scanners and findings mapped to OWASP and CWE. Software composition analysis identifies vulnerable and malicious packages across direct and transitive dependencies, protecting more than 2 billion monthly package downloads. Secret detection scans full commit history for hardcoded credentials, API keys, and tokens. SBOM generation runs continuously across every repository. Cloud security: Cloud security posture management detects misconfigurations across your cloud accounts and maps them to compliance frameworks. Threat detection surfaces active adversary behavior in the cloud environment. Container scanning inspects images and registries for vulnerable packages and embedded secrets. Virtual machine scanning covers running workloads and their installed dependencies. Runtime security: Dynamic application security testing probes running applications for exploitable behavior. Attack surface management continuously discovers exposed assets, domains, and services outside the perimeter. Grey box AI pentesting runs more than 500 AI agents against that surface, chaining weaknesses into complete attack paths. Remediation arrives as a fix inside the pull request. Continuous AI learning draws on more than 1 billion lines of codebase history. Our security research team has discovered over 150 CVEs in production software, and CodeAnt has pentested more than 1,000 companies.

Who Is the Company Behind CodeAnt AI Code Security Platform?

  • Seller: CodeAnt AI
  • Year Founded: 2023
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    22 employees on LinkedIn®

Code Dx Enterprise

Code Dx Enterprise takes the results of all of your scans, processes them, and gives you a short list with no duplicates. It even points out which vulnerabilities were found by more than one tool, and provides an easy interface to prioritize each one based on severity. This can cut your testing time down, and get your application secured without falling behind schedule.

Who Is the Company Behind Code Dx Enterprise?

  • Seller: Code Dx
  • Year Founded: 2024
  • HQ Location: Burlington, Massachusetts, United States
  • LinkedIn® Page: www.linkedin.com
    1,317 employees on LinkedIn®

CodePatrol

CodePatrol performs powerful SAST scans on your project source code and identifies security flaws early. Powered by Claranet and Checkmarx

Who Is the Company Behind CodePatrol?

CodeThreat

Prevent the software flaws as early as possible in SDLC with CodeThreat SAST Platform. CodeThreat statically tests your code and helps you locate, prioritize and mitigate security weaknesses without pre-compilation. Self-Hosted Scan Center will help you to mitigate issues faster with real-time actions in your software development pipelines.

Who Is the Company Behind CodeThreat?

Conviso

The Conviso Platform is a complete Application Security Posture Management (ASPM) solution that centralizes visibility, correlation, and prioritization of vulnerabilities across the software development lifecycle. It integrates with your existing SAST, DAST, SCA, IaC, and CI/CD tools, automates triage, and provides a unified view of risk — helping security and development teams work together to reduce complexity and strengthen AppSec maturity.

Who Is the Company Behind Conviso?

Dam Secure

Dam Secure is an AI-native application security platform for teams that build software with AI coding agents. It enforces security rules across the development lifecycle, including agentic planning, the local development environment, and CI/CD, before code ships to production. The platform reviews an organization's existing codebase and generates security rules in plain English, tailored to that codebase's own patterns rather than generic policy. These rules are enforced across every developer, AI agent, and repository. At the planning stage, Dam Secure reviews plans co-authored by developers and AI agents. In the dev environment, it checks AI-generated code before it's committed. In CI/CD, it checks pull and merge requests before they reach production. Dam Secure is built to catch business logic flaws in AI-generated code that traditional tools miss, using codebase context to reduce false positives. It integrates with common AI coding tools (including Cursor, Claude Code, and GitHub Copilot) and version control platforms (Bitbucket, GitHub, GitLab), and keeps a persistent record of security context across the workflow.

Who Is the Company Behind Dam Secure?

Devknox

Devknox is a security plugin for the Android Studio IDE that detects and corrects security issues as you write code, real-time. Simply install the plugin and let Devknox detect, suggest and remediate all your security threats while you code and build your app.

Who Is the Company Behind Devknox?

  • Seller: Appknox
  • Year Founded: 2014
  • HQ Location: Singapore, Singapore
  • Twitter: @appknox
    3,055 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    84 employees on LinkedIn®

Enso Security

Enso Application Security Posture is a platform for AppSec teams to manage their day-to-day work, implement their security strategy into an AppSec organizational program, enforce it and automate it. And all of that in a scalable rapidly changing environment. AppSec teams struggle with prioritization - they may have a vision and concept of how to handle AppSec, but they don’t know where to invest and what actions to take. To keep up with R&D velocity and scale, Enso provides full visibility on the application inventory, focuses the AppSec teams on the most important tasks and insights, and takes a policy-based “call to action” approach so that the AppSec professionals won’t waste their time looking for application changes, prioritizing, or doing manual work.

Who Is the Company Behind Enso Security?

ForAllSecure

Mayhem Security, formerly known as ForAllSecure, is a provider of autonomous application security solutions designed to identify and remediate vulnerabilities in software applications and APIs. Leveraging advanced artificial intelligence and dynamic analysis techniques, Mayhem Security offers a comprehensive platform that integrates seamlessly into development workflows, enabling organizations to enhance their security posture without compromising development speed. Key Features and Functionality: - Code Security: Mayhem tests applications by simulating real-world attack scenarios, pinpointing vulnerabilities, and guiding rapid remediation efforts. - API Security: The platform provides continuous validation and verification of APIs, ensuring they are robust against potential threats. - Dynamic Software Bill of Materials (SBOM: Mayhem's Dynamic SBOM reduces security alert noise by up to 80% by analyzing an application's runtime behavior to identify only exploitable vulnerabilities, thereby minimizing false positives. - Advanced Fuzz Testing: Utilizing AI-powered, network-aware fuzzing combined with symbolic execution, Mayhem conducts intelligent triage to uncover defects that might otherwise go unnoticed. - Seamless Integration: Mayhem integrates with popular development tools and platforms, including GitHub, Jenkins, GitLab, Jira, Slack, and more, facilitating easy adoption into existing workflows. Primary Value and Problem Solved: Mayhem Security addresses the critical challenge of securing software applications in an era of rapid development and deployment. By automating the process of vulnerability detection and remediation, Mayhem enables development teams to focus on innovation while ensuring their applications are secure. The platform's ability to reduce false positives and provide actionable insights accelerates the development lifecycle, enhances software reliability, and protects organizations from potential cyber threats.

Who Is the Company Behind ForAllSecure?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024