Best Static Application Security Testing (SAST) Software - Page 7

How Many Static Application Security Testing (SAST) Software Products Does G2 Track?

Total Products under this Category: 113

Category Stats (Aug 2026)

  • Average Rating: 4.54/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Coverity Static (+0.61%) - Among all products in this category, Black Duck Coverity Static recorded the largest rating increase compared to last month

Last updated: August 12, 2026

How Does G2 Rank Static Application Security Testing (SAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 113+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Application Security Testing (SAST) Software

G2 Grid® for Static Application Security Testing (SAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, GitHub, GitGuardian, GitLab, SonarQube, Semgrep, Snyk, and OX Security.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-application-security-testing-sast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=github&focus%5B%5D=gitguardian&focus%5B%5D=gitlab&focus%5B%5D=sonarqube&focus%5B%5D=semgrep&focus%5B%5D=snyk&focus%5B%5D=ox-security)

Sponsored

Performio

We calculate commissions and incentives better than anyone else. Performio is sales compensation software that helps finance and compensation teams calculate complex commissions and incentives with greater accuracy, less manual work, and full visibility into every payout. Built for organizations that have outgrown spreadsheets, manual processes, and rigid systems, Performio makes it easier to manage evolving compensation requirements without sacrificing accuracy, transparency, or control. Performio combines flexible data management with structured plan building, giving teams a reliable way to manage complex commissions as plans evolve. Compensation teams can update plan logic, process calculations, and trace every payout without rebuilding their system or depending on external support. The platform is designed to support complex data, changing business rules, and growing sales organizations while keeping commission operations consistent and easier to manage. AI is embedded throughout the platform to reduce administrative work, accelerate plan changes, and provide trusted answers grounded in structured compensation data and business logic. Compensation teams can investigate results and respond to questions faster, while sellers gain clear visibility into how their earnings are calculated. This helps organizations reduce errors, shorten commission cycles, limit disputes, and move away from shadow accounting. Trusted by customers including Equifax, Uber Freight, WP Engine, and TD SYNNEX, Performio serves mid-market and enterprise organizations around the world. Founded in Australia in 2006 and headquartered in Irvine, California, Performio is built for finance, sales compensation, and revenue operations teams that need to manage complex commission programs at scale and adapt as their business grows. By combining accurate calculations, flexible plan management, embedded AI, and transparent payout information, Performio gives organizations the clarity, confidence, and control to manage sales compensation more effectively.

Visit website

Nullify

The post-human product security program. Nullify continuously allocates AI capacity toward the highest-impact product security work, maximizing outcomes from every engineer hour and every token spent.

Who Is the Company Behind Nullify?

  • Seller: Nullify
  • Company Website:
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    27 employees on LinkedIn®

Osto

Osto is the complete cybersecurity platform for startups. One platform that runs your full security stack, automates compliance directly from the security stack itself, delivers VAPT by OSCP-certified engineers, and answers security questionnaire in 5 minutes. Most startups today end up paying for a compliance tool (Vanta, Drata, Sprinto), a separate stack of security tools that does not connect to it (WAF, endpoint protection, ZTNA, cloud posture management), an annual VAPT firm, and weeks of engineering time burned on security questionnaires.. An auditor who cannot tell the difference between configured and operational. Osto replaces all of that. CLOUD SECURITY - Cloud Posture (CSPM): Scan AWS, Azure, GCP for misconfigs and drift - Web API Protection: Shadow API discovery, schema enforcement, malicious traffic blocking - Web App Protection: OWASP Top 10, DDoS, bot blocking, virtual patching APPLICATION SECURITY - Mobile App Scanner: Assess mobile app builds for weaknesses before release - SAST / SBOM: Static analysis and software bill of materials - Web App Scanner: Continuously scan internet-facing applications for exploitable issues - SCA (Software Composition Analysis): Detect known vulnerabilities in open-source dependencies and third-party libraries used by your application - License Compliance: Surface and track open-source licenses in your codebase to avoid legal and IP exposure NETWORK SECURITY - Domain Filtering: Block malicious domains, enforce browsing policies - ZTNA Secure Access: Zero Trust with 2FA, time-based permissions, instant blocking ENDPOINT SECURITY - App Control: Control application behavior to reduce unauthorized execution risk - Device Control: Control USB peripherals and removable media access on company devices - Disk Encryption: Protect startup devices and sensitive data at rest - Endpoint Antimalware: Real-time malware detection, ransomware prevention - File Access DLP: Protect sensitive files with access controls and data-loss prevention - Screen Lock: Enforce automatic device lock and idle-session protection - Swipe Clean: Remote wipe and cleanup actions for managed startup devices COMPLIANCE - AI Security Q&A: Pre-fill questionnaires in 5 minutes at 99% precision - Compliance Automation: Continuously mapped controls, evidence collection, and audit workflows (SOC 2, ISO 27001, HIPAA, PCI-DSS) - Security Awareness Training: Train employees continuously and keep participation evidence audit-ready AUDITS - Logs Analyzer: Centralized logs and audit-ready posture across every module ASSESSMENT - VAPT: OSCP-certified engineers, 2 weeks+ delivery, covering web applications, APIs, networks, mobile, and source code This is what we call TrulyOne: Osto's vision of one cybersecurity platform for startups, where everything you build, protect, and prove runs as a single system. Compliance evidence flows directly from the security stack, audit readiness becomes continuous rather than quarterly, and one dashboard replaces 5-7 separate vendors plus the annual VAPT firm plus manual GRC work. Built for startup founders going from first enterprise deal to Series B and beyond, where compliance is no longer optional and the cost of fragmented security tools adds up fast. Backed by PointOne Capital, GSF, and India Accelerator.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Osto?

  • Seller: Osto
  • Year Founded: 2025
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Osto?

PHP Secure Vulnerability Scanner

Every second, a website around the world is hacked. Over 60% of websites are vulnerable to SQL injection. Leakage of personal data, theft of money and even the site destruction - this is what vulnerabilities of your sites and scripts can result in. PHP Secure is a code scanner that analyzes your PHP code for vulnerabilities. PHP Secure detects an exploit—SQL, Command injections, XSS, PHP Serialize Injections, RCE, Double Escaping, Directory Traversal, ReDos—alerts you to the threat, gives explicit reports and recommendations to fix them. PHP Secure Scanner is suitable for analyzing sites on Php, framework Laravel, and CMS Wordpress, Drupal and Joomla. It’s as simple as clicking the Scan button and uploading your code. You can also link your Git repository, which PHP Secure can automatically connect to and scan. After being scanned, code is immediately deleted from the server. When registering, you will get 6 months free access to PHP Secure scanner, while similar solutions, like the salary of a code security specialist, can cost $10,000 a month. A mega discount for new users while the product is in the beta phase. Hurry to take advantage of this limited-time offer!

Who Is the Company Behind PHP Secure Vulnerability Scanner?

Proscan

Proscan is a unified application security platform designed to help organizations streamline the management of their security tools. By integrating multiple standalone solutions into a single cohesive experience, Proscan provides comprehensive security visibility across the entire software stack. This platform replaces the complexity of managing various tools for static analysis, dynamic testing, and dependency scanning, allowing teams to focus on building secure applications without the hassle of juggling disparate systems. The platform is particularly beneficial for security teams, developers, and engineering leaders who require a consolidated view of application security risks. Proscan combines nine specialized security scanners, including Static Application Security Testing (SAST), which analyzes source code in over 30 programming languages using advanced detection methods. Dynamic Application Security Testing (DAST) further enhances security by testing live applications, identifying vulnerabilities that may only become apparent during runtime. Additionally, Software Composition Analysis (SCA) evaluates open-source dependencies across 196 package ecosystems, helping organizations detect known vulnerabilities before they can impact production environments. Proscan's capabilities extend beyond code analysis. It includes scanning for hardcoded secrets, misconfigurations in Infrastructure-as-Code, and vulnerabilities in container images. The platform also offers API security testing that validates endpoints against the OWASP API Security Top 10, ensuring robust protection for applications that leverage APIs. For organizations developing AI-powered applications, Proscan features a dedicated AI and LLM security scanner that identifies potential risks associated with prompt injections and other vulnerabilities, utilizing over 4,600 techniques mapped to the OWASP LLM Top 10. Artificial intelligence plays a crucial role in enhancing Proscan's efficiency and accuracy. The platform employs machine-learning algorithms to reduce false positives and prioritize vulnerabilities based on their potential impact. This intelligent approach allows teams to focus on the most critical security issues while providing clear explanations and actionable remediation guidance. Proscan integrates seamlessly into existing development workflows, offering IDE plugins and native CI/CD integrations that ensure security checks are part of the development process without causing disruptions. Compliance readiness is another key feature of Proscan, as it generates audit-ready reports aligned with major security standards, including OWASP Top 10, PCI DSS, HIPAA, and GDPR. This automated evidence collection simplifies the compliance process, providing organizations with the necessary documentation in various formats. Proscan is designed for security teams looking to consolidate fragmented toolchains, developers needing quick feedback, and managed security service providers managing multiple client environments, making it a versatile solution for modern application security challenges.

Who Is the Company Behind Proscan?

Puma Scan

Puma Scan runs as engineers write code. Real-time results. Puma Scan Editions include Server, Azure DevOps and End User.

Who Is the Company Behind Puma Scan?

  • Seller: Puma Scan
  • Year Founded: 2016
  • HQ Location: West Des Moines, US
  • Twitter: @puma_scan
    300 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    16 employees on LinkedIn®

PVS-Studio

PVS-Studio is a SAST solution that helps enhance code quality, security, and safety. The analyzer detects bugs and potential vulnerabilities in C, C++, C#, and Java code on Windows, Linux, and macOS. Features - Supports various analysis types (intermodular, incremental, data flow analysis, taint analysis); - Can be used offline; - Provides cross-platform integration; - Offers ways to handle false positives; - Helps small and large teams maintain code quality. Pros - Quick and high-quality support from the analyzer developers; - 900+ diagnostic rules with detailed descriptions and examples; - Compliance with safety and security standards: OWASP TOP 10, MISRA C, C++, AUTOSAR, CWE; - Detailed reports and reminders for developers and managers (Blame Notifier); - User-friendly ways to handle legacy code, including mass suppression of analyzer’s warnings; - Support of the Open Source Community, analysis of open-source projects; - Integration with SonarQube. Pricing - In the commercial version, prices are set on request and can be changed depending on the required set of features; - Free trial is available; - PVS-Studio may offer a free licensing option to students, MVPs, public experts in security, and contributors to open-source projects.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate PVS-Studio?

  • Quality of Support: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind PVS-Studio?

  • Seller: PVS-Studio
  • Year Founded: 2008
  • HQ Location: Astana, KZ
  • Twitter: @Code_Analysis
    5,907 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    29 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of PVS-Studio?

What Are G2 Users Discussing About PVS-Studio?

Quokka Q-mast

Designed for app development, Q-mast embeds security directly into your workflow to identify security, privacy, and compliance risks before the mobile app is released. With a design tailored for DevSecOps workflows, Q-mast supports continuous, automated security testing that aligns with tools like Jenkins, GitLab, and GitHub. Q-mast capabilities: • Automated scanning in minutes, no source code needed • Analysis of compiled app binary, regardless of in-app or run-time obfuscations • Precise SBOM generation and analysis for vulnerability reporting to specific library version, including embedded libraries • Comprehensive static (SAST), dynamic (DAST), interactive (IAST), and forced-path execution app analysis • Malicious behavior profiling, including app collusion • Checks against privacy & security standards: NIAP, NIST, MASVS

Who Is the Company Behind Quokka Q-mast?

RIPS PHP Analyser

RIPS is the code analysis solution dedicated to the PHP language. It supports all major PHP frameworks, SDLC integration, relevant industry standards and can be deployed as a self-hosted software or used as a cloud service.

Who Is the Company Behind RIPS PHP Analyser?

  • Seller: RIPS Technologies
  • Year Founded: 2008
  • HQ Location: Vernier, Geneva, Switzerland
  • Twitter: @ripstech
    19 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    827 employees on LinkedIn®

Scantist

Scantist is a spin-off company founded in 2016 working to commercialize the vulnerability research carried out at the Cyber Security Lab at Nanyang Technological University.

Who Is the Company Behind Scantist?

  • Seller: Scantist
  • Year Founded: 2016
  • HQ Location: Singapore, SG
  • LinkedIn® Page: www.linkedin.com
    15 employees on LinkedIn®

Sec1 ProSAST

Sec1 is pioneering innovation in cybersecurity by developing advanced, AI-based products that predict and prevent cyber threats before they strike. Sec1 platform offers the smartest way to stay ahead of vulnerabilities, ensuring security policies are enforced from one powerful, unified interface. Sec1 comprehensive suite of services includes: • Software Composition Analysis (SCA): Detect vulnerabilities in third-party components. • Static Application Security Testing (SAST): Identify security issues in source code during development. • Dynamic Application Security Testing (DAST): Simulate attacks to uncover vulnerabilities in running applications. • World’s Largest Vulnerability Database: AI-enhanced real-time threat insights. • Fix Advisor and Auto Fixes: AI-driven, automated vulnerability remediation. • Cloud Security & Container Scanning: Secure your cloud infrastructure and containerized applications. • Penetration Testing & Cyber Risk Assessment: In-depth security evaluations to uncover risks and strengthen defences. • AI-Based Notification Services: Personalized alerts on emerging threats. • AI-Based Threat Predictor: AI-driven insights to predict and prevent future threats. • Generative AI Security: Advanced security solutions for cloud environments and SCA.

Who Is the Company Behind Sec1 ProSAST?

  • Seller: Sec1
  • Year Founded: 2023
  • HQ Location: Pune, IN
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Seczone

Products and Services —————————————— Seczone Group offers a comprehensive suite of products and services covering the entire software security development lifecycle (S-SDLC), including: CodeSec - Code Review Platform for Static Application Security Testing (SAST) VulHunter - Gray Box Security Testing Platform for Interactive Application Security Testing (IAST) SourceCheck - Open Source Component Security and Compliance Management Platform (SCA) SFuzz - Fuzz Testing Platform for identifying vulnerabilities through fuzzing techniques RASP - Real-Time Application Self-Protection Platform for runtime application self-protection S-SDLC - R&D Security Full Process Management Platform for end-to-end security management DevSecOps - Integrated Security Management Platform for R&D and Operations https://www.seczone.com/en/

Who Is the Company Behind Seczone?

Silk Security

Silk security is the platform that enables enterprises to take a strategic, sustainable approach to resolving code, infrastructure and application risk.

Who Is the Company Behind Silk Security?

Snappy Tick

SnappyTick helps to identify the Vulnerability during Source code review.

Who Is the Company Behind Snappy Tick?

Source Code Scanning

Ostorlab Source Code helps teams find and fix security risks directly in their code, without the noise of traditional static analysis. Its agentic testing reviews the surrounding implementation, dependencies, configuration, and usage context to validate whether a risk is actually present, delivering high-confidence findings with no false positives. Teams can scan a selected repository, branch, tag, or commit, review risks in the exact code version assessed, generate complete proposed fixes, and request deeper investigation when additional validation is needed.

Who Is the Company Behind Source Code Scanning?

  • Seller: Ostorlab
  • Year Founded: 2021
  • HQ Location: Middletown, US
  • Twitter: @OstorlabSec
  • LinkedIn® Page: www.linkedin.com
    31 employees on LinkedIn®

SpectralOps

Discover, classify, and protect your codebases, logs, and other assets. Monitor and detect API keys, tokens, credentials, high-risk security misconfiguration and more.

Who Is the Company Behind SpectralOps?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024