Best Static Application Security Testing (SAST) Software - Page 7

How Many Static Application Security Testing (SAST) Software Products Does G2 Track?

Total Products under this Category: 123

Category Stats (Oct 2026)

  • Average Rating: 4.54/5 (↓0.01 vs Sep 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: HCL AppScan (+0.7%) - Among all products in this category, HCL AppScan recorded the largest rating increase compared to last month

Last updated: October 01, 2026

How Does G2 Rank Static Application Security Testing (SAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,600+ Authentic Reviews
  • 123+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Application Security Testing (SAST) Software

G2 Grid® for Static Application Security Testing (SAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, GitGuardian, GitHub, GitLab, SonarQube, Snyk, Semgrep, and Checkmarx.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-application-security-testing-sast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=gitguardian&focus%5B%5D=github&focus%5B%5D=gitlab&focus%5B%5D=sonarqube&focus%5B%5D=snyk&focus%5B%5D=semgrep&focus%5B%5D=checkmarx)

FuzzLabs

FuzzLabs is the most comprehensive fuzzer for finding bugs and zero-day vulnerabilities in custom/proprietary products, protocols, and complex environments.

Who Is the Company Behind FuzzLabs?

  • Seller: Guardara
  • Year Founded: 2018
  • HQ Location: London, GB
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

IDA Pro

IDA Pro is a state-of-the-art, multi-processor disassembler and debugger developed by Hex-Rays. It is widely recognized as the gold standard for reverse engineering and binary analysis, enabling professionals to dissect and understand complex software executables across various platforms. With over thirty years of development, IDA Pro combines powerful static and dynamic analysis tools, offering unparalleled support for a vast array of processor architectures and file formats. Its interactive and programmable environment allows users to navigate through disassembled code efficiently, making it an indispensable tool for malware analysis, vulnerability research, and software debugging. Key Features and Functionality: - Multitarget Disassembler: Supports disassembly for over 60 processor families, allowing analysis of diverse binary files. - Integrated Debugger: Facilitates dynamic analysis with support for local and remote debugging across multiple platforms. - Decompilers: Generates high-level, readable pseudocode from machine code, enhancing code comprehension. - Extensibility: Offers APIs, SDKs, and scripting capabilities (including IDAPython for automation and customization. - Interactive Interface: Allows users to edit and redefine disassembly outputs, providing an intuitive analysis experience. - Security and Reliability: Undergoes continuous improvement with regular updates, rigorous testing, and secure coding practices. Primary Value and User Solutions: IDA Pro addresses the critical need for in-depth binary code analysis by providing a comprehensive suite of tools that transform complex machine code into human-readable formats. This capability is essential for cybersecurity professionals, malware analysts, and software developers who require a deep understanding of software behavior, vulnerabilities, and potential threats. By offering both static and dynamic analysis features, along with extensive customization options, IDA Pro empowers users to efficiently reverse-engineer software, identify security flaws, and develop robust solutions to mitigate risks.

Who Is the Company Behind IDA Pro?

  • Seller: Hex-Rays
  • Year Founded: 2005
  • HQ Location: Liège, BE
  • LinkedIn® Page: www.linkedin.com
    31 employees on LinkedIn®

IMCA.AI Code Vulnerability Scanner

IMCA.AI helps organizations 𝗱𝗲𝘁𝗲𝗰𝘁 𝗺𝗮𝗹𝗶𝗰𝗶𝗼𝘂𝘀 𝗮𝗻𝗱 𝗶𝗻𝘁𝗲𝗻𝘁𝗶𝗼𝗻𝗮𝗹𝗹𝘆 𝗵𝗶𝗱𝗱𝗲𝗻 𝗰𝗼𝗱𝗲 that traditional security scanners miss. Using agentic AI workflows and RAG, IMCA analyzes source code contextually to 𝘂𝗻𝗰𝗼𝘃𝗲𝗿 𝗯𝗮𝗰𝗸𝗱𝗼𝗼𝗿𝘀, 𝗶𝗻𝘀𝗶𝗱𝗲𝗿 𝘁𝗵𝗿𝗲𝗮𝘁𝘀, 𝘀𝘂𝗽𝗽𝗹𝘆-𝗰𝗵𝗮𝗶𝗻 𝗿𝗶𝘀𝗸𝘀, 𝗮𝗻𝗱 𝗼𝗯𝗳𝘂𝘀𝗰𝗮𝘁𝗲𝗱 𝗮𝘁𝘁𝗮𝗰𝗸 𝗽𝗮𝘁𝘁𝗲𝗿𝗻𝘀 — across proprietary and open-source codebases. Our platform 𝗿𝗲𝗱𝘂𝗰𝗲𝘀 𝗺𝗮𝗻𝘂𝗮𝗹 𝗿𝗲𝘃𝗶𝗲𝘄 𝗲𝗳𝗳𝗼𝗿𝘁 𝗯𝘆 𝘂𝗽 𝘁𝗼 𝟵𝟬%, integrates into CI/CD pipelines, and supports secure deployment in SaaS, private cloud, or Swiss-hosted environments. IMCA.AI extends existing SAST tools — so security teams can see what others don’t.

Who Is the Company Behind IMCA.AI Code Vulnerability Scanner?

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

IRIS

CodeEye's IRIS is a next-generation application security posture management (ASPM) platform, offers an all-in-one solution with real-time, AI-powered vulnerability and threat detection, correlation, prioritization, and remediation, easing the tension between time-to-market and risk mitigation. How it Works? Unlike traditional ASPM Solutions, IRIS detects vulnerabilities within the product development lifecycle and application infrastructure, while simultaneously providing continuous penetration testing and attack surface management to production environments. IRIS detects, correlates, provides risk-based analysis, and prioritizes application security findings in real time with automated workflows for remediation – all within one platform. IRIS seamlessly integrates with your tools, pipelines, and workflows, and supports your favourite languages. Unlock the Benefits: 1) Centralize detection, prioritization, and remediation of application threats and vulnerabilities. 2) Real-time actionable insights. 3) Establish resilient DevSecOps processes based on risk management. 4) Implement automated workflows to accelerate the identification and resolution of application risks. 5) Adopt a straightforward licensing model. 6) Ability to measure the effectiveness of your application security program. 7) Deploy within 24 hours with simplicity and ease of operation. 8) Built-in policy compliance measures. Next-Gen ASPM Managed Service In today's digital landscape, organizations grapple with deciphering and prioritizing the criticality of code and application related threats and vulnerabilities. The scarcity and expense of specialized talent capable of bridging the gap between DevOps and SecOps exacerbates this challenge. CodeEye's expertise in Application Security provides a Continuous AppSec Partner, accelerating program maturity with expert guidance and advanced technology. Our IRIS Managed Service centralizes application risk management, helping you define compliance measures and policies for prioritization and remediation, ensuring you grasp and address program risk in real-time. Key Features - Static Application Security Testing (SAST): Scans your source code for security risks before an issue goes to production. - Software Composition Analysis (SCA): Continuously monitors your code for known vulnerabilities and other security risks. - Container Scanning: Scans your container in real time for packages that contain security threats and vulnerabilities. - Dynamic Application Security Testing (DAST): Dynamically tests your production applications for vulnerabilities through simulated attacks. - Attack Surface Management (ASM): Continuously identifies, monitors, and manages external internet-connected assets for potential attack vectors and exposures. - Risk and Compliance: Continuously evaluates regulatory and internal security policy compliance using real-time and historical reporting. Vendor of Record Award CodeEye's IRIS is recognized as a Vendor of Record by the Ministry of Government and Consumer Services for IT Security Products In 2024, NIST updated its Cyber Security Framework (CSF) with significant implications for security by design and secure SDLC. Our Risk and Compliance module supports compliance with NIST CSF 2.0 throughout the software development lifecycle. Gain a comprehensive view of various scanning modules aligned with the CSF's five core functions: Identify, Protect, Detect, Respond, and Recover. Our Difference: An all-in-one platform with straight forward licensing and seamless integration. Your Results: A tool that works with your existing tools and workflows, providing security without hidden costs or complexities. Our Difference: Continuous penetration testing and attack surface management. Your Results: Identify and close gaps before an attacker exploits them across your ever-changing attack surface. Our Difference: Quick and Easy Deployment Your Results: Security monitoring and testing within 24 hours, without extensive setup or training. Our difference: Built-in risk and compliance policy module Your Results: Ensure regulatory and internal compliance with built-in policy measures aligned with industry standards like NIST CSF 2.0. Our Difference: Automated Workflows for remediation. Your Results: Rapid risk mitigation, reducing the time, effort and cost of finding and fixing vulnerabilities to ensure continuous protection. Our Difference: Real-Time, AI-powered vulnerability Your Results: Immediately identify and address security threats with precise, actionable intelligence. Our Difference: Threat and vulnerability detection, correlation, and risk-based analysis. Your Results: Simplified security operations where critical vulnerabilities are addressed first.

Who Is the Company Behind IRIS?

  • Seller: CodeEye
  • Year Founded: 2015
  • HQ Location: Toronto, CA
  • Twitter: @CodeEyeAI
    6 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

IronSCAN

Quick and reliable security assessment platform that scans your mobile application for vulnerabilities without the need for high-profile penetration testing's. IronSCAN assessment platform provides quick and easy vulnerability identification and remediation, without the need for custom plugins or programming. Scan across multiple platforms and applications with ease using integrated scanners. Audit your entire infrastructure in minutes, not days!

Who Is the Company Behind IronSCAN?

  • Seller: SecIron
  • Year Founded: 2017
  • HQ Location: Tokyo, JP
  • LinkedIn® Page: www.linkedin.com
    15 employees on LinkedIn®

Magdox

MAGDOX Code Security reviews source code, dependencies, secrets, configuration and cryptographic usage. The scan runs on your developer machines and CI runners, so your source code never leaves your environment. Only findings go to one dashboard, where security teams track every repository, triage, record decisions and export reports in SARIF, CycloneDX and SPDX.

Who Is the Company Behind Magdox?

  • Seller: Magdox
  • Year Founded: 2025
  • HQ Location: N/A
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Mobix

Mobix is a SaaS mobile application testing platform that reduces application analysis costs and time, making tests creation and finding vulnerabilities effortless. Mobix's unique characteristics include: - Non-invasive tool, which augments existing SDLC (Software Development Life Cycle) - Automates 90% of the entire test coverage for dynamic and static analysis - No code, plug and play analysis - Automated recording of tests - Machine Learning to automatically adapt auto-tests - Scalable multithread testing, custom scan rules - Compliance to all major mobile security standards

Who Is the Company Behind Mobix?

Nullify

The post-human product security program. Nullify continuously allocates AI capacity toward the highest-impact product security work, maximizing outcomes from every engineer hour and every token spent.

Who Is the Company Behind Nullify?

  • Seller: Nullify
  • Company Website:
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    27 employees on LinkedIn®

Panel Review by TruVerifAI

Panel Review is the guardian agent for AI's highest-stakes coding decisions. Before an agent's riskiest designs, diffs, or commits ship, four frontier models, from OpenAI, Anthropic, Google, and xAI, argue them through and return severity-tagged findings, with review gates the agent cannot silently skip. A single model reviewer can share blind spots with the model that wrote the code, including a documented tendency to rate its own family's output more favorably. Four independently trained models don't share those specific gaps: on hard review cases, different models catch different failure classes, and no single model produces the complete findings set. Panel Review's consensus mechanism finds where the models genuinely disagree and makes them argue it through: cross-examination, not polling, so the strongest argument survives instead of the disagreement getting averaged away. That is what makes it useful inside the agent loop: it catches blind spots before the write and before the commit, not after a PR is open. In ten weeks of live production use building this product, 46% of audits surfaced at least one critical or major issue and 66% of acted-on review calls changed the agent's decision, including a prompt injection hole caught one commit from production. The client is open source with zero runtime dependencies, so you can npm pack and read every line before installing: no build step and no transitive supply chain, MIT licensed.

Who Is the Company Behind Panel Review by TruVerifAI?

Proscan

Proscan is a unified application security platform designed to help organizations streamline the management of their security tools. By integrating multiple standalone solutions into a single cohesive experience, Proscan provides comprehensive security visibility across the entire software stack. This platform replaces the complexity of managing various tools for static analysis, dynamic testing, and dependency scanning, allowing teams to focus on building secure applications without the hassle of juggling disparate systems. The platform is particularly beneficial for security teams, developers, and engineering leaders who require a consolidated view of application security risks. Proscan combines nine specialized security scanners, including Static Application Security Testing (SAST), which analyzes source code in over 30 programming languages using advanced detection methods. Dynamic Application Security Testing (DAST) further enhances security by testing live applications, identifying vulnerabilities that may only become apparent during runtime. Additionally, Software Composition Analysis (SCA) evaluates open-source dependencies across 196 package ecosystems, helping organizations detect known vulnerabilities before they can impact production environments. Proscan's capabilities extend beyond code analysis. It includes scanning for hardcoded secrets, misconfigurations in Infrastructure-as-Code, and vulnerabilities in container images. The platform also offers API security testing that validates endpoints against the OWASP API Security Top 10, ensuring robust protection for applications that leverage APIs. For organizations developing AI-powered applications, Proscan features a dedicated AI and LLM security scanner that identifies potential risks associated with prompt injections and other vulnerabilities, utilizing over 4,600 techniques mapped to the OWASP LLM Top 10. Artificial intelligence plays a crucial role in enhancing Proscan's efficiency and accuracy. The platform employs machine-learning algorithms to reduce false positives and prioritize vulnerabilities based on their potential impact. This intelligent approach allows teams to focus on the most critical security issues while providing clear explanations and actionable remediation guidance. Proscan integrates seamlessly into existing development workflows, offering IDE plugins and native CI/CD integrations that ensure security checks are part of the development process without causing disruptions. Compliance readiness is another key feature of Proscan, as it generates audit-ready reports aligned with major security standards, including OWASP Top 10, PCI DSS, HIPAA, and GDPR. This automated evidence collection simplifies the compliance process, providing organizations with the necessary documentation in various formats. Proscan is designed for security teams looking to consolidate fragmented toolchains, developers needing quick feedback, and managed security service providers managing multiple client environments, making it a versatile solution for modern application security challenges.

Who Is the Company Behind Proscan?

Puma Scan

Puma Scan runs as engineers write code. Real-time results. Puma Scan Editions include Server, Azure DevOps and End User.

Who Is the Company Behind Puma Scan?

  • Seller: Puma Scan
  • Year Founded: 2016
  • HQ Location: West Des Moines, US
  • Twitter: @puma_scan
    300 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    16 employees on LinkedIn®

PVS-Studio

PVS-Studio is a static application security testing (SAST) solution that helps enhance code quality, security, and safety. It detects bugs and potential vulnerabilities in C, C++, C#, Java, JavaScript, TypeScript and Go code on Windows, Linux, and macOS. Features: - Supports various analysis types: intermodular, incremental, data flow analysis, taint analysis; - Integrates into cloud platforms; - Works offline & on-premise; - Provides cross-platform integration; - Offers ways to handle false positives; - Quick technical support directly from developers; - 1200+ diagnostic rules with detailed descriptions and examples; - Compliance with safety & security standards: OWASP TOP 10, MISRA C/C++, CWE, SEI CERT; - Detailed reports and reminders for developers and managers; - Efficiently handles legacy code (baselining of analyzer results); - Active support of the Open Source Community, analysis of open-source projects; - Integration with popular IDEs, code quality platforms, CI/CD, build systems. Good option for: - game developers (Unity & UE integration included) - embedded developers (embedded platform support); - DevSecOps experts (CLI) - project managers (code quality platform integration included) - FinTech (compliance with OWASP ASVS) - mature projects (seamless legacy handling) More on website: pvs-studio.com Pricing - In the commercial version, prices are set on request and can be changed depending on the required set of features; - Free trial is available; - PVS-Studio may offer a free licensing option to students, MVPs, public experts in security, and contributors to open-source projects.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate PVS-Studio?

  • Quality of Support: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind PVS-Studio?

  • Seller: PVS-Studio
  • Year Founded: 2008
  • HQ Location: Astana, KZ
  • Twitter: @Code_Analysis
    5,907 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    29 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of PVS-Studio?

What Are G2 Users Discussing About PVS-Studio?

Quokka Q-mast

Designed for app development, Q-mast embeds security directly into your workflow to identify security, privacy, and compliance risks before the mobile app is released. With a design tailored for DevSecOps workflows, Q-mast supports continuous, automated security testing that aligns with tools like Jenkins, GitLab, and GitHub. Q-mast capabilities: • Automated scanning in minutes, no source code needed • Analysis of compiled app binary, regardless of in-app or run-time obfuscations • Precise SBOM generation and analysis for vulnerability reporting to specific library version, including embedded libraries • Comprehensive static (SAST), dynamic (DAST), interactive (IAST), and forced-path execution app analysis • Malicious behavior profiling, including app collusion • Checks against privacy & security standards: NIAP, NIST, MASVS

Who Is the Company Behind Quokka Q-mast?

Risk Matrix

Free AI-powered risk scan for legacy VB6 applications. Zero source code exposure. Results in minutes.

Who Is the Company Behind Risk Matrix?

  • Seller: Macrosoft
  • Year Founded: 1993
  • HQ Location: Bedminster, US
  • LinkedIn® Page: www.linkedin.com
    735 employees on LinkedIn®
Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024