Best Static Application Security Testing (SAST) Software - Page 8

How Many Static Application Security Testing (SAST) Software Products Does G2 Track?

Total Products under this Category: 113

Category Stats (Aug 2026)

  • Average Rating: 4.54/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Coverity Static (+0.61%) - Among all products in this category, Black Duck Coverity Static recorded the largest rating increase compared to last month

Last updated: August 12, 2026

How Does G2 Rank Static Application Security Testing (SAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 113+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Application Security Testing (SAST) Software

G2 Grid® for Static Application Security Testing (SAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, GitHub, GitGuardian, GitLab, SonarQube, Semgrep, Snyk, and OX Security.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-application-security-testing-sast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=github&focus%5B%5D=gitguardian&focus%5B%5D=gitlab&focus%5B%5D=sonarqube&focus%5B%5D=semgrep&focus%5B%5D=snyk&focus%5B%5D=ox-security)

Sponsored

Tremendous

Tremendous Overview Tremendous is the global payouts platform for businesses sending gift cards and money at scale. Trusted by 20,000+ leading organizations, Tremendous has delivered billions of rewards and enables businesses to reach recipients across 200+ countries and regions. From research incentives to marketing and sales rewards to employee recognition programs, the free-to-use platform makes it easy to send thousands of payouts quickly. How Tremendous Works Getting started is simple: add a funding method and place your first order in minutes. Teams can send rewards via bulk upload, integration, or API. Tremendous automates language translation, currency conversion, tracking, and reporting, and includes built-in fraud controls. The result? Teams can focus on the work that matters most while Tremendous handles all the payout details. Gift Card and Payout Options Tremendous offers 2,500+ popular payout options, including gift card options, prepaid cards, monetary payouts, and donations. Teams can choose to offer curated reward options or give recipients the freedom to choose what works best for them. If recipients ever run into redemption issues, the Tremendous support team handles them directly. Pricing Tremendous is free to use with no minimums or subscription fees. Most businesses only spend what they send, while high-volume customers have opportunities to explore discounted pricing to stretch their budgets further. Integrations and Automation Tremendous integrates seamlessly with the tools businesses already use, including Salesforce, HubSpot, Qualtrics, SurveyMonkey, Zapier, and more. Developers can also use our easy-to-implement API to automate reward delivery at scale. Why Organizations Choose Tremendous Tremendous combines an extensive reward catalog, global reach, automation, and best-in-class support in one free-to-use platform. With billions in rewards delivered across millions of payouts, Tremendous is the platform businesses trust to send incentives worldwide.

Visit website

Splint

Splint is a tool for statically checking C programs for security vulnerabilities and coding mistakes. With minimal effort, Splint can be used as a better lint. If additional effort is invested adding annotations to programs, Splint can perform stronger checking than can be done by any standard lint.

Who Is the Company Behind Splint?

SpotBugs

The SpotBugs plugin for security audits of Java web applications can detect 131 different vulnerability types with over 811 unique API signatures.

Who Is the Company Behind SpotBugs?

ThunderScan

DefenseCode ThunderScan® is a SAST (Static Application Security Testing, WhiteBox Testing) solution for performing deep and extensive security analysis of application source code. ThunderScan® is easy to use, requires almost no user input and can be deployed during or after development with easy integration into your DevOps environment and CI/CD pipeline. Our SAST solution provides an excellent way to automate code inspection as an alternative to the demanding and time-consuming procedure of manual code reviews. Find out why large enterprises are replacing their current SAST solutions with DefenseCode ThunderScan® SAST. With DefenseCode ThunderScan® SAST it is possible to scan millions of source code lines across 29 different programming languages and various programming frameworks within hours or even minutes. Scalability combined with repeatability of automation provides an easy and painless way to introduce security into your DevOps for organizations ranging from small development teams up to the largest enterprises. ThunderScan® includes a Dependency Check component (Software Composition Analysis – SCA) that will detect publicly disclosed vulnerabilities contained within a project’s dependencies with associated CVE entries. Application source code security analysis has proven consistently to be the most comprehensive way to ensure that your application is free of security vulnerabilities (SQL Injections, Cross Site Scripting, Path/Directory Traversal, Code Injection, and many more.). With ThunderScan® SAST it is very easy to meet the compliance standards requirements such as PCI-DSS, SANS/CWE Top 25, OWASP Top 10, HIPPA, HITRUST or NIST. ThunderScan® SAST easy to use and very powerful REST API allows you to customize source code scanning and scale across large number of scanning agents. DefenseCode ThunderScan® has repeatedly recognized its effectiveness by discovering critical vulnerabilities in well known open source application.

Who Is the Company Behind ThunderScan?

TrueCode

TrueCode is a static application security testing solution.

Who Is the Company Behind TrueCode?

  • Seller: SiteLock
  • Year Founded: 2008
  • HQ Location: Scottsdale, AZ
  • Twitter: @SiteLock
    2,440 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    90 employees on LinkedIn®

TruStacks

TruStacks is a software delivery engine that offers standardized, efficient DevOps workflows to help teams ship products faster and more frequently.

Who Is the Company Behind TruStacks?

we45

AppSec Testing(AST) - Whatever your motivation, a proactive security push or a compliance compulsion, our AST service can help keep your application secure against external threats. Security Automation - Secure your agile Software Development Life Cycle(SDLC) without compromising on quality or time. AppSec Training - Our numerous/variegated training offerings help product teams gain the security understanding necessary to keep their deployments secure. Orchestron - Make Application Security efficient with one of the most integral parts of a modern DevSecOps toolchain - An AVC engine. Threat PlayBook - A (relatively) Unopinionated framework that faciliates Threat Modeling as Code married with Application Security Automation on a single Fabric. Perform Iterative Threat Modeling in an Agile Environment with Threat Playbook.

Who Is the Company Behind we45?

  • Seller: we45
  • Year Founded: 2019
  • HQ Location: San Jose, US
  • LinkedIn® Page: www.linkedin.com
    37 employees on LinkedIn®

YAG-Suite

YAGAAN is a french startup established in 2017 and located in the Brittany Cyber Valley. In the SAST landscape, the YAG-Suite offers unique features to auditors and developers that only machine learning can bring on top of static analysis : - Smart detection of vulnerabilities - Automated qualification and hierarchization of the warnings raised by SAST, based on their likeliness to be true positives and their criticallity (individual CVSS score) - Advanced diagnostics of the detected vulnerabilities to help users understand their causes - Remediation support with recommended vulnerability fix - Code mining queries to help auditors and experts to accelerate further manual investigations The Scanner is available in saas access or on premise to be integrated in CI/CD Request your free saas trial at https://yagaan.com/en/

Who Is the Company Behind YAG-Suite?

  • Seller: YAGAAN
  • Year Founded: 2010
  • HQ Location: Paris, FR
  • LinkedIn® Page: linkedin.com
    41 employees on LinkedIn®

ZeroNorth

Continuous security delivery fabric for modern enterprise infrastructure.

Who Is the Company Behind ZeroNorth?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024