Best Static Application Security Testing (SAST) Software - Page 8

How Many Static Application Security Testing (SAST) Software Products Does G2 Track?

Total Products under this Category: 123

Category Stats (Oct 2026)

  • Average Rating: 4.54/5 (↓0.01 vs Sep 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: HCL AppScan (+0.7%) - Among all products in this category, HCL AppScan recorded the largest rating increase compared to last month

Last updated: October 01, 2026

How Does G2 Rank Static Application Security Testing (SAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,600+ Authentic Reviews
  • 123+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Static Application Security Testing (SAST) Software

G2 Grid® for Static Application Security Testing (SAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, GitGuardian, GitHub, GitLab, SonarQube, Snyk, Semgrep, and Checkmarx.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-application-security-testing-sast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=gitguardian&focus%5B%5D=github&focus%5B%5D=gitlab&focus%5B%5D=sonarqube&focus%5B%5D=snyk&focus%5B%5D=semgrep&focus%5B%5D=checkmarx)

Scantist

Scantist is a spin-off company founded in 2016 working to commercialize the vulnerability research carried out at the Cyber Security Lab at Nanyang Technological University.

Who Is the Company Behind Scantist?

  • Seller: Scantist
  • Year Founded: 2016
  • HQ Location: Singapore, SG
  • LinkedIn® Page: www.linkedin.com
    15 employees on LinkedIn®

Sec1 ProSAST

Sec1 is pioneering innovation in cybersecurity by developing advanced, AI-based products that predict and prevent cyber threats before they strike. Sec1 platform offers the smartest way to stay ahead of vulnerabilities, ensuring security policies are enforced from one powerful, unified interface. Sec1 comprehensive suite of services includes: • Software Composition Analysis (SCA): Detect vulnerabilities in third-party components. • Static Application Security Testing (SAST): Identify security issues in source code during development. • Dynamic Application Security Testing (DAST): Simulate attacks to uncover vulnerabilities in running applications. • World’s Largest Vulnerability Database: AI-enhanced real-time threat insights. • Fix Advisor and Auto Fixes: AI-driven, automated vulnerability remediation. • Cloud Security & Container Scanning: Secure your cloud infrastructure and containerized applications. • Penetration Testing & Cyber Risk Assessment: In-depth security evaluations to uncover risks and strengthen defences. • AI-Based Notification Services: Personalized alerts on emerging threats. • AI-Based Threat Predictor: AI-driven insights to predict and prevent future threats. • Generative AI Security: Advanced security solutions for cloud environments and SCA.

Who Is the Company Behind Sec1 ProSAST?

  • Seller: Sec1
  • Year Founded: 2023
  • HQ Location: Pune, IN
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Seczone

Products and Services —————————————— Seczone Group offers a comprehensive suite of products and services covering the entire software security development lifecycle (S-SDLC), including: CodeSec - Code Review Platform for Static Application Security Testing (SAST) VulHunter - Gray Box Security Testing Platform for Interactive Application Security Testing (IAST) SourceCheck - Open Source Component Security and Compliance Management Platform (SCA) SFuzz - Fuzz Testing Platform for identifying vulnerabilities through fuzzing techniques RASP - Real-Time Application Self-Protection Platform for runtime application self-protection S-SDLC - R&D Security Full Process Management Platform for end-to-end security management DevSecOps - Integrated Security Management Platform for R&D and Operations https://www.seczone.com/en/

Who Is the Company Behind Seczone?

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

Silk Security

Silk security is the platform that enables enterprises to take a strategic, sustainable approach to resolving code, infrastructure and application risk.

Who Is the Company Behind Silk Security?

Snappy Tick

SnappyTick helps to identify the Vulnerability during Source code review.

Who Is the Company Behind Snappy Tick?

Source Code Scanning

Ostorlab Source Code helps teams find and fix security risks directly in their code, without the noise of traditional static analysis. Its agentic testing reviews the surrounding implementation, dependencies, configuration, and usage context to validate whether a risk is actually present, delivering high-confidence findings with no false positives. Teams can scan a selected repository, branch, tag, or commit, review risks in the exact code version assessed, generate complete proposed fixes, and request deeper investigation when additional validation is needed.

Who Is the Company Behind Source Code Scanning?

  • Seller: Ostorlab
  • Year Founded: 2021
  • HQ Location: Middletown, US
  • Twitter: @OstorlabSec
  • LinkedIn® Page: www.linkedin.com
    31 employees on LinkedIn®

SpectralOps

Discover, classify, and protect your codebases, logs, and other assets. Monitor and detect API keys, tokens, credentials, high-risk security misconfiguration and more.

Who Is the Company Behind SpectralOps?

Splint

Splint is a tool for statically checking C programs for security vulnerabilities and coding mistakes. With minimal effort, Splint can be used as a better lint. If additional effort is invested adding annotations to programs, Splint can perform stronger checking than can be done by any standard lint.

Who Is the Company Behind Splint?

SpotBugs

The SpotBugs plugin for security audits of Java web applications can detect 131 different vulnerability types with over 811 unique API signatures.

Who Is the Company Behind SpotBugs?

ThunderScan

DefenseCode ThunderScan® is a SAST (Static Application Security Testing, WhiteBox Testing) solution for performing deep and extensive security analysis of application source code. ThunderScan® is easy to use, requires almost no user input and can be deployed during or after development with easy integration into your DevOps environment and CI/CD pipeline. Our SAST solution provides an excellent way to automate code inspection as an alternative to the demanding and time-consuming procedure of manual code reviews. Find out why large enterprises are replacing their current SAST solutions with DefenseCode ThunderScan® SAST. With DefenseCode ThunderScan® SAST it is possible to scan millions of source code lines across 29 different programming languages and various programming frameworks within hours or even minutes. Scalability combined with repeatability of automation provides an easy and painless way to introduce security into your DevOps for organizations ranging from small development teams up to the largest enterprises. ThunderScan® includes a Dependency Check component (Software Composition Analysis – SCA) that will detect publicly disclosed vulnerabilities contained within a project’s dependencies with associated CVE entries. Application source code security analysis has proven consistently to be the most comprehensive way to ensure that your application is free of security vulnerabilities (SQL Injections, Cross Site Scripting, Path/Directory Traversal, Code Injection, and many more.). With ThunderScan® SAST it is very easy to meet the compliance standards requirements such as PCI-DSS, SANS/CWE Top 25, OWASP Top 10, HIPPA, HITRUST or NIST. ThunderScan® SAST easy to use and very powerful REST API allows you to customize source code scanning and scale across large number of scanning agents. DefenseCode ThunderScan® has repeatedly recognized its effectiveness by discovering critical vulnerabilities in well known open source application.

Who Is the Company Behind ThunderScan?

Topscan

Topscan is a continuous security monitoring platform for the DevOps engineer or CTO who owns security among other things. It covers the whole delivery pipeline in one subscription — static analysis in your code, dynamic scanning of live applications and infrastructure, and continuous monitoring of everything you expose to the internet — instead of three separate vendors for SAST, DAST and attack surface management. Perimeter. External infrastructure scanning reports open ports, service versions and known server vulnerabilities matched against CVE databases, with unlimited scheduled rescans. Asset discovery maps the subdomains and hosts you forgot about — the Grafana, the Sentry, the staging box nobody remembers deploying — and new hosts arrive with a review prompt: you confirm ownership before anything is scanned. Attack surface monitoring keeps every exposed service inventoried, and certificate watch catches TLS/SSL expiry weeks early instead of on the Friday night it happens. Applications and code. Web application scanning runs OWASP-class checks against live apps: SQL injection, XSS, exposed admin panels, default credentials, missing headers. Static application security testing covers three kinds of risk in one scan — vulnerable code patterns, committed secrets and keys, and known CVEs in dependencies (software composition analysis) — on every commit, pointing at the exact file and line. Pipeline and cloud. A CI/CD webhook gives you a unique event link to call from the last step of your deploy script: no API keys, no agent, nothing installed on your servers. AWS connects with keys you issue to discover EC2 and Route 53 resources, which are added to monitoring and rescanned when they change. Workflow. Findings are deduplicated and carry severity in your context, CVSS, a first-seen date and an SLA clock with overdue flags. Snooze what you accept, mark false positives and they stop resurfacing, and work through a large backlog in triage mode. Informational findings stay out of the feed and never touch your score. One security score tracks the whole estate over time — the number you show yourself, your CEO or an auditor. Alerts reach the team in Slack or Microsoft Teams and turn into Jira tickets; chat and tracker routing starts on the Advanced plan. Audit and compliance. Auditors ask for evidence of regular scanning and an inventory of what is exposed: scan history with downloadable reports and an exportable asset inventory answer both, which is what most teams use Topscan for ahead of SOC 2, ISO 27001 or a customer security review. Auditor seats are free and read-only, and users are unlimited on every plan. Pricing starts at $129 per month and is published on the site — no demo call required to see it — with a 14-day free trial of the full plan and no credit card. Add a domain and the first map of your perimeter arrives in five to ten minutes.

Average Rating: 4.9/5.0

Total Reviews: 4

How Do G2 Users Rate Topscan?

  • Quality of Support: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind Topscan?

  • Seller: Topscan
  • Year Founded: 2024
  • HQ Location: Dubai, AE
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 75% Small, 25% Medium

What Are Recent G2 Reviews of Topscan?

Traceable

Traceable is a document-style workspace that keeps your design records connected and visible. It replaces spreadsheets, wikis and disconnected tools with one place to author, trace, control, review and publish the documentation your standards demand, with live traceability, gated e-signatures and audit-ready output. It manages your source of truth for any product development, especially regulated products such as medical device, SaMD, IVD and Defence. Adaptable to any standard ISO 9001, ISO 13485, ISO 14971, IEC 62304 and more.

Who Is the Company Behind Traceable?

TrueCode

TrueCode is a static application security testing solution.

Who Is the Company Behind TrueCode?

  • Seller: SiteLock
  • Year Founded: 2008
  • HQ Location: Scottsdale, AZ
  • Twitter: @SiteLock
    2,440 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    90 employees on LinkedIn®

TruStacks

TruStacks is a software delivery engine that offers standardized, efficient DevOps workflows to help teams ship products faster and more frequently.

Who Is the Company Behind TruStacks?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024