Best Vulnerability Scanner Software with Static Code Analysis Capabilities

How Many Vulnerability Scanner Software Products Does G2 Track?

Total Products under this Category: 236

Category Stats (Sep 2026)

  • Average Rating: 4.59/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Armis (+0.18%) - Among all products in this category, Armis recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Vulnerability Scanner Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 7,800+ Authentic Reviews
  • 236+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Vulnerability Scanner Software

G2 Grid® for Vulnerability Scanner Software plotting products by satisfaction and market presence

Highlighted products: Wiz, Aikido Security, CrowdStrike Falcon Cloud Security, Orca Security, Tenable Nessus, Astra Pentest, Intruder, and Burp Suite.

Underlying data: [Grid® JSON](https://www.g2.com/categories/vulnerability-scanner/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=orca-security&focus%5B%5D=tenable-nessus&focus%5B%5D=astra-pentest&focus%5B%5D=intruder&focus%5B%5D=burp-suite)

Amazon Inspector

Amazon Inspector est un service de gestion des vulnérabilités automatisé qui analyse en continu les charges de travail AWS, y compris les instances Amazon EC2, les images de conteneurs dans Amazon ECR, les fonctions AWS Lambda et les dépôts de code, à la recherche de vulnérabilités logicielles et d'expositions réseau non intentionnelles. En s'intégrant parfaitement aux environnements AWS, il fournit une détection en temps réel et une priorisation des problèmes de sécurité, permettant aux organisations d'améliorer efficacement leur posture de sécurité. Caractéristiques clés et fonctionnalités : - Découverte automatisée et analyse continue : Identifie et évalue automatiquement les ressources AWS pour les vulnérabilités et les expositions réseau, garantissant une couverture complète sans intervention manuelle. - Évaluation des risques contextualisée : Génère des scores de risque en corrélant les données de vulnérabilité avec des facteurs environnementaux tels que l'accessibilité réseau et l'exploitabilité, aidant à la priorisation des efforts de remédiation. - Intégration avec les services AWS : S'intègre parfaitement avec AWS Security Hub et Amazon EventBridge, facilitant les flux de travail automatisés et la gestion centralisée des résultats de sécurité. - Prise en charge de plusieurs types de ressources : Étend la gestion des vulnérabilités à divers services AWS, y compris les instances EC2, les images de conteneurs, les fonctions Lambda et les dépôts de code, fournissant une évaluation de sécurité unifiée à travers l'environnement cloud. - Analyse sans agent pour les instances EC2 : Offre une surveillance continue des instances EC2 pour les vulnérabilités logicielles sans besoin d'installer des agents supplémentaires, simplifiant le déploiement et la maintenance. Valeur principale et problème résolu : Amazon Inspector répond au besoin critique de gestion continue et automatisée des vulnérabilités au sein des environnements AWS. En fournissant une détection en temps réel et une priorisation des problèmes de sécurité, il permet aux organisations d'identifier et de remédier de manière proactive aux vulnérabilités, réduisant le risque de violations de sécurité et assurant la conformité avec les normes de l'industrie. Son intégration avec les services AWS existants et son support pour divers types de ressources rationalisent les opérations de sécurité, permettant aux équipes de se concentrer sur des initiatives stratégiques tout en maintenant une posture de sécurité robuste.

Average Rating: 4.4/5.0

Total Reviews: 25

How Do G2 Users Rate Amazon Inspector?

  • the product a-t-il été un bon partenaire commercial?: 9.3/10 (Category avg: 9.2/10)
  • Taux de détection: 9.2/10 (Category avg: 9.0/10)
  • Analyses automatisées: 9.2/10 (Category avg: 9.1/10)
  • Surveillance de la configuration: 7.8/10 (Category avg: 8.5/10)

Who Is the Company Behind Amazon Inspector?

  • Vendeur: Amazon Web Services (AWS)
  • Année de fondation: 2006
  • Emplacement du siège social: Seattle, WA
  • Twitter: @awscloud
    2,232,483 abonnés Twitter
  • Page LinkedIn®: www.linkedin.com
    147,094 employés sur LinkedIn®
  • Propriété: NASDAQ: AMZN

Who Uses This Product?

  • Top Industries: Logiciels informatiques
  • Company Size: 41% Small, 33% Medium

What Do G2 Reviewers Say About Amazon Inspector?

AI-generated summary from verified user reviews

Pros
  • Les utilisateurs apprécient les alertes de sécurité fournies par Amazon Inspector, ce qui améliore leur capacité à répondre efficacement aux vulnérabilités.
  • Les utilisateurs louent le excellent support client d'AWS, améliorant leur expérience et aidant à la gestion de la sécurité.
  • Les utilisateurs apprécient les capacités de gestion centralisée d'Amazon Inspector, améliorant la surveillance et la conformité dans leur environnement.
  • Les utilisateurs apprécient les capacités collaboratives d'Amazon Inspector, améliorant efficacement leurs efforts de surveillance de la sécurité et de conformité.
  • Les utilisateurs louent la détection automatisée des problèmes de sécurité d'Amazon Inspector, appréciant sa facilité d'installation et ses conseils.
Cons
  • Les utilisateurs trouvent que la complexité de la configuration d'Amazon Inspector peut entraver une mise en œuvre efficace de la sécurité sans formation adéquate.
  • Les utilisateurs rencontrent des problèmes de complexité avec Amazon Inspector, car une connaissance avancée est nécessaire pour une configuration et une sécurité efficaces.
  • Les utilisateurs estiment que la pour Amazon Inspector est abrupte, nécessitant des administrateurs bien formés pour une utilisation efficace.
  • Les utilisateurs trouvent qu'Amazon Inspector a des fonctionnalités limitées, ce qui rend difficile de répondre efficacement à des besoins de sécurité spécifiques.
  • Les utilisateurs trouvent qu'Amazon Inspector n'est pas convivial, nécessitant des connaissances avancées pour une configuration et une gestion de la sécurité appropriées.

What Are Recent G2 Reviews of Amazon Inspector?

Invicti

Invicti (formerly known as Netsparker) is an enterprise application and API security testing platform that helps organizations secure thousands of web applications and APIs at scale while dramatically reducing the risk of attack. Combining advanced DAST and IAST capabilities in a single platform, Invicti enables security teams to continuously identify, prioritize, and remediate vulnerabilities across complex modern environments with confidence and automation. With Invicti, security teams can: - Automate application security testing workflows and save hundreds of hours every month - Discover and secure all web applications and APIs, including forgotten, unmanaged, and shadow assets - Deliver actionable, developer-friendly feedback that helps teams remediate vulnerabilities faster and build more secure code over time - Reduce false positives with proof-based scanning technology that validates exploitable vulnerabilities - Scale application security programs across large enterprises without slowing development teams - Integrate security seamlessly into existing DevSecOps and CI/CD workflows Built for organizations with the most demanding security requirements, Invicti empowers teams to confidently secure their entire attack surface with accuracy, scalability, and automation.

Average Rating: 4.5/5.0

Total Reviews: 69

How Do G2 Users Rate Invicti?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)
  • Detection Rate: 9.0/10 (Category avg: 9.0/10)
  • Automated Scans: 9.1/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    326 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 46% Large, 29% Medium

What Do G2 Reviewers Say About Invicti?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Invicti, facilitating quick setup and effective vulnerability scanning in their workflow.
  • Users value the quick and easy scanning technology of Invicti, enhancing workflow efficiency and accuracy in vulnerability detection.
  • Users value the simplicity and integration of Invicti, enhancing security measures through user-friendly report generation and detailed views.
  • Users value the easy-to-read and well-formatted reports from Invicti, enhancing efficiency and supporting ISO certification needs.
  • Users value the high accuracy and ease of use in Invicti's vulnerability detection, effectively identifying true issues.
Cons
  • Users find the customer support lacking, often experiencing slow responses and inadequate technical assistance.
  • Users experience slow performance during scans and setups, impacting overall efficiency and satisfaction.
  • Users experience slow scanning issues with Invicti, often leading to frustrating delays during the scanning process.
  • Users face API scanning issues with Invicti, limiting its effectiveness for their specific needs despite decent support.
  • Users find the complex setup of Invicti challenging initially, hindering their ability to quickly navigate configurations.

What Are Recent G2 Reviews of Invicti?

What Are G2 Users Discussing About Invicti?

Acunetix by Invicti

Acunetix (by Invicti) is an automated application security testing tool that enables small security teams to tackle huge application security challenges. With fast scanning, comprehensive results, and intelligent automation, Acunetix helps organizations to reduce risk across all types of web applications, websites, and APIs. With Acunetix, security teams can: - Save time and resources by automating manual security processes - Work more seamlessly with developers, or embrace DevSecOps by integrating directly into development tools - Feel confident that every web application has been crawled entirely thanks to DAST + IAST scanning and intelligent crawling technology - Finally, make web application and API security a priority and not just an add-on with a solution that is dedicated to application and API security 100% of the time You can depend on Acunetix to meet your organization’s needs today and face the challenges of modern web technology together tomorrow.

Average Rating: 4.1/5.0

Total Reviews: 100

How Do G2 Users Rate Acunetix by Invicti?

  • Has the product been a good partner in doing business?: 8.2/10 (Category avg: 9.2/10)
  • Detection Rate: 8.5/10 (Category avg: 9.0/10)
  • Automated Scans: 8.6/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 7.9/10 (Category avg: 8.5/10)

Who Is the Company Behind Acunetix by Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    326 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 40% Large, 34% Medium

What Do G2 Reviewers Say About Acunetix by Invicti?

AI-generated summary from verified user reviews

Pros
  • Users value the accurate and fast vulnerability detection of Acunetix, enhancing their security scanning capabilities efficiently.
  • Users praise the ease of use of Acunetix, highlighting its simple integration and effective security scanning capabilities.
  • Users value the robust security features of Acunetix, enhancing the safety of web applications effectively.
  • Users value the effective vulnerability identification by Acunetix, enhancing web application security and streamlining remediation processes.
  • Users highlight the accuracy of results from Acunetix, noting its impressive ability to identify vulnerabilities effectively.
Cons
  • Users find Acunetix by Invicti to be expensive, making it less accessible for smaller teams or projects.
  • Users find Acunetix's complex setup and resource intensity challenging, especially for large applications and first-time configurations.
  • Users find the setup process complex, particularly for new users and large application configurations.
  • Users note that the scanning process is often slow, affecting efficiency and delaying normal workflows, especially with large applications.
  • Users find the difficult customization of Acunetix challenging, requiring technical expertise to set up and fine-tune integrations.

What Are Recent G2 Reviews of Acunetix by Invicti?

What Are G2 Users Discussing About Acunetix by Invicti?

Kiuwan Code Security & Insights

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

Average Rating: 4.5/5.0

Total Reviews: 29

How Do G2 Users Rate Kiuwan Code Security & Insights?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.2/10)
  • Detection Rate: 8.5/10 (Category avg: 9.0/10)
  • Automated Scans: 8.6/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 6.5/10 (Category avg: 8.5/10)

Who Is the Company Behind Kiuwan Code Security & Insights?

  • Seller: Sembi
  • Company Website:
  • Year Founded: 2023
  • HQ Location: Austin, US
  • LinkedIn® Page: www.linkedin.com
    94 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Banking
  • Company Size: 41% Large, 35% Medium

What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the accuracy of the results from Kiuwan Code Security & Insights, enhancing their overall experience.
  • Users value the accuracy of findings from Kiuwan, enhancing their satisfaction with code security and reporting.
  • Users commend the efficient customer support of Kiuwan, ensuring timely assistance and strong satisfaction overall.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, making it very easy to navigate.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, enhancing ease of use for dashboards.

What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

Zenmap

Zenmap is the official graphical user interface (GUI) for the Nmap Security Scanner, designed to make network scanning accessible for both beginners and experienced users. This multi-platform, free, and open-source application supports operating systems such as Linux, Windows, Mac OS X, and BSD. Zenmap simplifies the process of network discovery and security auditing by providing an intuitive interface to Nmap's powerful features. Key Features and Functionality: - Profile Management: Users can save frequently used scans as profiles, enabling quick and consistent execution of routine network assessments. - Command Creation: An interactive command creator assists in building Nmap command lines, making it easier to customize scans without extensive command-line knowledge. - Result Management: Scan results can be saved for future reference, compared to identify changes over time, and are stored in a searchable database for efficient retrieval. - Network Topology Visualization: Zenmap offers an interactive, animated visualization of network topology, illustrating the relationships and paths between hosts. - Cross-Platform Compatibility: The application runs on multiple operating systems, ensuring flexibility and broad accessibility. Primary Value and User Solutions: Zenmap addresses the need for a user-friendly interface to Nmap's comprehensive network scanning capabilities. By providing graphical representations and simplified management of scan profiles and results, it enables users to efficiently monitor network security, detect unauthorized devices, and manage service upgrades. This tool is particularly valuable for system and network administrators seeking to maintain secure and well-documented network environments.

Average Rating: 4.5/5.0

Total Reviews: 26

How Do G2 Users Rate Zenmap?

  • Has the product been a good partner in doing business?: 7.9/10 (Category avg: 9.2/10)
  • Detection Rate: 8.8/10 (Category avg: 9.0/10)
  • Automated Scans: 8.3/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 7.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Zenmap?

  • Seller: Nmap
  • HQ Location: N/A
  • Twitter: @nmap
    136,374 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 50% Medium, 39% Small

What Do G2 Reviewers Say About Zenmap?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Zenmap, making it ideal for penetration testers and cyber security analysts.
  • Users value the ease of implementation of Zenmap, finding it user-friendly and straightforward for various security tasks.
Cons
  • Users find the limited command functionality of Zenmap frustrating, affecting their overall experience on Kali Linux.
  • Users find Zenmap's poor interface design limits usability and complicates command execution within Kali Linux.

What Are Recent G2 Reviews of Zenmap?

What Are G2 Users Discussing About Zenmap?

Veracode Application Security Platform

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

Average Rating: 3.8/5.0

Total Reviews: 25

How Do G2 Users Rate Veracode Application Security Platform?

  • Has the product been a good partner in doing business?: 7.9/10 (Category avg: 9.2/10)
  • Detection Rate: 8.3/10 (Category avg: 9.0/10)
  • Automated Scans: 9.2/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.4/10 (Category avg: 8.5/10)

Who Is the Company Behind Veracode Application Security Platform?

  • Seller: VERACODE
  • Year Founded: 2006
  • HQ Location: Burlington, MA
  • Twitter: @Veracode
    21,950 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    500 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 69% Large, 31% Medium

What Do G2 Reviewers Say About Veracode Application Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the effective security vulnerability identification offered by Veracode, enhancing overall application safety and code integrity.
  • Users find Veracode's vulnerability detection excellent for identifying security issues and ensuring high application security standards.
  • Users value the automated scanning of Veracode, streamlining security checks and enhancing code quality effortlessly.
  • Users value the effective detection of security vulnerabilities, enabling robust protection and streamlined development processes.
  • Users appreciate the ease of integration with GitHub and CI/CD pipelines, streamlining their development process effectively.
Cons
  • Users find Veracode to be expensive, with high costs, complex licensing, and unfulfilled feature delivery.
  • Users face a lack of information due to mismatches in documentation and delayed notifications during uploads.
  • Users express concerns over licensing issues, including rising costs, complex models, and unequal feature availability.
  • Users report poor customer support with pushy account executives and difficulties in resolving issues efficiently.
  • Users express concerns about pricing issues, with rising costs and a complex licensing model affecting value perception.

What Are Recent G2 Reviews of Veracode Application Security Platform?

What Are G2 Users Discussing About Veracode Application Security Platform?