Top Free Vulnerability Scanner Software - Page 4

How Many Vulnerability Scanner Software Products Does G2 Track?

Total Products under this Category: 235

Category Stats (Sep 2026)

  • Average Rating: 4.59/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Armis (+0.18%) - Among all products in this category, Armis recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Vulnerability Scanner Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 7,900+ Authentic Reviews
  • 235+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Vulnerability Scanner Software

G2 Grid® for Vulnerability Scanner Software plotting products by satisfaction and market presence

Highlighted products: Wiz, Aikido Security, CrowdStrike Falcon Cloud Security, Tenable Nessus, Orca Security, Astra Pentest, Intruder, and Burp Suite.

Underlying data: [Grid® JSON](https://www.g2.com/categories/vulnerability-scanner/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=tenable-nessus&focus%5B%5D=orca-security&focus%5B%5D=astra-pentest&focus%5B%5D=intruder&focus%5B%5D=burp-suite)

Cyber Chief

Cyber Chief is a vulnerability scanner & issue management tool that helps you ship software with zero known security vulnerabilities. It gives your software team the power to find and fix thousands of vulnerabilities in your web applications and cloud infrastructure. With its one-click vulnerability scanning and smart vulnerability management features, Cyber Chief will help your software team secure their applications abs infrastructure, even if there is zero application security qualifications or experience on the team. Cyber Chief is cloud-based and has military-grade security controls so that your security secrets are kept safe.

Average Rating: 4.5/5.0

Total Reviews: 7

How Do G2 Users Rate Cyber Chief?

  • Has the product been a good partner in doing business?: 7.8/10 (Category avg: 9.2/10)
  • Detection Rate: 8.8/10 (Category avg: 9.0/10)
  • Automated Scans: 8.8/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.8/10 (Category avg: 8.5/10)

Who Is the Company Behind Cyber Chief?

  • Seller: Audacix
  • Year Founded: 2015
  • HQ Location: Melbourne, Victoria
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 43% Medium, 43% Small

What Do G2 Reviewers Say About Cyber Chief?

AI-generated summary from verified user reviews

Pros
  • Users value the automated scanning capabilities of Cyber Chief, streamlining security testing across all platforms effectively.
  • Users appreciate the responsive customer support of Cyber Chief, which ensures thorough assistance throughout their security journey.
  • Users appreciate the comprehensive cybersecurity solutions of Cyber Chief, ensuring thorough testing and support in one platform.
  • Users praise Cyber Chief for its comprehensive vulnerability detection, streamlining security testing within a single, user-friendly platform.
  • Users appreciate the vulnerability identification capability of Cyber Chief, enhancing security and collaboration across platforms.

What Are Recent G2 Reviews of Cyber Chief?

What Are G2 Users Discussing About Cyber Chief?

ZeroPath

ZeroPath (YC S24) is the first AI-native application security platform that fundamentally reimagines how organizations find and fix vulnerabilities. Unlike deterministic SAST tools that bolt AI onto legacy rule engines, ZeroPath was built from the ground up to combine large language models with advanced program analysis (AST, data flow, taint tracking) by Ex-Tesla Red Team and Google Security engineers. ZeroPath's core differentiation is detecting critical vulnerabilities that pattern-matching SAST fundamentally cannot find. It catches IDORs, authorization bypasses, race conditions, and authentication bugs by reasoning about application behavior and developer intent. This capability achieved a 92% alert reduction when triaging findings from legacy tools. ZeroPath is best suited for enterprises and startups that want a complete appsec experience with: AI-powered SAST across 16+ languages, SCA with exploitability analysis (90% noise reduction by determining if dependency CVEs are actually reachable in your code), secrets detection with validation, IaC scanning for Terraform/CloudFormation/Kubernetes, and natural language security policies. Context-aware autopatch generation fixes 70% of vulnerabilities automatically with framework-specific patches that match your coding standards. To keep the developer experience seamless, ZeroPath integrates into existing workflows with zero configuration. It provides Sub-60-second PR scans on GitHub, GitLab, Bitbucket, and Azure DevOps to provide instant security feedback without blocking development. Developers receive clear explanations, one-click fixes, and can refine patches using natural language commands directly in PR comments. The platform automatically attributes vulnerabilities to responsible developers and syncs bidirectionally with Jira, Linear, and more. Overall, less noise, along with the breadth of integrations, has already made security teams faster in triaging and finding real vulnerabilities. Having been security engineers ourselves, we also understand how important visibility is for the evaluations. ZeroPath users get executive dashboards with real-time MTTR tracking, automated compliance reporting for SOC2 and ISO27001, and risk-based prioritization using CVSS 4.0 scoring. The platform provides complete visibility across organizational repositories, including security models, authentication patterns, and filtering logic, without manual configuration. Our research team dogfeeds our own technology and has discovered CVE-2025-61928 (critical account takeover in better-auth with 300k+ weekly downloads), identified 170+ verified bugs in curl, found 7 vulnerabilities in django-allauth enabling account impersonation, and discovered 0-days in production systems at Netflix, Hulu, and Salesforce. Currently trusted by 750+ companies running 200k+ scans monthly, ZeroPath delivers what security-conscious engineering teams need: more real vulnerabilities, dramatically less noise, and automated fixes that actually work.

Average Rating: 4.5/5.0

Total Reviews: 11

How Do G2 Users Rate ZeroPath?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind ZeroPath?

  • Seller: ZeroPath
  • Company Website:
  • Year Founded: 2024
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 36% Small, 27% Medium

What Do G2 Reviewers Say About ZeroPath?

AI-generated summary from verified user reviews

Pros
  • Users value the high accuracy of ZeroPath, effectively identifying real security issues with minimal false alarms.
  • Users value the accuracy of findings from ZeroPath, as it effectively identifies real security issues with minimal false alarms.
  • Users commend ZeroPath for its high accuracy in security detection, minimizing false alarms and enhancing issue resolution.
  • Users commend ZeroPath for its highly accurate vulnerability detection, minimizing false alarms and enhancing security efforts.
  • Users commend ZeroPath for its accurate vulnerability identification, significantly reducing false alarms and enhancing security efforts.
Cons
  • Users report bug issues with ZeroPath, but the support team addresses them quickly and effectively.
  • Users experience some bugs with ZeroPath, but the support team quickly resolves them to improve functionality.
  • Users face some software bugs in ZeroPath, though the team is responsive in resolving them quickly.
  • Users feel that the pricing structure of ZeroPath is not currently suitable for their organization's budget.
  • Users experience bugs in the dashboard, though the ZeroPath team swiftly addresses these problems.

What Are Recent G2 Reviews of ZeroPath?

ZeroThreat

ZeroThreat is an AI-powered web application and API penetration testing platform designed to identify real, exploitable vulnerabilities, not just surface-level findings. Built for modern engineering teams, it combines Agentic AI pentesting with a high-performance scanning engine to deliver up to 10× faster, deeply validated security testing. Unlike traditional DAST tools that rely on static signatures and generate excessive noise, ZeroThreat executes adaptive, attacker-style workflows that evolve based on application behavior. Its interpreter-driven vulnerability intelligence continuously ingests emerging threats and newly disclosed CVEs, enabling near real-time detection updates and rapid CVE-to-exploit mapping. The platform supports over 100,000 vulnerability checks, including native Nuclei template execution, and extends beyond known issues with zero-day detection through behavioral pattern analysis. It validates every finding through live exploit execution, ensuring only real, impactful vulnerabilities are reported, with clear proof of risk and exposed data.

Average Rating: 4.8/5.0

Total Reviews: 10

How Do G2 Users Rate ZeroThreat?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Detection Rate: 9.4/10 (Category avg: 9.0/10)
  • Automated Scans: 8.9/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.9/10 (Category avg: 8.5/10)

Who Is the Company Behind ZeroThreat?

Who Uses This Product?

  • Company Size: 50% Large, 30% Medium

What Do G2 Reviewers Say About ZeroThreat?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of ZeroThreat, enjoying smooth integration and a user-friendly interface for security management.
  • Users value the real-time vulnerability detection of ZeroThreat, enhancing security without disrupting workflow and reducing false positives.
  • Users commend the accuracy of results from ZeroThreat, significantly reducing false positives and enhancing security efficiency.
  • Users appreciate the setup ease of ZeroThreat, enabling quick integration into existing workflows without complications.
  • Users appreciate the easy setup of ZeroThreat, allowing quick integration and immediate security scanning in their workflow.
Cons
  • Users find the inefficient filtering in ZeroThreat's reporting section makes locating specific results unnecessarily time-consuming.
  • Users experience integration issues with ZeroThreat, finding it challenging to connect with DevOps tools and proprietary software.
  • Users feel that the limited integrations with other tools hinder a more seamless experience with ZeroThreat.
  • Users report slow performance in ZeroThreat, with lagging features and longer loading times affecting productivity.
  • Users note that the UX improvement in ZeroThreat is needed for better navigation, filtering, and faster loading times.

What Are Recent G2 Reviews of ZeroThreat?

MetaDefender

MetaDefender Platform is an advanced threat prevention solution that lets organizations embed multi-layer file security into existing applications and security architectures, especially to protect common attack vectors like malicious file uploads, untrusted file transfers, and file-based supply chain risk. It’s designed for environments that need stronger protection against highly evasive malware, zero-day attacks, and APTs, including IT and OT/critical infrastructure use cases. MetaDefender easily integrates into your existing IT solutions and can be deployed on-premises (including air-gapped), in cloud/IaaS, or as SaaS. We offer flexible implementation options for ICAP enabled devices, containerized applications, AWS, Azure, NAS/Storage workflows and Rest API. Overview: Multi-engine malware scanning: Quickly scan files with 30+ antivirus engines and detect over 99% of known malware. Deep CDR (Content Disarm & Reconstruction): Recursively sanitize and rebuild 200+ file types to neutralize embedded threats while maintaining file usability, with extensive reconstruction and file conversion options. Proactive DLP: Remove, redact, or watermark sensitive data in files before content enters or leaves the organization; also supports AI-powered document classification. File-based Vulnerability Assessment: Identify vulnerabilities in installers, binaries, and applications before they are installed/executed and reduce exposure to known software flaws. Threat intelligence-driven detection: Identify malicious domains and IPs embedded in documents and support near real-time blocking using curated threat intelligence. Adaptive threat analysis (sandboxing): Detonate and analyze suspicious files in a controlled environment and improve zero-day detection. SBOM & software supply chain visibility: Generate SBOMs and identify vulnerabilities in source code and containers. Reputation Engine: Use file hash reputation (known good/known bad/unknown) and advanced analysis to remediate false positives faster. Visibility, reporting, and policy control: Gain operational visibility, use automated reports for remediation, and configure workflow/analysis rules based on user, business priority, file source, and file type. Free Training - OPSWAT Academy: https://www.opswat.com/academy

Average Rating: 4.3/5.0

Total Reviews: 15

How Do G2 Users Rate MetaDefender?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Detection Rate: 10.0/10 (Category avg: 9.0/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 10.0/10 (Category avg: 8.5/10)

Who Is the Company Behind MetaDefender?

  • Seller: OPSWAT
  • Company Website:
  • Year Founded: 2002
  • HQ Location: Tampa, Florida
  • Twitter: @OPSWAT
    7,257 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,185 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 40% Medium, 40% Small

What Do G2 Reviewers Say About MetaDefender?

AI-generated summary from verified user reviews

Pros
  • Users find MetaDefender to be reliable and simple to manage, enhancing their cybersecurity experience effortlessly.
  • Users appreciate the exceptional security of MetaDefender, highlighting its reliability and effectiveness in threat elimination.
  • Users value the reliable protection of MetaDefender, praising its effectiveness against malware and ease of management.
  • Users benefit from the scanning efficiency of MetaDefender, confidently eliminating threats swiftly and effectively.
  • Users value the effective scanning capabilities of MetaDefender, enhancing security and providing thorough threat detection.
Cons
  • Users find the complex configuration requirements challenging, necessitating significant upfront planning and policy tuning effort.
  • Users experience a difficult setup process during rollout due to extensive policy tuning and adjustment needs.
  • Users experience excessive blocking issues during initial policy tuning, leading to unnecessary restrictions on business files.
  • Users find that overblocking can be an issue, requiring careful policy adjustments to ensure safe files aren't hindered.
  • Users find that policy tuning requires significant effort initially, particularly with archives and mixed file types.

What Are Recent G2 Reviews of MetaDefender?

What Are G2 Users Discussing About MetaDefender?

Plerion

Plerion is a cloud security platform designed to assist organizations in managing and mitigating risks within their cloud environments. Unlike traditional security tools that inundate users with alerts, Plerion focuses on actionable insights, enabling teams to address vulnerabilities effectively. By streamlining the risk management process, Plerion transforms the way organizations approach cloud security, ensuring that the most critical threats are prioritized and resolved. The platform is tailored for IT security teams and cloud administrators across various industries that utilize cloud services such as AWS, Azure, and Google Cloud Platform (GCP). Plerion’s unique approach allows users to visualize their cloud infrastructure, identities, workloads, and code as a cohesive graph. This visualization helps users identify the approximately 1% of risks that are genuinely exploitable, eliminating the noise typically associated with security alerts. By presenting a concise, ranked list of vulnerabilities, Plerion empowers teams to focus their efforts where they matter most. At the heart of the Plerion platform is Pleri, an AI-driven cloud security engineer that mimics the investigative capabilities of a human security expert. Pleri assesses findings, verifies their exploitability in context, and traces risks back to the underlying code responsible for them. This automated process culminates in the creation of pull requests or Jira tickets for remediation, ensuring that every proposed change awaits human approval. This feature not only enhances accountability through full audit trails but also allows for easy rollbacks if necessary. Plerion’s comprehensive coverage includes cloud configuration, workloads, identity and permissions, data, code, and AI workloads, making it a versatile solution for diverse cloud environments. The platform also offers compliance mapping against a wide range of frameworks, linking each identified failure to specific corrective actions rather than merely generating reports. This capability significantly reduces the time and effort required for compliance management. Organizations using Plerion have reported substantial improvements in their security operations. For instance, Deputy achieved an 80% reduction in alerts and decreased their time-to-remediation from 30 days to just 4 hours. Similarly, Basis eliminated 40 hours of manual review each week, illustrating the platform's efficiency. With ISO 27001 certification, SOC 2 attestation, and the AWS Security Software Competency, Plerion ensures a high standard of security and reliability. By deploying in minutes rather than months, Plerion allows organizations to put their cloud security on autopilot while maintaining a human touch in the decision-making process.

Average Rating: 4.7/5.0

Total Reviews: 30

How Do G2 Users Rate Plerion?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)
  • Automated Scans: 5.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Plerion?

  • Seller: Plerion
  • Company Website:
  • Year Founded: 2021
  • HQ Location: Sydney, AU
  • Twitter: @PlerionHQ
    141 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    30 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Financial Services
  • Company Size: 52% Medium, 35% Small

What Do G2 Reviewers Say About Plerion?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the centralized security data in Plerion, which enhances visibility and effective risk management.
  • Users appreciate the ease of use of Pleri, enhancing collaboration and simplifying cloud security management seamlessly.
  • Users commend Plerion's stellar customer support, highlighting responsiveness and commitment to customer success in security management.
  • Users appreciate the centralized security data of Plerion, benefiting from immediate visibility and actionable advice.
  • Users appreciate how Plerion's effective prioritization simplifies cloud security, focusing on critical issues without overwhelming alerts.
Cons
  • Users feel that improvements are needed in trend reporting and Jira ticket creation for better long-term value visibility.
  • Users note that while Plerion shows improvement needed in trend reporting and ongoing value visibility over time.
  • Users find the missing features of Plerion frustrating, particularly regarding customization and cloud support limitations.
  • Users note the limited support for Google Cloud, wishing for better feature parity with other providers.
  • Users experience integration issues due to manual updates and limited coverage, creating deployment challenges with Plerion.

What Are Recent G2 Reviews of Plerion?

RoboShadow

RoboShadow is a London-based Cyber Security start-up and a recent NCSC for Startups Alumni. As a business, RoboShadow is dedicated to making Cyber Security accessible, and levelling the Cyber Security playing field so that every organisation has access to enterprise grade cyber security tools without being inhibited by cost or complexity. The RoboShadow Platform offers free vulnerability scans, cyber security auditing, as well as upgradable features, including brand new "Cyber Heal",  RoboGuard continuous scanning,  and Robo AI Detection.   Its all very easy to use, and completely supported by a UK Cyber Support team.

Average Rating: 5.0/5.0

Total Reviews: 5

How Do G2 Users Rate RoboShadow?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Detection Rate: 10.0/10 (Category avg: 9.0/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.6/10 (Category avg: 8.5/10)

Who Is the Company Behind RoboShadow?

Who Uses This Product?

  • Company Size: 80% Small, 20% Medium

What Do G2 Reviewers Say About RoboShadow?

AI-generated summary from verified user reviews

Pros
  • Users rave about the excellent customer support from RoboShadow, enhancing their experience and satisfaction greatly.
  • Users commend RoboShadow for its powerful tools and exceptional support, significantly enhancing their cyber security discussions and compliance efforts.
  • Users highlight the easy onboarding of RoboShadow, appreciating clear pricing and excellent customer support throughout their experience.
  • Users find RoboShadow's platform to be super easy to setup and deploy, enhancing their overall experience and efficiency.
  • Users admire the constant development of features in RoboShadow, greatly enhancing their cybersecurity discussions and tools.
Cons
  • Users find the user interface overwhelming initially, but it becomes manageable with time and usage.

What Are Recent G2 Reviews of RoboShadow?

OX Security

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

Average Rating: 4.8/5.0

Total Reviews: 51

How Do G2 Users Rate OX Security?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.2/10)

Who Is the Company Behind OX Security?

Who Uses This Product?

  • Who Uses This: Security Engineer
  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 63% Medium, 25% Large

What Do G2 Reviewers Say About OX Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the intuitive dashboard of OX Security, enhancing issue management and streamlining security processes effectively.
  • Users find OX Security highly user-friendly, benefiting from an intuitive dashboard and responsive support for seamless operations.
  • Users value the responsive and professional customer support of OX Security, enhancing their overall experience and efficiency.
  • Users value the seamless integration support from OX Security, enhancing their workflow with fast and user-friendly solutions.
  • Users appreciate the comprehensive security capabilities of OX Security, ensuring a streamlined and effective security management experience.
Cons
  • Users report integration issues with OX Security's limited documentation and insufficient support for various tools.
  • Users note some missing features in OX Security, which can affect its overall usability and integration capabilities.
  • Users find the complexity of OX Security daunting, with inadequate documentation and a steep learning curve for new users.
  • Users find OX Security's inadequate reporting limits their ability to effectively showcase security progress to management.
  • Users find the limited cloud integration with certain tools frustrating, impacting overall connectivity and functionality.

What Are Recent G2 Reviews of OX Security?

BitNinja

State-of-the-art server security with an all-in-one platform BitNinja offers an advanced server security solution with a proactive and unified system designed to effectively defend against a wide range of malicious attacks. Breaking new ground, BitNinja will be the first server security tool that protects Windows servers. Main solutions: - Reduce the server load as a result of the real-time IP reputation, with a database of 100M+ IP addresses thanks to BitNinja’s Defense Network - Stop zero-day exploits with the WAF module, and BitNinja’s self-written rules - Remove malware quickly and prevent reinfections with the industry-leader malware scanner - Enable the AI Malware Scanner to remove malware than ever before - Identify possible backdoors in your system with the Defense Robot - Protect your server from brute-force attacks with the Log Analysis module that runs silently in the background - Regularly examine and clean your database with the Database Cleaner - Discover and eliminate vulnerabilities in your website at no additional cost with the SiteProtection module - Block spam accounts, prevent server blocklisting, and gain insights into outgoing spam emails with the Outbound - Spam Detection module powered by ChatGPT - Trap suspicious connections with Honeypots and block access through backdoors with the Web Honeypot BitNinja Security stops the latest attack types, including: - All types of malware - with the best malware scanner in the market - Brute-force attacks at both network and HTTP levels; - Vulnerability exploitation – CMS (WP/Drupal/Joomla) - SQL injection - XSS - Remote code execution - Zero-day attacks; - DoS (denial of service) attacks BitNinja Security makes it easy to secure web servers: - 1-line code installation - Fully automated operation keeps servers safe and eliminates human error - AI-powered community-driven worldwide Defense Network - Unified, intuitive Dashboard for your whole infrastructure - Easy server management with Cloud Configuration - Premium support with a maximum 5-min response time - The convenience of a robust CLI - API available for automation and reporting - Seamless integrations with a wide range of platforms like Enhance control panel, 360 Monitoring, and JetBackup. BitNinja is supported on THE PLATFORM and up, installed on the following Linux distributions: CentOS 7 and up 64 bit CloudLinux 7 and up 64 bit Debian 8 and up 64 bit Ubuntu 16.04 and up 64 bit RedHat 7 and up 64 bit AlmaLinux 8 64 bit VzLinux 7 and up 64 bit Rocky Linux 8 64 bit Amazon Linux 2 64 bit Windows 2012 RE and newer

Average Rating: 4.6/5.0

Total Reviews: 20

How Do G2 Users Rate BitNinja?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.2/10)
  • Detection Rate: 8.3/10 (Category avg: 9.0/10)
  • Automated Scans: 6.7/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 5.0/10 (Category avg: 8.5/10)

Who Is the Company Behind BitNinja?

  • Seller: BitNinja Ltd.
  • Year Founded: 2014
  • HQ Location: Debrecen
  • Twitter: @bitninjaio
    1,079 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    24 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Internet
  • Company Size: 88% Small, 8% Medium

What Are Recent G2 Reviews of BitNinja?

What Are G2 Users Discussing About BitNinja?

ImmuniWeb AI Platform

The ImmuniWeb AI Platform helps over 1,000 enterprise customers from more than 50 countries to test, secure and protect their web and mobile applications, APIs and microservices, cloud and networks, to prevent data breaches and reduce third-party risk, and to comply with regulatory requirements. ImmuniWeb’s products available on the Platform include Continuous Threat Exposure Management (CTEM), External Attack Surface Management (EASM), Dark Web Monitoring and phishing websites takedown, as well as vulnerability scanning and penetration testing for web and mobile apps, cloud and network infrastructure, and LLM models. Headquartered in Geneva, Switzerland, ImmuniWeb has offices in Washington, London and Dubai to provide an uninterrupted service to all global customers and partners.

Average Rating: 4.7/5.0

Total Reviews: 12

How Do G2 Users Rate ImmuniWeb AI Platform?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind ImmuniWeb AI Platform?

  • Seller: ImmuniWeb
  • Year Founded: 2019
  • HQ Location: Geneva, CH
  • Twitter: @immuniweb
    8,473 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    32 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 92% Medium, 8% Small

What Do G2 Reviewers Say About ImmuniWeb AI Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the effective vulnerability detection of ImmuniWeb AI Platform, significantly improving security and compliance efforts.
  • Users commend the responsive customer support, which offers prompt assistance and enhances the overall scanning experience.
  • Users value the continuous monitoring of the attack surface, ensuring proactive awareness of critical security issues.
  • Users value the continuous monitoring efficiency of ImmuniWeb AI Platform, ensuring proactive security and reducing potential losses.
  • Users value the alert notifications for keeping them informed about critical security issues and protecting their assets.
Cons
  • Users find the complexity of target scans leads to uncertain scanning times, complicating the overall experience.
  • Users face integration issues as ImmuniWeb AI Platform lacks connections with tools like Slack and PagerDuty.
  • Users find the lack of integration with Slack and PagerDuty complicates on-call support and accessibility after hours.
  • Users find the Excel export limited, which affects their data handling capabilities compared to the full JSON export.
  • Users note the limited flexibility in the algorithm for cost calculation, though improvements have been made.

What Are Recent G2 Reviews of ImmuniWeb AI Platform?

What Are G2 Users Discussing About ImmuniWeb AI Platform?

Siemba

Siemba is an AI-driven Continuous Threat Exposure Management (CTEM) platform that helps enterprises, government agencies, and growing organizations discover, prioritize, and fix critical vulnerabilities across their entire attack surface. Security teams use Siemba to build and mature CTEM programs without requiring deep hacking expertise or constant human intervention. The platform brings together four integrated capabilities on a single unified interface: Penetration Testing as a Service (PTaaS) for expert-led manual pen testing on demand; GenPT for AI-native Dynamic Application Security Testing (DAST) that simulates real-world attack techniques against web applications and APIs; GenVA for AI-driven vulnerability assessment that continuously scans and scores risks across your environment; and EASM for External Attack Surface Management that maps and monitors all external-facing assets, including shadow IT and exposed infrastructure. Together these capabilities deliver actionable intelligence across the full CTEM lifecycle, from asset discovery and attack surface mapping through to risk prioritization, validation, and remediation guidance. Security leaders gain the visibility, speed, and scalability needed to run continuous offensive security programs and generate strategic insights that maximize Return on Mitigation. Siemba is trusted by enterprises, global systems integrators, and government agencies looking to consolidate their offensive security tooling, reduce exposure windows, and demonstrate measurable security improvement over time.

Average Rating: 4.7/5.0

Total Reviews: 5

How Do G2 Users Rate Siemba?

  • Automated Scans: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Siemba?

  • Seller: Siemba
  • Year Founded: 2018
  • HQ Location: Alpharetta, US
  • LinkedIn® Page: www.linkedin.com
    38 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 60% Small, 40% Medium

What Are Recent G2 Reviews of Siemba?

Xygeni

Xygeni: AI-Native ASPM for the Software Supply Chain Xygeni is an AI-native ASPM (Application Security Posture Management) platform that unifies native and third-party security findings into one prioritized view. Its own detection engines cover SAST, SCA, DAST, Secrets, IaC, Container, CI/CD, and Build Security, and it also ingests results from tools like Snyk, Veracode, and Checkmarx so teams don't have to abandon what they've already invested in. Every finding, regardless of source, gets scored by exploitability, reachability, and business impact through Xygeni's Dynamic Funnels, which is what drives its reported 90% cut in alert noise. Two AI systems sit underneath the platform. CoreAI acts as a correlation and reporting layer for security leaders, turning scattered findings into a single risk narrative. DevAI works earlier, inside the developer's IDE and AI coding assistants, catching problems in both human-written and AI-generated code and proposing fixes before a pull request is even opened. On the supply chain side, Xygeni's MEW engine (Malware Early Warning) is built to catch malicious open-source packages the moment they hit a public registry, ahead of when a formal malware signature would normally exist. Shield takes that enforcement to the developer's own machine, blocking unauthorized package downloads at the OS level before they reach disk. Xygeni also runs a dedicated Code Quality engine across ten languages, ranking maintainability and complexity issues alongside security findings in the same console, so a team can see when the messiest file is also the riskiest one. The platform connects to GitHub, GitLab, Bitbucket, Jenkins, and Azure DevOps, and deploys as SaaS, on-premises, or fully air-gapped. Xygeni was named Hot Company in ASPM and in GenAI Application Security at the 2026 Global InfoSec Awards.

Average Rating: 4.6/5.0

Total Reviews: 4

How Do G2 Users Rate Xygeni?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Detection Rate: 9.2/10 (Category avg: 9.0/10)
  • Automated Scans: 6.7/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.2/10 (Category avg: 8.5/10)

Who Is the Company Behind Xygeni?

  • Seller: Xygeni Security
  • Year Founded: 2021
  • HQ Location: Madrid, ES
  • Twitter: @xygeni
    178 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    31 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 60% Small, 40% Medium

What Do G2 Reviewers Say About Xygeni?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the comprehensive security features of Xygeni, fostering a secure development environment without hindering productivity.
  • Users value the effective prioritization of security issues in Xygeni, allowing teams to focus on critical threats quickly.
  • Users value the effective risk management of Xygeni, enhancing security without hindering software development processes.
  • Users appreciate the robust security features of Xygeni, enhancing their development process while ensuring compliance and risk management.
  • Users value the seamless CI/CD integration of Xygeni, enabling early vulnerability detection without impacting release schedules.
Cons
  • Users face difficult setup issues with Xygeni, especially when dealing with certain edge cases requiring manual adjustments.
  • Users find the learning curve challenging for newcomers despite a generally intuitive platform, requiring familiarity with AppSec practices.

What Are Recent G2 Reviews of Xygeni?

ConnectSecure Vulnerability and Compliance Manager

ConnectSecure is a comprehensive SaaS cybersecurity solution designed to address vulnerabilities and secure assets for clients. It stands out for its strong emphasis on reporting customization, external and domain-level scanning, compliance management, and risk assessments. The platform offers a versatile and user-friendly experience, making it an attractive option for organizations seeking a robust and non-disruptive cybersecurity solution.

Average Rating: 4.0/5.0

Total Reviews: 2

How Do G2 Users Rate ConnectSecure Vulnerability and Compliance Manager?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)
  • Detection Rate: 10.0/10 (Category avg: 9.0/10)

Who Is the Company Behind ConnectSecure Vulnerability and Compliance Manager?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of ConnectSecure Vulnerability and Compliance Manager?

Crashtest Security

Crashtest Security is a SaaS-based security vulnerability scanner allowing agile development teams to ensure continuous security before every release. Our state-of-the-art dynamic application security testing (DAST) solution integrates seamlessly with your dev environment and protects multi-page and JavaScript apps, as well as microservices and APIs. Set up Crashtest Security Suite in minutes, get advanced crawling options, and automate your security. Whether you want to see vulnerabilities within the OWASP Top 10 or you want to go for deep scans, Crashtest Security is here to help you stay on top of your security and protect your code and customers.

Average Rating: 5.0/5.0

Total Reviews: 2

How Do G2 Users Rate Crashtest Security?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Crashtest Security?

Who Uses This Product?

  • Company Size: 50% Small, 50% Medium

What Are Recent G2 Reviews of Crashtest Security?

ManageEngine Vulnerability Manager Plus

ManageEngine Vulnerability Manager Plus is a comprehensive, all-in-one exposure management solution designed to help IT security teams build a proactive cybersecurity foundation. Rather than reacting to breaches, it empowers organizations to scan continuously, assess, prioritize, and remediate vulnerabilities before attackers can exploit them, all from a single, unified console. Asset discovery, vulnerability assessment and threat prioritization: Vulnerability Manager Plus manages every endpoint in your network, such as desktops, laptops, servers, virtual machines, DMZ servers, and network devices, whether in local offices, remote branches, or roaming environments. It delivers complete, real-time visibility into all vulnerabilities in a single window, including known, unknown, zero-day, and actively exploited vulnerabilities. AI-powered threat intelligence assigns risk scores to each vulnerability, helping security teams cut through the noise and focus remediation efforts on what matters most. Vulnerability remediation: This is the only vulnerability detection platform that comes with built-in patching, and automated patch deployment. It supports patching for Windows, macOS, and Linux operating systems, along with over 1,100 third-party applications. Admins can customize deployment policies, test and approve patches before rollout, and decline patches for specific groups; all while staying in control of the patching lifecycle from end-to-end. Security configuration management Vulnerability Manager Plus identifies misconfigurations in operating systems, applications, and web servers, and provides actionable steps to restore compliance. It audits firewalls, antivirus status, and BitLocker configurations; enforces strong password policies and account lockout settings; verifies memory protection settings like ASLR, DEP, and SEHOP; and manages share permissions and legacy protocol settings, all without disrupting business operations. Web server hardening: Vulnerability Manager Plus continuously monitors web servers for default and insecure configurations, validates SSL certificate setup, checks HTTPS enablement, and restricts unauthorized access at the server root level. Context-aware analysis delivers targeted security recommendations to harden your web servers. High-risk software, port, and antivirus audit: Stay ahead of risk with real-time visibility into end-of-life software, unsafe peer-to-peer applications, remote sharing tools, and open ports. Identify systems running outdated or disabled antivirus solutions and remediate them in a click. Compliance auditing: Automate compliance audits against regulations such as CIST, NIST, and UK Cyber Essentials across multiple machines and multiple benchmarks simultaneously. Customize benchmark rules to fit your organization's unique policies, and access detailed remediation guidance for every violation flagged. Network device vulnerability management: Maintain a consolidated inventory of all network devices across local and remote sites. Identify firmware versions, detect associated vulnerabilities, group devices by OS or vendor, and deploy the right firmware patches efficiently to close exposure gaps faster. System quarantine policy: Define compliance conditions based on OS patches, installed software, services, registry entries, file versions, and more. Automatically isolate non-compliant systems with network restrictions and restore normal access once issues are resolved, keeping your network clean without manual intervention. Vulnerability Manager Plus supports 18 languages, and supports patching for 1100+ applications, making it a fit for organizations of all sizes seeking a single, powerful platform to manage their entire vulnerability lifecycle.

Average Rating: 4.7/5.0

Total Reviews: 3

How Do G2 Users Rate ManageEngine Vulnerability Manager Plus?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.2/10)
  • Detection Rate: 8.3/10 (Category avg: 9.0/10)
  • Automated Scans: 9.4/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.3/10 (Category avg: 8.5/10)

Who Is the Company Behind ManageEngine Vulnerability Manager Plus?

  • Seller: Zoho
  • Year Founded: 1996
  • HQ Location: Austin, TX
  • Twitter: @Zoho
    137,880 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    30,913 employees on LinkedIn®
  • Phone: +1 (888) 900-9646

Who Uses This Product?

  • Company Size: 67% Medium, 33% Large

What Do G2 Reviewers Say About ManageEngine Vulnerability Manager Plus?

AI-generated summary from verified user reviews

Pros
  • Users find the effective detection capabilities of ManageEngine Vulnerability Manager Plus essential for global patch management efficiency.
  • Users find the ease of managing patches globally with ManageEngine Vulnerability Manager Plus incredibly beneficial and user-friendly.
  • Users find ManageEngine Vulnerability Manager Plus to be the best tool for patch management, thanks to its simplicity and global reach.
  • Users find patch management simple and efficient with ManageEngine Vulnerability Manager Plus across global machines.
  • Users find ManageEngine Vulnerability Manager Plus excellent for simplifying global patch management across all their devices.
Cons
  • Users report encountering false positives, where some CVEs listed as vulnerable are not actually identified in ManageEngine.
  • Users report inaccuracy issues in CVE ID identification, leading to confusion and unreliable vulnerability assessment.
  • Users report security vulnerabilities inconsistencies, where some CVE IDs are not identified correctly by ManageEngine.
  • Users often find discrepancies in CVE identification between MDE reports and ManageEngine, leading to confusion.

What Are Recent G2 Reviews of ManageEngine Vulnerability Manager Plus?

Topscan

Topscan is a continuous security monitoring platform for the DevOps engineer or CTO who owns security among other things. It covers the whole delivery pipeline in one subscription — static analysis in your code, dynamic scanning of live applications and infrastructure, and continuous monitoring of everything you expose to the internet — instead of three separate vendors for SAST, DAST and attack surface management. Perimeter. External infrastructure scanning reports open ports, service versions and known server vulnerabilities matched against CVE databases, with unlimited scheduled rescans. Asset discovery maps the subdomains and hosts you forgot about — the Grafana, the Sentry, the staging box nobody remembers deploying — and new hosts arrive with a review prompt: you confirm ownership before anything is scanned. Attack surface monitoring keeps every exposed service inventoried, and certificate watch catches TLS/SSL expiry weeks early instead of on the Friday night it happens. Applications and code. Web application scanning runs OWASP-class checks against live apps: SQL injection, XSS, exposed admin panels, default credentials, missing headers. Static application security testing covers three kinds of risk in one scan — vulnerable code patterns, committed secrets and keys, and known CVEs in dependencies (software composition analysis) — on every commit, pointing at the exact file and line. Pipeline and cloud. A CI/CD webhook gives you a unique event link to call from the last step of your deploy script: no API keys, no agent, nothing installed on your servers. AWS connects with keys you issue to discover EC2 and Route 53 resources, which are added to monitoring and rescanned when they change. Workflow. Findings are deduplicated and carry severity in your context, CVSS, a first-seen date and an SLA clock with overdue flags. Snooze what you accept, mark false positives and they stop resurfacing, and work through a large backlog in triage mode. Informational findings stay out of the feed and never touch your score. One security score tracks the whole estate over time — the number you show yourself, your CEO or an auditor. Alerts reach the team in Slack or Microsoft Teams and turn into Jira tickets; chat and tracker routing starts on the Advanced plan. Audit and compliance. Auditors ask for evidence of regular scanning and an inventory of what is exposed: scan history with downloadable reports and an exportable asset inventory answer both, which is what most teams use Topscan for ahead of SOC 2, ISO 27001 or a customer security review. Auditor seats are free and read-only, and users are unlimited on every plan. Pricing starts at $129 per month and is published on the site — no demo call required to see it — with a 14-day free trial of the full plan and no credit card. Add a domain and the first map of your perimeter arrives in five to ten minutes.

Average Rating: 4.8/5.0

Total Reviews: 2

Who Is the Company Behind Topscan?

  • Seller: Topscan
  • Year Founded: 2024
  • HQ Location: Dubai, AE
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Topscan?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated April 10, 2026