Best Vulnerability Scanner Software for Small Business - Page 2

How Many Vulnerability Scanner Software Products Does G2 Track?

Total Products under this Category: 235

Category Stats (Sep 2026)

  • Average Rating: 4.59/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Armis (+0.18%) - Among all products in this category, Armis recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Vulnerability Scanner Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 7,900+ Authentic Reviews
  • 235+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Vulnerability Scanner Software

G2 Grid® for Vulnerability Scanner Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, Wiz, Astra Pentest, CrowdStrike Falcon Cloud Security, Intruder, Sysdig Secure, Burp Suite, and CyberSmart.

Underlying data: [Grid® JSON](https://www.g2.com/categories/vulnerability-scanner/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=wiz-wiz&focus%5B%5D=astra-pentest&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=intruder&focus%5B%5D=sysdig-sysdig-secure&focus%5B%5D=burp-suite&focus%5B%5D=cybersmart&segment=small-business)

Tenable Vulnerability Management

Tenable Vulnerability Management provides a risk-based approach to identifying, prioritizing, and remediating vulnerabilities across your entire attack surface. Powered by Nessus technology and AI-driven analytics, it goes beyond CVSS scores to assess exploitability, asset criticality, and business impact—so you can focus on what matters most. With continuous visibility, automated scanning, and real-time risk insights, security teams can quickly expose and close critical vulnerabilities before they’re exploited. Advanced asset identification ensures accurate tracking in dynamic environments, while intuitive dashboards, comprehensive reporting, and seamless third-party integrations help streamline workflows. As a cloud-based solution, Tenable Vulnerability Management scales with your organization, empowering security teams to maximize efficiency, reduce risk, and improve resilience against evolving threats.

Average Rating: 4.5/5.0

Total Reviews: 119

How Do G2 Users Rate Tenable Vulnerability Management?

  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 9.2/10)
  • Detection Rate: 9.0/10 (Category avg: 9.0/10)
  • Automated Scans: 9.2/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.7/10 (Category avg: 8.5/10)

Who Is the Company Behind Tenable Vulnerability Management?

  • Seller: Tenable
  • Company Website:
  • HQ Location: Columbia, MD
  • Twitter: @TenableSecurity
    87,752 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,361 employees on LinkedIn®
  • Ownership: NASDAQ: TENB

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 53% Large, 34% Medium

What Do G2 Reviewers Say About Tenable Vulnerability Management?

AI-generated summary from verified user reviews

Pros
  • Users value the user-friendly interface of Tenable Vulnerability Management, facilitating easy prioritization and action on vulnerabilities.
  • Users value the scanning efficiency of Tenable Vulnerability Management, enhancing their ability to prioritize and manage vulnerabilities effectively.
  • Users value the robust scanning and reporting features of Tenable Vulnerability Management, enhancing vulnerability management efficiency.
  • Users appreciate the efficient automated scanning capabilities of Tenable, enhancing their vulnerability management process significantly.
  • Users value the effective vulnerability identification that helps prioritize remediation efforts efficiently within their environments.
Cons
  • Users find the high costs of Tenable Vulnerability Management prohibitive, especially for organizations with tight budgets.
  • Users find the reporting capabilities inadequate, leading to a need for external data processing for better insights.
  • Users find the reporting capabilities limited, often requiring external processing for better data refinement and insights.
  • Users find the pricing issues of Tenable Vulnerability Management to be complex and potentially prohibitive for budget-conscious organizations.
  • Users find the complexity of Tenable Vulnerability Management to be challenging, affecting usability and management efficiency.

What Are Recent G2 Reviews of Tenable Vulnerability Management?

What Are G2 Users Discussing About Tenable Vulnerability Management?

Beagle Security

Beagle Security helps you identify vulnerabilities in your web applications, APIs, GraphQL and remediate them with actionable insights before hackers harm you in any manner. With Beagle Security, you can integrate automated penetration testing into your CI/CD pipeline to identify security issues earlier in your development lifecycle and ship safer web applications. Major features: - Checks your web apps & APIs for 3000+ test cases to find security loopholes - OWASP & SANS standards - Recommendations to address security issues - Security test complex web apps with login - Compliance reports (GDPR, HIPAA & PCI DSS) - Test scheduling - DevSecOps integrations - API integration - Team access - Integrations with popular tools like Slack, Jira, Asana, Trello & 100+ other tools

Average Rating: 4.7/5.0

Total Reviews: 85

How Do G2 Users Rate Beagle Security?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.2/10)
  • Detection Rate: 9.2/10 (Category avg: 9.0/10)
  • Automated Scans: 9.5/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Beagle Security?

  • Seller: Beagle Security
  • Year Founded: 2020
  • HQ Location: San Francisco, US
  • Twitter: @beaglesecure
    206 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    55 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO, Director
  • Top Industries: Marketing and Advertising, Information Technology and Services
  • Company Size: 91% Small, 7% Medium

What Do G2 Reviewers Say About Beagle Security?

AI-generated summary from verified user reviews

Pros
  • Users commend the attractive reporting of Beagle Security, finding it easy to configure and comprehensive.
  • Users appreciate the easy setup of Beagle Security, finding it efficient for quick and effective implementation.

What Are Recent G2 Reviews of Beagle Security?

What Are G2 Users Discussing About Beagle Security?

Amazon Inspector

Amazon Inspector is an automated vulnerability management service that continuously scans AWS workloads—including Amazon EC2 instances, container images in Amazon ECR, AWS Lambda functions, and code repositories—for software vulnerabilities and unintended network exposure. By integrating seamlessly with AWS environments, it provides real-time detection and prioritization of security issues, enabling organizations to enhance their security posture efficiently. Key Features and Functionality: - Automated Discovery and Continuous Scanning: Automatically identifies and assesses AWS resources for vulnerabilities and network exposures, ensuring comprehensive coverage without manual intervention. - Contextualized Risk Scoring: Generates risk scores by correlating vulnerability data with environmental factors such as network accessibility and exploitability, aiding in the prioritization of remediation efforts. - Integration with AWS Services: Seamlessly integrates with AWS Security Hub and Amazon EventBridge, facilitating automated workflows and centralized management of security findings. - Support for Multiple Resource Types: Extends vulnerability management to various AWS services, including EC2 instances, container images, Lambda functions, and code repositories, providing a unified security assessment across the cloud environment. - Agentless Scanning for EC2 Instances: Offers continuous monitoring of EC2 instances for software vulnerabilities without the need for installing additional agents, simplifying deployment and maintenance. Primary Value and Problem Solved: Amazon Inspector addresses the critical need for continuous and automated vulnerability management within AWS environments. By providing real-time detection and prioritization of security issues, it enables organizations to proactively identify and remediate vulnerabilities, reducing the risk of security breaches and ensuring compliance with industry standards. Its integration with existing AWS services and support for various resource types streamline security operations, allowing teams to focus on strategic initiatives while maintaining a robust security posture.

Average Rating: 4.4/5.0

Total Reviews: 25

How Do G2 Users Rate Amazon Inspector?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Detection Rate: 9.2/10 (Category avg: 9.0/10)
  • Automated Scans: 9.2/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 7.8/10 (Category avg: 8.5/10)

Who Is the Company Behind Amazon Inspector?

  • Seller: Amazon Web Services (AWS)
  • Year Founded: 2006
  • HQ Location: Seattle, WA
  • Twitter: @awscloud
    2,232,483 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    147,094 employees on LinkedIn®
  • Ownership: NASDAQ: AMZN

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 41% Small, 33% Medium

What Do G2 Reviewers Say About Amazon Inspector?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the security alerts provided by Amazon Inspector, enhancing their ability to respond to vulnerabilities effectively.
  • Users commend the excellent customer support from AWS, enhancing their experience and helping with security management.
  • Users value the centralized management capabilities of Amazon Inspector, enhancing monitoring and compliance across their environment.
  • Users value the collaborative capabilities of Amazon Inspector, enhancing their security monitoring and compliance efforts effectively.
  • Users commend the automated security issue detection of Amazon Inspector, appreciating its ease of setup and guidance.
Cons
  • Users find the complexity of Amazon Inspector's configuration can hinder effective security implementation without proper training.
  • Users find complexity issues with Amazon Inspector, as advanced knowledge is required for effective configuration and security.
  • Users feel the learning curve for Amazon Inspector is steep, requiring well-trained admins for effective use.
  • Users find Amazon Inspector has limited features, making it challenging to address specific security needs effectively.
  • Users find Amazon Inspector not user-friendly, requiring advanced knowledge for proper configuration and security management.

What Are Recent G2 Reviews of Amazon Inspector?

Edgescan

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

Average Rating: 4.6/5.0

Total Reviews: 58

How Do G2 Users Rate Edgescan?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.2/10)
  • Detection Rate: 9.3/10 (Category avg: 9.0/10)
  • Automated Scans: 9.6/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Edgescan?

  • Seller: Edgescan
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Dublin, Dublin
  • Twitter: @edgescan
    2,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    90 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 38% Large, 28% Medium

What Do G2 Reviewers Say About Edgescan?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Edgescan, highlighting its intuitive interface and straightforward navigation.
  • Users value the automated vulnerability detection features of Edgescan for efficient risk assessment and remediation support.
  • Users value the excellent customer support from Edgescan, noting their responsiveness and proactivity in addressing queries.
  • Users value the detailed vulnerability identification from Edgescan, enabling effective risk management and threat mitigation strategies.
  • Users value Edgescan for its intuitive interface and comprehensive functionality that streamlines security assessments and support.
Cons
  • Users find the complex UI of Edgescan challenging, often requiring guidance to navigate key functions effectively.
  • Users find limited customization options frustrating, particularly with filtering systems and administrative functionalities.
  • Users find the poor interface design of Edgescan challenging, causing navigation and task completion difficulties.
  • Users experience slow performance with Edgescan as manual reviews lead to longer scan completion times.
  • Users find the user interface challenging and unintuitive, leading to difficulties in navigation and task completion.

What Are Recent G2 Reviews of Edgescan?

What Are G2 Users Discussing About Edgescan?

Mend.io

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

Average Rating: 4.3/5.0

Total Reviews: 117

How Do G2 Users Rate Mend.io?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.2/10)
  • Detection Rate: 10.0/10 (Category avg: 9.0/10)
  • Automated Scans: 9.6/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 10.0/10 (Category avg: 8.5/10)

Who Is the Company Behind Mend.io?

  • Seller: Mend
  • Company Website:
  • Year Founded: 2011
  • HQ Location: Boston, Massachusetts
  • Twitter: @Mend_io
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    259 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 36% Small, 33% Large

What Do G2 Reviewers Say About Mend.io?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the scanning efficiency of Mend.io, enabling quick and accurate scans across multiple repositories seamlessly.
  • Users appreciate the ease of use of Mend.io, made simpler by effective integrations and an attractive interface.
  • Users value the easy integrations of Mend.io, allowing seamless scanning across multiple repositories and CI/CD platforms.
  • Users appreciate the quick and accurate scanning capabilities of Mend.io, benefiting from a range of integrations.
  • Users value the automated vulnerability detection of Mend.io, enhancing efficiency in identifying and addressing issues seamlessly.
Cons
  • Users face integration issues with Mend.io, finding it difficult to connect on-premise tools and features like Jira.
  • Users express concern over limited features in Mend.io, necessitating workarounds for optimal functionality and integration.
  • Users find the missing features in Mend.io cumbersome, often resorting to workarounds for integration and functionality.
  • Users face complex implementation, with challenging integration and frequent false positives affecting their experience.
  • Users find the confusing interface challenging due to the awkward transitions between different portals.

What Are Recent G2 Reviews of Mend.io?

What Are G2 Users Discussing About Mend.io?

VulScan

Automated Vulnerability Scanning. Affordably Priced For Everyone! With almost 70 new hidden vulnerabilities identified every day, you would need to be a super hero with X-ray vision to find them all. Or, you can let VulScan do it for you. VulScan is purpose-built for MSPs and for IT Departments that handle their own IT security. It has all the features you need for both internal and external vulnerability management, but without all the complexity found in older solutions. Best of all, VulScan is priced so that cost is no longer a barrier to scanning as many assets as you need, as frequently as you want. That’s why our slogan is “Vulnerability Management For The Rest of Us! VulScan is an affordable cloud-based vulnerability management platform. It includes the software needed to spin up an unlimited number of virtual network scanner appliances using Hyper-V or VMWare, and a cloud-based portal to control the scanners and manage the discovered issues. For internal network scanning, the appliances can be installed on any existing computer that has excess capacity on the network, or installed on a dedicated box to be permanently installed. You can add multiple scanners and configure them each to scan separate parts of the network to get even faster results pushed into the same client site dashboard at no additional cost. For external scanning, the appliances are installed on the MSP’s data center or other remote location and “pointed” to the public facing IP addresses of the target network.

Average Rating: 4.1/5.0

Total Reviews: 121

How Do G2 Users Rate VulScan?

  • Has the product been a good partner in doing business?: 8.2/10 (Category avg: 9.2/10)
  • Detection Rate: 7.8/10 (Category avg: 9.0/10)
  • Automated Scans: 8.6/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 6.9/10 (Category avg: 8.5/10)

Who Is the Company Behind VulScan?

  • Seller: Kaseya
  • Company Website:
  • Year Founded: 2000
  • HQ Location: Miami, FL
  • Twitter: @KaseyaCorp
    17,411 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5,483 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 66% Small, 32% Medium

What Do G2 Reviewers Say About VulScan?

AI-generated summary from verified user reviews

Pros
  • Users find VulScan's ease of use exceptional, appreciating its simplicity in scheduling scans and generating reports.
  • Users appreciate the ease of reporting with VulScan, benefiting from automated scans and consolidated reports.
  • Users value the seamless integrations of VulScan, enhancing efficiency in documentation and vulnerability management.
  • Users appreciate the easy automated scanning of VulScan, simplifying network assessments and uncovering hidden vulnerabilities effectively.
Cons
  • Users are frustrated by the poor customer support from VulScan, facing difficulty in obtaining timely assistance.
  • Users find the difficult setup of VulScan to be a hindrance, requiring extensive configuration and proper hardware.

What Are Recent G2 Reviews of VulScan?

Acunetix by Invicti

Acunetix (by Invicti) is an automated application security testing tool that enables small security teams to tackle huge application security challenges. With fast scanning, comprehensive results, and intelligent automation, Acunetix helps organizations to reduce risk across all types of web applications, websites, and APIs. With Acunetix, security teams can: - Save time and resources by automating manual security processes - Work more seamlessly with developers, or embrace DevSecOps by integrating directly into development tools - Feel confident that every web application has been crawled entirely thanks to DAST + IAST scanning and intelligent crawling technology - Finally, make web application and API security a priority and not just an add-on with a solution that is dedicated to application and API security 100% of the time You can depend on Acunetix to meet your organization’s needs today and face the challenges of modern web technology together tomorrow.

Average Rating: 4.1/5.0

Total Reviews: 100

How Do G2 Users Rate Acunetix by Invicti?

  • Has the product been a good partner in doing business?: 8.2/10 (Category avg: 9.2/10)
  • Detection Rate: 8.5/10 (Category avg: 9.0/10)
  • Automated Scans: 8.6/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 7.9/10 (Category avg: 8.5/10)

Who Is the Company Behind Acunetix by Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    326 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 40% Large, 34% Medium

What Do G2 Reviewers Say About Acunetix by Invicti?

AI-generated summary from verified user reviews

Pros
  • Users value the accurate and fast vulnerability detection of Acunetix, enhancing their security scanning capabilities efficiently.
  • Users praise the ease of use of Acunetix, highlighting its simple integration and effective security scanning capabilities.
  • Users value the robust security features of Acunetix, enhancing the safety of web applications effectively.
  • Users value the effective vulnerability identification by Acunetix, enhancing web application security and streamlining remediation processes.
  • Users highlight the accuracy of results from Acunetix, noting its impressive ability to identify vulnerabilities effectively.
Cons
  • Users find Acunetix by Invicti to be expensive, making it less accessible for smaller teams or projects.
  • Users find Acunetix's complex setup and resource intensity challenging, especially for large applications and first-time configurations.
  • Users find the setup process complex, particularly for new users and large application configurations.
  • Users note that the scanning process is often slow, affecting efficiency and delaying normal workflows, especially with large applications.
  • Users find the difficult customization of Acunetix challenging, requiring technical expertise to set up and fine-tune integrations.

What Are Recent G2 Reviews of Acunetix by Invicti?

What Are G2 Users Discussing About Acunetix by Invicti?

Invicti

Invicti (formerly known as Netsparker) is an enterprise application and API security testing platform that helps organizations secure thousands of web applications and APIs at scale while dramatically reducing the risk of attack. Combining advanced DAST and IAST capabilities in a single platform, Invicti enables security teams to continuously identify, prioritize, and remediate vulnerabilities across complex modern environments with confidence and automation. With Invicti, security teams can: - Automate application security testing workflows and save hundreds of hours every month - Discover and secure all web applications and APIs, including forgotten, unmanaged, and shadow assets - Deliver actionable, developer-friendly feedback that helps teams remediate vulnerabilities faster and build more secure code over time - Reduce false positives with proof-based scanning technology that validates exploitable vulnerabilities - Scale application security programs across large enterprises without slowing development teams - Integrate security seamlessly into existing DevSecOps and CI/CD workflows Built for organizations with the most demanding security requirements, Invicti empowers teams to confidently secure their entire attack surface with accuracy, scalability, and automation.

Average Rating: 4.5/5.0

Total Reviews: 69

How Do G2 Users Rate Invicti?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)
  • Detection Rate: 9.0/10 (Category avg: 9.0/10)
  • Automated Scans: 9.1/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    326 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 46% Large, 29% Medium

What Do G2 Reviewers Say About Invicti?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Invicti, facilitating quick setup and effective vulnerability scanning in their workflow.
  • Users value the quick and easy scanning technology of Invicti, enhancing workflow efficiency and accuracy in vulnerability detection.
  • Users value the simplicity and integration of Invicti, enhancing security measures through user-friendly report generation and detailed views.
  • Users value the easy-to-read and well-formatted reports from Invicti, enhancing efficiency and supporting ISO certification needs.
  • Users value the high accuracy and ease of use in Invicti's vulnerability detection, effectively identifying true issues.
Cons
  • Users find the customer support lacking, often experiencing slow responses and inadequate technical assistance.
  • Users experience slow performance during scans and setups, impacting overall efficiency and satisfaction.
  • Users experience slow scanning issues with Invicti, often leading to frustrating delays during the scanning process.
  • Users face API scanning issues with Invicti, limiting its effectiveness for their specific needs despite decent support.
  • Users find the complex setup of Invicti challenging initially, hindering their ability to quickly navigate configurations.

What Are Recent G2 Reviews of Invicti?

What Are G2 Users Discussing About Invicti?

APPCHECK

AppCheck is a Dynamic Application Security Testing (DAST) and network vulnerability testing solution, developed and supported by experienced penetration testers. We approach security testing as a hacker would, leveraging multiple proprietary crawling engines to analyse target behaviour across both modern and traditional technologies, including Single Page Applications (SPAs), APIs, and complex authentication flows such as SSO, 2FA, and TOTP. Organisations can conduct unlimited security assessments across Web Applications, SPAs, APIs, cloud services, networks, across internal or external assets. Supporting production and UAT testing, AppCheck also helps organisations ‘shift left’ by integrating with CI/CD pipelines and build servers, including ADO, GitHub, Jenkins, TeamCity, CircleCI, TravisCI, Bamboo, and GitLab CI/CD. Allowing automated security testing throughout development, identifying risks as soon as changes are introduced. AppCheck are proud to be part of the CVE Numbering Authority (CNA), contributing to global security research

Average Rating: 4.7/5.0

Total Reviews: 68

How Do G2 Users Rate APPCHECK?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.2/10)
  • Detection Rate: 9.2/10 (Category avg: 9.0/10)
  • Automated Scans: 9.5/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.8/10 (Category avg: 8.5/10)

Who Is the Company Behind APPCHECK?

  • Seller: APPCHECK
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Leeds, GB
  • Twitter: @AppcheckNG
    649 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    104 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 49% Medium, 31% Small

What Do G2 Reviewers Say About APPCHECK?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of AppCheck, making complex processes straightforward and efficient.
  • Users commend AppCheck for its exceptional vulnerability detection, providing thorough coverage and easy integration into workflows.
  • Users value the excellent pricing and functionality of AppCheck, praising its usability and proactive support from the team.
  • Users commend AppCheck for its efficiency in pentesting, notably for thorough vulnerability coverage and seamless integration.
  • Users love the scanning efficiency of AppCheck, finding it reliable and easy to integrate within development workflows.
Cons
  • Users suggest that UX improvements in scoring, customization, and integrations could enhance the AppCheck experience.
  • Users find the API issues frustrating, as endpoint changes require a service request and delays functionality.
  • Users find difficult customization in AppCheck's reporting features, needing more flexibility for contextual adjustments.
  • Users experience a notable difficult learning curve with Appcheck, which may hinder initial ease of use.
  • Users find the false positives in scan results problematic, necessitating manual validation and complicating the reporting process.

What Are Recent G2 Reviews of APPCHECK?

Orca Security

The Orca Cloud Security Platform identifies, prioritizes, and remediates risks and compliance issues in workloads, configurations, and identities across your cloud estate spanning AWS, Azure, Google Cloud, Kubernetes, Alibaba Cloud, and Oracle Cloud. Orca offers the industry’s most comprehensive cloud security solution in a single platform — eliminating the need to deploy and maintain multiple point solutions. Orca is agentless-first, and connects to your environment in minutes using Orca’s patented SideScanning™ technology that provides deep and wide visibility into your cloud environment, without requiring agents. In addition, Orca can integrate with third-party agents for runtime visibility and protection for critical workloads. Orca is at the forefront of leveraging Generative AI for simplified investigations and accelerated remediation – reducing required skill levels and saving cloud security, DevOps, and development teams time and effort, while significantly improving security outcomes. As a Cloud Native Application Protection Platform (CNAPP), Orca consolidates many point solutions in one platform, including: CSPM, CWPP, CIEM, Vulnerability Management, Container and Kubernetes Security, DSPM, API Security, CDR, Multi-cloud Compliance, Shift Left Security, and AI-SPM.

Average Rating: 4.7/5.0

Total Reviews: 312

How Do G2 Users Rate Orca Security?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Detection Rate: 8.8/10 (Category avg: 9.0/10)
  • Automated Scans: 9.2/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.8/10 (Category avg: 8.5/10)

Who Is the Company Behind Orca Security?

  • Seller: Orca Security
  • Company Website:
  • Year Founded: 2019
  • HQ Location: Portland, Oregon
  • Twitter: @orcasec
    4,835 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    523 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Engineer, CISO
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 53% Large, 36% Medium

What Do G2 Reviewers Say About Orca Security?

AI-generated summary from verified user reviews

Pros
  • Users highly value the ease of use of Orca Security, enabling quick setup and intuitive navigation.
  • Users value the great visibility provided by Orca Security, enabling effective vulnerability management and prioritization of alerts.
  • Users value the agentless feature and intuitive interface of Orca Security, enhancing their security management experience.
  • Users praise the visibility provided by Orca Security, gaining comprehensive insights into their cloud environment effortlessly.
  • Users praise Orca Security for its comprehensive security features, offering great visibility and ease of implementation.
Cons
  • Users express concerns about security vulnerabilities, especially regarding API security and detection of vulnerable packages.
  • Users experience dashboard issues like clutter, slow performance, and quirks that hinder efficient navigation and usability.
  • Users face challenges with delayed detection of vulnerabilities, impacting timely response and troubleshooting efforts in Orca Security.
  • Users report many false positives, complicating the assessment of actual vulnerabilities in Orca Security.
  • Users note that the reporting capabilities and customization options of Orca Security need significant improvement.

What Are Recent G2 Reviews of Orca Security?

What Are G2 Users Discussing About Orca Security?

Saner CVEM

Prevention-first Vulnerability and Exposure Management for unified visibility, prioritization, compliance, and remediation Saner Continuous Vulnerability and Exposure Management unifies asset exposure, posture anomaly detection, vulnerability assessment, compliance management, risk prioritization, patching, and endpoint actions in one dashboard. Saner CVEM is built to help teams continuously detect, assess, prioritize, and remediate vulnerabilities and other security risks from a unified console Why Choose Saner CVEM? • Unified dashboard with interactive views across visibility, detection, prioritization, and remediation for a single source of truth • Complete asset visibility across endpoint and non-endpoint devices, operating system applications, third-party applications, and lifecycle changes • Continuous risk discovery with rapid scans, daily-updated risk intelligence, and posture anomaly detection that helps surface outliers and misconfigurations faster • Context-driven prioritization with SSVC categories such as Act, Attend, Track, and Track* so teams can focus on the risks that deserve action first. • Continuous compliance management with built-in templates, customizable profiles, daily checks, and deviation tracking across common frameworks. • Integrated patching and remediation with vulnerability-to-patch mapping, automated deployment workflows, and endpoint actions from the same ecosystem. • Machine-learning-assisted analysis to identify deeper risk patterns, detect unusual posture, and support smarter remediation decisions. • Customizable, audit-ready reporting for security, IT, and compliance teams that need clearer evidence and easier tracking. • Flexible deployment on cloud or on-premises, with remediation support across Windows, Linux, macOS, and AIX environments.

Average Rating: 4.5/5.0

Total Reviews: 72

How Do G2 Users Rate Saner CVEM?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.2/10)
  • Detection Rate: 8.9/10 (Category avg: 9.0/10)
  • Automated Scans: 9.2/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.1/10 (Category avg: 8.5/10)

Who Is the Company Behind Saner CVEM?

  • Seller: SecPod
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Redwood City, California
  • Twitter: @secpod
    542 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    182 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 41% Small, 38% Medium

What Do G2 Reviewers Say About Saner CVEM?

AI-generated summary from verified user reviews

Pros
  • Users value the automatic security updates from Saner CVEM, ensuring timely compliance for remote workforce systems.
  • Users appreciate the advanced automation features of Saner CVEM, streamlining security patch management for remote systems.
  • Users value the seamless integrations of Saner CVEM, enhancing operational efficiency and strengthening digital security across IT processes.
  • Users value the automated compliance management of Saner CVEM, enhancing efficiency and reducing manual intervention significantly.
  • Users highlight the exceptional customer support from Saner CVEM, enhancing security and helping organizations stay protected.
Cons
  • Users often face integration issues with Saner CVEM, leading to frustrations during setup and ongoing maintenance.
  • Users note limited features in Saner CVEM, especially in multi-tenant support and integration capabilities, impacting efficiency.
  • Users experience slow performance when loading large data sets and during initial setup, affecting usability.
  • Users experience slow scanning, especially with initial dashboard load times and large data sets affecting daily checks.
  • Users find the limited cloud integration challenging, requiring workarounds and custom scripts for effective use.

What Are Recent G2 Reviews of Saner CVEM?

What Are G2 Users Discussing About Saner CVEM?

Microsoft Defender Vulnerability Management

Defender Vulnerability Management delivers asset visibility, intelligent assessments, and built-in remediation tools for Windows, macOS, Linux, Android, iOS, and network devices. Leveraging Microsoft threat intelligence, breach likelihood predictions, business contexts, and devices assessments, Defender Vulnerability Management rapidly and continuously prioritizes the biggest vulnerabilities on your most critical assets and provides security recommendations to mitigate risk. Reduce risk with continuous vulnerability assessment, risk-based prioritization, and remediation. Defender Vulnerability Management is available for cloud workloads and endpoints. Defender for Endpoint Plan 2 customers can access advanced vulnerability management capabilities with the Defender Vulnerability Management add-on, now generally available.

Average Rating: 4.4/5.0

Total Reviews: 34

How Do G2 Users Rate Microsoft Defender Vulnerability Management?

  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 9.2/10)
  • Detection Rate: 8.3/10 (Category avg: 9.0/10)
  • Automated Scans: 7.2/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 7.2/10 (Category avg: 8.5/10)

Who Is the Company Behind Microsoft Defender Vulnerability Management?

  • Seller: Microsoft
  • Year Founded: 1975
  • HQ Location: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    232,750 employees on LinkedIn®
  • Ownership: MSFT

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 41% Small, 35% Large

What Are Recent G2 Reviews of Microsoft Defender Vulnerability Management?

Detectify

Detectify sets a new standard for advanced application security testing, challenging traditional DAST by providing evolving coverage of each and every exposed asset across the changing attack surface. AppSec teams trust Detectify to expose how attackers will exploit their Internet-facing applications. The Detectify platform automates continuous real-world, payload-based attacks fuelled by its global community of elite ethical hackers into its own expert-built engines, exposing critical weaknesses before it's too late. The Detectify solution includes: - Automated discovery of known and unknown digital assets via domain & cloud connectors - Continuous coverage (24/7) of every corner of the attack surface with dynamic testing. Not just predefined targets - 100% payload-based testing fuelled by elite ethical hackers for a high signal-to-noise ratio - Distributed coverage across an unmatched array of relevant technologies - Actionable remediation tips for software development teams - Team functionality to easily share reports - Powerful integrations platform to prioritize and triage vulnerability findings onward to development teams -Advanced API functionality -Capabilities to set custom attack surface security policies

Average Rating: 4.5/5.0

Total Reviews: 49

How Do G2 Users Rate Detectify?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.2/10)
  • Detection Rate: 8.5/10 (Category avg: 9.0/10)
  • Automated Scans: 8.9/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Detectify?

  • Seller: Detectify
  • Year Founded: 2013
  • HQ Location: Stockholm, Sweden
  • Twitter: @detectify
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    96 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 47% Small, 35% Medium

What Do G2 Reviewers Say About Detectify?

AI-generated summary from verified user reviews

Pros
  • Users praise Detectify for its automation capabilities, making security testing seamless and adaptable to existing workflows.
  • Users appreciate Detectify's automation testing capabilities, making security assessments easier and more efficient to manage.
  • Users appreciate the customizability of Detectify, enjoying its easy integration and tailored security testing options.
  • Users praise Detectify for its easy integration and comprehensive dynamic application security testing, enhancing security without complex setups.
  • Users value Detectify for its effective dynamic application security testing and seamless integration into existing workflows.
Cons
  • Users find the initial setup complex, which can create challenges in getting started with Detectify.
  • Users struggle with the complex queries in Detectify, which hinder understanding of the spidering outcomes and assessments.
  • Users find the complex setup of Detectify challenging, making initial use more difficult than expected.
  • Users find Detectify expensive when testing multiple sites, affecting its accessibility for wider use.
  • Users face inaccuracies in Detectify's spidering results, leading to uncertainty in thorough application assessments.

What Are Recent G2 Reviews of Detectify?

What Are G2 Users Discussing About Detectify?

Jit

Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empowers organizations to proactively manage security risks across the entire software development lifecycle.​ AI-Powered Agents Jit's AI Agents, such as SERA (Security Evaluation and Remediation Agent) and COTA (Communication, Ops, and Ticketing Agent), collaborate with your teams to automate vulnerability triage, risk assessment, and remediation processes, significantly reducing manual workloads. ​ Comprehensive Security Scanning Achieve full-stack security coverage with integrated scanners for SAST, DAST, SCA, IaC, CSPM, and more. Jit's platform ensures continuous monitoring and immediate feedback on code changes, facilitating rapid identification and resolution of security issues. ​ Developer-Centric Experience With integrations into popular IDEs and CI/CD pipelines, Jit provides developers with contextual security insights directly within their workflows, promoting a shift-left approach without disrupting productivity. ​ Agentic AI for AppSec Teams Risk-Based Prioritization Utilizing the Model Context Protocol (MCP), Jit evaluates vulnerabilities in the context of runtime environments, business impact, and compliance requirements, enabling teams to focus on the most critical risks. ​ Seamless Integrations Jit integrates with a wide array of tools, including GitHub, GitLab, AWS, Azure, GCP, Jira, Slack, and more, ensuring that security processes are embedded within your existing technology stack. ​

Average Rating: 4.5/5.0

Total Reviews: 43

How Do G2 Users Rate Jit?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)
  • Detection Rate: 8.4/10 (Category avg: 9.0/10)
  • Automated Scans: 8.6/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.4/10 (Category avg: 8.5/10)

Who Is the Company Behind Jit?

  • Seller: jit
  • Year Founded: 2021
  • HQ Location: Boston, MA
  • Twitter: @jit_io
    522 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    161 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Financial Services
  • Company Size: 44% Medium, 42% Small

What Do G2 Reviewers Say About Jit?

AI-generated summary from verified user reviews

Pros
  • Users value the seamless integration of security in Jit, enhancing efficiency without overwhelming the development process.
  • Users value the easy integrations of Jit, streamlining security into development without overwhelming workflows.
  • Users appreciate the ease of use of Jit, as it simplifies integration and enhances productivity without added complexity.
  • Users value the efficiency of Jit, noting significant waste reduction and streamlined processes that enhance overall productivity.
  • Users praise the easy integration support of Jit, streamlining security practices in the development workflow.
Cons
  • Users note integration issues, as Jit may not support all enterprise environments and requires extra manual setup.
  • Users find the product has limited features, especially in customization and advanced analytics for complex environments.
  • Users express concerns about limited integration with enterprise environments and third-party tools, hindering overall usability.
  • Users find the documentation lacking for advanced configurations, making it difficult to fully utilize Jit.
  • Users find the complexity of Jit's advanced integrations and features overwhelming for beginners and experienced developers alike.

What Are Recent G2 Reviews of Jit?

Defendify All-In-One Cybersecurity Solution

Founded in 2017, Defendify is pioneering All-In-One Cybersecurity® for organizations with growing security needs, backed by experts offering ongoing guidance and support. Delivering multiple layers of protection, Defendify provides an all-in-one, easy-to-use platform designed to strengthen cybersecurity across people, process, and technology, continuously. With Defendify, organizations streamline cybersecurity assessments, testing, policies, training, detection, response & containment in one consolidated and cost-effective cybersecurity solution. 3 layers, 13 solutions, 1 platform, including: • Managed Detection & Response • Cyber Incident Response Plan • Cybersecurity Threat Alerts • Phishing Simulations • Cybersecurity Awareness Training • Cybersecurity Awareness Videos • Cybersecurity Awareness Posters & Graphics • Technology Acceptable Use Policy • Cybersecurity Risk Assessments • Penetration Testing • Vulnerability Scanning • Compromised Password Scanning • Website Security Scanning See Defendify in action at www.defendify.com.

Average Rating: 4.7/5.0

Total Reviews: 57

How Do G2 Users Rate Defendify All-In-One Cybersecurity Solution?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.2/10)
  • Detection Rate: 9.2/10 (Category avg: 9.0/10)
  • Automated Scans: 9.4/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.9/10 (Category avg: 8.5/10)

Who Is the Company Behind Defendify All-In-One Cybersecurity Solution?

  • Seller: Defendify
  • Year Founded: 2017
  • HQ Location: Portland, Maine
  • Twitter: @defendify
    305 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    36 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 65% Small, 35% Medium

What Do G2 Reviewers Say About Defendify All-In-One Cybersecurity Solution?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Defendify, streamlining cybersecurity management for small and medium-sized businesses.
  • Users praise Defendify for its comprehensive and cost-effective cybersecurity features, streamlining management for small to medium-sized businesses.
  • Users appreciate the easy setup of Defendify, finding it quick and simple for effective cybersecurity management.
  • Users value the ease of use of Defendify, appreciating quick setup and actionable insights for cybersecurity management.
  • Users value the continuous monitoring features of Defendify, easing the burden of network security management significantly.
Cons
  • Users note that inadequate reporting hinders effective communication, calling for improvements in clarity and detail.
  • Users feel that the poor reporting features hinder effective communication and internal analysis of cybersecurity efforts.
  • Users express frustration over the lack of concise information in reports, preferring clearer and more detailed summaries.
  • Users find the limited customization options restrictive, wishing for more personalized reporting and branding capabilities.
  • Users desire custom reporting options and co-branding features to enhance the personalization of their experience.

What Are Recent G2 Reviews of Defendify All-In-One Cybersecurity Solution?

What Are G2 Users Discussing About Defendify All-In-One Cybersecurity Solution?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated