Best Vulnerability Scanner Software - Page 5

How Many Vulnerability Scanner Software Products Does G2 Track?

Total Products under this Category: 236

Category Stats (Sep 2026)

  • Average Rating: 4.59/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Armis (+0.18%) - Among all products in this category, Armis recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Vulnerability Scanner Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 7,800+ Authentic Reviews
  • 236+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Vulnerability Scanner Software

G2 Grid® for Vulnerability Scanner Software plotting products by satisfaction and market presence

Highlighted products: Wiz, Aikido Security, CrowdStrike Falcon Cloud Security, Orca Security, Tenable Nessus, Astra Pentest, Intruder, and Burp Suite.

Underlying data: [Grid® JSON](https://www.g2.com/categories/vulnerability-scanner/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=orca-security&focus%5B%5D=tenable-nessus&focus%5B%5D=astra-pentest&focus%5B%5D=intruder&focus%5B%5D=burp-suite)

Qualys VMDR

Qualys VMDR is an all-in-one risk-based vulnerability management solution that quantifies cyber risk. It gives organizations unprecedented insights into their risk posture and provides actionable steps to reduce risk. It also gives cybersecurity and IT teams a shared platform to collaborate, and the power to quickly align and automate no-code workflows to respond to threats with automated remediation and integrations with ITSM solutions such as ServiceNow.

Average Rating: 4.4/5.0

Total Reviews: 165

How Do G2 Users Rate Qualys VMDR?

  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 9.2/10)
  • Detection Rate: 8.5/10 (Category avg: 9.0/10)
  • Automated Scans: 8.6/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.4/10 (Category avg: 8.5/10)

Who Is the Company Behind Qualys VMDR?

  • Seller: Qualys
  • Year Founded: 1999
  • HQ Location: Foster City, CA
  • Twitter: @qualys
    34,248 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,637 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 51% Large, 28% Medium

What Do G2 Reviewers Say About Qualys VMDR?

AI-generated summary from verified user reviews

Pros
  • Users value the swift and comprehensive vulnerability detection of Qualys VMDR, enhancing overall security and response times.
  • Users value the swift vulnerability identification of Qualys VMDR, allowing for quick corrections and enhanced security posture.
  • Users value the real-time alerting system of Qualys VMDR, which ensures quick responses to critical vulnerabilities.
  • Users value the automation capabilities of Qualys VMDR, simplifying vulnerability detection and remediation processes effectively.
  • Users value the cloud integration for its ease of deployment and comprehensive vulnerability management solutions.
Cons
  • Users find the interface complexity challenging, especially for new users during the initial setup.
  • Users find the complex reporting challenging, especially for new users, making initial use difficult.
  • Users find the complex setup challenging, especially for new users unfamiliar with the interface.
  • Users find the difficult learning curve of Qualys VMDR challenging, especially for newcomers to the platform.
  • Users find the feature complexity of Qualys VMDR challenging, especially during the initial stage for new users.

What Are Recent G2 Reviews of Qualys VMDR?

What Are G2 Users Discussing About Qualys VMDR?

DefectDojo

DefectDojo unifies and automates vulnerability management, enabling security teams to focus on strategic, data-driven analysis. We help teams reduce time spent on manual tracking and consolidate vulnerabilities from existing tools for seamless vulnerability management.

Average Rating: 4.6/5.0

Total Reviews: 11

How Do G2 Users Rate DefectDojo?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Detection Rate: 8.5/10 (Category avg: 9.0/10)
  • Automated Scans: 6.9/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.3/10 (Category avg: 8.5/10)

Who Is the Company Behind DefectDojo?

  • Seller: DefectDojo
  • Year Founded: 2017
  • HQ Location: Austin, US
  • Twitter: @defectdojo
    699 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    27 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 64% Medium, 36% Small

What Are Recent G2 Reviews of DefectDojo?

What Are G2 Users Discussing About DefectDojo?

Runecast

Runecast is an enterprise CNAPP platform which saves your Security and Operations teams time and resources by enabling a proactive approach to ITOM, CSPM, and compliance. It helps you proactively remediate vulnerabilities for continuous compliance, whether on-prem, cloud or containers. By proactively using our agentless scanning in real-time admins discover potential risks and remediation solutions before any issues can develop into a major outage. Runecast’s AI-RAIKA, leverages advanced natural language processing (NLP) capabilities to interpret a vast amount of information to provide automated audits for security compliance standards, vulnerabilities (such as KEVs, CVEs or VMSAs) and technology vendor best practices. The platform has been recognized with Frost & Sullivan's 2023 European New Product Innovation Award in the CNAPP industry for its strong overall performance and commitment to user experience. NAVIGATING YOUR COMPLEXITY Runecast helps teams with a simpler transition to cloud, enabling admins to fully understand their hybrid environments and Cloud Security Posture Management (CSPM) and Kubernetes Security Posture Management (KSPM). Running securely on-premises, it provides insights into what is happening both in the cloud and on-site. IMMEDIATE VALUE FOR TEAMS As Runecast helps teams to stabilize availability and ensure security compliance, it contributes also to greater ROI for both existing and future investments with AWS, Azure, Kubernetes and VMware. FULLY ON-PREM SECURE Operates fully on-prem to analyze your hybrid-cloud environment, so that your data remains safely on-site. To provide additional security, Runecast features a customizable, transparent rules engine. RUNECAST FOR SECURITY AND COMPLIANCE Vulnerability Management Regular automated scanning, recommendations, remediation, and the ability to set up vulnerability management policies are just some of the requirements many enterprises have. The Runecast platform is constantly updated to detect the latest vulnerabilities for all of the supported technologies. Container Security Runecast scans container images for known vulnerabilities and misconfigurations, and can also detect runtime issues such as exposed ports and running processes. It also provides a public API which can be used in your CI/CD platform to analyze the container images and whether they are vulnerable or not to known vulnerabilities, before deploying them in production. Compliance with Security Standards Runecast offers automated audits against security hardening guidelines and common industry standards like CIS Benchmarks, NIST 800-53, PCI DSS, HIPAA, DISA STIG 6, GDPR, KVKK (Turkey), ISO 27001, BSI IT-Grundschutz, Essential 8 and Cyber Essentials Security Standard. RUNECAST FOR IT OPERATIONS TEAMS Vendor Best Practices for Security Hardening Runecast continuously monitors your complex environment, reporting violations and providing recommendations against Vendor Best Practices. It maintains a database with Best Practices of the latest AWS, Azure, Kubernetes, GCP, VMware and Windows and Linux OS. It analyzes your environment to detect any configuration issues against Vendor Best Practices. This delivers valuable insights to improve the stability and security of your infrastructure. Configuration Vault Tracks your configuration to help you prevent drift. Reports your entire configuration and provides the ability to compare your configurations over time. Hardware Compatibility and Upgrade Stimulations Runecast has automated the process of validating the hardware compliance of hosts and clusters against a selected ESXi version, ensuring compliance with the VMware Compatibility Guide (VCG) and vSAN Hardware Compatibility List (vSAN HCL). The AI-powered platform runs a quick and automated analysis using the latest HCL for your servers, I/O devices, and vSAN controllers. For upgrade planning, admins can see the results of multiple HCL upgrade simulation scenarios within seconds, and the findings are presented in a comprehensive way with details about any non-compatibility and how to resolve it. Validates your hardware, drivers, and firmware against current and upstream releases of ESXi for faster upgrade planning. Remediation Scripts A growing number of findings in Runecast offer remediation actions – allowing you to download the customized script to perform the reconfiguration. Some rules offer more than one remediation option, for example PowerCLI and Ansible. SUPPORTED SERVICES SUPPORTED SYSTEMS: AWS, Azure GCP, Kubernetes (1.20 and above), VMware (VMware vSphere, NSX-V, NSX-T, VMware Horizon, VMware Cloud Director, AP HANA for VMware, VMware on Nutanix, Pure Storage), Windows (Microsoft Windows) and Linux OS (RHEL 8, CentOS 7). SECURITY STANDARDS: CIS Benchmarks, NIST 800-53, PCI DSS, HIPAA, DISA STIG 6, GDPR, KVKK (Turkey), ISO 27001, BSI IT-Grundschutz, Essential 8 and Cyber Essentials Security Standard. INTEGRATIONS: Jira, ServiceNow, vSphere Client Plugin, OpenID Connect, REST API, HPE Ezmeral. REMEDIATION TOOLS: Ansible (VMware), PowerCLI (VMware), AWS CLI (AWS), AWS Tools for PowerShell (AWS), GCP CLI

Average Rating: 4.8/5.0

Total Reviews: 21

How Do G2 Users Rate Runecast?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)
  • Detection Rate: 10.0/10 (Category avg: 9.0/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 10.0/10 (Category avg: 8.5/10)

Who Is the Company Behind Runecast?

  • Seller: Runecast Solutions
  • Year Founded: 2014
  • HQ Location: London, London
  • Twitter: @Runecast
    1,093 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 48% Large, 24% Medium

What Are Recent G2 Reviews of Runecast?

Detectify

Detectify sets a new standard for advanced application security testing, challenging traditional DAST by providing evolving coverage of each and every exposed asset across the changing attack surface. AppSec teams trust Detectify to expose how attackers will exploit their Internet-facing applications. The Detectify platform automates continuous real-world, payload-based attacks fuelled by its global community of elite ethical hackers into its own expert-built engines, exposing critical weaknesses before it's too late. The Detectify solution includes: - Automated discovery of known and unknown digital assets via domain & cloud connectors - Continuous coverage (24/7) of every corner of the attack surface with dynamic testing. Not just predefined targets - 100% payload-based testing fuelled by elite ethical hackers for a high signal-to-noise ratio - Distributed coverage across an unmatched array of relevant technologies - Actionable remediation tips for software development teams - Team functionality to easily share reports - Powerful integrations platform to prioritize and triage vulnerability findings onward to development teams -Advanced API functionality -Capabilities to set custom attack surface security policies

Average Rating: 4.5/5.0

Total Reviews: 49

How Do G2 Users Rate Detectify?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.2/10)
  • Detection Rate: 8.5/10 (Category avg: 9.0/10)
  • Automated Scans: 8.9/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Detectify?

  • Seller: Detectify
  • Year Founded: 2013
  • HQ Location: Stockholm, Sweden
  • Twitter: @detectify
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    96 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 47% Small, 35% Medium

What Do G2 Reviewers Say About Detectify?

AI-generated summary from verified user reviews

Pros
  • Users praise Detectify for its automation capabilities, making security testing seamless and adaptable to existing workflows.
  • Users appreciate Detectify's automation testing capabilities, making security assessments easier and more efficient to manage.
  • Users appreciate the customizability of Detectify, enjoying its easy integration and tailored security testing options.
  • Users praise Detectify for its easy integration and comprehensive dynamic application security testing, enhancing security without complex setups.
  • Users value Detectify for its effective dynamic application security testing and seamless integration into existing workflows.
Cons
  • Users find the initial setup complex, which can create challenges in getting started with Detectify.
  • Users struggle with the complex queries in Detectify, which hinder understanding of the spidering outcomes and assessments.
  • Users find the complex setup of Detectify challenging, making initial use more difficult than expected.
  • Users find Detectify expensive when testing multiple sites, affecting its accessibility for wider use.
  • Users face inaccuracies in Detectify's spidering results, leading to uncertainty in thorough application assessments.

What Are Recent G2 Reviews of Detectify?

What Are G2 Users Discussing About Detectify?

Finite State

Finite State empowers device OEMs to ship securely while enabling engineering teams to move at the speed of AI, immediately transforming product artifacts into audit-ready assurance through a single automated workflow. Leveraging deep binary analysis and AI-native execution, the platform unifies code, compiled components, and firmware in minutes—connecting security design with deployed software. By continuously generating SBOMs, VEX, and signed compliance packages, Finite State enables connected device companies across industries such as medical devices and automotive to meet evolving regulations, including the EU Cyber Resilience Act (CRA), and deliver continuous compliance at speed. Learn more at https://finitestate.io/

Average Rating: 4.3/5.0

Total Reviews: 12

How Do G2 Users Rate Finite State?

  • Detection Rate: 10.0/10 (Category avg: 9.0/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Finite State?

  • Seller: Finite State
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Columbus, Ohio, United States
  • Twitter: @FiniteStateInc
    670 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    78 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Large, 25% Medium

What Are Recent G2 Reviews of Finite State?

IBM Guardium Vulnerability Assessment

IBM Guardium Vulnerability Assessment scans data infrastructures (databases, data warehouses and big data environments) to detect vulnerabilities, and suggests remedial actions. The solution identifies exposures such as missing patches, weak passwords, unauthorized changes and misconfigured privileges. Full reports are provided as well as suggestions to address all vulnerabilities. Guardium Vulnerability Assessment detects behavioral vulnerabilities such as account sharing, excessive administrative logins and unusual after-hours activity. It identifies threats and security gaps in databases that could be exploited by hackers.

Average Rating: 4.5/5.0

Total Reviews: 12

How Do G2 Users Rate IBM Guardium Vulnerability Assessment?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.2/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.3/10 (Category avg: 8.5/10)

Who Is the Company Behind IBM Guardium Vulnerability Assessment?

  • Seller: IBM
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    344,328 employees on LinkedIn®
  • Ownership: SWX:IBM

Who Uses This Product?

  • Company Size: 58% Large, 25% Medium

What Are Recent G2 Reviews of IBM Guardium Vulnerability Assessment?

What Are G2 Users Discussing About IBM Guardium Vulnerability Assessment?

BugProve

As former security researchers, we founded BugProve to deliver the level of security that IoT deserves! Experience peace of mind by leveraging our automated firmware analysis platform: Swift Results: Upload your firmware image and receive first results in just 5 minutes. - Supply Chain Risk Management and Compliance: Identify components and known vulnerabilities, and opt for continuous CVE monitoring for compliance assurance. - Zero-day detection: Our built-in zero-day detection engine, PRIS, detects memory corruption vulnerabilities before they can be exploited. - All-in-One Hub: Seamlessly access product security reevaluations, comparisons, and updates, presented in an easily digestible format. - Effortless Sharing: Share findings via live links or export them as PDFs for convenient reporting. Involve your product development team with AI-assisted remediation recommendations. - Accelerated Testing: Save weeks in the pentesting process, enabling you to focus on in-depth discoveries and launch more secure products, without security bottlenecks. - IoT specific, detailed scans: BugProve runs checks directly on firmware, no source code needed. We run advanced static and dynamic analysis, unique multi-binary taint analysis, cryptographic analysis, and security configuration checks. No long-term contracts, commitments, and hidden fees. What’s more, we believe you should test the platform to see what it can do, so we offer a Free Plan. Sign up, and start scanning!

Average Rating: 4.9/5.0

Total Reviews: 20

How Do G2 Users Rate BugProve?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.2/10)
  • Detection Rate: 8.7/10 (Category avg: 9.0/10)
  • Automated Scans: 9.5/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.9/10 (Category avg: 8.5/10)

Who Is the Company Behind BugProve?

  • Seller: BugProve
  • Year Founded: 2021
  • HQ Location: Budapest, HU
  • Twitter: @Bugprove
    147 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 90% Small, 10% Large

What Are Recent G2 Reviews of BugProve?

FOSSA

Open source is a critical part of your software. In the average modern software product, over 80% of the source code shipped is derived from open source. Each component can have cascading legal, security, and quality implications for your customers, making it one of the most important things to manage correctly. FOSSA helps you manage your open source components. We plug into your development workflow to help your team automatically track, manage, and remediate issues with the open source you use to: - Stay compliant with software licenses and generate required attribution documents - Enforce usage and licensing policies throughout your CI/CD workflow - Monitor and remediate security vulnerabilities - Flag code quality issues and outdated components proactively By enabling open source, we help development teams increase development velocity and decrease risk.

Average Rating: 4.2/5.0

Total Reviews: 15

How Do G2 Users Rate FOSSA?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)
  • Detection Rate: 10.0/10 (Category avg: 9.0/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 10.0/10 (Category avg: 8.5/10)

Who Is the Company Behind FOSSA?

  • Seller: FOSSA
  • Year Founded: 2015
  • HQ Location: San Francisco, California
  • Twitter: @getfossa
    774 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    63 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 47% Small, 33% Medium

What Do G2 Reviewers Say About FOSSA?

AI-generated summary from verified user reviews

Pros
  • Users highlight the easy integrations of FOSSA, seamlessly working with Spring Boot and Angular applications through their pipeline.
  • Users appreciate FOSSA for its effective issue resolution, identifying library problems and recommending fixes in real-time.
  • Users find FOSSA's remediation solutions valuable for quickly identifying and recommending fixes for vulnerabilities in dependencies.
  • Users value the effective risk management provided by FOSSA, ensuring security and quality for applications.
  • Users value FOSSA for its robust security scanning, ensuring vulnerabilities are identified and managed effectively.

What Are Recent G2 Reviews of FOSSA?

Rainforest Application

Rainforest is the all-in-one cyber security platform with an end-to-end approach to simplify corporate reputation protection by using multiple intelligences and proactive observability, adding Application and Cloud Security (from DevOps to DevSecOps), Vulnerability Intelligence, and Brand reputation (Fraud and Leak monitoring). Rainforest Application, Rainforest Cloud, and Rainforest Asset modules allow development and security teams have visibility of all applications lifecycle, in a simple and quick way, providing vulnerability management always that a new line is coded. Rainforest Fraud, Rainforest Leak, and Rainforest Asset build an integrated vision of Vulnerability and Brand Intelligence, guiding security and compliance teams in an efficient manner on potential exposure points, according to their importance to the business regarding the company's reputation.

Average Rating: 4.9/5.0

Total Reviews: 12

How Do G2 Users Rate Rainforest Application?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.2/10)
  • Detection Rate: 9.0/10 (Category avg: 9.0/10)
  • Automated Scans: 9.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Rainforest Application?

Who Uses This Product?

  • Company Size: 42% Small, 42% Medium

What Are Recent G2 Reviews of Rainforest Application?

MalCare

Mitigate getting blacklisted by Google, being blocked by Webhosts or any possible security threats from the most complex malwares with MalCare's comprehensive and powerful automatic website malware scanning.

Average Rating: 4.1/5.0

Total Reviews: 13

How Do G2 Users Rate MalCare?

  • Has the product been a good partner in doing business?: 6.7/10 (Category avg: 9.2/10)
  • Detection Rate: 6.7/10 (Category avg: 9.0/10)
  • Automated Scans: 6.7/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 7.5/10 (Category avg: 8.5/10)

Who Is the Company Behind MalCare?

  • Seller: MalCare
  • Year Founded: 2016
  • HQ Location: Bangalore, Karnataka
  • Twitter: @malcaresecurity
    539 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 92% Small, 15% Medium

What Do G2 Reviewers Say About MalCare?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the efficiency improvement of MalCare, noting it does not slow down their websites at all.
Cons
  • Users experience false positives with MalCare, as it occasionally overlooks security issues in certain plugins.

What Are Recent G2 Reviews of MalCare?

What Are G2 Users Discussing About MalCare?

Zenmap

Zenmap is the official graphical user interface (GUI) for the Nmap Security Scanner, designed to make network scanning accessible for both beginners and experienced users. This multi-platform, free, and open-source application supports operating systems such as Linux, Windows, Mac OS X, and BSD. Zenmap simplifies the process of network discovery and security auditing by providing an intuitive interface to Nmap's powerful features. Key Features and Functionality: - Profile Management: Users can save frequently used scans as profiles, enabling quick and consistent execution of routine network assessments. - Command Creation: An interactive command creator assists in building Nmap command lines, making it easier to customize scans without extensive command-line knowledge. - Result Management: Scan results can be saved for future reference, compared to identify changes over time, and are stored in a searchable database for efficient retrieval. - Network Topology Visualization: Zenmap offers an interactive, animated visualization of network topology, illustrating the relationships and paths between hosts. - Cross-Platform Compatibility: The application runs on multiple operating systems, ensuring flexibility and broad accessibility. Primary Value and User Solutions: Zenmap addresses the need for a user-friendly interface to Nmap's comprehensive network scanning capabilities. By providing graphical representations and simplified management of scan profiles and results, it enables users to efficiently monitor network security, detect unauthorized devices, and manage service upgrades. This tool is particularly valuable for system and network administrators seeking to maintain secure and well-documented network environments.

Average Rating: 4.5/5.0

Total Reviews: 26

How Do G2 Users Rate Zenmap?

  • Has the product been a good partner in doing business?: 7.9/10 (Category avg: 9.2/10)
  • Detection Rate: 8.8/10 (Category avg: 9.0/10)
  • Automated Scans: 8.3/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 7.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Zenmap?

  • Seller: Nmap
  • HQ Location: N/A
  • Twitter: @nmap
    136,374 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 50% Medium, 39% Small

What Do G2 Reviewers Say About Zenmap?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Zenmap, making it ideal for penetration testers and cyber security analysts.
  • Users value the ease of implementation of Zenmap, finding it user-friendly and straightforward for various security tasks.
Cons
  • Users find the limited command functionality of Zenmap frustrating, affecting their overall experience on Kali Linux.
  • Users find Zenmap's poor interface design limits usability and complicates command execution within Kali Linux.

What Are Recent G2 Reviews of Zenmap?

What Are G2 Users Discussing About Zenmap?

Veracode Application Security Platform

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

Average Rating: 3.8/5.0

Total Reviews: 25

How Do G2 Users Rate Veracode Application Security Platform?

  • Has the product been a good partner in doing business?: 7.9/10 (Category avg: 9.2/10)
  • Detection Rate: 8.3/10 (Category avg: 9.0/10)
  • Automated Scans: 9.2/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.4/10 (Category avg: 8.5/10)

Who Is the Company Behind Veracode Application Security Platform?

  • Seller: VERACODE
  • Year Founded: 2006
  • HQ Location: Burlington, MA
  • Twitter: @Veracode
    21,950 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    500 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 69% Large, 31% Medium

What Do G2 Reviewers Say About Veracode Application Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the effective security vulnerability identification offered by Veracode, enhancing overall application safety and code integrity.
  • Users find Veracode's vulnerability detection excellent for identifying security issues and ensuring high application security standards.
  • Users value the automated scanning of Veracode, streamlining security checks and enhancing code quality effortlessly.
  • Users value the effective detection of security vulnerabilities, enabling robust protection and streamlined development processes.
  • Users appreciate the ease of integration with GitHub and CI/CD pipelines, streamlining their development process effectively.
Cons
  • Users find Veracode to be expensive, with high costs, complex licensing, and unfulfilled feature delivery.
  • Users face a lack of information due to mismatches in documentation and delayed notifications during uploads.
  • Users express concerns over licensing issues, including rising costs, complex models, and unequal feature availability.
  • Users report poor customer support with pushy account executives and difficulties in resolving issues efficiently.
  • Users express concerns about pricing issues, with rising costs and a complex licensing model affecting value perception.

What Are Recent G2 Reviews of Veracode Application Security Platform?

What Are G2 Users Discussing About Veracode Application Security Platform?

HostedScan.com

HostedScan provides 24x7 alerts and detection for security vulnerabilities. Industry-standard, open-source, vulnerability scans. Automated alerts when something changes. Manage target list manually or import automatically from providers, such as AWS, DigitalOcean, and Linode, with read-only access. Manage and audit risks with dashboarding and reporting.

Average Rating: 4.3/5.0

Total Reviews: 13

How Do G2 Users Rate HostedScan.com?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)
  • Detection Rate: 9.2/10 (Category avg: 9.0/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 10.0/10 (Category avg: 8.5/10)

Who Is the Company Behind HostedScan.com?

  • Seller: HostedScan
  • Year Founded: 2019
  • HQ Location: Seattle, Washington
  • Twitter: @hostedscan
    59 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 85% Small, 15% Medium

What Are Recent G2 Reviews of HostedScan.com?

OpenVAS

OpenVAS is a framework of several services and tools offering a comprehensive and powerful vulnerability scanning and vulnerability management solution.

Average Rating: 4.4/5.0

Total Reviews: 28

How Do G2 Users Rate OpenVAS?

  • Has the product been a good partner in doing business?: 7.5/10 (Category avg: 9.2/10)
  • Detection Rate: 8.1/10 (Category avg: 9.0/10)
  • Automated Scans: 8.3/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 7.0/10 (Category avg: 8.5/10)

Who Is the Company Behind OpenVAS?

  • Seller: OpenVAS
  • Year Founded: 2020
  • HQ Location: Zug, CH
  • Twitter: @openvas
    1,362 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 56% Medium, 34% Small

What Are Recent G2 Reviews of OpenVAS?

What Are G2 Users Discussing About OpenVAS?

Core6

StorageGuard - Verify and Harden the Security Posture of your Storage and Backup Systems The tactics being used by ransomware groups have changed. And it puts organizations’ storage and backup systems at major risk. The attackers realize that an attack on the storage or system is the single biggest determining factor to show if the organization will pay the ransom. Security Hardening for Storage and Backup Systems StorageGuard - by Core6 provides security hardening for all storage and backup systems, to improve your security posture, enable cyber-resiliency, and meet IT audit requirements. StorageGuard checks the security configuration of your storage and backup systems - ensuring those systems are hardened, meet security best practices, and comply with industry standards and regulatory requirements. For the first time, get complete visibility of security risks across these mission-critical systems, and ensure compliance with security regulations and industry standards StorageGuard supports Dell, NetApp, Hitachi Vantara, Everpure (formerly Pure Storage), IBM, Broadcom (Brocade), Cisco, VAST, HPE, Huawei, Infinidat (Lenovo), Nasuni, Rubrik, Cohesity (incl. Veritas Netbackup), Commvault, Veeam, and more. Benefits: • Ensure your storage and backup systems are continuously hardened, to withstand cyberattacks • Eliminate manual security validation efforts, and continuously validate against your security baseline • Eliminate configuration drift – by tracking security configuration changes • Leverage remediation guidance to speed time-to-resolve • Meet IT audit requirements, providing evidence for compliance Discover Continuously analyzes your storage & backup systems, to automatically detect security misconfigurations and vulnerabilities, The built-in knowledgebase of checks covers: • Security best-practices from storage & backup vendors • Standards (NIST, ISO, CIS, DORA, PCI etc.) as applied to storage & backup systems • Vulnerabilities (CVEs) in the storage & backup environment • Commonly used security baselines Prioritize Prioritizes those risks in order of urgency and business impact. Remediate Provides clear security remediation commands and guidance, which can be integrated into your IT service management and SIEM workflows. For every finding, StorageGuard provides detailed remediation commands for your team to quickly resolve the issue. This can also be integrated into your IT service management and SIEM workflows. Improve your security posture StorageGuard improves the ransomware-readiness and overall security posture of your storage and backup systems. We reduce the effort required by IT operations and storage teams to develop and enforce security policies, prove compliance for audit, and chase down false positive CVE alerts raised by tools that aren’t storage-aware. Meet IT Audit requirements StorageGuard provides broad storage and backup system support, and an extremely wide knowledgebase of automated checks, built on industry standards (e.g., NIST, ISO, and CIS), regulatory frameworks (e.g., PCI and DORA), and storage & backup vendor best practices. This makes it easy to audit and report on security misconfigurations and vulnerabilities across your entire storage and backup infrastructure. Fills a major gap StorageGuard fills a critical gap in security posture management. Existing tools by the likes of Tenable, Qualys and Rapid7 provide almost zero coverage for storage and backup systems.

Average Rating: 4.4/5.0

Total Reviews: 18

How Do G2 Users Rate Core6?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Detection Rate: 9.3/10 (Category avg: 9.0/10)
  • Automated Scans: 9.3/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Core6?

  • Seller: Core6
  • Year Founded: 2005
  • HQ Location: New York, US
  • Twitter: @Core6cyber
    444 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 53% Large, 26% Small

What Are Recent G2 Reviews of Core6?

What Are G2 Users Discussing About Core6?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated April 10, 2026