# Best Secure Code Review Software

## How Many Secure Code Review Software Products Does G2 Track?

**Total Products under this Category:** 68

### Category Stats (Aug 2026)

- **Average Rating:** 4.53/5 (↓0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Black Duck Coverity Static (+0.61%) - Among all products in this category, Black Duck Coverity Static recorded the largest rating increase compared to last month

_Last updated: August 04, 2026_

## How Does G2 Rank Secure Code Review Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 5,300+ Authentic Reviews
- 68+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Secure Code Review Software
 ![G2 Grid® for Secure Code Review Software plotting products by satisfaction and market presence](https://www.g2.com/categories/secure-code-review/grids.png?focus%5B%5D=1392&focus%5B%5D=1259627&focus%5B%5D=135113&focus%5B%5D=19003&focus%5B%5D=52233&focus%5B%5D=7775&focus%5B%5D=4475&focus%5B%5D=1312693)

Highlighted products: GitHub, Aikido Security, GitGuardian, GitLab, Microsoft Defender for Cloud, SonarQube, Checkmarx, and OX Security.

Underlying data: [Grid® JSON](https://www.g2.com/categories/secure-code-review/grids.json?focus%5B%5D=github&focus%5B%5D=aikido-security&focus%5B%5D=gitguardian&focus%5B%5D=gitlab&focus%5B%5D=microsoft-defender-for-cloud&focus%5B%5D=sonarqube&focus%5B%5D=checkmarx&focus%5B%5D=ox-security)

**Sponsored**

### OX Security

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=2639&secure%5Bchosen_at%5D=2026-08-04T18%3A03%3A49Z&secure%5Bdisplayable_resource_id%5D=2639&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=2639&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1312693&secure%5Bresource_id%5D=2639&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsecure-code-review&secure%5Btoken%5D=326857638ec4a185da7168f5513c7acfddaa666f584e7461f7db3357c246e17f&secure%5Burl%5D=https%3A%2F%2Fwww.ox.security%2Fbook-a-demo%2F&secure%5Burl_type%5D=custom_url)

### [GitHub](https://www.g2.com/products/github/reviews)

GitHub is where the world builds software. Millions of individuals, organizations and businesses around the world use GitHub to discover, share, and contribute software. Developers at startups to Fortune 50 companies use GitHub, every step of the way.

**Average Rating:** 4.7/5.0

**Total Reviews:** 2,329

#### How Do G2 Users Rate GitHub?

- **Quality of Support:** 8.7/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 8.9/10)
- **Ease of Setup:** 9.0/10 (Category avg: 8.7/10)

#### Who Is the Company Behind GitHub?

- **Seller:** [GitHub](https://www.g2.com/sellers/github)
- **Year Founded:** 2008
- **HQ Location:** San Francisco, CA
- **Twitter:** @github  
2,673,925 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c06a67fd698737e0e0058dd8a6726d5e9af42b7ce88417153ae8028eed3914af&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1418841%2F&secure%5Burl_type%5D=linkedin_company_website)  
6,106 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 47% Small, 31% Medium

#### What Do G2 Reviewers Say About GitHub?

_AI-generated summary from verified user reviews_

##### Pros

- Users value **exceptional collaboration and version control** features, making GitHub essential for code tracking and development.
- Users value the **ease of use** that GitHub offers, enhancing collaboration and version control effortlessly.
- Users value the **seamless team collaboration** on GitHub, enhancing project transparency and workflow automation effectively.
- Users value the **seamless collaboration** GitHub offers, enabling efficient teamwork and project transparency for developers.
- Users value the **seamless version control** in GitHub, enhancing collaboration and simplifying code management throughout projects.

##### Cons

- Users find the **learning curve and complexity** of advanced features like GitHub Actions challenging for newcomers.
- Users find the **learning curve steep** , facing challenges with complexity and configuration in GitHub Actions.
- Users find the **learning difficulty** of GitHub challenging, especially for beginners unfamiliar with Git workflows.
- Users find the **complexity for beginners** challenging, especially with CI/CD workflows and permission management in GitHub.
- Users find the **steep learning curve** of GitHub challenging, especially when configuring workflows and managing permissions.

#### What Are Recent G2 Reviews of GitHub?

**["Essential Version Control and Collaboration for Building CanniComply"](https://www.g2.com/survey_responses/github-review-13193636)**

**Rating:** 5.0/5.0 stars

_— Wayne D._

[Read full review](https://www.g2.com/survey_responses/github-review-13193636)

**["A One-Stop Hub for Code Collaboration and Automation"](https://www.g2.com/survey_responses/github-review-13168414)**

**Rating:** 5.0/5.0 stars

_— Tejas A._

[Read full review](https://www.g2.com/survey_responses/github-review-13168414)

#### What Are G2 Users Discussing About GitHub?

- [How is GitHub shaping the landscape of collaborative software development and version control?](https://www.g2.com/discussions/how-is-github-shaping-the-landscape-of-collaborative-software-development-and-version-control) - 4 comments
- [What is GitHub used for?](https://www.g2.com/discussions/what-is-github-used-for) - 8 comments, 5 upvotes
- [What does GitHub mean?](https://www.g2.com/discussions/what-does-github-mean) - 2 comments
- [Is GitHub a CASE tool?](https://www.g2.com/discussions/is-github-a-case-tool)
- [What can GitHub be used for?](https://www.g2.com/discussions/what-can-github-be-used-for) - 5 comments

### [Aikido Security](https://www.g2.com/products/aikido-security/reviews)

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

**Average Rating:** 4.6/5.0

**Total Reviews:** 255

#### How Do G2 Users Rate Aikido Security?

- **Quality of Support:** 9.2/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 8.9/10)
- **Ease of Setup:** 9.4/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Aikido Security?

- **Seller:** [Aikido Security](https://www.g2.com/sellers/aikido-security)
- **Company Website:** aikido.dev
- **Year Founded:** 2022
- **HQ Location:** Ghent, Belgium
- **Twitter:** @AikidoSecurity  
11,770 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=79406802efc597500b142b19f023ee80eb82879906d7e1e458900293346529a9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faikido-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
241 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Founder, CTO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 80% Small, 13% Medium

#### What Do G2 Reviewers Say About Aikido Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Aikido Security, benefiting from its clear, actionable insights and seamless integration.
- Users praise Aikido Security for its **fast and user-friendly identification of security issues** in codebases, enhancing development practices.
- Users appreciate the **robust features of Aikido Security** , valuing its usability and effectiveness in enhancing security workflows.
- Users value the **easy integrations** with GitLab, allowing for quick start and effective tracking of security issues.
- Users commend the **easy setup** of Aikido Security, simplifying integration and enhancing their security workflow significantly.

##### Cons

- Users note the **missing features** in Aikido Security, wishing for more integration and advanced configuration options.
- Users find the **pricing excessive** , particularly for startups, despite acknowledging the product's value.
- Users find Aikido Security has **limited features** , particularly in advanced customization and reporting for complex environments.
- Users find the **entry-level pricing** of Aikido Security too high for startups, limiting adoption and experimentation.
- Users are frustrated by the **lack of features** , especially with local scanning and branch handling limitations.

#### What Are Recent G2 Reviews of Aikido Security?

**["Enterprise Security Without an Enterprise Security Team"](https://www.g2.com/survey_responses/aikido-security-review-13108704)**

**Rating:** 4.0/5.0 stars

_— Ian M._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13108704)

**["Seamless GitHub Integration with Solid Security Findings and Smart False-Positive Analysis"](https://www.g2.com/survey_responses/aikido-security-review-13109689)**

**Rating:** 4.5/5.0 stars

_— Jordan B._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13109689)

### [GitGuardian](https://www.g2.com/products/gitguardian/reviews)

GitGuardian is an end-to-end Secrets and Non-Human Identity (NHI) Security platform designed to help organizations eliminate secrets sprawl, govern machine identities, and meet compliance requirements under PCI-DSS v4.0, DORA, NYDFS Part 500, and NIS 2. As attackers increasingly target NHIs like service accounts, service principals, AI agents, and applications, protecting the credentials they rely on has become critical. GitGuardian's platform is built on three pillars: Secrets Security, NHI Governance, and Developer Endpoint Protection. \*\*Secrets Security\*\* eliminates leaks across every environment. Internal Secrets Monitoring detects hardcoded credentials in source code, CI/CD pipelines, container images, and collaboration tools like Slack, Jira, and Confluence with 500+ purpose-built detectors and a false positive rate under 10%. Public Secrets Monitoring scans 1B+ public GitHub commits daily, alerting teams the moment a secret is exposed externally. Honeytokens deploy decoy credentials that trigger immediate alerts on unauthorized access attempts. \*\*NHI Governance\*\* provides a centralized inventory of machine identities, including those outside vaults, with ownership attribution, risk scoring, and compliance evidence to support access reviews and rotation policy configuration. \*\*Developer Endpoint Protection\*\* extends coverage to the credential layer that repo and CI scanning can't reach: developer laptops. GitGuardian scans project directories, .env files, cloud credential stores, AI agent configs, and shell history across the entire fleet, delivering a prioritized inventory of exposed secrets by machine and severity. Trusted by Snowflake, ING, BASF, Datadog, Webflow, Bouygues Telecom, and more, and the #1 most-installed security app on the GitHub Marketplace.

**Average Rating:** 4.8/5.0

**Total Reviews:** 276

#### How Do G2 Users Rate GitGuardian?

- **Quality of Support:** 9.2/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 9.0/10 (Category avg: 8.9/10)
- **Ease of Setup:** 9.4/10 (Category avg: 8.7/10)

#### Who Is the Company Behind GitGuardian?

- **Seller:** [GitGuardian](https://www.g2.com/sellers/gitguardian-c1eb71ef-0ed6-4024-9679-56d9bee1fe3e)
- **Company Website:** www.gitguardian.com
- **Year Founded:** 2017
- **HQ Location:** Paris, Île-de-France
- **Twitter:** @GitGuardian  
6,055 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=b48a5941635607325adaf34ffb75cb9880fc425470fce263cbaa5b1453bbb2b9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fgitguardian&secure%5Burl_type%5D=linkedin_company_website)  
182 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Software Developer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 84% Small, 12% Medium

#### What Do G2 Reviewers Say About GitGuardian?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **alert notifications** of GitGuardian, enabling instant updates on key leaks after code pushes.
- Users praise the **automated security features** of GitGuardian, ensuring seamless and proactive detection of secrets.
- Users love the **automated vulnerability detection** of GitGuardian, appreciating its swift and proactive monitoring of secrets.
- Users value the **accurate and fast detection** of GitGuardian, ensuring real-time alerts and precise incident management.
- Users commend GitGuardian for its **immediate detection speed** , offering quick alerts and actionable fixes during development.

##### Cons

- Users find that **false positives** can be cumbersome, requiring significant tuning and impacting user experience.
- Users find the **inefficient notifications** overwhelming, as alerts accumulate and false positives increase workflow complexity.
- Users find the **limited customization** options in GitGuardian a barrier for tailoring alerts and policies effectively.
- Users find the **interface confusing** , struggling with cluttered navigation and excessive alert filtering across multiple incidents.
- Users report **excessive notifications** from GitGuardian, leading to clutter and increased review time for incident management.

#### What Are Recent G2 Reviews of GitGuardian?

**["Seamless Workflow Integration with Fast, Reliable Secret Detection"](https://www.g2.com/survey_responses/gitguardian-review-13192254)**

**Rating:** 5.0/5.0 stars

_— Rohit P._

[Read full review](https://www.g2.com/survey_responses/gitguardian-review-13192254)

**["Proactive Secrets Detection That Fits Developers’ Workflow"](https://www.g2.com/survey_responses/gitguardian-review-13197898)**

**Rating:** 4.5/5.0 stars

_— Shemanti P._

[Read full review](https://www.g2.com/survey_responses/gitguardian-review-13197898)

#### What Are G2 Users Discussing About GitGuardian?

- [What is GitGuardian used for?](https://www.g2.com/discussions/what-is-gitguardian-used-for) - 1 comment, 2 upvotes

### [GitLab](https://www.g2.com/products/gitlab/reviews)

GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab, teams can create, deliver, and manage code quickly and continuously instead of managing disparate tools and scripts. GitLab helps your teams across the complete DevSecOps lifecycle, from developing, securing, and deploying software. What makes us truly different? - Flexibility: Consume as a service or manage your own deployment - Cloud-Agnostic: Deploy anywhere with no vendor lock-in - No rip and replace: Scale to a platform approach at your own pace

**Average Rating:** 4.5/5.0

**Total Reviews:** 884

#### How Do G2 Users Rate GitLab?

- **Quality of Support:** 8.5/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 8.8/10 (Category avg: 8.9/10)
- **Ease of Setup:** 8.7/10 (Category avg: 8.7/10)

#### Who Is the Company Behind GitLab?

- **Seller:** [GitLab Inc.](https://www.g2.com/sellers/gitlab-inc)
- **Company Website:** about.gitlab.com
- **Year Founded:** 2014
- **HQ Location:** San Francisco, California
- **Twitter:** @gitlab  
171,534 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a712a3bc9d0c8f9d0d986490c4b4786dfb8085e13a770fa4c99cd9d01137c372&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5101804%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,473 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 37% Medium, 37% Small

#### What Do G2 Reviewers Say About GitLab?

_AI-generated summary from verified user reviews_

##### Pros

- Users enjoy the **ease of use** of GitLab, thanks to its unified interface and streamlined CI/CD integrations.
- Users value the **all-in-one platform** of GitLab, which streamlines development processes and enhances team collaboration.
- Users praise GitLab for its **powerful CI/CD integration** , which simplifies automation and enhances pipeline efficiency.
- Users value GitLab's **s seamless integrations** allowing streamlined workflows without the need for multiple tools.
- Users value GitLab's **seamless CI/CD integration** , which simplifies automation and enhances overall development efficiency.

##### Cons

- Users find the **complexity** of GitLab's group structure and management challenging, particularly for newcomers and infrastructure.
- Users face a **difficult learning curve** with GitLab, especially for those unfamiliar with its unique structure and features.
- Users find the **confusing interface** of GitLab overwhelming, especially new users navigating its complex functionalities and settings.
- Users find the **complex user interface** of GitLab requires significant effort to master and is not always intuitive.
- Users find the **steep learning curve** of GitLab challenging, especially when adapting to its comprehensive features and UI.

#### What Are Recent G2 Reviews of GitLab?

**["GitLab’s All-in-One DevOps Platform with CI/CD and Security Scanning"](https://www.g2.com/survey_responses/gitlab-review-12864830)**

**Rating:** 5.0/5.0 stars

_— mani s._

[Read full review](https://www.g2.com/survey_responses/gitlab-review-12864830)

**["All-in-One DevOps Platform That Streamlines CI/CD and Collaboration"](https://www.g2.com/survey_responses/gitlab-review-12894467)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/gitlab-review-12894467)

#### What Are G2 Users Discussing About GitLab?

- [What is GitLab used for?](https://www.g2.com/discussions/what-is-gitlab-used-for) - 2 comments
- [Why GitLab is better than Jenkins?](https://www.g2.com/discussions/why-gitlab-is-better-than-jenkins) - 1 comment
- [Is GitLab paid?](https://www.g2.com/discussions/is-gitlab-paid) - 5 comments, 2 upvotes
- [Is GitLab free software?](https://www.g2.com/discussions/is-gitlab-free-software) - 4 comments, 1 upvote
- [What can GitLab do?](https://www.g2.com/discussions/what-can-gitlab-do) - 2 comments

### [Microsoft Defender for Cloud](https://www.g2.com/products/microsoft-defender-for-cloud/reviews)

Microsoft Defender for Cloud is a cloud native application protection platform for multicloud and hybrid environments with comprehensive security across the full lifecycle, from development to runtime.

**Average Rating:** 4.4/5.0

**Total Reviews:** 396

#### How Do G2 Users Rate Microsoft Defender for Cloud?

- **Quality of Support:** 8.5/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 8.9/10)
- **Ease of Setup:** 8.6/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Microsoft Defender for Cloud?

- **Seller:** [Microsoft](https://www.g2.com/sellers/microsoft)
- **Year Founded:** 1975
- **HQ Location:** Redmond, Washington
- **Twitter:** @microsoft  
13,091,739 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9458f51bd6ded48ad432a804f19ad736469f007787569b63827154231c315630&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmicrosoft%2F&secure%5Burl_type%5D=linkedin_company_website)  
231,632 employees on LinkedIn®
- **Ownership:** MSFT

#### Who Uses This Product?

- **Who Uses This:** Saas Consultant, Software Engineer
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 38% Medium, 35% Large

#### What Do G2 Reviewers Say About Microsoft Defender for Cloud?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **robust security features** of Microsoft Defender for Cloud, enhancing protection against cyber threats and vulnerabilities.
- Users value the **comprehensive security features** of Microsoft Defender for Cloud, effectively protecting against various cyber threats.
- Users appreciate the **robust security features** of Microsoft Defender for Cloud, enhancing their protection against cyber threats.
- Users appreciate the **security alerts** provided by Microsoft Defender for Cloud, enhancing their overall cloud security experience.
- Users value the **automated threat detection** of Microsoft Defender for Cloud, enhancing security and mitigating risks effectively.

##### Cons

- Users find Microsoft Defender for Cloud's setup **complex and difficult to understand** , requiring significant effort to configure effectively.
- Users acknowledge that Microsoft Defender for Cloud is **somewhat expensive** , particularly for small to medium businesses.
- Users experience **delayed detection** of threats, with occasional false positives affecting the reliability of Microsoft Defender for Cloud.
- Users experience **false positives** with Microsoft Defender for Cloud, leading to confusion over flagged legitimate files.
- Users note the need for **improvement in user experience** and quicker threat alerts to enhance usability.

#### What Are Recent G2 Reviews of Microsoft Defender for Cloud?

**["Seamless Azure Integration with Robust, Real-Time Threat Detection"](https://www.g2.com/survey_responses/microsoft-defender-for-cloud-review-13128844)**

**Rating:** 5.0/5.0 stars

_— Ahyar R._

[Read full review](https://www.g2.com/survey_responses/microsoft-defender-for-cloud-review-13128844)

**["All-in-One Security Visibility and Strong Threat Protection Across Hybrid and Multi-Cloud"](https://www.g2.com/survey_responses/microsoft-defender-for-cloud-review-13184116)**

**Rating:** 4.5/5.0 stars

_— DEEPAK M._

[Read full review](https://www.g2.com/survey_responses/microsoft-defender-for-cloud-review-13184116)

#### What Are G2 Users Discussing About Microsoft Defender for Cloud?

- [What is Microsoft Defender for Cloud used for?](https://www.g2.com/discussions/what-is-microsoft-defender-for-cloud-used-for) - 1 comment
- [What are the three security services provided by Windows Azure?](https://www.g2.com/discussions/what-are-the-three-security-services-provided-by-windows-azure) - 2 comments
- [What is Azure security management?](https://www.g2.com/discussions/what-is-azure-security-management) - 1 comment
- [Is Azure security Center a SIEM?](https://www.g2.com/discussions/is-azure-security-center-a-siem) - 1 comment, 1 upvote
- [How does Azure provide security?](https://www.g2.com/discussions/how-does-azure-provide-security)

### [SonarQube](https://www.g2.com/products/sonarqube/reviews)

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 152

#### How Do G2 Users Rate SonarQube?

- **Quality of Support:** 8.2/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 8.9/10)
- **Ease of Setup:** 8.1/10 (Category avg: 8.7/10)

#### Who Is the Company Behind SonarQube?

- **Seller:** [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)
- **Company Website:** www.sonarsource.com
- **Year Founded:** 2008
- **HQ Location:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** DevOps Engineer, Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 42% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Users value how SonarQube **efficiently flags code quality and security issues** , ensuring a clean and maintainable codebase.
- Users value the **issue filtering and prioritization features** of SonarQube, enhancing focus on high-priority tasks.
- Users value the **issue identification and prioritization** features of SonarQube, improving focus on critical tasks.
- Users find SonarQube's **ease of use** invaluable for maintaining code quality and integrating seamlessly into development workflows.
- Users appreciate the **easy integrations** with existing CI/CD tools, enhancing their development workflow seamlessly.

##### Cons

- Users face challenges with **software bugs** as SonarQube can consume excessive RAM and occasionally reports false positives.
- Users find SonarQube's configuration **complex** , especially for beginners, leading to difficulties and overwhelming warnings to manage.
- Users encounter **false positives** that complicate evaluations, though mitigation options exist through detailed analysis and rule customization.
- Users find that SonarQube's **complexity in configuration** and excessive warnings can hinder effective usage and efficiency.
- Users find the **complex setup** of SonarQube challenging, especially for beginners unfamiliar with the configuration process.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube: Easy Integration, Simple UI, and Solid Free Code Quality Scanning"](https://www.g2.com/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-12975264)

**["SonarQube Makes Code Quality Clear with Strong Quality Gates and CI/CD Integration"](https://www.g2.com/survey_responses/sonarqube-review-13142666)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-13142666)

#### What Are G2 Users Discussing About SonarQube?

- [What is SonarLint used for?](https://www.g2.com/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)

### [Checkmarx](https://www.g2.com/products/checkmarx/reviews)

Checkmarx is a type of application security solution designed to help organizations safeguard their software development processes while enhancing efficiency and reducing costs. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. With the increasing reliance on AI technologies and the rapid pace of software development, Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as AI SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

**Average Rating:** 4.2/5.0

**Total Reviews:** 44

#### How Do G2 Users Rate Checkmarx?

- **Quality of Support:** 8.3/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 8.9/10)
- **Ease of Setup:** 8.1/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Checkmarx?

- **Seller:** [Checkmarx](https://www.g2.com/sellers/checkmarx)
- **Company Website:** www.checkmarx.com
- **Year Founded:** 2006
- **HQ Location:** Paramus, NJ
- **Twitter:** @Checkmarx  
7,284 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=18f6741e77df71b112ecb3ec6620912d3a0f67666525358c0a4f3b1278b173df&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheckmarx&secure%5Burl_type%5D=linkedin_company_website)  
1,019 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 56% Large, 23% Medium

#### What Do G2 Reviewers Say About Checkmarx?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Checkmarx **easy to implement** , seamlessly integrating into existing repositories with a user-friendly interface.
- Users appreciate the **intuitive user interface** of Checkmarx, making security reviews simple and user-friendly.
- Users value the **accuracy of results** from Checkmarx, as it simplifies security reviews with detailed vulnerability insights.
- Users value the **automation testing capabilities** of Checkmarx, finding it easy to integrate and use effectively.
- Users praise the **exceptional customer support** at Checkmarx, ensuring prompt assistance for any unresolved issues.

##### Cons

- Users face a high number of **false positives** in Checkmarx when working with Kotlin projects, affecting accuracy and reliability.
- Users report **lacking feature support** for Kotlin, leading to numerous false positives not seen in Java or JavaScript.
- Users experience **missing features** in Checkmarx, specifically regarding poor support for Kotlin that leads to false positives.
- Users find the **poor navigation** in Checkmarx frustrating, as the dashboard layout and display need enhancement.

#### What Are Recent G2 Reviews of Checkmarx?

**["Centralized Source Code Security with Seamless CI/CD Integration"](https://www.g2.com/survey_responses/checkmarx-review-12980590)**

**Rating:** 5.0/5.0 stars

_— Aman M._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12980590)

**["Checkmarx: Reliable SAST Solution for Strengthening Application Security"](https://www.g2.com/survey_responses/checkmarx-review-13085824)**

**Rating:** 4.0/5.0 stars

_— Naushad T._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-13085824)

#### What Are G2 Users Discussing About Checkmarx?

- [What is Checkmarx used for?](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for) - 1 comment, 1 upvote
- [How much does Checkmarx cost?](https://www.g2.com/discussions/how-much-does-checkmarx-cost)
- [Which testing method does Checkmarx support?](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support) - 1 comment
- [Does Checkmarx support DAST?](https://www.g2.com/discussions/does-checkmarx-support-dast) - 1 comment
- [What is Checkmarx used for?](https://www.g2.com/discussions/what-is-checkmarx-used-for) - 2 comments

### [OX Security](https://www.g2.com/products/ox-security/reviews)

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

**Average Rating:** 4.8/5.0

**Total Reviews:** 51

#### How Do G2 Users Rate OX Security?

- **Quality of Support:** 9.6/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 8.9/10)
- **Ease of Setup:** 9.0/10 (Category avg: 8.7/10)

#### Who Is the Company Behind OX Security?

- **Seller:** [OX Security](https://www.g2.com/sellers/ox-security)
- **Year Founded:** 2021
- **HQ Location:** New York, USA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ee8e1fc166aedd5d2f8edd57605f86ae8eec3007f5eee8810871f0e4645b4f4d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fox-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
199 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer
- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 63% Medium, 25% Large

#### What Do G2 Reviewers Say About OX Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **intuitive dashboard and seamless integration** of OX Security, enhancing their security management and workflow efficiency.
- Users value the **seamless collaboration** enabled by OX Security, enhancing their focus on critical development tasks.
- Users commend the **responsive customer support** of OX Security, enhancing their overall operational efficiency and satisfaction.
- Users value the **seamless integrations** with existing tools, enhancing workflows and boosting overall development efficiency.
- Users appreciate the **speed** of OX Security, enabling faster remediation of vulnerabilities and cloud misconfigurations.

##### Cons

- Users find the **complexity** of OX Security daunting, facing a steep learning curve and inadequate documentation.
- Users find the **interface overwhelming** , with a steep learning curve and insufficient documentation to guide new users.
- Users find the **complex setup** challenging, especially due to inadequate documentation and overwhelming UI for new users.
- Users find the **executive dashboard limiting** , impacting effective reporting on product security enhancements to management.
- Users find OX Security's **difficult learning curve** challenging, particularly due to its complex interface and lacking documentation.

#### What Are Recent G2 Reviews of OX Security?

**["Holistic Security Solution with Seamless Integration"](https://www.g2.com/survey_responses/ox-security-review-10487561)**

**Rating:** 4.5/5.0 stars

_— Sharon S._

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10487561)

**["A powerful and comprehensive tool that meets most best practices for web app security testing"](https://www.g2.com/survey_responses/ox-security-review-10961361)**

**Rating:** 4.5/5.0 stars

_— Verified User in Gambling & Casinos_

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10961361)

### [Semgrep](https://www.g2.com/products/semgrep/reviews)

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

**Average Rating:** 4.6/5.0

**Total Reviews:** 56

#### How Do G2 Users Rate Semgrep?

- **Quality of Support:** 8.8/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 8.9/10)
- **Ease of Setup:** 9.4/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Semgrep?

- **Seller:** [Semgrep](https://www.g2.com/sellers/semgrep)
- **Company Website:** semgrep.dev
- **Year Founded:** 2017
- **HQ Location:** San Francisco, US
- **Twitter:** @semgrep  
4,433 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=968a71f2060531e986a3873882c34b492bee4d8d264ff88e0089e53b8f7771f4&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freturntocorp&secure%5Burl_type%5D=linkedin_company_website)  
262 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 45% Large, 43% Medium

#### What Do G2 Reviewers Say About Semgrep?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Semgrep, praising its intuitive syntax and smooth CI/CD integration.
- Users appreciate the **intuitive pattern-matching syntax** of Semgrep, enabling effective custom rules for various programming languages.
- Users appreciate Semgrep's **effective vulnerability detection** , enabling quick identification of security issues with low false positives.
- Users value the **scanning efficiency** of Semgrep, benefiting from rapid scans and seamless CI/CD integration.
- Users appreciate the **robust security features** of Semgrep, enabling effective identification and remediation of vulnerabilities effortlessly.

##### Cons

- Users find Semgrep **not user-friendly** , citing a steep learning curve and challenges in initial setup and customization.
- Users note the **limited features** of Semgrep, making categorization and comprehensive analysis more challenging.
- Users find the **difficult learning** curve for custom rules in Semgrep challenging, impacting new user experiences and efficiency.
- Users face a **lack of guidance** in mastering rule creation and initial setup, impacting effective tool utilization.
- Users find the **learning curve steep** for rule writing, especially for those new to static analysis tools.

#### What Are Recent G2 Reviews of Semgrep?

**["Streamlined Code Security with Semgrep"](https://www.g2.com/survey_responses/semgrep-review-11971635)**

**Rating:** 5.0/5.0 stars

_— Shreekanth k._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-11971635)

**["Fast, Easy-to-Customize Rules That Catch Security and Code-Quality Issues Early"](https://www.g2.com/survey_responses/semgrep-review-13079252)**

**Rating:** 4.5/5.0 stars

_— Milan K._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-13079252)

### [Qodo](https://www.g2.com/products/qodo/reviews)

Qodo is the AI Code Quality and Governance Platform that helps engineering teams maintain code quality as AI accelerates coding velocity. Qodo works across IDEs and Git platforms to catch bugs earlier, enforce standards automatically, and scale review to match faster coding output. Qodo combines deep codebase understanding with a self-learning rules system and multi-agent review to validate code logic, detect architectural drift, surface security issues, and enforce standards before merge. Qodo goes beyond pattern matching or static AI reviews by combining full codebase context, PR memory, and your rules to deliver high-signal feedback that aligns with your project's unique architecture and standards. Key capabilities include agentic pull request review with context-enriched code suggestions, local code review in your IDE, custom rules enforcement, and multi-repo codebase indexing.

**Average Rating:** 4.6/5.0

**Total Reviews:** 92

#### How Do G2 Users Rate Qodo?

- **Quality of Support:** 8.7/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 8.9/10)
- **Ease of Setup:** 9.2/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Qodo?

- **Seller:** [CodiumAI](https://www.g2.com/sellers/codiumai)
- **Company Website:** www.codium.ai
- **Year Founded:** 2022
- **HQ Location:** Tel Aviv, IL
- **Twitter:** @CodiumAI  
109 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ac2f2f61987a9648c5b1c231a4b5f8e4c22a14c216c42587faf0ef49bba53b4d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcodiumai%2F&secure%5Burl_type%5D=linkedin_company_website)  
134 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 53% Small, 27% Medium

#### What Do G2 Reviewers Say About Qodo?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Qodo incredibly **easy to use** , with seamless integration into Visual Studio Code right from the start.
- Users value the **time-saving features** of Qodo, enhancing productivity and improving code quality during development.
- Users appreciate the **context-aware functionality** of Qodo, enhancing productivity with tailored suggestions and easy integration.
- Users value the **robust functionality** of Qodo, especially for its automated testing and intelligent code suggestions.
- Users highlight the **automation capabilities** of Qodo, enhancing productivity with effortless test generation and code suggestions.

##### Cons

- Users face **testing issues** with Qodo, including inaccurate suggestions and unit tests that often require repeated attempts to function.
- Users report **bug issues** in Qodo, with occasional inaccuracies and context misunderstandings affecting overall performance.
- Users note a **steep learning curve** for Qodo, requiring tutorials and time to become proficient with the features.
- Users experience **slow performance** with Qodo, noting delays in code suggestions and challenges with excessive test recommendations.
- Users find that Qodo can sometimes struggle with **complex coding tasks** , which can hinder their overall experience.

#### What Are Recent G2 Reviews of Qodo?

**["AI-Powered Code Reviews That Actually Improve Development"](https://www.g2.com/survey_responses/qodo-review-13194306)**

**Rating:** 4.0/5.0 stars

_— Jeni J._

[Read full review](https://www.g2.com/survey_responses/qodo-review-13194306)

**["All-in-One AI Coding, Review, and Testing That Fits Seamlessly into Your Workflow"](https://www.g2.com/survey_responses/qodo-review-13202262)**

**Rating:** 4.5/5.0 stars

_— Subhashree S._

[Read full review](https://www.g2.com/survey_responses/qodo-review-13202262)

### [DryRun Security](https://www.g2.com/products/dryrun-security/reviews)

Security leaders face a paradox: ship faster and enable agentic development while staying secure and keeping developers productive. DryRun Security resolves this by securing every pull request and repo with a high-precision, automated security engineer review right where developers and their agents build. DryRun Security is the industry’s most accurate agentic code security intelligence platform. Powered by its proprietary Contextual Security Analysis (CSA) engine, DryRun Security delivers the AI moment for security teams in an AI-native developer world. Traditional static application security testing (SAST) floods teams with alerts, misses higher-order risk, and burns time in triage. DryRun Security goes beyond SAST with contextual analysis that prioritizes what is exploitable and impactful in your codebase, then helps engineers remediate fast. Instead of “find everything and hope someone sorts it out,” DryRun Security delivers code security intelligence that is ready to act on. DryRun Security puts a security engineer directly into developer workflows. In pull requests, the Code Review Agent reviews changes in context, explains risk in plain language, and guides fixes where developers already work. In repos, the DeepScan Agent produces focused, human-grade findings for the issues that actually matter, without weeks of manual review before major milestones. The Custom Policy Agent enforces guardrails with Natural Language Code Policies, so you can standardize security and compliance requirements across teams without brittle rule sets. Codebase Insights allows leaders to ask questions of their entire codebase like "Are we exposed to this new vulnerability" and have confidence in minutes. DryRun Security also integrates with AI coding workflows, so remediation happens with the precision of a security engineer working at machine speed. Teams connect DryRun Security insights and guidance into Claude, Cursor, OpenAI Codex, and Windsurf, helping developers and their agents fix issues with contextual, security-engineered direction tied to the PR and codebase. What DryRun Security delivers (beyond SAST) • Automated secure code review in every pull request with high-signal findings and low noise • Contextual Security Analysis that catches common vulnerabilities and deeper multi-dependency and logic risks • Automated remediation guidance that helps engineers fix faster, with explanations and next steps • Secrets analysis identifies genuine hardcoded secrets and suppresses the usual false alarms • Policy enforcement in PRs using Natural Language Code Policies for consistent guardrails across repos • Codebase intelligence and reporting for AppSec visibility, prioritization, and audit-ready evidence DryRun Security supports most code environments, languages, and frameworks, including: • GitHub, GitLab • C#, Golang, Elixir, JavaScript, TypeScript, Python, Ruby, Java, Kotlin, PHP, Swift, HTML • Infrastructure as Code (Terraform, YAML) • And more

**Average Rating:** 4.9/5.0

**Total Reviews:** 20

#### How Do G2 Users Rate DryRun Security?

- **Quality of Support:** 10.0/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 8.9/10)
- **Ease of Setup:** 10.0/10 (Category avg: 8.7/10)

#### Who Is the Company Behind DryRun Security?

- **Seller:** [DryRun Security](https://www.g2.com/sellers/dryrun-security)
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6a05a774e1320fb12547e26ce7fe95d94335bc0c4be6317172500089b5b6db36&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdryrun-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
16 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 40% Small, 30% Medium

#### What Do G2 Reviewers Say About DryRun Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **context-aware security feedback** from DryRun Security, enhancing vulnerability mitigation during development in GitHub.
- Users appreciate the **quick and context-aware vulnerability detection** of DryRun Security, enhancing security during the development process.
- Users value the **seamless integration and advanced detections** of DryRun Security, enhancing code security and development efficiency.
- Users value the **accuracy of feedback** from DryRun Security, effectively minimizing false positives and identifying complex vulnerabilities.
- Users appreciate the **easy setup** of DryRun Security, enabling seamless integration and quick vulnerability detection.

##### Cons

- Users find the **slow performance** of DryRun Security's management portal frustrating, impacting their overall experience.
- Users experience **slow speed** issues with the management portal, impacting overall usability and efficiency.
- Users note the **sluggish UI** of DryRun Security, which hampers the overall developer experience during use.
- Users feel there are **limited customization options** for analyzers, though improvements may be forthcoming.
- Users feel that there are **workflow issues** that hinder the developer experience and adoption of DryRun Security.

#### What Are Recent G2 Reviews of DryRun Security?

**["Catches Logic and Authorization Flaws Traditional SAST Often Misses"](https://www.g2.com/survey_responses/dryrun-security-review-12357188)**

**Rating:** 5.0/5.0 stars

_— Jabez A._

[Read full review](https://www.g2.com/survey_responses/dryrun-security-review-12357188)

**["Next Gen of SAST Tool That Has Cutting Edge Tech"](https://www.g2.com/survey_responses/dryrun-security-review-12462338)**

**Rating:** 5.0/5.0 stars

_— Francis D._

[Read full review](https://www.g2.com/survey_responses/dryrun-security-review-12462338)

### [Assembla](https://www.g2.com/products/assembla/reviews)

Assembla is the only managed cloud hosting provider for Perforce (Helix Core) and SVN, with project management built in. We provision, manage, and support your entire version control infrastructure so your team never has to touch a server. Teams running Perforce or SVN in the cloud come to Assembla because we are the only provider that handles everything: dedicated instances, automated backups, failovers, SOC 2 and GDPR compliance, and 24/5 DevOps support. No self-managed infrastructure. No custom integrations. No DevOps overhead. Perforce Cloud delivers managed Helix Core hosting on a shared, high-performance cloud environment with monthly licensing and the Perforce license included. Perforce Enterprise Cloud gives larger teams a dedicated single-tenant instance with custom architecture and unlimited users and storage. SVN Cloud Hosting brings the same managed approach to Subversion, with modern collaboration features like merge requests, locking, and code search that most SVN providers do not offer. More than 5,500 development teams worldwide trust Assembla to keep their most critical code available, secure, and compliant.

**Average Rating:** 4.2/5.0

**Total Reviews:** 146

#### How Do G2 Users Rate Assembla?

- **Quality of Support:** 8.4/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 8.9/10)
- **Ease of Setup:** 8.8/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Assembla?

- **Seller:** [Assembla](https://www.g2.com/sellers/assembla)
- **Year Founded:** 2005
- **HQ Location:** San Antonio, TX
- **Twitter:** @assembla  
3,818 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=b6715b540786561e0b3220c3f4c9faf8ef3b12ec94da5b694a830766d4c87f7d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F339775%2F&secure%5Burl_type%5D=linkedin_company_website)  
20 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Product Manager
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 51% Small, 40% Medium

#### What Are Recent G2 Reviews of Assembla?

**["Assembla Keeps Code, Tickets, and Projects Together—Reliable and Secure"](https://www.g2.com/survey_responses/assembla-review-12973341)**

**Rating:** 5.0/5.0 stars

_— Raj V._

[Read full review](https://www.g2.com/survey_responses/assembla-review-12973341)

**["Rock-Solid Ticket Tracking and Git Repos with Assembla"](https://www.g2.com/survey_responses/assembla-review-13104952)**

**Rating:** 4.5/5.0 stars

_— Johnny P._

[Read full review](https://www.g2.com/survey_responses/assembla-review-13104952)

#### What Are G2 Users Discussing About Assembla?

- [What is Assembla used for?](https://www.g2.com/discussions/what-is-assembla-used-for)

### [Jit](https://www.g2.com/products/jit/reviews)

Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empowers organizations to proactively manage security risks across the entire software development lifecycle.​ AI-Powered Agents Jit's AI Agents, such as SERA (Security Evaluation and Remediation Agent) and COTA (Communication, Ops, and Ticketing Agent), collaborate with your teams to automate vulnerability triage, risk assessment, and remediation processes, significantly reducing manual workloads. ​ Comprehensive Security Scanning Achieve full-stack security coverage with integrated scanners for SAST, DAST, SCA, IaC, CSPM, and more. Jit's platform ensures continuous monitoring and immediate feedback on code changes, facilitating rapid identification and resolution of security issues. ​ Developer-Centric Experience With integrations into popular IDEs and CI/CD pipelines, Jit provides developers with contextual security insights directly within their workflows, promoting a shift-left approach without disrupting productivity. ​ Agentic AI for AppSec Teams Risk-Based Prioritization Utilizing the Model Context Protocol (MCP), Jit evaluates vulnerabilities in the context of runtime environments, business impact, and compliance requirements, enabling teams to focus on the most critical risks. ​ Seamless Integrations Jit integrates with a wide array of tools, including GitHub, GitLab, AWS, Azure, GCP, Jira, Slack, and more, ensuring that security processes are embedded within your existing technology stack. ​

**Average Rating:** 4.5/5.0

**Total Reviews:** 43

#### How Do G2 Users Rate Jit?

- **Quality of Support:** 9.3/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 8.9/10)
- **Ease of Setup:** 9.2/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Jit?

- **Seller:** [jit](https://www.g2.com/sellers/jit)
- **Year Founded:** 2021
- **HQ Location:** Boston, MA
- **Twitter:** @jit\_io  
522 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c12301146938a4e9885aeef608ceac690a4eb5c023d31e5d2df099a15cbff3c7&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fjit%2F&secure%5Burl_type%5D=linkedin_company_website)  
150 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Financial Services
- **Company Size:** 44% Medium, 42% Small

#### What Do G2 Reviewers Say About Jit?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **seamless integration of security into development workflows** , highlighting efficiency and centralized management.
- Users find Jit to be **very easy to use** , streamlining integration of security into development workflows effectively.
- Users love the **easy integrations** of Jit, streamlining security within their development workflows effortlessly.
- Users appreciate the **efficiency** of Jit, which reduces waste and streamlines processes, enhancing overall productivity.
- Users value the **automation of security controls** in Jit, streamlining workflows and enhancing efficiency in development processes.

##### Cons

- Users face **integration issues** with Jit, particularly in enterprise environments and with certain CI tools requiring extra setup.
- Users find the **limited features** of Jit restrict complex setups and hinder comprehensive analytics and reporting.
- Users feel the **limited integration** with enterprise environments restricts Jit's full potential and usability.
- Users find the **documentation lacking** , particularly for advanced configurations, impacting their overall experience with Jit.
- Users find the **complexity** of Jit challenging, particularly with advanced integrations and configuration for newcomers.

#### What Are Recent G2 Reviews of Jit?

**["Helpful Tool for Integrating Security in Mobile App Development"](https://www.g2.com/survey_responses/jit-review-11750234)**

**Rating:** 4.0/5.0 stars

_— Ali A._

[Read full review](https://www.g2.com/survey_responses/jit-review-11750234)

**["Exploring jit a personal review"](https://www.g2.com/survey_responses/jit-review-11751139)**

**Rating:** 4.0/5.0 stars

_— Mohamed A._

[Read full review](https://www.g2.com/survey_responses/jit-review-11751139)

### [Black Duck Coverity Static](https://www.g2.com/products/black-duck-coverity-static/reviews)

Coverity® is a fast, accurate, and highly scalable static analysis (SAST) solution that helps development and security teams address security and quality defects early in the software development life cycle (SDLC), track and manage risks across the application portfolio, and ensure compliance with security and coding standards.

**Average Rating:** 4.3/5.0

**Total Reviews:** 65

#### How Do G2 Users Rate Black Duck Coverity Static?

- **Quality of Support:** 8.6/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 8.9/10)
- **Ease of Setup:** 8.3/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Black Duck Coverity Static?

- **Seller:** [Black Duck](https://www.g2.com/sellers/black-duck)
- **Year Founded:** 2024
- **HQ Location:** Burlington, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ca66ef383f133f101804712b9ed7a89aec2633a8efa048bd261db3b92eb47e73&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fblack-duck-software&secure%5Burl_type%5D=linkedin_company_website)  
1,345 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 55% Large, 34% Medium

#### What Are Recent G2 Reviews of Black Duck Coverity Static?

**["Effective Static Code Analysis with Great Integration, but Outdated UI"](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10763088)**

**Rating:** 5.0/5.0 stars

_— Lokesh T._

[Read full review](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10763088)

**["A decent security software for any organization which is lighweight and useful also."](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10522202)**

**Rating:** 4.5/5.0 stars

_— Ambrish M._

[Read full review](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10522202)

#### What Are G2 Users Discussing About Black Duck Coverity Static?

- [What is Coverity used for?](https://www.g2.com/discussions/what-is-coverity-used-for)
- [What is coverity connect?](https://www.g2.com/discussions/what-is-coverity-connect)
- [How does Coverity Static Analysis work?](https://www.g2.com/discussions/how-does-coverity-static-analysis-work)
- [What is Coverity report?](https://www.g2.com/discussions/what-is-coverity-report)
- [What is Coverity software?](https://www.g2.com/discussions/what-is-coverity-software)

### [Kiuwan Code Security & Insights](https://www.g2.com/products/kiuwan-code-security-insights/reviews)

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

**Average Rating:** 4.5/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate Kiuwan Code Security & Insights?

- **Quality of Support:** 8.9/10 (Category avg: 9.2/10)
- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 8.9/10)
- **Ease of Setup:** 9.0/10 (Category avg: 8.7/10)

#### Who Is the Company Behind Kiuwan Code Security & Insights?

- **Seller:** [Sembi](https://www.g2.com/sellers/sembi)
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7ed5860a727a31b32edfba64808a6ea32fccad50d052e993a08b626d675d5c69&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsembi-inc%2F&secure%5Burl_type%5D=linkedin_company_website)  
94 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Banking
- **Company Size:** 41% Large, 35% Medium

#### What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **accuracy** of Kiuwan's code scans, ensuring reliable results and satisfaction with reporting capabilities.
- Users value the **accuracy of findings** from Kiuwan Code Security & Insights, enhancing their confidence in code security.
- Users appreciate the **efficient customer support** of Kiuwan, enhancing their overall experience and satisfaction with the product.
- Users value the **user-friendly interface** of Kiuwan, enhancing their experience with efficient code scans and reporting.
- Users appreciate the **user-friendly interface** of Kiuwan Code Security & Insights, making dashboard navigation easy and efficient.

#### What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

**["Impeccable Security and Code Analysis, with Potential for Improvement in Customization"](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)**

**Rating:** 5.0/5.0 stars

_— Abelardo I._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)

**["Elevated our software security to the next level. Improved our code quality."](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)**

**Rating:** 5.0/5.0 stars

_— Abdullah Enes K._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/secure-code-review?order=g2_score&page=2#product-list)
- [3](/categories/secure-code-review?order=g2_score&page=3#product-list)
- [4](/categories/secure-code-review?order=g2_score&page=4#product-list)
- [5](/categories/secure-code-review?order=g2_score&page=5#product-list)
- [Next &rsaquo;Next ›](/categories/secure-code-review?order=g2_score&page=2#product-list)

Spotlight Categories

[Product Lifecycle Management (PLM) Software](https://www.g2.com/categories/product-lifecycle-management-plm)

[Lead Intelligence Software](https://www.g2.com/categories/lead-intelligence)

[Social Media Management Tools](https://www.g2.com/categories/social-media-mgmt)

[Expense Management Software](https://www.g2.com/categories/expense-management)

[Experience Management Software](https://www.g2.com/categories/experience-management)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)

- [Log Analysis](/categories/log-analysis)
- [Penetration Testing](/categories/penetration-testing-tools)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Secure Code Review Themes](/categories/secure-code-review/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated October 3, 2024

Secure code review software enables either automated or manual code examination to seek out vulnerabilities and security risks. These solutions are similar to [peer code review software](https://www.g2.com/categories/peer-code-review), but they are specifically focused on ensuring security best practices as opposed to general coding best practices, and some solutions execute automated code review rather than enabling peer review. Manual secure code review software allows multiple developers to view and comment on changes to code so that the code’s author can remediate any security issues. Automated secure code review software takes the place of a human peer, scanning for noncompliant code and leaving remediation suggestions for the author.

This software helps DevSecOps teams to shift the onus of secure software onto developers, allowing teams to remediate security issues earlier in the continuous delivery process. In doing so, teams can better achieve secure code as the default, rather than risk deploying vulnerable software.

To qualify for inclusion in the Secure Code Review category, a product must:

- Scan an author’s code or allow other developers to view it
- Automatically leave comments on specific code, or allow other developers to do the same
- Explicitly focus on code security
- Send messages when requests for code review happen or code review comments are submitted

Show More