# Best Static Application Security Testing (SAST) Software

## How Many Static Application Security Testing (SAST) Software Products Does G2 Track?

**Total Products under this Category:** 110

### Category Stats (Jul 2026)

- **Average Rating:** 4.53/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Finite State (+1.29%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month

_Last updated: July 29, 2026_

## How Does G2 Rank Static Application Security Testing (SAST) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 5,400+ Authentic Reviews
- 110+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Static Application Security Testing (SAST) Software
 ![G2 Grid® for Static Application Security Testing (SAST) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/static-application-security-testing-sast/grids.png?focus%5B%5D=1259627&focus%5B%5D=1392&focus%5B%5D=135113&focus%5B%5D=19003&focus%5B%5D=7775&focus%5B%5D=1225549&focus%5B%5D=36094&focus%5B%5D=1312693)

Highlighted products: Aikido Security, GitHub, GitGuardian, GitLab, SonarQube, Semgrep, Snyk, and OX Security.

Underlying data: [Grid® JSON](https://www.g2.com/categories/static-application-security-testing-sast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=github&focus%5B%5D=gitguardian&focus%5B%5D=gitlab&focus%5B%5D=sonarqube&focus%5B%5D=semgrep&focus%5B%5D=snyk&focus%5B%5D=ox-security)

**Sponsored**

### Endor Labs

Endor Labs turns application security into a competitive advantage. At the core is AURI, the security harness for agentic development. It helps coding agents write secure code by default, automates PR security reviews, and gives agents deterministic context to fix what matters fast. At the core is our patented code context graph: a continuously updated model of application behavior across code, dependencies, secrets, and containers. The result: 83% fewer blocked PRs, 10x fewer security tickets, and 6x faster remediation at Atlassian, Cursor, Rubrik, and Snowflake.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=paid_promo&secure%5Bad_slot%5D=category_product_list&secure%5Bcategory_id%5D=1520&secure%5Bchosen_at%5D=2026-07-29T15%3A18%3A00Z&secure%5Bmedium%5D=sponsored&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1317430&secure%5Bresource_id%5D=1520&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fstatic-application-security-testing-sast%3Fopen_modal_url%3D%252Fproducts%252Fguardrails-guardrails%252Fwishlists%253Fhost_path%253D%25252Fcategories%25252Fstatic-application-security-testing-sast%2526source%253Dcategory&secure%5Btoken%5D=e0624b1ab7164c2afc300706ab78c3fda4a63a8bdae1ddb6a6d2f491a288f56d&secure%5Burl%5D=https%3A%2F%2Fwww.endorlabs.com%2Fplatform&secure%5Burl_type%5D=paid_promos)

### [Aikido Security](https://www.g2.com/products/aikido-security/reviews)

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

**Average Rating:** 4.6/5.0

**Total Reviews:** 250

#### How Do G2 Users Rate Aikido Security?

- **Test Automation:** 8.6/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.1/10)
- **Quality of Support:** 9.2/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 8.1/10 (Category avg: 8.3/10)

#### Who Is the Company Behind Aikido Security?

- **Seller:** [Aikido Security](https://www.g2.com/sellers/aikido-security)
- **Company Website:** aikido.dev
- **Year Founded:** 2022
- **HQ Location:** Ghent, Belgium
- **Twitter:** @AikidoSecurity  
11,770 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=79406802efc597500b142b19f023ee80eb82879906d7e1e458900293346529a9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faikido-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
241 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Founder, CTO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 80% Small, 13% Medium

#### What Do G2 Reviewers Say About Aikido Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Aikido Security, benefiting from its clear, actionable insights and seamless integration.
- Users praise Aikido Security for its **fast and user-friendly identification of security issues** in codebases, enhancing development practices.
- Users appreciate the **robust features of Aikido Security** , valuing its usability and effectiveness in enhancing security workflows.
- Users value the **easy integrations** with GitLab, allowing for quick start and effective tracking of security issues.
- Users commend the **easy setup** of Aikido Security, simplifying integration and enhancing their security workflow significantly.

##### Cons

- Users note the **missing features** in Aikido Security, wishing for more integration and advanced configuration options.
- Users find the **pricing excessive** , particularly for startups, despite acknowledging the product's value.
- Users find Aikido Security has **limited features** , particularly in advanced customization and reporting for complex environments.
- Users find the **entry-level pricing** of Aikido Security too high for startups, limiting adoption and experimentation.
- Users are frustrated by the **lack of features** , especially with local scanning and branch handling limitations.

#### What Are Recent G2 Reviews of Aikido Security?

**["Seamless GitHub Integration with Solid Security Findings and Smart False-Positive Analysis"](https://www.g2.com/survey_responses/aikido-security-review-13109689)**

**Rating:** 4.5/5.0 stars

_— Jordan B._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13109689)

**["Enterprise Security Without an Enterprise Security Team"](https://www.g2.com/survey_responses/aikido-security-review-13108704)**

**Rating:** 4.0/5.0 stars

_— Ian M._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13108704)

### [GitHub](https://www.g2.com/products/github/reviews)

GitHub is where the world builds software. Millions of individuals, organizations and businesses around the world use GitHub to discover, share, and contribute software. Developers at startups to Fortune 50 companies use GitHub, every step of the way.

**Average Rating:** 4.7/5.0

**Total Reviews:** 2,323

#### How Do G2 Users Rate GitHub?

- **Test Automation:** 8.5/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 9.1/10)
- **Quality of Support:** 8.7/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 8.3/10 (Category avg: 8.3/10)

#### Who Is the Company Behind GitHub?

- **Seller:** [GitHub](https://www.g2.com/sellers/github)
- **Year Founded:** 2008
- **HQ Location:** San Francisco, CA
- **Twitter:** @github  
2,673,925 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c06a67fd698737e0e0058dd8a6726d5e9af42b7ce88417153ae8028eed3914af&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1418841%2F&secure%5Burl_type%5D=linkedin_company_website)  
6,106 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 47% Small, 31% Medium

#### What Do G2 Reviewers Say About GitHub?

_AI-generated summary from verified user reviews_

##### Pros

- Users value **exceptional collaboration and version control** features, making GitHub essential for code tracking and development.
- Users value the **ease of use** that GitHub offers, enhancing collaboration and version control effortlessly.
- Users value the **seamless team collaboration** on GitHub, enhancing project transparency and workflow automation effectively.
- Users value the **seamless collaboration** GitHub offers, enabling efficient teamwork and project transparency for developers.
- Users value the **seamless version control** in GitHub, enhancing collaboration and simplifying code management throughout projects.

##### Cons

- Users find the **learning curve and complexity** of advanced features like GitHub Actions challenging for newcomers.
- Users find the **learning curve steep** , facing challenges with complexity and configuration in GitHub Actions.
- Users find the **learning difficulty** of GitHub challenging, especially for beginners unfamiliar with Git workflows.
- Users find the **complexity for beginners** challenging, especially with CI/CD workflows and permission management in GitHub.
- Users find the **steep learning curve** of GitHub challenging, especially when configuring workflows and managing permissions.

#### What Are Recent G2 Reviews of GitHub?

**["Great Developer Platform with Helpful AI Features"](https://www.g2.com/survey_responses/github-review-13164989)**

**Rating:** 4.5/5.0 stars

_— SNEHA S._

[Read full review](https://www.g2.com/survey_responses/github-review-13164989)

**["A One-Stop Hub for Code Collaboration and Automation"](https://www.g2.com/survey_responses/github-review-13168414)**

**Rating:** 5.0/5.0 stars

_— Tejas A._

[Read full review](https://www.g2.com/survey_responses/github-review-13168414)

#### What Are G2 Users Discussing About GitHub?

- [How is GitHub shaping the landscape of collaborative software development and version control?](https://www.g2.com/discussions/how-is-github-shaping-the-landscape-of-collaborative-software-development-and-version-control) - 4 comments
- [What is GitHub used for?](https://www.g2.com/discussions/what-is-github-used-for) - 8 comments, 5 upvotes
- [What does GitHub mean?](https://www.g2.com/discussions/what-does-github-mean) - 2 comments
- [Is GitHub a CASE tool?](https://www.g2.com/discussions/is-github-a-case-tool)
- [What can GitHub be used for?](https://www.g2.com/discussions/what-can-github-be-used-for) - 5 comments

### [GitGuardian](https://www.g2.com/products/gitguardian/reviews)

GitGuardian is an end-to-end Secrets and Non-Human Identity (NHI) Security platform designed to help organizations eliminate secrets sprawl, govern machine identities, and meet compliance requirements under PCI-DSS v4.0, DORA, NYDFS Part 500, and NIS 2. As attackers increasingly target NHIs like service accounts, service principals, AI agents, and applications, protecting the credentials they rely on has become critical. GitGuardian's platform is built on three pillars: Secrets Security, NHI Governance, and Developer Endpoint Protection. \*\*Secrets Security\*\* eliminates leaks across every environment. Internal Secrets Monitoring detects hardcoded credentials in source code, CI/CD pipelines, container images, and collaboration tools like Slack, Jira, and Confluence with 500+ purpose-built detectors and a false positive rate under 10%. Public Secrets Monitoring scans 1B+ public GitHub commits daily, alerting teams the moment a secret is exposed externally. Honeytokens deploy decoy credentials that trigger immediate alerts on unauthorized access attempts. \*\*NHI Governance\*\* provides a centralized inventory of machine identities, including those outside vaults, with ownership attribution, risk scoring, and compliance evidence to support access reviews and rotation policy configuration. \*\*Developer Endpoint Protection\*\* extends coverage to the credential layer that repo and CI scanning can't reach: developer laptops. GitGuardian scans project directories, .env files, cloud credential stores, AI agent configs, and shell history across the entire fleet, delivering a prioritized inventory of exposed secrets by machine and severity. Trusted by Snowflake, ING, BASF, Datadog, Webflow, Bouygues Telecom, and more, and the #1 most-installed security app on the GitHub Marketplace.

**Average Rating:** 4.8/5.0

**Total Reviews:** 274

#### How Do G2 Users Rate GitGuardian?

- **Test Automation:** 8.3/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 9.0/10 (Category avg: 9.1/10)
- **Quality of Support:** 9.2/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 9.0/10 (Category avg: 8.3/10)

#### Who Is the Company Behind GitGuardian?

- **Seller:** [GitGuardian](https://www.g2.com/sellers/gitguardian-c1eb71ef-0ed6-4024-9679-56d9bee1fe3e)
- **Company Website:** www.gitguardian.com
- **Year Founded:** 2017
- **HQ Location:** Paris, Île-de-France
- **Twitter:** @GitGuardian  
6,055 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=b48a5941635607325adaf34ffb75cb9880fc425470fce263cbaa5b1453bbb2b9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fgitguardian&secure%5Burl_type%5D=linkedin_company_website)  
182 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Software Developer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 84% Small, 12% Medium

#### What Do G2 Reviewers Say About GitGuardian?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **alert notifications** of GitGuardian, enabling instant updates on key leaks after code pushes.
- Users praise the **automated security features** of GitGuardian, ensuring seamless and proactive detection of secrets.
- Users love the **automated vulnerability detection** of GitGuardian, appreciating its swift and proactive monitoring of secrets.
- Users value the **accurate and fast detection** of GitGuardian, ensuring real-time alerts and precise incident management.
- Users commend GitGuardian for its **immediate detection speed** , offering quick alerts and actionable fixes during development.

##### Cons

- Users find that **false positives** can be cumbersome, requiring significant tuning and impacting user experience.
- Users find the **inefficient notifications** overwhelming, as alerts accumulate and false positives increase workflow complexity.
- Users find the **limited customization** options in GitGuardian a barrier for tailoring alerts and policies effectively.
- Users find the **interface confusing** , struggling with cluttered navigation and excessive alert filtering across multiple incidents.
- Users report **excessive notifications** from GitGuardian, leading to clutter and increased review time for incident management.

#### What Are Recent G2 Reviews of GitGuardian?

**["Effortless Secret Detection with GitGuardian"](https://www.g2.com/survey_responses/gitguardian-review-13091541)**

**Rating:** 5.0/5.0 stars

_— Mihir R._

[Read full review](https://www.g2.com/survey_responses/gitguardian-review-13091541)

**["Seamless GitHub Secret Scanning with High Signal-to-Noise Alerts"](https://www.g2.com/survey_responses/gitguardian-review-13164824)**

**Rating:** 4.5/5.0 stars

_— Aswin K._

[Read full review](https://www.g2.com/survey_responses/gitguardian-review-13164824)

#### What Are G2 Users Discussing About GitGuardian?

- [What is GitGuardian used for?](https://www.g2.com/discussions/what-is-gitguardian-used-for) - 1 comment, 2 upvotes

### [GitLab](https://www.g2.com/products/gitlab/reviews)

GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab, teams can create, deliver, and manage code quickly and continuously instead of managing disparate tools and scripts. GitLab helps your teams across the complete DevSecOps lifecycle, from developing, securing, and deploying software. What makes us truly different? - Flexibility: Consume as a service or manage your own deployment - Cloud-Agnostic: Deploy anywhere with no vendor lock-in - No rip and replace: Scale to a platform approach at your own pace

**Average Rating:** 4.5/5.0

**Total Reviews:** 884

#### How Do G2 Users Rate GitLab?

- **Test Automation:** 9.2/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 8.8/10 (Category avg: 9.1/10)
- **Quality of Support:** 8.5/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 8.9/10 (Category avg: 8.3/10)

#### Who Is the Company Behind GitLab?

- **Seller:** [GitLab Inc.](https://www.g2.com/sellers/gitlab-inc)
- **Company Website:** about.gitlab.com
- **Year Founded:** 2014
- **HQ Location:** San Francisco, California
- **Twitter:** @gitlab  
171,534 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a712a3bc9d0c8f9d0d986490c4b4786dfb8085e13a770fa4c99cd9d01137c372&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5101804%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,473 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 37% Medium, 37% Small

#### What Do G2 Reviewers Say About GitLab?

_AI-generated summary from verified user reviews_

##### Pros

- Users enjoy the **ease of use** of GitLab, thanks to its unified interface and streamlined CI/CD integrations.
- Users value the **all-in-one platform** of GitLab, which streamlines development processes and enhances team collaboration.
- Users praise GitLab for its **powerful CI/CD integration** , which simplifies automation and enhances pipeline efficiency.
- Users value GitLab's **s seamless integrations** allowing streamlined workflows without the need for multiple tools.
- Users value GitLab's **seamless CI/CD integration** , which simplifies automation and enhances overall development efficiency.

##### Cons

- Users find the **complexity** of GitLab's group structure and management challenging, particularly for newcomers and infrastructure.
- Users face a **difficult learning curve** with GitLab, especially for those unfamiliar with its unique structure and features.
- Users find the **confusing interface** of GitLab overwhelming, especially new users navigating its complex functionalities and settings.
- Users find the **complex user interface** of GitLab requires significant effort to master and is not always intuitive.
- Users find the **steep learning curve** of GitLab challenging, especially when adapting to its comprehensive features and UI.

#### What Are Recent G2 Reviews of GitLab?

**["GitLab’s All-in-One DevOps Platform with CI/CD and Security Scanning"](https://www.g2.com/survey_responses/gitlab-review-12864830)**

**Rating:** 5.0/5.0 stars

_— mani s._

[Read full review](https://www.g2.com/survey_responses/gitlab-review-12864830)

**["All-in-One DevOps Platform That Streamlines CI/CD and Collaboration"](https://www.g2.com/survey_responses/gitlab-review-12894467)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/gitlab-review-12894467)

#### What Are G2 Users Discussing About GitLab?

- [What is GitLab used for?](https://www.g2.com/discussions/what-is-gitlab-used-for) - 2 comments
- [Why GitLab is better than Jenkins?](https://www.g2.com/discussions/why-gitlab-is-better-than-jenkins) - 1 comment
- [Is GitLab paid?](https://www.g2.com/discussions/is-gitlab-paid) - 5 comments, 2 upvotes
- [Is GitLab free software?](https://www.g2.com/discussions/is-gitlab-free-software) - 4 comments, 1 upvote
- [What can GitLab do?](https://www.g2.com/discussions/what-can-gitlab-do) - 2 comments

### [SonarQube](https://www.g2.com/products/sonarqube/reviews)

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 153

#### How Do G2 Users Rate SonarQube?

- **Test Automation:** 6.4/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 9.1/10)
- **Quality of Support:** 8.2/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 6.8/10 (Category avg: 8.3/10)

#### Who Is the Company Behind SonarQube?

- **Seller:** [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)
- **Company Website:** www.sonarsource.com
- **Year Founded:** 2008
- **HQ Location:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** DevOps Engineer, Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 42% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Users value how SonarQube **efficiently flags code quality and security issues** , ensuring a clean and maintainable codebase.
- Users value the **issue filtering and prioritization features** of SonarQube, enhancing focus on high-priority tasks.
- Users value the **issue identification and prioritization** features of SonarQube, improving focus on critical tasks.
- Users find SonarQube's **ease of use** invaluable for maintaining code quality and integrating seamlessly into development workflows.
- Users appreciate the **easy integrations** with existing CI/CD tools, enhancing their development workflow seamlessly.

##### Cons

- Users face challenges with **software bugs** as SonarQube can consume excessive RAM and occasionally reports false positives.
- Users find SonarQube's configuration **complex** , especially for beginners, leading to difficulties and overwhelming warnings to manage.
- Users encounter **false positives** that complicate evaluations, though mitigation options exist through detailed analysis and rule customization.
- Users find that SonarQube's **complexity in configuration** and excessive warnings can hinder effective usage and efficiency.
- Users find the **complex setup** of SonarQube challenging, especially for beginners unfamiliar with the configuration process.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube: Easy Integration, Simple UI, and Solid Free Code Quality Scanning"](https://www.g2.com/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-12975264)

**["SonarQube Makes Code Quality Clear with Strong Quality Gates and CI/CD Integration"](https://www.g2.com/survey_responses/sonarqube-review-13142666)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-13142666)

#### What Are G2 Users Discussing About SonarQube?

- [What is SonarLint used for?](https://www.g2.com/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)

### [Semgrep](https://www.g2.com/products/semgrep/reviews)

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

**Average Rating:** 4.6/5.0

**Total Reviews:** 56

#### How Do G2 Users Rate Semgrep?

- **Test Automation:** 9.2/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 9.1/10)
- **Quality of Support:** 8.8/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 7.5/10 (Category avg: 8.3/10)

#### Who Is the Company Behind Semgrep?

- **Seller:** [Semgrep](https://www.g2.com/sellers/semgrep)
- **Company Website:** semgrep.dev
- **Year Founded:** 2017
- **HQ Location:** San Francisco, US
- **Twitter:** @semgrep  
4,433 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=968a71f2060531e986a3873882c34b492bee4d8d264ff88e0089e53b8f7771f4&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freturntocorp&secure%5Burl_type%5D=linkedin_company_website)  
262 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 45% Large, 43% Medium

#### What Do G2 Reviewers Say About Semgrep?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Semgrep, praising its intuitive syntax and smooth CI/CD integration.
- Users appreciate the **intuitive pattern-matching syntax** of Semgrep, enabling effective custom rules for various programming languages.
- Users appreciate Semgrep's **effective vulnerability detection** , enabling quick identification of security issues with low false positives.
- Users value the **scanning efficiency** of Semgrep, benefiting from rapid scans and seamless CI/CD integration.
- Users appreciate the **robust security features** of Semgrep, enabling effective identification and remediation of vulnerabilities effortlessly.

##### Cons

- Users find Semgrep **not user-friendly** , citing a steep learning curve and challenges in initial setup and customization.
- Users note the **limited features** of Semgrep, making categorization and comprehensive analysis more challenging.
- Users find the **difficult learning** curve for custom rules in Semgrep challenging, impacting new user experiences and efficiency.
- Users face a **lack of guidance** in mastering rule creation and initial setup, impacting effective tool utilization.
- Users find the **learning curve steep** for rule writing, especially for those new to static analysis tools.

#### What Are Recent G2 Reviews of Semgrep?

**["Streamlined Code Security with Semgrep"](https://www.g2.com/survey_responses/semgrep-review-11971635)**

**Rating:** 5.0/5.0 stars

_— Shreekanth k._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-11971635)

**["Fast, Easy-to-Customize Rules That Catch Security and Code-Quality Issues Early"](https://www.g2.com/survey_responses/semgrep-review-13079252)**

**Rating:** 4.5/5.0 stars

_— Milan K._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-13079252)

### [Snyk](https://www.g2.com/products/snyk/reviews)

Snyk (pronounced sneak) is a developer security platform for securing custom code, open source dependencies, containers, and cloud infrastructure all from a single platform. Snyk’s developer security solutions enable modern applications to be built securely, empowering developers to own and build security for the whole application, from code & open source to containers & cloud infrastructure. Secure while you code in your IDE: find issues quickly using the scanner, fix issues easily with remediation advice, verify the updated code. Integrate your source code repositories to secure applications: integrate a repository to find issues, prioritize with context, fix & merge. Secure your containers as you build, throughout the SDLC: start fixing containers as soon as your write a Dockerfile, continuously monitor container images throughout their lifecycle, and prioritize with context. Secure build and deployment pipelines: Integrate natively with your CI/CD tool, configure your rules, find & fix issues in your application, and monitor your applications. Secure your apps quickly with Snyk’s vulnerability scanning and automated fixes - Try for Free!

**Average Rating:** 4.5/5.0

**Total Reviews:** 135

#### How Do G2 Users Rate Snyk?

- **Test Automation:** 7.8/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 8.7/10 (Category avg: 9.1/10)
- **Quality of Support:** 8.6/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 6.2/10 (Category avg: 8.3/10)

#### Who Is the Company Behind Snyk?

- **Seller:** [Snyk](https://www.g2.com/sellers/snyk)
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @snyksec  
21,057 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=53ae05ab7bc9d48691ba96e338012b66175e75679973854c2a6c213b21fab33f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F10043614%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,370 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 44% Medium, 35% Small

#### What Do G2 Reviewers Say About Snyk?

_AI-generated summary from verified user reviews_

##### Pros

- Users value Snyk's **rapid vulnerability detection** , enabling efficient identification and remediation in development environments.
- Users appreciate Snyk's **rapid vulnerability identification** , enhancing security through quick updates and effective integration.
- Users value the **easy integrations** of Snyk, enhancing workflow efficiency in CI/CD pipelines and GitHub.
- Users appreciate the **easy setup** of Snyk, enabling seamless integration with GitHub and efficient codebase scanning.
- Users commend Snyk for its **intuitive GUI and customizable organization structure** , enhancing vulnerability management and reporting efficiency.

##### Cons

- Users experience **false positives** from Snyk, leading to confusion and slowing down the scanning process.
- Users feel the **poor interface design** of Snyk hinders usability, especially with the separate DAST interface.
- Users face **pricing issues** with Snyk, as the cost can be high for accessing all features.
- Users often face **scanning issues** such as false positives and slow scans, affecting overall efficiency and workflow.
- Users report **false positives** and slow scans in Snyk, affecting efficiency and integration with other tools.

#### What Are Recent G2 Reviews of Snyk?

**["Seamless Dev-First Security with Fast Scans and Actionable Fixes"](https://www.g2.com/survey_responses/snyk-review-12676270)**

**Rating:** 4.5/5.0 stars

_— Prateek J._

[Read full review](https://www.g2.com/survey_responses/snyk-review-12676270)

**["Developer-Friendly Security with Clear, Automated Fixes"](https://www.g2.com/survey_responses/snyk-review-12974957)**

**Rating:** 4.5/5.0 stars

_— Hemanth K._

[Read full review](https://www.g2.com/survey_responses/snyk-review-12974957)

#### What Are G2 Users Discussing About Snyk?

- [What is Snyk scanning?](https://www.g2.com/discussions/what-is-snyk-scanning) - 2 comments, 2 upvotes
- [Is Snyk a SaaS?](https://www.g2.com/discussions/is-snyk-a-saas) - 2 comments
- [How good is Snyk?](https://www.g2.com/discussions/how-good-is-snyk) - 2 comments
- [What is Snyk used for?](https://www.g2.com/discussions/what-is-snyk-used-for)

### [OX Security](https://www.g2.com/products/ox-security/reviews)

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

**Average Rating:** 4.8/5.0

**Total Reviews:** 51

#### How Do G2 Users Rate OX Security?

- **Test Automation:** 7.3/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 9.1/10)
- **Quality of Support:** 9.6/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 7.7/10 (Category avg: 8.3/10)

#### Who Is the Company Behind OX Security?

- **Seller:** [OX Security](https://www.g2.com/sellers/ox-security)
- **Year Founded:** 2021
- **HQ Location:** New York, USA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ee8e1fc166aedd5d2f8edd57605f86ae8eec3007f5eee8810871f0e4645b4f4d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fox-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
199 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer
- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 63% Medium, 25% Large

#### What Do G2 Reviewers Say About OX Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **intuitive dashboard and seamless integration** of OX Security, enhancing their security management and workflow efficiency.
- Users value the **seamless collaboration** enabled by OX Security, enhancing their focus on critical development tasks.
- Users commend the **responsive customer support** of OX Security, enhancing their overall operational efficiency and satisfaction.
- Users value the **seamless integrations** with existing tools, enhancing workflows and boosting overall development efficiency.
- Users appreciate the **speed** of OX Security, enabling faster remediation of vulnerabilities and cloud misconfigurations.

##### Cons

- Users find the **complexity** of OX Security daunting, facing a steep learning curve and inadequate documentation.
- Users find the **interface overwhelming** , with a steep learning curve and insufficient documentation to guide new users.
- Users find the **complex setup** challenging, especially due to inadequate documentation and overwhelming UI for new users.
- Users find the **executive dashboard limiting** , impacting effective reporting on product security enhancements to management.
- Users find OX Security's **difficult learning curve** challenging, particularly due to its complex interface and lacking documentation.

#### What Are Recent G2 Reviews of OX Security?

**["A powerful and comprehensive tool that meets most best practices for web app security testing"](https://www.g2.com/survey_responses/ox-security-review-10961361)**

**Rating:** 4.5/5.0 stars

_— Verified User in Gambling & Casinos_

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10961361)

**["Holistic Security Solution with Seamless Integration"](https://www.g2.com/survey_responses/ox-security-review-10487561)**

**Rating:** 4.5/5.0 stars

_— Sharon S._

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10487561)

### [Checkmarx](https://www.g2.com/products/checkmarx/reviews)

Checkmarx is a type of application security solution designed to help organizations safeguard their software development processes while enhancing efficiency and reducing costs. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. With the increasing reliance on AI technologies and the rapid pace of software development, Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as AI SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

**Average Rating:** 4.2/5.0

**Total Reviews:** 43

#### How Do G2 Users Rate Checkmarx?

- **Test Automation:** 8.7/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 9.1/10)
- **Quality of Support:** 8.3/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 5.6/10 (Category avg: 8.3/10)

#### Who Is the Company Behind Checkmarx?

- **Seller:** [Checkmarx](https://www.g2.com/sellers/checkmarx)
- **Company Website:** www.checkmarx.com
- **Year Founded:** 2006
- **HQ Location:** Paramus, NJ
- **Twitter:** @Checkmarx  
7,284 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=18f6741e77df71b112ecb3ec6620912d3a0f67666525358c0a4f3b1278b173df&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheckmarx&secure%5Burl_type%5D=linkedin_company_website)  
1,019 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 57% Large, 21% Medium

#### What Do G2 Reviewers Say About Checkmarx?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Checkmarx **easy to implement** , seamlessly integrating into existing repositories with a user-friendly interface.
- Users appreciate the **intuitive user interface** of Checkmarx, making security reviews simple and user-friendly.
- Users value the **accuracy of results** from Checkmarx, as it simplifies security reviews with detailed vulnerability insights.
- Users value the **automation testing capabilities** of Checkmarx, finding it easy to integrate and use effectively.
- Users praise the **exceptional customer support** at Checkmarx, ensuring prompt assistance for any unresolved issues.

##### Cons

- Users face a high number of **false positives** in Checkmarx when working with Kotlin projects, affecting accuracy and reliability.
- Users report **lacking feature support** for Kotlin, leading to numerous false positives not seen in Java or JavaScript.
- Users experience **missing features** in Checkmarx, specifically regarding poor support for Kotlin that leads to false positives.
- Users find the **poor navigation** in Checkmarx frustrating, as the dashboard layout and display need enhancement.

#### What Are Recent G2 Reviews of Checkmarx?

**["Centralized Source Code Security with Seamless CI/CD Integration"](https://www.g2.com/survey_responses/checkmarx-review-12980590)**

**Rating:** 5.0/5.0 stars

_— Aman M._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12980590)

**["Checkmarx: Reliable SAST Solution for Strengthening Application Security"](https://www.g2.com/survey_responses/checkmarx-review-13085824)**

**Rating:** 4.0/5.0 stars

_— Naushad T._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-13085824)

#### What Are G2 Users Discussing About Checkmarx?

- [What is Checkmarx used for?](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for) - 1 comment, 1 upvote
- [How much does Checkmarx cost?](https://www.g2.com/discussions/how-much-does-checkmarx-cost)
- [Which testing method does Checkmarx support?](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support) - 1 comment
- [Does Checkmarx support DAST?](https://www.g2.com/discussions/does-checkmarx-support-dast) - 1 comment
- [What is Checkmarx used for?](https://www.g2.com/discussions/what-is-checkmarx-used-for) - 2 comments

### [DryRun Security](https://www.g2.com/products/dryrun-security/reviews)

Security leaders face a paradox: ship faster and enable agentic development while staying secure and keeping developers productive. DryRun Security resolves this by securing every pull request and repo with a high-precision, automated security engineer review right where developers and their agents build. DryRun Security is the industry’s most accurate agentic code security intelligence platform. Powered by its proprietary Contextual Security Analysis (CSA) engine, DryRun Security delivers the AI moment for security teams in an AI-native developer world. Traditional static application security testing (SAST) floods teams with alerts, misses higher-order risk, and burns time in triage. DryRun Security goes beyond SAST with contextual analysis that prioritizes what is exploitable and impactful in your codebase, then helps engineers remediate fast. Instead of “find everything and hope someone sorts it out,” DryRun Security delivers code security intelligence that is ready to act on. DryRun Security puts a security engineer directly into developer workflows. In pull requests, the Code Review Agent reviews changes in context, explains risk in plain language, and guides fixes where developers already work. In repos, the DeepScan Agent produces focused, human-grade findings for the issues that actually matter, without weeks of manual review before major milestones. The Custom Policy Agent enforces guardrails with Natural Language Code Policies, so you can standardize security and compliance requirements across teams without brittle rule sets. Codebase Insights allows leaders to ask questions of their entire codebase like "Are we exposed to this new vulnerability" and have confidence in minutes. DryRun Security also integrates with AI coding workflows, so remediation happens with the precision of a security engineer working at machine speed. Teams connect DryRun Security insights and guidance into Claude, Cursor, OpenAI Codex, and Windsurf, helping developers and their agents fix issues with contextual, security-engineered direction tied to the PR and codebase. What DryRun Security delivers (beyond SAST) • Automated secure code review in every pull request with high-signal findings and low noise • Contextual Security Analysis that catches common vulnerabilities and deeper multi-dependency and logic risks • Automated remediation guidance that helps engineers fix faster, with explanations and next steps • Secrets analysis identifies genuine hardcoded secrets and suppresses the usual false alarms • Policy enforcement in PRs using Natural Language Code Policies for consistent guardrails across repos • Codebase intelligence and reporting for AppSec visibility, prioritization, and audit-ready evidence DryRun Security supports most code environments, languages, and frameworks, including: • GitHub, GitLab • C#, Golang, Elixir, JavaScript, TypeScript, Python, Ruby, Java, Kotlin, PHP, Swift, HTML • Infrastructure as Code (Terraform, YAML) • And more

**Average Rating:** 4.9/5.0

**Total Reviews:** 20

#### How Do G2 Users Rate DryRun Security?

- **Test Automation:** 10.0/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 9.1/10)
- **Quality of Support:** 10.0/10 (Category avg: 9.2/10)

#### Who Is the Company Behind DryRun Security?

- **Seller:** [DryRun Security](https://www.g2.com/sellers/dryrun-security)
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6a05a774e1320fb12547e26ce7fe95d94335bc0c4be6317172500089b5b6db36&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdryrun-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
16 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 40% Small, 30% Medium

#### What Do G2 Reviewers Say About DryRun Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **context-aware security feedback** from DryRun Security, enhancing vulnerability mitigation during development in GitHub.
- Users appreciate the **quick and context-aware vulnerability detection** of DryRun Security, enhancing security during the development process.
- Users value the **seamless integration and advanced detections** of DryRun Security, enhancing code security and development efficiency.
- Users value the **accuracy of feedback** from DryRun Security, effectively minimizing false positives and identifying complex vulnerabilities.
- Users appreciate the **easy setup** of DryRun Security, enabling seamless integration and quick vulnerability detection.

##### Cons

- Users find the **slow performance** of DryRun Security's management portal frustrating, impacting their overall experience.
- Users experience **slow speed** issues with the management portal, impacting overall usability and efficiency.
- Users note the **sluggish UI** of DryRun Security, which hampers the overall developer experience during use.
- Users feel there are **limited customization options** for analyzers, though improvements may be forthcoming.
- Users feel that there are **workflow issues** that hinder the developer experience and adoption of DryRun Security.

#### What Are Recent G2 Reviews of DryRun Security?

**["Catches Logic and Authorization Flaws Traditional SAST Often Misses"](https://www.g2.com/survey_responses/dryrun-security-review-12357188)**

**Rating:** 5.0/5.0 stars

_— Jabez A._

[Read full review](https://www.g2.com/survey_responses/dryrun-security-review-12357188)

**["Next Gen of SAST Tool That Has Cutting Edge Tech"](https://www.g2.com/survey_responses/dryrun-security-review-12462338)**

**Rating:** 5.0/5.0 stars

_— Francis D._

[Read full review](https://www.g2.com/survey_responses/dryrun-security-review-12462338)

### [OpenText Static Application Security Testing](https://www.g2.com/products/opentext-static-application-security-testing/reviews)

OpenText™ Static Application Security Testing (SAST) is a comprehensive solution designed to identify and remediate security vulnerabilities within an application's source code during the early stages of development. By analyzing code from the "inside out," SAST provides immediate feedback to developers, enabling them to address security issues promptly and effectively. Key Features and Functionality: - Extensive Language Support: Supports over 33 programming languages and more than 1,400 vulnerability categories, ensuring broad applicability across various development environments. - Integration with Development Tools: Seamlessly integrates with popular Integrated Development Environments (IDEs) such as Eclipse, Visual Studio, and JetBrains, as well as Continuous Integration/Continuous Deployment (CI/CD) tools like Jenkins and Bamboo, facilitating a smooth incorporation into existing workflows. - Scalable Deployment Options: Offers flexible deployment models, including on-premises, cloud-based, and Software as a Service (SaaS) solutions, allowing organizations to choose the setup that best fits their needs. - Advanced Analysis Capabilities: Utilizes multiple algorithms and an expansive knowledge base of secure coding rules to perform thorough code analysis, pinpointing the root causes of vulnerabilities and providing detailed remediation guidance. Primary Value and Problem Solved: OpenText SAST empowers organizations to proactively manage application security by detecting and addressing vulnerabilities early in the Software Development Life Cycle (SDLC). This proactive approach reduces the risk of security breaches, minimizes the cost and effort associated with late-stage remediation, and enhances the overall security posture of applications. By integrating security testing into the development process, OpenText SAST helps developers create more secure code, leading to robust and reliable software products.

**Average Rating:** 4.5/5.0

**Total Reviews:** 21

#### How Do G2 Users Rate OpenText Static Application Security Testing?

- **Test Automation:** 8.7/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 9.1/10)
- **Quality of Support:** 8.7/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 7.0/10 (Category avg: 8.3/10)

#### Who Is the Company Behind OpenText Static Application Security Testing?

- **Seller:** [OpenText](https://www.g2.com/sellers/opentext)
- **Year Founded:** 1991
- **HQ Location:** Waterloo, ON
- **Twitter:** @OpenText  
21,565 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c339a6555764b5ffce77c3df08d6ed9c9b1cb1ee1baeebac8435f0485b7cca5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2709%2F&secure%5Burl_type%5D=linkedin_company_website)  
23,048 employees on LinkedIn®
- **Ownership:** NASDAQ:OTEX

#### Who Uses This Product?

- **Top Industries:** Financial Services, Banking
- **Company Size:** 50% Large, 29% Small

#### What Do G2 Reviewers Say About OpenText Static Application Security Testing?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **easy integrations** of OpenText Static Application Security Testing with various third-party tools for enhanced functionality.
- Users value the **extensive integration capabilities** of OpenText Static Application Security Testing with various third-party tools.
- Users value the **integration support** of OpenText Static Application Security Testing, enhancing compatibility with various tools and technologies.

##### Cons

- Users find the **false positives** in OpenText Static Application Security Testing somewhat problematic, despite options to ignore them.

#### What Are Recent G2 Reviews of OpenText Static Application Security Testing?

**["Fortify Static Code Analyzer (SCA)"](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-10770814)**

**Rating:** 4.0/5.0 stars

_— Lokesh T._

[Read full review](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-10770814)

**["Efficient and easy to use Code Analyzer"](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-7271508)**

**Rating:** 4.5/5.0 stars

_— Nav N._

[Read full review](https://www.g2.com/survey_responses/opentext-static-application-security-testing-review-7271508)

#### What Are G2 Users Discussing About OpenText Static Application Security Testing?

- [What is Fortify Static Code Analyzer used for?](https://www.g2.com/discussions/what-is-fortify-static-code-analyzer-used-for)
- [What tools does fortify include?](https://www.g2.com/discussions/what-tools-does-fortify-include)
- [What are the main components of Fortify?](https://www.g2.com/discussions/fortify-static-code-analyzer-what-are-the-main-components-of-fortify) - 1 comment
- [What is Fortify software used for?](https://www.g2.com/discussions/fortify-static-code-analyzer-what-is-fortify-software-used-for)
- [What is Micro Focus Fortify static code analyzer?](https://www.g2.com/discussions/what-is-micro-focus-fortify-static-code-analyzer)

### [Kiuwan Code Security & Insights](https://www.g2.com/products/kiuwan-code-security-insights/reviews)

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

**Average Rating:** 4.5/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate Kiuwan Code Security & Insights?

- **Test Automation:** 9.4/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 9.1/10)
- **Quality of Support:** 8.9/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 8.3/10 (Category avg: 8.3/10)

#### Who Is the Company Behind Kiuwan Code Security & Insights?

- **Seller:** [Sembi](https://www.g2.com/sellers/sembi)
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7ed5860a727a31b32edfba64808a6ea32fccad50d052e993a08b626d675d5c69&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsembi-inc%2F&secure%5Burl_type%5D=linkedin_company_website)  
94 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Banking
- **Company Size:** 41% Large, 35% Medium

#### What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **accuracy** of Kiuwan's code scans, ensuring reliable results and satisfaction with reporting capabilities.
- Users value the **accuracy of findings** from Kiuwan Code Security & Insights, enhancing their confidence in code security.
- Users appreciate the **efficient customer support** of Kiuwan, enhancing their overall experience and satisfaction with the product.
- Users value the **user-friendly interface** of Kiuwan, enhancing their experience with efficient code scans and reporting.
- Users appreciate the **user-friendly interface** of Kiuwan Code Security & Insights, making dashboard navigation easy and efficient.

#### What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

**["Impeccable Security and Code Analysis, with Potential for Improvement in Customization"](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)**

**Rating:** 5.0/5.0 stars

_— Abelardo I._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)

**["Elevated our software security to the next level. Improved our code quality."](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)**

**Rating:** 5.0/5.0 stars

_— Abdullah Enes K._

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)

### [Jit](https://www.g2.com/products/jit/reviews)

Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empowers organizations to proactively manage security risks across the entire software development lifecycle.​ AI-Powered Agents Jit's AI Agents, such as SERA (Security Evaluation and Remediation Agent) and COTA (Communication, Ops, and Ticketing Agent), collaborate with your teams to automate vulnerability triage, risk assessment, and remediation processes, significantly reducing manual workloads. ​ Comprehensive Security Scanning Achieve full-stack security coverage with integrated scanners for SAST, DAST, SCA, IaC, CSPM, and more. Jit's platform ensures continuous monitoring and immediate feedback on code changes, facilitating rapid identification and resolution of security issues. ​ Developer-Centric Experience With integrations into popular IDEs and CI/CD pipelines, Jit provides developers with contextual security insights directly within their workflows, promoting a shift-left approach without disrupting productivity. ​ Agentic AI for AppSec Teams Risk-Based Prioritization Utilizing the Model Context Protocol (MCP), Jit evaluates vulnerabilities in the context of runtime environments, business impact, and compliance requirements, enabling teams to focus on the most critical risks. ​ Seamless Integrations Jit integrates with a wide array of tools, including GitHub, GitLab, AWS, Azure, GCP, Jira, Slack, and more, ensuring that security processes are embedded within your existing technology stack. ​

**Average Rating:** 4.5/5.0

**Total Reviews:** 43

#### How Do G2 Users Rate Jit?

- **Test Automation:** 8.7/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 9.1/10)
- **Quality of Support:** 9.3/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 8.2/10 (Category avg: 8.3/10)

#### Who Is the Company Behind Jit?

- **Seller:** [jit](https://www.g2.com/sellers/jit)
- **Year Founded:** 2021
- **HQ Location:** Boston, MA
- **Twitter:** @jit\_io  
522 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c12301146938a4e9885aeef608ceac690a4eb5c023d31e5d2df099a15cbff3c7&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fjit%2F&secure%5Burl_type%5D=linkedin_company_website)  
150 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Financial Services
- **Company Size:** 44% Medium, 42% Small

#### What Do G2 Reviewers Say About Jit?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **seamless integration of security into development workflows** , highlighting efficiency and centralized management.
- Users find Jit to be **very easy to use** , streamlining integration of security into development workflows effectively.
- Users love the **easy integrations** of Jit, streamlining security within their development workflows effortlessly.
- Users appreciate the **efficiency** of Jit, which reduces waste and streamlines processes, enhancing overall productivity.
- Users value the **automation of security controls** in Jit, streamlining workflows and enhancing efficiency in development processes.

##### Cons

- Users face **integration issues** with Jit, particularly in enterprise environments and with certain CI tools requiring extra setup.
- Users find the **limited features** of Jit restrict complex setups and hinder comprehensive analytics and reporting.
- Users feel the **limited integration** with enterprise environments restricts Jit's full potential and usability.
- Users find the **documentation lacking** , particularly for advanced configurations, impacting their overall experience with Jit.
- Users find the **complexity** of Jit challenging, particularly with advanced integrations and configuration for newcomers.

#### What Are Recent G2 Reviews of Jit?

**["Exploring jit a personal review"](https://www.g2.com/survey_responses/jit-review-11751139)**

**Rating:** 4.0/5.0 stars

_— Mohamed A._

[Read full review](https://www.g2.com/survey_responses/jit-review-11751139)

**["Helpful Tool for Integrating Security in Mobile App Development"](https://www.g2.com/survey_responses/jit-review-11750234)**

**Rating:** 4.0/5.0 stars

_— Ali A._

[Read full review](https://www.g2.com/survey_responses/jit-review-11750234)

### [Black Duck Coverity Static](https://www.g2.com/products/black-duck-coverity-static/reviews)

Coverity® is a fast, accurate, and highly scalable static analysis (SAST) solution that helps development and security teams address security and quality defects early in the software development life cycle (SDLC), track and manage risks across the application portfolio, and ensure compliance with security and coding standards.

**Average Rating:** 4.3/5.0

**Total Reviews:** 65

#### How Do G2 Users Rate Black Duck Coverity Static?

- **Test Automation:** 8.0/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 9.1/10)
- **Quality of Support:** 8.6/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 7.9/10 (Category avg: 8.3/10)

#### Who Is the Company Behind Black Duck Coverity Static?

- **Seller:** [Black Duck](https://www.g2.com/sellers/black-duck)
- **Year Founded:** 2024
- **HQ Location:** Burlington, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ca66ef383f133f101804712b9ed7a89aec2633a8efa048bd261db3b92eb47e73&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fblack-duck-software&secure%5Burl_type%5D=linkedin_company_website)  
1,345 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 55% Large, 34% Medium

#### What Are Recent G2 Reviews of Black Duck Coverity Static?

**["Effective Static Code Analysis with Great Integration, but Outdated UI"](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10763088)**

**Rating:** 5.0/5.0 stars

_— Lokesh T._

[Read full review](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10763088)

**["A decent security software for any organization which is lighweight and useful also."](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10522202)**

**Rating:** 4.5/5.0 stars

_— Ambrish M._

[Read full review](https://www.g2.com/survey_responses/black-duck-coverity-static-review-10522202)

#### What Are G2 Users Discussing About Black Duck Coverity Static?

- [What is Coverity used for?](https://www.g2.com/discussions/what-is-coverity-used-for)
- [What is coverity connect?](https://www.g2.com/discussions/what-is-coverity-connect)
- [How does Coverity Static Analysis work?](https://www.g2.com/discussions/how-does-coverity-static-analysis-work)
- [What is Coverity report?](https://www.g2.com/discussions/what-is-coverity-report)
- [What is Coverity software?](https://www.g2.com/discussions/what-is-coverity-software)

### [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews)

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

**Average Rating:** 3.8/5.0

**Total Reviews:** 25

#### How Do G2 Users Rate Veracode Application Security Platform?

- **Test Automation:** 9.2/10 (Category avg: 8.7/10)
- **Has the product been a good partner in doing business?:** 7.9/10 (Category avg: 9.1/10)
- **Quality of Support:** 8.0/10 (Category avg: 9.2/10)
- **Black-Box Scanning:** 8.3/10 (Category avg: 8.3/10)

#### Who Is the Company Behind Veracode Application Security Platform?

- **Seller:** [VERACODE](https://www.g2.com/sellers/veracode)
- **Year Founded:** 2006
- **HQ Location:** Burlington, MA
- **Twitter:** @Veracode  
21,950 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d799a3c2e821841d648bc54266ea8fb1c07039938aa9c79b60d2cf275f0dcf34&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F27845%2F&secure%5Burl_type%5D=linkedin_company_website)  
502 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 69% Large, 31% Medium

#### What Do G2 Reviewers Say About Veracode Application Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **comprehensive security analysis** offered by Veracode, effectively addressing vulnerabilities and streamlining development.
- Users value Veracode for its **effective vulnerability detection** , ensuring high-security standards and seamless integration into development processes.
- Users appreciate the **automated scanning** feature of Veracode, which effectively identifies vulnerabilities and enhances security standards.
- Users value the **effective detection capabilities** of Veracode, enabling thorough security checks and vulnerability identification.
- Users value the **ease of use** of Veracode, benefiting from seamless integration and comprehensive security analysis.

##### Cons

- Users find the platform to be **expensive** , with rising costs and unjustifiable investment in customer success packages.
- Users face a **lack of information** regarding features and services, leading to confusion and unmet expectations.
- Users express concerns about **licensing issues** , citing high costs, complex models, and unmet feature expectations.
- Users report **poor customer support** , experiencing pressure from sales and challenges with feature delivery and documentation.
- Users express concerns over **pricing issues** , citing increased costs, complex licensing, and pressure from sales executives.

#### What Are Recent G2 Reviews of Veracode Application Security Platform?

**["Streamlined Security, Effortless Integration"](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)**

**Rating:** 5.0/5.0 stars

_— Bhanu Prakash M._

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)

**["Clear, Unified View of Application Capabilities"](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)**

**Rating:** 4.5/5.0 stars

_— Christopher S._

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)

#### What Are G2 Users Discussing About Veracode Application Security Platform?

- [What is difference between veracode and SonarQube?](https://www.g2.com/discussions/what-is-difference-between-veracode-and-sonarqube)
- [What is veracode software composition analysis?](https://www.g2.com/discussions/what-is-veracode-software-composition-analysis)
- [What is veracode used for?](https://www.g2.com/discussions/what-is-veracode-used-for)
- [What is the veracode application security platform?](https://www.g2.com/discussions/what-is-the-veracode-application-security-platform)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/static-application-security-testing-sast?order=g2_score&page=2#product-list)
- [3](/categories/static-application-security-testing-sast?order=g2_score&page=3#product-list)
- [4](/categories/static-application-security-testing-sast?order=g2_score&page=4#product-list)
- [5](/categories/static-application-security-testing-sast?order=g2_score&page=5#product-list)
- …
- [7](/categories/static-application-security-testing-sast?order=g2_score&page=7#product-list)
- [8](/categories/static-application-security-testing-sast?order=g2_score&page=8#product-list)
- [Next &rsaquo;Next ›](/categories/static-application-security-testing-sast?order=g2_score&page=2#product-list)

Spotlight Categories

[Operational Risk Management Software](https://www.g2.com/categories/operational-risk-management)

[Payroll Software](https://www.g2.com/categories/payroll)

[Security Awareness Training Software](https://www.g2.com/categories/security-awareness-training)

[Knowledge Base Software](https://www.g2.com/categories/knowledge-base-software)

[Auto Dialer Software](https://www.g2.com/categories/auto-dialer)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)

- [Log Analysis](/categories/log-analysis)
- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)

- [Software Composition Analysis](/categories/software-composition-analysis)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Static Application Security Testing (SAST) Themes](/categories/static-application-security-testing-sast/themes)

 ![Lauren Worth](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Lauren Worth")
LW

Researched and written by [Lauren Worth](https://research.g2.com/insights/author/lauren-worth)

Updated October 3, 2024

Static application security testing (SAST) software inspects and analyzes an application’s code to discover security vulnerabilities without actually executing code. These tools are frequently used by companies with [continuous delivery](https://www.g2.com/categories/continuous-delivery) practices to identify flaws prior to deployment. SAST tools provide vulnerability information and remediation suggestions for development teams to resolve. There is relation and overlap between SAST tools and [static code analysis](https://www.g2.com/categories/static-code-analysis) software, but SAST products are more focused on security testing. Static code analysis products, on the other hand, combine a number of analytical practices, test management, and team collaboration features.

[SAST vs DAST](https://research.g2.com/blog/sast-vs-dast) — Learn the difference

To qualify for inclusion in the Static Application Security Testing (SAST) category, a product must:

- Test applications to identify vulnerabilities
- Not execute code during testing, or have the ability to run static tests
- Provide information on relative vulnerabilities and exploits

Show More