# Best Vulnerability Scanner Software - Page 3

*By [Lauren Worth](https://research.g2.com/insights/author/lauren-worth)*


Vulnerability scanners continuously monitor applications and networks against an up-to-date database of known vulnerabilities, identifying potential exploits, producing analytical reports on the security state of applications and networks, and providing recommendations to remedy known issues.

### Core Capabilities of Vulnerability Scanner Software

To qualify for inclusion in the Vulnerability Scanner category, a product must:

- Maintain a database of known vulnerabilities
- Continuously scan applications for vulnerabilities
- Produce reports analyzing known vulnerabilities and new exploits

### Common Use Cases for Vulnerability Scanner Software

Security and IT teams use vulnerability scanners to proactively identify and address weaknesses before they can be exploited. Common use cases include:

- Running scheduled and on-demand scans of applications and network infrastructure for known CVEs
- Generating prioritized vulnerability reports to guide remediation efforts
- Testing application and network security posture as part of ongoing compliance and risk management programs

### How Vulnerability Scanner Software Differs from Other Tools

Some vulnerability scanners operate similarly to [dynamic application security testing (DAST)](https://www.g2.com/categories/dynamic-application-security-testing-dast) tools, but the key distinction is that vulnerability scanners test applications and networks against known vulnerability databases rather than mimicking real-world attacks or performing penetration tests. DAST tools simulate attacker behavior to uncover runtime vulnerabilities, while scanners focus on identification and reporting of known weaknesses.

### Insights from G2 on Vulnerability Scanner Software

Based on category trends on G2, continuous scanning and comprehensive vulnerability reporting stand out as standout capabilities. Faster identification of critical exposures and improved compliance readiness stand out as primary benefits of adoption.





## Top Vulnerability Scanner Software at a Glance
| # | Product | Rating | Best For | What Users Say |
|---|---------|--------|----------|----------------|
| 1 | [Wiz](https://www.g2.com/products/wiz-wiz/reviews) | 4.7/5.0 (822 reviews) | Risk-based cloud vulnerability prioritization with context | "[Wiz Delivers Clear Visibility Into Cloud Risks That Truly Matter](https://www.g2.com/survey_responses/wiz-review-12960477)" |
| 2 | [Aikido Security](https://www.g2.com/products/aikido-security/reviews) | 4.6/5.0 (232 reviews) | Auto-triaged DevSecOps scanning with low false positives | "[Enterprise Security Without an Enterprise Security Team](https://www.g2.com/survey_responses/aikido-security-review-13108704)" |
| 3 | [Orca Security](https://www.g2.com/products/orca-security/reviews) | 4.7/5.0 (304 reviews) | Agentless cloud vulnerability scanning with contextual risk prioritization | "[Orca Brings AI Agents Into Focus With Prioritized, Business-Relevant Risk Views](https://www.g2.com/survey_responses/orca-security-review-13129539)" |
| 4 | [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews) | 4.5/5.0 (289 reviews) | Credentialed infrastructure scans with compliance auditing | "[Self-Contained Nessus Scanning with Full Control in Offline Environments](https://www.g2.com/survey_responses/tenable-nessus-review-12937668)" |
| 5 | [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews) | 4.6/5.0 (214 reviews) | SaaS pentest certification with manual validation | "[Smooth Onboarding, Responsive Support, and Strong Pentest Lifecycle Controls](https://www.g2.com/survey_responses/astra-pentest-review-13001206)" |
| 6 | [Intruder](https://www.g2.com/products/intruder/reviews) | 4.8/5.0 (209 reviews) | Continuous vulnerability scanning with emerging threat detection | "[Reliable Service with Flexible Plans and Strong Support](https://www.g2.com/survey_responses/intruder-review-13110046)" |
| 7 | [CrowdStrike Falcon Cloud Security](https://www.g2.com/products/crowdstrike-falcon-cloud-security/reviews) | 4.5/5.0 (134 reviews) | — | "[Cuts Through the Noise with Actionable, Context-Rich Findings](https://www.g2.com/survey_responses/crowdstrike-falcon-cloud-security-review-13122457)" |
| 8 | [Sysdig Secure](https://www.g2.com/products/sysdig-sysdig-secure/reviews) | 4.8/5.0 (110 reviews) | Runtime vulnerability detection in Kubernetes workloads | "[Excellent Real-Time Kubernetes Security Visibility and Threat Detection](https://www.g2.com/survey_responses/sysdig-secure-review-12711991)" |
| 9 | [Burp Suite](https://www.g2.com/products/burp-suite/reviews) | 4.8/5.0 (126 reviews) | Manual web application penetration testing workflows | "[Complete Control Over Web Requests with Burp Suite](https://www.g2.com/survey_responses/burp-suite-review-12677559)" |
| 10 | [Tenable Vulnerability Management](https://www.g2.com/products/tenable-vulnerability-management/reviews) | 4.5/5.0 (113 reviews) | Risk-based vulnerability prioritization with VPR scoring | "[TVM Does What You Need](https://www.g2.com/survey_responses/tenable-vulnerability-management-review-12937561)" |

---
## What Are the Most Common Questions About Vulnerability Scanner Software?
*AI-generated · Last updated: May 26, 2026*
### What platform provides detailed vulnerability reporting and analytics?
Based on G2 reviews, several vulnerability scanner software products are praised for detailed reporting and clear visibility into findings. According to verified users, Tenable Nessus stands out for detailed reports, audit-friendly outputs, and remediation suggestions, while Intruder reviewers mention clear dashboards and practical reporting that help teams understand and act on issues quickly. G2 reviewers also mention Edgescan for trend reporting, time-to-resolve visibility, and dashboards that help track remediation progress over time. Buyers looking for strong reporting and analytics often value products that combine understandable findings with prioritization and historical visibility so teams can communicate risk clearly and manage remediation more efficiently.


### What platform integrates scanning with patch management systems?
Based on G2 reviews, products in this category often support remediation workflows by helping teams connect findings to patching or operational processes. According to verified users, CyberSmart is noted for patch management alongside vulnerability visibility, helping teams see outdated systems and remediate them from the same workflow. G2 reviewers also mention ConnectSecure Vulnerability and Compliance Manager and APPCHECK as tools that support organized remediation, while Qualys and Tenable products are described as integrating findings into broader operational environments. Buyers evaluating vulnerability scanner software for this use case should prioritize products reviewers say make it easier to move from finding issues to coordinating fixes, especially when patching and compliance work need to stay tightly connected.


### What is the most affordable vulnerability scanner for SMBs?
Based on G2 reviews, affordability for SMBs is usually described in terms of value, ease of setup, and reduced manual work rather than exact pricing. According to verified users, Aikido Security is frequently described as friendly for small and mid-sized businesses, with reviewers highlighting strong value and straightforward setup. G2 reviewers also mention Intruder as cost-effective and easy to operate, while Offensity is noted as an affordable way to stay on top of cyber risks without hiring dedicated experts. For SMB buyers, the strongest value signals in recent reviews come from products that combine simple onboarding, actionable findings, and automation that reduces the need for extra security staffing.

**Here are some of the top-rated products on G2:**

- [Aikido Security](https://www.g2.com/products/aikido-security/reviews/aikido-security-review-11660004) – reviewers describe it as suitable for SMBs with broad automated security testing and simple setup
- [Intruder](https://www.g2.com/products/intruder/reviews/intruder-review-11847236) – users highlight cost-effective scanning, easy implementation, and low operational overhead
- [Offensity](https://www.g2.com/products/offensity/reviews/offensity-review-11393651) – reviewers call out affordability and continuous automated scans for smaller teams


### Which vendor offers automated remediation guidance for vulnerabilities?
Based on G2 reviews, several vendors are recognized for helping teams move from findings to fixes with clear remediation guidance. According to verified users, Wiz is frequently praised for actionable remediation steps, contextual prioritization, and guidance that helps security and engineering teams understand what to fix first. G2 reviewers also mention Tenable Nessus for helpful remediation tips and APPCHECK for making vulnerability assignment and management easier. Buyers looking for vulnerability scanner software with strong remediation support should focus on products reviewers say reduce manual triage, explain issues clearly, and provide practical next steps instead of only listing findings.


### Which solution supports vulnerability scanning for cloud environments?
Based on G2 reviews, cloud vulnerability scanning is a major strength for multiple products in this category. According to verified users, Wiz is repeatedly praised for broad visibility across cloud environments, including vulnerabilities, misconfigurations, and risk prioritization in a single platform. G2 reviewers also mention Orca Security for agentless cloud scanning and centralized visibility, while Intruder and CrowdStrike Falcon Cloud Security are described as helping teams monitor cloud assets and workloads more effectively. Buyers focused on cloud use cases should look for recent review themes around fast onboarding, multi-cloud visibility, and the ability to prioritize real risks rather than simply generating large volumes of alerts.


### What is the top-rated vulnerability scanner for large organizations?
Based on G2 reviews, Wiz appears most frequently in recent feedback and is consistently described as a strong fit for large, complex environments. According to verified users, it helps organizations unify cloud visibility, reduce alert fatigue, and prioritize risks across broad environments without adding heavy deployment friction. G2 reviewers mention benefits such as multi-cloud visibility, strong collaboration across security and engineering teams, and support for scaling security operations in complex estates. For large organizations, the most common recent themes are broad coverage, contextual prioritization, and the ability to consolidate multiple security workflows into one platform, all of which are repeatedly associated with Wiz in the supplied review set.


### What is the best vulnerability scanning tool for enterprise IT teams?
Based on G2 reviews, Wiz is the strongest recent fit for enterprise IT teams because reviewers repeatedly describe it as helping large teams unify visibility, prioritize meaningful risks, and coordinate remediation across complex environments. According to verified users, it reduces noise by connecting vulnerabilities, misconfigurations, and exposures in context, which helps enterprise teams focus their efforts more effectively. G2 reviewers also mention fast onboarding, strong integrations, and better collaboration between security, infrastructure, and engineering teams. In the supplied review set, those enterprise-focused themes appear most consistently around Wiz, making it the clearest recent answer for buyers seeking a broad, scalable vulnerability scanner software platform.


### Which tool supports scanning for compliance with industry standards?
Based on G2 reviews, several tools are used to support compliance-driven vulnerability scanning. According to verified users, Tenable Nessus is commonly mentioned for helping teams scan against recognized standards and create reports for audit and compliance use cases. G2 reviewers also mention Intruder for ongoing scanning tied to compliance workflows, CyberSmart for Cyber Essentials-related monitoring, and Wiz for supporting PCI, SOC, and broader compliance visibility in cloud environments. Buyers looking for compliance-focused vulnerability scanner software should prioritize tools reviewers say generate understandable reports, surface remediation clearly, and fit into recurring audit or certification processes without adding heavy manual work.


### Which vendor provides real-time vulnerability detection and alerts?
Based on G2 reviews, real-time or continuously updated visibility is a common requirement for buyers who need fast response to new issues. According to verified users, Wiz is repeatedly described as providing rapid visibility into vulnerabilities and risks across cloud environments, with contextual prioritization that helps teams respond faster. G2 reviewers also mention Intruder for automatic scanning and timely notifications, while CyberSmart is noted for real-time style reporting on vulnerabilities and patching needs. For this use case, buyers should look for products that reviewers say combine continuous monitoring with useful alerts, so teams can act quickly without being buried in low-value noise.


### Which vulnerability scanner offers the most accurate network security assessments?
Based on G2 reviews, Tenable Nessus is one of the clearest choices for accurate network-focused assessments. According to verified users, it is praised for high scanning accuracy, broad plugin coverage, clear reports, and fast identification of vulnerabilities across networks and hybrid environments. G2 reviewers mention that it helps uncover hidden issues, supports regular scanning, and provides actionable remediation tips that make findings easier to address. Other products in the dataset also support network visibility, but Nessus is the one most directly associated in recent reviews with accurate, dependable vulnerability assessments for network assets and infrastructure.




## G2 Grid® for Vulnerability Scanner Software
![G2 Grid® for Vulnerability Scanner Software plotting products by satisfaction and market presence](https://www.g2.com/categories/vulnerability-scanner/grids.png?focus%5B%5D=146504&focus%5B%5D=1259627&focus%5B%5D=123609&focus%5B%5D=32494&focus%5B%5D=154599&focus%5B%5D=27706&focus%5B%5D=151443&focus%5B%5D=20460)
Highlighted products: Wiz, Aikido Security, Orca Security, Tenable Nessus, Astra Pentest, Intruder, CrowdStrike Falcon Cloud Security, and Sysdig Secure.
Underlying data: [Grid® JSON](https://www.g2.com/categories/vulnerability-scanner/grids.json?focus%5B%5D=wiz-wiz&amp;focus%5B%5D=aikido-security&amp;focus%5B%5D=orca-security&amp;focus%5B%5D=tenable-nessus&amp;focus%5B%5D=astra-pentest&amp;focus%5B%5D=intruder&amp;focus%5B%5D=crowdstrike-falcon-cloud-security&amp;focus%5B%5D=sysdig-sysdig-secure)


## How Many Vulnerability Scanner Software Products Does G2 Track?
**Total Products under this Category:** 223

### Category Stats (Jul 2026)
- **Average Rating**: 4.58/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product**: Finite State (+1.95%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month
*Last updated: July 21, 2026*


## How Does G2 Rank Vulnerability Scanner Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 7,500+ Authentic Reviews
- 223+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.


## Which Vulnerability Scanner Software Is Best for Your Use Case?

- **Leader:** [Wiz](https://www.g2.com/products/wiz-wiz/reviews)
- **Highest Performer:** [BugDazz API Scanner](https://www.g2.com/products/bugdazz-api-scanner/reviews)
- **Easiest to Use:** [Orca Security](https://www.g2.com/products/orca-security/reviews)
- **Top Trending:** [Aikido Security](https://www.g2.com/products/aikido-security/reviews)
- **Best Free Software:** [Wiz](https://www.g2.com/products/wiz-wiz/reviews)


---

**Sponsored**

### Spekit

Spekit is the Rep Acceleration Platform that turns GTM knowledge and unified deal intelligence into in-workflow insights, coaching, actions and buyer-ready experiences, so revenue teams can ramp fast, stay fast, and win more.



[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&amp;secure%5Bad_slot%5D=category_product_list&amp;secure%5Bcategory_id%5D=1423&amp;secure%5Bchosen_at%5D=2026-07-22T10%3A49%3A43Z&amp;secure%5Bdisplayable_resource_id%5D=1033&amp;secure%5Bdisplayable_resource_type%5D=Category&amp;secure%5Bmedium%5D=sponsored&amp;secure%5Bplacement_reason%5D=retargeted_product&amp;secure%5Bplacement_resource_ids%5D%5B%5D=59578&amp;secure%5Bprioritized%5D=false&amp;secure%5Bproduct_id%5D=59578&amp;secure%5Bresource_id%5D=1423&amp;secure%5Bresource_type%5D=Category&amp;secure%5Bsource_type%5D=llm_category_page&amp;secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fvulnerability-scanner&amp;secure%5Btoken%5D=41ba6b564263eea038ae5c00301900e079c7c6dcf83f96e4121be7f43cff1d94&amp;secure%5Burl%5D=https%3A%2F%2Fspekit.com%2F&amp;secure%5Burl_type%5D=company_website)

---


## Vulnerability Scanner Software Features & Capabilities

### What are the Best Vulnerability Scanner Software with Compliance Testing?
Allows users to scan applications and networks for specific compliance requirements.

**Top-rated Vulnerability Scanner Software for Compliance Testing:**
- [Wiz](https://www.g2.com/products/wiz-wiz/reviews)
- [Aikido Security](https://www.g2.com/products/aikido-security/reviews)
- [Orca Security](https://www.g2.com/products/orca-security/reviews)
[Explore Vulnerability Scanner Software with Compliance Testing](https://www.g2.com/categories/vulnerability-scanner/f/compliance-testing)

### What are the Best Vulnerability Scanner Software with Perimeter Scanning?
Analyzes network devices, servers and operating systems for vulnerabilities.

**Top-rated Vulnerability Scanner Software for Perimeter Scanning:**
- [Wiz](https://www.g2.com/products/wiz-wiz/reviews)
- [Aikido Security](https://www.g2.com/products/aikido-security/reviews)
- [Orca Security](https://www.g2.com/products/orca-security/reviews)
[Explore Vulnerability Scanner Software with Perimeter Scanning](https://www.g2.com/categories/vulnerability-scanner/f/perimeter-scanning)

### What are the Best Vulnerability Scanner Software with Manual Application Testing?
Allows users to perfrom hands-on live simulations and penetration tests.

**Top-rated Vulnerability Scanner Software for Manual Application Testing:**
- [Aikido Security](https://www.g2.com/products/aikido-security/reviews)
- [Orca Security](https://www.g2.com/products/orca-security/reviews)
- [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews)
[Explore Vulnerability Scanner Software with Manual Application Testing](https://www.g2.com/categories/vulnerability-scanner/f/manual-application-testing)

### What are the Best Vulnerability Scanner Software with Static Code Analysis?
Scans application source code for security flaws without executing it.

**Top-rated Vulnerability Scanner Software for Static Code Analysis:**
- [Aikido Security](https://www.g2.com/products/aikido-security/reviews)
- [Orca Security](https://www.g2.com/products/orca-security/reviews)
- [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews)
[Explore Vulnerability Scanner Software with Static Code Analysis](https://www.g2.com/categories/vulnerability-scanner/f/static-code-analysis)

### What are the Best Vulnerability Scanner Software with Automated Scans?
Runs pre-scripted vulnerability scans without requiring manual work.

**Top-rated Vulnerability Scanner Software for Automated Scans:**
- [Wiz](https://www.g2.com/products/wiz-wiz/reviews)
- [Aikido Security](https://www.g2.com/products/aikido-security/reviews)
- [Orca Security](https://www.g2.com/products/orca-security/reviews)
[Explore Vulnerability Scanner Software with Automated Scans](https://www.g2.com/categories/vulnerability-scanner/f/automated-scans)


## What Are the Top-Rated Vulnerability Scanner Software Products in 2026?
### 1. [Aqua Security](https://www.g2.com/products/aqua-security/reviews)
Aqua Security sees and stops attacks across the entire cloud native application lifecycle in a single, integrated platform. From software supply chain security for developers to cloud security and runtime protection for security teams, Aqua helps customers reduce risk while building the future of their businesses. The Aqua Platform is the industry’s most comprehensive Cloud Native Application Protection Platform (CNAPP). Founded in 2015, Aqua is headquartered in Boston, MA and Ramat Gan, IL with Fortune 1000 customers in over 40 countries.


**Average Rating:** 4.2/5.0
**Total Reviews:** 57
**How Do G2 Users Rate Aqua Security?**

- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 9.2/10)
- **Detection Rate:** 7.7/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.3/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 6.8/10 (Category avg: 8.4/10)

**Who Is the Company Behind Aqua Security?**

- **Seller:** [Aqua Security Software Ltd](https://www.g2.com/sellers/aqua-security-software-ltd)
- **Year Founded:** 2015
- **HQ Location:** Burlington, US
- **Twitter:** @AquaSecTeam (7,673 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/aquasecteam/ (466 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer Software, Financial Services
- **Company Size:** 56% Enterprise, 39% Mid-Market


#### What Are Aqua Security's Pros and Cons?

**Pros:**

- Security (18 reviews)
- Ease of Use (15 reviews)
- Detection (10 reviews)
- Features (10 reviews)
- Comprehensive Security (8 reviews)

**Cons:**

- Missing Features (7 reviews)
- Lack of Features (5 reviews)
- Improvement Needed (4 reviews)
- Limited Features (4 reviews)
- Complexity (3 reviews)


### What Do G2 Reviewers Say About Aqua Security?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value Aqua Security&#39;s **proactive threat intelligence** and comprehensive approach, ensuring robust protection for their code.
- Users commend the **ease of use** of Aqua Security, highlighting its intuitive UI and smooth implementation process.
- Users value Aqua Security for its **effective detection** of vulnerabilities, providing insightful security solutions and proactive threat intelligence.
- Users value the **extensive security insights** and intuitiveness of Aqua Security, enhancing their development process significantly.
- Users value the **comprehensive security** features of Aqua Security, simplifying container management and enhancing protection effectiveness.

**Cons:**

- Users note the **missing features** in Aqua Security, including limited integration, reporting, and drill-down capabilities.
- Users note a **lack of features** , limiting functionality and making analysis cumbersome with basic metrics and read-only visuals.
- Users indicate that **improvement is needed** in widget functionality, reporting, and integration for better usability.
- Users find Aqua Security&#39;s features **limited** , lacking crucial functionalities like dark mode and enhanced reporting capabilities.
- Users find Aqua Security&#39;s **complex interface** and setup process challenging, requiring significant technical knowledge and documentation.

#### What Are Recent G2 Reviews of Aqua Security?

**"[AquaSec have been very efficient and user friendly.](https://www.g2.com/survey_responses/aqua-security-review-7802942)"**

**Rating:** 5.0/5.0 stars
*— Adefolarin B.*

[Read full review](https://www.g2.com/survey_responses/aqua-security-review-7802942)

---

**"[Allows us to monitor security of or platforms and scan images easily.](https://www.g2.com/survey_responses/aqua-security-review-10502217)"**

**Rating:** 5.0/5.0 stars
*— Mitchell M.*

[Read full review](https://www.g2.com/survey_responses/aqua-security-review-10502217)

---



### 2. [Bright Security](https://www.g2.com/products/bright-security/reviews)
Bright Security’s dev-centric DAST platform empowers both developers and AppSec professionals with enterprise-grade security testing capabilities for web applications, APIs, and GenAI and LLM applications. Bright knows how to deliver the right tests, at the right time in the SDLC, in developers and AppSec tools and stacks of choice with minimal false positives and alert fatigue.


**Average Rating:** 4.7/5.0
**Total Reviews:** 29
**How Do G2 Users Rate Bright Security?**

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 9.2/10)
- **Detection Rate:** 7.8/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.3/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.3/10 (Category avg: 8.4/10)

**Who Is the Company Behind Bright Security?**

- **Seller:** [Bright Security ](https://www.g2.com/sellers/bright-security)
- **Year Founded:** 2018
- **HQ Location:** San Rafael
- **Twitter:** @BrightAppSec (1,511 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/brightappsec (111 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer &amp; Network Security, Information Technology and Services
- **Company Size:** 52% Enterprise, 34% Mid-Market


#### What Are Bright Security's Pros and Cons?

**Pros:**

- Accuracy of Results (4 reviews)
- Automated Scanning (4 reviews)
- Ease of Use (4 reviews)
- Detection (3 reviews)
- Easy Integrations (3 reviews)

**Cons:**

- Learning Curve (3 reviews)
- Complex Setup (2 reviews)
- Setup Complexity (2 reviews)
- Complexity (1 reviews)
- Confusing Interface (1 reviews)


### What Do G2 Reviewers Say About Bright Security?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **accuracy of results** from Bright Security, allowing focus on genuine vulnerabilities in development.
- Users value the **modern and efficient automated scanning** of Bright Security, enhancing the development workflow with relevant actionable insights.
- Users praise the **ease of use** of Bright Security, highlighting its seamless integration into modern development workflows.
- Users value the **effective detection of relevant vulnerabilities** by Bright Security, enhancing workflow and simplifying remediation.
- Users value the **easy integrations** of Bright Security, enhancing their CI/CD workflows without hindering deployment speed.

**Cons:**

- Users experience a **steep learning curve** with Bright Security, especially during the initial setup and configuration process.
- Users find the **complex setup** challenging, especially with a steep learning curve for configurations and customization.
- Users find the **setup complexity** challenging, particularly due to the learning curve for scan configurations.
- Users find the **complexity of initial setup** challenging and suggest improved onboarding for better understanding.
- Users find the **confusing interface** of Bright Security challenging, struggling to navigate the dense dashboard and settings.

#### What Are Recent G2 Reviews of Bright Security?

**"[Modern, Insightful, and Seamlessly Fits Our Workflow](https://www.g2.com/survey_responses/bright-security-review-12164035)"**

**Rating:** 4.5/5.0 stars
*— Gauri K.*

[Read full review](https://www.g2.com/survey_responses/bright-security-review-12164035)

---

**"[Reliable and Developer-Friendly Security Solution](https://www.g2.com/survey_responses/bright-security-review-12157897)"**

**Rating:** 4.5/5.0 stars
*— John S.*

[Read full review](https://www.g2.com/survey_responses/bright-security-review-12157897)

---



### 3. [Contrast Security](https://www.g2.com/products/contrast-security-contrast-security/reviews)
Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous, real-time defense, Contrast uncovers hidden application layer risks that traditional solutions miss. Contrast’s powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.


**Average Rating:** 4.5/5.0
**Total Reviews:** 49
**How Do G2 Users Rate Contrast Security?**

- **Has the product been a good partner in doing business?:** 9.0/10 (Category avg: 9.2/10)

**Who Is the Company Behind Contrast Security?**

- **Seller:** [Contrast Security](https://www.g2.com/sellers/contrast-security)
- **Company Website:** https://contrastsecurity.com
- **Year Founded:** 2014
- **HQ Location:** Pleasanton, CA
- **Twitter:** @contrastsec (5,468 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/contrast-security/ (196 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Insurance, Information Technology and Services
- **Company Size:** 67% Enterprise, 20% Mid-Market


#### What Are Contrast Security's Pros and Cons?

**Pros:**

- Accuracy of Findings (2 reviews)
- Accuracy of Results (2 reviews)
- Vulnerability Detection (2 reviews)
- Automated Scanning (1 reviews)
- Automation (1 reviews)

**Cons:**

- Complex Setup (1 reviews)
- Difficult Setup (1 reviews)
- Performance Issues (1 reviews)
- Problematic Updates (1 reviews)
- Setup Complexity (1 reviews)


### What Do G2 Reviewers Say About Contrast Security?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **accuracy of findings** from Contrast Security, ensuring greater precision in identifying vulnerabilities.
- Users value the **accuracy of results** from Contrast Security, benefiting from precise vulnerability monitoring and analysis.
- Users commend the **real-time vulnerability detection** of Contrast Security, appreciating its quick feedback and agile support.
- Users commend the **real-time vulnerability detection** of Contrast Security, appreciating its quick turnaround and excellent support.
- Users value the **real-time security testing** and excellent support from Contrast Security, enhancing their overall security posture.

**Cons:**

- Users experienced **performance issues** with Contrast Security, particularly with Java applications, but found support helpful in resolving them.

#### What Are Recent G2 Reviews of Contrast Security?

**"[Shift-Smart with Contrast](https://www.g2.com/survey_responses/contrast-security-review-8492224)"**

**Rating:** 5.0/5.0 stars
*— Kiran S.*

[Read full review](https://www.g2.com/survey_responses/contrast-security-review-8492224)

---

**"[Contrast Security makes application security simple](https://www.g2.com/survey_responses/contrast-security-review-8516563)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Higher Education*

[Read full review](https://www.g2.com/survey_responses/contrast-security-review-8516563)

---


#### What Are G2 Users Discussing About Contrast Security?

- [What is contrast protect?](https://www.g2.com/discussions/what-is-contrast-protect)
- [Is Contrast security SaaS?](https://www.g2.com/discussions/is-contrast-security-saas)
- [What is Contrast security tool?](https://www.g2.com/discussions/what-is-contrast-security-tool)
- [What does contrast security do?](https://www.g2.com/discussions/what-does-contrast-security-do)

### 4. [Probely](https://www.g2.com/products/probely/reviews)
Probely is a web vulnerability scanner that enables customers to easily test the security of their Web Applications &amp; APIs. Our goal is to narrow the gap between development, security, and operations by making security an intrinsic characteristic of web applications development life-cycle, and only report security vulnerabilities that matter, false-positive free and with simple instructions on how to fix them. Probely allows Security teams to efficiently scale security testing by shifting security testing to Development or DevOps teams. We adapt to our customers’ internal processes and integrate Probely into their stack. Probely scan restful APIs, websites, and complex web applications, including rich Javascript applications such as single-page applications (SPA). It detects over 20,000 vulnerabilities, including SQL injection, Cross-Site Scripting (XSS), Log4j, OS Command Injection, and SSL/TLS issues.


**Average Rating:** 4.7/5.0
**Total Reviews:** 19
**How Do G2 Users Rate Probely?**

- **Has the product been a good partner in doing business?:** 9.8/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.6/10 (Category avg: 8.9/10)
- **Automated Scans:** 10.0/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 9.2/10 (Category avg: 8.4/10)

**Who Is the Company Behind Probely?**

- **Seller:** [Probely](https://www.g2.com/sellers/probely)
- **Year Founded:** 2016
- **HQ Location:** Porto, PT
- **Twitter:** @probely (527 Twitter followers)
- **LinkedIn® Page:** https://pt.linkedin.com/company/probely (3 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 47% Small-Business, 37% Mid-Market



#### What Are Recent G2 Reviews of Probely?

**"[My to go API and DAST vulnerability scanner](https://www.g2.com/survey_responses/probely-review-9400661)"**

**Rating:** 5.0/5.0 stars
*— Valentina G.*

[Read full review](https://www.g2.com/survey_responses/probely-review-9400661)

---

**"[Effective DAST scanner, enhances security](https://www.g2.com/survey_responses/probely-review-9238375)"**

**Rating:** 5.0/5.0 stars
*— Cekna B.*

[Read full review](https://www.g2.com/survey_responses/probely-review-9238375)

---


#### What Are G2 Users Discussing About Probely?

- [What is Probely used for?](https://www.g2.com/discussions/what-is-probely-used-for)

### 5. [Evolve Security](https://www.g2.com/products/evolve-security-evolve-security/reviews)
Evolve Security&#39;s patent pending Darwin Attack® platform is a comprehensive collaboration and management tool designed to help organizations manage their cybersecurity services and reduce risks of successful cyberattacks. The platform serves as a repository for research, vulnerability and attack details, compliance requirements, remediation recommendations, and mitigating controls. It also functions as a security feed, collaboration tool, tracking tool, management platform, and reporting platform. The platform enables organizations to actively manage their security program by providing real-time updates on testing progress and findings, which allows for timely remediation. Darwin Attack® is constantly updated with new information and functionality to ensure that it remains effective and efficient in meeting the needs of Evolve Security&#39;s clients.


**Average Rating:** 4.8/5.0
**Total Reviews:** 53
**How Do G2 Users Rate Evolve Security?**

- **Has the product been a good partner in doing business?:** 9.8/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.2/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.2/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.6/10 (Category avg: 8.4/10)

**Who Is the Company Behind Evolve Security?**

- **Seller:** [Evolve Security](https://www.g2.com/sellers/evolve-security)
- **Year Founded:** 2016
- **HQ Location:** Chicago, Illinois
- **Twitter:** @theevolvesec (788 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/evolve-security/ (65 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Financial Services
- **Company Size:** 70% Mid-Market, 21% Small-Business


#### What Are Evolve Security's Pros and Cons?

**Pros:**

- Actionable Intelligence (2 reviews)
- Vulnerability Detection (2 reviews)
- Vulnerability Identification (2 reviews)
- Audit Support (1 reviews)
- Communication (1 reviews)



### What Do G2 Reviewers Say About Evolve Security?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **actionable intelligence** provided by Evolve Security, enhancing their ability to address vulnerabilities effectively.
- Users value the **effective vulnerability detection** and guidance provided by Evolve Security&#39;s expert team.
- Users commend Evolve Security&#39;s **effective vulnerability identification** , providing clear instructions and communication throughout the process.
- Users value the **thorough audit support** provided, ensuring clear communication and effective remediation of vulnerabilities.
- Users commend the **excellent communication** from Evolve Security, facilitating clear understanding and collaboration during pentesting.


#### What Are Recent G2 Reviews of Evolve Security?

**"[Professional, Well-Managed ASM and Pen Testing Experience](https://www.g2.com/survey_responses/evolve-security-review-12743932)"**

**Rating:** 5.0/5.0 stars
*— Kevin C.*

[Read full review](https://www.g2.com/survey_responses/evolve-security-review-12743932)

---

**"[Outstanding Cybersecurity Partner with Thorough, Actionable Pen Testing](https://www.g2.com/survey_responses/evolve-security-review-13059557)"**

**Rating:** 5.0/5.0 stars
*— Lesly V.*

[Read full review](https://www.g2.com/survey_responses/evolve-security-review-13059557)

---



### 6. [Cyrisma](https://www.g2.com/products/cyrisma/reviews)
Cyrisma helps MSPs and MSSPs turn cyber risk and compliance into revenue. Its unified platform combines vulnerability management, data and asset discovery, compliance tracking, secure configuration, and dark web monitoring into one continuous experience - enabling partners to identify, prioritize, and remediate cyber risk efficiently. With executive-ready reporting, risk monetization insights, and elegant visuals, Cyrisma helps MSPs demonstrate measurable value, strengthen client relationships, and scale their security services profitably.


**Average Rating:** 4.6/5.0
**Total Reviews:** 60
**How Do G2 Users Rate Cyrisma?**

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.7/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.7/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 7.9/10 (Category avg: 8.4/10)

**Who Is the Company Behind Cyrisma?**

- **Seller:** [Cyrisma](https://www.g2.com/sellers/cyrisma)
- **Company Website:** https://www.cyrisma.com/
- **Year Founded:** 2018
- **HQ Location:** Rochester, NY
- **Twitter:** @Cyrisma_USA (43 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/cyrisma/ (14 employees on LinkedIn®)

**Who Uses This Product?**
- **Who Uses This:** CEO
- **Top Industries:** Information Technology and Services, Computer &amp; Network Security
- **Company Size:** 75% Small-Business, 22% Mid-Market


#### What Are Cyrisma's Pros and Cons?

**Pros:**

- Time-saving (12 reviews)
- Ease of Use (10 reviews)
- Customer Support (9 reviews)
- Features (8 reviews)
- Vulnerability Identification (8 reviews)

**Cons:**

- Missing Features (4 reviews)
- Not User-Friendly (4 reviews)
- Limited Flexibility (3 reviews)
- Poor Interface Design (3 reviews)
- Poor Navigation (3 reviews)


### What Do G2 Reviewers Say About Cyrisma?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **time-saving features** of Cyrisma, streamlining cybersecurity tasks and enhancing overall efficiency.
- Users appreciate the **intuitive platform** of Cyrisma, making cybersecurity management efficient and straightforward.
- Users commend the **fantastic customer support** of Cyrisma, valuing their responsiveness and helpfulness during product usage.
- Users value the **actionable vulnerability intelligence** of Cyrisma, appreciating its user-friendly dashboard and comprehensive coverage.
- Users love CYRISMA for its **actionable vulnerability intelligence** , streamlining security management with ease and clarity.

**Cons:**

- Users express concerns about **missing features** like better UI, data correlation, and effective patch management in Cyrisma.
- Users find Cyrisma&#39;s interface to be **not user-friendly** , complicating navigation and hindering overall usability and support experience.
- Users feel Cyrisma has **limited flexibility** , finding navigation complex and agent deployment unnecessarily cumbersome.
- Users find the **poor interface design** of Cyrisma challenging, hindering navigation and access to key insights.
- Users find **navigation challenging** in Cyrisma, complicating access to insights and hindering overall usability.

#### What Are Recent G2 Reviews of Cyrisma?

**"[CYRISMA offers strong consolidation value, needs enhancements in data correlation &amp; patch coverage](https://www.g2.com/survey_responses/cyrisma-review-11229216)"**

**Rating:** 4.0/5.0 stars
*— Jathin D.*

[Read full review](https://www.g2.com/survey_responses/cyrisma-review-11229216)

---

**"[Effortless Penetration Testing with CYRISMA](https://www.g2.com/survey_responses/cyrisma-review-12781999)"**

**Rating:** 5.0/5.0 stars
*— Sarah M.*

[Read full review](https://www.g2.com/survey_responses/cyrisma-review-12781999)

---



### 7. [Gomboc.AI](https://www.g2.com/products/gomboc-ai/reviews)
Gomboc.AI is a platform engineering solution redefining AI Code Security Assistants (ACSA) for cloud and Infrastructure-as-Code environments. Built for DevOps and platform engineering teams, Gomboc focuses on closing the gap between security findings and reliable remediation. While many AI Code Security Assistants emphasize detection or inline suggestions, Gomboc applies deterministic AI to execute remediation directly in code. When an issue is identified, Gomboc generates a production-ready, standards-aligned code fix and delivers it as a merge-ready pull request through Git and CI/CD workflows. This approach eliminates manual triage, reduces remediation cycles, and helps teams scale secure infrastructure without slowing delivery.


**Average Rating:** 4.0/5.0
**Total Reviews:** 28
**How Do G2 Users Rate Gomboc.AI?**

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.2/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.4/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 9.2/10 (Category avg: 8.4/10)

**Who Is the Company Behind Gomboc.AI?**

- **Seller:** [Gomboc.AI](https://www.g2.com/sellers/gomboc-ai)
- **Company Website:** https://www.gomboc.ai
- **Year Founded:** 2022
- **HQ Location:** New York, US
- **LinkedIn® Page:** https://www.linkedin.com/company/gomboc-ai (20 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 21% Mid-Market, 11% Enterprise


#### What Are Gomboc.AI's Pros and Cons?

**Pros:**

- Ease of Use (15 reviews)
- Setup Ease (13 reviews)
- Automation (8 reviews)
- Security (7 reviews)
- Easy Integrations (4 reviews)

**Cons:**

- Complex Setup (6 reviews)
- Bugs (2 reviews)
- Expensive (2 reviews)
- Integration Issues (2 reviews)
- Complexity (1 reviews)


### What Do G2 Reviewers Say About Gomboc.AI?
*AI-generated summary from verified user reviews*

**Pros:**

- Users praise the **ease of use** of Gomboc.AI, appreciating its straightforward setup and seamless integration with Visual Studio Code.
- Users appreciate the **simple setup** of Gomboc.AI, making it easy to get started with code scanning.
- Users value the **automation** of Gomboc.AI for its accurate, efficient, and contextual security risk remediations.
- Users value the **enhanced security features** of Gomboc.AI, providing actionable insights for robust Kubernetes protection.
- Users value the **easy integrations** of Gomboc.AI with VS Code, enhancing focus and efficiency in their workflows.

**Cons:**

- Users find the **setup complex** , requiring significant time and expertise to configure Gomboc.AI effectively.
- Users experience **bugs and misleading detection** , complicating integration and requiring additional support for effective use.
- Users find Gomboc.AI to be **a little on the expensive side** , especially when considering scaling needs in the future.
- Users face **integration issues** with Gomboc.AI, particularly due to limited support for IaCs and complex setups.
- Users find the **integration complexity** of Gomboc.AI challenging, needing significant effort in existing CI/CD pipelines.

#### What Are Recent G2 Reviews of Gomboc.AI?

**"[Effortless Vulnerability Detection &amp; Fixing in Infrastructure Code](https://www.g2.com/survey_responses/gomboc-ai-review-12792444)"**

**Rating:** 4.5/5.0 stars
*— Sushant S.*

[Read full review](https://www.g2.com/survey_responses/gomboc-ai-review-12792444)

---

**"[Secure Cloud Fixes Without Extra Manual Work](https://www.g2.com/survey_responses/gomboc-ai-review-12824282)"**

**Rating:** 4.0/5.0 stars
*— Krishna V.*

[Read full review](https://www.g2.com/survey_responses/gomboc-ai-review-12824282)

---



### 8. [StackHawk](https://www.g2.com/products/stackhawk/reviews)
StackHawk is reimagining AppSec for AI-driven development, where applications are built faster than traditional AppSec tools can keep up. Our AppSec Intelligence Platform combines scalable runtime testing with complete attack surface discovery from source code. We integrate directly into development workflows and provide context-aware remediations to developers, enabling teams to find and fix exploitable vulnerabilities before they reach production. With real-time visibility and centralized program intelligence, AppSec teams can prioritize testing and fixing what matters. Companies like British Airways, ITV, and Norstella trust StackHawk to evaluate application risk, prove program value, and scale testing coverage to match development velocity.


**Average Rating:** 4.6/5.0
**Total Reviews:** 67
**How Do G2 Users Rate StackHawk?**

- **Has the product been a good partner in doing business?:** 9.1/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.7/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.7/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 5.3/10 (Category avg: 8.4/10)

**Who Is the Company Behind StackHawk?**

- **Seller:** [StackHawk](https://www.g2.com/sellers/stackhawk)
- **Year Founded:** 2019
- **HQ Location:** Denver, CO
- **Twitter:** @StackHawk (1,137 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/40780406/ (31 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 46% Small-Business, 35% Mid-Market


#### What Are StackHawk's Pros and Cons?

**Pros:**

- Easy Integrations (4 reviews)
- Customer Support (3 reviews)
- Customizability (3 reviews)
- Efficiency Improvement (3 reviews)
- Scanning Efficiency (3 reviews)

**Cons:**

- Complex Setup (3 reviews)
- High Learning Curve (3 reviews)
- Lacking Features (3 reviews)
- Limited Scope (3 reviews)
- Setup Complexity (3 reviews)


### What Do G2 Reviewers Say About StackHawk?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **easy integrations** of StackHawk, enhancing CI/CD pipelines and streamlining the onboarding process.
- Users commend StackHawk for its **exceptional customer support** , providing expert assistance and enhancing the overall user experience.
- Users value the **customizability** of StackHawk, appreciating its flexibility and integration options for unique workflows.
- Users find that StackHawk greatly enhances **efficiency** , enabling quicker identification and resolution of security vulnerabilities.
- Users value the **scanning efficiency** of StackHawk, enabling faster and more effective security scanning processes.

**Cons:**

- Users find the **complex setup** process frustrating due to the lack of simplified documentation and time-consuming configurations.
- Users face a **high learning curve** with StackHawk due to its complex setup and scripting requirements.
- Users find StackHawk **lacking features** , especially in API management and intuitive setup, hindering vulnerability management.
- Users note the **limited scope** of StackHawk, particularly regarding on-prem usage and automation capabilities.
- Users find **setup complexity** frustrating, as extensive YAML config trials are necessary for effective onboarding and scans.

#### What Are Recent G2 Reviews of StackHawk?

**"[StackHawk is a great DAST security tool](https://www.g2.com/survey_responses/stackhawk-review-10761348)"**

**Rating:** 5.0/5.0 stars
*— David M.*

[Read full review](https://www.g2.com/survey_responses/stackhawk-review-10761348)

---

**"[A Game-Changer for DevSecOps](https://www.g2.com/survey_responses/stackhawk-review-8847655)"**

**Rating:** 5.0/5.0 stars
*— Todd L.*

[Read full review](https://www.g2.com/survey_responses/stackhawk-review-8847655)

---


#### What Are G2 Users Discussing About StackHawk?

- [What is StackHawk used for?](https://www.g2.com/discussions/what-is-stackhawk-used-for)

### 9. [Threatspy](https://www.g2.com/products/secure-blink-threatspy/reviews)
ThreatSpy is an Autonomous Application &amp; API Security platform designed to help organizations discover, validate, prioritize, and remediate security vulnerabilities faster. Traditional security tools often generate large volumes of findings, leaving security and engineering teams to manually determine what is exploitable and what should be fixed first. ThreatSpy helps eliminate that noise by combining Dynamic Application Security Testing (DAST), API Security Testing, exploitability validation, reachability-based prioritization, and AI-assisted security review into a single workflow. ThreatSpy continuously evaluates web applications and APIs to identify both known vulnerabilities and hidden security weaknesses, helping teams focus on risks that have real business impact. The platform provides contextual remediation guidance, workflow integrations, and executive-level visibility to improve collaboration between security and development teams.


**Average Rating:** 4.7/5.0
**Total Reviews:** 24
**How Do G2 Users Rate Threatspy?**

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.7/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.4/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 9.7/10 (Category avg: 8.4/10)

**Who Is the Company Behind Threatspy?**

- **Seller:** [Secure Blink](https://www.g2.com/sellers/secure-blink)
- **Year Founded:** 2020
- **HQ Location:** Lewes, Delaware
- **LinkedIn® Page:** https://www.linkedin.com/company/secure-blink/ (10 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services
- **Company Size:** 42% Mid-Market, 42% Small-Business


#### What Are Threatspy's Pros and Cons?

**Pros:**

- Security (6 reviews)
- Ease of Use (5 reviews)
- Vulnerability Identification (5 reviews)
- Customer Support (4 reviews)
- Efficiency Improvement (3 reviews)

**Cons:**

- Limited Customization (1 reviews)
- Poor Customer Support (1 reviews)
- Slow Scanning (1 reviews)
- Vulnerability Management (1 reviews)


### What Do G2 Reviewers Say About Threatspy?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **efficient threat detection** of Threatspy, providing peace of mind and excellent customer support.
- Users find Threatspy&#39;s interface particularly **easy to use** , enabling seamless threat detection and management for everyone.
- Users value the **quick threat detection capabilities** of Threatspy, enhancing security and simplifying vulnerability management.
- Users appreciate the **helpful customer support** from Threatspy, enhancing their overall experience with the tool.
- Users value the **improved efficiency** of Threatspy, which streamlines workflows and reduces alert fatigue for security teams.

**Cons:**

- Users find that Threatspy offers **limited customization** , restricting tailored testing and deeper scan options for their needs.
- Users express concerns about **poor customer support** , which detracts from the overall value of Threatspy.
- Users report experiencing **sluggish performance during scans** , which affects the overall efficiency of Threatspy.
- Users find that Threatspy has **limited detection of complex exploits** and lacks customization for tailored vulnerability assessments.

#### What Are Recent G2 Reviews of Threatspy?

**"[Threatspy: Identifying Vulnerabilities Using This Amazing Software Is Simple and Fast](https://www.g2.com/survey_responses/threatspy-review-9325982)"**

**Rating:** 5.0/5.0 stars
*— Puzone C.*

[Read full review](https://www.g2.com/survey_responses/threatspy-review-9325982)

---

**"[ThreatSpy: Identifying Threats Using this Wonderful Software is So Easy: A Brilliant Tool for All](https://www.g2.com/survey_responses/threatspy-review-9376248)"**

**Rating:** 5.0/5.0 stars
*— Emanuela V.*

[Read full review](https://www.g2.com/survey_responses/threatspy-review-9376248)

---



### 10. [Defendify All-In-One Cybersecurity Solution](https://www.g2.com/products/defendify-all-in-one-cybersecurity-solution/reviews)
Founded in 2017, Defendify is pioneering All-In-One Cybersecurity® for organizations with growing security needs, backed by experts offering ongoing guidance and support. Delivering multiple layers of protection, Defendify provides an all-in-one, easy-to-use platform designed to strengthen cybersecurity across people, process, and technology, continuously. With Defendify, organizations streamline cybersecurity assessments, testing, policies, training, detection, response &amp; containment in one consolidated and cost-effective cybersecurity solution. 3 layers, 13 solutions, 1 platform, including: • Managed Detection &amp; Response • Cyber Incident Response Plan • Cybersecurity Threat Alerts • Phishing Simulations • Cybersecurity Awareness Training • Cybersecurity Awareness Videos • Cybersecurity Awareness Posters &amp; Graphics • Technology Acceptable Use Policy • Cybersecurity Risk Assessments • Penetration Testing • Vulnerability Scanning • Compromised Password Scanning • Website Security Scanning See Defendify in action at www.defendify.com.


**Average Rating:** 4.7/5.0
**Total Reviews:** 57
**How Do G2 Users Rate Defendify All-In-One Cybersecurity Solution?**

- **Has the product been a good partner in doing business?:** 9.8/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.2/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.4/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.9/10 (Category avg: 8.4/10)

**Who Is the Company Behind Defendify All-In-One Cybersecurity Solution?**

- **Seller:** [Defendify](https://www.g2.com/sellers/defendify)
- **Year Founded:** 2017
- **HQ Location:** Portland, Maine
- **Twitter:** @defendify (305 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/11098948/ (37 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer &amp; Network Security
- **Company Size:** 65% Small-Business, 35% Mid-Market


#### What Are Defendify All-In-One Cybersecurity Solution's Pros and Cons?

**Pros:**

- Ease of Use (8 reviews)
- Cybersecurity (6 reviews)
- Easy Setup (5 reviews)
- Insights (5 reviews)
- Monitoring (5 reviews)

**Cons:**

- Inadequate Reporting (4 reviews)
- Poor Reporting (4 reviews)
- Lack of Information (2 reviews)
- Limited Customization (2 reviews)
- Limited Features (2 reviews)


### What Do G2 Reviewers Say About Defendify All-In-One Cybersecurity Solution?
*AI-generated summary from verified user reviews*

**Pros:**

- Users highlight the **ease of use** of Defendify, streamlining cybersecurity management for organizations with limited resources.
- Users praise Defendify for its **comprehensive and cost-effective cybersecurity features** , streamlining management for small and medium-sized businesses.
- Users appreciate the **easy setup** of Defendify, making configuration and onboarding quick and efficient.
- Users value the **ease of use** of Defendify, enabling quick setup and clear insights into cybersecurity posture.
- Users value the **continuous monitoring** and ease of use of Defendify, enhancing their network security significantly.

**Cons:**

- Users note that the **reporting is inadequate** , desiring improvements like concise summaries and detailed penetration testing results.
- Users feel the **reporting could be improved** , expressing a need for more concise and detailed reports.
- Users feel the **lack of information** in reports diminishes clarity and thoroughness of penetration testing insights.
- Users find the **limited customization** options restrictive, desiring more flexibility in reports and branding features.
- Users find the lack of **custom reporting options** limits their ability to tailor insights for future needs.

#### What Are Recent G2 Reviews of Defendify All-In-One Cybersecurity Solution?

**"[Comprehensive and robust protection](https://www.g2.com/survey_responses/defendify-all-in-one-cybersecurity-solution-review-10560878)"**

**Rating:** 4.5/5.0 stars
*— Verified User in Computer &amp; Network Security*

[Read full review](https://www.g2.com/survey_responses/defendify-all-in-one-cybersecurity-solution-review-10560878)

---

**"[Perfect  Vulnerability Management for Software Companies](https://www.g2.com/survey_responses/defendify-all-in-one-cybersecurity-solution-review-10488301)"**

**Rating:** 4.5/5.0 stars
*— Akhil V.*

[Read full review](https://www.g2.com/survey_responses/defendify-all-in-one-cybersecurity-solution-review-10488301)

---


#### What Are G2 Users Discussing About Defendify All-In-One Cybersecurity Solution?

- [What is Defendify Cybersecurity Platform used for?](https://www.g2.com/discussions/what-is-defendify-cybersecurity-platform-used-for)

### 11. [DefectDojo](https://www.g2.com/products/defectdojo/reviews)
DefectDojo unifies and automates vulnerability management, enabling security teams to focus on strategic, data-driven analysis. We help teams reduce time spent on manual tracking and consolidate vulnerabilities from existing tools for seamless vulnerability management.


**Average Rating:** 4.6/5.0
**Total Reviews:** 11
**How Do G2 Users Rate DefectDojo?**

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.5/10 (Category avg: 8.9/10)
- **Automated Scans:** 6.9/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.3/10 (Category avg: 8.4/10)

**Who Is the Company Behind DefectDojo?**

- **Seller:** [DefectDojo](https://www.g2.com/sellers/defectdojo)
- **Year Founded:** 2017
- **HQ Location:** Austin, US
- **Twitter:** @defectdojo (699 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/defectdojo/ (27 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer &amp; Network Security
- **Company Size:** 64% Mid-Market, 36% Small-Business



#### What Are Recent G2 Reviews of DefectDojo?

**"[DefectDojo: Ultimate Vulnerability Management Solution](https://www.g2.com/survey_responses/defectdojo-review-9910554)"**

**Rating:** 4.5/5.0 stars
*— Anjali A.*

[Read full review](https://www.g2.com/survey_responses/defectdojo-review-9910554)

---

**"[A pertinacious and authentic platform for security programs in the organization](https://www.g2.com/survey_responses/defectdojo-review-9244500)"**

**Rating:** 4.5/5.0 stars
*— Henry E.*

[Read full review](https://www.g2.com/survey_responses/defectdojo-review-9244500)

---


#### What Are G2 Users Discussing About DefectDojo?

- [What is DefectDojo used for?](https://www.g2.com/discussions/what-is-defectdojo-used-for)

### 12. [ARMO Platform](https://www.g2.com/products/armo-platform/reviews)
ARMO Platform is the only runtime-driven, open-source first, cloud security platform. It is the only security platform that continuously minimizes cloud attack surface based on runtime insights, while actively detecting and responding to cyberattacks with real risk context. Using an eBPF-based runtime sensor to record application behavior and related activities, ARMO Platform enables DevOps, security, and platform teams to eliminate the security noise and go from thousands of irrelevant alerts to focus on the most important and exploitable threats. This allows those teams to shift from managing hypothetical security issues to mitigating actual risks and providing them with the means to remediate them. ARMO is an open-source-driven company and the creator of Kubescape, a leading open-source Kubernetes security project, now an official CNCF project. To learn more about ARMO Platform please visit: https://www.armosec.io/


**Average Rating:** 4.5/5.0
**Total Reviews:** 44
**How Do G2 Users Rate ARMO Platform?**

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.4/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.7/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.2/10 (Category avg: 8.4/10)

**Who Is the Company Behind ARMO Platform?**

- **Seller:** [ARMO](https://www.g2.com/sellers/armo)
- **Year Founded:** 2019
- **HQ Location:** Tel Aviv, IL
- **Twitter:** @armosec (3,074 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/armosec/ (96 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 59% Small-Business, 36% Mid-Market


#### What Are ARMO Platform's Pros and Cons?

**Pros:**

- Ease of Use (8 reviews)
- Features (8 reviews)
- Security (8 reviews)
- Deployment Ease (7 reviews)
- Container Security (6 reviews)

**Cons:**

- Integration Issues (5 reviews)
- Missing Features (4 reviews)
- Difficult Configuration (3 reviews)
- Complex Querying (2 reviews)
- Complex Setup (2 reviews)


### What Do G2 Reviewers Say About ARMO Platform?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **ease of use** of ARMO Platform, as it simplifies security operations and streamlines workflows.
- Users appreciate the **automation and integration features** of ARMO Platform, enhancing efficiency and simplifying security operations.
- Users value ARMO Platform for its **advanced security features** , enhancing Kubernetes application safety and compliance effortlessly.
- Users value the **deployment ease** of ARMO Platform, enabling quick setup and seamless integration with existing tools.
- Users value the **easy setup and automation** of ARMO Platform, enhancing security and compliance for cloud-native applications.

**Cons:**

- Users face **integration issues** with ARMO Platform that lead to disruptions and confusion during project work.
- Users experience **missing features** in ARMO Platform that hinder efficient project workflows and cause confusion during use.
- Users face a **difficult configuration** process on the ARMO Platform, requiring time and effort to master.
- Users face a noticeable **learning curve** with ARMO Platform&#39;s complex interface, impacting efficiency and integration ease.
- Users find the **complex setup** of ARMO Platform challenging, especially those with less experience in Kubernetes.

#### What Are Recent G2 Reviews of ARMO Platform?

**"[Game-Changer for Application Cluster Security &amp; Visibility](https://www.g2.com/survey_responses/armo-platform-review-11603726)"**

**Rating:** 5.0/5.0 stars
*— Jay N.*

[Read full review](https://www.g2.com/survey_responses/armo-platform-review-11603726)

---

**"[Streamlined Kubernetes Security with Actionable Remediations](https://www.g2.com/survey_responses/armo-platform-review-11159133)"**

**Rating:** 4.5/5.0 stars
*— Abhineet S.*

[Read full review](https://www.g2.com/survey_responses/armo-platform-review-11159133)

---


#### What Are G2 Users Discussing About ARMO Platform?

- [What is ARMO used for?](https://www.g2.com/discussions/what-is-armo-used-for)

### 13. [Runecast](https://www.g2.com/products/runecast/reviews)
Runecast is an enterprise CNAPP platform which saves your Security and Operations teams time and resources by enabling a proactive approach to ITOM, CSPM, and compliance. It helps you proactively remediate vulnerabilities for continuous compliance, whether on-prem, cloud or containers. By proactively using our agentless scanning in real-time admins discover potential risks and remediation solutions before any issues can develop into a major outage. Runecast’s AI-RAIKA, leverages advanced natural language processing (NLP) capabilities to interpret a vast amount of information to provide automated audits for security compliance standards, vulnerabilities (such as KEVs, CVEs or VMSAs) and technology vendor best practices. The platform has been recognized with Frost &amp; Sullivan&#39;s 2023 European New Product Innovation Award in the CNAPP industry for its strong overall performance and commitment to user experience. NAVIGATING YOUR COMPLEXITY Runecast helps teams with a simpler transition to cloud, enabling admins to fully understand their hybrid environments and Cloud Security Posture Management (CSPM) and Kubernetes Security Posture Management (KSPM). Running securely on-premises, it provides insights into what is happening both in the cloud and on-site. IMMEDIATE VALUE FOR TEAMS As Runecast helps teams to stabilize availability and ensure security compliance, it contributes also to greater ROI for both existing and future investments with AWS, Azure, Kubernetes and VMware. FULLY ON-PREM SECURE Operates fully on-prem to analyze your hybrid-cloud environment, so that your data remains safely on-site. To provide additional security, Runecast features a customizable, transparent rules engine. RUNECAST FOR SECURITY AND COMPLIANCE Vulnerability Management Regular automated scanning, recommendations, remediation, and the ability to set up vulnerability management policies are just some of the requirements many enterprises have. The Runecast platform is constantly updated to detect the latest vulnerabilities for all of the supported technologies. Container Security Runecast scans container images for known vulnerabilities and misconfigurations, and can also detect runtime issues such as exposed ports and running processes. It also provides a public API which can be used in your CI/CD platform to analyze the container images and whether they are vulnerable or not to known vulnerabilities, before deploying them in production. Compliance with Security Standards Runecast offers automated audits against security hardening guidelines and common industry standards like CIS Benchmarks, NIST 800-53, PCI DSS, HIPAA, DISA STIG 6, GDPR, KVKK (Turkey), ISO 27001, BSI IT-Grundschutz, Essential 8 and Cyber Essentials Security Standard. RUNECAST FOR IT OPERATIONS TEAMS Vendor Best Practices for Security Hardening Runecast continuously monitors your complex environment, reporting violations and providing recommendations against Vendor Best Practices. It maintains a database with Best Practices of the latest AWS, Azure, Kubernetes, GCP, VMware and Windows and Linux OS. It analyzes your environment to detect any configuration issues against Vendor Best Practices. This delivers valuable insights to improve the stability and security of your infrastructure. Configuration Vault Tracks your configuration to help you prevent drift. Reports your entire configuration and provides the ability to compare your configurations over time. Hardware Compatibility and Upgrade Stimulations Runecast has automated the process of validating the hardware compliance of hosts and clusters against a selected ESXi version, ensuring compliance with the VMware Compatibility Guide (VCG) and vSAN Hardware Compatibility List (vSAN HCL). The AI-powered platform runs a quick and automated analysis using the latest HCL for your servers, I/O devices, and vSAN controllers. For upgrade planning, admins can see the results of multiple HCL upgrade simulation scenarios within seconds, and the findings are presented in a comprehensive way with details about any non-compatibility and how to resolve it. Validates your hardware, drivers, and firmware against current and upstream releases of ESXi for faster upgrade planning. Remediation Scripts A growing number of findings in Runecast offer remediation actions – allowing you to download the customized script to perform the reconfiguration. Some rules offer more than one remediation option, for example PowerCLI and Ansible. SUPPORTED SERVICES SUPPORTED SYSTEMS: AWS, Azure GCP, Kubernetes (1.20 and above), VMware (VMware vSphere, NSX-V, NSX-T, VMware Horizon, VMware Cloud Director, AP HANA for VMware, VMware on Nutanix, Pure Storage), Windows (Microsoft Windows) and Linux OS (RHEL 8, CentOS 7). SECURITY STANDARDS: CIS Benchmarks, NIST 800-53, PCI DSS, HIPAA, DISA STIG 6, GDPR, KVKK (Turkey), ISO 27001, BSI IT-Grundschutz, Essential 8 and Cyber Essentials Security Standard. INTEGRATIONS: Jira, ServiceNow, vSphere Client Plugin, OpenID Connect, REST API, HPE Ezmeral. REMEDIATION TOOLS: Ansible (VMware), PowerCLI (VMware), AWS CLI (AWS), AWS Tools for PowerShell (AWS), GCP CLI


**Average Rating:** 4.8/5.0
**Total Reviews:** 21
**How Do G2 Users Rate Runecast?**

- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 9.2/10)
- **Detection Rate:** 10.0/10 (Category avg: 8.9/10)
- **Automated Scans:** 10.0/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 10.0/10 (Category avg: 8.4/10)

**Who Is the Company Behind Runecast?**

- **Seller:** [Runecast Solutions](https://www.g2.com/sellers/runecast-solutions)
- **Year Founded:** 2014
- **HQ Location:** London, London
- **Twitter:** @Runecast (1,093 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/5226278 (14 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 48% Enterprise, 24% Mid-Market



#### What Are Recent G2 Reviews of Runecast?

**"[Runecast](https://www.g2.com/survey_responses/runecast-review-7966299)"**

**Rating:** 5.0/5.0 stars
*— Manolis F.*

[Read full review](https://www.g2.com/survey_responses/runecast-review-7966299)

---

**"[Runecast gives me great audit and security compliance insights immediately.](https://www.g2.com/survey_responses/runecast-review-5371828)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Telecommunications*

[Read full review](https://www.g2.com/survey_responses/runecast-review-5371828)

---



### 14. [Finite State](https://www.g2.com/products/finite-state/reviews)
Finite State empowers device OEMs to ship securely while enabling engineering teams to move at the speed of AI, immediately transforming product artifacts into audit-ready assurance through a single automated workflow. Leveraging deep binary analysis and AI-native execution, the platform unifies code, compiled components, and firmware in minutes—connecting security design with deployed software. By continuously generating SBOMs, VEX, and signed compliance packages, Finite State enables connected device companies across industries such as medical devices and automotive to meet evolving regulations, including the EU Cyber Resilience Act (CRA), and deliver continuous compliance at speed. Learn more at https://finitestate.io/


**Average Rating:** 4.3/5.0
**Total Reviews:** 12
**How Do G2 Users Rate Finite State?**

- **Detection Rate:** 10.0/10 (Category avg: 8.9/10)
- **Automated Scans:** 10.0/10 (Category avg: 9.0/10)

**Who Is the Company Behind Finite State?**

- **Seller:** [Finite State](https://www.g2.com/sellers/finite-state)
- **Company Website:** https://finitestate.io
- **Year Founded:** 2017
- **HQ Location:** Columbus, Ohio, United States
- **Twitter:** @FiniteStateInc (670 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/finitestate (78 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 50% Enterprise, 25% Mid-Market



#### What Are Recent G2 Reviews of Finite State?

**"[Deep Visibility Into Supply Chain Risks and CVEs—Boosting Product Security](https://www.g2.com/survey_responses/finite-state-review-12966722)"**

**Rating:** 5.0/5.0 stars
*— Suru S.*

[Read full review](https://www.g2.com/survey_responses/finite-state-review-12966722)

---

**"[Finite State Review: Firmware Security Simplified](https://www.g2.com/survey_responses/finite-state-review-12997919)"**

**Rating:** 5.0/5.0 stars
*— Prasanth B.*

[Read full review](https://www.g2.com/survey_responses/finite-state-review-12997919)

---



### 15. [IBM Guardium Vulnerability Assessment](https://www.g2.com/products/ibm-guardium-vulnerability-assessment/reviews)
IBM Guardium Vulnerability Assessment scans data infrastructures (databases, data warehouses and big data environments) to detect vulnerabilities, and suggests remedial actions. The solution identifies exposures such as missing patches, weak passwords, unauthorized changes and misconfigured privileges. Full reports are provided as well as suggestions to address all vulnerabilities. Guardium Vulnerability Assessment detects behavioral vulnerabilities such as account sharing, excessive administrative logins and unusual after-hours activity. It identifies threats and security gaps in databases that could be exploited by hackers.


**Average Rating:** 4.5/5.0
**Total Reviews:** 12
**How Do G2 Users Rate IBM Guardium Vulnerability Assessment?**

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 9.2/10)
- **Automated Scans:** 10.0/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.3/10 (Category avg: 8.4/10)

**Who Is the Company Behind IBM Guardium Vulnerability Assessment?**

- **Seller:** [IBM](https://www.g2.com/sellers/ibm)
- **Year Founded:** 1911
- **HQ Location:** Armonk, New York, United States
- **Twitter:** @IBMSecurity (74,660 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/1009/ (328,202 employees on LinkedIn®)
- **Ownership:** SWX:IBM

**Who Uses This Product?**
- **Company Size:** 58% Enterprise, 25% Mid-Market



#### What Are Recent G2 Reviews of IBM Guardium Vulnerability Assessment?

**"[More Secure Data](https://www.g2.com/survey_responses/ibm-guardium-vulnerability-assessment-review-7966388)"**

**Rating:** 5.0/5.0 stars
*— Ali Rıza O.*

[Read full review](https://www.g2.com/survey_responses/ibm-guardium-vulnerability-assessment-review-7966388)

---

**"[Shows us our databses weaknesses so that we can fix them](https://www.g2.com/survey_responses/ibm-guardium-vulnerability-assessment-review-7071542)"**

**Rating:** 4.5/5.0 stars
*— Amy M.*

[Read full review](https://www.g2.com/survey_responses/ibm-guardium-vulnerability-assessment-review-7071542)

---


#### What Are G2 Users Discussing About IBM Guardium Vulnerability Assessment?

- [What is IBM Security Guardium Vulnerability Assessment used for?](https://www.g2.com/discussions/what-is-ibm-security-guardium-vulnerability-assessment-used-for)

### 16. [Detectify](https://www.g2.com/products/detectify/reviews)
Detectify sets a new standard for advanced application security testing, challenging traditional DAST by providing evolving coverage of each and every exposed asset across the changing attack surface. AppSec teams trust Detectify to expose how attackers will exploit their Internet-facing applications. The Detectify platform automates continuous real-world, payload-based attacks fuelled by its global community of elite ethical hackers into its own expert-built engines, exposing critical weaknesses before it&#39;s too late. The Detectify solution includes: - Automated discovery of known and unknown digital assets via domain &amp; cloud connectors - Continuous coverage (24/7) of every corner of the attack surface with dynamic testing. Not just predefined targets - 100% payload-based testing fuelled by elite ethical hackers for a high signal-to-noise ratio - Distributed coverage across an unmatched array of relevant technologies - Actionable remediation tips for software development teams - Team functionality to easily share reports - Powerful integrations platform to prioritize and triage vulnerability findings onward to development teams -Advanced API functionality -Capabilities to set custom attack surface security policies


**Average Rating:** 4.5/5.0
**Total Reviews:** 49
**How Do G2 Users Rate Detectify?**

- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.5/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.9/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.3/10 (Category avg: 8.4/10)

**Who Is the Company Behind Detectify?**

- **Seller:** [Detectify](https://www.g2.com/sellers/detectify)
- **Year Founded:** 2013
- **HQ Location:** Stockholm, Sweden
- **Twitter:** @detectify (11,256 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/2850066/ (92 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 47% Small-Business, 35% Mid-Market


#### What Are Detectify's Pros and Cons?

**Pros:**

- Automation (2 reviews)
- Automation Testing (2 reviews)
- Customizability (2 reviews)
- Features (2 reviews)
- Security (2 reviews)

**Cons:**

- Complexity (1 reviews)
- Complex Queries (1 reviews)
- Complex Setup (1 reviews)
- Expensive (1 reviews)
- Inaccuracy (1 reviews)


### What Do G2 Reviewers Say About Detectify?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **automation capabilities** of Detectify, enjoying seamless integration and tailored security testing processes.
- Users value the **easy automation and integration** features of Detectify that enhance security testing efficiently.
- Users value the **customizability** of Detectify, enabling easy integration and tailored security testing to fit diverse needs.
- Users appreciate the **easy integration and comprehensive features** of Detectify for efficient security testing.
- Users appreciate Detectify for its **effective dynamic application security testing** , ensuring comprehensive security without complex setups.

**Cons:**

- Users find the **initial complexity** of setting up Detectify to be a challenging aspect of the product.
- Users find the **complex queries** in Detectify challenging, impacting clarity on spidering results and app assessment.
- Users find the **complex setup** of Detectify to be a challenging start, impacting its usability for newcomers.
- Users find Detectify to be **expensive** when testing multiple sites, impacting its affordability for small operations.
- Users find **inaccuracy in outcomes** from Detectify&#39;s spidering, lacking clarity on app assessment completeness.

#### What Are Recent G2 Reviews of Detectify?

**"[Vulnerability scans made easy](https://www.g2.com/survey_responses/detectify-review-9059869)"**

**Rating:** 5.0/5.0 stars
*— Arkadiusz K.*

[Read full review](https://www.g2.com/survey_responses/detectify-review-9059869)

---

**"[Very happy from an admin/IT security manager view](https://www.g2.com/survey_responses/detectify-review-8197913)"**

**Rating:** 5.0/5.0 stars
*— Björn L.*

[Read full review](https://www.g2.com/survey_responses/detectify-review-8197913)

---


#### What Are G2 Users Discussing About Detectify?

- [What is Detectify used for?](https://www.g2.com/discussions/what-is-detectify-used-for)
- [Is Detectify a DAST tool?](https://www.g2.com/discussions/is-detectify-a-dast-tool)
- [How does Detectify app work?](https://www.g2.com/discussions/how-does-detectify-app-work)
- [What does Detectify scan for?](https://www.g2.com/discussions/what-does-detectify-scan-for)
- [What is Detectify Deep scan?](https://www.g2.com/discussions/what-is-detectify-deep-scan)

### 17. [BugProve](https://www.g2.com/products/bugprove/reviews)
As former security researchers, we founded BugProve to deliver the level of security that IoT deserves! Experience peace of mind by leveraging our automated firmware analysis platform: Swift Results: Upload your firmware image and receive first results in just 5 minutes. - Supply Chain Risk Management and Compliance: Identify components and known vulnerabilities, and opt for continuous CVE monitoring for compliance assurance. - Zero-day detection: Our built-in zero-day detection engine, PRIS, detects memory corruption vulnerabilities before they can be exploited. - All-in-One Hub: Seamlessly access product security reevaluations, comparisons, and updates, presented in an easily digestible format. - Effortless Sharing: Share findings via live links or export them as PDFs for convenient reporting. Involve your product development team with AI-assisted remediation recommendations. - Accelerated Testing: Save weeks in the pentesting process, enabling you to focus on in-depth discoveries and launch more secure products, without security bottlenecks. - IoT specific, detailed scans: BugProve runs checks directly on firmware, no source code needed. We run advanced static and dynamic analysis, unique multi-binary taint analysis, cryptographic analysis, and security configuration checks. No long-term contracts, commitments, and hidden fees. What’s more, we believe you should test the platform to see what it can do, so we offer a Free Plan. Sign up, and start scanning!


**Average Rating:** 4.9/5.0
**Total Reviews:** 20
**How Do G2 Users Rate BugProve?**

- **Has the product been a good partner in doing business?:** 9.8/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.7/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.5/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.9/10 (Category avg: 8.4/10)

**Who Is the Company Behind BugProve?**

- **Seller:** [BugProve](https://www.g2.com/sellers/bugprove)
- **Year Founded:** 2021
- **HQ Location:** Budapest, HU
- **Twitter:** @Bugprove (147 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/bugprove (2 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer &amp; Network Security
- **Company Size:** 90% Small-Business, 10% Enterprise



#### What Are Recent G2 Reviews of BugProve?

**"[BugProve has all the potential to be the leading platform for IoT security scanning](https://www.g2.com/survey_responses/bugprove-review-8958416)"**

**Rating:** 4.5/5.0 stars
*— Imre R.*

[Read full review](https://www.g2.com/survey_responses/bugprove-review-8958416)

---

**"[Securing the IoT Landscape: A Thorough Review of BugProve for Firmware Penetration Testing](https://www.g2.com/survey_responses/bugprove-review-8865710)"**

**Rating:** 5.0/5.0 stars
*— Barnabas S.*

[Read full review](https://www.g2.com/survey_responses/bugprove-review-8865710)

---



### 18. [MalCare](https://www.g2.com/products/malcare/reviews)
Mitigate getting blacklisted by Google, being blocked by Webhosts or any possible security threats from the most complex malwares with MalCare&#39;s comprehensive and powerful automatic website malware scanning.


**Average Rating:** 4.1/5.0
**Total Reviews:** 13
**How Do G2 Users Rate MalCare?**

- **Has the product been a good partner in doing business?:** 6.7/10 (Category avg: 9.2/10)
- **Detection Rate:** 6.7/10 (Category avg: 8.9/10)
- **Automated Scans:** 6.7/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 7.5/10 (Category avg: 8.4/10)

**Who Is the Company Behind MalCare?**

- **Seller:** [MalCare](https://www.g2.com/sellers/malcare)
- **Year Founded:** 2016
- **HQ Location:** Bangalore, Karnataka
- **Twitter:** @malcaresecurity (539 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/27206560 (1 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 92% Small-Business, 15% Mid-Market


#### What Are MalCare's Pros and Cons?

**Pros:**

- Efficiency Improvement (1 reviews)

**Cons:**

- False Positives (1 reviews)


### What Do G2 Reviewers Say About MalCare?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **efficiency improvement** of MalCare, appreciating that it enhances security without slowing down their website.

**Cons:**

- Users have observed **false positives** as MalCare occasionally fails to detect security issues with certain plugins.

#### What Are Recent G2 Reviews of MalCare?

**"[MalCare -  a reliable and efficient choice for securing your WordPress site on Cloudways](https://www.g2.com/survey_responses/malcare-review-10619146)"**

**Rating:** 4.0/5.0 stars
*— Rui d.*

[Read full review](https://www.g2.com/survey_responses/malcare-review-10619146)

---

**"[Great customer service and easy to work with!](https://www.g2.com/survey_responses/malcare-review-9235195)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Hospitality*

[Read full review](https://www.g2.com/survey_responses/malcare-review-9235195)

---


#### What Are G2 Users Discussing About MalCare?

- [What is MalCare waf php?](https://www.g2.com/discussions/malcare-what-is-malcare-waf-php)
- [What is MalCare waf php?](https://www.g2.com/discussions/what-is-malcare-waf-php)
- [Is MalCare plugin safe?](https://www.g2.com/discussions/malcare-is-malcare-plugin-safe)
- [Is MalCare plugin safe?](https://www.g2.com/discussions/is-malcare-plugin-safe)
- [Is MalCare any good?](https://www.g2.com/discussions/malcare-is-malcare-any-good) - 1 comment

### 19. [FOSSA](https://www.g2.com/products/fossa/reviews)
Open source is a critical part of your software. In the average modern software product, over 80% of the source code shipped is derived from open source. Each component can have cascading legal, security, and quality implications for your customers, making it one of the most important things to manage correctly. FOSSA helps you manage your open source components. We plug into your development workflow to help your team automatically track, manage, and remediate issues with the open source you use to: - Stay compliant with software licenses and generate required attribution documents - Enforce usage and licensing policies throughout your CI/CD workflow - Monitor and remediate security vulnerabilities - Flag code quality issues and outdated components proactively By enabling open source, we help development teams increase development velocity and decrease risk.


**Average Rating:** 4.2/5.0
**Total Reviews:** 15
**How Do G2 Users Rate FOSSA?**

- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 9.2/10)
- **Detection Rate:** 10.0/10 (Category avg: 8.9/10)
- **Automated Scans:** 10.0/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 10.0/10 (Category avg: 8.4/10)

**Who Is the Company Behind FOSSA?**

- **Seller:** [FOSSA](https://www.g2.com/sellers/fossa)
- **Year Founded:** 2015
- **HQ Location:** San Francisco, California
- **Twitter:** @getfossa (774 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/fossa/ (59 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer Software
- **Company Size:** 47% Small-Business, 33% Mid-Market


#### What Are FOSSA's Pros and Cons?

**Pros:**

- Easy Integrations (1 reviews)
- Issue Resolution (1 reviews)
- Remediation Solutions (1 reviews)
- Risk Management (1 reviews)
- Security (1 reviews)



### What Do G2 Reviewers Say About FOSSA?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **easy integrations** of FOSSA, seamlessly working with Maven and Gardle in their pipelines.
- Users benefit from Fossa&#39;s **effective issue resolution** , identifying vulnerabilities and recommending fixes for library dependencies.
- Users value the **effective remediation solutions** of FOSSA, which identify and suggest fixes for vulnerabilities in applications.
- Users value FOSSA for its **effective risk management** , identifying library issues and recommending fixes swiftly.
- Users value FOSSA&#39;s **security insights** that identify vulnerabilities and recommend fixes for their applications.


#### What Are Recent G2 Reviews of FOSSA?

**"[Fossa for enterprise applications](https://www.g2.com/survey_responses/fossa-review-10931000)"**

**Rating:** 4.0/5.0 stars
*— Pavan Kumar G.*

[Read full review](https://www.g2.com/survey_responses/fossa-review-10931000)

---

**"[&quot;The FOSSA Experience&quot;](https://www.g2.com/survey_responses/fossa-review-8576931)"**

**Rating:** 5.0/5.0 stars
*— Elvis M.*

[Read full review](https://www.g2.com/survey_responses/fossa-review-8576931)

---



### 20. [Zenmap](https://www.g2.com/products/zenmap/reviews)
Zenmap is the official graphical user interface (GUI) for the Nmap Security Scanner, designed to make network scanning accessible for both beginners and experienced users. This multi-platform, free, and open-source application supports operating systems such as Linux, Windows, Mac OS X, and BSD. Zenmap simplifies the process of network discovery and security auditing by providing an intuitive interface to Nmap&#39;s powerful features. Key Features and Functionality: - Profile Management: Users can save frequently used scans as profiles, enabling quick and consistent execution of routine network assessments. - Command Creation: An interactive command creator assists in building Nmap command lines, making it easier to customize scans without extensive command-line knowledge. - Result Management: Scan results can be saved for future reference, compared to identify changes over time, and are stored in a searchable database for efficient retrieval. - Network Topology Visualization: Zenmap offers an interactive, animated visualization of network topology, illustrating the relationships and paths between hosts. - Cross-Platform Compatibility: The application runs on multiple operating systems, ensuring flexibility and broad accessibility. Primary Value and User Solutions: Zenmap addresses the need for a user-friendly interface to Nmap&#39;s comprehensive network scanning capabilities. By providing graphical representations and simplified management of scan profiles and results, it enables users to efficiently monitor network security, detect unauthorized devices, and manage service upgrades. This tool is particularly valuable for system and network administrators seeking to maintain secure and well-documented network environments.


**Average Rating:** 4.5/5.0
**Total Reviews:** 26
**How Do G2 Users Rate Zenmap?**

- **Has the product been a good partner in doing business?:** 7.9/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.8/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.3/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 7.3/10 (Category avg: 8.4/10)

**Who Is the Company Behind Zenmap?**

- **Seller:** [Nmap](https://www.g2.com/sellers/nmap)
- **HQ Location:** N/A
- **Twitter:** @nmap (136,374 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/nmap-corp (4 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services
- **Company Size:** 50% Mid-Market, 39% Small-Business


#### What Are Zenmap's Pros and Cons?

**Pros:**

- Ease of Use (1 reviews)
- Implementation Ease (1 reviews)

**Cons:**

- Issue Management (1 reviews)
- Poor Interface Design (1 reviews)


### What Do G2 Reviewers Say About Zenmap?
*AI-generated summary from verified user reviews*

**Pros:**

- Users find Zenmap&#39;s **ease of use** highly beneficial for penetration testing and cybersecurity tasks.
- Users find Zenmap to be **easy to implement** , making it accessible for penetration testers and security analysts.

**Cons:**

- Users find the **limited command functionality** of Zenmap restricts their experience compared to other tools.
- Users find Zenmap&#39;s **poor interface design** challenging, limiting their command usage and overall experience.

#### What Are Recent G2 Reviews of Zenmap?

**"[GUI front-end that brings Nmap’s power to the desktop](https://www.g2.com/survey_responses/zenmap-review-11453646)"**

**Rating:** 4.5/5.0 stars
*— Luca P.*

[Read full review](https://www.g2.com/survey_responses/zenmap-review-11453646)

---

**"[A quick review of Zenmap](https://www.g2.com/survey_responses/zenmap-review-6592716)"**

**Rating:** 4.0/5.0 stars
*— mohit m.*

[Read full review](https://www.g2.com/survey_responses/zenmap-review-6592716)

---


#### What Are G2 Users Discussing About Zenmap?

- [What is Zenmap used for?](https://www.g2.com/discussions/zenmap-what-is-zenmap-used-for)
- [How do I install Zenmap?](https://www.g2.com/discussions/how-do-i-install-zenmap)
- [Is Nmap scanning illegal?](https://www.g2.com/discussions/is-nmap-scanning-illegal)
- [What are the features of nmap?](https://www.g2.com/discussions/what-are-the-features-of-nmap)
- [What is Zenmap used for?](https://www.g2.com/discussions/what-is-zenmap-used-for)

### 21. [Rainforest Application](https://www.g2.com/products/rainforest-technologies-rainforest-application/reviews)
Rainforest is the all-in-one cyber security platform with an end-to-end approach to simplify corporate reputation protection by using multiple intelligences and proactive observability, adding Application and Cloud Security (from DevOps to DevSecOps), Vulnerability Intelligence, and Brand reputation (Fraud and Leak monitoring). Rainforest Application, Rainforest Cloud, and Rainforest Asset modules allow development and security teams have visibility of all applications lifecycle, in a simple and quick way, providing vulnerability management always that a new line is coded. Rainforest Fraud, Rainforest Leak, and Rainforest Asset build an integrated vision of Vulnerability and Brand Intelligence, guiding security and compliance teams in an efficient manner on potential exposure points, according to their importance to the business regarding the company&#39;s reputation.


**Average Rating:** 4.9/5.0
**Total Reviews:** 12
**How Do G2 Users Rate Rainforest Application?**

- **Has the product been a good partner in doing business?:** 9.8/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.0/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.0/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 9.3/10 (Category avg: 8.4/10)

**Who Is the Company Behind Rainforest Application?**

- **Seller:** [Rainforest Technologies](https://www.g2.com/sellers/rainforest-technologies)
- **HQ Location:** Wilmington, Delaware
- **LinkedIn® Page:** https://www.linkedin.com/company/80967943 (11 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 42% Small-Business, 42% Mid-Market



#### What Are Recent G2 Reviews of Rainforest Application?

**"[Rainforest is very safe!](https://www.g2.com/survey_responses/rainforest-application-review-9743078)"**

**Rating:** 5.0/5.0 stars
*— Paulo Z.*

[Read full review](https://www.g2.com/survey_responses/rainforest-application-review-9743078)

---

**"[My Experience with Rainforest Platform](https://www.g2.com/survey_responses/rainforest-application-review-9843958)"**

**Rating:** 4.5/5.0 stars
*— Lucas M.*

[Read full review](https://www.g2.com/survey_responses/rainforest-application-review-9843958)

---



### 22. [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews)
Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.


**Average Rating:** 3.8/5.0
**Total Reviews:** 25
**How Do G2 Users Rate Veracode Application Security Platform?**

- **Has the product been a good partner in doing business?:** 7.9/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.3/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.2/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 9.4/10 (Category avg: 8.4/10)

**Who Is the Company Behind Veracode Application Security Platform?**

- **Seller:** [VERACODE](https://www.g2.com/sellers/veracode)
- **Year Founded:** 2006
- **HQ Location:** Burlington, MA
- **Twitter:** @Veracode (21,950 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/27845/ (502 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services
- **Company Size:** 69% Enterprise, 31% Mid-Market


#### What Are Veracode Application Security Platform's Pros and Cons?

**Pros:**

- Security (5 reviews)
- Vulnerability Detection (5 reviews)
- Automated Scanning (3 reviews)
- Detection (3 reviews)
- Ease of Use (3 reviews)

**Cons:**

- Expensive (2 reviews)
- Lack of Information (2 reviews)
- Licensing Issues (2 reviews)
- Poor Customer Support (2 reviews)
- Pricing Issues (2 reviews)


### What Do G2 Reviewers Say About Veracode Application Security Platform?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **comprehensive security analysis** offered by Veracode, effectively addressing vulnerabilities and streamlining development.
- Users value Veracode for its **effective vulnerability detection** , ensuring high-security standards and seamless integration into development processes.
- Users appreciate the **automated scanning** feature of Veracode, which effectively identifies vulnerabilities and enhances security standards.
- Users value the **effective detection capabilities** of Veracode, enabling thorough security checks and vulnerability identification.
- Users value the **ease of use** of Veracode, benefiting from seamless integration and comprehensive security analysis.

**Cons:**

- Users find the platform to be **expensive** , with rising costs and unjustifiable investment in customer success packages.
- Users face a **lack of information** regarding features and services, leading to confusion and unmet expectations.
- Users express concerns about **licensing issues** , citing high costs, complex models, and unmet feature expectations.
- Users report **poor customer support** , experiencing pressure from sales and challenges with feature delivery and documentation.
- Users express concerns over **pricing issues** , citing increased costs, complex licensing, and pressure from sales executives.

#### What Are Recent G2 Reviews of Veracode Application Security Platform?

**"[Streamlined Security, Effortless Integration](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)"**

**Rating:** 5.0/5.0 stars
*— Bhanu Prakash M.*

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)

---

**"[Clear, Unified View of Application Capabilities](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)"**

**Rating:** 4.5/5.0 stars
*— Christopher S.*

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)

---


#### What Are G2 Users Discussing About Veracode Application Security Platform?

- [What is difference between veracode and SonarQube?](https://www.g2.com/discussions/what-is-difference-between-veracode-and-sonarqube)
- [What is veracode software composition analysis?](https://www.g2.com/discussions/what-is-veracode-software-composition-analysis)
- [What is veracode used for?](https://www.g2.com/discussions/what-is-veracode-used-for)
- [What is the veracode application security platform?](https://www.g2.com/discussions/what-is-the-veracode-application-security-platform)

### 23. [HostedScan.com](https://www.g2.com/products/hostedscan-com/reviews)
HostedScan provides 24x7 alerts and detection for security vulnerabilities. Industry-standard, open-source, vulnerability scans. Automated alerts when something changes. Manage target list manually or import automatically from providers, such as AWS, DigitalOcean, and Linode, with read-only access. Manage and audit risks with dashboarding and reporting.


**Average Rating:** 4.3/5.0
**Total Reviews:** 13
**How Do G2 Users Rate HostedScan.com?**

- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.2/10 (Category avg: 8.9/10)
- **Automated Scans:** 10.0/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 10.0/10 (Category avg: 8.4/10)

**Who Is the Company Behind HostedScan.com?**

- **Seller:** [HostedScan](https://www.g2.com/sellers/hostedscan)
- **Year Founded:** 2019
- **HQ Location:** Seattle, Washington
- **Twitter:** @hostedscan (59 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/69116669 (4 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 85% Small-Business, 15% Mid-Market



#### What Are Recent G2 Reviews of HostedScan.com?

**"[Excellent option for small charities](https://www.g2.com/survey_responses/hostedscan-com-review-9823419)"**

**Rating:** 5.0/5.0 stars
*— Stephen H.*

[Read full review](https://www.g2.com/survey_responses/hostedscan-com-review-9823419)

---

**"[Unmatched customer service](https://www.g2.com/survey_responses/hostedscan-com-review-10196707)"**

**Rating:** 5.0/5.0 stars
*— Maximiliano S.*

[Read full review](https://www.g2.com/survey_responses/hostedscan-com-review-10196707)

---



### 24. [Continuity Software](https://www.g2.com/products/continuity-software/reviews)
New ransomware groups are targeting storage and backup systems (e.g., Conti, Hive and REvil). However, storage &amp; backup are currently the only infrastructure layers NOT COVERED by traditional vulnerability management solutions. This is a glaring blind spot, since the working assumption should be that some attacks will succeed. When that happens, storage and backups are your last line of defense. Continuity&#39;s StorageGuard is the industry’s ONLY security posture management solution for storage &amp; backup systems, helping you protect your most valuable data, and ensuring data recoverability in case of a breach. For the first time, get complete visibility of security risks across your storage &amp; backup systems, automatically prioritized in order of business impact, and with clear remediation guidelines. Now’s the time to get the peace of mind that your storage &amp; backup systems can withstand a ransomware attack.


**Average Rating:** 4.4/5.0
**Total Reviews:** 18
**How Do G2 Users Rate Continuity Software?**

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.3/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.3/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 9.3/10 (Category avg: 8.4/10)

**Who Is the Company Behind Continuity Software?**

- **Seller:** [Continuity Software](https://www.g2.com/sellers/continuity-software)
- **Year Founded:** 2005
- **HQ Location:** New York, US
- **LinkedIn® Page:** https://www.linkedin.com/company/continuity-software/ (37 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 53% Enterprise, 26% Small-Business



#### What Are Recent G2 Reviews of Continuity Software?

**"[Comprehensive Analysis of Continuity Software: Ensuring Robust IT Resilience](https://www.g2.com/survey_responses/continuity-software-review-9874058)"**

**Rating:** 5.0/5.0 stars
*— AFZAL R D.*

[Read full review](https://www.g2.com/survey_responses/continuity-software-review-9874058)

---

**"[Reliable Continuity Solutions for Business Operations](https://www.g2.com/survey_responses/continuity-software-review-9874350)"**

**Rating:** 4.0/5.0 stars
*— Prafull  S.*

[Read full review](https://www.g2.com/survey_responses/continuity-software-review-9874350)

---


#### What Are G2 Users Discussing About Continuity Software?

- [What is Continuity Software used for?](https://www.g2.com/discussions/what-is-continuity-software-used-for)

### 25. [OpenVAS](https://www.g2.com/products/openvas/reviews)
OpenVAS is a framework of several services and tools offering a comprehensive and powerful vulnerability scanning and vulnerability management solution.


**Average Rating:** 4.4/5.0
**Total Reviews:** 28
**How Do G2 Users Rate OpenVAS?**

- **Has the product been a good partner in doing business?:** 7.5/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.1/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.3/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 7.0/10 (Category avg: 8.4/10)

**Who Is the Company Behind OpenVAS?**

- **Seller:** [OpenVAS](https://www.g2.com/sellers/openvas)
- **Year Founded:** 2020
- **HQ Location:** Zug, CH
- **Twitter:** @openvas (1,362 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/openvasp-association (2 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer &amp; Network Security, Information Technology and Services
- **Company Size:** 56% Mid-Market, 34% Small-Business



#### What Are Recent G2 Reviews of OpenVAS?

**"[Openvas pros and cons](https://www.g2.com/survey_responses/openvas-review-4559042)"**

**Rating:** 4.5/5.0 stars
*— Talha A.*

[Read full review](https://www.g2.com/survey_responses/openvas-review-4559042)

---

**"[A powerful and free tool](https://www.g2.com/survey_responses/openvas-review-8158632)"**

**Rating:** 4.0/5.0 stars
*— Victor Hugo M.*

[Read full review](https://www.g2.com/survey_responses/openvas-review-8158632)

---


#### What Are G2 Users Discussing About OpenVAS?

- [What is OpenVAS used for?](https://www.g2.com/discussions/what-is-openvas-used-for)


## What Is Vulnerability Scanner Software?

[DevSecOps Software](https://www.g2.com/categories/devsecops)

## What Software Categories Are Similar to Vulnerability Scanner Software?

- [Website Security Software](https://www.g2.com/categories/website-security)
- [Penetration Testing Tools](https://www.g2.com/categories/penetration-testing-tools)
- [Dynamic Application Security Testing (DAST) Software](https://www.g2.com/categories/dynamic-application-security-testing-dast)
- [Software Composition Analysis Tools](https://www.g2.com/categories/software-composition-analysis)
- [Risk-Based Vulnerability Management Software](https://www.g2.com/categories/risk-based-vulnerability-management)
- [Cloud Security Posture Management (CSPM) Software](https://www.g2.com/categories/cloud-security-posture-management-cspm)
- [ Attack Surface Management Software](https://www.g2.com/categories/attack-surface-management)


---

## How Do You Choose the Right Vulnerability Scanner Software?

### What You Should Know About Vulnerability Scanner Software

### What is Vulnerability Scanner Software?

Vulnerability scanners are used to examine applications, networks, and environments for security flaws and misconfigurations. These tools run a variety of dynamic security tests to identify security threats along an application or network’s attack surface. Scans can be used for anything from an application penetration test to a compliance scan. Depending on the specific objectives a user has, they can customize the vulnerability scanner to test for specific issues or requirements.

Companies can configure these tests to their unique environment. Companies that handle lots of personal or financial data may scan to ensure every transaction or datastore is encrypted from the public. They could also test their web applications against specific threats like SQL injection or cross-site scripting (XSS) attacks. The highly-customizable nature of vulnerability scanners provides users with tailor-made solutions for application and network security examination.

Many of these tools offer continuous scanning and testing for nonstop protection and monitoring. Whatever administrators set as a priority will be tested periodically and inform employees of issues or incidents. Continuous monitoring makes it much easier to discover vulnerabilities before they become an issue and drastically reduce the amount of time a vulnerability takes to remediate.

Top vulnerability scanner software with CVE remediation guidance typically combines automated scanning with prioritized fix recommendations that map findings to severity scores, exposure paths, and patch availability. Based on G2 reviews, security teams evaluate vulnerability scanner software by comparing CVE remediation depth, false positive rates, and how quickly the platform integrates into existing CI/CD pipelines and cloud environments.

Key Benefits of Vulnerability Scanner Software

- Scan networks and applications for security flaws
- Diagnose, track, and remediate vulnerabilities
- Identify and resolve misconfigurations
- Perform ad hoc security tests

### Why Use Vulnerability Scanner Software?

Applications and networks are only beneficial to a business if they operate smoothly and securely. Vulnerability scanners are a useful tool to view internal systems and applications from the perspective of the attacker. These tools allow for dynamic testing while applications operate. This helps security teams take a step beyond patches and code analysis to evaluate security posture while the application, network, or instance actually runs.

**Application security—** Cloud, web, and desktop applications all require security, but operate differently. While many vulnerability scanners support testing for all kinds of applications, vulnerability scanners often support a few application types, but not others. Still, they will all examine the application itself, as well as the paths a user needs to access it. For example, if a vulnerability scanner is used on a web application, the tool will take into account the various attack vectors a hacker might take. This includes a site’s navigation, regional access, privileges, and other factors decided by the user. From there, the scanner will output reports on specific vulnerabilities, compliance issues, and other operational flaws.

**Networks —** While software applications are often the most obvious use cases for vulnerability scanners, network vulnerability scanners are also quite common. These tools take into account the network itself, as well as computers, servers, mobile devices and any other asset accessing a network. This helps businesses identify vulnerable devices and abnormal behaviors within a network to identify and remediate issues as well as improve their network&#39;s security posture. Many even provide visual tools for mapping networks and their associated assets to simplify the management and prioritization of vulnerabilities requiring remediation.

**Cloud environments —** Not to be confused with cloud-based solutions delivered in a SaaS model, cloud vulnerability scanners examine cloud services, cloud computing environments, and integrated connections. Like network vulnerability scanners, cloud environments require an examination on a few levels. Cloud assets come in many forms including devices, domains, and instances; but all must be accounted for and scanned. In a properly secured cloud computing environment, integrations and API connections, assets, and environments must all be mapped, configurations must be monitored, and requirements must be enforced.

Based on G2 reviews, vulnerability scanner platforms generating VLAN audit reports are evaluated primarily by security teams running segmented enterprise networks where compliance frameworks (PCI, HIPAA, SOC 2, ISO 27001) require documented scans across each network zone. Reviewers point to audit-ready compliance reporting, granular scan scope by IP range and network segment, and exportable evidence formats as the features that determine whether the platform shortens the audit prep cycle or adds another step to it.

### What are the Common Features of Vulnerability Scanner Software?

Vulnerability scanners can provide a wide range of features, but here are a few of the most common found in the market.

**Network mapping —** Network mapping features provide a visual representation of network assets including endpoints, servers, and mobile devices to intuitively demonstrate an entire network’s components.

**Web inspection —** Web inspection features are used to assess the security of a web application in the context of its availability. This includes site navigation, taxonomies, scripts, and other web-based operations that may impact a hacker’s abilities.

[**Defect tracking**](https://www.g2.com/categories/vulnerability-scanner/f/issue-tracking) **—** Defect and issue tracking functionality helps users discover and document vulnerabilities and track them to their source through the resolution process.

**Interactive scanning —** Interactive scanning or interactive application security testing features allow a user to be directly involved in the scanning process, watch tests in real time, and perform ad hoc tests.

[**Perimeter scanning**](https://www.g2.com/categories/vulnerability-scanner/f/perimeter-scanning) **—** Perimeter scanning will analyze assets connected to a network or cloud environment for vulnerabilities.

[**Black box testing**](https://www.g2.com/categories/vulnerability-scanner/f/black-box-testing) **—** Black box scanning refers to tests conducted from the hacker’s perspective. Black box scanning examines functional applications externally for vulnerabilities like SQL injection or XSS.

**Continuous monitoring —** Continuous monitoring allows users to set it and forget it. They enable scanners to run all the time as they alert users of new vulnerabilities.

[**Compliance monitoring**](https://www.g2.com/categories/vulnerability-scanner/f/compliance-testing) **—** Compliance-related monitoring features are used to monitor data quality and send alerts based on violations or misuse.

**Asset discovery —** Asset discovery features unveil applications in use and trends associated with asset traffic, access, and usage.

**Logging and reporting —** Log documentation and reporting provides required reports to manage operations. It provides adequate logging to troubleshoot and support auditing.

**Threat intelligence —** Threat intelligence features integrate with or store information related to common threats and how to resolve them once incidents occur.

**Risk analysis —** Risk scoring and risk analysis features identify, score, and prioritize security risks, vulnerabilities, and compliance impacts of attacks and breaches.

**Extensibility —** Extensibility and integration features provide the ability to extend the platform or product to include additional features and functionalities.

Based on G2 reviews, the most trusted vulnerability scanner platforms in 2026 for security teams lead on CVE remediation guidance and easy setup onboarding, with reviewers describing time-to-first-scan in hours rather than weeks. SOC and AppSec teams point to clear remediation steps, severity scoring, and actionable findings as the features that distinguish platforms they actively use from ones that produce noise. Vulnerability scanner solutions with easy setup onboarding are highlighted in recent reviews for delivering full environment visibility on day one through agentless, API-driven architectures, with documentation that reduces the engineering lift typically associated with rolling out vulnerability scanning.

Many vulnerability scanner tools will also offer the following features:&amp;nbsp;

- [Configuration monitoring capabilities](https://www.g2.com/categories/vulnerability-scanner/f/configuration-monitoring)
- [Automated scan capabilities](https://www.g2.com/categories/vulnerability-scanner/f/automated-scans)
- [Manual application testing capabilities](https://www.g2.com/categories/vulnerability-scanner/f/manual-application-testing)
- [Static code analysis capabilities](https://www.g2.com/categories/vulnerability-scanner/f/static-code-analysis)

### Potential Issues with Vulnerability Scanner Software

**False positives —** False positives are one of the most common issues with security tools. They indicate a tool is not running efficiently and introduce lots of unnecessary labor. Users should examine figures related to specific products and their accuracy before purchasing a solution.

**Integrations —** Integrations can make an application or product do virtually anything, but only if the integration is supported. If a specific solution must be integrated or a specific data source is highly relevant, be sure it’s compatible with the vulnerability scanner before making that decision.

**Scalability —** Scalability is always important, especially for growing teams. Cloud and SaaS-based solutions are traditionally the most scalable, but desktop and open source tools may be as well. Scalability will be important for teams considering collaborative use, concurrent use, and multi-application and environment scanning.

### Software and Services Related to Vulnerability Scanner Software

These technology families are either closely related to vulnerability scanners or there is frequent overlap between products.

[**Risk-based vulnerability management software**](https://www.g2.com/categories/risk-based-vulnerability-management) **—** Risk-based vulnerability management software is used to analyze security posture based on a wide array of risk factors. From there, companies prioritize vulnerabilities based on their risk score. These tools often have some overlapping features, but they’re more geared towards prioritizing risks in large organizations rather than identifying vulnerabilities to individual applications or environments.

[**Dynamic application security testing (DAST) software**](https://www.g2.com/categories/dynamic-application-security-testing-dast) **—** DAST software is very closely related to vulnerability scanners and are sometimes used interchangeably. The differentiating factor here, though, is the ability to scan networks, cloud services, and IT assets in addition to applications. While they do scan for vulnerabilities, they won’t allow users to map networks, visualize environments, or examine vulnerabilities beyond the scope of the application.

[**Static application security testing (SAST) software**](https://www.g2.com/categories/static-application-security-testing-sast) **—** SAST software is not that similar to vulnerability scanners, unlike DAST tools. SAST tools allow for the examination of source code and non-operational application components. They also can’t simulate attacks or perform functional security tests. Still, these can be useful for defect and bug tracking if the vulnerability is rooted in an application’s source code.

[**Penetration testing software**](https://www.g2.com/categories/penetration-testing) **—** Penetration testing software is one aspect of vulnerability scanning, but a penetration test will not provide a wide variety of security tests. They are useful for testing common attack types, but they won’t be very effective in identifying and remediating the root cause of a vulnerability.

Based on G2 reviews, Software Composition Analysis tools Jenkins GitLab integration continuous vulnerability scanning is the workflow pattern reviewers describe as the standard for developer-led security programs running checks inside the build pipeline rather than as a separate stage. Reviewers point to agentless, API-driven scanners integrating into CI/CD pipelines to catch secrets, misconfigurations, and open-source dependency vulnerabilities pre-deployment as the setup that scales with engineering velocity. Reviewers note that consolidated platforms unifying SCA, SAST, and exposure-management scanning under one interface are the preferred consolidation pattern over stitching together standalone tools.



