# Best AI AppSec Assistants

## How Many AI AppSec Assistants Products Does G2 Track?

**Total Products under this Category:** 27

### Category Stats (Aug 2026)

- **Average Rating:** 4.49/5 (↑0.02 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Tabnine (+1.11%) - Among all products in this category, Tabnine recorded the largest rating increase compared to last month

_Last updated: August 01, 2026_

## How Does G2 Rank AI AppSec Assistants Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 1,700+ Authentic Reviews
- 27+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for AI AppSec Assistants
 ![G2 Grid® for AI AppSec Assistants plotting products by satisfaction and market presence](https://www.g2.com/categories/ai-appsec-assistants/grids.png?focus%5B%5D=1259627&focus%5B%5D=1292770&focus%5B%5D=7775&focus%5B%5D=36094&focus%5B%5D=1305807&focus%5B%5D=1312693&focus%5B%5D=1461836)

Highlighted products: Aikido Security, GitHub Copilot, SonarQube, Snyk, Replit, OX Security, and DryRun Security.

Underlying data: [Grid® JSON](https://www.g2.com/categories/ai-appsec-assistants/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=github-copilot&focus%5B%5D=sonarqube&focus%5B%5D=snyk&focus%5B%5D=replit&focus%5B%5D=ox-security&focus%5B%5D=dryrun-security)

**Sponsored**

### Gemini Enterprise Agent Platform

Google Cloud's comprehensive platform for developers to build, scale, govern and optimize agents and models. It's a single destination for technical teams to build agents that can transform enterprise applications and workflows into powerful agentic systems.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1012568&secure%5Bchosen_at%5D=2026-08-01T16%3A22%3A04Z&secure%5Bdisplayable_resource_id%5D=1012568&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=1012568&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=21469&secure%5Bresource_id%5D=1012568&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fai-appsec-assistants%3Fopen_modal_url%3D%252Fproducts%252Freplit%252Fwishlists%253Fhost_path%253D%25252Fcategories%25252Fai-appsec-assistants%2526source%253Dcategory&secure%5Btoken%5D=9aa058814c1d932beafa8ba43c85998f95bdadebaf7d63c0eaec6f200f74afba&secure%5Burl%5D=https%3A%2F%2Fcloud.google.com%2Fproducts%2Fgemini-enterprise-agent-platform%3Futm_source%3DG2%26utm_medium%3Ddisplay%26utm_campaign%3DCloud-SS-DR-GCP-1713658-GCP-DR-NA-US-en-G2-Display-Banner-All-%2525epid%21-%2525ecid%21-geap%26utm_content%3D%257Bdevice%257D-%257Badgroupid%257D-%257Bnetwork%257D-%257Btargetid%257D-%257Bloc_physical_ms%257D-%257Bcampaignid%257D&secure%5Burl_type%5D=custom_url)

### [Aikido Security](https://www.g2.com/products/aikido-security/reviews)

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

**Average Rating:** 4.6/5.0

**Total Reviews:** 254

#### Who Is the Company Behind Aikido Security?

- **Seller:** [Aikido Security](https://www.g2.com/sellers/aikido-security)
- **Company Website:** aikido.dev
- **Year Founded:** 2022
- **HQ Location:** Ghent, Belgium
- **Twitter:** @AikidoSecurity  
11,770 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=79406802efc597500b142b19f023ee80eb82879906d7e1e458900293346529a9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faikido-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
241 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Founder, CTO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 80% Small, 13% Medium

#### What Do G2 Reviewers Say About Aikido Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Aikido Security, benefiting from its clear, actionable insights and seamless integration.
- Users praise Aikido Security for its **fast and user-friendly identification of security issues** in codebases, enhancing development practices.
- Users appreciate the **robust features of Aikido Security** , valuing its usability and effectiveness in enhancing security workflows.
- Users value the **easy integrations** with GitLab, allowing for quick start and effective tracking of security issues.
- Users commend the **easy setup** of Aikido Security, simplifying integration and enhancing their security workflow significantly.

##### Cons

- Users note the **missing features** in Aikido Security, wishing for more integration and advanced configuration options.
- Users find the **pricing excessive** , particularly for startups, despite acknowledging the product's value.
- Users find Aikido Security has **limited features** , particularly in advanced customization and reporting for complex environments.
- Users find the **entry-level pricing** of Aikido Security too high for startups, limiting adoption and experimentation.
- Users are frustrated by the **lack of features** , especially with local scanning and branch handling limitations.

#### What Are Recent G2 Reviews of Aikido Security?

**["Seamless GitHub Integration with Solid Security Findings and Smart False-Positive Analysis"](https://www.g2.com/survey_responses/aikido-security-review-13109689)**

**Rating:** 4.5/5.0 stars

_— Jordan B._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13109689)

**["Enterprise Security Without an Enterprise Security Team"](https://www.g2.com/survey_responses/aikido-security-review-13108704)**

**Rating:** 4.0/5.0 stars

_— Ian M._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13108704)

### [GitHub Copilot](https://www.g2.com/products/github-copilot/reviews)

GitHub Copilot helps more than 1 million developers and over 20,000 businesses push what’s possible in software development. Based on powerful LLMs, including OpenAI’s GPT models, this AI pair programmer helps developers write code faster and with less work by drawing context from comments and code to suggest individual lines and whole functions instantly. All languages are supported, however the more common a language, the better represented it will be in the training data and the more robust suggestions will be.

**Average Rating:** 4.4/5.0

**Total Reviews:** 376

#### Who Is the Company Behind GitHub Copilot?

- **Seller:** [GitHub](https://www.g2.com/sellers/github)
- **Year Founded:** 2008
- **HQ Location:** San Francisco, CA
- **Twitter:** @github  
2,673,925 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c06a67fd698737e0e0058dd8a6726d5e9af42b7ce88417153ae8028eed3914af&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1418841%2F&secure%5Burl_type%5D=linkedin_company_website)  
6,106 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 36% Small, 32% Medium

#### What Do G2 Reviewers Say About GitHub Copilot?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of GitHub Copilot, seamlessly integrating into their coding workflow and enhancing productivity.
- Users value the **seamless coding assistance** from GitHub Copilot, enhancing productivity and supporting learning for new programmers.
- Users appreciate how GitHub Copilot significantly enhances **productivity by generating relevant code and suggestions in real-time**.
- Users value the **effective problem-solving capabilities** of GitHub Copilot, providing timely solutions and smart coding suggestions.
- Users value the **efficiency** of GitHub Copilot for reducing errors and simplifying the coding process.

##### Cons

- Users find that **poor coding accuracy** can lead to unhelpful suggestions and inconsistent code generation experiences.
- Users find **poor suggestions** from GitHub Copilot can lead to inaccuracies and require careful review before use.
- Users find GitHub Copilot **expensive** , which can be a barrier for students and new developers to access its features.
- Users often experience **inaccuracy issues** with GitHub Copilot, leading to mistakes and increased review times for solutions.
- Users experience **context understanding issues** with GitHub Copilot, leading to confusion and inefficiencies in coding tasks.

#### What Are Recent G2 Reviews of GitHub Copilot?

**["A highly productive mobile companion for repository management and brainstorming code logic"](https://www.g2.com/survey_responses/github-copilot-review-13138457)**

**Rating:** 4.0/5.0 stars

_— Chandra K._

[Read full review](https://www.g2.com/survey_responses/github-copilot-review-13138457)

**["My personal AI assistant to understand code repo"](https://www.g2.com/survey_responses/github-copilot-review-13189952)**

**Rating:** 4.5/5.0 stars

_— Balram T._

[Read full review](https://www.g2.com/survey_responses/github-copilot-review-13189952)

### [SonarQube](https://www.g2.com/products/sonarqube/reviews)

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 153

#### Who Is the Company Behind SonarQube?

- **Seller:** [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)
- **Company Website:** www.sonarsource.com
- **Year Founded:** 2008
- **HQ Location:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** DevOps Engineer, Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 42% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Users value how SonarQube **efficiently flags code quality and security issues** , ensuring a clean and maintainable codebase.
- Users value the **issue filtering and prioritization features** of SonarQube, enhancing focus on high-priority tasks.
- Users value the **issue identification and prioritization** features of SonarQube, improving focus on critical tasks.
- Users find SonarQube's **ease of use** invaluable for maintaining code quality and integrating seamlessly into development workflows.
- Users appreciate the **easy integrations** with existing CI/CD tools, enhancing their development workflow seamlessly.

##### Cons

- Users face challenges with **software bugs** as SonarQube can consume excessive RAM and occasionally reports false positives.
- Users find SonarQube's configuration **complex** , especially for beginners, leading to difficulties and overwhelming warnings to manage.
- Users encounter **false positives** that complicate evaluations, though mitigation options exist through detailed analysis and rule customization.
- Users find that SonarQube's **complexity in configuration** and excessive warnings can hinder effective usage and efficiency.
- Users find the **complex setup** of SonarQube challenging, especially for beginners unfamiliar with the configuration process.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube: Easy Integration, Simple UI, and Solid Free Code Quality Scanning"](https://www.g2.com/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-12975264)

**["SonarQube Makes Code Quality Clear with Strong Quality Gates and CI/CD Integration"](https://www.g2.com/survey_responses/sonarqube-review-13142666)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-13142666)

#### What Are G2 Users Discussing About SonarQube?

- [What is SonarLint used for?](https://www.g2.com/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)

### [Snyk](https://www.g2.com/products/snyk/reviews)

Snyk (pronounced sneak) is a developer security platform for securing custom code, open source dependencies, containers, and cloud infrastructure all from a single platform. Snyk’s developer security solutions enable modern applications to be built securely, empowering developers to own and build security for the whole application, from code & open source to containers & cloud infrastructure. Secure while you code in your IDE: find issues quickly using the scanner, fix issues easily with remediation advice, verify the updated code. Integrate your source code repositories to secure applications: integrate a repository to find issues, prioritize with context, fix & merge. Secure your containers as you build, throughout the SDLC: start fixing containers as soon as your write a Dockerfile, continuously monitor container images throughout their lifecycle, and prioritize with context. Secure build and deployment pipelines: Integrate natively with your CI/CD tool, configure your rules, find & fix issues in your application, and monitor your applications. Secure your apps quickly with Snyk’s vulnerability scanning and automated fixes - Try for Free!

**Average Rating:** 4.5/5.0

**Total Reviews:** 135

#### Who Is the Company Behind Snyk?

- **Seller:** [Snyk](https://www.g2.com/sellers/snyk)
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @snyksec  
21,057 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=53ae05ab7bc9d48691ba96e338012b66175e75679973854c2a6c213b21fab33f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F10043614%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,370 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 44% Medium, 35% Small

#### What Do G2 Reviewers Say About Snyk?

_AI-generated summary from verified user reviews_

##### Pros

- Users value Snyk's **rapid vulnerability detection** , enabling efficient identification and remediation in development environments.
- Users appreciate Snyk's **rapid vulnerability identification** , enhancing security through quick updates and effective integration.
- Users value the **easy integrations** of Snyk, enhancing workflow efficiency in CI/CD pipelines and GitHub.
- Users appreciate the **easy setup** of Snyk, enabling seamless integration with GitHub and efficient codebase scanning.
- Users commend Snyk for its **intuitive GUI and customizable organization structure** , enhancing vulnerability management and reporting efficiency.

##### Cons

- Users experience **false positives** from Snyk, leading to confusion and slowing down the scanning process.
- Users feel the **poor interface design** of Snyk hinders usability, especially with the separate DAST interface.
- Users face **pricing issues** with Snyk, as the cost can be high for accessing all features.
- Users often face **scanning issues** such as false positives and slow scans, affecting overall efficiency and workflow.
- Users report **false positives** and slow scans in Snyk, affecting efficiency and integration with other tools.

#### What Are Recent G2 Reviews of Snyk?

**["Seamless Dev-First Security with Fast Scans and Actionable Fixes"](https://www.g2.com/survey_responses/snyk-review-12676270)**

**Rating:** 4.5/5.0 stars

_— Prateek J._

[Read full review](https://www.g2.com/survey_responses/snyk-review-12676270)

**["Developer-Friendly Security with Clear, Automated Fixes"](https://www.g2.com/survey_responses/snyk-review-12974957)**

**Rating:** 4.5/5.0 stars

_— Hemanth K._

[Read full review](https://www.g2.com/survey_responses/snyk-review-12974957)

#### What Are G2 Users Discussing About Snyk?

- [What is Snyk scanning?](https://www.g2.com/discussions/what-is-snyk-scanning) - 2 comments, 2 upvotes
- [Is Snyk a SaaS?](https://www.g2.com/discussions/is-snyk-a-saas) - 2 comments
- [How good is Snyk?](https://www.g2.com/discussions/how-good-is-snyk) - 2 comments
- [What is Snyk used for?](https://www.g2.com/discussions/what-is-snyk-used-for)

## FAQs About AI AppSec Assistants

Generated using AI

Last updated: June 3, 2026

### Which AI AppSec platforms avoid high false positive rates that waste security and developer time

Based on G2 reviews, these products are most often praised for reducing noisy findings and helping teams focus on real issues.

- [Aikido Security](https://www.g2.com/products/aikido-security) — low-noise findings with fast remediation.
- [DryRun Security](https://www.g2.com/products/dryrun-security) — contextual PR feedback with high signal.
- [SonarQube](https://www.g2.com/products/sonarqube) — early code checks with quality gates.
- [Snyk](https://www.g2.com/products/snyk) — reachability-based triage for dependencies.

### AI AppSec Assistants with accurate detection of OWASP Top 10 vulnerabilities and supply chain risks

According to verified users, strong AI AppSec Assistants are valued for surfacing meaningful vulnerabilities across code, dependencies, containers, secrets, and cloud environments without overwhelming teams with noise. Reviews repeatedly highlight the importance of clear remediation guidance, contextual findings, and prioritization that helps developers act quickly. Recent G2 feedback also points to demand for coverage of common web application risks such as injection flaws, authorization issues, leaked secrets, and insecure dependencies. Buyers evaluating this category should look for products that combine code scanning with software composition analysis, explain why an issue matters, and fit naturally into pull requests, CI pipelines, or repository-based workflows so fixes happen before release.

### Which AI AppSec solutions integrate into IDEs and provide real-time guidance during code development

Based on G2 reviews, these products stand out for developer-facing workflows, in-editor feedback, or fast guidance during coding and review.

- [SonarQube](https://www.g2.com/products/sonarqube) — IDE plugin feedback with quality gates.
- [Snyk](https://www.g2.com/products/snyk) — VS Code scans and remediation help.
- [Amazon Q Developer](https://www.g2.com/products/amazon-q-developer) — IDE assistance with security suggestions.
- [Aikido Security](https://www.g2.com/products/aikido-security) — workflow guidance with actionable fixes.

### What are AI AppSec Assistants

AI AppSec Assistants are tools that help teams find, prioritize, and remediate application security issues within software development workflows. Recent G2 reviews describe them as products that scan code, dependencies, containers, secrets, and related environments while giving developers actionable guidance instead of long lists of raw alerts. They are commonly used in pull requests, repositories, CI pipelines, and dashboards so teams can catch vulnerabilities earlier and reduce manual review effort. Across the category, buyers consistently value fast setup, clear explanations, lower false-positive rates, and remediation support that helps engineering and security teams work from the same findings without slowing delivery.

### How does AI AppSec Assistants integrate with GitHub

G2 reviewers mention GitHub integration as one of the most practical workflows in this category. Recent reviews describe teams connecting repositories quickly, scanning pull requests or merged code, and receiving findings directly where developers already work. Common benefits include PR comments, automatic repository onboarding, alerts on new issues, and remediation guidance that reduces context switching. Buyers also appear to value tools that support continuous monitoring after code changes, help prioritize what should be fixed first, and make security review easier for both developers and AppSec teams. In the latest G2 feedback, GitHub-connected workflows are especially associated with faster reviews, earlier detection, and better trust in findings.

### [OX Security](https://www.g2.com/products/ox-security/reviews)

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

**Average Rating:** 4.8/5.0

**Total Reviews:** 51

#### Who Is the Company Behind OX Security?

- **Seller:** [OX Security](https://www.g2.com/sellers/ox-security)
- **Year Founded:** 2021
- **HQ Location:** New York, USA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ee8e1fc166aedd5d2f8edd57605f86ae8eec3007f5eee8810871f0e4645b4f4d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fox-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
199 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer
- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 63% Medium, 25% Large

#### What Do G2 Reviewers Say About OX Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **intuitive dashboard and seamless integration** of OX Security, enhancing their security management and workflow efficiency.
- Users value the **seamless collaboration** enabled by OX Security, enhancing their focus on critical development tasks.
- Users commend the **responsive customer support** of OX Security, enhancing their overall operational efficiency and satisfaction.
- Users value the **seamless integrations** with existing tools, enhancing workflows and boosting overall development efficiency.
- Users appreciate the **speed** of OX Security, enabling faster remediation of vulnerabilities and cloud misconfigurations.

##### Cons

- Users find the **complexity** of OX Security daunting, facing a steep learning curve and inadequate documentation.
- Users find the **interface overwhelming** , with a steep learning curve and insufficient documentation to guide new users.
- Users find the **complex setup** challenging, especially due to inadequate documentation and overwhelming UI for new users.
- Users find the **executive dashboard limiting** , impacting effective reporting on product security enhancements to management.
- Users find OX Security's **difficult learning curve** challenging, particularly due to its complex interface and lacking documentation.

#### What Are Recent G2 Reviews of OX Security?

**["A powerful and comprehensive tool that meets most best practices for web app security testing"](https://www.g2.com/survey_responses/ox-security-review-10961361)**

**Rating:** 4.5/5.0 stars

_— Verified User in Gambling & Casinos_

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10961361)

**["Holistic Security Solution with Seamless Integration"](https://www.g2.com/survey_responses/ox-security-review-10487561)**

**Rating:** 4.5/5.0 stars

_— Sharon S._

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10487561)

### [Replit](https://www.g2.com/products/replit/reviews)

Replit turns your ideas into apps, fast. With Replit, anyone—technical or non-technical—can build and deploy fully-functional, full-stack apps directly from their browser, without any installation, setup, or configuration. Replit's Agent and Assistant enables you to create entire applications from natural language, turning bullet points into working apps in minutes. Its built-in tools, including databases and deployment features, allow you to launch with a single click. Replit bridges the gap between non-technical and technical users, driving collaboration for everything from product roadmaps and prototypes to custom APIs and internal tools. Replit empowers everyone to not just consume software but to create it, transforming app development into an accessible, instant, and impactful process. Go from 'why doesn't this app exist?' to building it for&nbsp;yourself.

**Average Rating:** 4.5/5.0

**Total Reviews:** 398

#### Who Is the Company Behind Replit?

- **Seller:** [Replit](https://www.g2.com/sellers/replit)
- **Year Founded:** 2016
- **HQ Location:** San Francisco, US
- **Twitter:** @Replit  
234,474 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=17f5b5008fb2b84ef743fdad87fe673f616078933e0679c4cae52958a8096fed&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Frepl-it%2F&secure%5Burl_type%5D=linkedin_company_website)  
516 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Founder, CEO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 66% Small, 12% Medium

#### What Do G2 Reviewers Say About Replit?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Replit's **ease of use** invaluable, enabling seamless prototyping and deployment of sophisticated applications effortlessly.
- Users value Replit for its **instant coding and execution** capabilities, enhancing prototyping and collaborative development swiftly.
- Users commend the **implementation ease** of Replit, praising its user-friendly setup for building applications effortlessly.
- Users value the **time-saving features** of Replit, allowing for rapid prototyping and seamless deployment of applications.
- Users find Replit's **coding assistance invaluable** , enabling effortless project development and enhancing coding skills for beginners and pros alike.

##### Cons

- Users find Replit **expensive** due to confusing pricing, unexpected charges, and difficulties in estimating project costs.
- Users express frustration over the **rapid depletion of credits** , making cost management and usage transparency a challenge.
- Users experience **poor coding** with Replit, leading to wasted resources and frustrating errors in complex projects.
- Users experience **system unreliability** with Replit, facing issues like time-consuming loops and broken functionality during projects.
- Users experience **slow performance** with Replit, particularly during edits, which can hinder project development and usability.

#### What Are Recent G2 Reviews of Replit?

**["Zero-Setup Replit Cloud Dev That Makes Rapid Prototyping Lightning-Fast"](https://www.g2.com/survey_responses/replit-review-13138653)**

**Rating:** 4.5/5.0 stars

_— Vaibhav T._

[Read full review](https://www.g2.com/survey_responses/replit-review-13138653)

**["Coding anywhere: the browser based revolution."](https://www.g2.com/survey_responses/replit-review-13164550)**

**Rating:** 4.5/5.0 stars

_— Arjun s._

[Read full review](https://www.g2.com/survey_responses/replit-review-13164550)

#### What Are G2 Users Discussing About Replit?

- [Does Repl.it have GUI?](https://www.g2.com/discussions/does-repl-it-have-gui) - 1 comment, 1 upvote
- [What is REPL software?](https://www.g2.com/discussions/what-is-repl-software) - 2 comments
- [What is Repl.it good for?](https://www.g2.com/discussions/what-is-repl-it-good-for) - 2 comments

### [DryRun Security](https://www.g2.com/products/dryrun-security/reviews)

Security leaders face a paradox: ship faster and enable agentic development while staying secure and keeping developers productive. DryRun Security resolves this by securing every pull request and repo with a high-precision, automated security engineer review right where developers and their agents build. DryRun Security is the industry’s most accurate agentic code security intelligence platform. Powered by its proprietary Contextual Security Analysis (CSA) engine, DryRun Security delivers the AI moment for security teams in an AI-native developer world. Traditional static application security testing (SAST) floods teams with alerts, misses higher-order risk, and burns time in triage. DryRun Security goes beyond SAST with contextual analysis that prioritizes what is exploitable and impactful in your codebase, then helps engineers remediate fast. Instead of “find everything and hope someone sorts it out,” DryRun Security delivers code security intelligence that is ready to act on. DryRun Security puts a security engineer directly into developer workflows. In pull requests, the Code Review Agent reviews changes in context, explains risk in plain language, and guides fixes where developers already work. In repos, the DeepScan Agent produces focused, human-grade findings for the issues that actually matter, without weeks of manual review before major milestones. The Custom Policy Agent enforces guardrails with Natural Language Code Policies, so you can standardize security and compliance requirements across teams without brittle rule sets. Codebase Insights allows leaders to ask questions of their entire codebase like "Are we exposed to this new vulnerability" and have confidence in minutes. DryRun Security also integrates with AI coding workflows, so remediation happens with the precision of a security engineer working at machine speed. Teams connect DryRun Security insights and guidance into Claude, Cursor, OpenAI Codex, and Windsurf, helping developers and their agents fix issues with contextual, security-engineered direction tied to the PR and codebase. What DryRun Security delivers (beyond SAST) • Automated secure code review in every pull request with high-signal findings and low noise • Contextual Security Analysis that catches common vulnerabilities and deeper multi-dependency and logic risks • Automated remediation guidance that helps engineers fix faster, with explanations and next steps • Secrets analysis identifies genuine hardcoded secrets and suppresses the usual false alarms • Policy enforcement in PRs using Natural Language Code Policies for consistent guardrails across repos • Codebase intelligence and reporting for AppSec visibility, prioritization, and audit-ready evidence DryRun Security supports most code environments, languages, and frameworks, including: • GitHub, GitLab • C#, Golang, Elixir, JavaScript, TypeScript, Python, Ruby, Java, Kotlin, PHP, Swift, HTML • Infrastructure as Code (Terraform, YAML) • And more

**Average Rating:** 4.9/5.0

**Total Reviews:** 20

#### Who Is the Company Behind DryRun Security?

- **Seller:** [DryRun Security](https://www.g2.com/sellers/dryrun-security)
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6a05a774e1320fb12547e26ce7fe95d94335bc0c4be6317172500089b5b6db36&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdryrun-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
16 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 40% Small, 30% Medium

#### What Do G2 Reviewers Say About DryRun Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **context-aware security feedback** from DryRun Security, enhancing vulnerability mitigation during development in GitHub.
- Users appreciate the **quick and context-aware vulnerability detection** of DryRun Security, enhancing security during the development process.
- Users value the **seamless integration and advanced detections** of DryRun Security, enhancing code security and development efficiency.
- Users value the **accuracy of feedback** from DryRun Security, effectively minimizing false positives and identifying complex vulnerabilities.
- Users appreciate the **easy setup** of DryRun Security, enabling seamless integration and quick vulnerability detection.

##### Cons

- Users find the **slow performance** of DryRun Security's management portal frustrating, impacting their overall experience.
- Users experience **slow speed** issues with the management portal, impacting overall usability and efficiency.
- Users note the **sluggish UI** of DryRun Security, which hampers the overall developer experience during use.
- Users feel there are **limited customization options** for analyzers, though improvements may be forthcoming.
- Users feel that there are **workflow issues** that hinder the developer experience and adoption of DryRun Security.

#### What Are Recent G2 Reviews of DryRun Security?

**["Catches Logic and Authorization Flaws Traditional SAST Often Misses"](https://www.g2.com/survey_responses/dryrun-security-review-12357188)**

**Rating:** 5.0/5.0 stars

_— Jabez A._

[Read full review](https://www.g2.com/survey_responses/dryrun-security-review-12357188)

**["Next Gen of SAST Tool That Has Cutting Edge Tech"](https://www.g2.com/survey_responses/dryrun-security-review-12462338)**

**Rating:** 5.0/5.0 stars

_— Francis D._

[Read full review](https://www.g2.com/survey_responses/dryrun-security-review-12462338)

### [Codeant AI Code Reviewer](https://www.g2.com/products/codeant-ai-code-reviewer/reviews)

CodeAnt AI reviews your code line by line, finds critical code quality issues and security vulnerabilities, explains their impact, and guides you on how to fix them. It’s SOC 2 and HIPAA compliant, doesn’t store your code, and uses end-to-end encryption for security.

**Average Rating:** 4.7/5.0

**Total Reviews:** 7

#### Who Is the Company Behind Codeant AI Code Reviewer?

- **Seller:** [CodeAnt AI](https://www.g2.com/sellers/codeant-ai)
- **Year Founded:** 2023
- **HQ Location:** San Francisco, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8b8ad0e1a4add2a2c9b8a5432a9fd01f6ff9fe8b595842b674830f2dd00fddda&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcodeant-ai&secure%5Burl_type%5D=linkedin_company_website)  
22 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 57% Small, 43% Medium

#### What Do G2 Reviewers Say About Codeant AI Code Reviewer?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **high code quality** of Codeant AI Code Reviewer, benefiting from effective linting and inline suggestions.
- Users value the **one-click fixes and comprehensive coverage** of Codeant AI Code Reviewer, enhancing their coding experience.
- Users appreciate the **end-to-end functionality** of Codeant AI Code Reviewer, offering a simple interface for comprehensive code assessment.
- Users value the **custom rules** feature for improving code context and enhancing review efficiency.
- Users appreciate the **ease of use** of Codeant AI Code Reviewer, benefiting from its comprehensive and simple interface.

##### Cons

- Users find the **difficult learning curve** challenging due to cautious suggestions requiring manual tweaks and prolonged onboarding.
- Users find the **false positives** in suggestions excessive, requiring manual adjustments and making onboarding time-consuming.
- Users find the **improvement needed** for Codeant AI Code Reviewer due to cautious suggestions and lengthy onboarding.
- Users find the **inefficient notifications** can be overly cautious, requiring manual adjustments and time-consuming onboarding processes.
- Users find the **lack of guidance** in Codeant AI Code Reviewer can lead to cautious suggestions and slow onboarding.

#### What Are Recent G2 Reviews of Codeant AI Code Reviewer?

**["Time-Saving, Error-Free Code Reviews"](https://www.g2.com/survey_responses/codeant-ai-code-reviewer-review-12739633)**

**Rating:** 4.0/5.0 stars

_— abhilekh T._

[Read full review](https://www.g2.com/survey_responses/codeant-ai-code-reviewer-review-12739633)

**["Useful for improving code quality during reviews"](https://www.g2.com/survey_responses/codeant-ai-code-reviewer-review-13002627)**

**Rating:** 4.5/5.0 stars

_— Bhavishya J._

[Read full review](https://www.g2.com/survey_responses/codeant-ai-code-reviewer-review-13002627)

### [Amazon Q Developer](https://www.g2.com/products/amazon-q-developer/reviews)

Amazon Q Developer is a generative AI-powered assistant designed to enhance the entire software development lifecycle. It integrates seamlessly into various development environments, offering real-time code suggestions, automating routine tasks, and providing expert guidance on AWS services. By leveraging advanced AI capabilities, Amazon Q Developer aims to boost developer productivity, improve code quality, and streamline operations. Key Features and Functionality: - Real-Time Code Suggestions: Generates code snippets and full functions based on comments and existing code, supporting multiple programming languages. - Inline Chat and CLI Support: Offers inline chat within code editors and command-line interface (CLI) completions, including natural language-to-bash translation. - Security and Reliability Enhancements: Scans code for vulnerabilities, suggests remediations, and assists in writing unit tests to optimize code performance. - Agentic Capabilities: Autonomously performs tasks such as implementing features, documenting, testing, reviewing, refactoring code, and executing software upgrades. - AWS Integration: Provides expert assistance on AWS services, helping to optimize cloud resources, analyze costs, and adhere to architectural best practices. - Multi-Platform Availability: Compatible with popular integrated development environments (IDEs) like JetBrains, Visual Studio Code, Eclipse, and Visual Studio, as well as command-line interfaces and chat applications like Microsoft Teams and Slack. Primary Value and User Solutions: Amazon Q Developer addresses common challenges in software development by automating time-consuming tasks, reducing the cognitive load on developers, and enhancing code quality. Its integration with AWS services ensures that applications are built following best practices, leading to more efficient and secure cloud operations. By providing real-time assistance and automating routine processes, Amazon Q Developer enables developers to focus on innovation and delivering value to their users.

**Average Rating:** 4.6/5.0

**Total Reviews:** 50

#### Who Is the Company Behind Amazon Q Developer?

- **Seller:** [Amazon Web Services (AWS)](https://www.g2.com/sellers/amazon-web-services-aws-3e93cc28-2e9b-4961-b258-c6ce0feec7dd)
- **Year Founded:** 2006
- **HQ Location:** Seattle, WA
- **Twitter:** @awscloud  
2,232,483 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=072881eee28a2afe24f8d1bda9f20e3e146b9fb4b214f216411ce2ed6898b31e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Famazon-web-services%2F&secure%5Burl_type%5D=linkedin_company_website)  
147,094 employees on LinkedIn®
- **Ownership:** NASDAQ: AMZN

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 41% Small, 31% Large

#### What Do G2 Reviewers Say About Amazon Q Developer?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Amazon Q Developer for speeding up coding and debugging processes.
- Users value the **coding assistance** of Amazon Q Developer, enhancing learning and speeding up development processes.
- Users value the **easy integrations** of Amazon Q Developer, enhancing coding assistance and troubleshooting for AWS tasks.
- Users appreciate the **context-aware code suggestions** and guidance of Amazon Q Developer, enhancing learning and coding efficiency.
- Users appreciate the **seamless integration and multi-language support** of Amazon Q Developer, enhancing productivity and learning experiences.

##### Cons

- Users face **poor suggestions** from Amazon Q Developer, causing confusion with incomplete or incorrect code recommendations.
- Users experience **inaccuracy** in suggestions, affecting code performance and usability, especially for complex scenarios.
- Users experience **irrelevant or generic responses** with Amazon Q Developer, especially for niche coding patterns and frameworks.
- Users find the **poor integration** with other tools and AWS credentials cumbersome, affecting learning and functionality.
- Users report **slow performance** when handling large files, affecting overall usability and generating awkward suggestions.

#### What Are Recent G2 Reviews of Amazon Q Developer?

**["Amazon Q Developer Speeds Up Development with Helpful Code Generation and Explanations"](https://www.g2.com/survey_responses/amazon-q-developer-review-13149880)**

**Rating:** 4.5/5.0 stars

_— Brian A._

[Read full review](https://www.g2.com/survey_responses/amazon-q-developer-review-13149880)

**["Context-Aware AWS Coding Help That Keeps Me in the IDE"](https://www.g2.com/survey_responses/amazon-q-developer-review-13160466)**

**Rating:** 4.5/5.0 stars

_— Atharva P._

[Read full review](https://www.g2.com/survey_responses/amazon-q-developer-review-13160466)

### [Appdome](https://www.g2.com/products/appdome/reviews)

Appdome is an agentic platform that protects mobile apps and the mobile business at scale. Trusted by enterprises worldwide, Appdome automates mobile app security, fraud prevention, bot defense, and threat detection and response across Android and iOS applications. Unlike legacy SDK-based approaches that require manual implementation and ongoing maintenance, Appdome uses AI agents to embed protections directly into mobile apps, analyze threats in real time, and continuously adapt defenses without code or complex integration. Organizations use Appdome to protect mobile apps, APIs, identities, accounts, transactions, and users from fraud, bots, malware, account takeover, deepfakes, and other cyber threats. Appdome’s agentic mobile defense platform includes: Identity and reputation protection Fraud and account takeover (ATO) prevention Bot and API defense Mobile app security (RASP and app shielding) DevSecOps and CI/CD integration Threat management and response (including ThreatScope™ Mobile XDR, ThreatEvents™, and Threat Resolution Center™)

**Average Rating:** 4.8/5.0

**Total Reviews:** 90

#### Who Is the Company Behind Appdome?

- **Seller:** [Appdome](https://www.g2.com/sellers/appdome)
- **Company Website:** www.appdome.com
- **Year Founded:** 2012
- **HQ Location:** Redwood City, California, United States
- **Twitter:** @appdome  
2,107 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e96815550f91fcda1fc5c83b1e0150743d209e6e4a96929e4af0346d903767b7&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fappdome%2F&secure%5Burl_type%5D=linkedin_company_website)  
173 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Banking, Financial Services
- **Company Size:** 50% Large, 34% Medium

#### What Do G2 Reviewers Say About Appdome?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **proactive customer support** provided by Appdome, ensuring timely assistance and resolution of issues.
- Users appreciate the **superior security protections** offered by Appdome, enhancing the safety of their applications effortlessly.
- Users appreciate the **ease of use** of Appdome, complemented by its intuitive GUI and responsive support.
- Users value the **runtime application protection** of Appdome, appreciating the ease of use and no code requirements.
- Users highlight the **ease of implementation** with Appdome, benefiting from fast and efficient no-code integration.

##### Cons

- Users note that Appdome's licensing is **quite expensive** , making it challenging for smaller companies to afford fully.
- Users find the platform's **overwhelming complexity** challenging due to its numerous features and configuration options.
- Users find the **initial learning curve** challenging due to the overwhelming number of features and configurations.
- Users find the **learning difficulty** challenging due to the complex configurations and initial setup required for Appdome.
- Users find the **poor documentation** of Appdome makes configuration and understanding features needlessly complicated.

#### What Are Recent G2 Reviews of Appdome?

**["Efficiency and Innovation in Mobile Security with Appdome"](https://www.g2.com/survey_responses/appdome-review-13122430)**

**Rating:** 5.0/5.0 stars

_— Adelmo A._

[Read full review](https://www.g2.com/survey_responses/appdome-review-13122430)

**["Runtime Protection with Zero Code Changes and Streamlined Diagnostics"](https://www.g2.com/survey_responses/appdome-review-12380321)**

**Rating:** 5.0/5.0 stars

_— Ersa D._

[Read full review](https://www.g2.com/survey_responses/appdome-review-12380321)

### [CybeDefend](https://www.g2.com/products/cybedefend-cybedefend/reviews)

CybeDefend is the application security platform built for the AI coding era. Traditional shift-left security detects vulnerabilities after the code is written. But with Claude Code, Cursor, Copilot and Codex generating thousands of lines per developer per day, human review can no longer keep pace and the pull request is no longer the right control point. CybeDefend operates at shift-zero, directly inside the AI coding agent loop. Our flagship product VibeDefend is the MCP-native security layer that injects your business rules and compliance policies straight into the agent's context, before the first line of code is written. The agent ships safe code by default, on every developer's machine, without slowing the team down. Our AI-BOM scanner discovers every AI asset in your code (models, datasets, prompts, agents, MCP servers, guardrails) and produces the EU AI Act Annex IV evidence dossier plus NIST AI RMF mapping directly in your CI pipeline. No questionnaire, no consultant. Built-in build gate on prohibited and ungoverned high-risk components. The complete AppSec stack comes unified on top: SAST, SCA, IaC, CI/CD, Secrets and Container scanning, powered by a knowledge graph of business-logic rules auto-mined from your repository. Sovereign cloud (SecNumCloud-certified) or US cloud at your choice, on-premise deployment available for regulated industries. Code never leaves the machine, only metadata.

**Average Rating:** 5.0/5.0

**Total Reviews:** 3

#### Who Is the Company Behind CybeDefend?

- **Seller:** [CybeDefend](https://www.g2.com/sellers/cybedefend)
- **Year Founded:** 2025
- **HQ Location:** Paris, FR
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=42b551069b3ef1a88027137d4dd6f2f45c052aa4e72c18ecb19da11d34f3f0c3&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcybedefend&secure%5Burl_type%5D=linkedin_company_website)  
3 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Small, 33% Medium

#### What Are Recent G2 Reviews of CybeDefend?

**["Seamless CI/GitOps Integration and Time-Saving MCP-Powered Remediation"](https://www.g2.com/survey_responses/cybedefend-review-13101698)**

**Rating:** 5.0/5.0 stars

_— Olivier d._

[Read full review](https://www.g2.com/survey_responses/cybedefend-review-13101698)

**["Reactive updates and top-notch GitHub CI/CD integration"](https://www.g2.com/survey_responses/cybedefend-review-13109769)**

**Rating:** 5.0/5.0 stars

_— Geoffrey P._

[Read full review](https://www.g2.com/survey_responses/cybedefend-review-13109769)

### [Checkmarx](https://www.g2.com/products/checkmarx/reviews)

Checkmarx is a type of application security solution designed to help organizations safeguard their software development processes while enhancing efficiency and reducing costs. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. With the increasing reliance on AI technologies and the rapid pace of software development, Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as AI SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

**Average Rating:** 4.2/5.0

**Total Reviews:** 44

#### Who Is the Company Behind Checkmarx?

- **Seller:** [Checkmarx](https://www.g2.com/sellers/checkmarx)
- **Company Website:** www.checkmarx.com
- **Year Founded:** 2006
- **HQ Location:** Paramus, NJ
- **Twitter:** @Checkmarx  
7,284 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=18f6741e77df71b112ecb3ec6620912d3a0f67666525358c0a4f3b1278b173df&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheckmarx&secure%5Burl_type%5D=linkedin_company_website)  
1,019 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 56% Large, 23% Medium

#### What Do G2 Reviewers Say About Checkmarx?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Checkmarx **easy to implement** , seamlessly integrating into existing repositories with a user-friendly interface.
- Users appreciate the **intuitive user interface** of Checkmarx, making security reviews simple and user-friendly.
- Users value the **accuracy of results** from Checkmarx, as it simplifies security reviews with detailed vulnerability insights.
- Users value the **automation testing capabilities** of Checkmarx, finding it easy to integrate and use effectively.
- Users praise the **exceptional customer support** at Checkmarx, ensuring prompt assistance for any unresolved issues.

##### Cons

- Users face a high number of **false positives** in Checkmarx when working with Kotlin projects, affecting accuracy and reliability.
- Users report **lacking feature support** for Kotlin, leading to numerous false positives not seen in Java or JavaScript.
- Users experience **missing features** in Checkmarx, specifically regarding poor support for Kotlin that leads to false positives.
- Users find the **poor navigation** in Checkmarx frustrating, as the dashboard layout and display need enhancement.

#### What Are Recent G2 Reviews of Checkmarx?

**["Centralized Source Code Security with Seamless CI/CD Integration"](https://www.g2.com/survey_responses/checkmarx-review-12980590)**

**Rating:** 5.0/5.0 stars

_— Aman M._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12980590)

**["Checkmarx: Reliable SAST Solution for Strengthening Application Security"](https://www.g2.com/survey_responses/checkmarx-review-13085824)**

**Rating:** 4.0/5.0 stars

_— Naushad T._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-13085824)

#### What Are G2 Users Discussing About Checkmarx?

- [What is Checkmarx used for?](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for) - 1 comment, 1 upvote
- [How much does Checkmarx cost?](https://www.g2.com/discussions/how-much-does-checkmarx-cost)
- [Which testing method does Checkmarx support?](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support) - 1 comment
- [Does Checkmarx support DAST?](https://www.g2.com/discussions/does-checkmarx-support-dast) - 1 comment
- [What is Checkmarx used for?](https://www.g2.com/discussions/what-is-checkmarx-used-for) - 2 comments

### [Tabnine](https://www.g2.com/products/tabnine/reviews)

Tabnine provides the world’s most contextually-aware AI software development agents, autonomously completing the broadest variety of tasks across the SDLC without sacrificing privacy. Tabnine boosts engineering velocity and software quality through AI tools customized to each unique organization’s coding patterns, standards, and expectations. Many AI tools can write software, but only Tabnine generates and validates software like your best engineers.Unlike generic coding assistants, Tabnine is the AI software development platform tailored to you and your team: - Personalized — Tabnine delivers an optimized experience for each development team; it is highly context-aware, integrates with the widest variety of IT systems to gain understanding and to act, and learns and applies your unique approach and policies,. - Private — You choose where and how to deploy Tabnine (SaaS, VPC, or on-premises) to maximize control over your IP, and you choose both the underlying LLM and how it is applied (including private endpoints and fully private deployment). - Protected — Tabnine has the most comprehensive approach to assuring license and copyright compliance. Tabnine evaluates all AI-generated code (flagging any matches with publicly visible code) and also offers a proprietary model exclusively trained on permissively licensed code to support the strictest teams and use cases. Tabnine pioneered AI-enabled software development and now supports more than a million developers across thousands of teams, making it one of the most widely used AI applications in the world. Tabnine is privately held and backed by top-tier investors. We support all the popular IDEs namely - VS Code - JetBrains IDEs - Eclipse - Visual Studio 2022 We support all the major programming languages. Refer here for more details (https://docs.tabnine.com/main/welcome/readme/supported-languages) - JavaScript - TypeScript - Python - Java - C - C++ - C# - Go - Php - Ruby - Kotlin / Dart - Rust - React / Vue - HTML 5 - CSS - Lua - Cuda - Perl - SQL - Scala - Shell (bash) - Swift - R - Julia - VB - Groovy - Matlab - Terraform - ABAP

**Average Rating:** 4.1/5.0

**Total Reviews:** 59

#### Who Is the Company Behind Tabnine?

- **Seller:** [Tabnine](https://www.g2.com/sellers/tabnine)
- **Company Website:** www.tabnine.com
- **Year Founded:** 2017
- **HQ Location:** Tel Aviv, IL
- **Twitter:** @tabnine  
14,894 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=4b8ac3b5de0eb36d828fb21a3b093cb5899624a37236eca3554b408548191dfe&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftabnine&secure%5Burl_type%5D=linkedin_company_website)  
68 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 66% Small, 25% Medium

#### What Do G2 Reviewers Say About Tabnine?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Tabnine, benefiting from quick task completion and reliable auto-suggestions.
- Users appreciate the **coding assistance** from Tabnine, enhancing productivity with quick, reliable auto-suggestions and insights.
- Users appreciate the **fast performance and team collaboration features** of Tabnine, enhancing productivity and code quality.
- Users appreciate the **reliable auto-suggestions** from Tabnine, greatly enhancing productivity and coding speed during development.
- Users value the **rapid performance and intelligent code suggestions** of Tabnine, enhancing productivity and code quality.

##### Cons

- Users criticize Tabnine for its **poor coding performance** , finding better alternatives like ChatGPT Plus for their needs.
- Users experience **poor suggestions** from Tabnine, particularly struggling with JS UI frameworks and incorrect recommendations.
- Users find Tabnine's **AI integration lacking** in performance and limited compared to other available options.
- Users face **compatibility issues** with Tabnine, especially for JS UI frameworks, affecting reliability and accuracy.
- Users often face **irrelevant responses** , leading to incorrect suggestions and frustrating coding experiences, especially with UI frameworks.

#### What Are Recent G2 Reviews of Tabnine?

**["Streamlined Coding with Predictive Assistance"](https://www.g2.com/survey_responses/tabnine-review-13181160)**

**Rating:** 4.5/5.0 stars

_— Praney M._

[Read full review](https://www.g2.com/survey_responses/tabnine-review-13181160)

**["Super useful VS Code extension for typing code faster in college projects"](https://www.g2.com/survey_responses/tabnine-review-13154965)**

**Rating:** 4.5/5.0 stars

_— Krishnakant R._

[Read full review](https://www.g2.com/survey_responses/tabnine-review-13154965)

#### What Are G2 Users Discussing About Tabnine?

- [Can I use Tabnine for free?](https://www.g2.com/discussions/can-i-use-tabnine-for-free) - 2 comments
- [Which is better kite or Tabnine?](https://www.g2.com/discussions/which-is-better-kite-or-tabnine) - 1 comment
- [What languages does Tabnine support?](https://www.g2.com/discussions/what-languages-does-tabnine-support) - 1 comment
- [What is Tabnine used for?](https://www.g2.com/discussions/what-is-tabnine-used-for) - 1 comment

### [Black Duck SCA](https://www.g2.com/products/black-duck-sca/reviews)

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it, development and DevSecOps teams to automate testing within development pipelines without compromising velocity, and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

**Average Rating:** 4.1/5.0

**Total Reviews:** 31

#### Who Is the Company Behind Black Duck SCA?

- **Seller:** [Black Duck](https://www.g2.com/sellers/black-duck)
- **Year Founded:** 2024
- **HQ Location:** Burlington, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ca66ef383f133f101804712b9ed7a89aec2633a8efa048bd261db3b92eb47e73&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fblack-duck-software&secure%5Burl_type%5D=linkedin_company_website)  
1,345 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 44% Large, 34% Medium

#### What Do G2 Reviewers Say About Black Duck SCA?

_AI-generated summary from verified user reviews_

##### Pros

- Users praise the **accuracy of findings** in Black Duck, citing its powerful engine for identifying open source issues.
- Users praise Black Duck for its **powerful engine in identifying open source issues** and vast knowledge base.

##### Cons

- Users face **huge resource constraints** when deploying Black Duck on-prem, which complicates implementation efforts.

#### What Are Recent G2 Reviews of Black Duck SCA?

**["Accurate Vulnerability Insights and Remediation—A Must-Have SCA Platform"](https://www.g2.com/survey_responses/black-duck-sca-review-13130414)**

**Rating:** 5.0/5.0 stars

_— Sonal K._

[Read full review](https://www.g2.com/survey_responses/black-duck-sca-review-13130414)

**["Reliable Open Source Security Tool with Strong CI/CD Integration"](https://www.g2.com/survey_responses/black-duck-sca-review-13033411)**

**Rating:** 5.0/5.0 stars

_— Md Sarfaraz H._

[Read full review](https://www.g2.com/survey_responses/black-duck-sca-review-13033411)

#### What Are G2 Users Discussing About Black Duck SCA?

- [What languages does Black Duck support?](https://www.g2.com/discussions/what-languages-does-black-duck-support)
- [What is software composition analysis?](https://www.g2.com/discussions/what-is-software-composition-analysis)
- [What is Black Duck analysis?](https://www.g2.com/discussions/what-is-black-duck-analysis)
- [What is the use of Black Duck software?](https://www.g2.com/discussions/what-is-the-use-of-black-duck-software)

### [Semgrep](https://www.g2.com/products/semgrep/reviews)

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

**Average Rating:** 4.6/5.0

**Total Reviews:** 56

#### Who Is the Company Behind Semgrep?

- **Seller:** [Semgrep](https://www.g2.com/sellers/semgrep)
- **Company Website:** semgrep.dev
- **Year Founded:** 2017
- **HQ Location:** San Francisco, US
- **Twitter:** @semgrep  
4,433 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=968a71f2060531e986a3873882c34b492bee4d8d264ff88e0089e53b8f7771f4&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freturntocorp&secure%5Burl_type%5D=linkedin_company_website)  
262 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 45% Large, 43% Medium

#### What Do G2 Reviewers Say About Semgrep?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Semgrep, praising its intuitive syntax and smooth CI/CD integration.
- Users appreciate the **intuitive pattern-matching syntax** of Semgrep, enabling effective custom rules for various programming languages.
- Users appreciate Semgrep's **effective vulnerability detection** , enabling quick identification of security issues with low false positives.
- Users value the **scanning efficiency** of Semgrep, benefiting from rapid scans and seamless CI/CD integration.
- Users appreciate the **robust security features** of Semgrep, enabling effective identification and remediation of vulnerabilities effortlessly.

##### Cons

- Users find Semgrep **not user-friendly** , citing a steep learning curve and challenges in initial setup and customization.
- Users note the **limited features** of Semgrep, making categorization and comprehensive analysis more challenging.
- Users find the **difficult learning** curve for custom rules in Semgrep challenging, impacting new user experiences and efficiency.
- Users face a **lack of guidance** in mastering rule creation and initial setup, impacting effective tool utilization.
- Users find the **learning curve steep** for rule writing, especially for those new to static analysis tools.

#### What Are Recent G2 Reviews of Semgrep?

**["Streamlined Code Security with Semgrep"](https://www.g2.com/survey_responses/semgrep-review-11971635)**

**Rating:** 5.0/5.0 stars

_— Shreekanth k._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-11971635)

**["Fast, Easy-to-Customize Rules That Catch Security and Code-Quality Issues Early"](https://www.g2.com/survey_responses/semgrep-review-13079252)**

**Rating:** 4.5/5.0 stars

_— Milan K._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-13079252)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/ai-appsec-assistants?open_modal_url=%2Fproducts%2Freplit%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fai-appsec-assistants%26source%3Dcategory&order=g2_score&page=2#product-list)
- [Next &rsaquo;Next ›](/categories/ai-appsec-assistants?open_modal_url=%2Fproducts%2Freplit%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fai-appsec-assistants%26source%3Dcategory&order=g2_score&page=2#product-list)

Spotlight Categories

[Contract Management Software](https://www.g2.com/categories/contract-management)

[Sales Compensation Software](https://www.g2.com/categories/sales-compensation)

[Influencer Marketing Platforms](https://www.g2.com/categories/influencer-marketing-platforms)

[User Research Tools](https://www.g2.com/categories/user-research)

[VoIP Providers](https://www.g2.com/categories/voip)

Similar Categories

- [AI App Builder](/categories/ai-app-builder)
- [AI Chatbots](/categories/ai-chatbots)
- [AI Code Generation](/categories/ai-code-generation)
- [AI Coding Assistants](/categories/ai-coding-assistants)
- [AI Content Creation Platforms](/categories/ai-content-creation-platforms)

- [AI Image Generators](/categories/ai-image-generators)
- [AI SDK](/categories/ai-sdk)
- [AI Search & Retrieval Infrastructure Platforms](/categories/ai-search-retrieval-infrastructure-platforms)
- [AI Software Testing Tools](/categories/ai-software-testing-tools)
- [Generative AI Infrastructure](/categories/generative-ai-infrastructure)

- [Large Language Model Operationalization (LLMOps)](/categories/large-language-model-operationalization-llmops)
- [Large Language Models (LLMs)](/categories/large-language-models-llms)
- [Small Language Models (SLMs)](/categories/small-language-models-slms)
- [Synthetic Media](/categories/synthetic-media)

[Browse AI AppSec Assistants Themes](/categories/ai-appsec-assistants/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated April 9, 2026

AI AppSec assistants apply artificial intelligence and machine learning to help developers identify and fix security vulnerabilities throughout the software development lifecycle, embedding directly into development environments to provide real-time application security insights, contextual explanations, and automated or semi-automated remediation guidance.

### Core Capabilities of AI AppSec Assistants

To qualify for inclusion in the AI AppSec Assistants category, a product must:

- Use AI to provide real-time application security assistance within a development environment
- Automatically identify security weaknesses and vulnerabilities
- Remediate issues or deliver contextual, actionable remediation guidance
- Seamlessly integrate into development teams' existing workflows and practices

### Common Use Cases for AI AppSec Assistants

Development and security teams use AI AppSec assistants to shift security left, catching and fixing vulnerabilities earlier in the development cycle without slowing down engineering workflows. Common use cases include:

- Detecting insecure code patterns and vulnerabilities in real time as developers write code
- Providing contextual remediation guidance that explains security issues and suggests specific fixes in the developer's language and framework
- Improving collaboration between development and security teams by making security feedback actionable within existing developer environments

### How AI AppSec Assistants Differ from Other Tools

While [AI coding assistants](https://www.g2.com/categories/ai-coding-assistants) help developers with general programming tasks such as code completion and error detection, AI AppSec assistants focus specifically on application security, identifying vulnerabilities, explaining security risks, and guiding remediation within the development environment. This specialization makes them distinct from general coding assistants and from broader [application security tools](https://www.g2.com/categories/application-security) that operate outside the IDE, enabling a "secure by default" approach embedded directly in developer workflows.

### Insights from G2 on AI AppSec Assistants

Based on category trends on G2, real-time vulnerability detection and contextual remediation guidance stand out as standout capabilities. Faster vulnerability resolution and improved developer adoption of secure coding practices stand out as primary outcomes of adoption.

Show More