getapp-logo

App comparison

Add up to 4 apps below to see how they compare. You can also use the "Compare" buttons while browsing.

GetApp offers objective, independent research and verified user reviews. We may earn a referral fee when you visit a vendor through our links. 

Top Rated Static Application Security Testing (SAST) Software with Vulnerability scanning - Page 2

Last updated: September 2026

1 filter applied

Features


Integrated with


Pricing model


Devices supported


Organization types


User rating


46 software options

Checkmarx logo

Cloud-native application security platform for enterprises

learn more
Checkmarx is a cloud-native AppSec platform for enterprises, delivering SAST, SCA, DAST, API security, ASPM, and agentic AI.

Read more about Checkmarx

Users also considered
BuildPiper logo

Delivering software just got faster

learn more
BuildPiper is a product by OpsTree Labs, which is an end-to-end Kubernetes and microservices Delivery Platform. It is a hybrid cloud-enabled system that facilitates the deployment of dockerized code across multiple environments.

Read more about BuildPiper

Users also considered
Coverity logo

Build secure, high-quality software faster.

learn more
Coverity is a static application security testing (SAST) solution designed to help businesses manage risks across the application portfolio, address quality defects in the software development life cycle, and maintain compliance with many coding and security standards.

Read more about Coverity

Users also considered
Kiuwan logo

Secure your applications confidently with Kiuwan.

learn more
Kiuwan is an end-to-end application security platform supporting 30+ languages with SAST, SCA, & QA. Kiuwan integrates with IDEs for direct analysis, offers tailored reports, and meets NIST, CWE, & OWASP standards.

Manage open source components and secure your projects confidently with Kiuwan.

Read more about Kiuwan

Users also considered
Sigrid logo

One platform to manage your entire application landscape

learn more
Sigrid delivers a holistic SAST solution that empowers organizations to manage software security risks. By offering actionable insights, Sigrid helps companies strengthen their security defenses, streamline compliance processes, and accelerate the deployment of secure software applications.

Read more about Sigrid

Users also considered
Acunetix logo

Cloud-based and automated web application security solution

learn more
Acunetix is a cybersecurity solution offering automatic web security testing technology that enables organizations to scan and audit complex, authenticated, HTML5 and JavaScript-heavy websites to detect vulnerabilities such as XSS, SQL Injection, and more.

Read more about Acunetix

Users also considered
SonarQube logo

Code quality & security platform for all team sizes

learn more
SonarQube is a cloud-based and self-hosted code quality and security platform that detects bugs, vulnerabilities, and architecture.

Read more about SonarQube

Users also considered
SiteLock logo

Threat intelligence software for eCommerce businesses

learn more
SiteLock is a static application security testing (SAST) software designed to help businesses protect websites against malware and distributed denial-of-service (DDoS) attacks. Key features of the platform include threat detection, database scanning, bad bot blocking, automated plugin patching, security vulnerability repair, and website acceleration.

Read more about SiteLock

Users also considered
Codacy logo

Automated code review tool for developers

learn more
Codacy is an automated code reviews and code analytics platform which allows technical engineers and developers within businesses to automatically and accurately identify and address security concerns, code duplication, code style violations, and drops in coverage in every commit and pull request

Read more about Codacy

Users also considered
SpectralOps logo

Code security software for code and cloud

learn more
Spectral is a cloud-based software that enables teams to ship & build software while avoiding security mistakes, misconfigurations, credential leakage and data breaches without agents, across the entire software development lifecycle.

Read more about SpectralOps

Users also considered
Moderne logo

Source code modernization and maintenance platform

learn more
Moderne is an automated code refactoring and analysis platform for securing, migrating, maintaining, and modernizing software at mass scale. We make it easy for developers to collaborate and make big changes in their codebase fast, freeing time for innovation.

Read more about Moderne

Users also considered
Topscan logo

Automated security scanning for servers and APIs

learn more
TopScan is a security scanning platform that automatically detects vulnerabilities in servers, libraries, and APIs. The solution offers continuous monitoring, attack surface discovery, and vulnerability management capabilities using open-source scanning engines such as OWASP ZAP and Nuclei. TopScan includes features for web application security, cloud security, static code analysis, and SSL/TLS certificate monitoring, with integration options for CI/CD pipelines and Slack notifications.

Read more about Topscan

Users also considered
Axivion logo

Static Code Analysis to Assure the Quality of Your Software

learn more
Axivion Static Code Analysis by Qt QA enhances code quality via automated analysis for C/C++, compliance, and software longevity.

Read more about Axivion

Users also considered
HCL AppScan logo

Fast, Accurate, Agile Application Security Testing

learn more
HCL AppScan empowers developers, DevOps and security teams with a suite of testing tools to find and fix vulnerabilities in applications at all phases of development. It integrates seamlessly with DevSecOps pipelines to ensure continuous security and compliance.

Read more about HCL AppScan

Users also considered
SoonLab logo

AI-driven game creation & browser gaming platform

learn more
SoonLab is an AI-powered game creation and discovery platform that enables users to generate games without coding knowledge. The platform hosts a library of user-created games across multiple genres including action, puzzle, RPG, simulation, and strategy that can be played instantly in a web browser. Users can browse community-created content and utilize AI tools to design and publish their own games through the platform's game generator feature.

Read more about SoonLab

Users also considered
Coco logo

Code coverage analysis software for embedded devices

learn more
Coco is an embedded device code coverage analysis software that enables developers to assess how much of their code is being tested.

Read more about Coco

Users also considered
Ostorlab logo

Cloud-based vulnerability management platform

learn more
Ostorlab is a cloud-based vulnerability management platform designed to help businesses detect, monitor, and remediate risks across enterprises' external attack surfaces.

Read more about Ostorlab

Users also considered
DryRun Security logo

Cloud-based AI app security for dev & AppSec teams

learn more
DryRun Security is a cloud-based AI-native application security platform for engineering and AppSec teams that reviews every pull.

Read more about DryRun Security

Users also considered
AquilaX logo

AI-enabled security solution for developers

learn more
AquilaX provides AI-enabled security scanning for developers, supporting GitHub, GitLab, and Bitbucket repositories. With SecuriTron, their AI assistant, users can automate scan setup and identify vulnerabilities through both automated and tailored scans.

Read more about AquilaX

Users also considered
Akto logo

API Security Platform for Modern Appsec teams

learn more
Akto is an industry-leading solution for API discovery, API security posture management, sensitive data exposure, API security testing.

Read more about Akto

Users also considered
ThunderScan logo

SAST Application Security

learn more
ThunderScan by DefenseCode is a Static Application Security Testing (SAST) software that allows businesses to perform deep and extensive security analysis of various application source codes. ThunderScan can be integrated with existing CI/CD pipelines and DevOps environment, offering a platform that requires almost no user input, easy to use, and can be deployed during or after development.

Read more about ThunderScan

Users also considered