All categories

Static Application Security Testing (SAST)

https://www.capterra.com/sast-software/
Launch brief →
57 products2 pages scraped of 258 in category2 sponsored0 shortlisted
#ProductRatingReviewsRecEase / Svc / Feat / ValueDescription
100-– / – / – / –JFrog Advanced Security is a software supply chain tool that analyzes vulnerabilities, scans code, and detects exposures. Learn more about JFrog Advanced Security
24.76-4.8 / 5.0 / 4.2 / 5.0Security-first SAST with zero distractions. Scan your code for quality and vulnerabilities & get alerts only for real security risks. Learn more about Aikido Security
34.86,16992%4.4 / 4.3 / 4.7 / 4.6Find vulnerabilities in custom code using static analysis. Prevent new vulnerabilities from being introduced by scanning every PR. Learn more about GitHub
44.61,21886%4.4 / 4.2 / 4.6 / 4.5GitLab unifies planning, CI/CD, security, and agentic AI, eliminating the tool handoffs that slow software delivery. Learn more today. Learn more about GitLab
54.683-4.3 / 4.2 / 4.5 / 4.3Dynatrace provides software intelligence to simplify cloud complexity and accelerate digital transformation. Learn more about Dynatrace
64.567-4.2 / 4.0 / 4.4 / 4.4SonarQube helps developers control code security by detecting Vulnerabilities and Security Hotspots early in the workflow. Learn more about SonarQube
74.435-4.5 / 4.4 / 4.6 / 4.2Kiuwan | Code Scanning That’s Built for Developers and Trusted by Security Teams Learn more about Kiuwan
84.435-4.4 / 4.2 / 4.2 / 4.0Acunetix is web app and API security software that automates testing, finds vulnerabilities, and integrates into development. Learn more about Acunetix
93.327-3.5 / 3.1 / 3.2 / 2.8Cloud-based solution that enables businesses to detect & prevent cyber threats with website scanning, malware removal and more. Learn more about SiteLock
104.726-4.5 / 4.5 / 4.4 / 4.2Invicti, formerly Netsparker, is a DAST-first AppSec platform proving real risks, cutting noise, and securing everything at scale. Learn more about Invicti
114.621-4.4 / 4.3 / 4.5 / 3.8Snyk's Developer Security Platform puts security expertise in the toolbox of every developer. Learn more about Snyk
124.619-4.2 / 4.2 / 4.6 / 4.2The universal repository manager for DevOps & AI. Securely manage, store & distribute binaries across your entire software supply chain Learn more about Artifactory
134.116-4.1 / 4.1 / 4.1 / 3.8Sigrid delivers a holistic SAST solution that empowers organizations to proactively manage software security risks. Learn more about Sigrid
144.814-4.5 / 4.7 / 4.5 / 4.2CodeScan offers static code analysis and automated scans of Salesforce policies to strengthen code quality and data security. Learn more about CodeScan
154.213-4.4 / 4.7 / 4.4 / 4.3BuildPiper: The Most Powerful Microservice Delivery Platform Learn more about BuildPiper
164.711-4.0 / 4.9 / 4.5 / 4.4CodeScene is a code analysis, visualization, and reporting tool. Reduce technical debt and deliver better code quality. Learn more about CodeScene
174.810-4.5 / 4.5 / 4.5 / 4.8The all-in-one code health platform that equips organizations with everything they need to build maintainable and secure software. Learn more about DeepSource
184.98-4.6 / 4.8 / 4.8 / 4.5Load balancing platform that helps businesses monitor application performances, detect anomalies, analyze root causes, and more. Learn more about Radware Alteon
194.68-3.9 / 4.4 / 4.5 / 4.5Klocwork is a static code analysis tool that identifies issues to enforce standards compliance for multiple programming languages. Learn more about Klocwork
204.77-4.3 / 4.5 / 4.1 / 5.0SonarQube for IDE is a free IDE plugin that helps developers by detecting and highlighting issues in their code in real time. Learn more about SonarLint
214.67-4.3 / 4.8 / 4.3 / 4.5Manage Open Source supply chain threats intelligently with Bytesafe's cloud-native security platform. Learn more about Bytesafe
224.37-4.6 / 3.5 / 4.4 / 4.3SonarQube is an automated code review solution, serving as the verification layer to review AI code for quality and security. Learn more about SonarQube Cloud
233.97-3.7 / 4.0 / 4.3 / 3.0Checkmarx One is an enterprise cloud-native application security platform that helps teams cut through the noise fix what matters most. Learn more about Checkmarx One
243.56-3.3 / 3.2 / 4.0 / 3.8A SAST solution designed to help businesses manage risks across the application portfolio and address quality defects in the SDLC. Learn more about Coverity
2555-4.8 / 5.0 / 5.0 / 5.0AI-powered SAST with low noise, exploit-focused detection, smart prioritization, in-IDE guidance, fully integrated into CI/CD and ASPM. Learn more about Xygeni Security