search
Get Started
search

Best Appsec

Updated Daily
Filter by Tags

Rankings use category fit, feature coverage, pricing signals, public reception, and recency. Affiliate relationships do not affect scores.

0.0 - 10.0
Best 1 PortSwigger Burp Suite Professional

Burp Suite Professional is a widely-used tool for web security professionals and penetration testers. It facilitates detailed analysis of network communications between browsers and web servers. The software’s capabilities include intercepting, modifying, and scanning HTTP/HTTPS traffic to identify...

Security Software Vulnerability Scanner Web Security Pentesting Appsec Portswigger
2 Snyk Developer Security Platform

Snyk Developer Security Platform provides automated vulnerability scanning and remediation for applications built with popular languages and frameworks, integrating directly into the developer workflow to identify and address security risks throughout the software development lifecycle.

3 Veracode Static Analysis

Veracode Static Analysis automatically scans application source code for known vulnerabilities like SQL injection and cross-site scripting by identifying patterns and deviations from secure coding standards without executing the code.

Security Software Enterprise Sast Appsec Veracode Code Security
4 Checkmarx SAST

Checkmarx SAST analyzes source code for potential vulnerabilities by identifying patterns associated with common software flaws like SQL injection and cross-site scripting during the development lifecycle.

5 Checkmarx One Assist

Checkmarx One Assist is an artificial intelligence assistant integrated into the Checkmarx One application security platform. It analyzes static application security testing (SAST) results to provide developers with automated remediation guidance and context regarding detected vulnerabilities. The t...

6 ModSecurity

ModSecurity is an open-source web application firewall (WAF) that analyzes HTTP traffic in real-time, detecting and blocking malicious requests based on configurable rules and signatures to protect servers from attacks like SQL injection and cross-site scripting.

7 Black Duck SCA

Black Duck Software’s SCA Analyzer automatically identifies and manages open-source components within software projects, tracking licenses, vulnerabilities, and code usage to mitigate risks and ensure compliance throughout the development lifecycle.

8 Qualys Web Application Scanning

Qualys Web Application Scanning automatically identifies vulnerabilities in web applications by testing them against known weaknesses and misconfigurations, providing detailed reports for remediation efforts.

9 Sonatype Nexus Lifecycle

Sonatype Nexus Lifecycle is an open-source repository manager that automates the management of software artifacts across their entire lifecycle, providing visibility and control over dependencies, vulnerability remediation, and compliance adherence within DevOps workflows.

10 Mobb
Mobb

Mobb is an open-source extension for Chrome and Firefox that facilitates collaborative code editing directly within the OpenAI interface, allowing multiple users to simultaneously modify and review generated code in real time.

11 Qwiet AI preZero

Qwiet AI preZero is an open-source extension for Continue AI that utilizes a novel quantization technique to significantly reduce the memory footprint of large language models without substantial performance degradation.

12 Corgea
Corgea

Corgea is an open-source extension enabling continued conversations and memory management within AI language models like Llama 2, addressing limitations in standard chatbot interactions.

13 Pixee
Pixee

Pixee is a browser extension that utilizes AI to automatically generate detailed captions and alt text for images across various websites and platforms.

14 Aikido AutoFix

Aikido AutoFix is a Chrome extension leveraging AI to automatically correct and rephrase text within various online platforms, aiming to improve clarity and grammar for users.

15 Rapid7 InsightAppSec

Rapid7 InsightAppSec is a web application vulnerability scanner that performs continuous assessments of applications throughout the software development lifecycle, identifying vulnerabilities and prioritizing remediation efforts based on risk.

Security Software Web App Dast Appsec Rapid7 Vulnerability Scanning
16 HCL AppScan

HCL AppScan is a dynamic application security testing (DAST) tool that automatically scans web applications and APIs for vulnerabilities during runtime, generating detailed reports on identified weaknesses and potential risks within the development lifecycle.

You've reached the end — 16 items

Save to your list

Save your favorites and follow how their scores change over time.

Save favorites
Get updates
Compare scores

Already have an account? Sign in

Compare Items

See how they stack up against each other

Comparing
VS
Select 1 more item to compare