Best Vulnerability Scanning

Updated Daily
inventory_2 20 items
trending_up Scored across 12 criteria

Rankings are calculated based on verified user reviews, recency of updates, and community voting weighted by user reputation score.

emoji_events View Best Vulnerability Scanning Rankings
Filter by Tags
0.0 10.0
Best 1 FOSSA
FOSSA
Free Plan Available From Free for open source projects, Enterprise pricing varies

FOSSA is a comprehensive open source compliance platform that automates license and vulnerability scanning. It generates Software Bill of Materials (SBOMs) and provides detailed reports on license ris...

9.2 Excellent
Visit
2 Tenable Nessus
Tenable Nessus
Free Plan Available From Free (Essentials limited to 16 IPs); Professional pricing varies by scanner count and organizational needs

Tenable Nessus is the industry standard for vulnerability assessment. It is an essential tool for IT administrators and security professionals to identify misconfigurations, missing patches, and vulne...

9.1 Excellent
Visit
3 Burp Suite
Burp Suite

Burp Suite is the industry-standard tool for web application security testing. It provides a comprehensive suite of tools, including an intercepting proxy, a web vulnerability scanner, and an intruder...

8.8 Very Good
Visit
4 DeepCode (Snyk)
DeepCode (Snyk)

DeepCode, now integrated into the Snyk platform, uses a massive knowledge base of open-source code to identify security vulnerabilities and logic errors. It is exceptionally fast and provides highly a...

8.7 Very Good
Visit
5 Snyk Open Source
Snyk Open Source

Snyk Open Source is a developer-first platform focused on identifying and fixing open source vulnerabilities. It integrates directly into IDEs and CI/CD pipelines, providing real-time feedback to deve...

8.6 Very Good
Visit
6 Checkmarx (One)
Checkmarx (One)

Checkmarx is a heavyweight in the application security space. While it is primarily an enterprise tool, it offers a free tier for open-source projects that provides powerful security scanning capabili...

8.6 Very Good
Visit
7 Snyk Code
Snyk Code

Snyk Code is a developer-first security tool that uses AI to find and fix vulnerabilities in real-time. It is specifically optimized for DevSecOps workflows, allowing developers to identify security f...

8.6 Very Good
Visit
8 Checkmarx
Checkmarx

Checkmarx is a heavyweight in the application security space, offering comprehensive SAST, DAST, and SCA solutions. Its AI-powered analysis is designed for large-scale enterprise environments where se...

8.5 Very Good
Visit
9 Snyk Cloud
Snyk Cloud

Snyk Cloud is a cloud-based platform for security and dependency management, offering tools to identify and mitigate vulnerabilities in code. It provides real-time insights into potential security ris...

8.1 Very Good
Visit
10 Avast Business Security Pro
Avast Business Security Pro

Avast Business Security Pro offers cloud-based management and robust protection against malware, ransomware, and other threats. It includes a ransomware shield, behavioral analysis, a firewall, and vu...

7.9 Good
Visit
11 UpGuard
UpGuard

UpGuard focuses on cybersecurity risk and vendor risk management. It provides continuous security ratings for vendors and helps businesses assess and mitigate third-party risks. UpGuard also offers co...

7.9 Good
Visit
12 Lynis
Lynis
Free Plan Available From $25/mo

Lynis is an open-source security auditing tool, not strictly an antivirus, but crucial for system hardening. It performs comprehensive scans of Linux, macOS, and Unix-based systems, identifying potent...

7.9 Good
Visit
13 Nexus Repository Manager
Nexus Repository Manager

Nexus Repository Manager, from Sonatype, is primarily an artifact repository but includes features for managing open source components. It can scan dependencies for vulnerabilities and license complia...

7.8 Good
Visit
14 JFrog Xray
JFrog Xray

JFrog Xray is a universal repository manager that scans artifacts for vulnerabilities and license compliance issues. It integrates with JFrog Artifactory and provides a comprehensive view of software...

7.7 Good
Visit
15 OWASP Dependency-Check
OWASP Dependency-Check

OWASP Dependency-Check is a free and open-source tool for identifying known vulnerabilities in project dependencies. It provides a command-line interface and Maven plugin for easy integration into bui...

7.6 Good
Visit
16 GitHub Advanced Security (Code Scanning)
GitHub Advanced Security (Code Scanning)

GitHub's native Code Scanning, powered by CodeQL, is an essential tool for any GitHub-based project. It automatically scans your code for security vulnerabilities and coding errors. While it is not a...

7.2 Good
Visit
17 grype
grype

grype is a command-line tool for vulnerability scanning of container images and filesystems. It identifies vulnerabilities in open source dependencies and provides detailed reports. Its particularly u...

7.1 Good
Visit
18 Reposhack
Reposhack

Reposhack is a self-hosted tool that integrates with GitHub to scan repositories for vulnerabilities and license compliance issues. It generates SBOMs and provides detailed reports. It's a good option...

7.0 Good
Visit
19 LibreLabs
LibreLabs

LibreLabs is an open-source tool designed to generate SBOMs and identify vulnerabilities in open-source dependencies. It integrates with GitHub and provides a user-friendly interface for managing open...

6.8 Fair
Visit
20 Snyk
Snyk
Free Plan Available From $20/mo

Snyk is a cloud-native platform for secure software development. It offers automated dependency scanning, vulnerability management, and continuous security testing to help organizations identify and m...

4.8 Poor
Visit
You've reached the end — 20 items

Save to your list

Create your first list and start tracking the tools that matter to you.

Track favorites
Get updates
Compare scores

Already have an account? Sign in

Compare Items

See how they stack up against each other

Comparing
VS
Select 1 more item to compare