aisnoopy 105 brands · 36 answers

Markets application security testing tools 105 brands

Best application security testing toolsaccording to AI assistants

Snyk is named most often — in 30 of 36 answers. 6 questions a buyer would type, asked of 2 assistants 3 times each.

1 Snyk 3083%
2 SonarQube 2364%
3= Semgrep 2158%
3= Trivy 2158%
5= GitHub 2056%
5= WhiteSource 2056%
7 Dependabot 1953%
8= Black Duck 1747%
8= OWASP Dependency-Check 1747%
10= Mend 1542%
10= OWASP ZAP 1542%
12 Checkmarx 1439%
+79 more brands named at least once ranked below the top 12
13= CodeQL 1131%
13= npm audit 1131%
13= Burp Suite 1131%
16= Veracode 925%
16= GitLab 925%
16= Aqua Security 925%
19= SonarCloud 822%
19= Checkov 822%
19= Grype 822%
22= Acunetix 719%
22= pip-audit 719%
22= Sonatype Nexus Lifecycle 719%
22= TruffleHog 719%
22= GitHub Dependabot 719%
22= Prisma Cloud 719%
22= 42Crunch 719%
29= Synopsys 617%
29= ESLint 617%
29= Cargo audit 617%
29= Gitleaks 617%
33= Bandit 514%
33= Fortify 514%
33= GitHub Secret Scanning 514%
33= tfsec 514%
33= Invicti 514%
33= JFrog Xray 514%
33= bundler-audit 514%
33= safety 514%
41= Burp Suite Enterprise 411%
41= Checkmarx One 411%
41= JFrog 411%
41= Salt Security 411%
41= Snyk Open Source 411%
41= Sonatype 411%
41= ripgrep 411%
48= Anchore 38%
48= Burp Suite Professional 38%
48= Contrast Security 38%
48= GitHub Advanced Security 38%
48= GitLab Dependency Scanning 38%
48= Postman 38%
48= Rapid7 InsightAppSec 38%
48= Semgrep Community 38%
48= Snyk Container 38%
48= Synopsys Coverity 38%
58= Burp Suite Pro 26%
58= Nikto 26%
58= Snyk Code 26%
58= Sysdig 26%
58= WhiteSource (Mend) 26%
58= Wiz 26%
64= Anchore Labs 13%
64= Aqua Platform 13%
64= Black Duck/Synopsys 13%
64= Bundler Audit 13%
64= Clang 13%
64= Datadog 13%
64= Falco 13%
64= Fortify (Micro Focus) 13%
64= GitHub CodeQL 13%
64= GitHub Copilot 13%
64= GitLab Secure 13%
64= GitLab Ultimate 13%
64= Gradle Dependency Check 13%
64= LLVM 13%
64= Maven Dependency Check Plugin 13%
64= Noname 13%
64= Orca 13%
64= Palo Alto Prisma Cloud 13%
64= Pylance 13%
64= Rapid7 InsightAPI 13%
64= Renovate 13%
64= Rust-analyzer 13%
64= Semgrep Code 13%
64= Snyk Platform 13%
64= Veracode DAST 13%
64= Veracode Platform 13%
64= Veracode Static Analysis 13%
64= WhiteSource/JFrog Mend 13%

14 brands in this market were named in none of the 36 answers: Bearer, GitLab SAST, GitLab Ultimate Security, GitLab/GitHub Security, HCL AppScan, Mend.io, Micro Focus, OpenText Fortify and 6 more.

The questions

These belong to the market, not to any brand in it. Each was asked 6 times across two assistants. Questions naming a brand are excluded, since they hand that brand a free mention.

Want to get weekly ranking updates? Leave your email above.

Method

market application security testing tools
brands measured 105
run as subjects 0
questions 6
answers per brand 36
brand list version d614237529c2

Questions went to the OpenAI and Anthropic APIs with web search off, each in a fresh context with no history. That measures what the models already know about these brands rather than what they would find on the web today, so it is a floor on visibility rather than a replica of any one person's chat.

Repeated measurements of the same brand move within about 12 points, so a difference smaller than that is not meaningful. Brands closer together than that are shown tied rather than ordered.

How the table is ordered. By how many of the 36 answers named each brand. Brands on the same count share a rank and are shown in the order the assistants tended to list them. A brand counts once per answer, however many times it is named in it.

How close is close. Two brands share a rank only when their counts are identical. Beyond that, a gap smaller than about four answers is inside what this measurement moves between runs — so read near-neighbours as close rather than settled, which is why every row keeps its interval.

All markets