Static Application Security Testing (SAST) Tools

Compare the best SAST tools for static application security testing. Find the right static code analysis solution with expert reviews, pricing, and feature comparisons.

Aikido

Aikido provides everything the average startup to mid-market company needs for security in a box - every code and cloud security scanner under the sun without much feature compromise, alongside a surprisingly robust runtime application solution for things like bot prevention. A no-nonsense replacement for a lot of more "specialized" solutions that tend to slow developers down.

ASPMCSPM
Hands-on Nerdy
Corgea

Corgea provides a robust bundling of AI first scanning tools - from AI SAST to SCA and Secrets scanning. Corgea's especially strong at discovering vulnerabilities via AI scanning, and AI based prioritization for false positive analysis.

SASTSCA
Hands-on Best for Enterprise Best for MidMarket
10.0
ZeroPath

An AI-native application security platform that unifies various scanning and enforcement tools, identifies real vulnerabilities, reduces false positives, and generates contextual fixes integrated into developer workflows.

SASTSCA
Hands-on Best for Enterprise Best for MidMarket
Ox

Ox provides an all-in-one application security solution that provides their own scanners combined with the ability to import third party findings. They also have a robust API for managing the data in the tool.

ASPMCSPM
Hands-on Best for MidMarket
Checkmarx

Checkmarx has adapted well to the DevSecOps model, offering a lighter weight scanner in the Checkmarx One platform, that integrates well into the larger stack. They don't have all the latest features of some newer companies, but they certainly get the job done for diverse enterprises. I would not suggest venturing off Checkmarx One though.

ASPMSAST
Hands-on Best for Enterprise
Legit Security

Legit Security offers a holistic ASPM platform that focuses more on pipeline discovery, security, and third party data ingestion than native scanning solutions.

ASPMSAST
Best for Enterprise
Arnica

Arnica is a holistic application security solution that focuses primarily on providing a strong developer experience. They have robust policy and attribution engines to build detail oriented workflows getting the right finding to the right person at the right time.

ASPMSAST
Hands-on Best for MidMarket
Phoenix Security

Phoenix security is more on the vulnerability management side of ASPM, but they offer their own SCA and DAST options alongside existing scanners. Due to the emphasis on management & orchestration, they offer a wide variety of contextualizations and in depth vulnerability data. An especially great fit for enterprises.

ASPMVulnerability ManagementSAST
Hands-on Best for Enterprise
Boost Security

Boost Security has a shared vision for all in one configuration scanning out to runtime. They have smart kubernetes & Istio integrations for runtime context, alongside the standard suite of SCA, SDLC, SAST, IaC, Secrets, and Containers based on a combination of open source and in house built tools. I appreciate the openness of their rule set in their documentation.

ASPMSAST
Best for MidMarket Best for Startups
DryRun Security

DryRun is maximizing the value of LLMs for code analysis by creating robust SAST like scanners that can cover traditionally undetectable issues like BOLA.

SASTSCA
Hands-on Best for Enterprise
Mobb

Mobb integrates with SAST tools like Snyk, Checkmarx, Fortify, and Codeql to scan your code and then provides fixes for merging into your code base. Their generated fixes seem good, but it's something that other providers are also working to build natively such as Snyk's DeepCode. Mobb uses GenAI to help create fixes for SAST findings.

SAST
Hands-on Best for Enterprise
GitHub

GitHub Advanced Security is okay. It checks a lot of scanning boxes - most importantly SCA with dependabot, secrets scanning, and SAST with CodeQL. The tools tends to be very noisy, requires management via GitHub which can be challenging, and tends to generate a lot of false positives leading to operational difficulty over time

SASTSCASecret Scanning
Hands-on Included
10.0
Amplify Security

Amplify security leverages multi-AI Agents to generate relevant and accurate fixes, alongside SAST scanning capabilities. This approach replicates the process of developers and security engineers working together to fix issues so both teams are happy. Amplify tries to make the code fixes look as if the developer themselves wrote the fix, emphasizing the contextual nature of the code.

SAST
Hands-on Best for Startups
Codacy

Codacy is a code quality and scanning toolbox similar to SonarQube for code scanning. They support many languages via open source scanning tools and have a developer focus.

ASPMSAST
Hands-on Best for Startups
Pixee

Pixee creates pull request ready fixes for SAST findings for enterprises. They've especially focused on developer workflows and using a mix of LLMs with static rules to create fixes.

AISAST
Hands-on Best for Enterprise
VeraCode

Veracode is a legacy SAST vendor that has done a good job expanding into other categories. They are a great choice for organizations using more legacy or waterfall type development methods, but still don't have an intuitive interface or workflows for modern dev teams.

ASPMSAST
Best for Enterprise