Static Application Security Testing

Static Application Security Testing (SAST) tools for static code analysis that detect security vulnerabilities and coding flaws in source code during development.

Explore 76 curated cybersecurity tools, with 17,495+ visitors searching for solutions

FEATURED

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

Filter by:
Xygeni Secrets Security Logo

Detects and prevents secrets leakage across the software development lifecycle

0
Xygeni SAST Logo

SAST tool that detects vulnerabilities and malicious code in custom source code

0
Delphos Labs Cybersecurity Tool Logo

Binary analysis tool providing file summaries and security assessments

0
Jsmon Logo

A JavaScript security scanning platform that detects exposed secrets, API keys, and vulnerabilities in JavaScript files through continuous monitoring and automated discovery.

0
Symbiotic Security Logo

An IDE-integrated AI security solution that detects, remediates, and educates about code vulnerabilities in real-time as developers write code.

0
Boman.ai Logo

A DevSecOps platform that combines SAST, DAST, SCA, and secret scanning with AI/ML-based analysis for continuous application security testing and vulnerability management.

0
Offensive 360 Logo

A static application security testing (SAST) platform that performs comprehensive source code analysis to identify vulnerabilities, malware, and security issues in application code and dependencies.

0
DerScanner Logo

DerScanner is a comprehensive application security testing platform that combines SAST, DAST, MAST, SCA, and Binary Analysis capabilities with support for on-premises deployment and CI/CD integration.

0
OpenText Fortify Aviator Logo

An AI-powered code security tool that analyzes code for vulnerabilities

0
Qwiet Logo

Qwiet AI is an application security platform that combines SAST, SCA, container security, secrets detection, and SBOM scanning with AI-powered vulnerability prioritization and automated fix generation.

0
Fluid Attacks Continuous Hacking Logo

An application security testing platform that combines automated scanning, AI assistance, and manual expert testing to provide continuous security assessment throughout the software development lifecycle.

0
SonarQube Server Logo

A self-managed static code analysis platform that conducts continuous inspection of codebases to identify security vulnerabilities, bugs, and code quality issues.

0
Flyingduck Logo

A security analysis platform that combines SAST, SCA, SBOM generation and AI-assisted remediation to detect and fix vulnerabilities during the software development lifecycle.

2
Pixee Logo

An automated code security tool that analyzes repositories, identifies vulnerabilities, and generates pull requests with fixes while integrating with existing development workflows.

0
DryRun Logo

A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.

1
Amplify Logo

An automated code remediation tool that integrates with source control platforms to automatically fix security vulnerabilities in code through AI-driven analysis and one-click implementations.

0
Seekrets OSS Logo

A secret scanning tool that examines NPM modules and ZIP files for exposed credentials and sensitive information using nuclei templates.

0
Backlash Logo

Backslash Security is an application security platform that uses reachability analysis to enhance SAST and SCA, prioritize vulnerabilities, and provide remediation guidance.

0
Aikido Security Logo

Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.

0
Octoscan Logo

Octoscan is a static analysis tool that scans GitHub Actions workflows for security vulnerabilities and misconfigurations.

0
Snyk Code Logo

Snyk Code is a real-time SAST tool that provides secure code analysis and actionable remediation advice to prevent code delays and ensure secure development.

0
Checkmarx SAST Logo

Checkmarx One SAST is a static application security testing tool that combines speed and security to improve developer experience.

0
Veracode Logo

Veracode is an intelligent software security platform that helps developers and security teams secure code, find and fix flaws, and automate remediation.

0
Codacy Logo

A developer-first, API-driven platform that provides development teams with a suite of tools to improve code quality, security, and engineering performance, seamlessly integrated into their existing development workflows.

0

Static Application Security Testing Tools - FAQ

Common questions about Static Application Security Testing tools including selection guides, pricing, and comparisons.

Static Application Security Testing (SAST) tools for static code analysis that detect security vulnerabilities and coding flaws in source code during development.

Have more questions? Browse our categories or search for specific tools.