Loading...
Static Application Security Testing tools for Source Code Analysis: the Static Application Security Testing options most relevant when Source Code Analysis is the priority, compared side by side so you can shortlist faster. Filter by pricing or specialization. Independent and vendor-neutral: our scores and rankings are earned, never bought — sponsored placement is always labeled.
We cover 25 cybersecurity tools
AI-native SAST platform finding multi-step & business logic vulns in code.
AI-powered secure code platform for vulnerability detection & codebase analysis.
AI platform for automated code review, security risk detection across the SDLC.
AI agent that finds, exploits & verifies zero-day vulns with zero false positives.
Automated C code analysis and repair tool benchmarked against NIST SAMATE.
Developer-first SAST tool for finding security & privacy vulns in code.
AI-powered smart contract vulnerability scanner for Solidity code
Source code verification tool that finds bugs and security vulnerabilities
Source code malware scanner detecting backdoors and malicious code in repos
SAST tool for finding code quality & security defects in large-scale software
SAST tool that identifies vulnerabilities in source code across 30+ languages
SAST scanner for identifying security vulnerabilities in source code
SAST tool for continuous source code vulnerability scanning and remediation
SAST tool using virtual compilers to analyze source code for vulnerabilities
SAST tool for identifying security vulnerabilities in source code
SAST tool that identifies security and quality issues in source code
SAST engine that scans code commits for security vulnerabilities
SAST solution that scans 30+ languages to find and fix code vulnerabilities
Code quality and security platform with SAST, SCA, and AI-powered remediation
AI-powered SAST tool that finds and auto-fixes code vulnerabilities in real-time
A free online tool to scan for DOM-based XSS vulnerabilities in HTML, JavaScript, and CSS files.
Betterscan is an orchestration toolchain that coordinates multiple security tools to scan source code and infrastructure as code for security vulnerabilities, compliance risks, secrets, and misconfigurations.
Insider is an open-source CLI tool that performs static source code analysis to detect OWASP Top 10 vulnerabilities across multiple programming languages including Java, Kotlin, Swift, .NET, C#, and JavaScript.
A vulnerable web site in NodeJS for testing security source code analyzers.