

Find out what your peers are saying about Sonar, Veracode, GitGuardian and others in Static Application Security Testing (SAST).
| Product | Market Share (%) |
|---|---|
| OWASP Zap | 4.4% |
| SonarQube Server (formerly SonarQube) | 20.8% |
| Checkmarx One | 10.3% |
| Other | 64.5% |
| Product | Market Share (%) |
|---|---|
| Polaris Platform | 1.6% |
| Black Duck SCA | 14.5% |
| Snyk | 12.7% |
| Other | 71.2% |

| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 11 |
| Large Enterprise | 21 |
OWASP Zap is a free and open-source web application security scanner.
The solution helps developers identify vulnerabilities in their web applications by actively scanning for common security issues.
With its user-friendly interface and powerful features, Zap is a popular choice among developers for ensuring the security of their web applications.
Polaris Software Integrity Platform is an integrated, cloud-based application security testing solution optimized for the needs of development and DevSecOps teams.
Polaris brings our market-leading security analysis engines together in a unified platform, giving you the flexibility to run different tests at different times based on application, project, schedule, or SDLC events.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.