OWASP ZAP
Open SourceMature open-source web application scanner and proxy.
zaproxy.orgDAST, SAST, SCA, IAST, container, IaC, and secrets scanners — open-source and commercial.
Mature open-source web application scanner and proxy.
zaproxy.orgIndustry-standard web vulnerability scanner and testing platform.
portswigger.netTemplate-based fast vulnerability scanner.
projectdiscovery.ioAutomated web vulnerability scanning with broad coverage.
acunetix.comLightweight static analysis with custom rule support.
semgrep.devCode quality and security analysis across many languages.
sonarsource.comSemantic code analysis engine maintained by GitHub.
codeql.github.comEnterprise SAST with broad language and framework coverage.
checkmarx.comInteractive application security testing via runtime instrumentation.
contrastsecurity.comAll-in-one scanner for containers, IaC, and dependencies.
trivy.devPolicy-as-code IaC scanner for Terraform, CloudFormation, K8s.
checkov.ioDetects hardcoded secrets in git history and working trees.
gitleaks.io