Browse by category

Application Security

Explore SAST and DAST tools for identifying vulnerabilities in application code and runtime environments.

Refine results
Refine resultsClear all
Deployment
Source model
Pricing model

How to choose application security tools

Application Security tools support a defined technical workload. Start with the systems, users and operating constraints the tool must cover before comparing individual features.

What belongs in this category: A listing belongs in Application Security when this workload is a primary product function rather than a secondary integration or marketing label.

Who uses these tools

  • Technical owners responsible for the workload
  • Operators who deploy, secure and support the system
  • Teams evaluating integrations, cost and migration risk

Capabilities to compare

  • Core workflow and platform coverage
  • Deployment, identity and integration controls
  • Administration, observability and recovery

Operating considerations

  • Compatibility with the current environment
  • Security, data location and access boundaries
  • Migration effort, support and total operating cost

Selection checklist

  1. Write down the production workload, scale and failure scenarios.
  2. Test the most important integration and an export or recovery path.
  3. Verify current limits, licensing and support in official documentation.
Decision resources

Continue the technical evaluation

Use the resources that match your decision stage. Profile data and linked sources were refreshed through September 27, 2026.

Evaluation methodology · Corrections process

7 results in Application Security

Contrast Security, founded by OWASP co-creator Jeff Williams, instruments applications with in-app sensors: Contrast Assess (IAST) and Scan (SAST) find vulnerabilities, Contrast SCA flags risky dependencies, and its ADR/RASP layer detects and blocks attacks in production.

Application SecuritySelf-hostedOther license
Detectify

Detectify combines automated DAST scanning with crowdsourced vulnerability research to monitor internet-facing assets and web apps for exploitable issues.

Application SecurityOther license
ImmuniWeb

ImmuniWeb offers AI-assisted penetration testing, continuous application testing, attack surface discovery and dark web monitoring, plus free Community Edition tools.

Application SecurityOther license
Mend.io

Mend.io (formerly WhiteSource) pioneered software composition analysis and now covers SCA, SAST, container scanning, dependency updates (Mend Renovate), and AI security — red-teaming and runtime guardrails for LLM-based applications.

Application SecuritySelf-hostedOther license
Rapid7

Rapid7 helps security teams find vulnerabilities, assess exposure and investigate threats across its distinct products.

Application SecurityOther license
Snyk

Snyk scans open-source dependencies, code, containers and infrastructure-as-code for vulnerabilities, built into IDEs, CLI and CI/CD pipelines.

Application SecurityWebOther license
Veracode

Veracode supplies application security testing for proprietary code and open-source components.

Application SecurityOther license
CompareTool and summaryCategoryDeploymentSource model
Contrast SecurityContrast Security, founded by OWASP co-creator Jeff Williams, instruments applications with in-app sensors: Contrast Assess (IAST) and Scan (SAST) find vulnerabilities, Contrast SCA flags risky dependencies, and its ADR/RASP layer detects and blocks attacks in production.Application SecuritySelf-hostedOther license
DetectifyDetectify combines automated DAST scanning with crowdsourced vulnerability research to monitor internet-facing assets and web apps for exploitable issues.Application SecurityOther license
ImmuniWebImmuniWeb offers AI-assisted penetration testing, continuous application testing, attack surface discovery and dark web monitoring, plus free Community Edition tools.Application SecurityOther license
Mend.ioMend.io (formerly WhiteSource) pioneered software composition analysis and now covers SCA, SAST, container scanning, dependency updates (Mend Renovate), and AI security — red-teaming and runtime guardrails for LLM-based applications.Application SecuritySelf-hostedOther license
Rapid7Rapid7 helps security teams find vulnerabilities, assess exposure and investigate threats across its distinct products.Application SecurityOther license
SnykSnyk scans open-source dependencies, code, containers and infrastructure-as-code for vulnerabilities, built into IDEs, CLI and CI/CD pipelines.Application SecurityWebOther license
VeracodeVeracode supplies application security testing for proprietary code and open-source components.Application SecurityOther license