---
description: Discover and compare Static Application Security Testing (SAST) Software Applications & Tools for Windows. Capterra is a free interactive tool that lets you quickly narrow down your software selection, contact multiple vendors, and compare platforms for your business.
image: https://gdm-localsites-assets-gfprod.imgix.net/images/capterra/og_logo-e5a8c001ed0bd1bb922639230fcea71a.png?auto=format%2Cenhance%2Ccompress
title: Static Application Security Testing (SAST) Software for Windows - Price comparison & Reviews - Capterra Singapore 2026
---

Breadcrumb: [Home](/) > [Static Application Security Testing (SAST) Software for Windows](https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/software)

# Static Application Security Testing (SAST) Software

Canonical: https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/software

> Static Application Security Testing (SAST) automatically scans coding environments for security vulnerabilities during the application development process.

-----

## Products

1. [Acunetix](https://www.capterra.com.sg/software/171379/acunetix) — 4.4/5 (35 reviews) — Acunetix is web app and API security software that automates testing, finds vulnerabilities, and integrates into development.
2. [GitHub](https://www.capterra.com.sg/software/129067/github) — 4.8/5 (6155 reviews) — Find vulnerabilities in custom code using static analysis. Prevent new vulnerabilities from being introduced by scanning every PR.
3. [Dynatrace](https://www.capterra.com.sg/software/81932/dynatrace) — 4.5/5 (82 reviews) — Dynatrace provides software intelligence to simplify cloud complexity and accelerate digital transformation.
4. [SonarQube](https://www.capterra.com.sg/software/210481/sonarqube) — 4.5/5 (66 reviews) — SonarQube helps developers control code security by detecting Vulnerabilities and Security Hotspots early in the workflow.
5. [Kiuwan](https://www.capterra.com.sg/software/160729/kiuwan-code-security) — 4.4/5 (35 reviews) — Kiuwan | Code Scanning That’s Built for Developers and Trusted by Security Teams
6. [Invicti](https://www.capterra.com.sg/software/171539/netsparker-web-application-security-scanner) — 4.7/5 (26 reviews) — Invicti, formerly Netsparker, is a DAST-first AppSec platform proving real risks, cutting noise, and securing everything at scale.
7. [Snyk](https://www.capterra.com.sg/software/172252/snyk) — 4.6/5 (21 reviews) — Snyk's Developer Security Platform puts security expertise in the toolbox of every developer.
8. [Artifactory](https://www.capterra.com.sg/software/148994/artifactory) — 4.6/5 (19 reviews) — The universal repository manager for DevOps \&amp; AI. Securely manage, store \&amp; distribute binaries across your entire software supply chain
9. [Sigrid](https://www.capterra.com.sg/software/219140/sigrid) — 4.1/5 (16 reviews) — Sigrid delivers a holistic SAST solution that empowers organizations to proactively manage software security risks.
10. [CodeScan](https://www.capterra.com.sg/software/204478/codescan) — 4.8/5 (14 reviews) — CodeScan offers static code analysis and automated scans of Salesforce policies to strengthen code quality and data security.
11. [CodeScene](https://www.capterra.com.sg/software/193379/codescene) — 4.7/5 (11 reviews) — CodeScene is a code analysis, visualization, and reporting tool. Reduce technical debt and deliver better code quality.
12. [SonarLint](https://www.capterra.com.sg/software/1014000/sonarlint) — 4.7/5 (7 reviews) — SonarQube for IDE is a free IDE plugin that helps developers by detecting and highlighting issues in their code in real time.
13. [Coverity](https://www.capterra.com.sg/software/163552/coverity-static-code-analysis) — 3.5/5 (6 reviews) — A SAST solution designed to help businesses manage risks across the application portfolio and address quality defects in the SDLC.
14. [Aikido Security](https://www.capterra.com.sg/software/1060185/aikido) — 4.7/5 (6 reviews) — Security-first SAST with zero distractions. Scan your code for quality and vulnerabilities \&amp; get alerts only for real security risks.
15. [GuardRails](https://www.capterra.com.sg/software/199631/guardrails) — 5.0/5 (5 reviews) — Static Application Security Testing platform that empowers developers to create secure applications by providing continuous security.
16. [Sonatype Lifecycle](https://www.capterra.com.sg/software/171030/nexus-lifecycle) — 4.0/5 (4 reviews) — Pair Sonatype Lift with your favorite SAST tool to find and fix performance, reliability, and style issues deep in your code.
17. [OWASP ZAP](https://www.capterra.com.sg/software/1025564/owasp-zap) — 5.0/5 (4 reviews) — A web security software application that provides English-language vulnerability assessments and other online safeguarding measures.
18. [IDA Pro](https://www.capterra.com.sg/software/1015457/ida-pro) — 5.0/5 (1 reviews) — IDA Pro is a powerful disassembler and a versatile debugger.
19. [ThunderScan](https://www.capterra.com.sg/software/214854/thunderscan) (0 reviews) — Static Application Security Testing, WhiteBox Testing solution.
20. [Flawnter](https://www.capterra.com.sg/software/1021648/appsonar) (0 reviews) — Static code analysis software to find security and quality flaws faster. Trusted by many organizations worldwide.
21. [Akto](https://www.capterra.com.sg/software/1053906/Akto) (0 reviews) — Akto is an industry-leading solution for API discovery, API security posture management, sensitive data exposure, API security testing.
22. [Axivion](https://www.capterra.com.sg/software/1073138/Axivion-Static-Code-Analysis) (0 reviews) — Static code analysis tool that helps developers check standard compliance, security vulnerabilities, and code quality issues.
23. [CodeRisk](https://www.capterra.com.sg/software/1092250/CodeRisk) (0 reviews) — CodeRisk is a real-time static application security testing tool for VS Code that detects vulnerabilities as users code.

## Related Categories

- [Cloud Security Software](https://www.capterra.com.sg/directory/31344/cloud-security/software)
- [Source Code Management Software](https://www.capterra.com.sg/directory/31420/source-code-management/software)
- [Vulnerability Management Software](https://www.capterra.com.sg/directory/31062/vulnerability-management/software)
- [DevOps Tools](https://www.capterra.com.sg/directory/31120/devops/software)
- [Continuous Integration Tools](https://www.capterra.com.sg/directory/31119/continuous-integration/software)

## Links

- [View on Capterra](https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/software)
- [All Categories](https://www.capterra.com.sg/directory)

-----

## Structured Data

<script type="application/ld+json">
  {"@context":"https://schema.org","@graph":[{"name":null,"address":{"@type":"PostalAddress","addressLocality":null,"addressRegion":null,"postalCode":null,"streetAddress":null},"description":"Capterra Singapore helps find the best business software. With software reviews, ratings, infographics, and the most comprehensive list of business software.","email":"info@capterra.com.sg","url":"https://www.capterra.com.sg/","logo":"https://dm-localsites-assets-prod.imgix.net/images/capterra/logo-a9b3b18653bd44e574e5108c22ab4d3c.svg","@id":"https://www.capterra.com.sg/#organization","@type":"Organization","parentOrganization":"Gartner, Inc.","sameAs":["https://twitter.com/capterra","https://www.facebook.com/Capterra/","https://www.linkedin.com/company/capterra","https://www.instagram.com/capterra/","https://www.youtube.com/user/CapterraTV"]},{"name":null,"url":"https://www.capterra.com.sg/","@id":"https://www.capterra.com.sg/#website","@type":"WebSite","publisher":{"@id":"https://www.capterra.com.sg/#organization"},"potentialAction":{"query":"required","target":"https://www.capterra.com.sg/search/?q={search_term_string}","@type":"SearchAction","query-input":"required name=search_term_string"}},{"name":"Static Application Security Testing (SAST) Software","description":"Discover and compare Static Application Security Testing (SAST) Software Applications & Tools for Windows. Capterra is a free interactive tool that lets you quickly narrow down your software selection, contact multiple vendors, and compare platforms for your business.","url":"https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/deployment-options/windows/software","about":{"@id":"https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/deployment-options/windows/software#itemlist"},"breadcrumb":{"@id":"https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/deployment-options/windows/software#breadcrumblist"},"@id":"https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/deployment-options/windows/software#webpage","@type":["WebPage","CollectionPage"],"isPartOf":{"@id":"https://www.capterra.com.sg/#website"},"inLanguage":"en-SG","mainEntity":{"@id":"https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/deployment-options/windows/software#itemlist"},"publisher":{"@id":"https://www.capterra.com.sg/#organization"}},{"@id":"https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/deployment-options/windows/software#breadcrumblist","@type":"BreadcrumbList","itemListElement":[{"name":"Home","position":1,"item":"/","@type":"ListItem"},{"name":"Static Application Security Testing (SAST) Software for Windows","position":2,"item":"https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/software","@type":"ListItem"}]}]}
</script><script type="application/ld+json">
  {"name":"Static Application Security Testing (SAST) Software for Windows - Price comparison &amp; Reviews - Capterra Singapore 2026","@context":"https://schema.org","@id":"https://www.capterra.com.sg/directory/32818/static-application-security-testing-%28sast%29/deployment-options/windows/software#itemlist","@type":"ItemList","itemListElement":[{"name":"Acunetix","position":1,"description":"Acunetix is web application and API security software designed to automate security testing and vulnerability management. It features a vulnerability scanner capable of detecting vulnerabilities, including zero-day threats, across web applications and APIs. A standout feature is its ability to discover and crawl an organization's entire web attack surface, scanning areas like single-page applications and script-heavy sites. Acunetix's Predictive Risk Scoring uses machine learning to assess risk levels, helping prioritize critical vulnerabilities. It integrates with tools such as issue trackers and CI/CD pipelines, promoting a shared security responsibility. Continuous security capabilities allow for regular scans, ensuring new vulnerabilities are swiftly addressed. Acunetix streamlines application security efforts, reducing risk and enhancing the security of web-based assets.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/9a1f201e-3bde-45b3-a0e2-bfe0c3a29b9e.png","url":"https://www.capterra.com.sg/software/171379/acunetix","@type":"ListItem"},{"name":"GitHub","position":2,"description":"Find vulnerabilities in custom code using static analysis. Prevent new vulnerabilities from being introduced by scanning every pull request. We have security tools for every level of user - Dependency Graph is a map of the code libraries and repos your project relies on. Dependabot alerts you when these libraries were updated. These are available to every user. When you use GitHub Enterprise, you can add Token, Secret and Code Scanning to your repos for automatic security updates.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/d0cfa614-0cde-454f-b5f0-aed4c83f6a76.png","url":"https://www.capterra.com.sg/software/129067/github","@type":"ListItem"},{"name":"Dynatrace","position":3,"description":"Dynatrace is an application performance and lifecycle management solution designed to help retail businesses, financial markets, transportation companies, emergency services, and government bodies monitor and analyze the performance of applications on a unified dashboard. Key features of the platform include anomaly detection, root cause determination, network process monitoring, log entry analysis, cross-team collaboration, AI-assistance, and more among others.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/68183a9d-ab05-4850-890c-50d319013242.png","url":"https://www.capterra.com.sg/software/81932/dynatrace","@type":"ListItem"},{"name":"SonarQube","position":4,"description":"SonarQube enables your team to systematically deliver code that meets high-quality standards, for every project, at every step of the workflow. Covering over 30 programming languages, while pairing up with your existing software pipeline, SonarQube provides clear remediation guidance for developers to understand and fix issues, and for teams overall to deliver better and safer software.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/f45c49bb-a722-495f-8c4c-b1b8bb5009fe.png","url":"https://www.capterra.com.sg/software/210481/sonarqube","@type":"ListItem"},{"name":"Kiuwan","position":5,"description":"Fast, Flexible Code Security!\n\nKiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. \n\nOur toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities.\n\nTop features:\n✅ Extensive language support: Over 30 programming languages.\n✅ Detailed action plans: Prioritize remediation with tailored action plans.\n✅ Code Security: Seamless Static Application Security Testing (SAST) integration.\n✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats.\n✅ One-click Software Bill of Materials (SBOM) generation.\n\n\nCode Smarter. Secure Faster. Ship Sooner","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/a8dcb3c0-541d-479f-a555-bed59bc42274.png","url":"https://www.capterra.com.sg/software/160729/kiuwan-code-security","@type":"ListItem"},{"name":"Invicti","position":6,"description":"Invicti Security, formerly Netsparker, delivers application security with zero noise through a DAST-first approach that focuses on real, exploitable vulnerabilities in your running applications. The platform combines enterprise-grade dynamic application security testing (DAST), API security, web asset and API discovery, IAST, and dynamic SCA with static application security testing (SAST), static software composition analysis (SCA), and container security—all within a single, scalable solution. With proof-based scanning, Invicti automatically confirms exploitable vulnerabilities, to reduce false positives and speed remediation. Teams can prioritize real risk, reduce alert fatigue, and confidently secure their entire attack surface. Invicti integrates into modern development pipelines for continuous scanning and actionable insights across the SDLC. Trusted by leading enterprises, Invicti empowers security and DevOps teams to fix what matters most—quickly, accurately, and at scale.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/d386ac3d-34c6-4fa7-a326-728dc8167276.png","url":"https://www.capterra.com.sg/software/171539/netsparker-web-application-security-scanner","@type":"ListItem"},{"name":"Snyk","position":7,"description":"Snyk is the leader in developer security. Snyk is used by 1,200 customers worldwide today, including industry leaders such as Asurion, Google, Intuit, MongoDB, New Relic, Revolut and Salesforce. Snyk is recognized on the Forbes Cloud 100 2021, the 2021 CNBC Disruptor 50 and was named a Visionary in the 2021 Gartner Magic Quadrant for AST.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/0b834ddb-8c1a-4529-9ac4-28e194ec2eaf.png","url":"https://www.capterra.com.sg/software/172252/snyk","@type":"ListItem"},{"name":"Artifactory","position":8,"description":"JFrog Artifactory is the world’s leading universal binary repository manager and the core of the JFrog Software Supply Chain Platform. Designed for modern DevOps, it provides a single source of truth for all software components, including binaries, packages, and AI/ML models. With native support for 40+ package types (Docker, Kubernetes, Maven, npm, PyPI, and Terraform), Artifactory eliminates silos and ensures consistent, reliable access across the SDLC.\n\nScale your global infrastructure with multi-site replication and high availability, while securing your supply chain through deep integration with JFrog Xray for vulnerability scanning. Artifactory powers cloud-native, hybrid, and on-premises environments, offering the \"Database of DevOps\" for enterprises prioritizing speed, security, and compliance. Automate releases with robust REST APIs and CLI tools to accelerate CI/CD pipelines and ensure every build is traceable, governed, and ready for production at scale.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/2f492671-8e3d-4523-9fdf-2fd3b4ec5487.png","url":"https://www.capterra.com.sg/software/148994/artifactory","@type":"ListItem"},{"name":"Sigrid","position":9,"description":"Sigrid is an advanced software security platform that specializes in Static Application Security Testing (SAST). \n\nThe platform offers comprehensive and continuous scanning capabilities, utilizing a range of best-in-class technologies to identify, classify, and prioritize vulnerabilities across your entire software portfolio. \n\nSigrid provides unified, risk-based, and actionable insights to help organizations secure their software from the code level up to the entire system. It simplifies complex security data into clear and prioritized recommendations, ensuring that even non-technical managers can make informed decisions about security risks.\n\nSigrid is designed to serve a broad range of roles within an organization, from developers who need to identify and address specific security issues in their code, to security specialists seeking a unified view of security threats, and managers and C-level stakeholders who require oversight without needing to delve into technical details.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/7fbb591b-986a-4cbd-812b-c8ee8870d591.png","url":"https://www.capterra.com.sg/software/219140/sigrid","@type":"ListItem"},{"name":"CodeScan","position":10,"description":"AutoRABIT's CodeScan offers powerful static code analysis designed specifically for Salesforce environments. By automating the detection of security vulnerabilities, code quality issues, and compliance risks, it integrates seamlessly into your CI/CD pipeline to support continuous monitoring. CodeScan helps teams ensure their Salesforce codebase remains secure, consistent, and aligned with best practices. This significantly reduces manual review efforts, accelerates deployment times, and improves the overall performance of Salesforce applications. With advanced reporting and actionable insights, CodeScan empowers development and security teams to maintain high standards of security, compliance, and application quality throughout the software development lifecycle.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/27625740-314b-462c-a10a-0d1f1f138f0c.png","url":"https://www.capterra.com.sg/software/204478/codescan","@type":"ListItem"},{"name":"CodeScene","position":11,"description":"CodeScene is a code analysis, visualization, and reporting tool. Cross reference contextual factors such as code quality, team dynamics, and delivery output to get actionable insights to effectively reduce technical debt and deliver better code quality.\n\nWe enable software development teams to make confident, data-driven decisions that fuel performance and developer productivity.\n\nSupporting 28+ programming languages, CodeScene also offers an automated integration with GitHub, BitBucket, Azure DevOps or GitLab pull requests to incorporate the analysis results into existing delivery workflows. Get early warnings and recommendations about complex code before merging it to the main branch, set quality gates to trigger in case your code health declines.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/9a5a497c-b29b-47e3-96a2-e490a5926b35.jpeg","url":"https://www.capterra.com.sg/software/193379/codescene","@type":"ListItem"},{"name":"SonarLint","position":12,"description":"SonarQube for IDE is a free IDE plugin for automated code review brought to you by Sonar. It’s your first line of defense, designed to detect coding issues in real-time for 3+0 languages, frameworks, and IaC platforms.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/34d17e79-84da-474e-a790-2a114c3d6dce.png","url":"https://www.capterra.com.sg/software/1014000/sonarlint","@type":"ListItem"},{"name":"Coverity","position":13,"description":"Coverity is an intelligent, highly scalable static analysis (SAST) solution that helps developers find and fix critical security and quality issues as they code with help from the CodeSight IDE plug-in. Coverity works with 22 different languages and integrates into your CI/CD pipeline, allowing teams to address security and quality defects early in the SDLC. Coverity provides detailed reporting and issue management dashboards, which helps ensure compliance with security and coding standards.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/c76a7108-9c84-41a9-84e0-fc4aef15e694.jpeg","url":"https://www.capterra.com.sg/software/163552/coverity-static-code-analysis","@type":"ListItem"},{"name":"Aikido Security","position":14,"description":"Aikido scans your code for quality issues and security vulnerabilities such as SQL injection, XSS, buffer overflows, and other security risks. Checks against popular CVE databases. It works out-of-the-box and supports all major languages.\n\nAikido combines scanning capabilities like SAST, IaC, DAST, Container Scanning, SCA, CSPM & Secrets Detection, all in one platform.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/3a6ac642-6836-44e8-9489-54089fc64a58.png","url":"https://www.capterra.com.sg/software/1060185/aikido","@type":"ListItem"},{"name":"GuardRails","position":15,"description":"GuardRails provides the perfect customizable SAST security solution for organizations that need a flexible approach to their internal process. With thousands of possible coding vulnerabilities, you can stay ahead of threats and weaknesses in your organizations software by tracking which ones matter the most and need the most prior attention!","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/1f625515-6e4f-4af3-8560-e94181abe258.png","url":"https://www.capterra.com.sg/software/199631/guardrails","@type":"ListItem"},{"name":"Sonatype Lifecycle","position":16,"description":"Sonatype's Nexus Platform scales open source security monitoring across the software supply chain and reclaims time spent fighting risks in the software development life cycle.\n\nSoftware developers, application security professionals, and DevSecOps experts are empowered with the highest quality Nexus vulnerability intelligence to drive faster releases, decrease false positives, and deliver in-depth, developer remediation guidance.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/235422da-fc87-4523-bcc0-32eaad933197.jpeg","url":"https://www.capterra.com.sg/software/171030/nexus-lifecycle","@type":"ListItem"},{"name":"OWASP ZAP","position":17,"description":"OWASP ZAP is an open-source web content scanning program that helps businesses with online materials perform security assessments. Along with code reviews that specifically look for security vulnerabilities, the English-language utility features penetration testing tools that simulate hacker attacks. Designed for businesses of all kinds that want to provide online materials for employees and clients, it undertakes security testing and assessments from an end-user perspective n real-time. The system is designed to embed itself between the user's browser interface and the web applications offered by companies. However, it can also work in setups that utilize a network proxy. The system can perform security assessments with all major operating systems. The program aims to exploit known cyber threats and identify vulnerabilities that are already known, then reports those with any potential use to malicious users.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/275a67e4-ca21-4766-a7b6-454bec142600.jpeg","url":"https://www.capterra.com.sg/software/1025564/owasp-zap","@type":"ListItem"},{"name":"IDA Pro","position":18,"description":"The source code of the software we use on a daily basis isn’t always available. A disassembler like IDA Pro is capable of creating maps of their execution to show the binary instructions that are actually executed by the processor in a symbolic representation called assembly language. This disassembly process allows software specialists to analyze programs that are suspected to be nefarious in nature, such as spyware or malware.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/dc625d1a-47fe-42e7-9ebb-3074fc2ad3ed.png","url":"https://www.capterra.com.sg/software/1015457/ida-pro","@type":"ListItem"},{"name":"ThunderScan","position":19,"description":"DefenseCode ThunderScan® is a SAST (Static Application Security Testing, WhiteBox Testing) solution for performing deep and extensive security analysis of application source code. ThunderScan® is easy to use, requires almost no user input and can be deployed during or after development with easy integration into your DevOps environment and CI/CD pipeline.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/9b8cdc3e-be32-44bb-8796-455dffb1f686.png","url":"https://www.capterra.com.sg/software/214854/thunderscan","@type":"ListItem"},{"name":"Flawnter","position":20,"description":"Flawnter Static Code Analyzer Helps Improve the Security and Quality of Your Application Code. Automate static application security testing to find hidden security and quality flaws faster. Over thousands of rules and over 25 programming language support. Based on industry standards.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/6f1659d4-a23d-472b-8fce-fca3bbce94b7.png","url":"https://www.capterra.com.sg/software/1021648/appsonar","@type":"ListItem"},{"name":"Akto","position":21,"description":"Akto is a leading API security platform trusted by over 1,000 application security teams worldwide. Designed for modern appsec and product security teams, Akto enables organizations to build enterprise-grade API security programs throughout their DevSecOps pipeline. \n\nIts comprehensive suite includes API discovery, sensitive data and PII exposure detection, API security testing, CI/CD integration, and continuous security posture management. Akto provides deep authentication and authorization testing, monitors API changes, and offers the largest API security test library. \n\nRecognized by Forbes, Nasdaq, and Gartner®, Akto is your all-in-one solution to discover APIs, find sensitive data, test vulnerabilities, and prioritize critical findings—ensuring complete DevSecOps coverage.\n\nAkto is also a High performer in API Security and DAST Categories by G2 and has 4.7 overall rating by customers on Gartner Peer Insights.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/ec77bf0b-42aa-4b22-9056-3c0af90dbd0e.jpeg","url":"https://www.capterra.com.sg/software/1053906/Akto","@type":"ListItem"},{"name":"Axivion","position":22,"description":"Axivion Static Code Analysis is a static code analysis tool that helps developers check standard compliance, security vulnerabilities, and code quality issues for C and C++ code. It performs automated analysis to identify violations of coding guidelines like MISRA C and detect clones, dead code, and security vulnerabilities. Key features include coding standards compliance checking, metric monitoring, defect analysis, and certification for safety-critical software development.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/80fef66b-dfb3-4003-838e-c577f6cf894e.png","url":"https://www.capterra.com.sg/software/1073138/Axivion-Static-Code-Analysis","@type":"ListItem"},{"name":"CodeRisk","position":23,"description":"CodeRisk is a static application security testing (SAST) extension for Visual Studio Code that detects vulnerabilities in real time as developers write code. Operating entirely offline without AI or telemetry, it ensures privacy for sensitive codebases. CodeRisk scans JavaScript and TypeScript projects automatically, identifying security issues without cloud connectivity.\nThe extension integrates into VS Code with a security dashboard, sidebar for hierarchical findings, and editor features like gutter icons, inline annotations, and hover tooltips. It performs taint-flow analysis to trace vulnerabilities from source to sink. Covering over 15 vulnerability classes aligned with OWASP Top 10 and CWE, it detects issues like SQL injection, XSS, SSRF, and insecure randomness. CodeRisk runs background analysis during coding and full scans on startup, exporting results in SARIF format for CI/CD integration. Free and open-source, it’s available on the VS Code Marketplace.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/08273a49-464b-4351-874e-0f819b682ffa.jpeg","url":"https://www.capterra.com.sg/software/1092250/CodeRisk","@type":"ListItem"}],"numberOfItems":23}
</script>
