Best Application Security Testing (SAST/DAST/SCA) Tools

Explore leading tools in the Application Security Testing (SAST/DAST/SCA) category, including open-source options and SaaS products. Compare features, use cases, and find the best fit for your workflow.

10+ open-source projects · 6 SaaS products

Top open-source Application Security Testing (SAST/DAST/SCA)

These projects are active, self-hostable choices for knowledge management teams evaluating alternatives to SaaS tools.

View all 10+ open-source options
Most starred project
25,726★

Fast, template-driven vulnerability scanner with zero false positives

Recently updated
3 days ago

Dependency-Check scans project libraries, maps them to CPE identifiers, and reports associated CVEs, helping teams identify and remediate known security flaws across multiple ecosystems.

Dominant language
Java • 4 projects

Expect a strong Java presence among maintained projects.

Popular SaaS Platforms to Replace

Understand the commercial incumbents teams migrate from and how many open-source alternatives exist for each product.

Acunetix logo

Acunetix

Web vulnerability scanner for automated security testing of websites and web apps

Application Security Testing (SAST/DAST/SCA)
Alternatives tracked
15 alternatives
AppCheck logo

AppCheck

Automated web application and infrastructure vulnerability scanning platform

Application Security Testing (SAST/DAST/SCA)
Alternatives tracked
15 alternatives
Burp Suite logo

Burp Suite

Web application security testing platform

Application Security Testing (SAST/DAST/SCA)
Alternatives tracked
15 alternatives
Checkmarx One logo

Checkmarx One

Cloud‑native application security platform with SAST, SCA, DAST, and more

Application Security Testing (SAST/DAST/SCA)
Alternatives tracked
15 alternatives
TruffleHog logo

TruffleHog

Secret scanning tool for detecting exposed credentials in code repositories

Application Security Testing (SAST/DAST/SCA)
Alternatives tracked
15 alternatives
Veracode logo

Veracode

Application security platform for vulnerability scanning and testing

Application Security Testing (SAST/DAST/SCA)
Alternatives tracked
15 alternatives
Most compared product
10+ open-source alternatives

Acunetix is a web vulnerability scanner that automatically tests websites and web applications for over 6,500 security vulnerabilities. It features advanced crawling and audit tools to identify issues like SQL injection, XSS, and other exploits, helping organizations remediate web security risks.

Leading hosted platforms

Frequently replaced when teams want private deployments and lower TCO.

Explore related categories

Browse neighbouring categories in Security to widen your evaluation.