AppSecNews

Independent profiles of application security tools

236 tools 13 categories

The catalog

Every AppSec tool, mapped.

Independent, structured profiles of application security tools, placed where each one fits in your delivery pipeline.

6 head to head comparisons

Two tools. One decision.

Tools that teams actually shortlist together, compared on the one difference that decides it, with the facts side by side.

Start here

Know what runs where.

From the first commit to production: which category catches what, when it runs, and what to adopt first.

Editorial policy

No scores. No paid placement.

Every profile names its limitations. Vendors cannot buy a listing, a rank or an endorsement.

Why this exists

Independent profiles for the people who have to choose these tools, and then live with them.

Limitations first. Structured the same way for every tool. Nothing on this site is for sale.

Read the editorial policy

The AppSec lifecycle

Which tools fit where

All 13 categories, placed at the stage of delivery where they catch what the others miss. Each one says what it finds, when it runs, and which tools lead it.

  1. Editor, pre-commit and pull request

    Code

    Catch the flaw while its author still has the context to fix it in minutes.

  2. Dependencies and artifacts

    Build

    Most of what you ship, you did not write. Check it before it is packaged.

  3. The running application

    Test

    Some flaws only exist once the pieces are wired together and serving requests.

  4. Posture, gating and ownership

    Release

    Decide what blocks a release and who owns each finding, across every scanner.

  5. Production

    Run

    Assume something got through. Detect and block exploitation while it happens.

  6. Across every stage

    AI and LLM

    AI features bring a new input channel, and AI written code needs the same checks as any other.

The catalog, by the numbers

tools profiled, each one limitations first
236
categories, mapped across the lifecycle
13
guides, comparisons and roundups
19
paid placements, rankings bought or scores invented
0

Head to head

Tool comparisons

Two tools teams actually shortlist together, compared on the one difference that decides it, with the facts side by side.

All comparisons
SAST 7 min read

Semgrep vs GitHub CodeQL

Pattern Rules or Semantic Queries

Semgrep matches code shapes without a build; CodeQL queries a semantic database of your program. How that choice plays out in ownership, noise and depth.

Read the comparison

DAST 7 min read

ZAP vs Nuclei

Deep App Scanning or Fast Known-Issue Sweeps

Read the comparison

IaC Security 7 min read

Checkov vs KICS

Graph Checks or Rego Queries

Read the comparison

AI Security 7 min read

Garak vs PyRIT

Probe Scanner or Red Team Campaign Framework

Read the comparison

Start here

Resource hubs

Start with the discipline, then go deep on a category. Each hub says what you will learn and what to read first.

The discipline

Application security, end to end

The whole picture before you pick tools: what each category catches, how they fit across delivery, and what to adopt first.

Start with the guide

What you will learn

  • Which categories catch what, and at which stage of delivery
  • What to run first with a small team, and what can wait
  • Where suites overlap, so you do not pay for the same scan twice

Browse all 13 categories and 236 tools

Fresh in the catalog

Recently published

All tools

Zimperium zScan

Zimperium

Mobile Security

Automated scanner that analyzes compiled Android and iOS builds for security, privacy and compliance issues inside the release pipeline.

Commercial
Established

ZeroThreat

ZeroThreat

DAST

Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.

Freemium
Emerging

ZAP

ZAP project, Software Security Project

DAST

Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

Open source
Established Verified

Xygeni

Xygeni

ASPM

A software supply chain security platform covering malicious package detection, pipeline and source control hardening, secrets, dependencies and code analysis.

Commercial, free tier
Growing

Xage Security

Xage Security

AI Security

Distributed zero trust access platform for operational and industrial environments, extended to control what machine and AI agent identities may do.

Commercial
Established

Wiz

Wiz

IaC Security

An agentless cloud-native application protection platform that builds a graph of cloud resources, identities and workloads to surface real attack paths.

Commercial
Established

Guides and roundups

Latest articles

All articles
Secret Scanning roundup

The 10 Best Secret Scanning Tools

Ten secret scanning tools compared by where they sit in the lifecycle, whether they verify credentials, and whether they carry a leak through to rotation.

12 min read

SCA roundup

The 10 Best Software Composition Analysis Tools

Ten software composition analysis tools picked for distinct jobs: reachability triage, license compliance, SBOM monitoring, malicious package detection and patching.

12 min read

SAST roundup

The 10 Best SAST Tools

A practitioner's guide to ten static analysis tools, chosen for distinct scenarios rather than ranked, with the trade-offs each one brings.

12 min read

Editorial policy

How this catalog is written

Read the full policy
One standard for every profile
Each profile covers what the tool does, where it fits, its strengths, its limitations and who it suits. A profile without limitations is not published.
No pricing
No prices, no "starts at", no tier costs, anywhere in the editorial content. Edition names only; pricing belongs on the vendor's site.
No paid placement
Vendors cannot pay to be listed, to rank in a Top 10, or to be endorsed. Inclusion and order are editorial decisions.
No invented scores
No ratings, benchmarks or market share figures. Maturity says how established a project is, not how good it is.
Open questions are marked
Where a claim is still being confirmed with the vendor, the profile says so. Tools built by this site's operator carry a disclosure.
Ads are labelled
Advertising appears only in slots marked "Advertisement", and never changes which tools are listed or in what order.

236 tools, 13 categories, one standard

Find the tool that fits.