IT AI Index
September 2026 Edition · The permanent record of this edition. The unqualified address always carries the latest edition.
Index Developer platform SCA › Small business September 2026 Edition

Software composition analysis for small business buyers

Asked as “software composition analysis tool”, and as “open source dependency vulnerability scanner”, on behalf of a small B2B company. 42 first choices recorded across the direct, paraphrase, budget and scale prompts, twelve models each.
Standing
Contested
36% of first choices, contested.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

01The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all twelve models, for a small B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrant
01Trivy36%2%48endorsed leader
02Snyk Open Source33%4%50endorsed leader
03GitHub Dependabot5%12%17accepted challenger
04OWASP Dependency-Check5%32%31criticized challenger
05Semgrep Supply Chain2%5%20accepted challenger
06OSV-Scanner2%0%11accepted challenger
07Mend.io2%41%22criticized challenger
Show the five products at 0%, ordered by negative rate
12Black Duck0%80%20criticized challenger
11Sonatype Lifecycle0%73%11criticized challenger
10Endor Labs0%33%12criticized challenger
08Socket0%0%22accepted challenger
09FOSSA0%0%20accepted challenger
Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its vendor page.

Recommended versus criticized

Every product with at least 10 labels here, on both axes. The 30% line names a quadrant, not the verdict above: that one needs more than 40%.

Criticized challengerCriticized default
Negative label rate →
01
02
03
04
05
06
07
08
09
10
11
12
Accepted challengerEndorsed leader
0%First-choice share → · lines at 30% share and 25% negative50%
Key
01Trivy36%
02Snyk Open Source33%
03GitHub Dependabot5%
04OWASP Dependency-Check5%
05Semgrep Supply Chain2%
06OSV-Scanner2%
07Mend.io2%
08Socket0%
09FOSSA0%
10Endor Labs0%
11Sonatype Lifecycle0%
12Black Duck0%

02What they warned about

Zero of twelve models held their first choice under the paraphrase. Claude Haiku 4.5, GPT-5.4 mini, Gemini 3.5 Flash, Perplexity Sonar, Grok 4.1 Fast, Mistral Small, DeepSeek V4 Flash, Llama 4 Maverick, Qwen 3.7 Flash, Kimi K2, GLM 4.7 FlashX and MiniMax M2.5 changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
Black Duck
80%
16 of 20 labels negative · 8 of 12 models · 7 hard negative
“Black Duck has a high price and minimum licensing requirements that can be prohibitive for small teams or startups.” Claude Haiku 4.5, negative prompt
OWASP Dependency-Check
32%
10 of 31 labels negative · 8 of 12 models
“It generally has a higher false-positive rate and a less modern user interface compared to Trivy or Semgrep.” GLM 4.7 FlashX, budget prompt
Mend.io
41%
9 of 22 labels negative · 7 of 12 models · 4 hard negative
“premature and pricey for a small business ... rather than locking into an enterprise contract like Black Duck or Mend prematurely” DeepSeek V4 Flash, negative prompt
Sonatype Lifecycle
73%
8 of 11 labels negative · 7 of 12 models · 1 hard negative
“PeerSpot users call it "high" and "suitable only for enterprises," not small businesses.” Grok 4.1 Fast, negative prompt

03What they cite

Citations exist only for the models that return a source list: twelve of the twelve in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

64 of 72 answers in this category came back with a source list, from 12 of 12 models: citations where the model returns them, or the search results it consulted. 5 of those lists are Google grounding redirects that name no site and are left out of the counts. 812 links across 168 sites, every framing counted. Ranked by the number of answers carrying the site or page.

vendor site · Endor Labs47 answers · 74 citations · 10 models
32 answers · 32 citations · 9 models
30 answers · 31 citations · 10 models
vendor site · Guideflow25 answers · 25 citations · 9 models
24 answers · 48 citations · 9 models
vendor site · Aikido22 answers · 27 citations · 8 models
vendor site · Safeguard21 answers · 43 citations · 8 models
vendor site · Mend18 answers · 20 citations · 10 models
vendor site · Expert Insights18 answers · 18 citations · 10 models
vendor site · Cycode17 answers · 18 citations · 9 models
17 answers · 18 citations · 8 models
16 answers · 16 citations · 9 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

04How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ModelDirect“What is the best software composition analysis tool for a small B2B company?”Paraphrase“Which open source dependency vulnerability scanner would you recommend to a small business that sells to other businesses?”Comparative“What are the top software composition analysis tools for a small team and how do they differ?”Budget-constrained“What is the best software composition analysis tool for a small company with a tight budget?”Scale-constrained“We are a 30 person company evaluating a software composition analysis tool. What should we look at?”Negative“Which software composition analysis tools should a small business avoid or be cautious about?”
Claude Haiku 4.5SonarQube
One alternativeLibraries.io
OWASP Dependency-Check, Snyk Open SourceChanged
Two alternativesGrype, Trivy
Syft/Grype, Trivy
Four alternativesGitHub Dependabot, Mend.io, Semgrep Supply Chain, Snyk Open Source
Semgrep Supply Chain
Three alternativesFOSSA, OSS Review Toolkit, OWASP Dependency-Check
no first choiceagainst: Black Duck, Checkmarx SCA, Endor Labs
GPT-5.4 miniSnyk Open Source
Two alternativesOWASP Dependency-Track, Trivy
GitHub DependabotChanged
One alternativeOWASP Dependency-Check
against: Snyk Open Source
GitHub Dependabot
Three alternativesOWASP Dependency-Check, OWASP Dependency-Track, Snyk Open Source
against: Mend.io, Sonatype Lifecycle
OWASP Dependency-Check
Two alternativesFOSSA, Snyk Open Source
no first choicenothing named
Gemini 3.5 FlashAikido Security
Four alternativesFOSSA, Jit, Semgrep Supply Chain, Snyk Open Source
against: Black Duck, GitHub Dependabot, GitLab Dependency Scanning, Sonatype Lifecycle
TrivyChanged
Two alternativesOSV-Scanner, Syft/Grype
Semgrep Supply Chain
Three alternativesAikido Security, Snyk Open Source, Trivy
against: GitHub Dependabot
GitHub Dependabot, SOOS
Four alternativesAikido Security, Snyk Open Source, Syft/Grype, Trivy
against: Black Duck, Sonatype Lifecycle
Snyk Open Source
Six alternativesDebricked, GitHub Dependabot, GitLab Dependency Scanning, Renovate, Semgrep, Socket
against: Black Duck, Veracode
against: Black Duck, Checkmarx, Mend.io, OWASP Dependency-Check, Veracode
Perplexity SonarSnyk Open Source
Three alternativesFOSSA, Mend.io, Trivy
OSV-ScannerChanged
Three alternativesGrype, OWASP Dependency-Check, Trivy
Snyk Open Source
Four alternativesFOSSA, Semgrep Supply Chain, Socket, Trivy
Trivy
Two alternativesOWASP Dependency-Check, Snyk Open Source
no first choiceagainst: Black Duck, Checkmarx/Mend-style enterprise offerings, OWASP Dependency-Check, Sonatype Lifecycle, Trivy
Grok 4.1 FastSnyk Open Source
Three alternativesGitHub Dependabot, OWASP Dependency-Check, Trivy
against: Black Duck, Mend.io
TrivyChanged
One alternativeOSV-Scanner
against: OWASP Dependency-Check
Snyk Open Source, Trivy
Three alternativesFOSSA, OWASP Dependency-Check, Semgrep Supply Chain
Trivy
Four alternativesGitHub Dependabot, Grype + Syft, OSV-Scanner, Snyk Open Source
against: OWASP Dependency-Check
Mend.io, Snyk Open Sourceagainst: Black Duck, Checkmarx SCA, JFrog Xray, Mend.io, Sonatype Lifecycle
Mistral SmallSnyk Open Source
Two alternativesSemgrep, Trivy
TrivyChanged
One alternativeOSV-Scanner
against: OWASP Dependency-Check
GitHub Advanced Security + Dependabot, Snyk Open Source
Three alternativesFOSSA, Socket, Trivy
Trivy
Three alternativesSemgrep Supply Chain, Snyk Open Source, Socket
no first choicenothing named
DeepSeek V4 FlashSnyk Open Source
Three alternativesGitHub Dependabot, Mend.io, SOOS
against: OWASP Dependency-Check
OWASP Dependency-TrackChanged
One alternativeOWASP Dependency-Check
against: Anchore, Sonatype OSS Index
GitHub Dependabot
Four alternativesFOSSA, Snyk Open Source, Socket, Trivy
against: Endor Labs, Semgrep Supply Chain
Snyk Open Source, Trivy
Four alternativesGrype, Semgrep Supply Chain, Socket, Syft
no first choice
Six alternativesFOSSA, OWASP Dependency-Check, Semgrep, Snyk Open Source, Socket, Trivy
against: Black Duck, Endor Labs, Mend.io, OWASP Dependency-Check, Sonatype Lifecycle
Llama 4 Maverickno first choiceMeterianChanged
Two alternativesAikido Security, OSV-Scanner
Snyk Open Source
Two alternativesSocket, Trivy
Trivy
Three alternativesSemgrep, Snyk Open Source, Socket
no first choicenothing named
Qwen 3.7 FlashSnyk Open Source
Two alternativesGitHub Dependabot, Trivy
TrivyChanged
Two alternativesLicenseScanner, OWASP Dependency-Track
Snyk Open Source
Five alternativesFOSSA, Mend.io, OWASP Dependency-Check, OWASP Dependency-Track, Semgrep Supply Chain
against: Black Duck, Checkmarx SCA
Snyk Open Source, Trivy
Two alternativesSemgrep, Socket
against: OWASP Dependency-Check
no first choiceagainst: Black Duck, Sonatype Lifecycle
Kimi K2Snyk Open Source
Two alternativesGitHub Dependabot, Trivy
TrivyChanged
Three alternativesGrype, OSV-Scanner, OWASP Dependency-Check
Snyk Open Source, Trivy
Two alternativesSemgrep Supply Chain, Socket
Trivy
Three alternativesFOSSA, Semgrep, Snyk Open Source
against: OWASP Dependency-Check
no first choice
Three alternativesAikido Security, GitHub Dependabot, Snyk Open Source
against: Black Duck, Mend.io, Sonatype Nexus Lifecycle / Repository Pro
GLM 4.7 FlashXSnyk Open Source
Five alternativesGitHub Advanced Security, Mend.io, Semgrep Supply Chain, Socket, Sonatype Lifecycle
against: Black Duck
OWASP Dependency-TrackChanged
Five alternativesGrype, OSV-Scanner, OWASP Dependency-Check, Syft, Trivy
Snyk Open Source
Eight alternativesAikido Security, FOSSA, Jit, OWASP Dependency-Check, Semgrep Supply Chain, Socket, SonarQube, Trivy
against: Black Duck
Trivy
Two alternativesSOOS, Semgrep Supply Chain
against: Black Duck, Mend.io, OWASP Dependency-Check, Snyk Open Source
no first choiceagainst: Black Duck, Checkmarx SCA, Endor Labs, Mend.io, Sonatype Lifecycle
MiniMax M2.5Snyk Open Source
One alternativeFOSSA
against: Mend.io
TrivyChanged
Three alternativesGrype, OWASP Dependency-Check, Syft
Snyk Open Source
Four alternativesFOSSA, Semgrep Supply Chain, Socket, Trivy
Trivy
Three alternativesSemgrep, Snyk Open Source, Socket
no first choicenothing named
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

05The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Seventy-two rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 12:07yes2144 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 12:19yes27 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-09-17 11:51yes1025 s
Direct recommendationPerplexity Sonarsonar2026-09-17 12:38yes205 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 09:37yes3520 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-09-17 09:40yes53 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 11:25yes1316 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 12:12yes73 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 13:07yes1038 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-09-17 13:17yes1523 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 10:53yes2068 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 10:28yes518 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 11:39no04 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 10:23yes35 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-09-17 13:14yes1122 s
ParaphrasePerplexity Sonarsonar2026-09-17 10:40yes206 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 09:39yes2812 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-09-17 13:22yes56 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 10:45yes1920 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 11:05yes54 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 10:20no042 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-09-17 10:26yes1324 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 11:16yes1873 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 10:41yes1229 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 12:56yes159 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 09:24yes611 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-09-17 12:28yes2332 s
ComparativePerplexity Sonarsonar2026-09-17 10:19yes208 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 13:49yes3920 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-09-17 12:33yes57 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 09:44yes1922 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 13:17yes52 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 10:39yes522 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-09-17 12:57yes1547 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 14:07yes939 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 14:04yes1130 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 12:54yes169 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 09:38yes34 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-09-17 12:18yes1723 s
Budget constrainedPerplexity Sonarsonar2026-09-17 12:49yes205 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 14:15yes3418 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-09-17 14:09yes54 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 10:33yes913 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 13:23yes610 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 12:55yes531 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-09-17 11:37yes516 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 10:17yes27111 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 14:07yes542 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 11:33no05 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 11:36no010 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-09-17 09:50no016 s
Scale constrainedPerplexity Sonarsonar2026-09-17 12:31yes208 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 13:11yes1313 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-09-17 12:03no09 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 09:55yes1822 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 13:26yes53 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 12:10no034 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-09-17 12:35yes1020 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 13:52no017 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 11:11yes524 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 13:15yes169 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 13:33yes56 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-09-17 13:42yes1022 s
Negative framingPerplexity Sonarsonar2026-09-17 09:42yes207 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 10:25yes4518 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-09-17 13:15yes56 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 09:47yes2522 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 11:15yes52 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 11:53yes533 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-09-17 12:44yes2663 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 11:17yes2150 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 11:44yes831 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

Category-scoped readings
Aikido read as Aikido Security
GitLab read as GitLab Dependency Scanning
Mend read as Mend.io
Mend (WhiteSource) read as Mend.io
Mend (formerly WhiteSource) read as Mend.io
Snyk read as Snyk Open Source
Snyk (Free Tier) read as Snyk Open Source
Snyk (Open Source) read as Snyk Open Source
Snyk Free Tier read as Snyk Open Source
Snyk Team read as Snyk Open Source
Sonatype read as Sonatype Lifecycle
Unresolved, counted raw
Black Duck Binary Analysis (formerly Protecode)
CAST Highlight
Checkmarx/Mend-style enterprise offerings
GitLab Auto-DevSecOps
Libraries.io
LicenseScanner
Sonatype Nexus Lifecycle / Repository Pro
Sonatype OSS Index
Vulert
Discontinued, still offered
No shut-down product was recommended here.
← Feature flagsSource control →