AI Indexes
IT AI Index
October 2026 Edition · The permanent record of this edition. The unqualified address always carries the latest edition.
Index › Developer platform › SCA › Small business › October 2026 Edition

Software composition analysis for small business buyers

Asked as “software composition analysis tool”, and as “open source dependency vulnerability scanner”, on behalf of a small B2B company. 61 first choices recorded across the direct, paraphrase, budget and scale prompts, fourteen models each.
Standing · first-choice share
39%
Contested · Trivy 18%
39Snyk Open Source18Trivy15OWASP Dependency-Check28others

39% of first choices, contested.

Since September 2026↗new leaderNew leader since September 2026: Snyk Open Source (41%) replaces Trivy (36% then, 15% now), 26 points clear, past the 11-point floor.Snyk Open Source leads at 41%, replacing Trivy, which led at 36% and stands at 15% now: 26 points clear, past the floor. The verdict moved from contested to clear leader.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all fourteen models, for a small B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrantSince September 2026
01Snyk Open Source39%18%62endorsed leader▲+7Since September 2026: 33% → 41%, +7 points. Inside the 11-point floor: within noise. Read over the models both editions asked.33% → 41%
02Trivy18%0%41accepted challenger▼−21Since September 2026: 36% → 15%, −21 points. Past the 11-point floor: movement. Read over the models both editions asked.36% → 15%
03OWASP Dependency-Check15%22%41accepted challenger▲+12Since September 2026: 5% → 17%, +12 points. Past the 11-point floor: movement. Read over the models both editions asked.5% → 17%
04GitHub Dependabot5%14%28accepted challenger▼−1Since September 2026: 5% → 4%, −1 point. Inside the 11-point floor: within noise. Read over the models both editions asked.5% → 4%
05FOSSA5%0%19accepted challenger▲+4Since September 2026: 0% → 4%, +4 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 4%
06Aikido Security5%0%13accepted challenger▲+3Since September 2026: 2% → 6%, +3 points. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 6%
07Socket2%0%19accepted challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
08GitHub Advanced Security2%15%26accepted challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
09Grype2%0%12accepted challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
10OSV-Scanner2%7%14accepted challenger▼−1Since September 2026: 2% → 2%, −1 point. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 2%
11Sonatype Lifecycle2%55%22criticized challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
Show the three products at 0%, ordered by negative rate
14Black Duck0%80%25criticized challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
13Mend.io0%50%28criticized challenger▼−2Since September 2026: 2% → 0%, −2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 0%
12Semgrep Supply Chain0%14%14accepted challenger▼−2Since September 2026: 2% → 0%, −2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 0%

The floor is 11 points of share, measured: how far the models move a leader on their own when the same questions are asked twice with nothing changed. A larger change is movement; a smaller one is noise, and both are shown. Movement is read over the twelve models both editions asked; GPT-6 Luna, Muse Glimmer 30B joined this edition and are in the standing but not yet in the comparison. How the floor is measured

Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its product page.
All twenty-eight head-to-head pages: the top eight products, each against each

Recommended versus criticized

Every product with at least 10 labels here, on both axes. The 30% line names a quadrant, not the verdict above: that one needs more than 40%.

Criticized challengerCriticized default
Negative label rate →
01
02
03
04
05
06
07
08
G09
10
11
12
13
14
Accepted challengerEndorsed leader
0%First-choice share → · lines at 30% share and 25% negative50%
Key
01Snyk Open Source39%
02Trivy18%
03OWASP Dependency-Check15%
04GitHub Dependabot5%
05FOSSA5%
06Aikido Security5%
07Socket2%
08GitHub Advanced Security2%
09Grype2%
10OSV-Scanner2%
11Sonatype Lifecycle2%
12Semgrep Supply Chain0%
13Mend.io0%
14Black Duck0%

What they warned about

Zero of fourteen models held their first choice under the paraphrase. Claude Haiku 4.5, GPT-5.4 mini, Gemini 3.5 Flash, Perplexity Sonar, Grok 4.1 Fast, Mistral Small, DeepSeek V4 Flash, Llama 4 Maverick, Qwen 3.7 Flash, Kimi K2, GLM 4.7 FlashX, MiniMax M2.5, GPT-6 Luna and Muse Glimmer 30B changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
Black Duck
80%
20 of 25 labels negative · 10 of 14 models · 13 hard negative
“Marketed as a large‑enterprise solution; pricing can be prohibitive for small teams... Enterprise workflows and binary analysis are unnecessary for most small businesses.” GLM 4.7 FlashX, negative prompt
Mend.io
50%
14 of 28 labels negative · 9 of 14 models · 5 hard negative
“Priced on a per‑developer basis, often in the thousands of dollars per developer per year... renewal costs can rise year over year and that licensing is opaque.” GLM 4.7 FlashX, negative prompt
Snyk Open Source
18%
11 of 62 labels negative · 9 of 14 models · 1 hard negative
“What I'd Avoid ... eventually pushes toward paid plans; also requires account creation and has usage limits” Kimi K2, paraphrase prompt
Sonatype Lifecycle
55%
12 of 22 labels negative · 8 of 14 models · 8 hard negative
“"Enterprise-first" SCA platforms (e.g., Veracode, Checkmarx, Sonatype Nexus Lifecycle) ... Verdict: Avoid unless you are already an enterprise customer” DeepSeek V4 Flash, negative prompt

What they cite

Citations exist only for the models that return a source list: fourteen of the fourteen in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

79 of 84 answers in this category came back with a source list, from 14 of 14 models: citations where the model returns them, or the search results it consulted. 1067 links across 187 sites, every framing counted. Ranked by the number of answers carrying the site or page. 3 of the 252 answers across every segment cited this index's own page for the category; the method page measures whether that reading tilts an answer.

vendor site · Guideflow48 answers · 52 citations · 10 models
33 answers · 33 citations · 10 models
vendor site · Checkmarx31 answers · 34 citations · 10 models
29 answers · 47 citations · 10 models
vendor site · Aikido28 answers · 37 citations · 10 models
vendor site · Sonatype25 answers · 31 citations · 10 models
24 answers · 24 citations · 10 models
vendor site · Safeguard23 answers · 40 citations · 7 models
vendor site · Mend22 answers · 26 citations · 10 models
22 answers · 23 citations · 10 models
vendor site · G220 answers · 33 citations · 12 models
vendor site · Endor Labs20 answers · 21 citations · 9 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

Search against answers

Each company's standing in the answers beside its site's footprint in Google search, one row a site: the products the models named on it with their shares, and the share they add up to; monthly searches on Google, and DataForSEO's estimate of AI search demand (modeled from search signals, directional, not a count of queries to any assistant), for the most-searched of the company's and its products' names (the name is in each row's hover text); estimated monthly organic visits to the site; and its best position in Google's top ten for “best software composition analysis tool”, “software composition analysis tool”, “software composition analysis tools”. US estimates from DataForSEO and Google's Ads Transparency Center. A small company's site, or a mid-sized company's site for its flagship, is marked company; a product on a large parent's site (Google, Microsoft) has no site figures. A column with no figures for this category is left out, and an empty cell means none were seen, not none exist. Two measurements side by side: neither is read as the cause of the other.
Company and productsShareOwn site citedName searches, GoogleAI search demand, est.Organic visitsPaid search a month, est.Google ads, last 30 daysBest Google position
Snyk snyk.io
Snyk Open Source 39%
39%17212,10058161,651 company60
Trivy trivy.dev18%2075,4001823,093
OWASP Dependency-Check owasp.org
OWASP Dependency-Check 15%, OWASP Dependency-Track 2%
16%9572010365,2223
GitHub parent site
GitHub Dependabot 5%, GitHub Advanced Security 2%
7%1111,500,00031,479
FOSSA fossa.com5%5574,0004,140133,9021
Aikido aikido.dev
Aikido Security 5%
5%3422,400516,442 company$936120
Socket socket.dev2%3360,50095,97916,4651
Grype2%1,00044
OSV-Scanner osv.dev2%3139022749
Semgrep semgrep.dev
Semgrep 2%, Semgrep Supply Chain 0%
2%1948,1001913,46143

Google's top ten for the three searches hold 22 sites; 2 of them are among the sites the models cited here (endorlabs.com, sonatype.com). The first result for “best software composition analysis tool” is endorlabs.com.

How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ShowHide
ModelDirect“What is the best software composition analysis tool for a small B2B company?”Paraphrase“Which open source dependency vulnerability scanner would you recommend to a small business that sells to other businesses?”Comparative“What are the top software composition analysis tools for a small team and how do they differ?”Budget-constrained“What is the best software composition analysis tool for a small company with a tight budget?”Scale-constrained“We are a 30 person company evaluating a software composition analysis tool. What should we look at?”Negative“Which software composition analysis tools should a small business avoid or be cautious about?”
Claude Haiku 4.5Aikido Security, Snyk Open Source
Two alternativesFOSSA, OWASP Dependency-Check
TrivyChanged
Two alternativesOSV-Scanner, OWASP Dependency-Check
GitHub Dependabot, OWASP Dependency-Check, Snyk Open Source
Two alternativesGitLab Dependency Scanning, SOOS
against: Semgrep Supply Chain
Snyk Open Source
Four alternativesGitHub Dependabot, OWASP Dependency-Check, SOOS, Trivy
no first choiceagainst: Black Duck, Endor Labs, Snyk Open Source, Veracode SCA
GPT-5.4 miniSnyk Open Source
Two alternativesMend.io, Sonatype Lifecycle
OWASP Dependency-CheckChanged
Two alternativesOWASP Dependency-Track, Trivy
OWASP Dependency-Check, Snyk Open Source
One alternativeMend.io
against: Black Duck, Sonatype Lifecycle
OWASP Dependency-Track
Three alternativesOSS Review Toolkit, OWASP Dependency-Check, Trivy
against: Mend.io, Snyk Open Source
no first choiceagainst: GitHub Advanced Security, Snyk Open Source, Sonatype Lifecycle
Gemini 3.5 FlashAikido Security
Three alternativesFOSSA, SOOS, Snyk Open Source
against: GitHub Dependabot
TrivyChanged
Three alternativesGrype, OSV-Scanner, Syft
Aikido Security, GitHub Dependabot
Three alternativesSnyk Open Source, Socket, Trivy
GitHub Dependabot
Five alternativesAikido Security, GitLab Dependency Scanning, Grype + Syft, Snyk Open Source, Trivy
against: Black Duck, Mend.io, Veracode SCA
Aikido Security, SOOS
Four alternativesGitHub Dependabot, GitLab Dependency Scanning, Semgrep Supply Chain, Socket
against: Black Duck, Mend.io, Snyk Open Source, Sonatype Lifecycle
against: Black Duck, OWASP Dependency-Check, Snyk Open Source, Sonatype Lifecycle, Veracode SCA
Perplexity SonarSnyk Open Source
Four alternativesFOSSA, GitHub Advanced Security, OWASP Dependency-Check, Semgrep Supply Chain
OWASP Dependency-CheckChanged
One alternativeOSV-Scanner
Snyk Open Source
Three alternativesFOSSA, Grype, Trivy
against: Black Duck, Mend.io
Grype, Snyk Open Sourceno first choiceagainst: Black Duck, Checkmarx SCA, GitHub Dependabot, Mend.io, OWASP Dependency-Check, Sonatype Lifecycle
Grok 4.1 FastSnyk Open Source
Five alternativesFOSSA, GitHub Advanced Security, Grype, Syft, Trivy
against: Black Duck, Mend.io, Sonatype Lifecycle, Veracode SCA
TrivyChanged
One alternativeGrype
against: OWASP Dependency-Check
Snyk Open Source
Four alternativesGitHub Advanced Security (GHAS) / Dependabot, Mend.io, OWASP Dependency-Check, Trivy
against: Black Duck, Sonatype Lifecycle
Trivy
Three alternativesGrype, OWASP Dependency-Check, Snyk Open Source
against: GitHub Advanced Security, OWASP Dependency-Track
Snyk Open Source
Three alternativesGitHub Advanced Security, Mend.io, OWASP Dependency-Track
against: Black Duck, Checkmarx SCA, JFrog Xray, Mend.io, OSV-Scanner, OWASP Dependency-Check, Snyk Open Source, Sonatype Lifecycle
Mistral SmallFOSSA, Snyk Open Source
One alternativeGitHub Advanced Security
against: Mend.io
OWASP Dependency-CheckChanged
One alternativeGitHub Dependabot
Snyk Open Source
Four alternativesAikido Security, GitHub Advanced Security, Semgrep Supply Chain, Socket
Trivy
Four alternativesGitHub Dependabot, Renovate, Semgrep, Socket
against: Snyk Open Source
no first choicenothing named
DeepSeek V4 FlashSnyk Open Source
Three alternativesEndor Labs, FOSSA, OWASP Dependency-Check
against: Mend.io
OWASP Dependency-CheckChanged
Two alternativesOWASP Dependency-Track, Trivy
against: Snyk Open Source
Snyk Open Source
Four alternativesGitHub Dependabot, Mend.io, Semgrep Supply Chain, Trivy
against: OWASP Dependency-Check
Snyk Open Source
Three alternativesGitHub Dependabot, Semgrep Supply Chain, Trivy
Snyk Open Source
Two alternativesFOSSA, Semgrep Supply Chain
against: Mend.io, OWASP Dependency-Check
against: Black Duck, Checkmarx SCA, Microsoft Defender, OWASP Dependency-Check, Sonatype Lifecycle, Veracode SCA, Wiz
Llama 4 MaverickFOSSA, Snyk Open SourceOWASP Dependency-CheckChanged
Three alternativesAikido Security, GitLab Dependency Scanning, dep-scan
Aikido Security, Dependancy CheckerSemgrep, Snyk Open Source
Two alternativesGitHub Advanced Security, Insignary Clarity
no first choicenothing named
Qwen 3.7 FlashSnyk Open Source
One alternativeSonatype Lifecycle
against: Black Duck
TrivyChanged
Five alternativesOWASP Dependency-Check, cargo audit, govulncheck, npm audit, pip-audit
Snyk Open Source
Three alternativesAikido Security, OWASP Dependency-Check, Socket
Snyk Open Source, Trivy
Two alternativesGitHub Dependabot, Semgrep
no first choiceagainst: Black Duckagainst: Black Duck, Checkmarx SCA, Mend.io, OpenText Fortify
Kimi K2Snyk Open Source
Four alternativesFOSSA, GitHub Advanced Security, GitHub Dependabot, Semgrep
OSV-ScannerChanged
Two alternativesGrype + Syft, Trivy
against: OWASP Dependency-Check, Snyk Open Source
Snyk Open Source
Three alternativesSemgrep Supply Chain, Socket, Trivy
against: GitHub Advanced Security, GitHub Dependabot
GitHub Dependabot, OWASP Dependency-Check
Two alternativesSnyk Open Source, Trivy
GitHub Advanced Security, Snyk Open Source
One alternativeMend.io
against: Black Duck
against: Black Duck, JFrog Xray, Sonatype Lifecycle, Veracode SCA
GLM 4.7 FlashXSnyk Open Source
Two alternativesGitHub Advanced Security, Trivy
OWASP Dependency-CheckChanged
Two alternativesOSV-Scanner, OWASP Dependency-Track
Snyk Open Source, Trivy
Three alternativesFOSSA, Grype, Syft
against: Black Duck, Sonatype Lifecycle
Trivy
Six alternativesGitHub Advanced Security, GitHub Dependabot, Grype + Syft, OSV-Scanner, OWASP Dependency-Check, Semgrep
against: Black Duck, Endor Labs, Mend.io, Snyk Open Source
Snyk Open Source, Socket
Seven alternativesAikido Security, Black Duck, Endor Labs, GitHub Advanced Security, JFrog Xray, Semgrep Supply Chain, Sonatype Lifecycle
against: Black Duck, Checkmarx SCA, DeepSource, Endor Labs, GitHub Advanced Security, JFrog Xray, Mend.io, Semgrep Supply Chain, Wiz
MiniMax M2.5Snyk Open Source, Sonatype Lifecycle
Two alternativesGitHub Advanced Security, Mend.io
against: Black Duck
OWASP Dependency-CheckChanged
Two alternativesGitHub Advanced Security, Retire.js
Snyk Open Source
Four alternativesGitHub Dependabot, OWASP Dependency-Check, SonarQube, Trivy
OWASP Dependency-Check, Snyk Open Source
Two alternativesGitHub Dependabot, Mend.io
Snyk Open Source
Four alternativesBlack Duck, GitHub Advanced Security, GitHub Dependabot, Veracode SCA
nothing named
GPT-6 LunaSnyk Open Source
Two alternativesGitHub Dependabot, Socket
TrivyChanged
One alternativeOSV-Scanner
GitHub Dependabot
Four alternativesOSV-Scanner, Renovate, Snyk Open Source, Socket
GitHub Dependabot
Two alternativesOSV-Scanner, Trivy
against: Snyk Open Source
no first choiceagainst: GitHub Dependabot, GitHub's dependency graph, OWASP Dependency-Check, OWASP Dependency-Track, Renovate
Muse Glimmer 30BFOSSA, Snyk Open Source
Three alternativesGrype, OWASP Dependency-Check, Trivy
TrivyChanged
Three alternativesGitHub Dependabot, OWASP Dependency-Check, OWASP Dependency-Track
Snyk Open Source
Three alternativesFOSSA, OWASP Dependency-Check, Trivy
against: Mend.io
Trivy
Six alternativesGrype, OWASP Dependency-Check, Semgrep, Snyk Open Source, Socket, Syft
no first choiceagainst: JFrog Xray, Mend.io, formerly WhiteSource, Sonatype Lifecycle, Synopsys Black Duck SCA
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Eighty-four rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 07:39yes178 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 08:12yes36 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-10-01 11:20yes2225 s
Direct recommendationPerplexity Sonarsonar2026-10-01 09:39yes163 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 08:46yes237 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-10-01 09:15yes54 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 08:02yes2324 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 11:46yes52 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 12:08yes2068 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-10-01 11:40yes1927 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 12:23yes24145 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 11:57yes516 s
Direct recommendationGPT-6 Lunagpt-6-luna2026-10-01 12:05yes322 s
Direct recommendationMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 07:55yes2430 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 08:39yes179 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 09:29yes34 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-10-01 08:27yes1229 s
ParaphrasePerplexity Sonarsonar2026-10-01 08:27yes183 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 13:46yes218 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-10-01 13:19yes53 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 11:14yes2524 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 12:25yes52 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 08:57no030 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-10-01 10:54yes1820 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 08:17yes23176 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 10:06yes515 s
ParaphraseGPT-6 Lunagpt-6-luna2026-10-01 12:00yes220 s
ParaphraseMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 09:06yes1321 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 11:59yes98 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 11:05yes66 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-10-01 07:58yes1628 s
ComparativePerplexity Sonarsonar2026-10-01 11:26yes177 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 08:23yes239 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-10-01 10:09yes129 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 08:15yes2345 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 11:54yes52 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 11:40yes1446 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-10-01 10:45yes1830 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 08:53yes1821 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 10:34yes1624 s
ComparativeGPT-6 Lunagpt-6-luna2026-10-01 12:13yes922 s
ComparativeMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 07:45yes1238 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 07:36yes96 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 09:46yes36 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-01 09:59yes1722 s
Budget constrainedPerplexity Sonarsonar2026-10-01 08:50yes172 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 07:41yes206 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-10-01 11:40yes53 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 09:25yes2431 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 12:16yes52 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 11:35yes1041 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-01 08:29yes1424 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 10:15yes22128 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 11:36yes520 s
Budget constrainedGPT-6 Lunagpt-6-luna2026-10-01 12:03yes414 s
Budget constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 13:13yes1319 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 11:22no06 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 09:54no07 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-01 09:43yes1222 s
Scale constrainedPerplexity Sonarsonar2026-10-01 10:22yes164 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 13:31yes1410 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-10-01 10:56no08 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 08:53yes2537 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 13:22yes52 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 12:56no035 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-01 09:03yes1340 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 09:06yes1964 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 12:24yes1036 s
Scale constrainedGPT-6 Lunagpt-6-luna2026-10-01 10:24yes315 s
Scale constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 10:51yes1528 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 08:14yes189 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 11:49yes48 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-10-01 09:54yes1320 s
Negative framingPerplexity Sonarsonar2026-10-01 11:47yes173 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 09:33yes197 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-10-01 10:21yes53 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 12:35yes2145 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 11:53yes52 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 09:03yes1560 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-10-01 07:44yes2328 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 13:07yes1928 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 09:44yes828 s
Negative framingGPT-6 Lunagpt-6-luna2026-10-01 13:24yes419 s
Negative framingMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 10:43yes2236 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

ShowHide
Category-scoped readings
Aikido read as Aikido Security
Checkmarx read as Checkmarx SCA
Mend read as Mend.io
Mend (WhiteSource) read as Mend.io
Mend (formerly Veracode) read as Mend.io
Mend (formerly WhiteSource) read as Mend.io
Snyk read as Snyk Open Source
Snyk (Free Tier) read as Snyk Open Source
Snyk Team read as Snyk Open Source
Sonatype read as Sonatype Lifecycle
Veracode read as Veracode SCA
Veracode (SCA) read as Veracode SCA
Unresolved, counted raw
Dependancy Checker
GitHub's dependency graph
Mend.io, formerly WhiteSource
cargo audit
dep-scan
govulncheck
pip-audit
Discontinued, still offered
No shut-down product was recommended here.
← Secure code trainingSource control →