IT AI Index
Index Developer platform SCA › Enterprise September 2026 Edition

Software composition analysis for enterprise buyers

Asked as “software composition analysis tool”, and as “open source dependency vulnerability scanner”, on behalf of an enterprise B2B company. 42 first choices recorded across the direct, paraphrase, budget and scale prompts, twelve models each.
Standing
Contested
19% of first choices, contested.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

01The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all twelve models, for an enterprise B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrant
01Black Duck19%6%47accepted challenger
02Sonatype Lifecycle19%8%40accepted challenger
03Aikido Security14%0%12accepted challenger
04OWASP Dependency-Track14%0%10accepted challenger
05Snyk Open Source10%19%47accepted challenger
06Mend.io10%17%41accepted challenger
07Trivy7%0%15accepted challenger
08OWASP Dependency-Check5%61%18criticized challenger
09JFrog Xray2%16%19accepted challenger
Show the four products at 0%, ordered by negative rate
13FOSSA0%19%16accepted challenger
12Veracode0%8%13accepted challenger
11Checkmarx SCA0%7%15accepted challenger
10Endor Labs0%5%22accepted challenger
Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its vendor page.

Recommended versus criticized

Every product with at least 10 labels here, on both axes. The 30% line names a quadrant, not the verdict above: that one needs more than 40%.

Criticized challengerCriticized default
Negative label rate →
01
02
03
04
05
06
07
08
09
10
11
12
13
Accepted challengerEndorsed leader
0%First-choice share → · lines at 30% share and 25% negative30%
Key
01Black Duck19%
02Sonatype Lifecycle19%
03Aikido Security14%
04OWASP Dependency-Track14%
05Snyk Open Source10%
06Mend.io10%
07Trivy7%
08OWASP Dependency-Check5%
09JFrog Xray2%
10Endor Labs0%
11Checkmarx SCA0%
12Veracode0%
13FOSSA0%

02What they warned about

Zero of twelve models held their first choice under the paraphrase. Claude Haiku 4.5, GPT-5.4 mini, Gemini 3.5 Flash, Perplexity Sonar, Grok 4.1 Fast, Mistral Small, DeepSeek V4 Flash, Llama 4 Maverick, Qwen 3.7 Flash, Kimi K2, GLM 4.7 FlashX and MiniMax M2.5 changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
OWASP Dependency-Check
61%
11 of 18 labels negative · 7 of 12 models · 3 hard negative
“Avoid as your primary enterprise SCA; use only as a supplementary check for legacy Java-only codebases.” DeepSeek V4 Flash, negative prompt
Snyk Open Source
19%
9 of 47 labels negative · 7 of 12 models · 2 hard negative
“Avoid tools like **Snyk**, **Socket**, or **Semgrep** if your primary goal is cost prediction” Qwen 3.7 Flash, budget prompt
Mend.io
17%
7 of 41 labels negative · 4 of 12 models · 1 hard negative
“Same scaling problem; thousands of users = unpredictable ballooning costs” Kimi K2, budget prompt
FOSSA
19%
3 of 16 labels negative · 3 of 12 models · 1 hard negative
“What to Avoid for Your Use Case ... FOSSA | Per-project or per-developer hybrid” Kimi K2, budget prompt

03What they cite

Citations exist only for the models that return a source list: twelve of the twelve in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

66 of 72 answers in this category came back with a source list, from 12 of 12 models: citations where the model returns them, or the search results it consulted. 6 of those lists are Google grounding redirects that name no site and are left out of the counts. 1020 links across 250 sites, every framing counted. Ranked by the number of answers carrying the site or page.

vendor site · Endor Labs42 answers · 62 citations · 10 models
vendor site · Guideflow37 answers · 37 citations · 9 models
vendor site · Cycode31 answers · 36 citations · 10 models
vendor site · Safeguard28 answers · 53 citations · 7 models
vendor site · Mend23 answers · 29 citations · 9 models
vendor site · Aikido22 answers · 35 citations · 10 models
vendor site · Black Duck21 answers · 35 citations · 9 models
21 answers · 23 citations · 10 models
20 answers · 37 citations · 9 models
vendor site · Sonatype20 answers · 36 citations · 9 models
19 answers · 20 citations · 8 models
vendor site · Expert Insights19 answers · 19 citations · 10 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

04How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ModelDirect“What is the best software composition analysis tool for an enterprise B2B company?”Paraphrase“Which open source dependency vulnerability scanner would you recommend to a large B2B company with thousands of employees?”Comparative“What are the top enterprise-grade software composition analysis tools and how do they differ?”Budget-constrained“What is the best software composition analysis tool for a large company that needs predictable total cost across thousands of users?”Scale-constrained“We are a 5,000 person company with SSO, SOC 2 and procurement review requirements evaluating a software composition analysis tool. What should we look at?”Negative“Which software composition analysis tools should a large enterprise avoid or be cautious about?”
Claude Haiku 4.5Mend.io, Sonatype Lifecycle
Three alternativesBlack Duck, Checkmarx SCA, Snyk Open Source
OWASP Dependency-CheckChanged
Three alternativesMend.io, Snyk Open Source, Trivy
Black Duck
Four alternativesFOSSA, JFrog Xray, Snyk Open Source, Veracode
Mend.io
One alternativeBlack Duck
no first choicenothing named
GPT-5.4 miniSonatype Lifecycle
Four alternativesBlack Duck, Palo Alto Networks Cortex Cloud SCA, Snyk Open Source, Veracode
OWASP Dependency-TrackChanged
Two alternativesOSS Review Toolkit, OWASP Dependency-Check
no first choiceSonatype Lifecycle
One alternativeBlack Duck
no first choicenothing named
Gemini 3.5 FlashBlack Duck
Five alternativesFOSSA, GitHub Advanced Security, GitLab Dependency Scanning, Snyk Open Source, Sonatype Lifecycle
OWASP Dependency-TrackChanged
Three alternativesGrype, Syft, Trivy
against: OWASP Dependency-Check
Black Duck, Snyk Open Source
Five alternativesEndor Labs, GitHub Advanced Security, GitLab Dependency Scanning, Mend.io, Sonatype Lifecycle
Aikido Security, JFrog Xray
Five alternativesGrype, HCL AppScan, OWASP Dependency-Track, Trivy, Veracode
against: GitHub Advanced Security, Semgrep, Snyk Open Source
no first choiceagainst: GitHub Dependabot, GitLab Dependency Scanning, OWASP Dependency-Check
Perplexity SonarSonatype Lifecycle
Four alternativesBlack Duck, Checkmarx SCA, Mend.io, Snyk Open Source
Aikido SecurityChanged
Two alternativesOSV-Scanner, Trivy
against: OWASP Dependency-Check
Black Duck
Five alternativesEndor Labs, FOSSA, Mend.io, Snyk Open Source, Sonatype Lifecycle
OWASP Dependency-Track
Two alternativesBlack Duck, Sonatype Lifecycle
no first choiceagainst: GitHub, JFrog, OWASP Dependency-Check, Retire.js, Safety, Sonatype Lifecycle, bundler-audit
Grok 4.1 FastBlack Duck, Sonatype Lifecycle
One alternativeSnyk Open Source
against: Checkmarx SCA, Endor Labs, JFrog Xray
OWASP Dependency-TrackChanged
Two alternativesSyft/Grype, Trivy
against: OWASP Dependency-Check
Snyk Open Source, Sonatype Lifecycle
Three alternativesBlack Duck, Mend.io, Veracode
Black Duck, Sonatype Lifecycleagainst: Mend.io, Snyk Open Sourceno first choice
Six alternativesBlack Duck, Cycode, Endor Labs, Mend.io, Snyk Open Source, Sonatype Lifecycle
against: Black Duck, GitHub Advanced Security, JFrog Xray, Mend.io, OWASP Dependency-Check, Retire.js, Snyk Open Source, Sonatype Lifecycle
Mistral SmallSnyk Open Source, Sonatype Lifecycle
Two alternativesBlack Duck, Mend.io
OWASP Dependency-TrackChanged
Two alternativesGrype, Trivy
no first choiceBlack Duck, Mend.ioagainst: Checkmarx One, FOSSAno first choicenothing named
DeepSeek V4 FlashBlack Duck, Snyk Open Source
Three alternativesEndor Labs, Mend.io, Sonatype Lifecycle
TrivyChanged
Two alternativesGrype, OWASP Dependency-Track
against: OWASP Dependency-Check
Sonatype Lifecycle
Six alternativesBlack Duck, Endor Labs, FOSSA, JFrog Xray, Mend.io, Snyk Open Source
Aikido Security
Three alternativesBlack Duck, DeepSource, Sonatype Lifecycle
against: Mend.io, Snyk Open Source
Snyk Open Source
Seven alternativesBlack Duck, Endor Labs, FOSSA, GitHub Advanced Security, GitLab Dependency Scanning, Mend.io, Sonatype Lifecycle
against: Black Duck, Bumblebee, CodeQL, GitHub Dependabot, Mend.io, OWASP Dependency-Check, Retire.js, Snyk Open Source, Sonatype Lifecycle, npm audit
Llama 4 Maverickno first choiceAikido SecurityChanged
Four alternativesAnchore Open Source Dependency Scanner, FOSSA, OWASP Dependency-Check, Snyk Open Source
Cycode
Two alternativesSnyk Open Source, Veracode
no first choiceno first choice
Four alternativesBlack Duck, Endor Labs, Mend.io, Snyk Open Source
against: Snyk Open Source
Qwen 3.7 FlashMend.io
Three alternativesBlack Duck, Snyk Open Source, Sonatype Lifecycle
TrivyChanged
Six alternativesBlack Duck, Endor Labs, Grype, OSV-Scanner, Snyk Open Source, Syft
Black Duck
Five alternativesEndor Labs, FOSSA, Mend.io, Snyk Open Source, Sonatype Lifecycle
Aikido Security
Three alternativesBlack Duck, DeepSource, Trivy
against: Mend.io, Semgrep, Snyk Open Source, Socket
no first choiceagainst: Mend.io
Kimi K2Black Duck
Two alternativesSnyk Open Source, Sonatype Lifecycle
TrivyChanged
Three alternativesBlack Duck, Endor Labs, Snyk Open Source
against: OWASP Dependency-Check
Black Duck
Four alternativesEndor Labs, Mend.io, Snyk Open Source, Sonatype Lifecycle
Sonatype Lifecycle
One alternativeBlack Duck
against: FOSSA, Mend.io, Snyk Open Source
no first choiceagainst: Debricked, OpenText Core SCAnothing named
GLM 4.7 FlashXBlack Duck
Four alternativesEndor Labs, Mend.io, Snyk Open Source, Sonatype Lifecycle
OWASP Dependency-CheckChanged
Three alternativesAikido Security, OSV-Scanner, Trivy
Black Duck, Sonatype Lifecycle
Four alternativesAikido Security, Endor Labs, Mend.io, Snyk Open Source
Snyk Open Source
One alternativeSonatype Lifecycle
against: Black Duck, JFrog Xray
no first choiceagainst: OWASP Dependency-Checknothing named
MiniMax M2.5Black Duck
Two alternativesMend.io, Snyk Open Source
OWASP Dependency-TrackChanged
Four alternativesAnchore, GitLab Dependency Scanning, OWASP Dependency-Check, Trivy
Black Duck, Sonatype Lifecycle
Five alternativesCheckmarx SCA, Endor Labs, JFrog Xray, Mend.io, Snyk Open Source
Aikido Security
One alternativeBlack Duck
against: FOSSA, Snyk Open Source, Veracode
no first choiceagainst: OWASP Dependency-Check
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

05The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Seventy-two rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 11:41yes1610 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 12:31yes57 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-09-17 09:24yes1226 s
Direct recommendationPerplexity Sonarsonar2026-09-17 11:34yes196 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 11:58yes3716 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-09-17 10:53yes54 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 10:51yes1316 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 09:35yes58 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 11:35yes946 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-09-17 10:06yes1432 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 11:48yes1272 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 10:30yes1526 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 13:15no06 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 09:56yes36 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-09-17 12:20yes1624 s
ParaphrasePerplexity Sonarsonar2026-09-17 12:00yes206 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 11:25yes3419 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-09-17 13:17yes2014 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 13:58yes1920 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 12:11yes53 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 12:00yes1972 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-09-17 13:53yes1736 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 11:16yes2959 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 09:46yes1050 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 12:06yes025 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 13:34yes58 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-09-17 13:13yes1233 s
ComparativePerplexity Sonarsonar2026-09-17 12:51yes2010 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 12:20yes3116 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-09-17 10:54yes58 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 10:06yes1824 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 11:10yes53 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 12:37yes534 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-09-17 09:36yes1437 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 10:42yes28130 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 09:29yes1238 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 14:03yes169 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 11:55yes46 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-09-17 12:29yes2328 s
Budget constrainedPerplexity Sonarsonar2026-09-17 13:47yes205 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 13:50yes3920 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-09-17 12:51yes55 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 10:09yes2626 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 12:25yes53 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 13:42yes24135 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-09-17 13:16yes2548 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 10:25yes27129 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 13:37yes1874 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 14:11yes1812 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 10:39no011 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-09-17 12:10yes726 s
Scale constrainedPerplexity Sonarsonar2026-09-17 14:06yes2011 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 13:27yes1812 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-09-17 10:18no08 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 09:53yes3028 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 12:00yes54 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 13:43no035 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-09-17 11:47yes3068 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 12:39yes29124 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 10:04no086 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 13:52yes3414 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 12:10yes46 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-09-17 11:26yes1528 s
Negative framingPerplexity Sonarsonar2026-09-17 12:14yes205 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 11:21yes2115 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-09-17 12:55yes56 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 12:48yes2749 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 12:19yes55 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 13:17yes1453 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-09-17 12:35yes2750 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 12:00yes1259 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 12:00yes2378 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

Category-scoped readings
Aikido read as Aikido Security
GitLab Ultimate read as GitLab Dependency Scanning
Mend read as Mend.io
Mend (Formerly WhiteSource) read as Mend.io
Mend (Fortify) read as Mend.io
Mend (formerly WhiteSource) read as Mend.io
Snyk read as Snyk Open Source
Sonatype read as Sonatype Lifecycle
Sonatype (Nexus Lifecycle) read as Sonatype Lifecycle
Unresolved, counted raw
Anchore Open Source Dependency Scanner
Bumblebee
CyberArk CyberArk OSA
OpenText Core SCA
Palo Alto Networks Cortex Cloud SCA
Discontinued, still offered
No shut-down product was recommended here.
← Feature flagsSource control →