AI Indexes
IT AI Index
October 2026 Edition · The permanent record of this edition. The unqualified address always carries the latest edition.
Index › Developer platform › October 2026 Edition

Static application security testing

Asked as “SAST tool”, and as “static code security scanner”, on behalf of a mid-market B2B company. 50 first choices recorded across the direct, paraphrase, budget and scale prompts, fourteen models each.
Standing · first-choice share
36%
Contested · SonarQube 22%
36Semgrep22SonarQube14Snyk Code28others

36% of first choices, contested.

Since September 2026▼−17Since September 2026: 47% → 30%, −17 points. Past the 11-point floor: movement. Read over the models both editions asked.Semgrep held the lead, −17 points on 47%, past the floor.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all fourteen models, for a mid-market B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrantSince September 2026
01Semgrep36%5%63endorsed leader▼−17Since September 2026: 47% → 30%, −17 points. Past the 11-point floor: movement. Read over the models both editions asked.47% → 30%
02SonarQube22%18%62accepted challenger▲+1Since September 2026: 22% → 23%, +1 point. Inside the 11-point floor: within noise. Read over the models both editions asked.22% → 23%
03Snyk Code14%2%41accepted challenger▲+3Since September 2026: 13% → 16%, +3 points. Inside the 11-point floor: within noise. Read over the models both editions asked.13% → 16%
04Snyk8%9%11accepted challenger▲+2Since September 2026: 7% → 9%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.7% → 9%
05CodeQL4%11%27accepted challenger▲+2Since September 2026: 2% → 5%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 5%
06GitHub Advanced Security2%6%16accepted challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
07Veracode Static Analysis2%28%39criticized challenger=heldSince September 2026: 2% → 2%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 2%
08Checkmarx One2%45%44criticized challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
Show the two products at 0%, ordered by negative rate
10OpenText Fortify0%36%25criticized challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
09Bandit0%13%15accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%

The floor is 11 points of share, measured: how far the models move a leader on their own when the same questions are asked twice with nothing changed. A larger change is movement; a smaller one is noise, and both are shown. Movement is read over the twelve models both editions asked; GPT-6 Luna, Muse Glimmer 30B joined this edition and are in the standing but not yet in the comparison. How the floor is measured

Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its product page.
All twenty-eight head-to-head pages: the top eight products, each against each

Recommended versus criticized

Every product with at least 10 labels here, on both axes. The 30% line names a quadrant, not the verdict above: that one needs more than 40%.

Criticized challengerCriticized default
Negative label rate →
01
S02
03
04
C05
06
07
08
B09
10
Accepted challengerEndorsed leader
0%First-choice share → · lines at 30% share and 25% negative50%
Key
01Semgrep36%
02SonarQube22%
03Snyk Code14%
04Snyk8%
05CodeQL4%
06GitHub Advanced Security2%
07Veracode Static Analysis2%
08Checkmarx One2%
09Bandit0%
10OpenText Fortify0%

What they warned about

Three of fourteen models held their first choice under the paraphrase. Claude Haiku 4.5, GPT-5.4 mini, Gemini 3.5 Flash, Perplexity Sonar, Grok 4.1 Fast, Mistral Small, Llama 4 Maverick, Qwen 3.7 Flash, Kimi K2, MiniMax M2.5 and Muse Glimmer 30B changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
Checkmarx One
45%
20 of 44 labels negative · 10 of 14 models · 1 hard negative
“What I'd Avoid for Mid-Market: Checkmarx and Veracode are powerful but typically start at $60K–$100K+/year” Kimi K2, paraphrase prompt
SonarQube
18%
11 of 62 labels negative · 9 of 14 models · 1 hard negative
“Noisiest out-of-box (40-60%+ FPs on Java/TS; OWASP F1-score ~27% in some evals)... avoid for security-only if you can't invest in config” Grok 4.1 Fast, negative prompt
Veracode Static Analysis
28%
11 of 39 labels negative · 6 of 14 models · 1 hard negative
“What I'd Avoid for Mid-Market: Checkmarx and Veracode are powerful but typically start at $60K–$100K+/year” Kimi K2, paraphrase prompt
OpenText Fortify
36%
9 of 25 labels negative · 6 of 14 models
“Fortify is described as heavyweight \u2013 requiring dedicated infrastructure and a team to manage scans and triage.” Muse Glimmer 30B, negative prompt

What they cite

Citations exist only for the models that return a source list: fourteen of the fourteen in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

75 of 84 answers in this category came back with a source list, from 14 of 14 models: citations where the model returns them, or the search results it consulted. 955 links across 194 sites, every framing counted. Ranked by the number of answers carrying the site or page. 16 of the 252 answers across every segment cited this index's own page for the category; the method page measures whether that reading tilts an answer.

vendor site · Checkmarx42 answers · 55 citations · 12 models
40 answers · 79 citations · 12 models
vendor site · Safeguard28 answers · 29 citations · 10 models
27 answers · 32 citations · 12 models
vendor site · Aikido25 answers · 32 citations · 10 models
vendor site · ZeroPath22 answers · 23 citations · 9 models
vendor site · Opsera21 answers · 21 citations · 11 models
vendor site · Augment Code20 answers · 23 citations · 8 models
vendor site · Corgea19 answers · 20 citations · 7 models
vendor site · OX18 answers · 22 citations · 10 models
vendor site · OWASP18 answers · 21 citations · 10 models
vendor site · Cycode18 answers · 21 citations · 10 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

Search against answers

Each company's standing in the answers beside its site's footprint in Google search, one row a site: the products the models named on it with their shares, and the share they add up to; monthly searches on Google, and DataForSEO's estimate of AI search demand (modeled from search signals, directional, not a count of queries to any assistant), for the most-searched of the company's and its products' names (the name is in each row's hover text); estimated monthly organic visits to the site; and its best position in Google's top ten for “best sast tool”, “sast tool”, “sast tools”. US estimates from DataForSEO and Google's Ads Transparency Center. A small company's site, or a mid-sized company's site for its flagship, is marked company; a product on a large parent's site (Google, Microsoft) has no site figures. A column with no figures for this category is left out, and an empty cell means none were seen, not none exist. Two measurements side by side: neither is read as the cause of the other.
Company and productsShareOwn site citedName searches, GoogleAI search demand, est.Organic visitsPaid search a month, est.Google ads, last 30 days
Semgrep semgrep.dev36%1948,1001913,46143
Snyk snyk.io
Snyk Code 14%, Snyk 8%
22%14312,10058161,651 company60
SonarQube22%14,8001,353
CodeQL4%2,90081
GitHub parent site
GitHub Advanced Security 2%
2%1111,500,00031,479
Veracode Static Analysis veracode.com2%12540212,54317
Aikido aikido.dev
Aikido Security 2%
2%3422,400516,442 company$936120
DeepSource deepsource.com2%1632037,8470
Semgrep Community/OSS2%
Semgrep's free tier2%

Google's top ten for the three searches hold 24 sites; 4 of them are among the sites the models cited here (checkmarx.com, community.owasp.org, safeguard.sh, zeropath.com). The first result for “best sast tool” is reddit.com.

How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ShowHide
ModelDirect“What is the best SAST tool for a mid-market B2B company?”Paraphrase“Which static code security scanner would you recommend to a mid-sized B2B company?”Comparative“What are the top SAST tools and how do they differ?”Budget-constrained“What is the best SAST tool for a company with a limited budget?”Scale-constrained“We are a 500 person company evaluating a SAST tool. What should we look at?”Negative“Which SAST tools should I avoid or be cautious about?”
Claude Haiku 4.5no first choiceSnyk, SonarQubeChangedno first choiceSemgrep
Two alternativesQodana, SonarQube
no first choiceagainst: Checkmarx One, Semgrep, Snyk, SonarQube, Veracode Static Analysis
GPT-5.4 miniSemgrep
Three alternativesCheckmarx One, Snyk Code, Veracode Static Analysis
CodeQL, Snyk CodeChanged
One alternativeSonarQube
no first choice
Seven alternativesBlack Duck Coverity, Checkmarx One SAST, CodeQL, GitHub Advanced Security, OpenText Fortify, Semgrep, Veracode Static Analysis
against: SonarQube
Semgrep Community/OSS
Two alternativesCodeQL via GitHub code scanning / GitHub Advanced Security, SonarQube
no first choicenothing named
Gemini 3.5 FlashAikido Security
Four alternativesGitHub Advanced Security, GitLab SAST, Semgrep, Snyk Code
against: OpenText Fortify, Veracode Static Analysis
SnykChanged
Three alternativesGitLab SAST, Semgrep, SonarQube
against: GitHub Advanced Security
Semgrep, Snyk Code
Five alternativesBlack Duck, Checkmarx One, GitHub Advanced Security, SonarQube, Veracode Static Analysis
Semgrep
Three alternativesAikido Security, Snyk Code, SonarQube
against: CodeQL
no first choiceagainst: Checkmarx One, CodeQL, OpenText Fortify, Veracode Static Analysis
Perplexity SonarSemgrep
Two alternativesCheckmarx One, Snyk Code
SonarQubeChanged
Three alternativesCheckmarx One, OpenText Fortify, Veracode Static Analysis
no first choiceSonarQube
Two alternativesCodeQL, Semgrep
no first choicenothing named
Grok 4.1 FastSnyk Code
Two alternativesSemgrep, SonarQube
against: Checkmarx One
SonarQubeChanged
Two alternativesGitHub Advanced Security, Snyk Code
against: Checkmarx One, Veracode Static Analysis
Checkmarx One
Six alternativesBlack Duck, CodeQL, OpenText Fortify, Semgrep, Snyk Code, Veracode Static Analysis
against: SonarQube
Semgrep
Two alternativesCodeQL, SonarQube
no first choice
Five alternativesCheckmarx One, Semgrep, Snyk Code, SonarQube, Veracode Static Analysis
against: Checkmarx One, Flawfinder, HP Fortify, Insider, SonarQube, Veracode Static Analysis
Mistral SmallSnyk
Two alternativesAikido Security, Semgrep
SemgrepChanged
One alternativeSonarQube
against: Checkmarx One
no first choiceCodeQL
Two alternativesSemgrep, SonarQube
no first choiceagainst: Checkmarx One, OpenText Fortifyagainst: SonarQube
DeepSeek V4 FlashSnyk Code
Three alternativesCodeAnt.ai, Semgrep, SonarQube
against: Checkmarx One
Snyk CodeHeld
Three alternativesCodeQL, Semgrep, SonarQube
against: Checkmarx One, Veracode Static Analysis
Semgrep, Snyk Code
Six alternativesBlack Duck Coverity, CodeQL, OpenText Fortify, Perforce Klocwork, SonarQube, Veracode Static Analysis
against: Checkmarx One
Semgrep
Three alternativesCodeQL, Snyk Code, SonarQube
no first choiceagainst: CodeChecker, CodeQT, Contrast, CppChecker, Flawfinder, Graudit, Insider, JLint, Lapse+, PumaScan, RIPS, SonarQube, SpotBugs
Llama 4 MaverickSnyk CodeCheckmarx One, Veracode Static AnalysisChangedno first choiceDeepSource, Semgrep's free tier, Snyk Code's Team plan, SonarQubeno first choicenothing named
Qwen 3.7 FlashSonarQube
Two alternativesSemgrep, Snyk Code
Semgrep, SonarQubeChanged
One alternativeVeracode Static Analysis
against: Checkmarx One
Checkmarx One, Snyk Code
Three alternativesGitHub Advanced Security, OpenText Fortify, Veracode Static Analysis
against: SonarQube
Semgrep
Two alternativesCodeQL, SonarQube
against: OpenText Fortify
no first choiceagainst: Bandit, Checkmarx One, ESLint, OpenText Fortify, SonarQube, Veracode Static Analysis
Kimi K2Semgrep, Snyk Code
One alternativeSonarQube
against: Checkmarx One, Veracode Static Analysis
GitHub Advanced SecurityChanged
Two alternativesSemgrep, SonarQube
against: Checkmarx One, Veracode Static Analysis
Checkmarx One
Six alternativesCodeQL, OpenText Fortify, Semgrep, Snyk Code, SonarQube, Veracode Static Analysis
Semgrep
Five alternativesBandit, Brakeman, CodeQL, SonarQube, gosec
Semgrep
Three alternativesAikido Security, Snyk Code, ZeroPath
against: Checkmarx One, OpenText Fortify, Veracode Static Analysis
against: Checkmarx One, Horusec, OpenText Fortify, Reshift, TSLint, Veracode Static Analysis
GLM 4.7 FlashXSonarQube
Eight alternativesCheckmarx One, Codacy, DeepSource, GitHub Advanced Security, OpenText Fortify, Semgrep, Snyk Code, Veracode Static Analysis
SonarQubeHeld
Three alternativesCheckmarx One, DeepSource, Semgrep
no first choiceSemgrep
Five alternativesBandit, Brakeman, SonarQube, SpotBugs, gosec
against: Codacy
no first choiceagainst: Black Duck Coverity, Brakeman, Checkmarx One, Flawfinder, MobSF, NodeJS Analyzer, OpenText Fortify, Rational AppScan
MiniMax M2.5Snyk
Two alternativesSemgrep, Veracode Static Analysis
Snyk CodeChanged
Three alternativesCheckmarx One, SonarQube, Veracode Static Analysis
Semgrep
Four alternativesCheckmarx One, OpenText Fortify, Snyk Code, SonarQube
SonarQube
Six alternativesBandit, Brakeman, ESLint, GitHub Advanced Security, GitLab SAST, Snyk Code
against: Coverity Scan, FindBugs, PMD
no first choiceagainst: Checkmarx One, SonarQube
GPT-6 LunaSemgrep
Two alternativesGitHub Advanced Security, Snyk
SemgrepHeld
Two alternativesCodeQL, Snyk Code
Semgrep
Seven alternativesBlack Duck Coverity, Checkmarx One, CodeQL, OpenText Fortify SAST, Snyk Code, SonarQube, Veracode Static Analysis
Semgrep
Two alternativesCodeQL, SonarQube
no first choiceagainst: CodeQL, FindBugs, Semgrep, SonarQube
Muse Glimmer 30BSonarQube
One alternativeSemgrep
against: Snyk Code
SemgrepChanged
Two alternativesSnyk Code, SonarQube
against: Checkmarx One
no first choice
Eight alternativesBlack Duck Coverity, Checkmarx One, GitHub Advanced Security, OpenText Fortify, Semgrep, Snyk Code, SonarQube, Veracode Static Analysis
Semgrep
Three alternativesBandit, CodeQL, SonarQube
no first choiceagainst: Bandit, Checkmarx One, OpenText Fortify, Semgrep, SonarQube
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Eighty-four rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 09:09no04 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 08:01yes36 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-10-01 10:39yes1628 s
Direct recommendationPerplexity Sonarsonar2026-10-01 07:56yes183 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 09:06yes207 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-10-01 11:52yes52 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 11:39yes1925 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 13:39yes52 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 09:20yes1034 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-10-01 09:32yes1725 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 10:56yes1758 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 13:43yes517 s
Direct recommendationGPT-6 Lunagpt-6-luna2026-10-01 12:07yes312 s
Direct recommendationMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 12:53yes1426 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 08:29no05 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 12:04yes37 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-10-01 09:12yes1424 s
ParaphrasePerplexity Sonarsonar2026-10-01 08:53yes172 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 09:58yes217 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-10-01 07:52yes105 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 13:32yes2431 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 12:04yes52 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 08:46no039 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-10-01 12:31yes1830 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 08:48yes2273 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 11:32yes514 s
ParaphraseGPT-6 Lunagpt-6-luna2026-10-01 08:00yes318 s
ParaphraseMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 10:56yes1521 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 07:49yes109 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 09:33yes37 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-10-01 10:34yes1528 s
ComparativePerplexity Sonarsonar2026-10-01 08:56yes265 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 11:57yes238 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-10-01 10:36yes99 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 13:04yes2433 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 11:26yes51 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 12:43yes919 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-10-01 09:00yes1225 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 09:53yes1033 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 08:48yes1324 s
ComparativeGPT-6 Lunagpt-6-luna2026-10-01 08:11yes928 s
ComparativeMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 10:53yes1542 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 13:47yes98 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 12:41yes25 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-01 13:33yes1422 s
Budget constrainedPerplexity Sonarsonar2026-10-01 09:20yes195 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 12:39yes187 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-10-01 10:00yes53 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 12:43yes1628 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 13:09yes52 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 13:43yes524 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-01 07:40yes917 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 09:09yes1329 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 09:36no048 s
Budget constrainedGPT-6 Lunagpt-6-luna2026-10-01 11:14yes211 s
Budget constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 13:09yes1219 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 12:26no06 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 11:32no09 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-01 13:40yes1322 s
Scale constrainedPerplexity Sonarsonar2026-10-01 08:11yes206 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 11:39yes137 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-10-01 08:33no010 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 12:31yes2054 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 09:39yes52 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 08:27no027 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-01 12:27yes2227 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 12:16yes1453 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 12:35no09 s
Scale constrainedGPT-6 Lunagpt-6-luna2026-10-01 11:34yes317 s
Scale constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 08:06yes1321 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 13:07yes1711 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 12:34yes45 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-10-01 13:51yes2025 s
Negative framingPerplexity Sonarsonar2026-10-01 10:28yes184 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 09:20yes208 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-10-01 13:15yes54 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 10:44yes2428 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 11:06yes51 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 11:33yes737 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-10-01 11:25yes2330 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 10:17yes2563 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 12:49yes1429 s
Negative framingGPT-6 Lunagpt-6-luna2026-10-01 10:29yes521 s
Negative framingMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 07:52yes2451 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

ShowHide
Category-scoped readings
Aikido read as Aikido Security
Checkmarx read as Checkmarx One
Checkmarx (Checkmarx One) read as Checkmarx One
GitHub Advanced Security / CodeQL read as GitHub Advanced Security
GitHub Code Security / CodeQL read as GitHub Advanced Security
GitLab read as GitLab SAST
GitLab Ultimate read as GitLab SAST
Veracode read as Veracode Static Analysis
Unresolved, counted raw
Checkmarx One SAST
CodeAnt.ai
CodeChecker
CodeQL via GitHub code scanning / GitHub Advanced Security
CodeQT
Coverity Scan
CppChecker
Find Security Bugs
Graudit
HP Fortify
Infer
Intrigue Core
JLint
Lapse+
NodeJS Analyzer
OpenText Fortify SAST
PumaScan
Rational AppScan (IBM)
Reshift
Semgrep Community/OSS
Semgrep's free tier
Snyk Code's Team plan
TSLint
Discontinued, still offered
No shut-down product was recommended here.
← Source controlAI governance →