AI Indexes
IT AI Index
October 2026 Edition · The permanent record of this edition. The unqualified address always carries the latest edition.
Index › Developer platform › SAST › Small business › October 2026 Edition

Static application security testing for small business buyers

Asked as “SAST tool”, and as “static code security scanner”, on behalf of a small B2B company. 57 first choices recorded across the direct, paraphrase, budget and scale prompts, fourteen models each.
Standing · first-choice share
53%
Clear leader
53Semgrep14SonarQube11Snyk Code23others

53% of first choices, clear leader.

Since September 2026▼−20Since September 2026: 70% → 50%, −20 points. Past the 11-point floor: movement. Read over the models both editions asked.Semgrep held the lead, −20 points on 70%, past the floor.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all fourteen models, for a small B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrantSince September 2026
01Semgrep53%0%70endorsed leader▼−20Since September 2026: 70% → 50%, −20 points. Past the 11-point floor: movement. Read over the models both editions asked.70% → 50%
02SonarQube14%11%70accepted challenger▲+10Since September 2026: 2% → 12%, +10 points. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 12%
03Snyk Code11%2%44accepted challenger▲+4Since September 2026: 9% → 12%, +4 points. Inside the 11-point floor: within noise. Read over the models both editions asked.9% → 12%
04Snyk9%0%15accepted challenger▲+6Since September 2026: 4% → 10%, +6 points. Inside the 11-point floor: within noise. Read over the models both editions asked.4% → 10%
05Aikido Security5%4%24accepted challenger▼−2Since September 2026: 9% → 6%, −2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.9% → 6%
06GitHub Advanced Security2%5%20accepted challenger=heldSince September 2026: 2% → 2%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 2%
07CodeAnt AI2%8%12accepted challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
Show the six products at 0%, ordered by negative rate
11OpenText Fortify0%94%17criticized challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
12Veracode Static Analysis0%86%35criticized challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
13Checkmarx One0%80%41criticized challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
08CodeQL0%19%26accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
10Bandit0%8%12accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
09DeepSource0%0%10accepted challenger▼−2Since September 2026: 2% → 0%, −2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 0%

The floor is 11 points of share, measured: how far the models move a leader on their own when the same questions are asked twice with nothing changed. A larger change is movement; a smaller one is noise, and both are shown. Movement is read over the twelve models both editions asked; GPT-6 Luna, Muse Glimmer 30B joined this edition and are in the standing but not yet in the comparison. How the floor is measured

Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its product page.
All twenty-eight head-to-head pages: the top eight products, each against each

Recommended versus criticized

Every product with at least 10 labels here, on both axes. The 30% line names a quadrant, not the verdict above: that one needs more than 40%.

Criticized challengerCriticized default
Negative label rate →
01
S02
03
04
05
06
07
C08
09
B10
11
12
13
Accepted challengerEndorsed leader
0%First-choice share → · lines at 30% share and 25% negative70%
Key
01Semgrep53%
02SonarQube14%
03Snyk Code11%
04Snyk9%
05Aikido Security5%
06GitHub Advanced Security2%
07CodeAnt AI2%
08CodeQL0%
09DeepSource0%
10Bandit0%
11OpenText Fortify0%
12Veracode Static Analysis0%
13Checkmarx One0%

What they warned about

Three of fourteen models held their first choice under the paraphrase. Claude Haiku 4.5, Gemini 3.5 Flash, Perplexity Sonar, Grok 4.1 Fast, Mistral Small, Llama 4 Maverick, Qwen 3.7 Flash, Kimi K2, GLM 4.7 FlashX, MiniMax M2.5 and Muse Glimmer 30B changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
Checkmarx One
80%
33 of 41 labels negative · 13 of 14 models · 19 hard negative
“the clearest “avoid or be cautious” signals point to **Checkmarx**... described as expensive, complex to implement, and often too heavy for small teams” Perplexity Sonar, negative prompt
Veracode Static Analysis
86%
30 of 35 labels negative · 13 of 14 models · 17 hard negative
“Typically sold via long sales cycles and annual contracts, with complex workflows and no transparent pricing. Not ideal for small teams” Mistral Small, negative prompt
OpenText Fortify
94%
16 of 17 labels negative · 11 of 14 models · 12 hard negative
“**Enterprise suites** (Checkmarx, Veracode, Fortify) – typically require $40K+ annual contracts and dedicated security staff” Kimi K2, scale prompt
Black Duck Coverity
100%
7 of 7 labels negative · 7 of 14 models · 5 hard negative
“"Usually no. Checkmarx One, Veracode, Coverity, and Fortify are priced and built for organizations with dedicated security teams"” Muse Glimmer 30B, negative prompt

What they cite

Citations exist only for the models that return a source list: fourteen of the fourteen in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

73 of 84 answers in this category came back with a source list, from 14 of 14 models: citations where the model returns them, or the search results it consulted. 947 links across 158 sites, every framing counted. Ranked by the number of answers carrying the site or page. 16 of the 252 answers across every segment cited this index's own page for the category; the method page measures whether that reading tilts an answer.

51 answers · 98 citations · 12 models
39 answers · 48 citations · 11 models
vendor site · Checkmarx36 answers · 47 citations · 12 models
27 answers · 37 citations · 12 models
vendor site · Safeguard26 answers · 31 citations · 9 models
vendor site · Aikido24 answers · 34 citations · 11 models
vendor site · G223 answers · 28 citations · 11 models
vendor site · Jit19 answers · 19 citations · 9 models
vendor site · Opsera17 answers · 17 citations · 8 models
16 answers · 17 citations · 8 models
vendor site · OX16 answers · 16 citations · 8 models
vendor site · Corgea15 answers · 19 citations · 8 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

Search against answers

Each company's standing in the answers beside its site's footprint in Google search, one row a site: the products the models named on it with their shares, and the share they add up to; monthly searches on Google, and DataForSEO's estimate of AI search demand (modeled from search signals, directional, not a count of queries to any assistant), for the most-searched of the company's and its products' names (the name is in each row's hover text); estimated monthly organic visits to the site; and its best position in Google's top ten for “best sast tool”, “sast tool”, “sast tools”. US estimates from DataForSEO and Google's Ads Transparency Center. A small company's site, or a mid-sized company's site for its flagship, is marked company; a product on a large parent's site (Google, Microsoft) has no site figures. A column with no figures for this category is left out, and an empty cell means none were seen, not none exist. Two measurements side by side: neither is read as the cause of the other.
Company and productsShareOwn site citedName searches, GoogleAI search demand, est.Organic visitsPaid search a month, est.Google ads, last 30 days
Semgrep semgrep.dev53%1948,1001913,46143
Snyk snyk.io
Snyk Code 11%, Snyk 9%
19%14312,10058161,651 company60
SonarQube14%14,8001,353
Aikido aikido.dev
Aikido Security 5%
5%3422,400516,442 company$936120
GitHub parent site
GitHub Advanced Security 2%
2%1111,500,00031,479
CodeAnt AI codeant.ai2%1426092,282$47256
Codiga codiga.io2%7
GitHub Code Scanning with CodeQL2%
Semgrep's free AppSec Platform tier2%
CodeQL0%2,90081

Google's top ten for the three searches hold 24 sites; 2 of them are among the sites the models cited here (checkmarx.com, safeguard.sh). The first result for “best sast tool” is reddit.com.

How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ShowHide
ModelDirect“What is the best SAST tool for a small B2B company?”Paraphrase“Which static code security scanner would you recommend to a small business that sells to other businesses?”Comparative“What are the top SAST tools for a small team and how do they differ?”Budget-constrained“What is the best SAST tool for a small company with a tight budget?”Scale-constrained“We are a 30 person company evaluating a SAST tool. What should we look at?”Negative“Which SAST tools should a small business avoid or be cautious about?”
Claude Haiku 4.5no first choiceagainst: Checkmarx OneSnyk, SonarQubeChangedSemgrep, SonarQube
Two alternativesAikido Security, Snyk Code
Semgrep, SonarQube
Two alternativesOWASP Dependency-Check, Snyk
no first choiceagainst: Black Duck Coverity, Checkmarx One, CodeQL, Mend SAST, SonarQube, Veracode Static Analysis
GPT-5.4 miniSemgrep
Two alternativesGitHub Advanced Security, SonarQube
SemgrepHeld
Two alternativesSnyk Code, SonarQube
against: Checkmarx One, OpenText Fortify, Veracode Static Analysis
Semgrep
Three alternativesGitHub Advanced Security, GitLab SAST, SonarQube
against: Checkmarx One, Veracode Static Analysis
GitHub Code Scanning with CodeQL, SonarQube
One alternativeSemgrep Community / free tier
no first choicenothing named
Gemini 3.5 FlashAikido Security
Three alternativesSemgrep, Snyk, Snyk Code
against: Checkmarx One, Veracode Static Analysis
Aikido Security, Snyk CodeChanged
One alternativeSemgrep
against: Checkmarx One, OpenText Fortify, Veracode Static Analysis
Aikido Security, Semgrep
Three alternativesGitHub Advanced Security, Snyk Code, SonarQube
Semgrep
Three alternativesAikido Security, GitLab SAST, SonarQube
against: CodeQL
Semgrep
Three alternativesGitLab SAST, Snyk, SonarQube
against: GitHub Advanced Security
against: Black Duck Coverity, Checkmarx One, OpenText Fortify, SonarQube, Veracode Static Analysis
Perplexity SonarAikido Security
Two alternativesCodeQL, Semgrep
SemgrepChanged
One alternativeSonarQube
against: Checkmarx One, OpenText Fortify, Veracode Static Analysis
Semgrep
Four alternativesAikido Security, GitHub Advanced Security, Snyk Code, SonarQube
Semgrep
One alternativeSonarQube
against: CodeAnt AI
no first choiceagainst: Checkmarx One, traditional Fortify configurations
Grok 4.1 FastSemgrep
Two alternativesSnyk Code, SonarQube
against: Checkmarx One, Veracode Static Analysis
SnykChanged
Three alternativesCodeQL, Semgrep, SonarQube
against: Checkmarx One, Veracode Static Analysis
Semgrep, Snyk Code
Two alternativesAikido Security, SonarQube
Semgrep
Two alternativesCodeQL, SonarQube
Snyk Code
Three alternativesCodeQL, Semgrep, SonarQube
against: Black Duck Coverity, Checkmarx One, Micro Focus, OpenText Fortify, Veracode Static Analysis
Mistral SmallGitHub Advanced Security, Snyk Code
Two alternativesCheckmarx One, SonarQube
SnykChanged
Two alternativesSemgrep, SonarQube
Semgrep
Three alternativesCodiga, Qodana, Snyk Code
Semgrep
Four alternativesBandit, Brakeman, CodeQL, SonarQube
no first choiceagainst: Checkmarx One, OpenText Fortify, SonarQube, Veracode Static Analysis
DeepSeek V4 FlashSemgrep
Three alternativesCodacy, Snyk Code, SonarQube
against: Checkmarx One, CodeQL, OpenText Fortify, Veracode Static Analysis
SemgrepHeld
One alternativeSnyk Code
against: Checkmarx One, OpenText Fortify, Veracode Static Analysis
Semgrep
Five alternativesAikido Security, Codacy, CodeQL, Snyk Code, SonarQube
Semgrep
Two alternativesCodeQL, Opengrep
against: SonarQube
Semgrep
Three alternativesCodeQL, Snyk Code, SonarQube
against: Checkmarx One, OpenText Fortify, Veracode Static Analysis
against: Bandit, Black Duck Coverity, Brakeman, Checkmarx One, ESLint, OpenText Fortify, Perforce Klocwork, SonarQube, Veracode Static Analysis
Llama 4 Maverickno first choiceSemgrepChanged
Three alternativesAikido Security, Snyk Code, SonarQube
no first choiceSemgrep
Two alternativesCodeAnt AI, CodeQL
no first choiceagainst: Checkmarx One, OpenText Fortify, Veracode Static Analysis
Qwen 3.7 FlashSonarQube
Three alternativesGitHub Advanced Security, Semgrep, Snyk
Snyk, SonarQubeChanged
One alternativeSemgrep
Semgrep
Three alternativesAikido Security, GitHub Advanced Security, SonarQube
Semgrep
Two alternativesGitLab SAST, SonarQube
against: Checkmarx One, Veracode Static Analysis
Semgrep
Two alternativesSnyk, SonarQube
against: Checkmarx One
against: Black Duck Coverity, Checkmarx One, SonarQube, Veracode Static Analysis
Kimi K2Semgrep, Snyk Code
Two alternativesAikido Security, SonarQube
Snyk CodeChanged
Three alternativesGitHub Advanced Security, Semgrep, SonarQube
Semgrep
Four alternativesCodacy, DeepSource, Snyk Code, SonarQube
against: Aikido Security
Semgrep
Five alternativesBandit, Brakeman, CodeQL, SonarQube, gosec
Semgrep, Snyk
Three alternativesDeepSource, GitHub Advanced Security, SonarQube
against: Checkmarx One, OpenText Fortify, Veracode Static Analysis
against: Checkmarx One, HCL AppScan, OpenText Fortify, Veracode Static Analysis
GLM 4.7 FlashXSemgrep
Three alternativesGitHub Advanced Security, Snyk Code, SonarQube
against: Checkmarx One, Veracode Static Analysis
SonarQubeChanged
Two alternativesSemgrep, Snyk Code
Semgrep, Snyk Code
Seven alternativesAikido Security, Bandit, Codacy, DeepSource, ESLint security plugins, SonarQube, gosec
against: Checkmarx One, Veracode Static Analysis
Semgrep
Five alternativesBandit, GitHub Advanced Security, GitLab SAST, SonarQube, gosec
against: Checkmarx One, Veracode Static Analysis
no first choiceagainst: Black Duck Coverity, Checkmarx One, Fluid Attacks, OpenText Fortify, SonarQube, Veracode Static Analysis
MiniMax M2.5CodeAnt AI, Codiga
Two alternativesAikido Security, Snyk Code
Snyk CodeChanged
One alternativeSonarQube
Semgrep, SonarQube
One alternativeSnyk Code
against: Checkmarx One, Veracode Static Analysis
Semgrep
Two alternativesDeepSource, SonarQube
no first choiceagainst: Checkmarx One, OpenText Fortify, Veracode Static Analysis
GPT-6 LunaSemgrep
Two alternativesCodeQL, Snyk
SemgrepHeld
One alternativeGitHub Advanced Security
CodeQL, Semgrep
Two alternativesSnyk Code, SonarQube
Semgrep's free AppSec Platform tier
One alternativeSemgrep
against: CodeQL
no first choiceagainst: CodeQL, Semgrep's paid platform, Snyk Code, SonarQube
Muse Glimmer 30BSemgrep, SonarQube
Three alternativesAikido Security, CodeAnt AI, Codiga
against: Checkmarx One, Veracode Static Analysis
SemgrepChanged
Two alternativesCodeQL, Snyk Code
against: Checkmarx One, Veracode Static Analysis
Semgrep
Five alternativesCodacy, CodeAnt AI, GitHub Advanced Security, Snyk Code, SonarQube
against: Checkmarx One
Semgrep
Two alternativesCodeQL, SonarQube
Semgrep, SonarQube
Four alternativesCodeQL, DeepSource, GitLab SAST, Snyk Code
against: OpenText Fortify, Veracode Static Analysis
against: Black Duck Coverity, Checkmarx One, OpenText Fortify Software Security Center / Fortify SCA, Veracode Static Analysis
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Eighty-four rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 08:28no04 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 12:53yes35 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-10-01 12:39yes1532 s
Direct recommendationPerplexity Sonarsonar2026-10-01 10:40yes183 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 10:15yes208 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-10-01 09:19yes54 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 12:46yes2140 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 09:54yes51 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 13:49no032 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-10-01 10:45yes1920 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 11:44yes24179 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 08:16yes1225 s
Direct recommendationGPT-6 Lunagpt-6-luna2026-10-01 12:48yes311 s
Direct recommendationMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 12:00yes1426 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 10:58no04 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 07:59no03 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-10-01 13:31yes1021 s
ParaphrasePerplexity Sonarsonar2026-10-01 12:14yes193 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 11:43yes236 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-10-01 10:39yes138 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 07:56yes2425 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 08:41yes51 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 09:54yes521 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-10-01 12:19yes1518 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 09:43yes2516 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 08:37yes520 s
ParaphraseGPT-6 Lunagpt-6-luna2026-10-01 10:23yes312 s
ParaphraseMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 08:05yes1418 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 11:20yes1510 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 07:57yes89 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-10-01 12:47yes2231 s
ComparativePerplexity Sonarsonar2026-10-01 11:29yes205 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 12:47yes2110 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-10-01 12:05yes68 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 10:09yes2144 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 13:00yes51 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 11:04yes1530 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-10-01 09:37yes1829 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 08:42yes2046 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 11:30yes1017 s
ComparativeGPT-6 Lunagpt-6-luna2026-10-01 11:02yes618 s
ComparativeMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 08:25yes1532 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 08:38no04 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 11:52yes25 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-01 11:25yes521 s
Budget constrainedPerplexity Sonarsonar2026-10-01 12:20yes182 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 08:53yes216 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-10-01 13:38yes54 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 10:36yes2230 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 13:17yes52 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 12:14yes1031 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-01 11:51yes915 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 10:21yes944 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 10:06yes1223 s
Budget constrainedGPT-6 Lunagpt-6-luna2026-10-01 11:58yes39 s
Budget constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 13:44yes1119 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 09:35no06 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 09:04no08 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-01 10:17no015 s
Scale constrainedPerplexity Sonarsonar2026-10-01 08:44yes194 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 12:06yes1510 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-10-01 08:54no05 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 09:54yes1848 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 09:56yes52 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 12:01no027 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-01 12:00yes1833 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 08:08yes1540 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 12:45no010 s
Scale constrainedGPT-6 Lunagpt-6-luna2026-10-01 08:59yes314 s
Scale constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 09:07yes1529 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 11:44yes108 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 11:06yes47 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-10-01 12:57yes1421 s
Negative framingPerplexity Sonarsonar2026-10-01 07:46yes243 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 12:32yes218 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-10-01 12:00yes54 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 08:17yes1867 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 13:45yes52 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 07:27yes1464 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-10-01 11:55yes2224 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 09:09yes1954 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 10:58yes518 s
Negative framingGPT-6 Lunagpt-6-luna2026-10-01 09:21yes420 s
Negative framingMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 12:04yes2034 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

ShowHide
Category-scoped readings
Aikido read as Aikido Security
Checkmarx read as Checkmarx One
Checkmarx (Checkmarx One) read as Checkmarx One
Checkmarx (CxSAST / Checkmarx One) read as Checkmarx One
GitHub Advanced Security / CodeQL read as GitHub Advanced Security
GitHub Code Security with CodeQL read as GitHub Advanced Security
GitHub Code Security/CodeQL read as GitHub Advanced Security
GitLab read as GitLab SAST
GitLab Ultimate read as GitLab SAST
Mend.io read as Mend SAST
Veracode read as Veracode Static Analysis
Veracode (enterprise plans) read as Veracode Static Analysis
Unresolved, counted raw
ESLint with typescript-eslint
Fluid Attacks
GitHub Code Scanning with CodeQL
GitLab Security
OpenText Fortify Software Security Center / Fortify SCA
Oso
PVS-Studio
Ruff
Semgrep Community / free tier
Semgrep's free AppSec Platform tier
Semgrep's paid platform
Snyk Code Team plan
Veracode SOSS
traditional Fortify configurations
Discontinued, still offered
No shut-down product was recommended here.
← Source controlAI governance →