# Static application security testing: what AI models recommend, September 2026

IT AI Recommendation Index, September 2026 Edition. Asked as "SAST tool" and as "static code security scanner", six framings each, to twelve models with search on, on behalf of a mid-market B2B company. Page: https://it-ai-index.com/developer/static-application-security-testing/

**Standing:** Semgrep leads with 47% of first choices; verdict clear leader. 45 first choices across the direct, paraphrase, budget and scale prompts.

## First-choice share

| # | Product | Share | Negative rate | Labels |
|---|---|---|---|---|
| 1 | Semgrep | 47% | 0% | 56 |
| 2 | SonarQube | 22% | 10% | 48 |
| 3 | Snyk Code | 13% | 6% | 36 |
| 4 | Aikido Security | 4% | 0% | 16 |
| 5 | CodeQL | 2% | 8% | 26 |
| 6 | Veracode | 2% | 41% | 34 |
| 7 | GitHub Advanced Security | 0% | 8% | 12 |
| 8 | gosec | 0% | 0% | 10 |
| 9 | Bandit | 0% | 18% | 11 |
| 10 | Checkmarx One | 0% | 48% | 46 |
| 11 | OpenText Fortify | 0% | 52% | 23 |

## Each model's first choice on the direct prompt

- Claude Haiku 4.5: no first choice
- GPT-5.4 mini: Snyk Code; alternatives Checkmarx One, GitHub Advanced Security / CodeQL, Veracode
- Gemini 3.5 Flash: Aikido Security; alternatives GitHub Advanced Security, GitLab SAST, Semgrep, Snyk
- Perplexity Sonar: CodeAnt AI; alternatives Aikido Security, Semgrep
- Grok 4.1 Fast: Semgrep; alternatives Snyk Code, SonarQube
- Mistral Small: Semgrep; alternatives CodeAnt AI, SonarQube
- DeepSeek V4 Flash: Semgrep; alternatives Checkmarx One, GitHub Advanced Security, Snyk Code, SonarQube
- Llama 4 Maverick: Snyk Code; alternatives SonarQube
- Qwen 3.7 Flash: Snyk, SonarQube; alternatives GitHub Advanced Security, GitLab SAST
- Kimi K2: Semgrep, Snyk Code; alternatives SonarQube
- GLM 4.7 FlashX: Snyk Code; alternatives CodeAnt AI, Semgrep, SonarQube
- MiniMax M2.5: Snyk Code, SonarQube; alternatives Checkmarx One, Semgrep

## Sources the answers cite

63 of 72 answers came back with a source list, from 12 of 12 models. Sites named in the most answers:

- appsecsanta.com: 32 answers, 43 citations
- corgea.com: 31 answers, 34 citations
- zeropath.com: 30 answers, 30 citations
- dev.to: 27 answers, 44 citations
- ox.security: 21 answers, 22 citations
- augmentcode.com: 20 answers, 23 citations
- pixee.ai: 20 answers, 21 citations
- endorlabs.com: 19 answers, 26 citations

Pages named in the most answers:

- https://zeropath.com/blog/best-sast-tools (30 answers)
- https://corgea.com/learn/best-sast-tools (28 answers)
- https://appsecsanta.com/sast-tools (24 answers)
- https://dev.to/rahulxsingh/i-reviewed-32-sast-tools-the-ones-worth-using-283e (22 answers)
- https://ox.security/blog/static-application-security-sast-tools (21 answers)
- https://endorlabs.com/learn/best-sast-tools (17 answers)
- https://pixee.ai/blog/best-sast-tools-2026 (16 answers)
- https://dev.to/rahulxsingh/11-best-sast-tools-in-2026-static-application-security-testing-compared-4ajo (13 answers)
- https://augmentcode.com/tools/enterprise-sast-tools-large-teams-field-guide (12 answers)
- https://checkmarx.com/learn/sast/open-source-vs-premium-sast-tools (12 answers)

## Warned against

- Checkmarx One: 22 of 46 labels negative. "Tools to Avoid on a Tight Budget ... Checkmarx One / Fortify / Vercode: These are enterprise-grade tools" (Qwen 3.7 Flash, budget prompt)
- Veracode: 14 of 34 labels negative. "Avoid legacy, binary-upload scanners... historically pioneered by tools like Veracode)... a major friction point for modern, fast-paced DevSecOps teams." (Gemini 3.5 Flash, negative prompt)
- OpenText Fortify: 12 of 23 labels negative. "High-cost, legacy platforms (like OpenText Fortify or older on-premise setups of Checkmarx)... Avoid legacy, binary-upload scanners and heavyweight on-premise engines." (Gemini 3.5 Flash, negative prompt)
- SonarQube: 5 of 48 labels negative. "SonarQube: High false positive rates out-of-the-box (40-82% ...) ... Tune heavily or pair with security-specific tools." (Grok 4.1 Fast, negative prompt)

## Record

- Method: https://it-ai-index.com/methodology/
- Raw judge labels and full responses: https://it-ai-index.com/data/
- License: CC BY 4.0. Cite as IT AI Recommendation Index, September 2026 Edition, it-ai-index.com.
