Four of twelve models named Semgrep first on the direct prompt; two named SonarQube. Both were named by all twelve models and Semgrep carries 56 labels and SonarQube 48, so the shares are not directly comparable.
Named in three categories this edition.
Named in two categories this edition.
Share is the count of first choices across the direct, paraphrase, budget and scale prompts over all twelve models, for a mid-market B2B company; rank is within the category; every quote names the model and the prompt it came from. Both figures come from the static application security testing page.
Bold names in an answer are the products the judge labeled a first choice; a model naming several gives each of them that label. The full answer text for every row is in the record.
Every negative label with a quote, up to three, then the highest-weighted positives, up to three. Three of four in this category shown.
“For Developer-First Speed & Flexibility: Semgrep Code or Snyk Code. They are incredibly fast, have great PR integration, and are built around developer workflows.” Gemini 3.5 Flash · scale prompt · first choice
“The best SAST tool for a company with a limited budget is Semgrep CE, which is a free SAST scanner that supports 30+ languages” Llama 4 Maverick · budget prompt · first choice
“I recommend Semgrep (specifically the Semgrep AppSec Platform) as your primary static code security scanner.” GLM 4.7 FlashX · paraphrase prompt · first choice
Every negative label with a quote, up to three, then the highest-weighted positives, up to three. Six of seven in this category shown.
“SonarQube: High false positive rates out-of-the-box (40-82% ...) ... Tune heavily or pair with security-specific tools.” Grok 4.1 Fast · negative prompt · soft negative
“SonarQube on default settings flags 40‑60 % of findings as non‑issues on typical Java or TypeScript codebases” GLM 4.7 FlashX · negative prompt · soft negative
“Mature platform, 40+ languages, strong for governance — but noisier out of the box and requires tuning.” DeepSeek V4 Flash · paraphrase prompt · soft negative
“Choose SonarQube if you treat security as a subset of quality, need to reduce technical debt, and want better control over costs at scale.” Qwen 3.7 Flash · direct prompt · first choice
“Widely used, supports multiple languages, integrates well with CI/CD... making it a solid choice for mid-sized teams” Mistral Small · paraphrase prompt · first choice
“SonarQube or Snyk Code would be the best starting points. SonarQube offers the best overall value” MiniMax M2.5 · direct prompt · first choice
Comparisons are drawn for the top three products in each category. The output is the models' output; nothing here is a recommendation by the index.