| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Static application security testing | Developer platform | 2% | 6 of 47 | 8% | 26 | accepted challenger |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 0 | 1 | 0 | 1 |
| GPT-5.4 mini | 1 | 1 | 1 | 0 | 3 |
| Gemini 3.5 Flash | 0 | 1 | 0 | 0 | 1 |
| Perplexity Sonar | 0 | 1 | 0 | 1 | 2 |
| Grok 4.1 Fast | 1 | 2 | 1 | 0 | 4 |
| Mistral Small | 0 | 1 | 1 | 0 | 2 |
| DeepSeek V4 Flash | 0 | 3 | 1 | 1 | 5 |
| Llama 4 Maverick | 0 | 0 | 1 | 0 | 1 |
| Qwen 3.7 Flash | 0 | 0 | 0 | 0 | 0 |
| Kimi K2 | 1 | 2 | 0 | 0 | 3 |
| GLM 4.7 FlashX | 0 | 2 | 0 | 0 | 2 |
| MiniMax M2.5 | 0 | 2 | 0 | 0 | 2 |
Verbatim evidence the judge attached to positive labels.
“Look for modern alternatives - Tools with semantic analysis (like CodeQL) show lower false positive rates” Kimi K2 · SAST · negative prompt · first choice
“the best default choice is usually GitHub CodeQL if your code is already on GitHub” GPT-5.4 mini · SAST · budget prompt · first choice
“Prioritize reachability/taint analysis (CodeQL, Veracode <1-10% FP tuned)” Grok 4.1 Fast · SAST · negative prompt · first choice
“Powerful semantic analysis, backed by GitHub/Microsoft... Best for: Teams already using GitHub” Kimi K2 · SAST · budget prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“CodeQL is powerful, but Checkmarx notes it requires expertise to write queries” Perplexity Sonar · SAST · negative prompt · soft negative
“no steep query-DSL learning curve like CodeQL” DeepSeek V4 Flash · SAST · budget prompt · soft negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 57 of the 63 answers that named CodeQL and are not a share of its labels.
273 of the 273 domain citations in answers naming CodeQL came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when CodeQL's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as CodeQL, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at codeql.com is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.