| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Vulnerability management platforms | Security operations | 9% | 4 of 80 | 24% | 21 | accepted challenger |
| Penetration testing as a service | Security operations | 0% | 65 of 76 | 20% | 5 | under 10 labels · led by Cobalt at 44% |
| Attack surface management | Security operations | 0% | 29 of 104 | 0% | 3 | under 10 labels · led by Intruder at 59% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 1 | 0 | 0 | 1 |
| GPT-5.4 mini | 0 | 1 | 0 | 0 | 1 |
| Gemini 3.5 Flash | 0 | 1 | 2 | 0 | 3 |
| Perplexity Sonar | 0 | 1 | 2 | 1 | 4 |
| Grok 4.1 Fast | 1 | 2 | 0 | 0 | 3 |
| Mistral Small | 0 | 0 | 0 | 0 | 0 |
| DeepSeek V4 Flash | 0 | 1 | 1 | 1 | 3 |
| Llama 4 Maverick | 0 | 0 | 0 | 0 | 0 |
| Qwen 3.7 Flash | 0 | 1 | 0 | 2 | 3 |
| Kimi K2 | 1 | 0 | 1 | 0 | 2 |
| GLM 4.7 FlashX | 1 | 0 | 4 | 0 | 5 |
| MiniMax M2.5 | 1 | 0 | 1 | 2 | 4 |
Verbatim evidence the judge attached to positive labels.
“the best vulnerability management platform is OpenVAS (Greenbone Community Edition), a free, open-source solution” Grok 4.1 Fast · Vuln management · budget prompt · first choice
“I'd recommend starting with Greenbone Community Edition if you have technical resources” MiniMax M2.5 · Vuln management · budget prompt · first choice
“For absolute minimal cost: Greenbone Community Edition (OpenVAS) or OWASP ZAP” GLM 4.7 FlashX · Vuln management · budget prompt · first choice
“Very limited budget ($0) | Greenbone Community Edition + Wazuh” Kimi K2 · Vuln management · budget prompt · first choice
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“simply run a tool like Nessus or OpenVAS and hand you a PDF report. This is called Vulnerability Scanning, not Penetration Testing.” Qwen 3.7 Flash · PTaaS · budget prompt · hard negative
“Repeatedly criticized for heavy false positives... Good as a free baseline, but not for production accuracy.” DeepSeek V4 Flash · Vuln management · negative prompt · soft negative
“High Technical Barrier. ... Not recommended for generalist IT admins; intended for security engineers.” Qwen 3.7 Flash · Vuln management · budget prompt · soft negative
“Greenbone/OpenVAS is described as requiring more maintenance and not providing a full remediation workflow” Perplexity Sonar · Vuln management · negative prompt · soft negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 51 of the 68 answers that named OpenVAS and are not a share of its labels.
220 of the 220 domain citations in answers naming OpenVAS came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when OpenVAS's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as OpenVAS, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at openvas.org is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.