| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Software composition analysis | Developer platform | 14% | 4 of 49 | 38% | 32 | criticized challenger |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 2 | 0 | 0 | 0 | 2 |
| GPT-5.4 mini | 1 | 1 | 0 | 0 | 2 |
| Gemini 3.5 Flash | 0 | 0 | 0 | 3 | 3 |
| Perplexity Sonar | 0 | 1 | 1 | 1 | 3 |
| Grok 4.1 Fast | 0 | 1 | 1 | 1 | 3 |
| Mistral Small | 1 | 0 | 0 | 0 | 1 |
| DeepSeek V4 Flash | 0 | 0 | 0 | 4 | 4 |
| Llama 4 Maverick | 0 | 1 | 1 | 0 | 2 |
| Qwen 3.7 Flash | 1 | 0 | 0 | 1 | 2 |
| Kimi K2 | 0 | 2 | 1 | 1 | 4 |
| GLM 4.7 FlashX | 1 | 2 | 0 | 1 | 4 |
| MiniMax M2.5 | 0 | 1 | 1 | 0 | 2 |
Verbatim evidence the judge attached to positive labels.
“Primary recommendation: OWASP Dependency‑Check for a mid‑size B2B company that needs a mature, free, self‑hosted SCA scanner” GLM 4.7 FlashX · SCA · paraphrase prompt · first choice
“OWASP Dependency-Check and ORT are excellent starting points because they're open-source with no licensing fees” Claude Haiku 4.5 · SCA · budget prompt · first choice
“I recommend OWASP Dependency-Check as a strong open source dependency vulnerability scanner” Mistral Small · SCA · paraphrase prompt · first choice
“Trivy and OWASP Dependency-Check are generally considered the best zero-cost options” Qwen 3.7 Flash · SCA · budget prompt · first choice
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“You should actively avoid using the traditional OWASP Dependency-Check” Qwen 3.7 Flash · SCA · paraphrase prompt · hard negative
“Why you should avoid OWASP Dependency-Check (for now)” Gemini 3.5 Flash · SCA · paraphrase prompt · hard negative
“OWASP Dependency-Check for large or compliance-heavy environments, because it is positioned as a basic scanner and may not provide the advanced features some teams need” Perplexity Sonar · SCA · negative prompt · soft negative
“praised for Java/NVD, but consistently ranked behind newer tools on breadth, accuracy, and false‑positive rates across other languages” GLM 4.7 FlashX · SCA · negative prompt · soft negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 75 of the 83 answers that named OWASP Dependency-Check and are not a share of its labels.
347 of the 347 domain citations in answers naming OWASP Dependency-Check came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when OWASP Dependency-Check's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as OWASP Dependency-Check, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at owasp.org is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.