IT AI Index
Index Vendors › OWASP Dependency-Check · September 2026 Edition
1 category · Ranked

OWASP Dependency-Check

83Judge labels
10First choices
34Negative labels
12 of 12Models named it
1Category
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Best standing
14% in SCA for mid-market buyers
Rank 4 of 49 in the mid-market standingcriticized challenger
0 of 12 models made it the first choice on the direct prompt; 38% of its 32 labels there were negative.
By buyer segmentRead the same way at every buyer size.
In sca · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named OWASP Dependency-Check for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
Software composition analysisDeveloper platform14%4 of 4938%32criticized challenger

Movement

This is the first edition on this tier, so no move can be computed for OWASP Dependency-Check yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated OWASP Dependency-Check across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.520002
GPT-5.4 mini11002
Gemini 3.5 Flash00033
Perplexity Sonar01113
Grok 4.1 Fast01113
Mistral Small10001
DeepSeek V4 Flash00044
Llama 4 Maverick01102
Qwen 3.7 Flash10012
Kimi K202114
GLM 4.7 FlashX12014
MiniMax M2.501102

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct3 labelsNone
Paraphrase30 labels7
Comparative13 labelsNone
Budget-constrained18 labels3
Scale-constrained3 labelsNone
Negative16 labelsNone
First choiceAlternativeMentionNegative83 labels in all, every segment counted; 10 of the 10 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“Primary recommendation: OWASP Dependency‑Check for a mid‑size B2B company that needs a mature, free, self‑hosted SCA scanner” GLM 4.7 FlashX · SCA · paraphrase prompt · first choice
“OWASP Dependency-Check and ORT are excellent starting points because they're open-source with no licensing fees” Claude Haiku 4.5 · SCA · budget prompt · first choice
“I recommend OWASP Dependency-Check as a strong open source dependency vulnerability scanner” Mistral Small · SCA · paraphrase prompt · first choice
“Trivy and OWASP Dependency-Check are generally considered the best zero-cost options” Qwen 3.7 Flash · SCA · budget prompt · first choice

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

“You should actively avoid using the traditional OWASP Dependency-Check” Qwen 3.7 Flash · SCA · paraphrase prompt · hard negative
“Why you should avoid OWASP Dependency-Check (for now)” Gemini 3.5 Flash · SCA · paraphrase prompt · hard negative
“OWASP Dependency-Check for large or compliance-heavy environments, because it is positioned as a basic scanner and may not provide the advanced features some teams need” Perplexity Sonar · SCA · negative prompt · soft negative
“praised for Java/NVD, but consistently ranked behind newer tools on breadth, accuracy, and false‑positive rates across other languages” GLM 4.7 FlashX · SCA · negative prompt · soft negative

Named alongside

The products named in the same answers as OWASP Dependency-Check, over the 83 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and OWASP Dependency-Check was named but was not.
ProductSame answerTook the first choice insteadHead to head
Trivy55 of 8328Not in the top three
Snyk Open Source53 of 8315Not in the top three
Black Duck29 of 831Not in the top three
Mend.io28 of 831Not in the top three
OSV-Scanner24 of 831Not in the top three
FOSSA23 of 830Not in the top three
Grype23 of 830Not in the top three
OWASP Dependency-Track20 of 836Not in the top three
Endor Labs19 of 832Not in the top three
Sonatype Lifecycle19 of 832Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named OWASP Dependency-Check. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 75 of the 83 answers that named OWASP Dependency-Check and are not a share of its labels.

Domains cited

endorlabs.com53
appsecsanta.com43
safeguard.sh43
aikido.dev38
guideflow.com38
toolradar.com33
ox.security27
dupple.com26
expertinsights.com25
cycode.com21

347 of the 347 domain citations in answers naming OWASP Dependency-Check came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Names read as OWASP Dependency-Check

What the judge wrote, as written, with how often. The vendor table decides that these count as OWASP Dependency-Check; a claim can dispute any of them.
OWASP Dependency‑Check 2
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when OWASP Dependency-Check's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as OWASP Dependency-Check, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at owasp.org is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.

Subscribe to the pack