# OWASP Dependency-Check: how AI models rank it, September 2026

IT AI Recommendation Index, September 2026 Edition. Named in 32 judge labels across 1 categories by 12 of 12 models. Page: https://it-ai-index.com/vendors/owasp-dependency-check/

## Standing by category

| Category | Share | Rank | Negative rate | Labels |
|---|---|---|---|---|
| Software composition analysis | 14% | 4 | 38% | 32 |

## What the models said for it

- "Primary recommendation: OWASP Dependency‑Check for a mid‑size B2B company that needs a mature, free, self‑hosted SCA scanner" (GLM 4.7 FlashX, SCA)
- "OWASP Dependency-Check and ORT are excellent starting points because they're open-source with no licensing fees" (Claude Haiku 4.5, SCA)
- "I recommend OWASP Dependency-Check as a strong open source dependency vulnerability scanner" (Mistral Small, SCA)
- "Trivy and OWASP Dependency-Check are generally considered the best zero-cost options" (Qwen 3.7 Flash, SCA)

## And against it

- "You should actively avoid using the traditional OWASP Dependency-Check" (Qwen 3.7 Flash, SCA)
- "Why you should avoid OWASP Dependency-Check (for now)" (Gemini 3.5 Flash, SCA)
- "OWASP Dependency-Check for large or compliance-heavy environments, because it is positioned as a basic scanner and may not provide the advanced features some teams need" (Perplexity Sonar, SCA)
- "praised for Java/NVD, but consistently ranked behind newer tools on breadth, accuracy, and false‑positive rates across other languages" (GLM 4.7 FlashX, SCA)

## Record

- Method: https://it-ai-index.com/methodology/
- Raw judge labels and full responses: https://it-ai-index.com/data/
- License: CC BY 4.0. Cite as IT AI Recommendation Index, September 2026 Edition, it-ai-index.com.
