AI Indexes
IT AI Index
Index › Products › OWASP · October 2026 Edition
1 category · Named, not ranked

OWASP

8Judge labels
1First choices
0Negative labels
5 / 14Models named it
1Category
October 2026 Edition. Every number here is derived from the raw labels under vendor table v2026-10.8, every buyer segment counted.
Standing
5 labels, too few to rank
A product needs 10 labels in a category before a share or quadrant is stated. OWASP was named 5 times in Secure code training, where SecureFlag led with 26%. The labels and the evidence are below, counted exactly.
By buyer segmentRead the same way at every buyer size.
In secure code training · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named OWASP for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrantSince September 2026
Secure code trainingDeveloper platform0%25 of 970%5under 10 labels · led by SecureFlag at 26%

Movement

This is the first edition on this tier, so no move can be computed for OWASP yet. From the next edition this section shows, per buyer segment and per category, whether its share moved by more than the measured noise floor.

By model

How each model treated OWASP across every prompt where it was named for a mid-market B2B company. Fourteen models, six prompts per category.
ShowHide
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.500000
GPT-5.4 mini00000
Gemini 3.5 Flash00000
Perplexity Sonar01001
Grok 4.1 Fast02002
Mistral Small00000
DeepSeek V4 Flash00000
Llama 4 Maverick00000
Qwen 3.7 Flash00000
Kimi K200000
GLM 4.7 FlashX00101
MiniMax M2.500000
GPT-6 Luna00101
Muse Glimmer 30B00000

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct0 labelsNone
Paraphrase4 labels1
Comparative0 labelsNone
Budget-constrained2 labelsNone
Scale-constrained1 labelNone
Negative1 labelNone
First choiceAlternativeMentionNegative8 labels in all, every segment counted; 1 of the 1 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“the OWASP Top 10 and cheat sheets may be enough to start without paying for a platform” Perplexity Sonar · Secure code training · budget prompt · alternative
“Free/OWASP resources are reliable starters before paid options.” Grok 4.1 Fast · Secure code training · negative prompt · alternative
“Budget starters | Free OWASP Top 10 courses/labs” Grok 4.1 Fast · Secure code training · paraphrase prompt · alternative

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

No model argued against it.

Named alongside

The products named in the same answers as OWASP, over the 8 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and OWASP was named but was not.
ShowHide
ProductSame answerTook the first choice insteadHead to head
Avatao3 of 81Not among the top eight
SecureFlag3 of 81Not among the top eight
Coursera2 of 80Not among the top eight
Secure Code Warrior2 of 80Not among the top eight
Security Journey2 of 80Not among the top eight
Udemy2 of 80Not among the top eight
Veracode Security Labs2 of 80Not among the top eight
G2-listed platform1 of 81Not among the top eight
Practical DevSecOps1 of 81Not among the top eight
Checkmarx Codebashing1 of 80Not among the top eight
A head-to-head page exists where both products are among a category's top eight. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named OWASP. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, five of the fourteen in this edition, so these counts come from 7 of the 8 answers that named OWASP and are not a share of its labels.

Domains cited

f6s.com4
ransomleak.com4
securecodewarrior.com3
securityjourney.com3
sourceforge.net3
coursera.org2
devguide.owasp.orgYour site2
g2.com2
gartner.com2
omr.com2

Twenty-five of the twenty-seven domain citations in answers naming OWASP came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Search and answers

owasp.org ranks 8 on Google for the category's searches. In the answers, OWASP takes 0% of first choices and SecureFlag takes 26%.
ShowHide

In search

Google, US estimates
Position for “secure code training platform”
8
Position for “secure code training platforms”
–
not in the top ten
Organic visits to its site
about 365,222 a month
Searches its site ranks for
104,405 · 3,003 in the top three
Sites linking to it
65,251
Paid Google search
No ads found in the estimate; that does not mean it runs none
Ads on Google
None found in Google's ad transparency records for the US

In answers

This edition
Share of first choices
0%
rank 25 of 97 in secure code training
Segment leader
26%
SecureFlag
First choices
1 across its categories
Named in
8 answers
Its own site cited
in 7 of the answers that named it

Search figures are US estimates from DataForSEO, read September 28, 2026; AI search demand is its modeled, directional estimate, not a count of queries to any assistant. The answers are this edition's. Two measurements side by side: neither is read as the cause of the other.

What it publishes

ShowHide
Addresses on owasp.org
893
subdomains included
Content
154
counted in the table below
Documentation
1
Product · Integration
30 · 216
KindPagesLast 90 days2025-10 to 2026-09LatestCategories named
Blog8602025-08-05
Conference or event3502025-11-14
News or press1802024-11-20
Webinar or virtual event702026-05-13
Podcast or video4undated
Template or tool302024-05-08
Glossary or explainer1undated

Most recent

Events in person

Upcoming
Last twelve months

As the event pages on owasp.org state them, read September 28, 2026.

How it is countedHide how it is counted

Every page owasp.org exposes, subdomains included. Kind is read from the address and title. The last 90 days, the latest date and the twelve months count pages by when they were published, from the site's feeds, a date in the address, or the page's own publication date, read from up to a hundred of its most recently changed pages; a page that says only when it last changed is counted in its kind but not in when, so the recent counts are a floor, and a kind none of whose pages gives a publication date reads undated. An event counts as online when its address or title says so (webinar, on demand, virtual or online summit); a conference, summit, trade show, expo or roadshow that does not say so is counted as a conference or event, which on a vendor's site is mostly in person. Read September 29, 2026.

Names read as OWASP

What the judge wrote, as written, with how often. The vendor table decides that these count as OWASP; a claim can dispute any of them.
OWASP + OpenSSF Free Resources 1

Follow OWASP

An email the morning each edition publishes: where this product moved, where it held, and by how much against the noise floor. One address, confirmed by a click; a stop link in every email.

Already following? Everything you follow, with a stop for each.

The company

OWASP is its own company.
ShowHide

In its own words

Stated by the vendor, not checked
Positioning
The Open Source Foundation for Application Security
For
a global community
Price stated
free for everyone, everywhere owasp.org
Free plan or trial
All resources are free and open to everyone. owasp.org
Not stated on the pages read
Starting price, integrations, certifications, hosting, customers

What OWASP's own pages state, read October 6, 2026: owasp.org, owasp.org/security. A claimed page can correct any of them.

Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when OWASP's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as OWASP, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

What a new claim receivesHide what a new claim receives

A new claim receives the current edition's vendor brief for OWASP by email, built from the raw record of the edition. It shows:

  • where OWASP is named, by buyer and by framing, and which cells hold its first choices;
  • the claims the models make when they name it, ranked, with the strongest and the weakest quoted;
  • its vocabulary against the segment leader's, and the pages the models cited;
  • who was chosen in the answers that did not name OWASP, and every reason the record gives;
  • a battlecard for each top rival: the head-to-head split, why they win, and the reservation quoted against them;
  • one page of published figures cleared to show a buyer.

A verification link goes to your work email; an address at owasp.org is approved on the spot, any other is reviewed by hand. Your email is never published. Claiming gives no say over labels, shares, verdicts or which quotes appear.