| Category | Function | Share | Rank | Negative rate | Labels | Quadrant | Since September 2026 |
|---|---|---|---|---|---|---|---|
| Secure code training | Developer platform | 0% | 25 of 97 | 0% | 5 | under 10 labels · led by SecureFlag at 26% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 0 | 0 | 0 | 0 |
| GPT-5.4 mini | 0 | 0 | 0 | 0 | 0 |
| Gemini 3.5 Flash | 0 | 0 | 0 | 0 | 0 |
| Perplexity Sonar | 0 | 1 | 0 | 0 | 1 |
| Grok 4.1 Fast | 0 | 2 | 0 | 0 | 2 |
| Mistral Small | 0 | 0 | 0 | 0 | 0 |
| DeepSeek V4 Flash | 0 | 0 | 0 | 0 | 0 |
| Llama 4 Maverick | 0 | 0 | 0 | 0 | 0 |
| Qwen 3.7 Flash | 0 | 0 | 0 | 0 | 0 |
| Kimi K2 | 0 | 0 | 0 | 0 | 0 |
| GLM 4.7 FlashX | 0 | 0 | 1 | 0 | 1 |
| MiniMax M2.5 | 0 | 0 | 0 | 0 | 0 |
| GPT-6 Luna | 0 | 0 | 1 | 0 | 1 |
| Muse Glimmer 30B | 0 | 0 | 0 | 0 | 0 |
Verbatim evidence the judge attached to positive labels.
“the OWASP Top 10 and cheat sheets may be enough to start without paying for a platform” Perplexity Sonar · Secure code training · budget prompt · alternative
“Free/OWASP resources are reliable starters before paid options.” Grok 4.1 Fast · Secure code training · negative prompt · alternative
“Budget starters | Free OWASP Top 10 courses/labs” Grok 4.1 Fast · Secure code training · paraphrase prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
Citations exist only for the models that return a source list, five of the fourteen in this edition, so these counts come from 7 of the 8 answers that named OWASP and are not a share of its labels.
Twenty-five of the twenty-seven domain citations in answers naming OWASP came from somebody else's page.
Pages are listed as the models cited them.
Search figures are US estimates from DataForSEO, read September 28, 2026; AI search demand is its modeled, directional estimate, not a count of queries to any assistant. The answers are this edition's. Two measurements side by side: neither is read as the cause of the other.
| Kind | Pages | Last 90 days | 2025-10 to 2026-09 | Latest | Categories named |
|---|---|---|---|---|---|
| Blog | 86 | 0 | 2025-08-05 | ||
| Conference or event | 35 | 0 | 2025-11-14 | ||
| News or press | 18 | 0 | 2024-11-20 | ||
| Webinar or virtual event | 7 | 0 | 2026-05-13 | ||
| Podcast or video | 4 | undated | |||
| Template or tool | 3 | 0 | 2024-05-08 | ||
| Glossary or explainer | 1 | undated |
As the event pages on owasp.org state them, read September 28, 2026.
Every page owasp.org exposes, subdomains included. Kind is read from the address and title. The last 90 days, the latest date and the twelve months count pages by when they were published, from the site's feeds, a date in the address, or the page's own publication date, read from up to a hundred of its most recently changed pages; a page that says only when it last changed is counted in its kind but not in when, so the recent counts are a floor, and a kind none of whose pages gives a publication date reads undated. An event counts as online when its address or title says so (webinar, on demand, virtual or online summit); a conference, summit, trade show, expo or roadshow that does not say so is counted as a conference or event, which on a vendor's site is mostly in person. Read September 29, 2026.
An email the morning each edition publishes: where this product moved, where it held, and by how much against the noise floor. One address, confirmed by a click; a stop link in every email.
Already following? Everything you follow, with a stop for each.
What OWASP's own pages state, read October 6, 2026: owasp.org, owasp.org/security. A claimed page can correct any of them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when OWASP's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as OWASP, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
A new claim receives the current edition's vendor brief for OWASP by email, built from the raw record of the edition. It shows: