| Category | Function | Share | Rank | Negative rate | Labels | Quadrant | Since September 2026 |
|---|---|---|---|---|---|---|---|
| Dynamic application security testing | Developer platform | 0% | 15 of 58 | 16% | 19 | accepted challenger |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 1 | 0 | 0 | 1 |
| GPT-5.4 mini | 0 | 0 | 0 | 0 | 0 |
| Gemini 3.5 Flash | 0 | 0 | 1 | 0 | 1 |
| Perplexity Sonar | 0 | 0 | 2 | 0 | 2 |
| Grok 4.1 Fast | 0 | 1 | 2 | 0 | 3 |
| Mistral Small | 0 | 0 | 1 | 0 | 1 |
| DeepSeek V4 Flash | 0 | 2 | 0 | 0 | 2 |
| Llama 4 Maverick | 0 | 0 | 0 | 0 | 0 |
| Qwen 3.7 Flash | 0 | 0 | 0 | 1 | 1 |
| Kimi K2 | 0 | 0 | 2 | 1 | 3 |
| GLM 4.7 FlashX | 0 | 1 | 0 | 0 | 1 |
| MiniMax M2.5 | 0 | 1 | 0 | 0 | 1 |
| GPT-6 Luna | 0 | 1 | 0 | 0 | 1 |
| Muse Glimmer 30B | 0 | 0 | 1 | 1 | 2 |
Verbatim evidence the judge attached to positive labels.
“Best for mid-market enterprises prioritizing user experience, developer collaboration, and compliance requirements” Claude Haiku 4.5 · DAST · direct prompt · alternative
“If you're API-heavy and need compliance support, Rapid7 InsightAppSec is worth the premium.” GLM 4.7 FlashX · DAST · direct prompt · alternative
“Cloud-based, scalable, strong analytics and integration with Rapid7's broader platform” MiniMax M2.5 · DAST · direct prompt · alternative
“Best for: Enterprises wanting DAST integrated with a broader security platform” DeepSeek V4 Flash · DAST · comparative prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“Legacy solutions like Qualys DAST and Rapid7 have become outdated. They burden teams with false positives, manual setups, and limited remediation guidance.” Muse Glimmer 30B · DAST · negative prompt · hard negative
“teams that cannot afford enterprise-grade commercial tools like Burp Suite Professional, HCL AppScan, or Rapid7” Qwen 3.7 Flash · DAST · budget prompt · soft negative
“Reported issues with authentication handling, limited CI/CD integration compared to modern alternatives” Kimi K2 · DAST · negative prompt · soft negative
Citations exist only for the models that return a source list, five of the fourteen in this edition, so these counts come from 50 of the 56 answers that named Rapid7 InsightAppSec and are not a share of its labels.
258 of the 258 domain citations in answers naming Rapid7 InsightAppSec came from somebody else's page.
Pages are listed as the models cited them.
Search figures are US estimates from DataForSEO, read October 5, 2026; AI search demand is its modeled, directional estimate, not a count of queries to any assistant. The answers are this edition's. Two measurements side by side: neither is read as the cause of the other.
An email the morning each edition publishes: where this product moved, where it held, and by how much against the noise floor. One address, confirmed by a click; a stop link in every email.
Already following? Everything you follow, with a stop for each.
What Rapid7 InsightAppSec's own pages state, read October 5, 2026: docs.rapid7.com/insightappsec, docs.rapid7.com/insightappsec/rbac, docs.rapid7.com/insightappsec/graphql, rapid7.com/products/insightappsec, docs.rapid7.com/insightappsec/concepts. A claimed page can correct any of them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when Rapid7 InsightAppSec's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as Rapid7 InsightAppSec, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
A new claim receives the current edition's vendor brief for Rapid7 InsightAppSec by email, built from the raw record of the edition. It shows: