Skip to content

Arena

Security Scanners arenaSecurity Scanners

Code-security scanning tools — secret detection, SAST, dependency/SCA, and container scanning — judged on detection accuracy, noise and false-positive management, pre-commit and CI integration, and how well agents can run scans headlessly and act on the results.

55 user stories · 330 judged cells · updated 2026-09-16 · Evidence as of 2026-09-16

Buyer checklist →Procurement report →

Leaderboard — every product ranked by evidenceLeaderboard

Rank by

Best by user type — persona-weighted winnersBest by user type

Per persona, the product with the highest persona-weighted coverage over just that persona's stories — not the same ranking as the overall PA Score leaderboard above.

Best for developer

Semgrep logo

Semgrep

52/100

Runner-up: Gitleaks logo Gitleaks (50/100)

10 developer stories scored

Best for security-engineer

TruffleHog logo

TruffleHog

49/100

Runner-up: Semgrep logo Semgrep (45/100)

8 security-engineer stories scored

Best for devops-lead

Gitleaks logo

Gitleaks

80/100

Runner-up: Trivy logo Trivy (61/100)

4 devops-lead stories scored

Best for ai-native

Semgrep logo

Semgrep

33/100

Runner-up: Gecko Security logo Gecko Security (32/100)

33 ai-native stories scored

Story matrix — every product × every judged storyStory matrix

55/55 stories shown · legend

Agenticness — how well agents can access and operate the productAgenticness

Agent access

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docsai-native
partialT
4/10
fullT
8/10
fullT
8/10
none
0/10
none
0/10
fullT
9/10
Agenticness — how well agents can access and operate the productRun the product headlessly / in CI for automationai-native
fullC
7/10
fullX
9/10
fullC
8/10
fullC
8/10
fullT
9/10
fullT
7/10
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their toolsai-native
n/a
none
0/10
none
0/10
n/a
n/a
none
0/10
Agenticness — how well agents can access and operate the productConnect an agent via an official MCP serverai-native
n/a
fullT
6/10
fullT
8/10
n/a
fullT
8/10
fullT
7/10
Agenticness — how well agents can access and operate the productUse an official CLIai-native
fullT
8/10
fullT
8/10
fullT
9/10
fullT
8/10
fullT
8/10
none
0/10
Agenticness — how well agents can access and operate the productDrive the product through a documented public APIai-native
none
0/10
partialT
6/10
none
0/10
none
0/10
partialT
6/10
fullT
8/10
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agentai-native
n/a
none
0/10
none
0/10
n/a
n/a
disputedD
4/10
Agenticness — how well agents can access and operate the productBuild against official SDKsai-native
none
0/10
none
0/10
none
0/10
n/a
none
0/10
partialT
5/10
Agenticness — how well agents can access and operate the productSubscribe to events via webhooksai-native
partialT
4/10
none
0/10
none
0/10
none
0/10
none
0/10
fullC
8/10

Agentic features

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the productai-native
none
0/10
partialX
6/10
fullT
7/10
none
0/10
partialT
5/10
disputedD
5/10
Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the backgroundai-native
partialC
5/10
partialC
5/10
partialX
6/10
partialC
6/10
partialT
4/10
fullC
7/10
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the productai-native
n/a
partialC
5/10
fullT
7/10
n/a
none
0/10
partialT
5/10
Agenticness — how well agents can access and operate the productOperate the product with natural-language commandsai-native
n/a
partialT
3/10
fullT
8/10
n/a
partialT
6/10
partialT
6/10

Api quality

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examplesai-native
none
0/10
none
0/10
none
0/10
none
0/10
none
0/10
none
0/10
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)ai-native
none
0/10
none
0/10
none
0/10
none
0/10
none
0/10
fullT
9/10
Agenticness — how well agents can access and operate the productTest against a sandbox environment without touching production dataai-native
none
0/10
n/a
none
0/10
n/a
none
0/10
none
0/10
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policyai-native
none
0/10
none
0/10
none
0/10
none
0/10
none
0/10
partialT
3/10

Automation depth — how much of the product can run unattendedAutomation depth

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Automation depth — how much of the product can run unattendedPerform bulk operations across many items at onceai-native
partialC
5/10
partialC
6/10
fullX
7/10
partialC
6/10
partialX
5/10
partialC
5/10
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on eventsai-native
partialC
6/10
fullC
8/10
partialX
4/10
partialC
5/10
none
0/10
partialC
5/10
Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflowsai-native
none
0/10
partialC
3/10
none
0/10
none
0/10
n/a
partialC
4/10
Automation depth — how much of the product can run unattendedVersion, review, and roll back my automationsai-native
n/a
none
0/10
none
0/10
n/a
n/a
none
0/10

Ci precommit — stories about ci precommit in this arenaCi precommit

Agent scanning

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Ci precommit — stories about ci precommit in this arenaHave an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findingsai-native
partialC
5/10
partialX
7/10
partialT
5/10
partialC
5/10
partialX
7/10
partialX
4/10
Ci precommit — stories about ci precommit in this arenaWire the scanner into my coding agent so AI-generated code is scanned for issues before it landsai-native
partialC
5/10
fullT
7/10
fullT
9/10
partialC
4/10
partialT
6/10
partialT
6/10

Ci gates

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Ci precommit — stories about ci precommit in this arenaRun scans in CI on every pull request and fail the build on new findings via exit codesdevops-lead
partialC
6/10
fullX
9/10
partialT
6/10
fullC
8/10
partialX
4/10
fullC
8/10
Ci precommit — stories about ci precommit in this arenaSee scan findings surfaced as pull-request comments or checks in GitHub or GitLabdeveloper
none
0/10
fullC
7/10
partialC
5/10
fullC
8/10
none
0/10
fullC
8/10

Pre commit

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Ci precommit — stories about ci precommit in this arenaRun the scanner as a pre-commit hook so secrets and issues never enter my git historydeveloper
fullC
9/10
fullC
9/10
none
0/10
fullC
8/10
none
0/10
none
0/10

Container scanning — stories about container scanning in this arenaContainer scanning

Containers

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Container scanning — stories about container scanning in this arenaScan container images for OS-package and application-layer vulnerabilities before deploying themdevops-lead
n/a
none
0/10
fullX
7/10
n/a
fullX
9/10
none
0/10

Iac misconfig

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Container scanning — stories about container scanning in this arenaScan Terraform, Kubernetes, and other IaC files for security misconfigurationsdevops-lead
n/a
partialC
3/10
fullC
8/10
n/a
fullX
9/10
none
0/10

Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy

Coverage

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Coverage accuracy — stories about coverage accuracy in this arenaScan projects across all the major languages and package ecosystems my organization usesdeveloper
partialC
5/10
partialX
6/10
fullX
7/10
partialC
6/10
partialX
7/10
partialX
5/10

Output formats

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Coverage accuracy — stories about coverage accuracy in this arenaEmit scan results in machine-readable formats like JSON or SARIF for downstream toolingdeveloper
none
0/10
fullX
9/10
none
0/10
partialC
5/10
none
0/10
partialT
4/10

Dependency sca — stories about dependency sca in this arenaDependency sca

Dependency fixes

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Dependency sca — stories about dependency sca in this arenaGet concrete upgrade paths or automated fix pull requests that remediate vulnerable dependenciesdeveloper
n/a
none
0/10
disputedD
5/10
n/a
none
0/10
none
0/10

Sca scanning

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Dependency sca — stories about dependency sca in this arenaScan my dependency manifests and lockfiles for packages with known vulnerabilitiesdeveloper
n/a
fullX
7/10
fullT
8/10
n/a
fullX
9/10
none
0/10
Dependency sca — stories about dependency sca in this arenaPrioritize dependency alerts by whether the vulnerable code is actually reachable from my codesecurity-engineer
n/a
partialC
6/10
partialC
6/10
n/a
none
0/10
none
0/10

Openness — open source, data portability, and self-hosting storiesOpenness

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Openness — open source, data portability, and self-hosting storiesDo everything through the API that I can do in the UIai-native
none
0/10
partialT
4/10
none
0/10
n/a
n/a
partialT
6/10
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leaveai-native
none
0/10
partialC
5/10
none
0/10
n/a
partialC
5/10
partialT
3/10
Openness — open source, data portability, and self-hosting storiesRead the product's source under an open licenseai-native
fullT
7/10
partialX
5/10
none
0/10
fullT
7/10
partialT
6/10
none
0/10
Openness — open source, data portability, and self-hosting storiesSelf-host the core productai-native
fullC
8/10
fullC
7/10
none
0/10
fullC
8/10
fullT
7/10
partialC
6/10

Privacy posture — data-handling and privacy storiesPrivacy posture

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Privacy posture — data-handling and privacy storiesChoose where my data is stored (region/residency)ai-native
partialC
4/10
none
0/10
none
0/10
n/a
n/a
partialC
5/10
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI modelsai-native
n/a
partialC
4/10
none
0/10
n/a
n/a
none
0/10
Privacy posture — data-handling and privacy storiesControl data retention and deletionai-native
none
0/10
partialC
4/10
none
0/10
n/a
none
0/10
none
0/10
Privacy posture — data-handling and privacy storiesOpt out of telemetry and usage trackingai-native
none
0/10
partialC
5/10
none
0/10
none
0/10
none
0/10
none
0/10

Sast rules — stories about sast rules in this arenaSast rules

Ai remediation

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Sast rules — stories about sast rules in this arenaHave AI draft remediation pull requests for security findings that I review and mergeai-native
n/a
partialC
4/10
disputedD
4/10
n/a
none
0/10
fullX
8/10

Code analysis

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Sast rules — stories about sast rules in this arenaDetect taint-style vulnerabilities that flow across files and function boundariessecurity-engineer
n/a
fullC
8/10
fullC
7/10
n/a
none
0/10
disputedD
5/10
Sast rules — stories about sast rules in this arenaRun static analysis that finds vulnerability classes like injection and XSS in my source codedeveloper
n/a
fullX
8/10
fullC
8/10
n/a
none
0/10
disputedD
5/10

Custom rules

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Sast rules — stories about sast rules in this arenaWrite custom static-analysis rules in a simple syntax and share them across repositoriessecurity-engineer
partialC
5/10
fullX
8/10
partialC
3/10
partialC
7/10
none
0/10
none
0/10

Fix suggestions

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Sast rules — stories about sast rules in this arenaApply suggested or automatic code fixes for findings instead of only reading reportsdeveloper
none
0/10
partialC
6/10
disputedD
6/10
none
0/10
none
0/10
fullC
8/10

Secret detection — stories about secret detection in this arenaSecret detection

Custom detection

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Secret detection — stories about secret detection in this arenaDefine custom detection rules for my organization's internal token and secret formatssecurity-engineer
fullC
9/10
partialX
6/10
none
0/10
fullC
8/10
none
0/10
none
0/10

Secret scanning

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Secret detection — stories about secret detection in this arenaScan a repository and its full git history for hardcoded secrets and credentialsdeveloper
fullC
9/10
partialC
4/10
none
0/10
fullC
9/10
partialC
5/10
none
0/10
Secret detection — stories about secret detection in this arenaScan non-git sources like S3 buckets, Docker images, and CI logs for leaked secretssecurity-engineer
disputedD
4/10
none
0/10
none
0/10
none
0/10
partialX
4/10
n/a
Secret detection — stories about secret detection in this arenaHave detected secrets verified against the issuing service so I know which ones are livesecurity-engineer
fullC
9/10
fullC
8/10
none
0/10
none
0/10
none
0/10
n/a

Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom

Licenses

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Supply chain sbom — stories about supply chain sbom in this arenaDetect the licenses of my dependencies and enforce a license policy in scansdevops-lead
n/a
none
0/10
partialC
6/10
n/a
partialC
5/10
none
0/10

Sbom

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Supply chain sbom — stories about supply chain sbom in this arenaGenerate a software bill of materials (SPDX or CycloneDX) for my project or imagesecurity-engineer
n/a
partialC
5/10
none
0/10
n/a
fullC
9/10
none
0/10

Triage noise — stories about triage noise in this arenaTriage noise

Ai triage

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Triage noise — stories about triage noise in this arenaUse AI to triage findings — explaining them, deduplicating, and flagging likely false positivesai-native
none
0/10
partialX
6/10
partialX
5/10
none
0/10
partialT
4/10
disputedD
4/10

Fp management

StoryPersona
TruffleHog logoTruffleHog
Semgrep logoSemgrep
Snyk logoSnyk
Gitleaks logoGitleaks
Trivy logoTrivy
Gecko Security logoGecko Security
Triage noise — stories about triage noise in this arenaBaseline or ignore existing and false-positive findings so only new issues alertsecurity-engineer
partialC
5/10
partialC
4/10
partialC
5/10
fullC
8/10
none
0/10
partialX
6/10
Triage noise — stories about triage noise in this arenaFilter and gate on findings by severity or confidence so low-value noise does not block buildsdeveloper
partialC
6/10
none
0/10
partialC
6/10
none
0/10
none
0/10
partialC
6/10
Verdict✓ fullclear evidence~ partialwith caveats! disputedevidence conflicts— noneno evidence foundn/aquestion doesn't apply to this kind of product
ProofT probedtested by usX communityusers back itC claimedvendor claim onlyD contradictedevidence disagrees⚿ auth-gatedprobe hit a live sign-in wall — verified reachable, untestable keylessly
quality 0–10 · PA Score /100 · A–D = evidence confidence · full guide

Adjacent arenas — categories often shopped togetherAdjacent arenas

Shopping this category often means shopping these too.