Measured · 2026-08-07

Who ChatGPT and Gemini recommend for application security testing software

We put 6 buyer questions about application security testing software to ChatGPT and Gemini. One tool tied at the top, each named in 4 of 6 answers, and none in all six. Here is the full list, the pages the answers were built from, and what it means whether or not your product is on it.

Answers read
6
Products named
15
Top source
ox.security

Burp Suite is the one product ChatGPT and Gemini named most for application security testing software, landing in 4 of the 6 buyer answers we measured on 2026-08-07. No other tool in the category came close to that reach.

We put six buyer questions to ChatGPT and Gemini, gave each question one live web search, and recorded every product named and every source cited. Three tools tied for second at 3 of 6 answers each, a 50% hit rate: Checkmarx, OWASP ZAP, and SonarQube. So four names, Burp Suite plus those three, carried most of the category's visibility.

Below that tier the drop is steep. Invicti, Snyk, and "ZAP by Checkmarx" each appeared in 2 of 6 answers, or 33%. Everything else, eight separate products, showed up exactly once, 1 of 6, or 17%: AppScan, Checkmarx SAST, Contrast, GitGuardian, OpenText Application Security, OWASP PurpleTeam, StackHawk, and Veracode. Fifteen distinct product names came up across the six answers in total.

Two brands were counted under more than one label, and we kept them split rather than invent a merged number the data does not show. Checkmarx appears as both "Checkmarx" (3 of 6) and "Checkmarx SAST" (1 of 6). The open-source ZAP scanner appears as both "OWASP ZAP" (3 of 6) and "ZAP by Checkmarx" (2 of 6): the assistants used two names for the same scanner. Added together they would look larger, but each label stays its own row in the table below.

How the shortlist changed with the question

The most useful thing in this data is how far the shortlist moved when the question changed. The six questions read almost the same in plain English, yet 8 of the 15 products appeared in only one of the six answers, so more than half the names hung on a single phrasing.

The bare "best application security testing software" question returned 5 names: Burp Suite, Checkmarx, AppScan, Invicti, and "ZAP by Checkmarx." AppScan surfaced here and in none of the other five answers.

"Best free" collapsed the list to just 2 names, Snyk and GitGuardian, and shared nothing with the "best" answer. GitGuardian appeared only in the free answer. Burp Suite, the overall leader at 4 of 6, was absent from the free question entirely, which is the clearest sign that "free" is a different race.

"Most affordable" returned a third mix of 5 names: OWASP ZAP, Veracode, Burp Suite, SonarQube, and Checkmarx. Veracode showed up only in the affordable answer and nowhere else across the six.

"For small teams" was the sole appearance of OpenText Application Security, named alongside Checkmarx, SonarQube, and OWASP ZAP. "What should I use" was the sole appearance of OWASP PurpleTeam, named next to Burp Suite and "ZAP by Checkmarx." Each of those products lived in exactly 1 of 6 answers.

The broad "recommendations" question was the widest single answer at 8 names, and it was the only place Checkmarx SAST, StackHawk, and Contrast came up. Change the modifier, change the shortlist: "free" and "best" produced almost no overlap, and a vendor watching only the bare category term would miss the free, affordable, and small-team answers where a different set of names wins.

The source map

The answers lean on a small set of pages, and they are not the pages most vendors watch. Two domains fed all six answers: reddit.com (6 of 6) and ox.security (6 of 6). Community discussion and one security vendor's roundup sat behind every single answer.

Right behind them, cycode.com and owasp.org each fed 5 of 6 answers, and gartner.com, quora.com, and Carnegie Mellon's Software Engineering Institute (sei.cmu.edu) each fed 4 of 6. So the backbone is community threads (Reddit and Quora), security-vendor roundups (ox.security, cycode.com), the OWASP project site, one analyst (Gartner), and one academic institute.

The classic software review directories did not appear at all. G2 was cited 0 times. Capterra was cited 0 times. Whatever star ratings or review volume a vendor has built on those platforms did nothing to earn a mention in these six answers.

Here is the insight worth the whole page for a vendor: your own domain can be the source that gets you named. opentext.com was cited in the "small teams" answer, and OpenText Application Security was named in that same answer, 1 of 6. The page the assistant read was the vendor's own, and the vendor's product came straight out of it.

The pattern repeats more loosely with Contrast. contrastsecurity.com was cited once, in the "what should I use" answer, and Contrast was named once, in the "recommendations" answer that pulled from Reddit, Quora, Gartner, and OWASP. So Contrast got in both when it fed a page and when the community repeated its name. Owning the source is one road in; being what the community says is the other.

What it takes to get named here

The takeaway is blunt, and it is not about market share. The named set is decided by the source list, not by revenue or install base. Burp Suite leads at 4 of 6 because Reddit threads, OWASP pages, and the ox.security roundup keep naming it, not because a scoreboard ranked it first.

So the work for a vendor is unglamorous: be present in the exact pages these answers read, the 6-of-6 and 5-of-6 sources. That means the Reddit conversations, the OWASP ecosystem, and the roundup posts on ox.security and cycode.com. A slot in a roundup an assistant reads for 5 of 6 answers is worth more here than any directory profile, because the directories scored 0.

And because 8 of the 15 names rode in on a single question, the edges are open. Only Snyk and GitGuardian held the "free" answer. "Affordable" was loose enough that Veracode took a place with 1 of 6. A vendor with a real free tier or a low price has a specific, winnable answer to aim at instead of the whole category at once.

Where Glotier fits

Glotier does not sell application security testing, so we are correctly absent from all 6 of these answers. We would not expect our name in a list where we do not belong, and we are not going to pretend we belong in it.

This page, though, is the exact thing we run for a customer's own category. We take the six buyer questions a real shopper would type, ask ChatGPT and Gemini, and hand back the same counts you just read: who got named, in how many of 6 answers, and which pages fed each one. The check is free, needs no account, and takes about a minute.

The full list, counted

ProductNamed inShare
Burp Suite4 of 667%
Checkmarx3 of 650%
OWASP ZAP3 of 650%
SonarQube3 of 650%
Invicti2 of 633%
Snyk2 of 633%
ZAP by Checkmarx2 of 633%
AppScan1 of 617%
Checkmarx SAST1 of 617%

The questions we asked

One live web search per question, put to serper+or:chatgpt,gemini on 2026-08-07. 6 of 6 came back with an answer we could read. Whether a product was named is decided by looking for it in the answer text, not by asking a model for its opinion.

  1. best application security testing software
  2. best application security testing software for small teams
  3. what application security testing software should I use
  4. best free application security testing software
  5. most affordable application security testing software
  6. application security testing software recommendations

Questions people ask

Which application security testing tool do ChatGPT and Gemini name most?
Burp Suite. It appeared in 4 of the 6 buyer answers we measured on 2026-08-07, more than any other tool. Checkmarx, OWASP ZAP, and SonarQube tied for second at 3 of 6 each (50%), and Invicti, Snyk, and 'ZAP by Checkmarx' each landed 2 of 6.
What is the best free application security testing software according to AI?
The 'best free' answer named just 2 tools, Snyk and GitGuardian, and shared no names with the 'best' answer. GitGuardian appeared only in the free question. Burp Suite, the overall leader at 4 of 6, did not appear in the free answer at all, so the free race has a different set of names.
What is the most affordable application security testing tool AI suggests?
The 'most affordable' answer named 5 tools: OWASP ZAP, Veracode, Burp Suite, SonarQube, and Checkmarx. Veracode showed up only in this answer, 1 of 6, so 'affordable' surfaced a name the other five questions never did.
Do ChatGPT and Gemini rely on G2 or Capterra to pick these tools?
No. Across the six answers, G2 and Capterra were each cited 0 times. The sources that fed every answer were reddit.com (6 of 6) and ox.security (6 of 6), followed by cycode.com and owasp.org at 5 of 6, and Gartner, Quora, and Carnegie Mellon's sei.cmu.edu at 4 of 6.
Can a vendor get its own security tool named by AI?
Yes, and the data shows how. OpenText's own site (opentext.com) was cited in the 'small teams' answer, and OpenText Application Security was named in that same answer, 1 of 6. The source list, not market share, decides who gets named, so presence in Reddit threads, the OWASP ecosystem, and vendor roundups is what earns a mention.

Do you sell in application security testing software? Find out whether you are in that list.

Paste your domain and watch the same run happen for your own buyer questions: which of the three assistants names you, who gets named instead, and the exact pages those answers were built from. Free, no card, no account for the first check.

Show my visibility

For reference, Burp Suite was named in 4 of the 6 answers we read.

Start with Solo

Get Glotier Solo

Everything on this page is one measurement, taken by hand, on one day. Solo runs it for your product every day and writes the work it points to.

  • The Citation Agent: which of your pages an assistant can actually cite, and the fix for each
  • A paragraph-quality read of your pages: what an assistant can lift whole, and where a claim is missing its source
  • An X agent and a Reddit agent: the live threads worth answering in your category, with a reply drafted for each
  • A daily check, and an article written from what it measured that day, ready to publish
  • The same buyer questions re-asked every day, with every source page behind each answer

Track 3 products and up to 150 buyer questions across ChatGPT, Gemini and Perplexity. $39/month.

Cancel any time. Not for you? Email us within 7 days of a charge and we refund it in full. Refund policy

Not ready to pay? The check is free, with no card and no account. Run it on your own product.