Measured · 2026-08-04

Who ChatGPT and Gemini recommend for vulnerability scanning software

We put 6 buyer questions about vulnerability scanning software to ChatGPT and Gemini. Only Nessus was named in all 6 answers. Here is the full list, the pages the answers were built from, and what it means whether or not your product is on it.

Answers read
6
Products named
24
Top source
reddit.com

Nessus was the only product named in all 6 of 6 answers when we asked ChatGPT and Gemini which vulnerability scanning software is best. We ran six buyer questions on 2026-08-04, gave the assistants one live web search each, and wrote down every product named and every source domain behind the answer. Nessus is the one name no phrasing could shake loose: best, cheapest, free, or built for small teams, it showed up every single time.

After Nessus, the drop-off is steep. Rapid7 InsightVM came second, named in 4 of 6 answers (67%). Three tools tied for third at 3 of 6 (50%) each: Nmap, OpenVAS, and ZAP. Everything below that landed at 2 of 6 (33%) or a single mention. In total, ChatGPT and Gemini named 24 different product labels across the six answers, but only 5 of them were named in at least half.

How the shortlist changed from one question to the next

The word "affordable" barely changed the list. The bare "best vulnerability scanning software" question returned 8 names, and "most affordable vulnerability scanning software" returned 8 as well, with 6 of the 8 identical: Nessus, OpenVAS, Rapid7 InsightVM, Acunetix, Nmap, and ZAP appeared in both. The only real swap was Tenable dropping out of the "best" answer and Haxore coming into the "affordable" one, a tool that appeared in no other question. If you sell here, "best" and "affordable" are effectively the same query.

The word "free" is where the shortlist actually broke apart. "Best free vulnerability scanning software" returned only 4 names, and just 1 of them, Nessus, carried over from the "best" list. The other three were unique to the free question: Wazuh vulnerability scanner, ZeroThreat, and the Website Vulnerability Scanner from Pentest-Tools.com. None of those three appeared in any of the other 5 answers. The open-source and freemium names only surface when a buyer types the word "free."

"For small teams" pulled in a fresh cast too. That question named 8 tools, and 5 of them showed up nowhere else in the entire run: Qualys VMDR, Wiz, Astra Pentest, Microsoft Defender Vulnerability Management, and Vulscan. Nessus and Rapid7 InsightVM anchored this list like the others, but the buyer-segment phrasing is what surfaced Wiz and Microsoft Defender at all.

Across all six questions, 15 of the 24 product labels were named exactly once. QualysGuard showed up only in "best." A bare Rapid7 and Saner CVEM appeared only in "what should I use." Kiuwan, Qualys Vulnerability Management, and WithSecure Elements Vulnerability Management appeared only in "recommendations." A tool named once is one source page away from never being named at all.

The source map

One domain fed every answer: reddit.com appeared in all 6 of 6 source lists. Behind it, three domains tied at 5 of 6: gartner.com, owasp.org, and safe.security. redcanary.com followed at 4 of 6. So the recommendations were built mostly on a community forum, an analyst site, a standards body, and two security-company roundups, not on vendor ad pages.

Review directories barely registered. g2.com appeared in 2 of 6 answers, on the "small teams" and "most affordable" questions. Capterra did not appear at all, and no other review directory did either. If you are a vulnerability-scanning vendor pouring budget into G2 badges, note that G2 fed a third of these answers while Reddit fed all 6 of 6.

Here is the most useful pattern in the whole run: three vendor domains fed an answer and got their own product named in that same answer. In the "free" question, pentest-tools.com was a source and the Website Vulnerability Scanner from Pentest-Tools.com was named, and zerothreat.ai was a source and ZeroThreat was named. In the "recommendations" question, kiuwan.com was a source and Kiuwan was named. When your own page is in the retrieved set, you tend to be in the answer.

The reverse is visible too. safe.security fed 5 of 6 answers and ox.security fed 2 of 6, yet neither company's own product was named in a single answer. Both were cited as the authors of roundup lists that name other people's tools. Being the source is not the same as being the pick: a listicle you wrote can get retrieved and still hand the recommendation to Nessus.

What to do if you sell vulnerability scanning software

The lesson from this data is narrow and practical: the source list, not your market share, decides whether an assistant names you. Haxore, ZeroThreat, and Vulscan are not household names, and each was named on the strength of one or two pages that happened to be retrieved (1 of 6 each). Nessus wins at 6 of 6 because it sits on nearly every page these assistants read, not because a model consulted a leaderboard.

So the work is to be present in these exact places: the Reddit threads that fed all 6 answers, the Gartner, OWASP, and Red Canary roundups that fed 5, 5, and 4 of the 6, and, as the Kiuwan and ZeroThreat cases show, your own indexable comparison pages. You do not need all 13 source domains we recorded. You need to be on the handful that get pulled for your category's questions.

The full list, counted

ProductNamed inShare
Nessus6 of 6100%
Rapid7 InsightVM4 of 667%
Nmap3 of 650%
OpenVAS3 of 650%
ZAP3 of 650%
Acunetix2 of 633%
Qualys2 of 633%
Snyk2 of 633%
Tenable2 of 633%

Two brands are split across more than one label in this table and in our raw data, and we have left them split on purpose. Qualys appears four separate ways: Qualys (2 of 6), plus QualysGuard, Qualys Vulnerability Management, and Qualys VMDR at 1 of 6 each. Rapid7 appears twice: Rapid7 InsightVM (4 of 6) and a bare Rapid7 (1 of 6). We are not adding these up, because the assistants wrote them as different names, and the count we can stand behind is the one measured for each label. A vendor tracking its own visibility would want to watch every label, since a buyer never sees the sum.

Glotier does not sell vulnerability scanning software, so we are correctly absent from all 6 of these answers, and we would not fake our way in. But this measurement is the whole of what we do: point the same six buyer questions at ChatGPT and Gemini for your category, then show you who got named, in which sub-question, and which source page put them there. If you want your own category's version of this page, the check is free, needs no account, and takes about a minute.

The questions we asked

One live web search per question, put to serper+or:chatgpt,gemini on 2026-08-04. 6 of 6 came back with an answer we could read. Whether a product was named is decided by looking for it in the answer text, not by asking a model for its opinion.

  1. best vulnerability scanning software
  2. best vulnerability scanning software for small teams
  3. what vulnerability scanning software should I use
  4. best free vulnerability scanning software
  5. most affordable vulnerability scanning software
  6. vulnerability scanning software recommendations

Questions people ask

What is the best vulnerability scanning software according to AI?
Across the six buyer questions we put to ChatGPT and Gemini on 2026-08-04, Nessus was named in all 6 of 6 answers (100%), the only tool to appear every time. Rapid7 InsightVM was second at 4 of 6 (67%), and Nmap, OpenVAS, and ZAP tied at 3 of 6 (50%) each.
What free vulnerability scanner do ChatGPT and Gemini recommend?
On the "best free" question specifically, the assistants named just 4 tools: Nessus, Wazuh vulnerability scanner, ZeroThreat, and the Website Vulnerability Scanner from Pentest-Tools.com. Only Nessus also appeared in the paid-leaning questions; the other three showed up nowhere else across the six answers.
Does the AI answer change if I ask for "affordable" instead of "best"?
Barely. The "best" and "most affordable" questions each returned 8 names, and 6 were identical: Nessus, OpenVAS, Rapid7 InsightVM, Acunetix, Nmap, and ZAP. The only swap was Tenable dropping out and Haxore coming in. The word "free," by contrast, changed almost the whole list, leaving only Nessus from the original 8.
Which sources do AI assistants use to recommend vulnerability scanners?
Reddit fed all 6 of 6 answers. Gartner, OWASP, and safe.security each fed 5 of 6, and Red Canary fed 4 of 6. The review directory G2 appeared in 2 of 6 answers, and Capterra did not appear at all. Community threads and roundup pages, not vendor ad pages, did most of the work.
How can my vulnerability scanning product get recommended by AI?
Get onto the pages these assistants actually read. In our run, three vendors (Kiuwan, ZeroThreat, and Pentest-Tools.com) were each named in the same answer their own domain was cited as a source. The source list, not market share, decided the outcome: little-known tools like Haxore and Vulscan each got named on a single retrieved page (1 of 6), while Nessus was named 6 of 6 because it sits on nearly every source the assistants pulled.

Do you sell in vulnerability scanning software? Find out whether you are in that list.

Paste your domain and watch the same run happen for your own buyer questions: which of the three assistants names you, who gets named instead, and the exact pages those answers were built from. Free, no card, no account for the first check.

Show my visibility

For reference, Nessus was named in 6 of the 6 answers we read.

Start with Solo

Get Glotier Solo

Everything on this page is one measurement, taken by hand, on one day. Solo runs it for your product every day and writes the work it points to.

  • The Citation Agent: which of your pages an assistant can actually cite, and the fix for each
  • A paragraph-quality read of your pages: what an assistant can lift whole, and where a claim is missing its source
  • An X agent and a Reddit agent: the live threads worth answering in your category, with a reply drafted for each
  • A daily check, and an article written from what it measured that day, ready to publish
  • The same buyer questions re-asked every day, with every source page behind each answer

Track 3 products and up to 150 buyer questions across ChatGPT, Gemini and Perplexity. $39/month.

Cancel any time. Not for you? Email us within 7 days of a charge and we refund it in full. Refund policy

Not ready to pay? The check is free, with no card and no account. Run it on your own product.