The most visible B2C vulnerability scanners, October 2026

October 2026 · 15 questions asked in English, worldwide · ChatGPT, Google AI Overviews, Gemini and Google AI Mode · 120 answers read

Most cited source

owasp.org

66citations

From Google AI Mode, Google AI Overviews and ChatGPT

Where engines disagree most

Tenable Nessus

1/4engines put it in their top three

Top three on Google AI Overviews, not on Google AI Mode, Gemini and ChatGPT

Brands

Rank Brand Heralded Score Mentioned Recommended By engine Mentioned by Change
1#2 overall OWASP ZAP US 32 , range 20–38 22% 9% First reading
2#3 overall Trivy IL 27 , range 10–35 18% 6% First reading
3#4 overall Burp Suite GB 24 , range 9–34 19% 3% First reading
4#5 overall Tenable Nessus US 13 , range 6–32 13% 4% First reading
5#11 overall Greenbone OpenVAS DE 3 , range 2–9 4% 0% First reading
6#15 overall Nuclei US 2 , range 1–7 2% 0% First reading
– Clair US Too few answers 1% 0% First reading
– Nikto US Too few answers 1% 0% First reading

“=” marks brands whose score ranges overlap, so the test cannot separate them. Every brand named in at least three answers is ranked. By engine has one dot per engine (ChatGPT, Google AI Overviews, Gemini and Google AI Mode), darker the more often it names the brand.

Most cited sources

Rank Source Type Cited in Engines Pages cited Brands its pages mention
1 owasp.org Community 21.7% 3 of 4 32 5
2 reddit.com Community 9.2% 2 of 4 10 4
3 owasp.github.io Community 3.3% 1 of 4 8 0
4 medium.com Community 4.2% 1 of 4 5 0
5 quora.com Community 3.3% 1 of 4 3 0
6Withheld. Run a full Snapshot to see it.
7 stackexchange.com Community 1.7% 1 of 4 2 0
8Withheld. Run a full Snapshot to see it.
9 c-sharpcorner.com Community 0.8% 1 of 4 1 0
10 dev.to Community 0.8% 1 of 4 1 0

The questions, and who wins each

QuestionLanguageWins it
how do application scans compare with dependency checks for finding vulnerabilities English No brand recommended
should developers or security teams own vulnerability scanning English No brand recommended
what can replace manual security checks before each software release English No brand recommended
how can we replace spreadsheets for tracking software vulnerabilities English Tenable Nessus
what can replace separate scanners for code and dependencies English No brand recommended

Each engine's top three

Method

Each month Heralded asks every engine the same buyer questions, twice each, and reads every answer. An answer counts 0 for a brand it leaves out, 50 for a brand it names and 100 for a brand it recommends, and the Heralded Score is built from those. A brand named in at least three answers gets a score and a place.

How the leaderboards are measured