The most visible vulnerability scanners on ChatGPT, October 2026

October 2026 · 15 questions asked in English, worldwide · ChatGPT · 30 answers read

Leader

Snyk

30%of answers name it

Most cited source

owasp.org

61citations

From ChatGPT

Where engines disagree most

One engine

This page reads ChatGPT only. Set Engine to All to compare them.

Brands

Rank Brand Heralded Score Mentioned Recommended By engine Mentioned by Change
1 Snyk GB 39 , range 28–57 30% 20% First reading
2 OWASP ZAP US 33 , range 20–48 20% 17% First reading
3 Trivy IL 31 , range 17–44 20% 10% First reading
4 Burp Suite GB 20 , range 11–37 13% 3% First reading
5 Qualys US 17 , range 5–36 10% 3% None First reading
– Acunetix MT Too few answers 0% 0% First reading
– Aikido Security BE Too few answers 0% 0% First reading
– Aqua Security IL Too few answers 0% 0% First reading
– AWS Inspector US Too few answers 0% 0% First reading
– Clair US Too few answers 0% 0% First reading

“=” marks brands whose score ranges overlap, so the test cannot separate them. Every brand named in at least three answers is ranked. By engine has one dot per engine (ChatGPT, Google AI Overviews, Gemini and Google AI Mode), darker the more often it names the brand.

Most cited sources

Rank Source Type Cited in Engines Pages cited Brands its pages mention
1 owasp.org Community 73.3% 1 of 4 30 11
2Withheld. Run a full Snapshot to see it.
3 github.com Vendor site 30.0% 1 of 4 15 8
4Withheld. Run a full Snapshot to see it.
5 owasp.github.io Community 13.3% 1 of 4 8 3
6 trivy.dev Brand site 3.3% 1 of 4 5 2
7Withheld. Run a full Snapshot to see it.
8Withheld. Run a full Snapshot to see it.
9Withheld. Run a full Snapshot to see it.
10Withheld. Run a full Snapshot to see it.

The questions, and who wins each

QuestionLanguageWins it
what vulnerability scanner should a security team use to find software flaws English OWASP ZAP and Snyk, tied
which tool can scan our applications for security vulnerabilities English OWASP ZAP and Snyk, tied
how do small engineering teams scan code for vulnerabilities English Trivy
what can help developers find vulnerabilities before release English No brand recommended
how can i find vulnerabilities across our applications English OWASP ZAP
how do we catch security flaws in code before deployment English No brand recommended
how can my team find and prioritize software vulnerabilities English No brand recommended
how do i check whether our software has known vulnerabilities English Trivy
should we scan source code or running applications for vulnerabilities English No brand recommended
what works better for finding flaws, manual reviews or automated scans English No brand recommended

Each engine's top three

Method

Each month Heralded asks every engine the same buyer questions, twice each, and reads every answer. An answer counts 0 for a brand it leaves out, 50 for a brand it names and 100 for a brand it recommends, and the Heralded Score is built from those. A brand named in at least three answers gets a score and a place.

How the leaderboards are measured