---
description: Page 3 - Compare the best Static Application Security Testing (SAST) Software in Canada. Capterra offers software reviews from verified users, pricing, and features. Find the top rated software for your business.
image: https://gdm-localsites-assets-gfprod.imgix.net/images/capterra/og_logo-e5a8c001ed0bd1bb922639230fcea71a.png?auto=format%2Cenhance%2Ccompress
title: Page 3 - Static Application Security Testing (SAST) Software - Prices & Reviews - Capterra Canada 2026
---

Breadcrumb: [Home](/) > [Static Application Security Testing (SAST) Software](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software) > [Page 3](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3)

# Static Application Security Testing (SAST) Software

Canonical: https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software

Page: 3 / 3\
Prev: [Previous page](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2)

> Static Application Security Testing (SAST) automatically scans coding environments for security vulnerabilities during the application development process.

-----

## Products

1. [Virbox Protector](https://www.capterra.ca/software/1073740/Virbox-Protector) (0 reviews) — Virbox Protector is a comprehensive \&amp; versatile software protection tool that offers a range of advanced features to safeguard software
2. [ZeroPath](https://www.capterra.ca/software/1078538/ZeroPath) (0 reviews) — ZeroPath is an application security testing platform that uses AI to detect vulnerabilities while reducing false positives.
3. [Bugsmirror MASST](https://www.capterra.ca/software/1078778/Bugsmirror) (0 reviews) — Bugsmirror CodeLock scans code with SAST to catch vulnerabilities early, integrate into CI/CD, and deliver secure mobile apps faster.
4. [Enforster AI](https://www.capterra.ca/software/1080924/Enforster-AI) (0 reviews) — Enforster AI is a security tool using machine learning to detect vulnerabilities, secrets, infrastructure issues, and AI model risks.
5. [Fluid Attacks](https://www.capterra.ca/software/1083041/Fluid-Attacks) (0 reviews) — Fluid Attacks is a software for vulnerability management, helping organizations identify, prioritize, and fix flaws during development.
6. [npmscan](https://www.capterra.ca/software/1083682/npmscan) (0 reviews) — npmscan secures Node.js projects from supply chain attacks by detecting malware and vulnerabilities in npm packages.
7. [JFrog Advanced Security](https://www.capterra.ca/software/1084389/JFrog-Advanced-Security) (0 reviews) — JFrog Advanced Security is a software supply chain tool that analyzes vulnerabilities, scans code, and detects exposures.
8. [CodeRisk](https://www.capterra.ca/software/1092250/CodeRisk) (0 reviews) — CodeRisk is a real-time static application security testing tool for VS Code that detects vulnerabilities as users code.

-----

Page: 3 / 3\
Prev: [Previous page](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2)

## Related Categories

- [Source Code Management Software](https://www.capterra.ca/directory/31420/source-code-management/software)
- [Cloud Security Software](https://www.capterra.ca/directory/31344/cloud-security/software)
- [Vulnerability Management Software](https://www.capterra.ca/directory/31062/vulnerability-management/software)
- [DevOps Software](https://www.capterra.ca/directory/31120/devops/software)
- [Continuous Integration Software](https://www.capterra.ca/directory/31119/continuous-integration/software)

## Links

- [View on Capterra](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software)
- [All Categories](https://www.capterra.ca/directory)

-----

## Structured Data

<script type="application/ld+json">
  {"@context":"https://schema.org","@graph":[{"name":"Capterra Canada","address":{"@type":"PostalAddress","addressLocality":"Toronto","addressRegion":"ON","postalCode":"M2N 7E9","streetAddress":"5000 Yonge Street 14th Floor, Suite 1402 Toronto ON M2N 7E9"},"description":"Capterra Canada helps millions of people find the best business software. With software reviews, ratings, infographics and a comprehensive list of business software.","email":"info@capterra.ca","url":"https://www.capterra.ca/","logo":"https://dm-localsites-assets-prod.imgix.net/images/capterra/logo-a9b3b18653bd44e574e5108c22ab4d3c.svg","@type":"Organization","@id":"https://www.capterra.ca/#organization","parentOrganization":"G2.com, Inc.","sameAs":["https://twitter.com/Capterra","https://www.facebook.com/Capterra/","https://www.linkedin.com/company/capterra/","https://www.instagram.com/capterra/","https://www.youtube.com/channel/UCyUw9-HIkKiYcTqcFDUcxPA"]},{"name":"Capterra Canada","url":"https://www.capterra.ca/","@type":"WebSite","@id":"https://www.capterra.ca/#website","publisher":{"@id":"https://www.capterra.ca/#organization"},"potentialAction":{"query":"required","target":"https://www.capterra.ca/search/?q={search_term_string}","@type":"SearchAction","query-input":"required name=search_term_string"}},{"name":"Static Application Security Testing (SAST) Software","description":"Page 3 - Compare the best Static Application Security Testing (SAST) Software in Canada. Capterra offers software reviews from verified users, pricing, and features. Find the top rated software for your business.","url":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3","about":{"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3#itemlist"},"breadcrumb":{"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3#breadcrumblist"},"@type":["WebPage","CollectionPage"],"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3#webpage","mainEntity":{"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3#itemlist"},"publisher":{"@id":"https://www.capterra.ca/#organization"},"inLanguage":"en-CA","isPartOf":{"@id":"https://www.capterra.ca/#website"}},{"@type":"BreadcrumbList","itemListElement":[{"name":"Home","position":1,"item":"/","@type":"ListItem"},{"name":"Static Application Security Testing (SAST) Software","position":2,"item":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software","@type":"ListItem"},{"name":"Page 3","position":3,"item":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3","@type":"ListItem"}],"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3#breadcrumblist"}]}
</script><script type="application/ld+json">
  {"name":"Page 3 - Static Application Security Testing (SAST) Software - Prices &amp; Reviews - Capterra Canada 2026","@context":"https://schema.org","@type":"ItemList","itemListElement":[{"name":"Virbox Protector","position":1,"description":"Virbox Protector: Comprehensive Software Protection Solution\nOverview:\nVirbox Protector is an advanced software protection tool that offers high-intensity encryption, compression, obfuscation, and virtualization. It is designed to protect the intellectual property and commercial value of software products by preventing unauthorized access and modification. The tool is suitable for a wide range of applications, including enterprise software, industry-specific applications, games, and mobile applications.\nKey Features:\n1. Code Virtualization\n2. Advanced Obfuscation\n3. Code Encryption\n4. Resource Encryption\n5. Multiple Encryption Strategies\n6. Multi-Platform Support\n7. Support for Multiple Programming Languages\n8. Performance Analysis\nApplications:\nVirbox Protector is widely used in various industries, including software development, game development, IoT devices, and smart terminals. It helps protect the core algorithms and business logic of software products.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/b3c5bc2f-2321-4f9b-9b71-b972999a0395.png","url":"https://www.capterra.ca/software/1073740/Virbox-Protector","@type":"ListItem"},{"name":"ZeroPath","position":2,"description":"ZeroPath is an AI-native Static Application Security Testing and AppSec platform that analyzes code for security vulnerabilities. The system detects issues including authentication problems, vulnerable dependencies, and compliance breaches while minimizing false positives. ZeroPath offers additional security capabilities such as Software Composition Analysis, secrets detection, Infrastructure as Code scanning, and automated vulnerability remediation. The platform integrates with development environments including GitHub, GitLab, Bitbucket, and Azure DevOps to deliver security feedback within pull requests. ZeroPath provides context-aware analysis that understands codebase patterns and includes exploitability assessment for identified vulnerabilities. The platform generates educational security feedback and includes natural language assistance for remediation support.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/231b25c3-dd96-474a-9086-9a25ffb2fcd3.jpeg","url":"https://www.capterra.ca/software/1078538/ZeroPath","@type":"ListItem"},{"name":"Bugsmirror MASST","position":3,"description":"Bugsmirror CodeLock delivers powerful Static Application Security Testing (SAST) to identify vulnerabilities early in the development lifecycle. By analyzing source code at build time, it detects insecure coding patterns, data leaks, and compliance gaps before the app reaches production. CodeLock integrates smoothly into CI/CD pipelines and version control systems, providing developers with fast, accurate, and actionable insights. Its mobile-focused rule sets uncover critical risks such as injections, buffer overflows, and weak cryptography, enabling teams to remediate issues at the source. Designed to shift security left, CodeLock helps enterprises reduce costly fixes later, enforce secure coding standards, and accelerate release cycles. With CodeLock as your SAST solution, your apps ship faster, safer, and with reduced risk—ensuring compliance, protecting users, and maintaining trust without slowing down innovation.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/aabf3249-c38b-4490-8bb9-48bfad25f2ae.png","url":"https://www.capterra.ca/software/1078778/Bugsmirror","@type":"ListItem"},{"name":"Enforster AI","position":4,"description":"Enforster AI is a Static Application Security Testing tool that revolutionizes code security through intelligent, contextual analysis rather than traditional rule-based scanning. Using advanced language models and machine learning, it ensures comprehensive security throughout the software development lifecycle.\nThe scanner identifies vulnerabilities like SQL injection, cross-site scripting, and broken authentication, delivering rapid scans with actionable fixes and specific code examples to help developers resolve issues efficiently while minimizing false positives.\nBeyond basic scanning, Enforster AI offers infrastructure as code scanning, secret detection, software composition analysis, SBOM analysis, license compliance checks, and AI model security features. Supporting multiple programming languages, it protects diverse technology stacks. Its AI-native approach simplifies security processes by understanding application context and enhancing software delivery.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/127e10a7-abb0-47c6-ae4b-4a0ebe71d727.png","url":"https://www.capterra.ca/software/1080924/Enforster-AI","@type":"ListItem"},{"name":"Fluid Attacks","position":5,"description":"Fluid Attacks is a solution for vulnerability management and application security posture management, identifying, prioritizing, and remediating security vulnerabilities throughout the software development lifecycle. It centralizes findings from security testing methods like SAST, DAST, SCA, secure code reviews, and penetration testing as a service, offering visibility into vulnerability locations, severities, and priority scores.\n\nThe platform features risk-based prioritization with dynamic scoring models considering CVSS ratings, reachability, and fixing costs. Orchestrated remediation lets teams assign vulnerabilities to developers, request automated retests, and access AI-powered fix suggestions. It generates metrics and compliance-ready reports for standards like ISO 27001 and SOC 2. Fluid Attacks integrates with IDEs, bug-tracking systems like Jira, Azure DevOps, and CI/CD tools to enhance workflow efficiency and catch vulnerabilities early.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/f9bcf32a-ad46-4186-99b6-8b8ccbf64687.png","url":"https://www.capterra.ca/software/1083041/Fluid-Attacks","@type":"ListItem"},{"name":"npmscan","position":6,"description":"npmscan is a security tool that protects Node.js projects from supply chain attacks by detecting malware-like behavior in npm packages. It identifies crypto-drainers and obfuscated scripts through lightweight static analysis and advanced heuristics, helping to uncover emerging threats including non-CVE malware and zero-day vulnerabilities.\nThe tool features real-time threat intelligence that tracks major security incidents in the npm ecosystem. npmscan prioritizes user privacy with a no-installation approach that requires no login credentials or API keys. The system does not store source code or any sensitive data during the scanning process.\nnpmscan focuses specifically on identifying malicious behavior patterns in packages, complementing traditional vulnerability scanners. The privacy-first design and specialized detection capabilities make it effective for identifying security risks in Node.js dependencies that might otherwise remain undetected.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/ce57ca4c-7186-4f4a-8c5c-21174dde3d96.jpg","url":"https://www.capterra.ca/software/1083682/npmscan","@type":"ListItem"},{"name":"JFrog Advanced Security","position":7,"description":"JFrog Advanced Security is an application security testing solution that goes beyond traditional SCA scanning to deliver deeper vulnerability insights and prioritization. It features vulnerability contextual analysis, source code scanning (SAST), and security exposure scanning for both source code and binaries. Leveraging data from JFrog's Security Research Team, it helps teams understand CVE impacts, prioritize threats, and reduce false positives. The integrated SAST capability enables developers to write trusted code while minimizing zero-day risks. It detects exposed secrets in code and binaries to prevent credential leakage and includes Infrastructure as Code security to address cloud deployment issues before production. Misconfiguration detection identifies security risks in open-source libraries and services. Seamlessly integrating into DevOps workflows, JFrog Advanced Security enhances software supply chain security throughout development.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/4cb45e41-d60a-476b-87e1-192472ea7bad.jpeg","url":"https://www.capterra.ca/software/1084389/JFrog-Advanced-Security","@type":"ListItem"},{"name":"CodeRisk","position":8,"description":"CodeRisk is a static application security testing (SAST) extension for Visual Studio Code that detects vulnerabilities in real time as developers write code. Operating entirely offline without AI or telemetry, it ensures privacy for sensitive codebases. CodeRisk scans JavaScript and TypeScript projects automatically, identifying security issues without cloud connectivity.\nThe extension integrates into VS Code with a security dashboard, sidebar for hierarchical findings, and editor features like gutter icons, inline annotations, and hover tooltips. It performs taint-flow analysis to trace vulnerabilities from source to sink. Covering over 15 vulnerability classes aligned with OWASP Top 10 and CWE, it detects issues like SQL injection, XSS, SSRF, and insecure randomness. CodeRisk runs background analysis during coding and full scans on startup, exporting results in SARIF format for CI/CD integration. Free and open-source, it’s available on the VS Code Marketplace.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/08273a49-464b-4351-874e-0f819b682ffa.jpeg","url":"https://www.capterra.ca/software/1092250/CodeRisk","@type":"ListItem"}],"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3#itemlist","numberOfItems":8}
</script>
