Agent leaderboards / All sectors / Security platforms
Security platforms: which security platforms coding agents choose
Checkmarx One leads. GitLab apps get GitLab's own suite.
Read this leaderboard as textrankings, key learnings, method
Key learnings
We asked coding agents to choose one security platform for code, dependencies, secrets and live-app tests on seven applications.
Checkmarx One leads on Jenkins and Azure DevOps
Checkmarx One is chosen in 33% of all runs and in 50% on the apps that build in Jenkins or Azure DevOps.
GitLab apps keep GitLab
On the two apps built in GitLab CI, GitLab Security is chosen in 91% of runs. Elsewhere it is chosen in 2%.
GitHub apps do not get GitHub's
On the two apps built in GitHub Actions, GitHub Advanced Security is part of the choice in 4% of runs. Snyk is chosen in 33% there and Aikido Security in 25%.
- Muse Code chooses Checkmarx One in 4% of its runs, against 37% to 50% for the other agents, and Snyk in 39%.
The ranking118 runs
| Product | Wins | Share | ||
|---|---|---|---|---|
| 1 | Checkmarx Onecheckmarx.com | 39 | 33% | |
| 2 | GitLab Securitygitlab.com | 22 | 19% | |
| 3 | Snyksnyk.io | 19 | 16% | |
| 4 | Aikido Securityaikido.dev | 9 | 8% | |
| 5 | HCL AppScanhcltechsw.com | 5 | 4% | |
| 6 | GitHub Advanced Security + ZAP | 4 | 3% | |
| 7 | GitHub Advanced Security + Microsoft Defender for Cloud | 3 | 3% | |
| 8 | DefectDojo + Gitleaks + Semgrep + Trivy + ZAP | 3 | 3% | |
| 9 | DefectDojodefectdojo.com | 2 | 2% | |
| 10 | DefectDojo + Gitleaks + SonarQube + Trivy + ZAP | 1 | 1% | |
| 11 | DefectDojo + Dependency-Track + Gitleaks + SonarQube + Trivy + ZAP | 1 | 1% | |
| 12 | SonarQube + ZAP | 1 | 1% | |
| 13 | SOOSsoos.io | 1 | 1% | |
| 14 | DefectDojo + SonarQube + ZAP | 1 | 1% | |
| 15 | DefectDojo + Dependency-Track + Gitleaks + SonarQube + ZAP | 1 | 1% | |
| 16 | Fortify + Sonatype Lifecycle | 1 | 1% | |
| 17 | DefectDojo + Gitleaks + Semgrep + ZAP | 1 | 1% | |
| 18 | DefectDojo + GitHub Advanced Security + ZAP | 1 | 1% | |
| 19 | GitHub Advanced Securitygithub.com | 1 | 1% |
By agent, by persona, by wording
By agent
| Codex · GPT-6 Sol30 runs | Checkmarx One · 15then GitLab Security · 5 |
| Grok Build CLI · Grok 4.730 runs | Checkmarx One · 12then GitLab Security · 6 |
| Claude Code · Claude Opus 5.530 runs | Checkmarx One · 11then GitLab Security · 6 |
| Muse Code · Muse Spark 1.328 runs | Snyk · 11then GitLab Security · 5 |
By persona
| Enterprise team118 runs | Checkmarx One · 39then GitLab Security · 22 |
A case is one codebase with one agent, asked several times in different words and as different people. 21 of 27 cases did not hold to a single security platform.
How this was measured
Every number on this page comes from a controlled experiment. We took 7 small applications, asked 4 coding agents (Codex (GPT-6 Sol), Grok Build CLI (Grok 4.7), Claude Code (Claude Opus 5.5), Muse Code (Muse Spark 1.3)) to choose a security platform for each of them, in several wordings and as an enterprise team, and let the agent choose the product. Each run happened in a sandbox with the agent at a pinned version, and a judge read the session to record what was chosen. That is 118 runs. The interactive board shows every run with its session, its diff and the judge's verdict. A simulated user stood in for the owner of the codebase: it read the agent's plan and had to approve it before any code was written; it sent the agent back at least once in 27 runs. Read the methodology and the publications.
If you sell in this sector: what these numbers mean for a vendor.
Open the interactive boardThis page as MarkdownOther sectors
- Agent sandboxes
- Observability
- AI SRE
- Payments
- Deploy
- Auth
- Email providers
- Product analytics
- Databases
- File storage
- LLM evals & observability
- Voice Agents
- Serverless functions
- Cloud
- AI gateway
- Bot protection
- Search
- Agent frameworks
- Performance in CI
- Document processing & OCR
- Usage-based billing
- Internationalization
- Security testing
- Maps
- Message queues
- AI search
- Code review
- E-signature
- In-app chat & calls
- Vector search