Mobile Application Security Testing Reviews and Ratings
What is Mobile Application Security Testing (MAST)?
The mobile AST market is composed of buyers and sellers of products and services that analyze and identify vulnerabilities in applications used with mobile platforms (iOS, Android and Windows 10 Mobile) during or post development. Many variations and flavors of techniques exist, but fundamentally mobile AST solutions test applications in three main ways: (1) SAST: These solutions statically analyze the source, binary or bytecode of an application to identify vulnerabilities. (2) Behavioral testing: Mobile AST solutions use behavioral analysis to observe the behavior of the app during runtime and identify actions that could be exploited by an attacker. (3) DAST: These solutions also use dynamic analysis to test the app in its runtime state. DAST simulates attacks against an application and analyzes the application's reactions, determining whether it is vulnerable.
Product Listings
Filter by
Appknox is a software designed to assist organizations in identifying and addressing security vulnerabilities within mobile applications. It enables automated and manual testing to evaluate application source code, binaries, and behavior for potential risks and compliance issues. The software supports security assessment processes such as static, dynamic, and API testing to uncover misconfigurations, insecure coding practices, and potential data exposure. Appknox integrates with development workflows to streamline vulnerability detection and remediation, helping businesses protect sensitive information and comply with regulatory requirements. It is used to enhance mobile application security by providing actionable insights for IT and security teams.
Ostorlab is a software designed for automated mobile application security assessment. The software enables organizations to identify and address vulnerabilities in Android and iOS applications during development and deployment. Ostorlab provides dynamic and static analysis capabilities to detect security issues such as misconfigurations, insecure coding practices, and data leakage risks. The software integrates with development pipelines and supports detailed reporting, helping teams prioritize and remediate identified risks efficiently. The primary business problem addressed by Ostorlab is enhancing the security posture of mobile applications and reducing the likelihood of exploitation by adversaries.
Checkmarx SAST is a software designed to analyze application source code in order to identify security vulnerabilities during the software development process. The software supports multiple programming languages and frameworks, enabling development and security teams to detect issues early in the application life cycle. Checkmarx SAST provides features such as automated code scanning, integration with development environments and CI/CD pipelines, customizable reporting, and support for compliance requirements. The software addresses business problems related to software security by helping organizations manage and reduce risks associated with insecure code, promoting safer software releases, and assisting with regulatory adherence.
esChecker (Legacy) is a software designed to evaluate the security posture of mobile applications by facilitating automated and guided tests of app resilience against reverse engineering, tampering, and other threats. The software offers capabilities such as dynamic analysis, code inspection, and real-time scenario simulation in emulated environments. It assists security teams in identifying vulnerabilities, assessing the effectiveness of implemented security controls, and gauging compliance with industry standards. esChecker (Legacy) supports continuous integration workflows and provides detailed reporting to inform remediation strategies, helping organizations address risks associated with mobile application deployment and operation.
Synopsys Black Duck is a software that provides automated open source management and security solutions for software development teams. The software enables identification and monitoring of open source components within codebases, assisting organizations in detecting vulnerabilities and managing license compliance. Black Duck streamlines the process of analyzing open source dependencies to ensure that software applications adhere to regulatory requirements and corporate policies. By integrating with existing development workflows, the software supports the continuous assessment of security risks and assists in mitigating potential threats associated with open source usage. This solution is designed to address business challenges related to open source security, intellectual property risk, and code governance in software development environments.
NowSecure Platform is a software designed to automate the testing and analysis of mobile applications for security, privacy, and compliance issues. The software enables organizations to identify vulnerabilities, assess data risks, and ensure adherence to industry standards within iOS and Android apps. It integrates with DevOps workflows, allowing for continuous monitoring and remediation through comprehensive vulnerability detection, policy enforcement, and detailed reporting. NowSecure Platform addresses business concerns related to mobile app security and regulatory compliance by providing scalable application security testing and actionable insights for development teams and security professionals.
Data Theorem Mobile Secure is a software designed to assess and protect mobile applications by identifying vulnerabilities and security risks that could lead to data breaches or unauthorized access. The software performs automated analysis of mobile app code, APIs, and third-party components to detect potential threats and weaknesses. It offers reporting and remediation guidance to help organizations address identified issues and comply with industry standards. Data Theorem Mobile Secure assists businesses in reducing risks associated with mobile application deployment and operations by helping secure sensitive data and maintain the integrity of their mobile environments.
OpenText Application Security Aviator, also known as Fortify, is a software designed to identify, analyze, and remediate vulnerabilities in application code throughout the software development lifecycle. The software provides static, dynamic, and interactive application security testing capabilities to help detect security flaws before deployment. It supports multiple programming languages and integrates with development tools and workflows, enabling continuous assessment of code for potential risks. The software assists organizations in addressing compliance requirements and reducing exposure to threats by delivering actionable insights into application security posture, supporting both on-premises and cloud environments.
AppScan is a software developed to help organizations identify and manage security vulnerabilities in applications. It performs dynamic, static, interactive, and open-source security testing to analyze code and detect issues throughout the software development lifecycle. The software provides automated scanning capabilities for web, mobile, and API applications, offering remediation guidance and reporting functionalities to support compliance with regulatory standards. AppScan integrates with development and DevOps workflows to enable early detection of vulnerabilities and facilitate secure code deployment. The software addresses the business problem of reducing the risk of security breaches by enhancing application security and supporting continuous vulnerability management.
PRADEO SECURITY – Mobile Application Security Testing is a software designed to analyze and secure mobile applications by detecting vulnerabilities, threats, and compliance issues within app source code and behavior. This software provides dynamic and static analysis to identify risks such as data leakage, unauthorized access, and insecure communications. It tests applications against a range of security standards and guidelines, helping organizations address exposure to cyber threats and regulatory requirements. Through automated assessments, the software facilitates the evaluation and remediation of security flaws, supporting developers and security teams in minimizing risk associated with mobile application deployment and usage.
Testhouse Managed Testing Services is a software designed to handle end-to-end testing processes for organizations. The software offers features such as test planning, execution, and management, accommodating functional, performance, and security testing requirements. It enables businesses to optimize the quality of their applications by identifying and addressing defects throughout the development lifecycle. The software provides customizable frameworks and reporting tools to align with client-specific needs, supporting integration with various development environments. Its core objective is to enhance software reliability and mitigate risks associated with deployment, thereby supporting organizations in maintaining system integrity and compliance standards.
Mobisec's vulnerability assessment and penetration testing platform is designed to ensure the security of mobile applications. It is engineered to reduce security concerns and allow companies to focus on their core business. With our platform, we first conduct a vulnerability assessment of the application using automation, human intelligence, and artificial intelligence. We perform this in black box mode, meaning our client does not need to provide access to the code or download any software. Next, our team of ethical hackers simulates the behavior of a real attacker to verify the application's robustness. Our platform monitors, records, and analyzes all processes to identify potential issues. At the end of our work, we generate and present a clear, detailed report with no false positives, understandable at various management levels. The report includes a classification of vulnerabilities by severity and precise recommendations for remediation.
Q-mast is a software designed to automate and manage the process of metadata extraction, transformation, and validation for data pipelines. The software assists organizations in improving data governance by facilitating the organization, classification, and cataloging of data assets. Q-mast enables users to standardize metadata definitions, streamline compliance with data regulations, and support audit requirements through consistent validation procedures. The software targets data engineers, data analysts, and compliance teams by providing tools for scalable metadata management, allowing for enhanced traceability and transparency of data resources within an enterprise. Q-mast aims to solve challenges related to manual metadata tasks, inaccuracies, and the overhead in maintaining compliant and well-documented data pipelines.
Quixxi Scan is a software designed to assess mobile applications for potential security vulnerabilities. The software performs comprehensive analysis of application code, libraries, and third-party integrations to identify risks and compliance issues. It supports scanning for malware, insecure data storage, improper use of encryption, and permissions misuse. Quixxi Scan helps organizations address common security concerns in mobile app development by providing actionable insights and recommendations for remediation. This software aids businesses in maintaining secure mobile environments and assists in compliance with relevant regulations and standards by automatically detecting weaknesses and generating detailed reports for developers and security teams.
ImmuniWeb MobileSuite is a software designed to assess the security and compliance of mobile applications across iOS and Android platforms. It identifies vulnerabilities in mobile apps, application programming interfaces, and backend systems by conducting dynamic and static testing. The software provides detailed reports highlighting security issues, compliance gaps, and remediation guidance. It supports organizations in addressing regulatory requirements, reducing risks associated with mobile applications, and improving the security posture of their mobile assets. ImmuniWeb MobileSuite aims to streamline mobile app security testing through automation while enabling integration with existing workflows.
Pradeo is a software that provides mobile application security solutions for organizations seeking to protect their digital assets and sensitive data. The software analyzes, detects, and prevents threats targeting mobile applications by employing automated scanning, behavioral analysis, and compliance assessment. Pradeo supports the identification of vulnerabilities, malware, and data leakage risks across mobile apps, enabling organizations to maintain regulatory compliance and safeguard user information. The software integrates with existing development and operational workflows, allowing for continuous monitoring and protection of mobile environments. Pradeo addresses the business problem of securing mobile applications against evolving threats and helps organizations minimize the risk of data breaches.
Syhunt Hybrid is a software designed to assess the security of web applications by performing automated vulnerability scanning and source code analysis. The software supports multiple programming languages and identifies a range of security issues, including SQL injection, cross-site scripting, and other vulnerabilities within web application environments. It offers both dynamic application security testing and static application security testing methods, enabling organizations to detect issues in deployed applications as well as review the underlying code. Syhunt Hybrid aims to assist businesses in identifying and mitigating risks associated with application development and deployment, providing detailed reports and remediation guidance to improve overall security posture.
Aikido is a developer-centric security platform that gives developers and security teams an instant overview of all code-to-cloud security issues and guides teams to fix vulnerabilities fast. Aikido supports security teams execute by aggressively reducing false-positives, automatic triage and risk bundling, and translating Common Vulnerabilities and Exposures (CVEs) into easy step-by-step explanations to resolve.
Described as an "all-in-one" application security platform, Aikido's covers the entire Software Development Lifecycle (SDLC), including: static application security testing (SAST), dynamic application security testing (DAST), infrastructure-as-code (IaC), container scanning, secrets detection, open source lisence scanning, cloud posture management (CSPM), runtime protection, and more.
App-Ray is a software that performs automated mobile application security analysis. It examines Android and iOS applications for potential vulnerabilities by conducting both static and dynamic analysis. The software identifies risks such as insecure data storage, privacy issues, code manipulation, and communication weaknesses. App-Ray provides reports outlining discovered vulnerabilities and suggests technical mitigations, assisting businesses in evaluating the security compliance of their mobile apps and addressing threats in the software development process. The software is used by organizations to improve application security posture and to support compliance with various security standards.
AppCheck is a software designed for automated web application and infrastructure vulnerability scanning, identifying security weaknesses across digital assets. The software conducts comprehensive scans to detect vulnerabilities such as SQL injection, cross-site scripting, and misconfigurations, assisting organizations in improving their security posture. It includes features for continuous assessment, allowing users to prioritize findings and track remediation progress within the platform. AppCheck addresses the business problem of managing risks in digital environments by enabling organizations to proactively uncover and resolve security issues before they are exploited. The software supports integration with other security tools and workflows, facilitating the development of a systematic approach to vulnerability management and compliance requirements.

















