A vulnerability scanner finds the known holes in what you already run, which is a different job from stopping an attack in progress.
This guide ranks the scanners on what they can actually see, how much of the output is real, and what the licence counts when your estate grows: assets, targets, domains or developers.
Vendors can pay for visibility on this page. It never changes what an entry
says about a product, including the criticism, and we earn nothing when you click through to a
vendor. How that works.
In short
What vulnerability scanning software does
A vulnerability scanner checks systems, applications and dependencies against a feed of known flaws, then reports which ones your environment appears to have.
In this order: setup effort, what it really costs, how your data comes back out, whether
you can leave, and who each vulnerability scanning tool is built for. Why those five, and why there is no
score out of ten, is on the how we work page.
Per asset per year, quoted; modules priced separately
—
Large distributed estates that need agents everywhere and compliance reports
Small organisations wanting a scanner without a project
Country is where the vendor is headquartered or contracts from, which is a
different question from where your data is hosted. Where the two tell different stories, the
entry says so.
Greenbone is the only full network scanner here you can run entirely on your own hardware, with no vendor holding a list of your unpatched machines. For a hospital, a utility or anyone with an air-gapped segment, that is the deciding fact.
In exchange you accept an interface built by engineers for engineers, a feed that is good on infrastructure and weak on modern web stacks, and no help with triage. Budget staff time instead of licence fees.
What stands out
Open source
Self-hosted
German vendor
Where it costs you
No meaningful web application scanning
Community feed covers only a fraction of the enterprise feed
Right for
Teams that must keep scan results inside their own network
Wrong for
Organisations that need application and dependency coverage too
GermanyFree community edition; OPENVAS BASIC virtual appliance 2,524 euros a year, published; larger appliances quoted
Continuous external scanning with findings a non-specialist can act on
Ranked #2 of 20 in Best Vulnerability Scanner in 2026.
Free tierPublished pricingEurope
Intruder is the best purchase for a company whose entire security function is one engineer with other responsibilities. It watches the internet-facing estate continuously, on the Pro plan rescans within hours when something critical is disclosed, and writes findings in language a developer can act on without a translation layer.
The limits arrive when you grow: internal authenticated scanning across thousands of hosts, custom check tuning and detailed compliance evidence all push you towards the platforms lower on this page.
What stands out
Published price
External surface
Low noise
Where it costs you
Limited depth for large internal networks
Advanced tuning options are intentionally hidden
Right for
Small companies with an external footprint and no security team
Wrong for
Mature security teams needing deep configuration control
United KingdomFree plan; paid plans a base fee plus a fee per target, monthly or annual, published; enterprise quoted
Hosted scanner toolkit and reporting for very small teams
Ranked #3 of 20 in Best Vulnerability Scanner in 2026.
Free tierPublished pricingEurope
This is a toolkit with reporting, not a management platform, and it is honest about that. For an agency producing client assessments, or an internal team that scans quarterly and needs a document at the end, the economics are excellent and the reports need little rewriting.
Scan diffs, an asset workspace and a Jira integration are there, but it is still built around running scans rather than managing who owns each asset and who is fixing what.
What stands out
Published price
Report templates
Consultant friendly
Where it costs you
Ownership and remediation tracking are thin
Plans are capped by the number of assets scanned
Right for
Consultants and tiny teams running periodic external assessments
Wrong for
Running a continuous programme across a large estate
RomaniaFree edition; paid plans from 95 dollars a month for five assets, published; unlimited scans on those assets
The open-source Nuclei scanner, with an AI pentesting platform on top
Ranked #4 of 20 in Best Vulnerability Scanner in 2026.
Free tierOpen sourcePublished pricingNorth America
Nuclei turns a vulnerability check into a short YAML file, which means you can read exactly what a finding is based on and write your own for the service only you run. That transparency is the argument, and the open-source engine keeps working without the vendor.
The limits are scope and discipline: it looks at what answers on the network, not at installed package versions, and running every community template produces noise someone has to tune away.
What stands out
Open source
Template-based checks
External surface
Where it costs you
No authenticated patch-level scanning of hosts
Template quality varies, so noise depends on curation
Right for
Security engineers who want scriptable external and web scanning they control
Wrong for
Teams wanting a managed programme with remediation tracking
United StatesFree open-source engine and a limited free platform plan; 200 to 800 dollars per seat per month, published; enterprise quoted
The infrastructure scanner every other vendor is measured against
Ranked #5 of 20 in Best Vulnerability Scanner in 2026.
Published pricingNorth America
Nessus is where most people start and many stay: the check feed is the broadest in the industry, and a professional licence costs 4,790 dollars a year, the price of a few days of consultancy. The trouble starts at scale.
The managed platform prices per asset, cloud instances that live for an hour still count somewhere, and the default output is enormous. Plan for a quarter of tuning, exclusions and ownership mapping before anyone believes the dashboard.
What stands out
Largest check feed
Published Nessus price
Wide integrations
Where it costs you
Findings volume needs real tuning effort
Web application scanning needs Nessus Expert or a separate licence
Right for
Infrastructure teams that want the widest check coverage available
Wrong for
Buyers wanting one tool to cover apps and dependencies
United StatesNessus Professional 4,790 dollars per licence per year, published; platform per asset, published up to 250 assets
Belgian platform bundling code, dependency, container and cloud scanning
Ranked #6 of 20 in Best Vulnerability Scanner in 2026.
Free tierOpen sourcePublished pricingEurope
Aikido is the European answer to the developer-security platforms: connect the repositories and cloud accounts, and within an hour you have findings ranked with much of the noise already removed. The published plans and free tier make it the cheapest way to cover several scanner types at once.
The catch is depth. Each individual scanner is thinner than the specialist, and apart from cloud virtual machines on the higher plans, it looks at what you build rather than at the servers and devices you run.
What stands out
Belgian company
Free tier
Noise filtering
Where it costs you
No internal network scanning; host coverage stops at cloud virtual machines
Breadth comes before depth in each scanner
Right for
Software teams wanting one scanner for code, dependencies and cloud
Wrong for
Security teams scanning internal servers and network devices
BelgiumFree tier; plans from 300 dollars a month including ten users, published
Swedish platform covering network assets, web apps and phishing
Ranked #7 of 20 in Best Vulnerability Scanner in 2026.
Pricing on requestEurope
The argument for Holm Security is jurisdiction plus breadth: a single European supplier covering network assets and web applications, hosting the results in the EU, which matters because a vulnerability database is a target list for your own estate.
Against it, the depth on custom applications does not reach Burp Suite Enterprise or Detectify, and the infrastructure feed does not match Tenable. Suitable as the main platform for a mid-sized estate, not for a bank's public application.
What stands out
EU hosting
Systems and web
Nordic vendor
Where it costs you
Check feed is smaller than the American platforms'
No published pricing
Right for
Nordic and EU organisations wanting scan data hosted in Europe
Scanning, external attack surface and threat intelligence from one supplier
Ranked #8 of 20 in Best Vulnerability Scanner in 2026.
Pricing on requestEurope
Outpost24 works as a supplier relationship rather than as a tool. If you want European scanning, external attack surface discovery and some threat intelligence on one contract, with an analyst you can call, that is a real and reasonable purchase.
If you want one scanner, the modular structure makes you pay for a platform. Ask precisely which module contains each capability in the demonstration, because the boundaries are not obvious from the marketing.
What stands out
EU vendor
Modular platform
Managed option
Where it costs you
Acquired modules do not feel like one product
Cost escalates as modules are added
Right for
Mid-market European buyers consolidating several security services
Wrong for
Teams that only need one scanner and a clean price
SwedenQuoted per organisation; modules priced separately
British scanner covering web applications and infrastructure with authenticated crawling
Ranked #9 of 20 in Best Vulnerability Scanner in 2026.
Pricing on requestEurope
AppCheck sits between Intruder and Burp Suite Enterprise: broader than Burp because it scans infrastructure as well as applications, deeper than Intruder on authenticated web testing.
Scripting a login sequence once in GoScript and replaying it on a schedule is what makes it useful on real applications. It is a UK company, which suits buyers who want a European contract. Check how findings export to your ticketing system and whether the target count in the quote matches your estate.
What stands out
UK company
Web and infrastructure
Authenticated scanning
Where it costs you
Quoted pricing without a public list
Smaller user community outside the UK
Right for
UK and European organisations wanting web and infrastructure scanning together
Wrong for
Developer teams wanting dependency scanning in pull requests
United KingdomQuoted per organisation by target count
Application scanning built on real payloads, not version banners
Ranked #10 of 20 in Best Vulnerability Scanner in 2026.
Published pricingEurope
Detectify made a specific bet: verify by exploiting, not by fingerprinting, and buy the research from a community of testers. The consequence is a low false positive rate, which is the single thing that decides whether developers keep reading the reports.
The consequences are also narrow coverage and awkward economics. It scans what faces the web, plus internal systems through agents on the Enterprise plan, and an estate of two hundred marketing domains prices badly under a per-domain model.
What stands out
Web application focus
Crowdsourced research
Few false positives
Where it costs you
No authenticated host or patch-level scanning
Per-domain pricing hurts organisations with many small sites
Right for
Product teams protecting a handful of important web applications
Wrong for
Covering servers, endpoints or internal infrastructure
SwedenPlatform fee from 2,500 euros a year, published, plus fees per domain and per scanned target; Starter tier waives the platform fee
Application and API scanning that runs in the developer's pipeline
Ranked #11 of 20 in Best Vulnerability Scanner in 2026.
Published pricingNorth America
StackHawk puts dynamic testing where developers already work, running against a local or staging build and reporting in the pull request, which is where a fix costs least. API testing from an OpenAPI or GraphQL definition is well handled.
It is a developer tool first: reporting for a central security team needs the larger quoted plan, deep crawling of awkward login flows is not its strength, and it says nothing about the servers the application runs on.
What stands out
Developer DAST
API testing
CI integration
Where it costs you
No network, host or dependency scanning
Complex authenticated crawling is weaker than Burp Suite Enterprise Edition
Right for
Development teams wanting application and API tests on every pull request
Wrong for
Infrastructure teams needing coverage of servers and network devices
United States10 dollars per user per month, published; organisation-wide plan quoted
The tester's scanner, automated across an entire application estate
Ranked #12 of 20 in Best Vulnerability Scanner in 2026.
Pricing on requestEurope
PortSwigger quotes subscriptions by scanning capacity, from hours of ad hoc scanning to unlimited, with no limit on users, so the cost is driven by how much you scan rather than by how many applications you own, which suits a company with many small services.
The crawler handles single-page applications and authenticated flows better than anything else here. The maintenance burden is the recorded logins: they break when the application changes, and a broken login means a clean report that scanned only the front page.
What stands out
Deep DAST
Unlimited users
CI integration
Where it costs you
Application scanning only
Login sequences must be recorded and maintained per target
Right for
Engineering organisations scanning authenticated applications in the pipeline
Wrong for
Infrastructure teams needing network and host coverage
United KingdomQuoted subscription, from hourly ad hoc scanning to unlimited; unlimited users
Every finding validated by an analyst before it reaches you
Ranked #13 of 20 in Best Vulnerability Scanner in 2026.
Pricing on requestEurope
Edgescan's product is a person. Findings are checked before they reach you, so a critical in the queue is a critical, and the conversation with engineering changes completely as a result.
That is worth paying for when nobody internally has time to separate the real from the theoretical. It is money wasted when you do have that capacity, and the validation step means you learn about an exposure hours later than a raw scanner would tell you.
What stands out
Validated findings
Irish vendor
Managed service
Where it costs you
Higher cost per asset than self-service tools
Validation adds delay between scan and report
Right for
Teams with no capacity to triage raw scanner output themselves
Wrong for
Organisations with their own analysts already doing triage
IrelandPer asset per year, quoted; validation included
Agentless scanning of cloud workloads, images and configurations
Ranked #14 of 20 in Best Vulnerability Scanner in 2026.
Pricing on requestMiddle East
Orca's side-scanning reads a snapshot of each cloud disk through the provider's API, so coverage does not depend on agents being installed, and forgotten machines show up on the first day.
Combining vulnerability, configuration and exposure data cuts the queue to what is reachable. The trade is that results arrive on a scan cycle rather than live, nothing on premises is visible, and the scanner is priced as part of a suite you may not want.
What stands out
Agentless
Cloud workloads
Attack path context
Where it costs you
No coverage of on-premises networks or offices
Scanner is bought as part of a larger quoted platform
Right for
Cloud-first organisations wanting coverage of every workload without deploying agents
Wrong for
Estates that are mostly on-premises servers and network devices
IsraelQuoted per organisation; sold as a cloud security platform
Enterprise web application and API scanner with proof-based confirmation
Ranked #15 of 20 in Best Vulnerability Scanner in 2026.
Pricing on requestNorth America
Invicti's proof-based scanning answers the main complaint about dynamic scanners: that half the output is false. For many vulnerability classes it proves the issue exists, which saves a triage step.
It sells to large estates, with application discovery and integrations into issue trackers and pipelines. The downsides are cost and scope. Quotes grow with coverage, Acunetix is now sold as Invicti Web + API so check which package a quote covers, and host and network scanning are outside the product.
What stands out
Proof-based scanning
API discovery
Enterprise DAST
Where it costs you
Quoted pricing that grows with package and coverage
No network or host scanning
Right for
Enterprises with large web application estates and an AppSec team
Wrong for
Small teams with a handful of sites and no budget
United StatesQuoted by package, from Web + API to the full AppSec platform; agentic pentest priced per test on the site
Dependency and container scanning inside the developer's pull request
Ranked #16 of 20 in Best Vulnerability Scanner in 2026.
Free tierPublished pricingNorth America
Software composition analysis is a separate discipline from scanning machines, and Snyk is the most widely adopted way to do it. Its advantage is placement: the finding appears in the pull request, with the version to upgrade to, before the code merges.
The weaknesses are noise from vulnerabilities in code paths you never call, and a licence model tied to contributing developers, which turns a growing engineering team into a growing security bill.
What stands out
Dependency scanning
Free tier
Developer workflow
Where it costs you
Says nothing about network or host vulnerabilities
Per-developer pricing rises steeply with engineering headcount
Right for
Engineering teams fixing vulnerable dependencies during code review
Wrong for
Anyone trying to cover servers and network devices
United StatesFree tier; Team plan from 25 dollars a month for up to ten developers, published; enterprise credits quoted
Agentless cloud security platform with vulnerability scanning built in
Ranked #17 of 20 in Best Vulnerability Scanner in 2026.
Self-hostablePricing on requestNorth America
Wiz connects to cloud accounts through their APIs and builds a graph of workloads, identities, network exposure and vulnerabilities, so a finding arrives with the path an attacker would use to reach it.
That context is why its queue is shorter than a traditional scanner's. It is a platform sold in quoted modules, the scanner is only part of it, and its move into Google Cloud raises a fair question about neutrality across clouds.
What stands out
Agentless
Multi-cloud
Security graph
Where it costs you
Cloud only: nothing for on-premises networks
Modular quoted licensing that grows with every module
Right for
Cloud security teams on several providers wanting one agentless view
Wrong for
Organisations whose risk sits in offices and data centres
United StatesQuoted and modular; scales with workloads, developers, log ingestion or sensors
Dependency and code scanning inside GitHub pull requests
Ranked #18 of 20 in Best Vulnerability Scanner in 2026.
Published pricingNorth America
For a team already on GitHub this is the scanner with the least friction: Dependabot opens the update pull request, CodeQL flags the vulnerable code path, and both appear where review already happens. Dependabot alerts cost nothing.
The paid add-on counts active committers, which becomes expensive in a large engineering organisation, the checks stop at the repository boundary, and code hosted elsewhere is outside its view entirely.
What stands out
Dependabot
CodeQL
Pull request
Where it costs you
Covers only repositories hosted on GitHub
Per-committer pricing rises with every contributor
Right for
Development teams on GitHub wanting dependency and code scanning in pull requests
Wrong for
Security teams needing coverage of servers, networks or running applications
United StatesCode Security 30 dollars per active committer per month, published; add-on to GitHub Team or Enterprise, free on public repositories
Asset-based scanning with remediation tracked as assigned work
Ranked #19 of 20 in Best Vulnerability Scanner in 2026.
Pricing on requestNorth America
InsightVM's distinguishing feature is that it treats fixing as the workflow rather than as an afterthought: projects, owners, deadlines and progress against them, exported to the ticket system engineering actually uses.
Pricing now comes as a quote for an Exposure Command package, so budgeting starts with a sales call. Against that, the product assumes a dedicated security function, the learning curve is steep for a team of one, and Rapid7's account managers will propose the detection and response platform within the first quarter.
What stands out
Part of Exposure Command
Remediation projects
Agent-based
Where it costs you
Console and data model take weeks to learn
Heavy cross-selling of the wider platform
Right for
Security teams that need remediation ownership, not just findings
Wrong for
Small estates where a simple external scanner suffices
United StatesQuoted; sold within Exposure Command packages on consumption-based pricing
Scanning at estate scale, with a module for everything
Ranked #20 of 20 in Best Vulnerability Scanner in 2026.
Pricing on requestNorth America
At tens of thousands of assets, Qualys does things the smaller tools cannot: agents that report from anywhere, scanning appliances per site, and compliance evidence in the format auditors expect. It earns its place in a large regulated estate.
The purchase is a negotiation about modules rather than a price, the console is a museum of interface generations, and rolling it out is a programme with a project manager, not an afternoon of configuration.
What stands out
Large estates
Cloud agents
Module pricing
Where it costs you
Every capability is a separately licensed module
Interface shows two decades of accumulated features
Right for
Large distributed estates that need agents everywhere and compliance reports
Wrong for
Small organisations wanting a scanner without a project
United StatesPer asset per year, quoted; modules priced separately
A vulnerability scanner checks systems, applications and dependencies against a feed of known flaws, then reports which ones your environment appears to have. The differences that matter are rarely in the feature list, so this is
the order we would work through them.
01
Decide whether you need a published price
10 of the 20 tools here publish what they cost; the other 10 quote per organisation. The ones you can compare without a sales call: Greenbone, Intruder, Pentest-Tools.com, ProjectDiscovery, Tenable Nessus and Vulnerability Management, Aikido Security, Detectify, StackHawk, Snyk, GitHub Code Security.
02
Decide how much the jurisdiction matters
These 20 vendors are established in 8 countries across 3 regions (Europe 10, North America 9, Middle East 1). That decides whose disclosure law applies to what the vendor holds, wherever the servers are.
03
Consider whether you want the source
3 of these are open source: Greenbone, ProjectDiscovery, Aikido Security. Hosting one yourself trades a subscription for maintenance.
Three different scanners share the same word
Buyers ask for a vulnerability scanner and mean one of three products. Infrastructure scanning checks servers, network devices and operating systems against a feed of known flaws: Greenbone, Tenable Nessus, Rapid7 InsightVM and Qualys VMDR. Application scanning drives your web application like an attacker and watches what happens: Burp Suite Enterprise Edition and Detectify.
Dependency scanning reads your manifests and container images and finds the vulnerable library you shipped: Snyk. No single product does all three well, and the vendors who claim to do so are strong in one and adequate in the others. Decide which risk keeps you awake, buy the specialist for that, and add the second scanner in the next budget round.
Write down which of the three you are actually buying before the first demo.
Check whether application scanning is included or a separate line item.
Ask what the tool sees about a container that never touches your network.
Authenticated scanning shows a completely different machine
An unauthenticated scan sees what an outsider sees: open ports, banners, exposed services. An authenticated scan logs in and reads the installed package versions, and it typically finds several times more issues, most of them real. The gap is not marginal, it is the difference between guessing from a version string and reading the patch level.
Every serious platform here supports it, and getting it working is the actual project: service accounts, credential storage, and a change advisory board that does not want a scanner holding domain credentials. Rapid7 InsightVM and Qualys VMDR sidestep part of it with agents on the host. Greenbone and Tenable do it with credentials you must manage yourself.
Compare an authenticated and an unauthenticated scan of the same host during the trial.
Decide early whether you deploy agents or hand out scanning credentials.
Store scanner credentials in the vault, and rotate them like any other privileged account.
The false positive rate decides whether anyone reads the output
A scanner that reports four thousand issues, of which six hundred are wrong, does not get fixed. It gets ignored, then muted, then cancelled. This is the quiet reason Detectify verifies with a payload instead of a version banner, and the entire commercial argument for Edgescan, which pays analysts to validate findings before you see them.
Intruder attacks the same problem by reporting less. The platforms with the broadest feeds, Tenable and Qualys VMDR, produce the most noise by design, because the feed is their strength. Whichever you buy, measure it: take fifty findings from the trial, verify them by hand, and count how many were real.
Verify fifty trial findings manually and record the false positive count.
Ask how the vendor confirms a finding: version match, or working payload.
Check whether a suppressed finding stays suppressed after the next rescan.
What the licence counts, and what that does at scale
Every vendor here counts something different, and the unit decides your three-year bill. Intruder counts targets. Detectify adds domains and targets to a platform fee. Rapid7 InsightVM, Qualys VMDR and Holm Security count assets, which raises the question of what a short-lived cloud instance counts as. Burp Suite Enterprise Edition counts scanning capacity.
Snyk counts contributing developers, so a hiring plan is a security budget. Greenbone's community edition counts nothing, which is why it opens this list. Ask the counting question before the feature questions, then model it against your estate in three years, not today. Ask about exit at the same time: findings history should leave through an API in a format you can read without the vendor.
Model the licence unit against your projected estate, not the current one.
Ask specifically how ephemeral cloud instances and containers are counted.
Confirm the finding history exports through an open API before you sign.
What goes wrong most often when buying vulnerability scanning software
Scanning only the perimeter. Most incidents move sideways inside the network, where an unauthenticated external scan sees nothing at all.
Buying on the number of checks in the feed. A large feed produces a large queue, and the queue is the thing that kills the programme.
Leaving scanning unauthenticated because credentials were hard to arrange. It halves what you see and makes the clean report meaningless.
Measuring the programme by scans run rather than by issues closed. Nobody was ever breached through a vulnerability that was merely detected.
07
Frequently asked questions
8 answers
What is the best vulnerability scanning in 2026?
Greenbone leads our ranking of 20. The scanner behind OpenVAS, maintained in Germany, with a feed of network vulnerability tests you can run inside your own network and never send a result outside it. Only the open-source Nuclei engine from ProjectDiscovery comes close to that independence.
The interface is dated, the free community feed covers only a fraction of the paid one, with no checks for enterprise products such as Cisco or Exchange, and there is no serious application scanning, so it covers one third of the problem.
Which vulnerability scanning tools publish their pricing?
10 of the 20, with the pricing model each one publishes:
Greenbone: Free community edition; OPENVAS BASIC virtual appliance 2,524 euros a year, published; larger appliances quoted.
Intruder: Free plan; paid plans a base fee plus a fee per target, monthly or annual, published; enterprise quoted.
Pentest-Tools.com: Free edition; paid plans from 95 dollars a month for five assets, published; unlimited scans on those assets.
ProjectDiscovery: Free open-source engine and a limited free platform plan; 200 to 800 dollars per seat per month, published; enterprise quoted.
Tenable Nessus and Vulnerability Management: Nessus Professional 4,790 dollars per licence per year, published; platform per asset, published up to 250 assets.
Aikido Security: Free tier; plans from 300 dollars a month including ten users, published.
Detectify: Platform fee from 2,500 euros a year, published, plus fees per domain and per scanned target; Starter tier waives the platform fee.
StackHawk: 10 dollars per user per month, published; organisation-wide plan quoted.
Snyk: Free tier; Team plan from 25 dollars a month for up to ten developers, published; enterprise credits quoted.
GitHub Code Security: Code Security 30 dollars per active committer per month, published; add-on to GitHub Team or Enterprise, free on public repositories.
The other 10 quote per organisation.
Is there a free vulnerability scanning tool?
Greenbone, Intruder, Pentest-Tools.com, ProjectDiscovery, Aikido Security, Snyk offer a free tier or a free self-hosted edition.
Where are these vulnerability scanning vendors established?
In 8 countries across 3 regions: Europe 10, North America 9, Middle East 1.
Greenbone: Germany.
Intruder: United Kingdom.
Pentest-Tools.com: Romania.
ProjectDiscovery: United States.
Tenable Nessus and Vulnerability Management: United States.
Aikido Security: Belgium.
Holm Security: Sweden.
Outpost24: Sweden.
AppCheck: United Kingdom.
Detectify: Sweden.
StackHawk: United States.
Burp Suite DAST: United Kingdom.
Edgescan: Ireland.
Orca Security: Israel.
Invicti: United States.
Snyk: United States.
Wiz: United States.
GitHub Code Security: United States.
Rapid7 InsightVM: United States.
Qualys VMDR: United States.
Which vulnerability scanning tools are open source?
Greenbone, ProjectDiscovery, Aikido Security.
Which vulnerability scanning tools can you host yourself?
Greenbone, Wiz. The other 18 are hosted by the vendor only.
What should you use instead of Greenbone?
Intruder and Pentest-Tools.com are the next two on this page. Intruder is for small companies with an external footprint and no security team; Pentest-Tools.com is for Consultants and tiny teams running periodic external assessments.
Who should not buy Greenbone?
Organisations that need application and dependency coverage too. No meaningful web application scanning.
If your vulnerability scanning product belongs among these 20, tell us what it does and who it is for. Inclusion is an editorial call; what a listing is and is not is set out under software advice.