Best Vulnerability Scanner in 2026

A vulnerability scanner finds the known holes in what you already run, which is a different job from stopping an attack in progress.

This guide ranks the scanners on what they can actually see, how much of the output is real, and what the licence counts when your estate grows: assets, targets, domains or developers.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. How that works.

In short

What vulnerability scanning software does

A vulnerability scanner checks systems, applications and dependencies against a feed of known flaws, then reports which ones your environment appears to have.

01

The top three

20 tools reviewed
02

How we ranked these

5 criteria, in order

In this order: setup effort, what it really costs, how your data comes back out, whether you can leave, and who each vulnerability scanning tool is built for. Why those five, and why there is no score out of ten, is on the how we work page.

20tools reviewed
10publish a price
6have a free tier
8countries represented
03

Compared at a glance

20 tools
#ToolCountryPricingFree tier Right forNot for
#1GreenboneGermanyFree community edition; OPENVAS BASIC virtual appliance 2,524 euros a year, published; larger appliances quotedYesTeams that must keep scan results inside their own networkOrganisations that need application and dependency coverage too
#2IntruderUnited KingdomFree plan; paid plans a base fee plus a fee per target, monthly or annual, published; enterprise quotedYesSmall companies with an external footprint and no security teamMature security teams needing deep configuration control
#3Pentest-Tools.comRomaniaFree edition; paid plans from 95 dollars a month for five assets, published; unlimited scans on those assetsYesConsultants and tiny teams running periodic external assessmentsRunning a continuous programme across a large estate
#4ProjectDiscoveryUnited StatesFree open-source engine and a limited free platform plan; 200 to 800 dollars per seat per month, published; enterprise quotedYesSecurity engineers who want scriptable external and web scanning they controlTeams wanting a managed programme with remediation tracking
#5Tenable Nessus and Vulnerability ManagementUnited StatesNessus Professional 4,790 dollars per licence per year, published; platform per asset, published up to 250 assets—Infrastructure teams that want the widest check coverage availableBuyers wanting one tool to cover apps and dependencies
#6Aikido SecurityBelgiumFree tier; plans from 300 dollars a month including ten users, publishedYesSoftware teams wanting one scanner for code, dependencies and cloudSecurity teams scanning internal servers and network devices
#7Holm SecuritySwedenPer asset per year, quoted—Nordic and EU organisations wanting scan data hosted in EuropeDeep testing of complex custom web applications
#8Outpost24SwedenQuoted per organisation; modules priced separately—Mid-market European buyers consolidating several security servicesTeams that only need one scanner and a clean price
#9AppCheckUnited KingdomQuoted per organisation by target count—UK and European organisations wanting web and infrastructure scanning togetherDeveloper teams wanting dependency scanning in pull requests
#10DetectifySwedenPlatform fee from 2,500 euros a year, published, plus fees per domain and per scanned target; Starter tier waives the platform fee—Product teams protecting a handful of important web applicationsCovering servers, endpoints or internal infrastructure
#11StackHawkUnited States10 dollars per user per month, published; organisation-wide plan quoted—Development teams wanting application and API tests on every pull requestInfrastructure teams needing coverage of servers and network devices
#12Burp Suite DASTUnited KingdomQuoted subscription, from hourly ad hoc scanning to unlimited; unlimited users—Engineering organisations scanning authenticated applications in the pipelineInfrastructure teams needing network and host coverage
#13EdgescanIrelandPer asset per year, quoted; validation included—Teams with no capacity to triage raw scanner output themselvesOrganisations with their own analysts already doing triage
#14Orca SecurityIsraelQuoted per organisation; sold as a cloud security platform—Cloud-first organisations wanting coverage of every workload without deploying agentsEstates that are mostly on-premises servers and network devices
#15InvictiUnited StatesQuoted by package, from Web + API to the full AppSec platform; agentic pentest priced per test on the site—Enterprises with large web application estates and an AppSec teamSmall teams with a handful of sites and no budget
#16SnykUnited StatesFree tier; Team plan from 25 dollars a month for up to ten developers, published; enterprise credits quotedYesEngineering teams fixing vulnerable dependencies during code reviewAnyone trying to cover servers and network devices
#17WizUnited StatesQuoted and modular; scales with workloads, developers, log ingestion or sensors—Cloud security teams on several providers wanting one agentless viewOrganisations whose risk sits in offices and data centres
#18GitHub Code SecurityUnited StatesCode Security 30 dollars per active committer per month, published; add-on to GitHub Team or Enterprise, free on public repositories—Development teams on GitHub wanting dependency and code scanning in pull requestsSecurity teams needing coverage of servers, networks or running applications
#19Rapid7 InsightVMUnited StatesQuoted; sold within Exposure Command packages on consumption-based pricing—Security teams that need remediation ownership, not just findingsSmall estates where a simple external scanner suffices
#20Qualys VMDRUnited StatesPer asset per year, quoted; modules priced separately—Large distributed estates that need agents everywhere and compliance reportsSmall organisations wanting a scanner without a project

Country is where the vendor is headquartered or contracts from, which is a different question from where your data is hosted. Where the two tell different stories, the entry says so.

04

The 20 tools, reviewed

Ranked

1. Greenbone · 2. Intruder · 3. Pentest-Tools.com · 4. ProjectDiscovery · 5. Tenable Nessus and Vulnerability Management · 6. Aikido Security · 7. Holm Security · 8. Outpost24 · 9. AppCheck · 10. Detectify · 11. StackHawk · 12. Burp Suite DAST · 13. Edgescan · 14. Orca Security · 15. Invicti · 16. Snyk · 17. Wiz · 18. GitHub Code Security · 19. Rapid7 InsightVM · 20. Qualys VMDR

#1 Greenbone

Open source network scanning you run on hardware you own

Ranked #1 of 20 in Best Vulnerability Scanner in 2026.

Free tierOpen sourceSelf-hostablePublished pricingEurope

Greenbone is the only full network scanner here you can run entirely on your own hardware, with no vendor holding a list of your unpatched machines. For a hospital, a utility or anyone with an air-gapped segment, that is the deciding fact.

In exchange you accept an interface built by engineers for engineers, a feed that is good on infrastructure and weak on modern web stacks, and no help with triage. Budget staff time instead of licence fees.

What stands out
  • Open source
  • Self-hosted
  • German vendor
Where it costs you
  • No meaningful web application scanning
  • Community feed covers only a fraction of the enterprise feed
Right for

Teams that must keep scan results inside their own network

Wrong for

Organisations that need application and dependency coverage too

GermanyFree community edition; OPENVAS BASIC virtual appliance 2,524 euros a year, published; larger appliances quoted

#2 Intruder

Continuous external scanning with findings a non-specialist can act on

Ranked #2 of 20 in Best Vulnerability Scanner in 2026.

Free tierPublished pricingEurope

Intruder is the best purchase for a company whose entire security function is one engineer with other responsibilities. It watches the internet-facing estate continuously, on the Pro plan rescans within hours when something critical is disclosed, and writes findings in language a developer can act on without a translation layer.

The limits arrive when you grow: internal authenticated scanning across thousands of hosts, custom check tuning and detailed compliance evidence all push you towards the platforms lower on this page.

What stands out
  • Published price
  • External surface
  • Low noise
Where it costs you
  • Limited depth for large internal networks
  • Advanced tuning options are intentionally hidden
Right for

Small companies with an external footprint and no security team

Wrong for

Mature security teams needing deep configuration control

United KingdomFree plan; paid plans a base fee plus a fee per target, monthly or annual, published; enterprise quoted

#3 Pentest-Tools.com

Hosted scanner toolkit and reporting for very small teams

Ranked #3 of 20 in Best Vulnerability Scanner in 2026.

Free tierPublished pricingEurope

This is a toolkit with reporting, not a management platform, and it is honest about that. For an agency producing client assessments, or an internal team that scans quarterly and needs a document at the end, the economics are excellent and the reports need little rewriting.

Scan diffs, an asset workspace and a Jira integration are there, but it is still built around running scans rather than managing who owns each asset and who is fixing what.

What stands out
  • Published price
  • Report templates
  • Consultant friendly
Where it costs you
  • Ownership and remediation tracking are thin
  • Plans are capped by the number of assets scanned
Right for

Consultants and tiny teams running periodic external assessments

Wrong for

Running a continuous programme across a large estate

RomaniaFree edition; paid plans from 95 dollars a month for five assets, published; unlimited scans on those assets

#4 ProjectDiscovery

The open-source Nuclei scanner, with an AI pentesting platform on top

Ranked #4 of 20 in Best Vulnerability Scanner in 2026.

Free tierOpen sourcePublished pricingNorth America

Nuclei turns a vulnerability check into a short YAML file, which means you can read exactly what a finding is based on and write your own for the service only you run. That transparency is the argument, and the open-source engine keeps working without the vendor.

The limits are scope and discipline: it looks at what answers on the network, not at installed package versions, and running every community template produces noise someone has to tune away.

What stands out
  • Open source
  • Template-based checks
  • External surface
Where it costs you
  • No authenticated patch-level scanning of hosts
  • Template quality varies, so noise depends on curation
Right for

Security engineers who want scriptable external and web scanning they control

Wrong for

Teams wanting a managed programme with remediation tracking

United StatesFree open-source engine and a limited free platform plan; 200 to 800 dollars per seat per month, published; enterprise quoted

#5 Tenable Nessus and Vulnerability Management

The infrastructure scanner every other vendor is measured against

Ranked #5 of 20 in Best Vulnerability Scanner in 2026.

Published pricingNorth America

Nessus is where most people start and many stay: the check feed is the broadest in the industry, and a professional licence costs 4,790 dollars a year, the price of a few days of consultancy. The trouble starts at scale.

The managed platform prices per asset, cloud instances that live for an hour still count somewhere, and the default output is enormous. Plan for a quarter of tuning, exclusions and ownership mapping before anyone believes the dashboard.

What stands out
  • Largest check feed
  • Published Nessus price
  • Wide integrations
Where it costs you
  • Findings volume needs real tuning effort
  • Web application scanning needs Nessus Expert or a separate licence
Right for

Infrastructure teams that want the widest check coverage available

Wrong for

Buyers wanting one tool to cover apps and dependencies

United StatesNessus Professional 4,790 dollars per licence per year, published; platform per asset, published up to 250 assets

#6 Aikido Security

Belgian platform bundling code, dependency, container and cloud scanning

Ranked #6 of 20 in Best Vulnerability Scanner in 2026.

Free tierOpen sourcePublished pricingEurope

Aikido is the European answer to the developer-security platforms: connect the repositories and cloud accounts, and within an hour you have findings ranked with much of the noise already removed. The published plans and free tier make it the cheapest way to cover several scanner types at once.

The catch is depth. Each individual scanner is thinner than the specialist, and apart from cloud virtual machines on the higher plans, it looks at what you build rather than at the servers and devices you run.

What stands out
  • Belgian company
  • Free tier
  • Noise filtering
Where it costs you
  • No internal network scanning; host coverage stops at cloud virtual machines
  • Breadth comes before depth in each scanner
Right for

Software teams wanting one scanner for code, dependencies and cloud

Wrong for

Security teams scanning internal servers and network devices

BelgiumFree tier; plans from 300 dollars a month including ten users, published

#7 Holm Security

Swedish platform covering network assets, web apps and phishing

Ranked #7 of 20 in Best Vulnerability Scanner in 2026.

Pricing on requestEurope

The argument for Holm Security is jurisdiction plus breadth: a single European supplier covering network assets and web applications, hosting the results in the EU, which matters because a vulnerability database is a target list for your own estate.

Against it, the depth on custom applications does not reach Burp Suite Enterprise or Detectify, and the infrastructure feed does not match Tenable. Suitable as the main platform for a mid-sized estate, not for a bank's public application.

What stands out
  • EU hosting
  • Systems and web
  • Nordic vendor
Where it costs you
  • Check feed is smaller than the American platforms'
  • No published pricing
Right for

Nordic and EU organisations wanting scan data hosted in Europe

Wrong for

Deep testing of complex custom web applications

SwedenPer asset per year, quoted

#8 Outpost24

Scanning, external attack surface and threat intelligence from one supplier

Ranked #8 of 20 in Best Vulnerability Scanner in 2026.

Pricing on requestEurope

Outpost24 works as a supplier relationship rather than as a tool. If you want European scanning, external attack surface discovery and some threat intelligence on one contract, with an analyst you can call, that is a real and reasonable purchase.

If you want one scanner, the modular structure makes you pay for a platform. Ask precisely which module contains each capability in the demonstration, because the boundaries are not obvious from the marketing.

What stands out
  • EU vendor
  • Modular platform
  • Managed option
Where it costs you
  • Acquired modules do not feel like one product
  • Cost escalates as modules are added
Right for

Mid-market European buyers consolidating several security services

Wrong for

Teams that only need one scanner and a clean price

SwedenQuoted per organisation; modules priced separately

#9 AppCheck

British scanner covering web applications and infrastructure with authenticated crawling

Ranked #9 of 20 in Best Vulnerability Scanner in 2026.

Pricing on requestEurope

AppCheck sits between Intruder and Burp Suite Enterprise: broader than Burp because it scans infrastructure as well as applications, deeper than Intruder on authenticated web testing.

Scripting a login sequence once in GoScript and replaying it on a schedule is what makes it useful on real applications. It is a UK company, which suits buyers who want a European contract. Check how findings export to your ticketing system and whether the target count in the quote matches your estate.

What stands out
  • UK company
  • Web and infrastructure
  • Authenticated scanning
Where it costs you
  • Quoted pricing without a public list
  • Smaller user community outside the UK
Right for

UK and European organisations wanting web and infrastructure scanning together

Wrong for

Developer teams wanting dependency scanning in pull requests

United KingdomQuoted per organisation by target count

#10 Detectify

Application scanning built on real payloads, not version banners

Ranked #10 of 20 in Best Vulnerability Scanner in 2026.

Published pricingEurope

Detectify made a specific bet: verify by exploiting, not by fingerprinting, and buy the research from a community of testers. The consequence is a low false positive rate, which is the single thing that decides whether developers keep reading the reports.

The consequences are also narrow coverage and awkward economics. It scans what faces the web, plus internal systems through agents on the Enterprise plan, and an estate of two hundred marketing domains prices badly under a per-domain model.

What stands out
  • Web application focus
  • Crowdsourced research
  • Few false positives
Where it costs you
  • No authenticated host or patch-level scanning
  • Per-domain pricing hurts organisations with many small sites
Right for

Product teams protecting a handful of important web applications

Wrong for

Covering servers, endpoints or internal infrastructure

SwedenPlatform fee from 2,500 euros a year, published, plus fees per domain and per scanned target; Starter tier waives the platform fee

#11 StackHawk

Application and API scanning that runs in the developer's pipeline

Ranked #11 of 20 in Best Vulnerability Scanner in 2026.

Published pricingNorth America

StackHawk puts dynamic testing where developers already work, running against a local or staging build and reporting in the pull request, which is where a fix costs least. API testing from an OpenAPI or GraphQL definition is well handled.

It is a developer tool first: reporting for a central security team needs the larger quoted plan, deep crawling of awkward login flows is not its strength, and it says nothing about the servers the application runs on.

What stands out
  • Developer DAST
  • API testing
  • CI integration
Where it costs you
  • No network, host or dependency scanning
  • Complex authenticated crawling is weaker than Burp Suite Enterprise Edition
Right for

Development teams wanting application and API tests on every pull request

Wrong for

Infrastructure teams needing coverage of servers and network devices

United States10 dollars per user per month, published; organisation-wide plan quoted

#12 Burp Suite DAST

The tester's scanner, automated across an entire application estate

Ranked #12 of 20 in Best Vulnerability Scanner in 2026.

Pricing on requestEurope

PortSwigger quotes subscriptions by scanning capacity, from hours of ad hoc scanning to unlimited, with no limit on users, so the cost is driven by how much you scan rather than by how many applications you own, which suits a company with many small services.

The crawler handles single-page applications and authenticated flows better than anything else here. The maintenance burden is the recorded logins: they break when the application changes, and a broken login means a clean report that scanned only the front page.

What stands out
  • Deep DAST
  • Unlimited users
  • CI integration
Where it costs you
  • Application scanning only
  • Login sequences must be recorded and maintained per target
Right for

Engineering organisations scanning authenticated applications in the pipeline

Wrong for

Infrastructure teams needing network and host coverage

United KingdomQuoted subscription, from hourly ad hoc scanning to unlimited; unlimited users

#13 Edgescan

Every finding validated by an analyst before it reaches you

Ranked #13 of 20 in Best Vulnerability Scanner in 2026.

Pricing on requestEurope

Edgescan's product is a person. Findings are checked before they reach you, so a critical in the queue is a critical, and the conversation with engineering changes completely as a result.

That is worth paying for when nobody internally has time to separate the real from the theoretical. It is money wasted when you do have that capacity, and the validation step means you learn about an exposure hours later than a raw scanner would tell you.

What stands out
  • Validated findings
  • Irish vendor
  • Managed service
Where it costs you
  • Higher cost per asset than self-service tools
  • Validation adds delay between scan and report
Right for

Teams with no capacity to triage raw scanner output themselves

Wrong for

Organisations with their own analysts already doing triage

IrelandPer asset per year, quoted; validation included

#14 Orca Security

Agentless scanning of cloud workloads, images and configurations

Ranked #14 of 20 in Best Vulnerability Scanner in 2026.

Pricing on requestMiddle East

Orca's side-scanning reads a snapshot of each cloud disk through the provider's API, so coverage does not depend on agents being installed, and forgotten machines show up on the first day.

Combining vulnerability, configuration and exposure data cuts the queue to what is reachable. The trade is that results arrive on a scan cycle rather than live, nothing on premises is visible, and the scanner is priced as part of a suite you may not want.

What stands out
  • Agentless
  • Cloud workloads
  • Attack path context
Where it costs you
  • No coverage of on-premises networks or offices
  • Scanner is bought as part of a larger quoted platform
Right for

Cloud-first organisations wanting coverage of every workload without deploying agents

Wrong for

Estates that are mostly on-premises servers and network devices

IsraelQuoted per organisation; sold as a cloud security platform

#15 Invicti

Enterprise web application and API scanner with proof-based confirmation

Ranked #15 of 20 in Best Vulnerability Scanner in 2026.

Pricing on requestNorth America

Invicti's proof-based scanning answers the main complaint about dynamic scanners: that half the output is false. For many vulnerability classes it proves the issue exists, which saves a triage step.

It sells to large estates, with application discovery and integrations into issue trackers and pipelines. The downsides are cost and scope. Quotes grow with coverage, Acunetix is now sold as Invicti Web + API so check which package a quote covers, and host and network scanning are outside the product.

What stands out
  • Proof-based scanning
  • API discovery
  • Enterprise DAST
Where it costs you
  • Quoted pricing that grows with package and coverage
  • No network or host scanning
Right for

Enterprises with large web application estates and an AppSec team

Wrong for

Small teams with a handful of sites and no budget

United StatesQuoted by package, from Web + API to the full AppSec platform; agentic pentest priced per test on the site

#16 Snyk

Dependency and container scanning inside the developer's pull request

Ranked #16 of 20 in Best Vulnerability Scanner in 2026.

Free tierPublished pricingNorth America

Software composition analysis is a separate discipline from scanning machines, and Snyk is the most widely adopted way to do it. Its advantage is placement: the finding appears in the pull request, with the version to upgrade to, before the code merges.

The weaknesses are noise from vulnerabilities in code paths you never call, and a licence model tied to contributing developers, which turns a growing engineering team into a growing security bill.

What stands out
  • Dependency scanning
  • Free tier
  • Developer workflow
Where it costs you
  • Says nothing about network or host vulnerabilities
  • Per-developer pricing rises steeply with engineering headcount
Right for

Engineering teams fixing vulnerable dependencies during code review

Wrong for

Anyone trying to cover servers and network devices

United StatesFree tier; Team plan from 25 dollars a month for up to ten developers, published; enterprise credits quoted

#17 Wiz

Agentless cloud security platform with vulnerability scanning built in

Ranked #17 of 20 in Best Vulnerability Scanner in 2026.

Self-hostablePricing on requestNorth America

Wiz connects to cloud accounts through their APIs and builds a graph of workloads, identities, network exposure and vulnerabilities, so a finding arrives with the path an attacker would use to reach it.

That context is why its queue is shorter than a traditional scanner's. It is a platform sold in quoted modules, the scanner is only part of it, and its move into Google Cloud raises a fair question about neutrality across clouds.

What stands out
  • Agentless
  • Multi-cloud
  • Security graph
Where it costs you
  • Cloud only: nothing for on-premises networks
  • Modular quoted licensing that grows with every module
Right for

Cloud security teams on several providers wanting one agentless view

Wrong for

Organisations whose risk sits in offices and data centres

United StatesQuoted and modular; scales with workloads, developers, log ingestion or sensors

#18 GitHub Code Security

Dependency and code scanning inside GitHub pull requests

Ranked #18 of 20 in Best Vulnerability Scanner in 2026.

Published pricingNorth America

For a team already on GitHub this is the scanner with the least friction: Dependabot opens the update pull request, CodeQL flags the vulnerable code path, and both appear where review already happens. Dependabot alerts cost nothing.

The paid add-on counts active committers, which becomes expensive in a large engineering organisation, the checks stop at the repository boundary, and code hosted elsewhere is outside its view entirely.

What stands out
  • Dependabot
  • CodeQL
  • Pull request
Where it costs you
  • Covers only repositories hosted on GitHub
  • Per-committer pricing rises with every contributor
Right for

Development teams on GitHub wanting dependency and code scanning in pull requests

Wrong for

Security teams needing coverage of servers, networks or running applications

United StatesCode Security 30 dollars per active committer per month, published; add-on to GitHub Team or Enterprise, free on public repositories

#19 Rapid7 InsightVM

Asset-based scanning with remediation tracked as assigned work

Ranked #19 of 20 in Best Vulnerability Scanner in 2026.

Pricing on requestNorth America

InsightVM's distinguishing feature is that it treats fixing as the workflow rather than as an afterthought: projects, owners, deadlines and progress against them, exported to the ticket system engineering actually uses.

Pricing now comes as a quote for an Exposure Command package, so budgeting starts with a sales call. Against that, the product assumes a dedicated security function, the learning curve is steep for a team of one, and Rapid7's account managers will propose the detection and response platform within the first quarter.

What stands out
  • Part of Exposure Command
  • Remediation projects
  • Agent-based
Where it costs you
  • Console and data model take weeks to learn
  • Heavy cross-selling of the wider platform
Right for

Security teams that need remediation ownership, not just findings

Wrong for

Small estates where a simple external scanner suffices

United StatesQuoted; sold within Exposure Command packages on consumption-based pricing

#20 Qualys VMDR

Scanning at estate scale, with a module for everything

Ranked #20 of 20 in Best Vulnerability Scanner in 2026.

Pricing on requestNorth America

At tens of thousands of assets, Qualys does things the smaller tools cannot: agents that report from anywhere, scanning appliances per site, and compliance evidence in the format auditors expect. It earns its place in a large regulated estate.

The purchase is a negotiation about modules rather than a price, the console is a museum of interface generations, and rolling it out is a programme with a project manager, not an afternoon of configuration.

What stands out
  • Large estates
  • Cloud agents
  • Module pricing
Where it costs you
  • Every capability is a separately licensed module
  • Interface shows two decades of accumulated features
Right for

Large distributed estates that need agents everywhere and compliance reports

Wrong for

Small organisations wanting a scanner without a project

United StatesPer asset per year, quoted; modules priced separately
06

How to choose vulnerability scanning software

A vulnerability scanner checks systems, applications and dependencies against a feed of known flaws, then reports which ones your environment appears to have. The differences that matter are rarely in the feature list, so this is the order we would work through them.

  1. 01

    Decide whether you need a published price

    10 of the 20 tools here publish what they cost; the other 10 quote per organisation. The ones you can compare without a sales call: Greenbone, Intruder, Pentest-Tools.com, ProjectDiscovery, Tenable Nessus and Vulnerability Management, Aikido Security, Detectify, StackHawk, Snyk, GitHub Code Security.

  2. 02

    Decide how much the jurisdiction matters

    These 20 vendors are established in 8 countries across 3 regions (Europe 10, North America 9, Middle East 1). That decides whose disclosure law applies to what the vendor holds, wherever the servers are.

  3. 03

    Consider whether you want the source

    3 of these are open source: Greenbone, ProjectDiscovery, Aikido Security. Hosting one yourself trades a subscription for maintenance.

Three different scanners share the same word

Buyers ask for a vulnerability scanner and mean one of three products. Infrastructure scanning checks servers, network devices and operating systems against a feed of known flaws: Greenbone, Tenable Nessus, Rapid7 InsightVM and Qualys VMDR. Application scanning drives your web application like an attacker and watches what happens: Burp Suite Enterprise Edition and Detectify.

Dependency scanning reads your manifests and container images and finds the vulnerable library you shipped: Snyk. No single product does all three well, and the vendors who claim to do so are strong in one and adequate in the others. Decide which risk keeps you awake, buy the specialist for that, and add the second scanner in the next budget round.

  • Write down which of the three you are actually buying before the first demo.
  • Check whether application scanning is included or a separate line item.
  • Ask what the tool sees about a container that never touches your network.

Authenticated scanning shows a completely different machine

An unauthenticated scan sees what an outsider sees: open ports, banners, exposed services. An authenticated scan logs in and reads the installed package versions, and it typically finds several times more issues, most of them real. The gap is not marginal, it is the difference between guessing from a version string and reading the patch level.

Every serious platform here supports it, and getting it working is the actual project: service accounts, credential storage, and a change advisory board that does not want a scanner holding domain credentials. Rapid7 InsightVM and Qualys VMDR sidestep part of it with agents on the host. Greenbone and Tenable do it with credentials you must manage yourself.

  • Compare an authenticated and an unauthenticated scan of the same host during the trial.
  • Decide early whether you deploy agents or hand out scanning credentials.
  • Store scanner credentials in the vault, and rotate them like any other privileged account.

The false positive rate decides whether anyone reads the output

A scanner that reports four thousand issues, of which six hundred are wrong, does not get fixed. It gets ignored, then muted, then cancelled. This is the quiet reason Detectify verifies with a payload instead of a version banner, and the entire commercial argument for Edgescan, which pays analysts to validate findings before you see them.

Intruder attacks the same problem by reporting less. The platforms with the broadest feeds, Tenable and Qualys VMDR, produce the most noise by design, because the feed is their strength. Whichever you buy, measure it: take fifty findings from the trial, verify them by hand, and count how many were real.

  • Verify fifty trial findings manually and record the false positive count.
  • Ask how the vendor confirms a finding: version match, or working payload.
  • Check whether a suppressed finding stays suppressed after the next rescan.

What the licence counts, and what that does at scale

Every vendor here counts something different, and the unit decides your three-year bill. Intruder counts targets. Detectify adds domains and targets to a platform fee. Rapid7 InsightVM, Qualys VMDR and Holm Security count assets, which raises the question of what a short-lived cloud instance counts as. Burp Suite Enterprise Edition counts scanning capacity.

Snyk counts contributing developers, so a hiring plan is a security budget. Greenbone's community edition counts nothing, which is why it opens this list. Ask the counting question before the feature questions, then model it against your estate in three years, not today. Ask about exit at the same time: findings history should leave through an API in a format you can read without the vendor.

  • Model the licence unit against your projected estate, not the current one.
  • Ask specifically how ephemeral cloud instances and containers are counted.
  • Confirm the finding history exports through an open API before you sign.

What goes wrong most often when buying vulnerability scanning software

  • Scanning only the perimeter. Most incidents move sideways inside the network, where an unauthenticated external scan sees nothing at all.
  • Buying on the number of checks in the feed. A large feed produces a large queue, and the queue is the thing that kills the programme.
  • Leaving scanning unauthenticated because credentials were hard to arrange. It halves what you see and makes the clean report meaningless.
  • Measuring the programme by scans run rather than by issues closed. Nobody was ever breached through a vulnerability that was merely detected.
07

Frequently asked questions

8 answers
What is the best vulnerability scanning in 2026?

Greenbone leads our ranking of 20. The scanner behind OpenVAS, maintained in Germany, with a feed of network vulnerability tests you can run inside your own network and never send a result outside it. Only the open-source Nuclei engine from ProjectDiscovery comes close to that independence.

The interface is dated, the free community feed covers only a fraction of the paid one, with no checks for enterprise products such as Cisco or Exchange, and there is no serious application scanning, so it covers one third of the problem.

Which vulnerability scanning tools publish their pricing?

10 of the 20, with the pricing model each one publishes:

  • Greenbone: Free community edition; OPENVAS BASIC virtual appliance 2,524 euros a year, published; larger appliances quoted.
  • Intruder: Free plan; paid plans a base fee plus a fee per target, monthly or annual, published; enterprise quoted.
  • Pentest-Tools.com: Free edition; paid plans from 95 dollars a month for five assets, published; unlimited scans on those assets.
  • ProjectDiscovery: Free open-source engine and a limited free platform plan; 200 to 800 dollars per seat per month, published; enterprise quoted.
  • Tenable Nessus and Vulnerability Management: Nessus Professional 4,790 dollars per licence per year, published; platform per asset, published up to 250 assets.
  • Aikido Security: Free tier; plans from 300 dollars a month including ten users, published.
  • Detectify: Platform fee from 2,500 euros a year, published, plus fees per domain and per scanned target; Starter tier waives the platform fee.
  • StackHawk: 10 dollars per user per month, published; organisation-wide plan quoted.
  • Snyk: Free tier; Team plan from 25 dollars a month for up to ten developers, published; enterprise credits quoted.
  • GitHub Code Security: Code Security 30 dollars per active committer per month, published; add-on to GitHub Team or Enterprise, free on public repositories.

The other 10 quote per organisation.

Is there a free vulnerability scanning tool?

Greenbone, Intruder, Pentest-Tools.com, ProjectDiscovery, Aikido Security, Snyk offer a free tier or a free self-hosted edition.

Where are these vulnerability scanning vendors established?

In 8 countries across 3 regions: Europe 10, North America 9, Middle East 1.

  • Greenbone: Germany.
  • Intruder: United Kingdom.
  • Pentest-Tools.com: Romania.
  • ProjectDiscovery: United States.
  • Tenable Nessus and Vulnerability Management: United States.
  • Aikido Security: Belgium.
  • Holm Security: Sweden.
  • Outpost24: Sweden.
  • AppCheck: United Kingdom.
  • Detectify: Sweden.
  • StackHawk: United States.
  • Burp Suite DAST: United Kingdom.
  • Edgescan: Ireland.
  • Orca Security: Israel.
  • Invicti: United States.
  • Snyk: United States.
  • Wiz: United States.
  • GitHub Code Security: United States.
  • Rapid7 InsightVM: United States.
  • Qualys VMDR: United States.
Which vulnerability scanning tools are open source?

Greenbone, ProjectDiscovery, Aikido Security.

Which vulnerability scanning tools can you host yourself?

Greenbone, Wiz. The other 18 are hosted by the vendor only.

What should you use instead of Greenbone?

Intruder and Pentest-Tools.com are the next two on this page. Intruder is for small companies with an external footprint and no security team; Pentest-Tools.com is for Consultants and tiny teams running periodic external assessments.

Who should not buy Greenbone?

Organisations that need application and dependency coverage too. No meaningful web application scanning.

—

Tools reviewed

20 products
—

More Data & IT software advice

16 guides

For software vendors

Not on this list?

If your vulnerability scanning product belongs among these 20, tell us what it does and who it is for. Inclusion is an editorial call; what a listing is and is not is set out under software advice.

Suggest a product →