Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

DerScanner is a user-friendly, officially CWE-Compatible tool that integrates the functionalities of static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA) within a single platform. This solution significantly enhances oversight of application and information system security, allowing users to assess both proprietary and open-source code seamlessly. By correlating findings from SAST and DAST, it enables the verification and prioritization of vulnerability remediation. Users can bolster their code integrity by addressing weaknesses in both their own and third-party software components. Moreover, it facilitates an impartial code review process through application analysis that is independent of developers. This tool effectively identifies vulnerabilities and undocumented features throughout all phases of the software development lifecycle. Additionally, it allows for oversight of both in-house and external developers while ensuring the security of legacy applications. Ultimately, DerScanner aims to improve user experience by delivering a well-functioning and secure application that meets modern security demands. With its comprehensive approach, organizations can feel confident in their software's resilience against threats.

Description

PVS-Studio is a static application security testing tool that enhances code quality, security, and safety. It helps find errors and potential vulnerabilities in C, C++, C#, Java, JavaScript, TypeScript and Go code. It works on Windows, Linux, and macOS. Pros: - Various analysis types: intermodular, incremental, data flow analysis, taint analysis; - Integrates into cloud platforms; - Works offline & on-premise; - Provides cross-platform integration; - Offers ways to handle false positives; - Quick technical support directly from developers; - 1200+ diagnostics with descriptions and examples; - Provides compliance with safety & security standards: OWASP TOP 10, MISRA C/C++, CWE, SEI CERT; - Provides detailed reports and reminders for developers and managers; - Efficiently handles legacy code (baselining of analyzer results); - Active support of the Open Source Community, analysis of open-source projects; - Has integration with popular IDEs, code quality platforms, CI/CD, build systems. Good option for: - game developers (Unity & UE integration included) - embedded developers (embedded platform support); - DevSecOps experts (CLI) - project managers (code quality platform integration included) - FinTech (compliance with OWASP ASVS) - mature projects (seamless legacy handling)

API Access

Has API No 

API Access

Has API No 

Screenshots View All

No images available

Screenshots View All

Integrations

.NET No 
Android Studio No 
Azure DevOps No 
CLion No 
CircleCI No 
Docker No 
GoLand No 
Gradle No 
IntelliJ IDEA No 
Java No 
JavaScript No 
Keil MDK No 
PhpStorm No 
Platform.io No 
Qt Creator No 
SonarQube Cloud No 
TeamCity No 
Travis CI No 
Unity No 
Visual Studio Code No 

Integrations

.NET Yes 
Android Studio Yes 
Azure DevOps Yes 
CLion Yes 
CircleCI Yes 
Docker Yes 
GoLand Yes 
Gradle Yes 
IntelliJ IDEA Yes 
Java Yes 
JavaScript Yes 
Keil MDK Yes 
PhpStorm Yes 
Platform.io Yes 
Qt Creator Yes 
SonarQube Cloud Yes 
TeamCity Yes 
Travis CI Yes 
Unity Yes 
Visual Studio Code Yes 

Pricing Details

$500 USD
Free Trial Yes 
Free Version No 

Pricing Details

Trial version and pricing can be found on the website PVS-Studio or be requested via the contact form.
Free Trial Yes 
Free Version Yes 

Deployment

Web-Based Yes 
On-Premises Yes 
iPhone App No 
iPad App No 
Android App No 
Windows Yes 
Mac Yes 
Linux Yes 
Chromebook No 

Deployment

Web-Based No 
On-Premises Yes 
iPhone App No 
iPad App No 
Android App No 
Windows Yes 
Mac Yes 
Linux Yes 
Chromebook No 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support No 

Customer Support

Business Hours No 
Live Rep (24/7) Yes 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) Yes 
In Person Yes 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) Yes 
In Person No 

Vendor Details

Company Name

DerSecur

Founded

2011

Country

Israel

Website

derscanner.com

Vendor Details

Company Name

PVS-Studio

Founded

2008

Country

Kazakhstan

Website

pvs-studio.com/en/pvs-studio/

Product Features

Application Security

Analytics / Reporting No 
Open Source Component Monitoring No 
Source Code Analysis No 
Third-Party Tools Integration No 
Training Resources No 
Vulnerability Detection No 
Vulnerability Remediation No 

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Product Features

Application Development

Access Controls/Permissions No 
Code Assistance No 
Code Refactoring Yes 
Collaboration Tools No 
Compatibility Testing No 
Data Modeling No 
Debugging Yes 
Deployment Management Yes 
Graphical User Interface No 
Mobile Development No 
No-Code No 
Reporting/Analytics Yes 
Software Development Yes 
Source Control No 
Testing Management Yes 
Version Control No 
Web App Development No 

Automated Testing

Hierarchical View No 
Move & Copy No 
Parameterized Testing Yes 
Requirements-Based Testing No 
Security Testing Yes 
Supports Parallel Execution Yes 
Test Script Reviews No 
Unicode Compliance No 

DevOps

Approval Workflow Yes 
Dashboard Yes 
KPIs Yes 
Policy Management No 
Portfolio Management No 
Prioritization Yes 
Release Management Yes 
Timeline Management No 
Troubleshooting Reports Yes 

Source Code Management

Access Controls/Permissions No 
Bug Tracking Yes 
Build Automation No 
Change Management Yes 
Code Review Yes 
Collaboration No 
Continuous Integration Yes 
Repository Management No 
Version Control Yes 

Static Application Security Testing (SAST)

Application Security Yes 
Dashboard Yes 
Debugging Yes 
Deployment Management Yes 
IDE Yes 
Multi-Language Scanning Yes 
Real-Time Analytics No 
Source Code Scanning Yes 
Vulnerability Scanning Yes 

Alternatives

AppScan Reviews

AppScan

HCLSoftware

Alternatives