Best Software Composition Analysis Tools

How Many Software Composition Analysis Tools Products Does G2 Track?

Total Products under this Category: 76

Category Stats (Sep 2026)

  • Average Rating: 4.49/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Software Composition Analysis Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 6,600+ Authentic Reviews
  • 76+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Software Composition Analysis Tools

G2 Grid® for Software Composition Analysis Tools plotting products by satisfaction and market presence

Highlighted products: Wiz, Aikido Security, GitHub, Mend.io, Snyk, GitLab, JFrog, and DigiCert ONE.

Underlying data: [Grid® JSON](https://www.g2.com/categories/software-composition-analysis/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=github&focus%5B%5D=mend-io&focus%5B%5D=snyk&focus%5B%5D=gitlab&focus%5B%5D=jfrog-2024-03-28&focus%5B%5D=digicert-one)

Wiz

Wiz transforms cloud security for customers – including more than 50% of the Fortune 100 – by enabling a new operating model. With Wiz, organizations can democratize security across the development lifecycle, empowering them to build fast and securely. Its Cloud Native Application Protection Platform (CNAPP) consolidates CSPM, KSPM, CWPP, Vulnerability management, IaC scanning, CIEM, DSPM into a single platform. Wiz drives visibility, risk prioritization, and business agility. Protecting Your Cloud Environments Requires a Unified, Cloud Native Platform. Wiz connects to every cloud environment, scans every layer, and covers every aspect of your cloud security - including elements that normally require installing agents. Its comprehensive approach has all of these cloud security solutions built in. Hundreds of organizations worldwide, including 50 percent of the Fortune 100, to rapidly identify and remove critical risks in cloud environments. Its customers include Salesforce, Slack, Mars, BMW, Avery Dennison, Priceline, Cushman & Wakefield, DocuSign, Plaid, and Agoda, among others. Wiz is backed by Sequoia, Index Ventures, Insight Partners, Salesforce, Blackstone, Advent, Greenoaks, Lightspeed and Aglaé. Visit https://www.wiz.io for more information.

Average Rating: 4.7/5.0

Total Reviews: 841

How Do G2 Users Rate Wiz?

  • Quality of Support: 9.1/10 (Category avg: 9.0/10)
  • Language Support: 8.8/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.2/10 (Category avg: 8.7/10)
  • Integration: 9.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Wiz?

  • Seller: Wiz
  • Company Website:
  • Year Founded: 2020
  • HQ Location: New York, US
  • Twitter: @wiz_io
    24,733 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,147 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CISO, Security Engineer
  • Top Industries: Financial Services, Computer Software
  • Company Size: 53% Large, 39% Medium

What Do G2 Reviewers Say About Wiz?

AI-generated summary from verified user reviews

Pros
  • Users value the robust APIs and user-friendly UI, appreciating ongoing improvements and a wealth of insightful issues.
  • Users value the continuous enhancement of security features by Wiz, appreciating the support and innovation in their tool.
  • Users appreciate the ease of use of Wiz, benefiting from its user-friendly interface and seamless integration.
  • Users value the comprehensive visibility Wiz provides, enhancing security and prioritizing essential aspects of their cloud environment.
  • Users appreciate the easy setup of Wiz, enabling a quick and seamless integration into their workflows.
Cons
  • Users find a significant learning curve in mastering Wiz's extensive features, which can hinder initial usage.
  • Users find the feature limitations of Wiz frustrating, especially with complex management and reporting challenges.
  • Users note that improvement is needed for laggy query responses and better dashboard reporting capabilities.
  • Users identify improvements needed in dashboard reporting and feature streamlining for better usability and budgeting.
  • Users find the interface overwhelming initially, facing a steep learning curve and complex licensing issues.

What Are Recent G2 Reviews of Wiz?

Aikido Security

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

Average Rating: 4.6/5.0

Total Reviews: 264

How Do G2 Users Rate Aikido Security?

  • Quality of Support: 9.3/10 (Category avg: 9.0/10)
  • Language Support: 9.0/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.0/10 (Category avg: 8.7/10)
  • Integration: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Aikido Security?

  • Seller: Aikido Security
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Ghent, Belgium
  • Twitter: @AikidoSecurity
    11,770 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    320 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Founder, CTO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 78% Small, 15% Medium

What Do G2 Reviewers Say About Aikido Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Aikido Security, thanks to its clear insights and seamless integration.
  • Users appreciate Aikido Security's robust security capabilities, providing a comprehensive and seamless integration in their workflow.
  • Users value the intuitive dashboard of Aikido Security, which simplifies security issue identification and management.
  • Users value the easy integrations of Aikido Security, enhancing workflows with seamless connections to existing GitLab repositories.
  • Users find Aikido's easy setup highly efficient, enabling quick implementation and immediate usability for security assessments.
Cons
  • Users note the lack of advanced features in Aikido Security, such as dark mode and in-depth analysis options.
  • Users find the pricing structure expensive for micro businesses, making upgrades difficult to justify.
  • Users note the limited features of Aikido Security, wishing for more customization and advanced options.
  • Users find the pricing issues challenging, especially for micro businesses, due to the steep upgrade costs.
  • Users feel Aikido Security is lacking features like advanced reporting and deeper compliance analysis compared to competitors.

What Are Recent G2 Reviews of Aikido Security?

GitHub

GitHub is where the world builds software. Millions of individuals, organizations and businesses around the world use GitHub to discover, share, and contribute software. Developers at startups to Fortune 50 companies use GitHub, every step of the way.

Average Rating: 4.7/5.0

Total Reviews: 2,341

How Do G2 Users Rate GitHub?

  • Quality of Support: 8.7/10 (Category avg: 9.0/10)
  • Language Support: 8.8/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.0/10 (Category avg: 8.7/10)
  • Integration: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind GitHub?

  • Seller: GitHub
  • Year Founded: 2008
  • HQ Location: San Francisco, CA
  • Twitter: @github
    2,673,925 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6,653 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 47% Small, 31% Medium

What Do G2 Reviewers Say About GitHub?

AI-generated summary from verified user reviews

Pros
  • Users value GitHub's seamless collaboration and powerful version control, enhancing project transparency and workflow management.
  • Users appreciate the ease of use of GitHub, enabling seamless collaboration and efficient version control.
  • Users value the seamless team collaboration on GitHub, enhancing code sharing and workflow management effectively.
  • Users value the seamless collaboration offered by GitHub, enhancing project transparency and team workflow management.
  • Users value GitHub for its seamless version control, enhancing collaboration and streamlining the development process.
Cons
  • Users find the complexity in advanced features of GitHub challenging, particularly for newcomers and managing large repositories.
  • Users find the learning curve challenging, especially when designing workflows and managing permissions effectively.
  • Users find learning GitHub challenging due to overwhelming settings and complexities, making navigation difficult for newcomers.
  • Users find the complexity for beginners challenging, especially with CI/CD workflows and permission management.
  • Users find the steep learning curve of GitHub challenging, especially in mastering workflows and managing permissions.

What Are Recent G2 Reviews of GitHub?

What Are G2 Users Discussing About GitHub?

Mend.io

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

Average Rating: 4.3/5.0

Total Reviews: 117

How Do G2 Users Rate Mend.io?

  • Quality of Support: 8.7/10 (Category avg: 9.0/10)
  • Language Support: 8.5/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.8/10 (Category avg: 8.7/10)
  • Integration: 8.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Mend.io?

  • Seller: Mend
  • Company Website:
  • Year Founded: 2011
  • HQ Location: Boston, Massachusetts
  • Twitter: @Mend_io
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    259 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 36% Small, 33% Large

What Do G2 Reviewers Say About Mend.io?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the scanning efficiency of Mend.io, enabling quick and accurate scans across multiple repositories seamlessly.
  • Users appreciate the ease of use of Mend.io, made simpler by effective integrations and an attractive interface.
  • Users value the easy integrations of Mend.io, allowing seamless scanning across multiple repositories and CI/CD platforms.
  • Users appreciate the quick and accurate scanning capabilities of Mend.io, benefiting from a range of integrations.
  • Users value the automated vulnerability detection of Mend.io, enhancing efficiency in identifying and addressing issues seamlessly.
Cons
  • Users face integration issues with Mend.io, finding it difficult to connect on-premise tools and features like Jira.
  • Users express concern over limited features in Mend.io, necessitating workarounds for optimal functionality and integration.
  • Users find the missing features in Mend.io cumbersome, often resorting to workarounds for integration and functionality.
  • Users face complex implementation, with challenging integration and frequent false positives affecting their experience.
  • Users find the confusing interface challenging due to the awkward transitions between different portals.

What Are Recent G2 Reviews of Mend.io?

What Are G2 Users Discussing About Mend.io?

Snyk

Snyk (pronounced sneak) is a developer security platform for securing custom code, open source dependencies, containers, and cloud infrastructure all from a single platform. Snyk’s developer security solutions enable modern applications to be built securely, empowering developers to own and build security for the whole application, from code & open source to containers & cloud infrastructure. Secure while you code in your IDE: find issues quickly using the scanner, fix issues easily with remediation advice, verify the updated code. Integrate your source code repositories to secure applications: integrate a repository to find issues, prioritize with context, fix & merge. Secure your containers as you build, throughout the SDLC: start fixing containers as soon as your write a Dockerfile, continuously monitor container images throughout their lifecycle, and prioritize with context. Secure build and deployment pipelines: Integrate natively with your CI/CD tool, configure your rules, find & fix issues in your application, and monitor your applications. Secure your apps quickly with Snyk’s vulnerability scanning and automated fixes - Try for Free!

Average Rating: 4.5/5.0

Total Reviews: 136

How Do G2 Users Rate Snyk?

  • Quality of Support: 8.6/10 (Category avg: 9.0/10)
  • Language Support: 8.1/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.7/10 (Category avg: 8.7/10)
  • Integration: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Snyk?

  • Seller: Snyk
  • HQ Location: Boston, Massachusetts
  • Twitter: @snyksec
    21,057 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,764 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 45% Medium, 35% Small

What Do G2 Reviewers Say About Snyk?

AI-generated summary from verified user reviews

Pros
  • Users value Snyk's quick vulnerability detection, significantly improving efficiency in code security and remediation processes.
  • Users appreciate Snyk for its efficient vulnerability identification, significantly aiding in maintaining secure code and streamlining DevOps processes.
  • Users value the easy integration setup of Snyk, enhancing vulnerability detection in their development workflows.
  • Users appreciate the easy setup of Snyk, seamlessly integrating with GitHub for efficient vulnerability management.
  • Users benefit from Snyk's intuitive GUI and customizable features, facilitating effective vulnerability management and developer organization.
Cons
  • Users experience false positives in Snyk, which can hinder efficiency and slow down the scanning process.
  • Users find the poor interface design of Snyk cumbersome, impacting their overall experience with the product.
  • Users note that pricing issues can arise, especially when accessing all features of Snyk, impacting affordability.
  • Users report experiencing false positives and slow scan times, affecting their efficiency and integration within the Snyk product.
  • Users experience false positives and slow scans, complicating overall use and requiring additional tools for code quality.

What Are Recent G2 Reviews of Snyk?

What Are G2 Users Discussing About Snyk?

GitLab

GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab, teams can create, deliver, and manage code quickly and continuously instead of managing disparate tools and scripts. GitLab helps your teams across the complete DevSecOps lifecycle, from developing, securing, and deploying software. What makes us truly different? - Flexibility: Consume as a service or manage your own deployment - Cloud-Agnostic: Deploy anywhere with no vendor lock-in - No rip and replace: Scale to a platform approach at your own pace

Average Rating: 4.5/5.0

Total Reviews: 884

How Do G2 Users Rate GitLab?

  • Quality of Support: 8.5/10 (Category avg: 9.0/10)
  • Language Support: 8.7/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.0/10 (Category avg: 8.7/10)
  • Integration: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind GitLab?

  • Seller: GitLab Inc.
  • Year Founded: 2014
  • HQ Location: San Francisco, California
  • Twitter: @gitlab
    171,534 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,431 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 37% Medium, 37% Small

What Do G2 Reviewers Say About GitLab?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use in GitLab, enjoying its all-in-one DevOps capabilities and intuitive interface.
  • Users value the all-encompassing features of GitLab, which enhance collaboration and streamline the DevOps workflow.
  • Users love the seamless CI/CD integration of GitLab, simplifying automation and collaboration in DevOps workflows.
  • Users value the seamless integrations in GitLab, resulting in efficient workflows and streamlined management across multiple functions.
  • Users praise the seamless CI/CD integration in GitLab, enhancing automation and collaboration within their DevOps workflow.
Cons
  • Users find the complexity of GitLab's setup and management to be a significant barrier to efficient use.
  • Users find the difficult learning curve of GitLab challenging due to its complex interface and YAML syntax.
  • Users find the interface confusing due to clutter and slow performance with large repositories, complicating their navigation.
  • Users find the complex user interface challenging, especially with slow performance and difficulties in navigation and management.
  • Users find the learning curve steep, particularly for those new to DevOps and managing extensive features.

What Are Recent G2 Reviews of GitLab?

What Are G2 Users Discussing About GitLab?

JFrog

JFrog Ltd. (Nasdaq: FROG), the creators of the unified DevOps, DevSecOps, DevGovOps and MLOps platform, is on a mission to create a world of software delivered without friction from development to production. Driven by a “Liquid Software” vision to keep software continuously flowing, secure, and always up to date, the JFrog Platform serves as the definitive software supply chain system of record. It is uniquely engineered to power organizations as they build, manage, and distribute trusted software with unprecedented speed, security, and scale across hybrid and multi-cloud environments. As software engineering evolves in the AI era, JFrog’s newest offerings address the industry's most pressing trend: the rise of agentic software development and the hidden security risks of "Shadow AI." In response to threat actors increasingly targeting developer workflows including a massive surge in malicious open-source AI models and infected packages; JFrog has expanded its platform capabilities to deliver absolute end-to-end visibility and automated compliance. Key new innovations include the JFrog AI Catalog, which enables organizations to centralize, govern, and control the lifecycle of AI models approved for enterprise use. To secure autonomous coding environments, JFrog introduced the Universal MCP Registry and the Agent Skills Registry (developed alongside NVIDIA). These new solutions establish the industry’s first enterprise-grade trust layer to safely manage and store AI agent skills, monitor connections, and instantly block unsafe developer tools or malicious coding extensions right where developers work. Furthermore, the integration of advanced DevGovOps and Runtime Security tools allows teams to replace slow, manual compliance audits with continuous, background policy enforcement. By shifting security left directly into the binary pipeline, JFrog ensures that the volume of AI-assisted code does not outpace an organization's ability to verify its safety. Today, millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on the universal JFrog Platform to eliminate point-solution fatigue, bridge the governance gap, and securely embrace digital transformation. Learn more at www.jfrog.com or follow us on X @JFrog.

Average Rating: 4.3/5.0

Total Reviews: 162

How Do G2 Users Rate JFrog?

  • Quality of Support: 8.4/10 (Category avg: 9.0/10)
  • Language Support: 8.3/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.3/10 (Category avg: 8.7/10)
  • Integration: 7.9/10 (Category avg: 8.8/10)

Who Is the Company Behind JFrog?

  • Seller: JFrog Ltd
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Sunnyvale, CA
  • Twitter: @jfrog
    23,186 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,527 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, DevOps Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 50% Large, 30% Medium

What Do G2 Reviewers Say About JFrog?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the unified support for various package formats that simplifies DevOps management and integration.
  • Users praise JFrog for its efficient repository management, streamlining the storage and tracking of artifacts in DevOps workflows.
  • Users value the seamless integration of JFrog with CI/CD tools, enhancing efficiency in artifact management and security.
  • Users value the seamless integrations of JFrog with various tools, enhancing their CI/CD workflows significantly.
  • Users appreciate the easy integrations of JFrog, enhancing CI/CD processes and supporting various package formats seamlessly.
Cons
  • Users find the complexity of JFrog overwhelming, often needing extensive training to use all features effectively.
  • Users often find JFrog to be expensive, especially challenging for smaller teams and individual developers to afford.
  • Users find the steep learning curve of JFrog challenging, requiring significant time and investment to master.
  • Users note the difficult learning curve with JFrog, requiring extensive training to navigate its complex features effectively.
  • Users find the learning difficulty of JFrog challenging, requiring significant time investment to master its features.

What Are Recent G2 Reviews of JFrog?

What Are G2 Users Discussing About JFrog?

DigiCert ONE

DigiCert ONE is a cloud-native digital trust platform that helps organizations automate, manage, and secure certificates, identities, software, devices, DNS infrastructure, documents, and email communications from a single platform. Designed to simplify complex trust environments, DigiCert ONE provides centralized visibility, policy-based governance, and automation to reduce operational risk, improve compliance, and accelerate digital transformation initiatives. The platform includes: - Trust Lifecycle Manager for CA-agnostic certificate lifecycle management, certificate discovery, automation, and public and private PKI. - Software Trust Manager for secure code signing, software supply chain protection, and automated signing workflows. - Device Trust Manager for establishing and managing trusted device identities throughout the IoT and device lifecycle. - Content Trust Manager for digital signatures, electronic seals, timestamping, and document trust services. - UltraDNS for highly available, secure DNS infrastructure, intelligent traffic management, and application resiliency. - Messaging Trust for email authentication, domain protection, phishing prevention, and improved email deliverability. DigiCert ONE also integrates with CertCentral®, enabling organizations to streamline the issuance, management, and automation of publicly trusted TLS/SSL certificates alongside their broader digital trust operations. Built on a scalable, container-based architecture, DigiCert ONE supports cloud, on-premises, hybrid, and air-gapped deployments, enabling organizations to meet security, operational, and regulatory requirements while maintaining agility. Organizations use DigiCert ONE to eliminate manual trust management processes, prevent certificate-related outages, secure software and connected devices, protect critical infrastructure, and build trusted digital experiences at scale.

Average Rating: 4.3/5.0

Total Reviews: 72

How Do G2 Users Rate DigiCert ONE?

  • Quality of Support: 8.7/10 (Category avg: 9.0/10)

Who Is the Company Behind DigiCert ONE?

  • Seller: DigiCert
  • Company Website:
  • Year Founded: 2003
  • HQ Location: Lehi, UT
  • Twitter: @digicert
    6,675 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,957 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 39% Small, 37% Medium

What Are Recent G2 Reviews of DigiCert ONE?

What Are G2 Users Discussing About DigiCert ONE?

Semgrep

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

Average Rating: 4.6/5.0

Total Reviews: 56

How Do G2 Users Rate Semgrep?

  • Quality of Support: 8.8/10 (Category avg: 9.0/10)
  • Language Support: 8.4/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.3/10 (Category avg: 8.7/10)
  • Integration: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Semgrep?

  • Seller: Semgrep
  • Year Founded: 2017
  • HQ Location: San Francisco, US
  • Twitter: @semgrep
    4,433 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    265 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 45% Large, 43% Medium

What Do G2 Reviewers Say About Semgrep?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Semgrep, enabled by its intuitive syntax and smooth integration with CI/CD.
  • Users appreciate the flexibility and speed of Semgrep in enforcing coding standards and catching vulnerabilities effectively.
  • Users appreciate the effective vulnerability detection of Semgrep, facilitating quick identification and resolution of security issues.
  • Users appreciate the scanning efficiency of Semgrep, benefiting from rapid scans and streamlined CI/CD integration.
  • Users value Semgrep for its effective security vulnerability detection, enabling quick resolutions without hindering development speed.
Cons
  • Users find Semgrep not user-friendly due to a steep learning curve and complex initial setup requirements.
  • Users find the limited features of Semgrep restrict its usability and complicate effective vulnerability management.
  • Users find the difficult learning curve for Semgrep daunting, especially for creating advanced rules and setups.
  • Users express concerns about the lack of guidance in creating custom rules, complicating effective use of Semgrep.
  • Users note a steep learning curve for Semgrep's rule syntax, making it challenging for newcomers to master.

What Are Recent G2 Reviews of Semgrep?

Microsoft Defender for Cloud

Microsoft Defender for Cloud is a cloud native application protection platform for multicloud and hybrid environments with comprehensive security across the full lifecycle, from development to runtime.

Average Rating: 4.4/5.0

Total Reviews: 427

How Do G2 Users Rate Microsoft Defender for Cloud?

  • Quality of Support: 8.5/10 (Category avg: 9.0/10)
  • Language Support: 9.4/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 10.0/10 (Category avg: 8.7/10)
  • Integration: 9.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Microsoft Defender for Cloud?

  • Seller: Microsoft
  • Year Founded: 1975
  • HQ Location: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    232,750 employees on LinkedIn®
  • Ownership: MSFT

Who Uses This Product?

  • Who Uses This: Saas Consultant, Software Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 38% Medium, 35% Large

What Do G2 Reviewers Say About Microsoft Defender for Cloud?

AI-generated summary from verified user reviews

Pros
  • Users value the robust security features of Microsoft Defender for Cloud, effectively protecting against diverse cyber threats.
  • Users appreciate the comprehensive security of Microsoft Defender for Cloud, effectively protecting against various cyber threats.
  • Users praise the robust security features of Microsoft Defender for Cloud, enhancing threat detection and prevention effectively.
  • Users appreciate the security alerts from Microsoft Defender for Cloud, enhancing their overall cloud security experience.
  • Users value the effective threat detection of Microsoft Defender for Cloud, ensuring robust security for their cloud resources.
Cons
  • Users find the complexity of configuration in Microsoft Defender for Cloud challenging, affecting their overall experience.
  • Users note that while Microsoft Defender for Cloud is excellent, it can be expensive for small to medium businesses.
  • Users experience delayed detection with Microsoft Defender for Cloud, often missing suspicious threats and alerts.
  • Users find the complex interface and downtimes of Microsoft Defender for Cloud detracting from its overall usability.
  • Users experience false positives in Microsoft Defender for Cloud, leading to confusion over legitimate files being flagged.

What Are Recent G2 Reviews of Microsoft Defender for Cloud?

What Are G2 Users Discussing About Microsoft Defender for Cloud?

Cortex Cloud

Cortex Cloud by Palo Alto Networks, the next version of Prisma Cloud, understands a unified security approach is essential for effectively addressing AppSec, CloudSec, and SecOps. Connecting cloud security and SOC workflows enables teams to achieve holistic visibility, trace risk across the lifecycle, and correlate real-time threat activity with development and runtime contexts. Cortex Cloud is a unified platform built on three core pillars: data integration, AI-driven intelligence, and automation. Now you can safeguard applications, data, and infrastructure across multicloud and hybrid environments with a unified data model that consolidates telemetry from code, runtime, identity, and endpoints, all into a single data source. Empower teams with precise, AI-powered insights and 2200+ machine learning models to identify and stop zero-day threats with real-time advanced threat detection and response. And automate with 1000+ prebuilt playbooks across your cloud stack to reduce manual workloads, accelerate remediations, and cut response times tenfold. Cortex Cloud delivers more than tools—it transforms how organizations secure their cloud environments.

Average Rating: 4.1/5.0

Total Reviews: 125

How Do G2 Users Rate Cortex Cloud?

  • Quality of Support: 8.0/10 (Category avg: 9.0/10)
  • Language Support: 6.7/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 7.9/10 (Category avg: 8.7/10)
  • Integration: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind Cortex Cloud?

  • Seller: Palo Alto Networks
  • Company Website:
  • Year Founded: 2005
  • HQ Location: Santa Clara, CA
  • Twitter: @PaloAltoNtwks
    128,951 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,492 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 38% Large, 32% Medium

What Do G2 Reviewers Say About Cortex Cloud?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Cortex Cloud, benefiting from its streamlined interface and centralized management.
  • Users value the user-friendly interface and seamless integrations of Cortex Cloud, enhancing efficiency and incident management.
  • Users value the comprehensive security overview of Cortex Cloud, enhancing protection across all environments and stages.
  • Users value the comprehensive visibility provided by Cortex Cloud, enhancing efficiency and simplifying incident management.
  • Users appreciate the secure and centralized cloud integration of Cortex Cloud, enhancing efficiency and organization in their processes.
Cons
  • Users find Cortex Cloud to be expensive, particularly challenging for smaller teams with limited budgets.
  • Users find the difficult learning curve of Cortex Cloud frustrating, especially for beginners navigating its features.
  • Users face a steep learning curve with Cortex Cloud, as some features are not intuitive for beginners.
  • Users find the pricing issues with Cortex Cloud significant, especially affecting smaller teams considering affordability.
  • Users find the complex setup of Cortex Cloud challenging, especially for newcomers without prior experience.

What Are Recent G2 Reviews of Cortex Cloud?

Black Duck Polaris Platform

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it, development and DevSecOps teams to automate testing within development pipelines without compromising velocity, and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Average Rating: 4.2/5.0

Total Reviews: 103

How Do G2 Users Rate Black Duck Polaris Platform?

  • Quality of Support: 8.5/10 (Category avg: 9.0/10)
  • Language Support: 9.3/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.6/10 (Category avg: 8.7/10)
  • Integration: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Black Duck Polaris Platform?

  • Seller: Black Duck
  • Year Founded: 2024
  • HQ Location: Burlington, US
  • LinkedIn® Page: www.linkedin.com
    1,317 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 53% Large, 32% Medium

What Do G2 Reviewers Say About Black Duck Polaris Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the accuracy of findings from Black Duck SCA, highlighting its powerful engine and extensive knowledge base.
  • Users value the powerful identification of open source issues by Black Duck SCA, aided by extensive knowledge resources.
Cons
  • Users find that Black Duck SCA requires huge resources to deploy on-prem, which can be a significant drawback.

What Are Recent G2 Reviews of Black Duck Polaris Platform?

What Are G2 Users Discussing About Black Duck Polaris Platform?

SonarQube

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

Average Rating: 4.4/5.0

Total Reviews: 152

How Do G2 Users Rate SonarQube?

  • Quality of Support: 8.1/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 3.3/10 (Category avg: 8.7/10)
  • Integration: 3.3/10 (Category avg: 8.8/10)

Who Is the Company Behind SonarQube?

  • Seller: SonarSource Sàrl
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Geneva, Switzerland
  • Twitter: @SonarSource
    10,913 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    973 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: DevOps Engineer, Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 42% Large, 40% Medium

What Do G2 Reviewers Say About SonarQube?

AI-generated summary from verified user reviews

Pros
  • Users value SonarQube for its ability to quickly flag code quality and security issues, ensuring a reliable codebase.
  • Users value the flexible issue filtering and prioritization features of SonarQube, enhancing team productivity and focus.
  • Users appreciate how SonarQube quickly flags code quality and security issues, ensuring a clean and reliable codebase.
  • Users appreciate the ease of use of SonarQube, finding integration and actionable feedback simple and effective.
  • Users appreciate the easy integrations with CI/CD tools, enhancing their workflow and improving code quality effectively.
Cons
  • Users face software bugs that lead to false positives, complicating the experience and requiring significant knowledge to manage.
  • Users find the complex configuration of SonarQube challenging, especially for beginners needing extensive knowledge.
  • Users encounter false positives that complicate usage, despite helpful tools for review and customization of analysis.
  • Users find SonarQube's complexity in configuration and excessive warnings can make it cumbersome to use.
  • Users find the complex setup of SonarQube time-consuming, requiring significant effort to configure and tune effectively.

What Are Recent G2 Reviews of SonarQube?

What Are G2 Users Discussing About SonarQube?

OX Security

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

Average Rating: 4.8/5.0

Total Reviews: 51

How Do G2 Users Rate OX Security?

  • Quality of Support: 9.6/10 (Category avg: 9.0/10)
  • Language Support: 8.7/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.8/10 (Category avg: 8.7/10)
  • Integration: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind OX Security?

Who Uses This Product?

  • Who Uses This: Security Engineer
  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 63% Medium, 25% Large

What Do G2 Reviewers Say About OX Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the intuitive dashboard of OX Security, enhancing issue management and streamlining security processes effectively.
  • Users find OX Security highly user-friendly, benefiting from an intuitive dashboard and responsive support for seamless operations.
  • Users value the responsive and professional customer support of OX Security, enhancing their overall experience and efficiency.
  • Users value the seamless integration support from OX Security, enhancing their workflow with fast and user-friendly solutions.
  • Users appreciate the comprehensive security capabilities of OX Security, ensuring a streamlined and effective security management experience.
Cons
  • Users report integration issues with OX Security's limited documentation and insufficient support for various tools.
  • Users note some missing features in OX Security, which can affect its overall usability and integration capabilities.
  • Users find the complexity of OX Security daunting, with inadequate documentation and a steep learning curve for new users.
  • Users find OX Security's inadequate reporting limits their ability to effectively showcase security progress to management.
  • Users find the limited cloud integration with certain tools frustrating, impacting overall connectivity and functionality.

What Are Recent G2 Reviews of OX Security?

CAST Highlight

Portfolio-level insights for app modernization, AI readiness, tech debt, OSS risks CAST Highlight is a SaaS software intelligence technology that delivers rapid, fact-based insights across your entire application portfolio. With Ask CAST, IT leaders can query this intelligence in plain language through Microsoft Teams or AI assistants such as Claude and ChatGPT and receive grounded answers based on their portfolio data. By automatically analyzing the source code of hundreds or thousands of applications, CAST Highlight helps organizations assess cloud maturity, AI & Agentic readiness, software health, open source risk, resiliency, technical debt, and sustainability from a single lightweight scan. CAST Highlight is designed for CIOs, CTOs, enterprise architects, cloud leaders, application owners, security teams, and modernization teams that need a fact-based way to prioritize modernization, cloud, and AI adoption decisions at scale. It helps teams identify which applications are ready to move quickly, which require remediation, and where hidden software risks may affect transformation cost, timelines, security, resilience, or business outcomes. Unlike traditional manual or survey-based assessments, CAST Highlight analyzes application source code directly to rapidly segment portfolios, prioritize modernization paths, and uncover risks before they impact transformation programs. Organizations use CAST Highlight to: - Accelerate cloud migration and modernization planning - Segment applications by cloud maturity and transformation path - Identify high-value AI adoption opportunities - Assess Agentic Readiness across application portfolios - Prioritize technical debt, resiliency, and maintainability improvements - Assess open source vulnerabilities and IP / license exposure - Evaluate software sustainability with Green Impact insights - Reduce complexity, cost, and risk across transformation programs Businesses move faster using CAST to understand, improve, and transform their software. Through semantic analysis of source code, CAST generates dashboards and 3D maps for executives, technologists, and AI to navigate inside individual applications and across entire portfolios. This intelligence enables companies to steer, speed, and report on initiatives such as technical debt, modernization, and cloud. As the pioneer of the software intelligence field, CAST is trusted by the world’s leading companies and governments, their consultancies and cloud providers. See it all at castsoftware.com.

Average Rating: 4.5/5.0

Total Reviews: 86

How Do G2 Users Rate CAST Highlight?

  • Quality of Support: 9.1/10 (Category avg: 9.0/10)
  • Language Support: 8.5/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.5/10 (Category avg: 8.7/10)
  • Integration: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind CAST Highlight?

  • Seller: CAST
  • Company Website:
  • Year Founded: 1990
  • HQ Location: New York
  • Twitter: @SW_Intelligence
    1,887 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,270 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 57% Large, 24% Small

What Do G2 Reviewers Say About CAST Highlight?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of CAST Highlight, noting its quick setup and straightforward functionality for assessments.
  • Users find the easy setup of CAST Highlight highly beneficial, enabling quick integration and efficient use with enterprise tools.
  • Users value CAST Highlight for its insights into cloud migration and technical debt assessment, enhancing software health evaluation.
  • Users appreciate the efficient analysis offered by CAST Highlight, enabling fast insights and effective modernization strategies.
  • Users value the speed and simplicity of CAST Highlight, enabling quick, actionable insights for portfolio analysis.
Cons
  • Users find the complex navigation of CAST Highlight challenging, making it harder to efficiently use the tool.
  • Users find dashboard issues prevalent, including lack of depth and customization challenges for specific organizational needs.
  • Users find that the delayed detection of issues may hinder timely responses and overall effectiveness of CAST Highlight.
  • Users find the difficulty in initial configuration and metric interpretation a barrier for new teams using CAST Highlight.
  • Users find the high price of CAST Highlight a barrier for broader adoption in larger companies.

What Are Recent G2 Reviews of CAST Highlight?

What Are G2 Users Discussing About CAST Highlight?

Adam Crivello
AC
Researched and written by Adam Crivello
Updated October 3, 2024

Learn More About Software Composition Analysis Tools

What is Software Composition Analysis Software?

Software composition analysis (SCA) refers to the management and evaluation of open source and third-party components within the development environment. Software developers and development teams use SCA to keep tabs on the hundreds of open source components incorporated in their builds. These components fall out of compliance and require version updates; if left unchecked they can pose major security risks. With so many components to track, developers lean on SCA to automatically manage issues. SCA tools scan for actionable items and alerts developers, allowing teams to focus on development rather than manually combing through a mess of software components.

In conjunction with tools such as vulnerability scanner and dynamic application security testing (DAST) software, software composition analysis integrates with the development environment to curate a secure DevOps workflow. The synergy between cybersecurity and DevOps, sometimes referred to as DevSecOps, answers an urgent call for developers to approach software development with a security-first mindset. For a long time, software developers have relied on open source and third-party components, leaving siloed cybersecurity professionals to clean up builds. This outdated standard often leaves large unresolved gaps in security for stretches of time. Software composition analysis presents a solution for ensuring secure compliance before the worst happens.

Key Benefits of Software Composition Analysis Software

  • Help keep development secure
  • Ease the workloads of developers
  • Build a productive workflow across teams

Why Use Software Composition Analysis Software?

Security best practices are a necessary staple in any DevOps environment. Beyond industry standards, secure development is increasingly important as issues such as API vulnerabilities come to the forefront of cybersecurity. There are often many open source and third-party components in a software build—ensuring components are constantly updated and secure is a task better left to software. Software composition analysis does the job and saves development teams significant time and energy.

Peace of mind — Software composition analysis software constantly evaluates open source components. This means developers and teams can focus on advancing their projects without worrying about a mess of unchecked components. In the event of any issues, SCA software alerts users and provides suggestions for remediation.

Seamless security — Most SCA software integrates with preexisting development environments, meaning users don’t have to navigate between windows to address vulnerabilities. Developers can receive important and relevant information about the open source and third-party components in their builds without detaching themselves from their workspace.

Who Uses Software Composition Analysis Software?

DevOps teams that want to implement security best practices use SCA software as an integral part of the DevSecOps tool kit. SCA software empowers developers to proactively keep their open source and third-party components secure, rather than leave a mess of vulnerabilities for siloed cybersecurity team members to clean up. Tools like SCA software help break down the barriers between DevOps and cybersecurity practices, curating an integrated and agile workflow.

Solo developers — While SCA software does wonders for larger teams looking to marry their cybersecurity and DevOps processes, solo developers benefit from their own automated security watchdog. Developers working alone on personal projects can’t expect cybersecurity to be taken care of by someone else, so tools like SCA software help them manage their open source vulnerabilities without eating into their time and energy.

Small development teams — Similar to solo developers, small development teams often lack the assets to employ a full-time cybersecurity professional. SCA software also aids these teams, allowing them to focus their limited resources on building their project.

Large DevOps teams — Midsize and enterprise DevOps teams rely on SCA software to shape a secure and common sense DevSecOps workflow. Rather than isolate cybersecurity professionals from the DevOps process, companies use tools like SCA to integrate cybersecurity as a default standard for development. This practice mitigates stressors on both developers and IT teams by enabling a more agile environment.

Software Composition Analysis Software Features

Comprehensive insights — SCA software gives users meaningful visibility into the open source and third-party components they use. These tools organize relevant and timely information and present developers with useful updates. This interface often requires some level of development knowledge, meaning the onus is on developers to act on any information presented by SCA tools. Version updates, compliance issues, and vulnerabilities are constantly evaluated so users can be alerted as soon as issues arise.

Remediation information — Beyond identifying issues with developers’ open source components, SCA software provides users with relevant documentation for remediation. These suggestions give knowledgeable developers a jumping off point so they can address vulnerabilities in a timely manner. These remediation suggestions typically require development knowledge to understand, but developers can often pass these remediation tasks to cybersecurity professionals on their team.