Top Free Software Composition Analysis Tools - Page 2

How Many Software Composition Analysis Tools Products Does G2 Track?

Total Products under this Category: 75

Category Stats (Sep 2026)

  • Average Rating: 4.49/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Software Composition Analysis Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 6,600+ Authentic Reviews
  • 75+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Software Composition Analysis Tools

G2 Grid® for Software Composition Analysis Tools plotting products by satisfaction and market presence

Highlighted products: Wiz, Aikido Security, GitHub, Mend.io, Snyk, GitLab, DigiCert ONE, and JFrog.

Underlying data: [Grid® JSON](https://www.g2.com/categories/software-composition-analysis/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=github&focus%5B%5D=mend-io&focus%5B%5D=snyk&focus%5B%5D=gitlab&focus%5B%5D=digicert-one&focus%5B%5D=jfrog-2024-03-28)

Contrast Security

Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous, real-time defense, Contrast uncovers hidden application layer risks that traditional solutions miss. Contrast’s powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.

Average Rating: 4.5/5.0

Total Reviews: 49

How Do G2 Users Rate Contrast Security?

  • Quality of Support: 9.3/10 (Category avg: 9.0/10)
  • Language Support: 8.1/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.0/10 (Category avg: 8.7/10)
  • Integration: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Contrast Security?

  • Seller: Contrast Security
  • Year Founded: 2014
  • HQ Location: Pleasanton, CA
  • Twitter: @contrastsec
    5,468 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    182 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Insurance, Information Technology and Services
  • Company Size: 67% Large, 20% Medium

What Do G2 Reviewers Say About Contrast Security?

AI-generated summary from verified user reviews

Pros
  • Users value the accuracy of findings from Contrast Security, ensuring greater precision in identifying vulnerabilities.
  • Users value the accuracy of results from Contrast Security, benefiting from precise vulnerability monitoring and analysis.
  • Users commend the real-time vulnerability detection of Contrast Security, appreciating its quick feedback and agile support.
Cons
  • Users experienced performance issues with Contrast Security, particularly with Java applications, but found support helpful in resolving them.

What Are Recent G2 Reviews of Contrast Security?

What Are G2 Users Discussing About Contrast Security?

FOSSA

Open source is a critical part of your software. In the average modern software product, over 80% of the source code shipped is derived from open source. Each component can have cascading legal, security, and quality implications for your customers, making it one of the most important things to manage correctly. FOSSA helps you manage your open source components. We plug into your development workflow to help your team automatically track, manage, and remediate issues with the open source you use to: - Stay compliant with software licenses and generate required attribution documents - Enforce usage and licensing policies throughout your CI/CD workflow - Monitor and remediate security vulnerabilities - Flag code quality issues and outdated components proactively By enabling open source, we help development teams increase development velocity and decrease risk.

Average Rating: 4.2/5.0

Total Reviews: 15

How Do G2 Users Rate FOSSA?

  • Quality of Support: 8.3/10 (Category avg: 9.0/10)
  • Language Support: 8.8/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.5/10 (Category avg: 8.7/10)
  • Integration: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind FOSSA?

  • Seller: FOSSA
  • Year Founded: 2015
  • HQ Location: San Francisco, California
  • Twitter: @getfossa
    774 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    63 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 47% Small, 33% Medium

What Do G2 Reviewers Say About FOSSA?

AI-generated summary from verified user reviews

Pros
  • Users highlight the easy integrations of FOSSA, seamlessly working with Spring Boot and Angular applications through their pipeline.
  • Users appreciate FOSSA for its effective issue resolution, identifying library problems and recommending fixes in real-time.
  • Users find FOSSA's remediation solutions valuable for quickly identifying and recommending fixes for vulnerabilities in dependencies.
  • Users value the effective risk management provided by FOSSA, ensuring security and quality for applications.
  • Users value FOSSA for its robust security scanning, ensuring vulnerabilities are identified and managed effectively.

What Are Recent G2 Reviews of FOSSA?

MergeBase

MergeBase is revolutionizing software supply chain protection with a full-featured, developer-oriented SCA solution that brings the lowest false positives in the industry and complete DevOps coverage from coding/building to deployment and run-time. MergeBase’s SCA tool analyzes the open-source/third-party libraries for vulnerabilities. Our mission is to protect the software supply chain. We provide a full-featured, developer-oriented solution that has the industry’s lowest false positive rates and complete coverage of the DevOps process.

Average Rating: 4.5/5.0

Total Reviews: 20

How Do G2 Users Rate MergeBase?

  • Quality of Support: 9.3/10 (Category avg: 9.0/10)
  • Language Support: 7.9/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.5/10 (Category avg: 8.7/10)
  • Integration: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind MergeBase?

  • Seller: MergeBase Software
  • Year Founded: 2018
  • HQ Location: Coquitlam, British Columbia
  • Twitter: @mergebasesecure
    86 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 40% Small, 35% Medium

What Are Recent G2 Reviews of MergeBase?

Rainforest Application

Rainforest is the all-in-one cyber security platform with an end-to-end approach to simplify corporate reputation protection by using multiple intelligences and proactive observability, adding Application and Cloud Security (from DevOps to DevSecOps), Vulnerability Intelligence, and Brand reputation (Fraud and Leak monitoring). Rainforest Application, Rainforest Cloud, and Rainforest Asset modules allow development and security teams have visibility of all applications lifecycle, in a simple and quick way, providing vulnerability management always that a new line is coded. Rainforest Fraud, Rainforest Leak, and Rainforest Asset build an integrated vision of Vulnerability and Brand Intelligence, guiding security and compliance teams in an efficient manner on potential exposure points, according to their importance to the business regarding the company's reputation.

Average Rating: 4.9/5.0

Total Reviews: 12

How Do G2 Users Rate Rainforest Application?

  • Quality of Support: 9.8/10 (Category avg: 9.0/10)
  • Language Support: 8.0/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.0/10 (Category avg: 8.7/10)
  • Integration: 8.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Rainforest Application?

Who Uses This Product?

  • Company Size: 42% Medium, 42% Small

What Are Recent G2 Reviews of Rainforest Application?

Codacy

Codacy is the code quality and security platform for AI-assisted engineering teams. AI is now embedded through the engineering workflow, which has made teams faster, but also adds risk to everything they ship. Codacy helps AI-assisted teams ship high-quality, secure code across the full software development lifecycle, starting in the agent and editor, through pull requests in Git, and into containers and runtime security. At each stage we check for quality issues, security vulnerabilities and AI coding risk introduced into the codebase, and help devs and agent fix them effortlessly. A team's standards become automated guardrails that apply across every IDE, AI coding agent, and Pull Request. More than 250,000 developers rely on Codacy to keep quality and security stable as AI changes how software gets built. Add your repo and get your free scan report in minutes: https://codacy.com

Average Rating: 4.6/5.0

Total Reviews: 29

How Do G2 Users Rate Codacy?

  • Quality of Support: 9.1/10 (Category avg: 9.0/10)

Who Is the Company Behind Codacy?

  • Seller: Codacy
  • Year Founded: 2012
  • HQ Location: Lisbon, Lisboa
  • Twitter: @codacy
    5,002 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    62 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 59% Small, 24% Medium

What Do G2 Reviewers Say About Codacy?

AI-generated summary from verified user reviews

Pros
  • Users value the enhanced security features of Codacy, benefiting from integrated automation and insightful vulnerability management.
  • Users appreciate the integrated automation of Codacy, finding it easy to use and helpful for maintaining code quality.
  • Users find the out-of-the-box automation in Codacy to be user-friendly and effective for maintaining code quality.
  • Users value the high code quality provided by Codacy's integrated automation and effective static code analyses.
  • Users value the helpful customer support of Codacy, appreciating their immediate assistance during integration and security management.
Cons
  • Users find Codacy expensive at $19/month, which can be a barrier for smaller organizations.

What Are Recent G2 Reviews of Codacy?

ThreatWorx

ThreatWorx is a next-gen proactive cybersecurity platform that protects servers, cloud, containers and source code from malware and vulnerabilities without scanner appliances or bulky agents. ThreatWorx serves multiple use cases including threat intelligence, DevSecOps, cloud security, vulnerability management and third party risk assessment.

Average Rating: 4.7/5.0

Total Reviews: 9

How Do G2 Users Rate ThreatWorx?

  • Quality of Support: 9.8/10 (Category avg: 9.0/10)
  • Language Support: 8.3/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.2/10 (Category avg: 8.7/10)
  • Integration: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind ThreatWorx?

  • Seller: Threatwatch
  • Year Founded: 2016
  • HQ Location: LOS GATOS, US
  • Twitter: @threatwatch
    100 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 40% Medium, 40% Small

What Are Recent G2 Reviews of ThreatWorx?

What Are G2 Users Discussing About ThreatWorx?

Arnica

Arnica is a comprehensive application security posture management (ASPM) platform that protects developers, source code, and products throughout the software development lifecycle. The platform provides real-time application security scanning with 100% coverage across the software supply chain, addressing risks in Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC), hardcoded secrets detection, and more. At its core, Arnica offers AI-native security governance that takes control of AI-generated code through advanced AI SAST scanning and agentic rules enforcement. The platform automatically injects centrally-controlled security requirements into AI coding agents like Copilot, Cursor, and Claude at the point of code generation, ensuring every line of AI-written code is secure by default before vulnerabilities reach production. This approach addresses 92% of risks before they ever reach production environments. Arnica's pipelineless architecture provides automatic coverage for every repository without requiring CI/CD pipeline integrations or IDE deployments. The platform scans every code change at the feature branch level, delivering developer-native workflows that keep teams focused on building features rather than chasing security issues. Risk prioritization is enhanced through OWASP Top 10, CVSS, EPSS, and KEV scoring, combined with organizational context to surface the most critical vulnerabilities. The platform excels in developer experience by delivering security findings directly within existing workflows through Slack, Microsoft Teams, pull request comments, and automated ticket management in Jira and Azure DevOps Boards. AI-powered mitigation suggestions provide context-aware, automated fixes that align with organizational coding standards, significantly reducing mean-time-to-remediation. Key security capabilities include real-time secrets detection with automatic validation and mitigation, comprehensive container scanning that maps vulnerabilities directly to source code, and intelligent dependency management with automated SCA upgrades. The platform maintains SOC 2 Type 2 compliance and ISO 27001 certification, ensuring enterprise-grade security standards. Arnica's unique value proposition lies in its ability to scale security across entire organizations while maintaining development velocity, providing complete visibility into code risks, and enabling proactive security measures that prevent vulnerabilities from reaching production environments.

Average Rating: 4.9/5.0

Total Reviews: 8

How Do G2 Users Rate Arnica?

  • Quality of Support: 10.0/10 (Category avg: 9.0/10)
  • Language Support: 8.3/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 10.0/10 (Category avg: 8.7/10)
  • Integration: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Arnica?

  • Seller: Arnica
  • Company Website:
  • Year Founded: 2021
  • HQ Location: Alpharetta, Georgia
  • Twitter: @arnicaio
    124 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    60 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 63% Large, 25% Small

What Do G2 Reviewers Say About Arnica?

AI-generated summary from verified user reviews

Pros
  • Users value the accuracy of findings from Arnica, enhancing security through effective management of privileges.
  • Users value Arnica for its actionable recommendations, simplifying the management of elevated privileges in source code repositories.
  • Users appreciate the easy setup and administration of Arnica, which saves valuable time and effort.
  • Users love the easy setup of Arnica, making administration a quick and efficient process.
  • Users value Arnica for its ability to reduce attack surface by identifying and rectifying excessive privileged access efficiently.
Cons
  • Users find the paid features limited for smaller teams, restricting access to crucial protections in Arnica.

What Are Recent G2 Reviews of Arnica?

What Are G2 Users Discussing About Arnica?

GuardRails

GuardRails is an end-to-end security platform that makes AppSec easier for both security and development teams. We scan, detect, and provide real-time guidance to fix vulnerabilities early. Trusted by hundreds of teams around the world to build safer apps, GuardRails integrates seamlessly into the developers’ workflow, quietly scans as they code, and shows how to fix security issues on the spot via Just-in-Time training. GuardRails commits to keeping the noise low and only reporting high-impact vulnerabilities that are relevant to your organization. GuardRails helps organizations shift security everywhere and build a strong DevSecOps pipeline, so they can go faster to market without risking security.

Average Rating: 4.3/5.0

Total Reviews: 29

How Do G2 Users Rate GuardRails?

  • Quality of Support: 8.5/10 (Category avg: 9.0/10)
  • Language Support: 9.2/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 10.0/10 (Category avg: 8.7/10)
  • Integration: 8.9/10 (Category avg: 8.8/10)

Who Is the Company Behind GuardRails?

  • Seller: GuardRails
  • Year Founded: 2017
  • HQ Location: Singapore, Singapore
  • Twitter: @guardrailsio
    1,553 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 52% Small, 48% Medium

What Do G2 Reviewers Say About GuardRails?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the robust security features of GuardRails, ensuring efficient code scans and vulnerability management in DevSecOps.
  • Users value the vulnerability detection capabilities of GuardRails, enhancing security with automated, comprehensive code scans.
  • Users find GuardRails easy to use, offering integrated feedback on security issues directly within their development environment.
  • Users value the error reduction capabilities of GuardRails, enabling early detection and swift resolution of security issues.
  • Users value the effective threat detection of GuardRails, ensuring secure code and timely vulnerability alerts during development.
Cons
  • Users note missing features in GuardRails, such as limited developer support and lack of report generation capabilities.
  • Users find time management challenging with GuardRails due to insufficient resources and requirement for constant supervision.
  • Users face bug issues with GuardRails, resulting in frequent bottlenecks and complications during code pushing.
  • Users face challenges with dashboard issues, including insufficient report generation and syncing difficulties for new users.
  • Users report false positives in GuardRails, which can complicate the vulnerability management process despite a helpful dashboard.

What Are Recent G2 Reviews of GuardRails?

Vigiles

Vigiles is a best-in-class vulnerability monitoring and remediation tool that combines a curated CVE database, continuous security feed based on your SBOM, powerful filtering, and easy triage tools so you don’t get blindsided by vulnerabilities.

Average Rating: 4.2/5.0

Total Reviews: 6

How Do G2 Users Rate Vigiles?

  • Quality of Support: 8.8/10 (Category avg: 9.0/10)
  • Language Support: 8.9/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.9/10 (Category avg: 8.7/10)
  • Integration: 7.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Vigiles?

  • Seller: Timesys
  • Year Founded: 1996
  • HQ Location: Pittsburgh, US
  • Twitter: @Timesys
    540 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    52 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 83% Small, 17% Medium

What Are Recent G2 Reviews of Vigiles?

ZeroPath

ZeroPath (YC S24) is the first AI-native application security platform that fundamentally reimagines how organizations find and fix vulnerabilities. Unlike deterministic SAST tools that bolt AI onto legacy rule engines, ZeroPath was built from the ground up to combine large language models with advanced program analysis (AST, data flow, taint tracking) by Ex-Tesla Red Team and Google Security engineers. ZeroPath's core differentiation is detecting critical vulnerabilities that pattern-matching SAST fundamentally cannot find. It catches IDORs, authorization bypasses, race conditions, and authentication bugs by reasoning about application behavior and developer intent. This capability achieved a 92% alert reduction when triaging findings from legacy tools. ZeroPath is best suited for enterprises and startups that want a complete appsec experience with: AI-powered SAST across 16+ languages, SCA with exploitability analysis (90% noise reduction by determining if dependency CVEs are actually reachable in your code), secrets detection with validation, IaC scanning for Terraform/CloudFormation/Kubernetes, and natural language security policies. Context-aware autopatch generation fixes 70% of vulnerabilities automatically with framework-specific patches that match your coding standards. To keep the developer experience seamless, ZeroPath integrates into existing workflows with zero configuration. It provides Sub-60-second PR scans on GitHub, GitLab, Bitbucket, and Azure DevOps to provide instant security feedback without blocking development. Developers receive clear explanations, one-click fixes, and can refine patches using natural language commands directly in PR comments. The platform automatically attributes vulnerabilities to responsible developers and syncs bidirectionally with Jira, Linear, and more. Overall, less noise, along with the breadth of integrations, has already made security teams faster in triaging and finding real vulnerabilities. Having been security engineers ourselves, we also understand how important visibility is for the evaluations. ZeroPath users get executive dashboards with real-time MTTR tracking, automated compliance reporting for SOC2 and ISO27001, and risk-based prioritization using CVSS 4.0 scoring. The platform provides complete visibility across organizational repositories, including security models, authentication patterns, and filtering logic, without manual configuration. Our research team dogfeeds our own technology and has discovered CVE-2025-61928 (critical account takeover in better-auth with 300k+ weekly downloads), identified 170+ verified bugs in curl, found 7 vulnerabilities in django-allauth enabling account impersonation, and discovered 0-days in production systems at Netflix, Hulu, and Salesforce. Currently trusted by 750+ companies running 200k+ scans monthly, ZeroPath delivers what security-conscious engineering teams need: more real vulnerabilities, dramatically less noise, and automated fixes that actually work.

Average Rating: 4.5/5.0

Total Reviews: 11

How Do G2 Users Rate ZeroPath?

  • Quality of Support: 9.4/10 (Category avg: 9.0/10)
  • Integration: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind ZeroPath?

  • Seller: ZeroPath
  • Company Website:
  • Year Founded: 2024
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 36% Small, 27% Medium

What Do G2 Reviewers Say About ZeroPath?

AI-generated summary from verified user reviews

Pros
  • Users value the high accuracy of ZeroPath, effectively identifying real security issues with minimal false alarms.
  • Users value the accuracy of findings from ZeroPath, as it effectively identifies real security issues with minimal false alarms.
  • Users commend ZeroPath for its high accuracy in security detection, minimizing false alarms and enhancing issue resolution.
  • Users commend ZeroPath for its highly accurate vulnerability detection, minimizing false alarms and enhancing security efforts.
  • Users commend ZeroPath for its accurate vulnerability identification, significantly reducing false alarms and enhancing security efforts.
Cons
  • Users report bug issues with ZeroPath, but the support team addresses them quickly and effectively.
  • Users experience some bugs with ZeroPath, but the support team quickly resolves them to improve functionality.
  • Users face some software bugs in ZeroPath, though the team is responsive in resolving them quickly.
  • Users feel that the pricing structure of ZeroPath is not currently suitable for their organization's budget.
  • Users experience bugs in the dashboard, though the ZeroPath team swiftly addresses these problems.

What Are Recent G2 Reviews of ZeroPath?

Debricked

Debricked's SCA-tool allows you to manage your open source in an easy, smart and efficient manner. Automatically find, fix and prevent vulnerabilities, avoid non compliant licenses and evaluate the health of your dependencies - all in one tool. Security - Your developers shouldn't have to be security experts in order to write secure code. Debricked helps your developers automate open source security in their own pipelines and generate fixes with a button click. License Compliance - Make open source compliance a non issue by automating the prevention of non compliant licenses. Set customizable pipeline rules and make sure to be ready for launch year round. Community Health - Help your developers make informed decisions when choosing what open source to use. Search for name or functionality and easily compare similar projects side by side on a set of health metrics.

Average Rating: 4.8/5.0

Total Reviews: 5

How Do G2 Users Rate Debricked?

  • Quality of Support: 9.4/10 (Category avg: 9.0/10)
  • Language Support: 6.7/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.3/10 (Category avg: 8.7/10)
  • Integration: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind Debricked?

  • Seller: Debricked
  • Year Founded: 2018
  • HQ Location: Malmö, SE
  • Twitter: @debrickedab
    473 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 60% Small, 40% Medium

What Are Recent G2 Reviews of Debricked?

Sonatype Nexus Repository

World’s #1 Repository Manager with Free and Pro versions - Single source of truth for all of your components, binaries, and build artifacts. - Efficiently distribute parts and containers to developers. - Used by more than 5 million developers globally. Centralize Give your teams a single source of truth for every component they use. Store Optimize build performance and reliability by caching proxies of remote repositories. Adapt Deliver universal coverage for all major package types and formats Scale Install on an unlimited amount of servers for an unlimited amount of users. Universal Support for all Popular Build Tools Store and distribute Maven/Java, npm, NuGet, Helm, Docker, P2, OBR, APT, GO, R, Conan components and more. Manage components from dev through delivery: binaries, containers, assemblies, and finished goods. Awesome support for the Java Virtual Machine (JVM) ecosystem, including Gradle, Ant, Maven, and Ivy. Compatible with popular tools like Eclipse, IntelliJ, Hudson, Jenkins, Puppet, Chef, Docker, and more. Enterprise Control of Binaries and Build Artifacts Deliver innovation 24x7x365 with high availability. A single source of truth for components used across your entire software development lifecycle including QA, staging, and operations. Easily integrate with existing user and access provisioning systems including LDAP, Atlassian Crowd, and more. SAML/SSO authentication for enhanced security and single sign-on experience. See the Health of Your Software Supply Chain Repository Health Check (RHC) provides up-to-date component intelligence, so your teams make informed decisions early on. View components in need of remediation, prioritized by the severity of vulnerability. Easily avoid known security and license issues for Maven/Java, npm, NuGet, and PyPI components. Modern Features for Continuous Innovation Deploy directly to a desired repository with your choice of build or deployment tool or directly via HTTP. Stage and manage releases with dedicated security and automated rule validation. Enhanced staging provides streamlined oversight and approval of workflows for release candidates. Share binaries, snapshots and releases between groups of developers or post a collection of related, staged artifacts which can be easily tested, promoted, or discarded.

Average Rating: 4.5/5.0

Total Reviews: 21

How Do G2 Users Rate Sonatype Nexus Repository?

  • Quality of Support: 8.3/10 (Category avg: 9.0/10)

Who Is the Company Behind Sonatype Nexus Repository?

  • Seller: Sonatype
  • Year Founded: 2008
  • HQ Location: Fulton, US
  • Twitter: @sonatype
    10,589 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    567 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 43% Large, 39% Medium

What Are Recent G2 Reviews of Sonatype Nexus Repository?

What Are G2 Users Discussing About Sonatype Nexus Repository?

Kiuwan Code Security & Insights

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

Average Rating: 4.5/5.0

Total Reviews: 29

How Do G2 Users Rate Kiuwan Code Security & Insights?

  • Quality of Support: 8.9/10 (Category avg: 9.0/10)

Who Is the Company Behind Kiuwan Code Security & Insights?

  • Seller: Sembi
  • Company Website:
  • Year Founded: 2023
  • HQ Location: Austin, US
  • LinkedIn® Page: www.linkedin.com
    114 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Banking
  • Company Size: 41% Large, 35% Medium

What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the accuracy of the results from Kiuwan Code Security & Insights, enhancing their overall experience.
  • Users value the accuracy of findings from Kiuwan, enhancing their satisfaction with code security and reporting.
  • Users commend the efficient customer support of Kiuwan, ensuring timely assistance and strong satisfaction overall.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, making it very easy to navigate.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, enhancing ease of use for dashboards.

What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

Sonatype Lifecycle

Continuously secure your software supply chain with Sonatype Nexus Lifecycle, a software composition analysis (SCA) solution. Nexus Lifecycle helps development, security, and compliance teams reduce open source risk without slowing delivery. It detects vulnerable or non-compliant components early, provides clear remediation guidance, and enforces the same policies from development through CI/CD and release - powered by Sonatype Nexus Intelligence. Choose safer components up front: A Chrome extension and IDE integrations surface vulnerability, license, and quality insights as developers browse public repositories or add dependencies. Fix issues fast where work happens: In Eclipse, IntelliJ, and Visual Studio, developers can see exactly what's wrong and upgrade to an approved version with a click - no guesswork. Automate remediation in source control: Integrations with GitHub, GitLab, and Atlassian Bitbucket can comment on pull/merge requests and identify the specific dependency change that introduces risk, along with recommended versions to resolve it. You can also generate automated pull requests to update components that violate policy. Enforce open source policies across the SDLC: Create security, license, and architectural policies tailored by application type, team, or organization, then apply them consistently in developer tools, CI/CD, and repositories to prevent risky components from reaching production. Generate SBOMs in minutes: Produce accurate Software Bills of Materials (SBOMs) per application to understand what components and transitive dependencies are in use and verify compliance. Prove progress with reporting: Track trends like Mean Time to Resolution (MTTR) and violation reduction over time to demonstrate measurable risk reduction to stakeholders. Nexus Lifecycle integrates with common developer, CI/CD, and repository tools including Nexus Repository, Artifactory, Jira, Jenkins, Azure DevOps, and more.

Average Rating: 4.2/5.0

Total Reviews: 3

How Do G2 Users Rate Sonatype Lifecycle?

  • Quality of Support: 7.5/10 (Category avg: 9.0/10)

Who Is the Company Behind Sonatype Lifecycle?

  • Seller: Sonatype
  • Year Founded: 2008
  • HQ Location: Fulton, US
  • Twitter: @sonatype
    10,589 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    567 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 75% Large, 25% Medium

What Are Recent G2 Reviews of Sonatype Lifecycle?

Xygeni

Xygeni: AI-Native ASPM for the Software Supply Chain Xygeni is an AI-native ASPM (Application Security Posture Management) platform that unifies native and third-party security findings into one prioritized view. Its own detection engines cover SAST, SCA, DAST, Secrets, IaC, Container, CI/CD, and Build Security, and it also ingests results from tools like Snyk, Veracode, and Checkmarx so teams don't have to abandon what they've already invested in. Every finding, regardless of source, gets scored by exploitability, reachability, and business impact through Xygeni's Dynamic Funnels, which is what drives its reported 90% cut in alert noise. Two AI systems sit underneath the platform. CoreAI acts as a correlation and reporting layer for security leaders, turning scattered findings into a single risk narrative. DevAI works earlier, inside the developer's IDE and AI coding assistants, catching problems in both human-written and AI-generated code and proposing fixes before a pull request is even opened. On the supply chain side, Xygeni's MEW engine (Malware Early Warning) is built to catch malicious open-source packages the moment they hit a public registry, ahead of when a formal malware signature would normally exist. Shield takes that enforcement to the developer's own machine, blocking unauthorized package downloads at the OS level before they reach disk. Xygeni also runs a dedicated Code Quality engine across ten languages, ranking maintainability and complexity issues alongside security findings in the same console, so a team can see when the messiest file is also the riskiest one. The platform connects to GitHub, GitLab, Bitbucket, Jenkins, and Azure DevOps, and deploys as SaaS, on-premises, or fully air-gapped. Xygeni was named Hot Company in ASPM and in GenAI Application Security at the 2026 Global InfoSec Awards.

Average Rating: 4.6/5.0

Total Reviews: 4

How Do G2 Users Rate Xygeni?

  • Quality of Support: 10.0/10 (Category avg: 9.0/10)
  • Language Support: 8.3/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 10.0/10 (Category avg: 8.7/10)
  • Integration: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Xygeni?

  • Seller: Xygeni Security
  • Year Founded: 2021
  • HQ Location: Madrid, ES
  • Twitter: @xygeni
    178 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    30 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 60% Small, 40% Medium

What Do G2 Reviewers Say About Xygeni?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the comprehensive security features of Xygeni, fostering a secure development environment without hindering productivity.
  • Users value the effective prioritization of security issues in Xygeni, allowing teams to focus on critical threats quickly.
  • Users value the effective risk management of Xygeni, enhancing security without hindering software development processes.
  • Users appreciate the robust security features of Xygeni, enhancing their development process while ensuring compliance and risk management.
  • Users value the seamless CI/CD integration of Xygeni, enabling early vulnerability detection without impacting release schedules.
Cons
  • Users face difficult setup issues with Xygeni, especially when dealing with certain edge cases requiring manual adjustments.
  • Users find the learning curve challenging for newcomers despite a generally intuitive platform, requiring familiarity with AppSec practices.

What Are Recent G2 Reviews of Xygeni?