Best Software Composition Analysis Tools - Page 2

How Many Software Composition Analysis Tools Products Does G2 Track?

Total Products under this Category: 75

Category Stats (Sep 2026)

  • Average Rating: 4.49/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Software Composition Analysis Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 6,600+ Authentic Reviews
  • 75+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Software Composition Analysis Tools

G2 Grid® for Software Composition Analysis Tools plotting products by satisfaction and market presence

Highlighted products: Wiz, Aikido Security, GitHub, Mend.io, Snyk, GitLab, DigiCert ONE, and Semgrep.

Underlying data: [Grid® JSON](https://www.g2.com/categories/software-composition-analysis/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=github&focus%5B%5D=mend-io&focus%5B%5D=snyk&focus%5B%5D=gitlab&focus%5B%5D=digicert-one&focus%5B%5D=semgrep)

Socket

Socket is the leading developer-first security platform that protects modern applications from malicious and vulnerable open source dependencies. By combining real-time package monitoring with AI-powered code analysis, Socket detects and blocks supply chain attacks within minutes of publication. With advanced reachability analysis, automated remediation, and license compliance features, Socket enables teams to focus on building software, while we keep their open source code secure.

Average Rating: 4.7/5.0

Total Reviews: 10

How Do G2 Users Rate Socket?

  • Quality of Support: 9.0/10 (Category avg: 9.0/10)
  • Language Support: 8.9/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.3/10 (Category avg: 8.7/10)
  • Integration: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Socket?

  • Seller: Socket
  • Year Founded: 2020
  • HQ Location: San Francisco, US
  • Twitter: @SocketSecurity
    21,558 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    115 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 40% Medium, 30% Large

What Do G2 Reviewers Say About Socket?

AI-generated summary from verified user reviews

Pros
  • Users value the robust security features of Socket, particularly its effectiveness in monitoring supply chain attacks.
  • Users value Socket's effective open source security analysis, which simplifies package evaluation and enhances overall efficiency.
  • Users commend the accuracy of findings from Socket, appreciating its unique analysis methods and time-saving capabilities.
  • Users value Socket's proactive alerts for supply chain attacks, enhancing security and customer support responsiveness.
  • Users value the comprehensive security that Socket provides, enhancing decision-making in software supply-chain management.
Cons
  • Users feel the missing features in Socket hinder its ability to consolidate tools for diverse use cases.
  • Users report experiencing system slowness with Socket, particularly noting delays in UI loading times.

What Are Recent G2 Reviews of Socket?

SOOS

SOOS is the complete application security posture management platform. Scan your software for vulnerabilities, control the introduction of new dependencies, exclude unwanted license types, generate and manage Software Bill of Materials (SBOM), and fill out your compliance worksheets across all your teams. SOOS’s ASPM is a dynamic, comprehensive approach to safeguarding your application infrastructure from vulnerabilities across the Software Development Life Cycle (SDLC) and live deployments. Easy to integrate, all in one dashboard. SCA - Deep tree vulnerability scanning, license compliance, governance DAST - Automated Web & API vulnerability scanning Containers - Scan contents for vulnerabilities SAST - Analyze code for security vulnerabilities IaC - Cloud security coverage SBOMs - Create – monitor – manage

Average Rating: 4.6/5.0

Total Reviews: 42

How Do G2 Users Rate SOOS?

  • Quality of Support: 9.3/10 (Category avg: 9.0/10)
  • Language Support: 9.5/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.4/10 (Category avg: 8.7/10)
  • Integration: 9.5/10 (Category avg: 8.8/10)

Who Is the Company Behind SOOS?

  • Seller: SOOS
  • Year Founded: 2019
  • HQ Location: Winooski, US
  • Twitter: @soostech
    44 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    21 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 50% Medium, 43% Small

What Do G2 Reviewers Say About SOOS?

AI-generated summary from verified user reviews

Pros
  • Users commend the ease of use of SOOS, highlighting its user-friendly setup and supportive onboarding process.
  • Users value the easy integrations of SOOS, enhancing workflow without hindering developer efficiency.
  • Users appreciate the easy integrations of SOOS, enhancing workflow without hindering development processes.
  • Users highlight the awesome customer support from SOOS, enhancing the overall user experience during onboarding.
  • Users value the continuous vulnerability detection by SOOS, enhancing security and compliance without disrupting workflow.
Cons
  • Users note the need for inadequate reporting features, highlighting a lack of customization and richer options for analysis.
  • Users highlight poor reporting in SOOS, seeking better filtering and display options for vulnerability analysis.
  • Users find SOOS to be lacking features, particularly in reporting and user interface intuitiveness.
  • Users express concern over the lack of guidance in documentation and actionable recommendations for vulnerability remediation.
  • Users find the dashboard issues frustrating, as richer reporting and filtering options are lacking.

What Are Recent G2 Reviews of SOOS?

HCL AppScan

HCL AppScan is a comprehensive suite of market-leading application security testing solutions (SAST, DAST, IAST, SCA, API), available on-premises and on-cloud. These powerful DevSecOps tools pinpoint application vulnerabilities, allowing for quick remediation in every phase of the software development lifecycle. Fast and Accurate Scanning for Secure DevOps Developers and DevOps teams can quickly and accurately scan code, applications, and APIs for security vulnerabilities while applications are being developed. This allows companies to fix issues at the earliest stages of the software development lifecycle, when it is least costly to the business. Focus on the Fix Continuous monitoring with IAST, along with auto issue correlation with DAST and SAST scan results allows DevOps teams to group and prioritize findings for faster, more streamlined remediation. Enterprise Management for Security Teams Centralized, easy-to-use dashboards provide visibility and oversight of all security scanning and remediation, and allow users to set scan parameters and compliance policies.

Average Rating: 4.2/5.0

Total Reviews: 87

How Do G2 Users Rate HCL AppScan?

  • Quality of Support: 8.4/10 (Category avg: 9.0/10)
  • Language Support: 8.8/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.8/10 (Category avg: 8.7/10)
  • Integration: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind HCL AppScan?

  • Seller: HCL Technologies
  • Company Website:
  • Year Founded: 1999
  • HQ Location: Noida, Uttar Pradesh
  • Twitter: @hcltech
    425,043 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    258,955 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 53% Large, 28% Small

What Are Recent G2 Reviews of HCL AppScan?

What Are G2 Users Discussing About HCL AppScan?

Contrast Security

Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous, real-time defense, Contrast uncovers hidden application layer risks that traditional solutions miss. Contrast’s powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.

Average Rating: 4.5/5.0

Total Reviews: 49

How Do G2 Users Rate Contrast Security?

  • Quality of Support: 9.3/10 (Category avg: 9.0/10)
  • Language Support: 8.1/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.0/10 (Category avg: 8.7/10)
  • Integration: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Contrast Security?

  • Seller: Contrast Security
  • Year Founded: 2014
  • HQ Location: Pleasanton, CA
  • Twitter: @contrastsec
    5,468 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    182 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Insurance, Information Technology and Services
  • Company Size: 67% Large, 20% Medium

What Do G2 Reviewers Say About Contrast Security?

AI-generated summary from verified user reviews

Pros
  • Users value the accuracy of findings from Contrast Security, ensuring greater precision in identifying vulnerabilities.
  • Users value the accuracy of results from Contrast Security, benefiting from precise vulnerability monitoring and analysis.
  • Users commend the real-time vulnerability detection of Contrast Security, appreciating its quick feedback and agile support.
Cons
  • Users experienced performance issues with Contrast Security, particularly with Java applications, but found support helpful in resolving them.

What Are Recent G2 Reviews of Contrast Security?

What Are G2 Users Discussing About Contrast Security?

Jit

Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empowers organizations to proactively manage security risks across the entire software development lifecycle.​ AI-Powered Agents Jit's AI Agents, such as SERA (Security Evaluation and Remediation Agent) and COTA (Communication, Ops, and Ticketing Agent), collaborate with your teams to automate vulnerability triage, risk assessment, and remediation processes, significantly reducing manual workloads. ​ Comprehensive Security Scanning Achieve full-stack security coverage with integrated scanners for SAST, DAST, SCA, IaC, CSPM, and more. Jit's platform ensures continuous monitoring and immediate feedback on code changes, facilitating rapid identification and resolution of security issues. ​ Developer-Centric Experience With integrations into popular IDEs and CI/CD pipelines, Jit provides developers with contextual security insights directly within their workflows, promoting a shift-left approach without disrupting productivity. ​ Agentic AI for AppSec Teams Risk-Based Prioritization Utilizing the Model Context Protocol (MCP), Jit evaluates vulnerabilities in the context of runtime environments, business impact, and compliance requirements, enabling teams to focus on the most critical risks. ​ Seamless Integrations Jit integrates with a wide array of tools, including GitHub, GitLab, AWS, Azure, GCP, Jira, Slack, and more, ensuring that security processes are embedded within your existing technology stack. ​

Average Rating: 4.5/5.0

Total Reviews: 43

How Do G2 Users Rate Jit?

  • Quality of Support: 9.3/10 (Category avg: 9.0/10)
  • Language Support: 8.3/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.5/10 (Category avg: 8.7/10)
  • Integration: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Jit?

  • Seller: jit
  • Year Founded: 2021
  • HQ Location: Boston, MA
  • Twitter: @jit_io
    522 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    161 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Financial Services
  • Company Size: 44% Medium, 42% Small

What Do G2 Reviewers Say About Jit?

AI-generated summary from verified user reviews

Pros
  • Users value the seamless integration of security in Jit, enhancing efficiency without overwhelming the development process.
  • Users value the easy integrations of Jit, streamlining security into development without overwhelming workflows.
  • Users appreciate the ease of use of Jit, as it simplifies integration and enhances productivity without added complexity.
  • Users value the efficiency of Jit, noting significant waste reduction and streamlined processes that enhance overall productivity.
  • Users praise the easy integration support of Jit, streamlining security practices in the development workflow.
Cons
  • Users note integration issues, as Jit may not support all enterprise environments and requires extra manual setup.
  • Users find the product has limited features, especially in customization and advanced analytics for complex environments.
  • Users express concerns about limited integration with enterprise environments and third-party tools, hindering overall usability.
  • Users find the documentation lacking for advanced configurations, making it difficult to fully utilize Jit.
  • Users find the complexity of Jit's advanced integrations and features overwhelming for beginners and experienced developers alike.

What Are Recent G2 Reviews of Jit?

Aqua Security

Aqua Security sees and stops attacks across the entire cloud native application lifecycle in a single, integrated platform. From software supply chain security for developers to cloud security and runtime protection for security teams, Aqua helps customers reduce risk while building the future of their businesses. The Aqua Platform is the industry’s most comprehensive Cloud Native Application Protection Platform (CNAPP). Founded in 2015, Aqua is headquartered in Boston, MA and Ramat Gan, IL with Fortune 1000 customers in over 40 countries.

Average Rating: 4.2/5.0

Total Reviews: 57

How Do G2 Users Rate Aqua Security?

  • Quality of Support: 8.0/10 (Category avg: 9.0/10)
  • Language Support: 7.3/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 6.3/10 (Category avg: 8.7/10)
  • Integration: 7.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Aqua Security?

Who Uses This Product?

  • Top Industries: Computer Software, Financial Services
  • Company Size: 56% Large, 39% Medium

What Do G2 Reviewers Say About Aqua Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the robust security features of Aqua Security, effectively managing vulnerabilities and ensuring compliance.
  • Users highlight the ease of use of Aqua Security, noting its intuitive design and straightforward implementation process.
  • Users appreciate the intuitive setup of Aqua Security, finding deployment and scanning straightforward and manageable.
  • Users appreciate the effective detection capabilities of Aqua Security, simplifying the management of container security challenges.
  • Users value Aqua Security for its effective vulnerability identification, simplifying management of container security and compliance.
Cons
  • Users find missing features in Aqua Security, like inadequate dashboards and minimal reporting, hinder their experience.
  • Users find the lack of features frustrating, particularly with inadequate APIs and ineffective dashboards for analysis.
  • Users find Aqua Security has limited features, lacking support for various applications and essential reporting options.
  • Users find the difficult navigation of Aqua Security’s UI complicates data identification and overall experience.
  • Users find improvement needed in Aqua Security's dashboards and reporting features, causing delays in necessary enhancements.

What Are Recent G2 Reviews of Aqua Security?

FOSSA

Open source is a critical part of your software. In the average modern software product, over 80% of the source code shipped is derived from open source. Each component can have cascading legal, security, and quality implications for your customers, making it one of the most important things to manage correctly. FOSSA helps you manage your open source components. We plug into your development workflow to help your team automatically track, manage, and remediate issues with the open source you use to: - Stay compliant with software licenses and generate required attribution documents - Enforce usage and licensing policies throughout your CI/CD workflow - Monitor and remediate security vulnerabilities - Flag code quality issues and outdated components proactively By enabling open source, we help development teams increase development velocity and decrease risk.

Average Rating: 4.2/5.0

Total Reviews: 15

How Do G2 Users Rate FOSSA?

  • Quality of Support: 8.3/10 (Category avg: 9.0/10)
  • Language Support: 8.8/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.5/10 (Category avg: 8.7/10)
  • Integration: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind FOSSA?

  • Seller: FOSSA
  • Year Founded: 2015
  • HQ Location: San Francisco, California
  • Twitter: @getfossa
    774 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    63 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 47% Small, 33% Medium

What Do G2 Reviewers Say About FOSSA?

AI-generated summary from verified user reviews

Pros
  • Users highlight the easy integrations of FOSSA, seamlessly working with Spring Boot and Angular applications through their pipeline.
  • Users appreciate FOSSA for its effective issue resolution, identifying library problems and recommending fixes in real-time.
  • Users find FOSSA's remediation solutions valuable for quickly identifying and recommending fixes for vulnerabilities in dependencies.
  • Users value the effective risk management provided by FOSSA, ensuring security and quality for applications.
  • Users value FOSSA for its robust security scanning, ensuring vulnerabilities are identified and managed effectively.

What Are Recent G2 Reviews of FOSSA?

MergeBase

MergeBase is revolutionizing software supply chain protection with a full-featured, developer-oriented SCA solution that brings the lowest false positives in the industry and complete DevOps coverage from coding/building to deployment and run-time. MergeBase’s SCA tool analyzes the open-source/third-party libraries for vulnerabilities. Our mission is to protect the software supply chain. We provide a full-featured, developer-oriented solution that has the industry’s lowest false positive rates and complete coverage of the DevOps process.

Average Rating: 4.5/5.0

Total Reviews: 20

How Do G2 Users Rate MergeBase?

  • Quality of Support: 9.3/10 (Category avg: 9.0/10)
  • Language Support: 7.9/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 8.5/10 (Category avg: 8.7/10)
  • Integration: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind MergeBase?

  • Seller: MergeBase Software
  • Year Founded: 2018
  • HQ Location: Coquitlam, British Columbia
  • Twitter: @mergebasesecure
    86 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 40% Small, 35% Medium

What Are Recent G2 Reviews of MergeBase?

Sandworm

Sandworm is a comprehensive software supply chain security solution that detects vulnerabilities in dependencies, provides actionable insights, and ensures a secure and reliable development process for organizations across multiple programming languages. It empowers developers to identify and remediate potential risks, strengthens cybersecurity resilience, and fosters a safer software ecosystem.

Average Rating: 5.0/5.0

Total Reviews: 11

How Do G2 Users Rate Sandworm?

  • Quality of Support: 9.6/10 (Category avg: 9.0/10)
  • Language Support: 9.1/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.6/10 (Category avg: 8.7/10)
  • Integration: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Sandworm?

Who Uses This Product?

  • Top Industries: Marketing and Advertising
  • Company Size: 73% Small, 18% Medium

What Are Recent G2 Reviews of Sandworm?

Endor Labs

Endor Labs turns application security into a competitive advantage. At the core is AURI, the security harness for agentic development. It helps coding agents write secure code by default, automates PR security reviews, and gives agents deterministic context to fix what matters fast. At the core is our patented code context graph: a continuously updated model of application behavior across code, dependencies, secrets, and containers. The result: 83% fewer blocked PRs, 10x fewer security tickets, and 6x faster remediation at Atlassian, Cursor, Rubrik, and Snowflake.

Average Rating: 4.8/5.0

Total Reviews: 9

How Do G2 Users Rate Endor Labs?

  • Quality of Support: 9.8/10 (Category avg: 9.0/10)
  • Language Support: 9.4/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.7/10 (Category avg: 8.7/10)
  • Integration: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind Endor Labs?

  • Seller: Endor Labs
  • Company Website:
  • Year Founded: 2021
  • HQ Location: Palo Alto, California, United States
  • Twitter: @EndorLabs
    592 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    207 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 78% Medium, 22% Large

What Do G2 Reviewers Say About Endor Labs?

AI-generated summary from verified user reviews

Pros
  • Users praise Endor Labs for its effective reachability analysis feature, enhancing accuracy and user experience in security management.
  • Users find Endor Labs' ease of use remarkable, allowing quick access to critical data and intuitive navigation.
  • Users highlight the high accuracy of findings from Endor Labs, enhancing vulnerability assessment and risk management significantly.
  • Users commend Endor Labs for their responsive customer support, consistently providing timely assistance and implementing feature requests.
  • Users value the responsive integration support from Endor Labs, enhancing ease of setup and overall user experience.
Cons
  • Users feel that the UI/UX needs improvement, particularly in API accessibility and clearer authentication displays.
  • Users find the API limitations restrictive, requesting more features to be accessible through the UI.
  • Users find the difficult setup of Endor Labs could be simplified to enhance the overall experience.
  • Users find integration issues challenging, particularly with Jira, though improvements are underway for a better experience.
  • Users note that the UI/UX lacks essential features, such as improved IdP authentication and default branch settings.

What Are Recent G2 Reviews of Endor Labs?

Rainforest Application

Rainforest is the all-in-one cyber security platform with an end-to-end approach to simplify corporate reputation protection by using multiple intelligences and proactive observability, adding Application and Cloud Security (from DevOps to DevSecOps), Vulnerability Intelligence, and Brand reputation (Fraud and Leak monitoring). Rainforest Application, Rainforest Cloud, and Rainforest Asset modules allow development and security teams have visibility of all applications lifecycle, in a simple and quick way, providing vulnerability management always that a new line is coded. Rainforest Fraud, Rainforest Leak, and Rainforest Asset build an integrated vision of Vulnerability and Brand Intelligence, guiding security and compliance teams in an efficient manner on potential exposure points, according to their importance to the business regarding the company's reputation.

Average Rating: 4.9/5.0

Total Reviews: 12

How Do G2 Users Rate Rainforest Application?

  • Quality of Support: 9.8/10 (Category avg: 9.0/10)
  • Language Support: 8.0/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.0/10 (Category avg: 8.7/10)
  • Integration: 8.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Rainforest Application?

Who Uses This Product?

  • Company Size: 42% Medium, 42% Small

What Are Recent G2 Reviews of Rainforest Application?

Arnica

Arnica is a comprehensive application security posture management (ASPM) platform that protects developers, source code, and products throughout the software development lifecycle. The platform provides real-time application security scanning with 100% coverage across the software supply chain, addressing risks in Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC), hardcoded secrets detection, and more. At its core, Arnica offers AI-native security governance that takes control of AI-generated code through advanced AI SAST scanning and agentic rules enforcement. The platform automatically injects centrally-controlled security requirements into AI coding agents like Copilot, Cursor, and Claude at the point of code generation, ensuring every line of AI-written code is secure by default before vulnerabilities reach production. This approach addresses 92% of risks before they ever reach production environments. Arnica's pipelineless architecture provides automatic coverage for every repository without requiring CI/CD pipeline integrations or IDE deployments. The platform scans every code change at the feature branch level, delivering developer-native workflows that keep teams focused on building features rather than chasing security issues. Risk prioritization is enhanced through OWASP Top 10, CVSS, EPSS, and KEV scoring, combined with organizational context to surface the most critical vulnerabilities. The platform excels in developer experience by delivering security findings directly within existing workflows through Slack, Microsoft Teams, pull request comments, and automated ticket management in Jira and Azure DevOps Boards. AI-powered mitigation suggestions provide context-aware, automated fixes that align with organizational coding standards, significantly reducing mean-time-to-remediation. Key security capabilities include real-time secrets detection with automatic validation and mitigation, comprehensive container scanning that maps vulnerabilities directly to source code, and intelligent dependency management with automated SCA upgrades. The platform maintains SOC 2 Type 2 compliance and ISO 27001 certification, ensuring enterprise-grade security standards. Arnica's unique value proposition lies in its ability to scale security across entire organizations while maintaining development velocity, providing complete visibility into code risks, and enabling proactive security measures that prevent vulnerabilities from reaching production environments.

Average Rating: 4.8/5.0

Total Reviews: 9

How Do G2 Users Rate Arnica?

  • Quality of Support: 10.0/10 (Category avg: 9.0/10)
  • Language Support: 8.3/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 10.0/10 (Category avg: 8.7/10)
  • Integration: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Arnica?

  • Seller: Arnica
  • Company Website:
  • Year Founded: 2021
  • HQ Location: Alpharetta, Georgia
  • Twitter: @arnicaio
    124 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    60 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 56% Large, 33% Small

What Do G2 Reviewers Say About Arnica?

AI-generated summary from verified user reviews

Pros
  • Users value the accuracy of findings from Arnica, enhancing security through effective management of privileges.
  • Users value Arnica for its actionable recommendations, simplifying the management of elevated privileges in source code repositories.
  • Users appreciate the easy setup and administration of Arnica, which saves valuable time and effort.
  • Users love the easy setup of Arnica, making administration a quick and efficient process.
  • Users value Arnica for its ability to reduce attack surface by identifying and rectifying excessive privileged access efficiently.
Cons
  • Users find the paid features limited for smaller teams, restricting access to crucial protections in Arnica.

What Are Recent G2 Reviews of Arnica?

What Are G2 Users Discussing About Arnica?

Codacy

Codacy is the code quality and security platform for AI-assisted engineering teams. AI is now embedded through the engineering workflow, which has made teams faster, but also adds risk to everything they ship. Codacy helps AI-assisted teams ship high-quality, secure code across the full software development lifecycle, starting in the agent and editor, through pull requests in Git, and into containers and runtime security. At each stage we check for quality issues, security vulnerabilities and AI coding risk introduced into the codebase, and help devs and agent fix them effortlessly. A team's standards become automated guardrails that apply across every IDE, AI coding agent, and Pull Request. More than 250,000 developers rely on Codacy to keep quality and security stable as AI changes how software gets built. Add your repo and get your free scan report in minutes: https://codacy.com

Average Rating: 4.6/5.0

Total Reviews: 29

How Do G2 Users Rate Codacy?

  • Quality of Support: 9.1/10 (Category avg: 9.0/10)

Who Is the Company Behind Codacy?

  • Seller: Codacy
  • Year Founded: 2012
  • HQ Location: Lisbon, Lisboa
  • Twitter: @codacy
    5,002 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    62 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 59% Small, 24% Medium

What Do G2 Reviewers Say About Codacy?

AI-generated summary from verified user reviews

Pros
  • Users value the enhanced security features of Codacy, benefiting from integrated automation and insightful vulnerability management.
  • Users appreciate the integrated automation of Codacy, finding it easy to use and helpful for maintaining code quality.
  • Users find the out-of-the-box automation in Codacy to be user-friendly and effective for maintaining code quality.
  • Users value the high code quality provided by Codacy's integrated automation and effective static code analyses.
  • Users value the helpful customer support of Codacy, appreciating their immediate assistance during integration and security management.
Cons
  • Users find Codacy expensive at $19/month, which can be a barrier for smaller organizations.

What Are Recent G2 Reviews of Codacy?

DerScanner

DerScanner is a complete application security testing solution to eliminate known and unknown code threats across Software Development Lifecycle. DerScanner static code analysis offers developers the support for 43 programming languages ensuring thorough security coverage for almost any application. DerScanner's SAST uniquely analyzes both source and binary files, revealing hidden vulnerabilities that are often missed in standard scans. This is especially crucial for legacy applications or when source code access is limited. DerScanner’s DAST feature mimics an external attacker, similar to penetration testing. This is vital for finding vulnerabilities that only appear when the application is operational. DAST in DerScanner enriches SAST findings by cross-checking and correlating vulnerabilities detected by both methods. With DerScanner Software Composition Analysis you can gain critical insights into open-source components and dependencies in your projects. It helps identify vulnerabilities early and ensures compliance with licensing terms, reducing legal risks. DerScanner's Supply Chain Security continuously monitors public repositories, evaluating the security posture of each package. This allows you to make informed decisions about using open-source components in your applications.

Average Rating: 5.0/5.0

Total Reviews: 8

How Do G2 Users Rate DerScanner?

  • Quality of Support: 10.0/10 (Category avg: 9.0/10)
  • Language Support: 10.0/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.2/10 (Category avg: 8.7/10)
  • Integration: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind DerScanner?

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 88% Small, 63% Medium

What Are Recent G2 Reviews of DerScanner?

ThreatWorx

ThreatWorx is a next-gen proactive cybersecurity platform that protects servers, cloud, containers and source code from malware and vulnerabilities without scanner appliances or bulky agents. ThreatWorx serves multiple use cases including threat intelligence, DevSecOps, cloud security, vulnerability management and third party risk assessment.

Average Rating: 4.7/5.0

Total Reviews: 9

How Do G2 Users Rate ThreatWorx?

  • Quality of Support: 9.8/10 (Category avg: 9.0/10)
  • Language Support: 8.3/10 (Category avg: 8.5/10)
  • Continuous Monitoring: 9.2/10 (Category avg: 8.7/10)
  • Integration: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind ThreatWorx?

  • Seller: Threatwatch
  • Year Founded: 2016
  • HQ Location: LOS GATOS, US
  • Twitter: @threatwatch
    100 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 40% Medium, 40% Small

What Are Recent G2 Reviews of ThreatWorx?

What Are G2 Users Discussing About ThreatWorx?

Adam Crivello
AC
Researched and written by Adam Crivello
Updated October 3, 2024