Introducing G2.ai, the future of software buying.Try now
Product Avatar Image
Endor Labs

By Endor Labs

4.8 out of 5 stars
3 star
0%
2 star
0%
1 star
0%

How would you rate your experience with Endor Labs?

Endor Labs Reviews & Product Details

Endor Labs Media

Endor Labs Demo - Endor Labs AppSec Platform
The AppSec platform that understands your code and everything it depends on.
Endor Labs Demo - Endor Labs AppSec Platform
Most SCA scanners will scan a manifest file and call it a day. Endor Labs go deeper to find the risks that are worth your time.
Endor Labs Demo - Endor Labs AppSec Platform
Consolidate all your AppSec findings in one place. No context switching, only one tool is needed for correlation.
Endor Labs Demo - Endor Labs AppSec Platform
Upgrade Impact Analysis lets us see the breaking changes this upgrade will introduce. This is why the remediation risk is high!
With Endor Labs for software composition analysis (SCA), you can fix what's easy and patch hard-to-upgrade packages.
Play Endor Labs Video
With Endor Labs for software composition analysis (SCA), you can fix what's easy and patch hard-to-upgrade packages.
How to target the vulnerabilities that (actually) matter
Play Endor Labs Video
How to target the vulnerabilities that (actually) matter
Relativity is the leading legal technology vendor in the legal data intelligence field, also providing services including breach response and contract review. They use Endor Labs for SCA and improved their ability to identify and prioritize
Play Endor Labs Video
Relativity is the leading legal technology vendor in the legal data intelligence field, also providing services including breach response and contract review. They use Endor Labs for SCA and improved their ability to identify and prioritize
Product Avatar Image

Have you used Endor Labs before?

Answer a few questions to help the Endor Labs community

Endor Labs Reviews (7)

Reviews

Endor Labs Reviews (7)

4.8
7 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Verified User in Information Technology and Services
AI
Enterprise (> 1000 emp.)
"Took the SCA scans to whole another level with their reachability analysis"
What do you like best about Endor Labs?

We appreciate Endor Labs for several reasons that have significantly benefited my team and me. Their support team is always helpful, promptly assisting us whenever we encounter obstacles and even implementing feature requests that directly address our issues. This active and responsive customer support is crucial in our daily operations. The Reachability Analysis feature has been a lifesaver, enabling our engineers to allocate their efforts effectively and focus only on impactful upgrades, which prevents the unnecessary use of vulnerable functions from open-source libraries.

Endor Labs' solution gives our team confidence and speed in tackling supply chain security concerns, as it ensures that all libraries are thoroughly scanned for vulnerabilities. Their centralized dashboard is incredibly convenient for quickly checking the usage of dependencies in our code, drastically reducing the time spent on security checks. Their innovative approach to Software Composition Analysis (SCA) is impressive; they prioritize actionable alerts based on reachability, thereby lessening the overwhelming number of findings we might typically have to sift through.

Moreover, setting up Endor Labs was straightforward, which made the initial integration almost seamless. Overall, their extended support and impactful innovations in addressing SCA findings serve as a compelling reason for us to continue using and recommending Endor Labs. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

Nothing so far, they have been good at what they are doing to security landscape. Review collected by and hosted on G2.com.

Response from Jenn Gile of Endor Labs

Thanks for the positive feedback!

I'm not surprised at all to hear such kind words about our support team, they indeed are fantastic. It's great to hear about your experience with reachability (customers average 92% noise reduction) and other features helping you reduce the amount of time spent on security checks.

MS
Principal Software Engineer
Mid-Market (51-1000 emp.)
"Leader in the SCA technology"
What do you like best about Endor Labs?

Reachability analysis feature, detailed and useful recommendations, higher accuracy, flexibility of integration and usage, user friendly UI. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

Endor Labs need to make more of the API capabilities available in the UI. Review collected by and hosted on G2.com.

Response from Jenn Gile of Endor Labs

Hi Muhammad, thank you for your review! We're so glad you're getting value from the platform and totally agree - great features (like reachability analysis) are only great when they're part of a great experience. And of course, we continue to work on the user experience through both the UI and API.

James K.
JK
Head of Security and Privacy
Mid-Market (51-1000 emp.)
"Jellyfish Enables Data-Driven AppSec with Endor Labs"
What do you like best about Endor Labs?

Endor Labs is, in a good way, simplistic. The data we care about is quickly available to us. Our prior SCA tooling reachability analysis wasn't robust and we couldn't determine which vulnerabilities could truly threaten our business, so we couldn't manually research reachability or perform upgrades without knowing if they mattered. Our risk models were overly aggressive to compensate, which has now been dramatically improved by using Endor Labs. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

Endor Labs is a new entrant into the SCA space, and has only been around for a short period of time (2022). There is always a risk of engaging with a critical vendor that you depend on for Security and Compliance, when they are a relatively new business.

We are happy with all of their current features. Review collected by and hosted on G2.com.

Alex O.
AO
DevSecOps Engineer
Mid-Market (51-1000 emp.)
"Likely the Market Leader"
What do you like best about Endor Labs?

Endor Labs is scrappy company that has left me with the impression that they will do what it takes to see their customers succeed. For software composition and reachabiity analysis, it was difficult to find a competing product in the current market that is as fully featured as their platform. They place a big emphasis on methodology (and have SMEs that write about this) and are also capable of performing reachability analysis on transitive dependencies, which was a big selling point for us.

Implementation and ease of integration were also a big selling point. All the basics are there - a CLI tool, an optional Github application, and a well-maintained github action with all the features of the CLI tool. Members of the team, outside of customer support, were ready and able to help whenever we ran into issues in one of our many Java / Maven repositories. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

UI/UX could use some fine tuning. For example, users authenticating via a custom IdP sometimes show up as have an "unknown provider" in the access control tab, despite it being clear that they are sourced from the IdP. It would also be nice to be able to set a default monitored branch from the console (this is currently only possible via a CLI flag). Review collected by and hosted on G2.com.

Young Jin K.
YK
DevSecOps Lead
Mid-Market (51-1000 emp.)
"Endor Labs is an industry leader in the SCA space"
What do you like best about Endor Labs?

Endor Labs has revolutionized our approach to managing our OSS dependency & securitization of our software supply chain. SCA solution goes beyond traditional vulnerability scanning, offering deep reachbility that has dramatically reduced not only our risk exposure but developer productivity while addressing such issues.

Really loved how they do the same with all the verticals. They are expanding to including container scanning where they link vulnerability found in container level back to source code and OSS scan results.

In a few years we have used Endor we have found them to be rapid in reflecting our needs and continually syncing to deliver on our requests throughout the Journey. Customer sympathy is truly a factor to highlight when we think of Endor Labs as a partner. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

It would be great if Endor Labs continue to expand their vertical all the way to runtime analysis of containers to truly make it an end to end software lifecycle vulnerability/security platform. Review collected by and hosted on G2.com.

João P.
JP
Application Security Engineer
Mid-Market (51-1000 emp.)
"The best reachability analysis I've tested, with an intuitive yet powerful UI"
What do you like best about Endor Labs?

The way SCA is performed on projects is the best I've seen from all products I've tested. Function-level reachability for many languages/technologies differentiates it from most, if not all, competitors. The UI easily shows me the findings on all projects, with detailed information on location, call-stack, impact, CVEs...

It also lets us, from the UI, fine-tune policies on when to warn/block/ignore builds on findings. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

The only downside I've come across is setting up Endor Labs for a project could be easier. It's not hard, but some errors or problems could have a more explicit message on how to solve (e.g. some project's dependencies failed to be analysed), but given the large amount of supported technologies, it's understandable. Review collected by and hosted on G2.com.

Verified User in Telecommunications
UT
Enterprise (> 1000 emp.)
"Endor Labs unparalleled in function reachability"
What do you like best about Endor Labs?

Endor Labs has a very sophisticated engine for function reachability. I would say it is unparallel in the industry as of right now. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

The UI/UX experience needs some work. However, it has been getting better in the last two years. I have used this product. Also, it needs better Jira integration. Again, this is something they're actively working on. Review collected by and hosted on G2.com.

Pricing

Pricing details for this product isn’t currently available. Visit the vendor’s website to learn more.

Product Avatar Image
Product Avatar Image
Endor Labs