---
title: Mend.io Reviews
meta_title: 'Mend.io Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 124 reviews by the users' company size, role or industry
  to find out how Mend.io works for a business like yours.
aggregate_rating:
  rating_value: 4.3
  review_count: 124
  scale: '5'
date_modified: '2026-08-12'
parent_category:
  name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t"
  url: https://www.g2.com/categories/devsecops
---


# Mend.io Reviews
**Vendor:** Mend  
**Category:** [Software Composition Analysis Tools](https://www.g2.com/categories/software-composition-analysis)  
**Average Rating:** 4.3/5.0  
**Total Reviews:** 124
## About Mend.io
Modern risk doesn&#39;t live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.



## Mend.io Pros & Cons
**What users like:**

- Users value the **scanning efficiency** of Mend.io, appreciating its quick and accurate results across multiple repositories. (8 reviews)
- Users appreciate the **ease of use** of Mend.io, highlighting simple integration and efficient navigation to find vulnerabilities. (7 reviews)
- Users appreciate the **easy integrations** of Mend.io, enabling efficient scanning and streamlined workflows across multiple repositories. (6 reviews)
- Users appreciate the **quick and accurate scanning** capabilities of Mend.io, enhancing their development workflow and security. (6 reviews)
- Users commend the **excellent automated vulnerability detection** in Mend.io, enhancing efficiency in their CI/CD processes. (6 reviews)
- Customer Support (5 reviews)
- Users find that Mend.io provides **easy integration support** , enhancing application security effortlessly. (5 reviews)
- Comprehensive Solutions (4 reviews)
- Security Scanning (4 reviews)
- Useful (4 reviews)

**What users dislike:**

- Users struggle with **integration issues** , finding the setup process for tools like Jira and on-premise systems challenging. (6 reviews)
- Users find **limited features** in Mend.io, struggling with functionality and integration challenges for various tools and cases. (3 reviews)
- Users note that Mend.io lacks **essential features** , requiring additional tools and workarounds for effective integration. (3 reviews)
- Users experience **complex implementation** with Mend.io, citing difficulties in integration and frequent false positives. (2 reviews)
- Users find the **confusing interface** of Mend.io awkward, especially when switching between different product portals. (2 reviews)
- Users find the product to be **too pricy** , feeling that its integration lacks value for the cost. (2 reviews)
- False Positives (2 reviews)
- Overwhelming Interface (2 reviews)
- Poor Customer Support (2 reviews)
- Poor Interface Design (2 reviews)

## Mend.io Reviews
  ### 1. Real-Time Security Analysis in Modern Code Editors

**Rating:** 4.0/5.0 stars

**Reviewed by:** Ram K. | Associate Consultant, Enterprise (> 1000 emp.)

**Reviewed Date:** July 28, 2026

**What do you like best about Mend.io?**

Offer real time security analysis inside modern code editors like cursor and support for governing AI components.

**What do you dislike about Mend.io?**

Configurating policies for large enterprise codebases requires significant initial overhead

**What problems is Mend.io solving and how is that benefiting you?**

Finds hidden security bugs in third-party software packages.Malicious Packages: Blocks open-source supply chain attacks before they enter codebases.License Non-Compliance: Identifies legal risks from restrictive open-source licenses.AI Security Risks: Secures AI applications by tracking vulnerabilities in open-source AI models and datasets.
Saves Developer Time: Uses automated pull requests to fix code bugs automatically.Reduces Noise: Uses reachability analysis to tell developers if a bug is actually operational, eliminating up to 85% of false alerts.Accelerates Shipping: Integrates directly into repositories (like GitHub) so security happens during development, avoiding last-minute launch delays.

  ### 2. Fast GitHub Scanning and Helpful Automation, but UI and False Positives Need Work

**Rating:** 3.5/5.0 stars

**Reviewed by:** Vern H. | Technical Support III, Enterprise (> 1000 emp.)

**Reviewed Date:** July 30, 2026

**What do you like best about Mend.io?**

Easy setup: It integrates quickly with GitHub and fits smoothly into CI/CD workflows. Effective scanning: It rapidly tracks open-source dependencies and helps with license compliance. Helpful automation: The Renovate feature supports automated dependency updates. Good support: Customer service is often described as fast and helpful.

**What do you dislike about Mend.io?**

Interface: Parts of the UI clunky or a bit outdated. False Positives: It can generate noise, which then requires extra manual triage. Pricing: It’s sometimes considered a little high for smaller teams or mid-market buyers. Integrations: Third-party tool connections, like Jira, can occasionally bug out.

**What problems is Mend.io solving and how is that benefiting you?**

Used to resolve issues with SCA

  ### 3. Keep your dependency up to date

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** March 30, 2023

**What do you like best about Mend.io?**

Especially in the age of AI, keeping dependencies up to date is a must — the number of vulnerabilities in third-party libraries is growing at an accelerating rate every single month.

**What do you dislike about Mend.io?**

By 2026, the landscape had changed, and GitHub Dependabot had become much more mature than it was before.
In my opinion, Mend Renovate is losing market share because people prefer to use native tools when they store their code on GitHub.

**What problems is Mend.io solving and how is that benefiting you?**

Mend Renovate for GitHub help us keep our dependencies up to date, which causes fewer vulnerabilities in the final Product. The time required to update dependency was significantly decreased.

  ### 4. Mend.io review

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Human Resources | Enterprise (> 1000 emp.)

**Reviewed Date:** July 10, 2023

**What do you like best about Mend.io?**

The automated remediation feature (via Mend Remediate/Renovate) is excellent. It doesn't just find vulnerabilities; it automatically generates pull requests with the necessary dependency updates. The integration into our existing CI/CD pipelines is seamless, allowing us to catch open-source vulnerabilities early in the development lifecycle.

**What do you dislike about Mend.io?**

The user interface can occasionally feel a bit cluttered, and navigating through deep reporting menus isn't always intuitive. Also, the initial configuration and tuning to reduce noise/false positives took a bit longer than expected.

**What problems is Mend.io solving and how is that benefiting you?**

manual dependency tracking and vulnerability management. Instead of our team spending hours researching which libraries are outdated or insecure, the platform alerts us automatically. This saves our development team significant time and ensures our applications remain secure without slowing down our release velocity.

  ### 5. SAST SCA scanning in good budget

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Security and Investigations | Mid-Market (51-1000 emp.)

**Reviewed Date:** August 08, 2022

**What do you like best about Mend.io?**

there are multiple new things that we like 
1. container scanning is enabled
2. AI code scanning is enabled

**What do you dislike about Mend.io?**

UI needs to be improved.
Number of false positives in some cases.
Support should be improved

**What problems is Mend.io solving and how is that benefiting you?**

Mend is scanning our source code as well as the libraries and providing us the list of vulnerabilities present in our source code or libraries where we need to improve and produce a better product.

  ### 6. Good for reducing a lot manual effort without reliance on AI tools

**Rating:** 3.5/5.0 stars

**Reviewed by:** Chris S. | Principal Software Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 23, 2026

**What do you like best about Mend.io?**

The range and breadth of what it offers is very extensive. The SCA vulnerability management is particularly clever, and the ability to start auto-remediating issues is genuinely useful.

**What do you dislike about Mend.io?**

Some of the setup with branch management was a little odd and didn't aid with our ways of working

**What problems is Mend.io solving and how is that benefiting you?**

Dependency updates that remove all the manual effort needed.

  ### 7. Mend is a key part of your development process.

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Enterprise (> 1000 emp.)

**Reviewed Date:** May 21, 2024

**What do you like best about Mend.io?**

It's scanning capabilities are more than useful. CSM and support teams are really helpful and reactive.

**What do you dislike about Mend.io?**

Its integration with on-premise tools can be challenging.

**What problems is Mend.io solving and how is that benefiting you?**

We want to identify and mitigate issues with vurnerabilities and those licenses .

  ### 8. Leader in the field

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Non-Profit Organization Management | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 22, 2023

**What do you like best about Mend.io?**

Mend has several strengths.  First, the company behind it is relatively transparent, helpful, and straightforward.  I appreciated that they didn't oversell the product the way several competitors did.  The software integrates nicely with Microsoft development tools.  Customer support is good and responsive as well.

**What do you dislike about Mend.io?**

This isn't really a knock, but as a point in time, they are integrating the SCA and the, I think, acquired SAST solutions together into a common platform.  Obviously, that's a large effort, and once that is done, it will be even better.

**What problems is Mend.io solving and how is that benefiting you?**

Mend simplifies the reporting and auditing aspect of documenting that vulnerabilities have been managed properly.

  ### 9. Mend - Fixing What I Didn't Know Was Broken

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** August 06, 2023

**What do you like best about Mend.io?**

Using the CLI unified agent is a breeze and the syntax is easy to understand/follow. The web UI is not only easy on the eyes but the user experience makes it easy to find what you're looking for.

**What do you dislike about Mend.io?**

Currently, at least in my use of the product, there are two different portals depending on which product I'm using, SAST vs SCA, which is kind of awkward to bounce between.

**What problems is Mend.io solving and how is that benefiting you?**

Mend takes the reigns on most of the heavy lifting around the Static Code Analysis needs, considering it is much quicker and effecient at scanning the nearly 400,000 lines of code I'm throwing at it than I would be if doing it by hand like a caveman.

  ### 10. Gartner Review

**Rating:** 4.0/5.0 stars

**Reviewed by:** Mohd A. | Cloud Security Architect, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 25, 2023

**What do you like best about Mend.io?**

Scanning capabilities, scanning of open source and sending notifications

**What do you dislike about Mend.io?**

Reporting feature needs to have more user friendly reports

**What problems is Mend.io solving and how is that benefiting you?**

we use open source components and mend is giving us good info about vulnerabilities

  ### 11. Using Mend integration to Continuous Integration system

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Enterprise (> 1000 emp.)

**Reviewed Date:** December 14, 2016

**What do you like best about Mend.io?**

The API, The Unified agent JAR and the service-oriented attitude from Mend engineering and success managers

**What do you dislike about Mend.io?**

Performance in huge projects (might be solved with workarounds) .
The CLI is running as JAVA jar only. 
The dashboard UX is bad. Really need to improve it

**What problems is Mend.io solving and how is that benefiting you?**

Keeps us and our customers safe from legal and security aspects

  ### 12. Makes easy to manage your 3rd party libraries

**Rating:** 4.0/5.0 stars

**Reviewed by:** Rajesh T. | Penetration Tester, Enterprise (> 1000 emp.)

**Reviewed Date:** April 12, 2023

**What do you like best about Mend.io?**

The scans are quick, and a detailed report is provided.
Easy to manage.

**What do you dislike about Mend.io?**

The dashboard/UI would be improved and made more user-friendly.

**What problems is Mend.io solving and how is that benefiting you?**

It helps us to scan the libraries before the release. Is also a part of CI/CD pipeline.

  ### 13. Better code.

**Rating:** 4.0/5.0 stars

**Reviewed by:** louay n. | DevOps engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** September 26, 2022

**What do you like best about Mend.io?**

Scanning for the vulnerabilities is always updated and the research team is doing an amazing job keeping everything up-to-date and not missing any vulnerability.

**What do you dislike about Mend.io?**

I feel that the dashboard's UI can look nicer and more readable. eg better views, more modern design, easier access to products and related projects with a tree view.

**What problems is Mend.io solving and how is that benefiting you?**

Security vulnerabilities, avoiding/fixing them to get a more secure product that satisfies the higher-ups and the clients together which increased the business performance

  ### 14. Rocky Implementation with Reliable Vulnerability Management

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Accounting | Enterprise (> 1000 emp.)

**Reviewed Date:** August 26, 2022

**What do you like best about Mend.io?**

Mend has timely support through their portal and sales rep which has been very helpful. Their newest documentation is overhauled which is a huge plus compared to their previous WhiteSource documentation. Their vulnerability management has timely alerts, a wealth of information on findings and integrations.

**What do you dislike about Mend.io?**

Implementation was challenging even with technical support. We were unable to effectively get the unified agent configuration working even though we had this 5 months prior in a POC. We opted to go for Azure integration which worked easily out of the box (a plus) but is a bit limited in scope for how we handled effective vulnerabilities. 

Reporting is lacking especially when using the tool as a compliance/inventory management process. Risk acceptance lasts indefinitely rather than a threshold e.g. 90 days / 360 days.

**What problems is Mend.io solving and how is that benefiting you?**

We primarily use Mend for automated static code analysis of our open-source development projects. THe product solves our vulnerability management gap with open-source solutions and is used to solve as a list of approved libraries.

  ### 15. A very promising security product and business line

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** August 25, 2022

**What do you like best about Mend.io?**

The simplicity of scanning
The simplicity of the GUI and able to drill down into where exactly a particular library is fetched from
Ability to download reports and more meaningful reports as compared to other products (Snyk, CodeClimate)

**What do you dislike about Mend.io?**

The complexity in scanning different technologies and educating developers how to scan their code and read their dashboards
Sometimes, downstream dependencies are displayed (false positives) , it is extremely hard for engineers to figure out the tree maps and fix the problematic lines of code
The "Requires Review" section is very wide and demands the review and sign off from different departments like developer+devops+Management. But the GUI does not support this in a user friendly way.
When we mark a library "in-house" or try to "whitelist it" it becomes permanently marked as such instead of allowing us to revisit it.

**What problems is Mend.io solving and how is that benefiting you?**

The problem of knowing what are the OSS bundled into our source code
Developers urgently reference libraries to develop features without much focus on static application security, as admins we are able to capture those early in SDLC

  ### 16. Make it easy for your development team to address open source risk

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Utilities | Enterprise (> 1000 emp.)

**Reviewed Date:** October 28, 2022

**What do you like best about Mend.io?**

Mend is a very intuitive tool that has integrations with many typical pipelines and repos. We have found it to be very good at identifying vulnerable components with a low false positive rate. It provides good recommendations for the best fix version of a library.

**What do you dislike about Mend.io?**

Mend is starting to build out full support for exporting results in standard SBOM formats, but generating these outputs currently requires running separate Python scripts.

**What problems is Mend.io solving and how is that benefiting you?**

Mend is used to address open source risk by evaluating for vulnerabilities, license risk, and code quality. It supports the enforcement of policies.

  ### 17. Good

**Rating:** 3.5/5.0 stars

**Reviewed by:** Amit K. | Security Analyst, Small-Business (50 or fewer emp.)

**Reviewed Date:** November 29, 2022

**What do you like best about Mend.io?**

For Commerical Use Helpful this is the Best But Some Slow Conditions is that

**What do you dislike about Mend.io?**

nothingthis is the Best But Some Slow Conditions is that

**What problems is Mend.io solving and how is that benefiting you?**

Slow

  ### 18. Effective and easy to use OSS scanning

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** September 12, 2022

**What do you like best about Mend.io?**

Scanning is simple with an easy-to-use agent.
Reports are easy to read providing useful insight.

**What do you dislike about Mend.io?**

The Mend Portal can be slow on occassion.
Some parts of the interface are not as intuitive as they could be.

**What problems is Mend.io solving and how is that benefiting you?**

I have some maven based build issues. Mend Support is providing effective and swift guidance on how to solve these issues.

  ### 19. modern UI

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Internet | Enterprise (> 1000 emp.)

**Reviewed Date:** September 01, 2020

**What do you like best about Mend.io?**

modern and familiar UI, easy to use and comfortable

**What do you dislike about Mend.io?**

structure of pages are not easy to understand

**What problems is Mend.io solving and how is that benefiting you?**

detect company's license policy violations and solve them

  ### 20. Whitesource Fenovate is solid

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Education Management | Small-Business (50 or fewer emp.)

**Reviewed Date:** March 31, 2022

**What do you like best about Mend.io?**

I setup whitesource rennovate to help keep our dependencies up to date. Since doing that we have slowly but surely updated all of our dependencies without spending much developer time.

**What do you dislike about Mend.io?**

The downside is that rennovate is a bit slow to rerun after you've made a change. For the most part it's fine but when you're getting started and have lots to update it can feel slow.

**What problems is Mend.io solving and how is that benefiting you?**

Keeping my dependencies up to date for a modern python project that's using poetry and docker.

  ### 21. Renovate bot works nicely

**Rating:** 4.0/5.0 stars

**Reviewed by:** Ran N. | CTO, Small-Business (50 or fewer emp.)

**Reviewed Date:** February 19, 2022

**What do you like best about Mend.io?**

The automation of the process of updating

**What do you dislike about Mend.io?**

The initial setup. Going through a quick wizard would reduce friction of understanding the config options

**What problems is Mend.io solving and how is that benefiting you?**

Saving time in keeping my software up to date. Much less manual work

  ### 22. Extremely Flexible Dependency Update Manager

**Rating:** 4.0/5.0 stars

**Reviewed by:** Sam B. | Software Engineer, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 12, 2021

**What do you like best about Mend.io?**

They had an option for nearly every configuration I wanted.

**What do you dislike about Mend.io?**

Renovate really taxes my build system credits since there are so many PRs. There's an option to group PRs, but then if they fail CI I have to figure out which dependency caused the failure manually. Ideally, it would group dependency updates but then do a binary search to find the update that broke the build (Similar to bors for regular PRs, but I can't use bors to solve dependency problems because automerge will always fail due to conflicts in lockfiles)

**What problems is Mend.io solving and how is that benefiting you?**

Trying to regularly update my dependencies to get ahead of security vulnerabilities and prevent dependency ossification.

  ### 23. Whitesource

**Rating:** 4.0/5.0 stars

**Reviewed by:** Vivek Kumar S. | Software Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** February 21, 2022

**What do you like best about Mend.io?**

Interface and flow of the application.Also the simplicity

**What do you dislike about Mend.io?**

Nothing specific thing that i would dislike

**What problems is Mend.io solving and how is that benefiting you?**

Business needs and mostly it's in trial phase so no enough data for now

  ### 24. First steps with renovate and Terraform

**Rating:** 4.0/5.0 stars

**Reviewed by:** Sujith Q. | Azure Architect, Small-Business (50 or fewer emp.)

**Reviewed Date:** August 05, 2021

**What do you like best about Mend.io?**

It works with a bare minimum of configuration

**What do you dislike about Mend.io?**

It took me quite a while to find out what that bare minimum was although there is documentation available.

**What problems is Mend.io solving and how is that benefiting you?**

Find out when you run behind using certain versions of Terraform modules

  ### 25. Invaluable tool to keep your software safe

**Rating:** 4.0/5.0 stars

**Reviewed by:** Christian D. | Senior Java Analyst Programmer, Small-Business (50 or fewer emp.)

**Reviewed Date:** September 02, 2020

**What do you like best about Mend.io?**

Summary: Whitesource shows us which libraries can be upgraded and which ones are vulnerable. This keeps our code up-to-date with other project's releases. Having an integration into our pipeline assures us we can follow this up easily.

Applying Whitesource to our projects has helped us tremendously in keeping our project secure. It would be more difficult for our developers to search around to try and find those vulnerabilities by themselves. Most projects do have hundreds of third-party libraries, and even more are downloaded transitively. By comparing the used libraries with known and reported vulnerabilities, we have everything we need in one place. 

Each new branch with updated code, triggers a Whitesource build in our pipeline. The email reports are nice triggers for our developers to start looking into vulnerabilities and library updates. Whitesource gives useful resolution suggestions, such as how to avoid the vulnerabilities or which library version no longer has the issue.

Another useful feature is the check on licences. Most developers do not bother looking into which libraries are included in their projects. Whitesource gives a comprehensive list and overview of all licences used in a project. This allows early detection of any non-free library and gives the opportunity to find alternatives quickly.

**What do you dislike about Mend.io?**

For each new branch we add to the project, a new product section is created. When our branches are then merged into the master branch, those products remain. Each email report will also include and compare them to the other branches, making the report less useful. This has triggered us to regularly and manually delete those product sections, and only keep the latest reports and branches.

**Recommendations to others considering Mend.io:**

Anyone should have some tool such as WhiteSource to keep their software safe.

**What problems is Mend.io solving and how is that benefiting you?**

Our security operations has never been happier with our results. We were also able to quickly detect a non-free license that was used, so we could avoid legal issues when our software was put into production.

  ### 26. Works like a charm

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Program Development | Small-Business (50 or fewer emp.)

**Reviewed Date:** February 18, 2021

**What do you like best about Mend.io?**

Out of the box it's already helping a lot. When you dive into the configurations there's even more awesome things you can achieve.

**What do you dislike about Mend.io?**

I didn't like the constant stream of emails from Github pull requests. Something you can easily manage with the right config settings.

**What problems is Mend.io solving and how is that benefiting you?**

I want to keep my JAMstack codebase up to date

  ### 27. Positive experience while rolling out WhiteSource

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Enterprise (> 1000 emp.)

**Reviewed Date:** September 04, 2020

**What do you like best about Mend.io?**

WhiteSource has been very active helping us to get started and get the most out of the tool, this also helps resolves the "dislikes" to a great extent. WhiteSource has also been very willing to help out investigate incorrect attribution. Single Sign-on makes makes it easy to switch to the portal. The home-view is a good dashboard with an overview of the organization, product, or project status. There are many integration options, such as Jira, GitHub, Travis CI, Jenkins, TeamCity, Bamboo, Azure DevOps, Circle CI, AWS CodeBuild, Google Cloud Build, etc.

**What do you dislike about Mend.io?**

The "Policies" are quite limited in their current form and only a single policy can trigger. This means a policy at the product level can prevent organization wide policy violations to trigger. This can be useful when making exceptions as the product level, but this also means a product level admin can overrule organization wide decisions.  The products - projects model takes quite a bit of insight and help to be used effectively.

**Recommendations to others considering Mend.io:**

Ask WhiteSource for a presentation, and possibly demo, on their capabilities and then request to start a trial. Let them help you try out the tool with one of your own projects.

**What problems is Mend.io solving and how is that benefiting you?**

WhiteSource helps getting an overview of all open source software in use. It provides information about vulnerabilities and their possible implications. WhiteSource also provides license information that helps us ensure we comply with all license requirements and we do not use libraries that are only available under unacceptable licenses.

  ### 28. Great way to keep up your app updated

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Education Management | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 23, 2021

**What do you like best about Mend.io?**

Automation of the process, auto merging pull requests, the information provided inside.

**What do you dislike about Mend.io?**

I haven't found the pin dependencies feature useful, but maybe I need to dig more to fully benefit from it.

**Recommendations to others considering Mend.io:**

I would highly reccomend

**What problems is Mend.io solving and how is that benefiting you?**

Keeping all app dependencies up to date, without human work.

  ### 29. WhiteSource makes everything easier!

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Small-Business (50 or fewer emp.)

**Reviewed Date:** October 20, 2020

**What do you like best about Mend.io?**

I love how it makes easy it is to manage my openSource web components. I never have to worry about missing an important notification if something goes wrong!

**What do you dislike about Mend.io?**

There isn't much to dislike with whiteSource! Maybe one thing I'd suggest is to make it a little less expensive. But honestly, it's already worth the price!

**What problems is Mend.io solving and how is that benefiting you?**

We use it to monitor our various UI libraries along with other smaller repositories that are vital to our company. It was very easy to setup and get started with almost instant monitoring.

  ### 30. Pleasant to use, highly-configurable yet powerful out of the box

**Rating:** 4.0/5.0 stars

**Reviewed by:** Charalampos F. | President, Small-Business (50 or fewer emp.)

**Reviewed Date:** December 31, 2020

**What do you like best about Mend.io?**

Configuration as code, easy out of the box setup, all aspects are customizable

**What do you dislike about Mend.io?**

The lack of a useful web dashboard to make first-time configuration a bit easier

**What problems is Mend.io solving and how is that benefiting you?**

We're using WhiteSource's software to update dependencies for our Rust projects

  ### 31. White Source Bolt Review (open source packages scanner)

**Rating:** 3.5/5.0 stars

**Reviewed by:** Elyes C. | Application Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** September 02, 2020

**What do you like best about Mend.io?**

the easy way to implement in the cloud into our pipelines

**What do you dislike about Mend.io?**

at the moment i didn't noticed anything that i can dislike

**Recommendations to others considering Mend.io:**

i recommend whitesource to scan opensource code

**What problems is Mend.io solving and how is that benefiting you?**

the problems that everyone are facing, we all use opensource packages but without scanning them for known vulnerabilities, whitesource bolt is a great scanner for that purpose

  ### 32. Easy interface - Max productivity

**Rating:** 4.0/5.0 stars

**Reviewed by:** Gagandeep R. | Small-Business (50 or fewer emp.)

**Reviewed Date:** October 08, 2020

**What do you like best about Mend.io?**

Easy setup, smooth user experience and friendly user interface

**What do you dislike about Mend.io?**

Not robust adaptation to certain website source codes.

**What problems is Mend.io solving and how is that benefiting you?**

Go-to solution but work needs to be done to refine automation.

  ### 33. Automating software IPR checking

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** June 19, 2020

**What do you like best about Mend.io?**

The offering is delivered as SaaS and has an intuitive and easy to use interface which provides rapid access to key information on IPR and security vulnerabilities in an easy to understand graphical format. the wide range of reporting options allow potential issues to be captured and explored in more detail.

**What do you dislike about Mend.io?**

Configuration of the scanning element of the offering requires some practice and there are a large number of parameters to master.

**What problems is Mend.io solving and how is that benefiting you?**

We have transitioned from a manual process of IPR audit to a fully automated and integrated one which saves considerable time and allows experts to concentrate in areas the specifically require human intervention. This greatly reduces the exposure to to potential IPR liability issues for the organisation.

  ### 34. This is tool is better to review for security vulnerability for libraries.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** August 30, 2020

**What do you like best about Mend.io?**

This is tool is better to review for security vulnerability for libraries.

**What do you dislike about Mend.io?**

try to give flexible version of libraries.

**What problems is Mend.io solving and how is that benefiting you?**

xstream and poi as well as spring security.

  ### 35. White source review

**Rating:** 3.5/5.0 stars

**Reviewed by:** Clyde F. | Security Analyst, Newspapers, Enterprise (> 1000 emp.)

**Reviewed Date:** December 18, 2016

**What do you like best about Mend.io?**

Reactif for customers issues and services. Well understanding the customer's issue and quick remediation.

**What do you dislike about Mend.io?**

Wide panel of services proposed but some of them not really well implemented with bug fixing needed.

**What problems is Mend.io solving and how is that benefiting you?**

Involving my whole company for using White source, most particularly developers teams.
Having reduced the among of high and critical vulnerable products.

  ### 36. Great product and great support!

**Rating:** 4.0/5.0 stars

**Reviewed by:** John B. | Senior Software Engineer, Computer Software, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 24, 2016

**What do you like best about Mend.io?**

 The online interface looks nice and is easy to use and intuitive.  WhiteSource allows us to easily see all of our 3rd-party Java libraries at a glance and quickly tell which ones we need to fix- whether they conflict with our license, have security holes, or need to be updated.  What used to be a manual process (as in no one ever really did it..) is now a nice automated process. 
  What really shines is their support- they are quick to meet with us and solve any issues we have.  Even during the evaluation period, they made improvements to the product in areas we were concerned.  It always pays to have awesome customer support.  I know if we run into any other issues that they'll be quick to fix them.


**What do you dislike about Mend.io?**

WhiteSource has trouble with C++ libraries, but its not a deal breaker.  It just requires more manual work. However, I expect it to get better as we get everything set up+ I know the WhiteSource team is continuing to improve this part.
Also, I would appreciate them improving the Jenkins plugin.  It doesn't support variable replacement in the includes/excludes, so I was forced to use the command-line tool.  The WhiteSource team mentioned that they would look into fixing it.


**What problems is Mend.io solving and how is that benefiting you?**

We needed to go through all our 3rd-party libraries to make sure we aren't going against our license or company policy.  We also wanted to be able to fix security vulnerabilities before they make it into our product.  Furthermore, in the future, we want to continue to ensure that future added libraries do not cause issues.  Recently found out that they have a simple workflow for approving libraries, so that is a nice bonus.


  ### 37. Very nice

**Rating:** 3.5/5.0 stars

**Reviewed by:** Aakash K. | Senior Application Security Engineer, Computer Software, Enterprise (> 1000 emp.)

**Reviewed Date:** December 19, 2016

**What do you like best about Mend.io?**

Integration features are good .................

**What do you dislike about Mend.io?**

No custom Report generation available .......

**What problems is Mend.io solving and how is that benefiting you?**

Yo confidential

  ### 38. Great Product to identify OpenSource violations & Vulnerabilities

**Rating:** 4.0/5.0 stars

**Reviewed by:** Balaji R. | Sr. Director, Engineering Services & Release Management, Computer Hardware, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 24, 2016

**What do you like best about Mend.io?**

Ease of use
Ease of integration
Meaningful reports
Customer Support

**What do you dislike about Mend.io?**

Documentation: Need more documentation
Support for new file types


**What problems is Mend.io solving and how is that benefiting you?**

Identifying and remediating Open Source we use in the product
Fixing Vulnerabilities
Getting Compliant

  ### 39. White Source for Open Source Software Management

**Rating:** 3.5/5.0 stars

**Reviewed by:** Cristian F. | Engineering Manager, Computer Software, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 05, 2015

**What do you like best about Mend.io?**

Quick and easy setup. The trial was very quick to get up and running and the support through the trial process was excellent. The interface is simple and easy to get at important information. Support has been quick and responsive. 

**What do you dislike about Mend.io?**

There are a few features missing that would make dealing with large codebases and large amounts of managed open source libraries much easier. Reporting could be easier, it does not export filtered down lists so while you can filter down lists in the product, the filtered down results do not export, it instead exports the fill results.

**Recommendations to others considering Mend.io:**

Understand what you are trying to get out of open source software management. This will help you better evaluate reporting, workflows, and key features.

**What problems is Mend.io solving and how is that benefiting you?**

Managing our open source license usage and enforcing our open source usage policy. Managing key library version updates and security vulnerabilities. 

  ### 40. License- and Dependency Tracking on the go

**Rating:** 4.0/5.0 stars

**Reviewed by:** Albrecht S. | Head of Product Development, Computer Software, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 05, 2015

**What do you like best about Mend.io?**

Really easy to setup, convincing technology to scan for dependencies - as long as you run pure Java projects with maven.
License reports can easily be produced to satisfy RFPs.

**What do you dislike about Mend.io?**

Does not support JavaScript libraries which should be supported since they are vulnerability relevant.
The tool is sometimes slow.
Non-Open Source but widespread libraries  such as Microsoft SQL Server Driver are missing.

**Recommendations to others considering Mend.io:**

Really use the trial to evaluate to completeness and integration of the tool into your deployment systems.

**What problems is Mend.io solving and how is that benefiting you?**

a) Produce third-party library reports for RFPs
b) Produce third-party license reports for RFPs
c) Regularly check for library updates.
d) Check for vulnerablities in third party libraries.
e) Get notified when license policy has been hit by a commit.

All the steps have been done manually before and the tool really saved time.

  ### 41. Bwin.PartyhiteSource customer

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Entertainment | Enterprise (> 1000 emp.)

**Reviewed Date:** September 30, 2015

**What do you like best about Mend.io?**

The ability to compare the versions of open-source libraries.

**What do you dislike about Mend.io?**

The quiltly slow dashboard web-interface.

**What problems is Mend.io solving and how is that benefiting you?**

Complete view over the third-party libraries we use.

  ### 42. architect

**Rating:** 3.5/5.0 stars

**Reviewed by:** Petr N. | Lead Software Architect, Computer Software, Small-Business (50 or fewer emp.)

**Reviewed Date:** September 30, 2015

**What do you like best about Mend.io?**

dashboard, export to excel, charts, integration

**What do you dislike about Mend.io?**

we facing issues with weak support of .net and C++

**What problems is Mend.io solving and how is that benefiting you?**

security of open source


## Mend.io Discussions
  - [Does the above pricing include all vulnerabilities sources?](https://www.g2.com/discussions/do-you-offer-an-on-premise-option) - 1 comment, 1 upvote
  - [What languages and platforms does your solution support?](https://www.g2.com/discussions/is-my-code-secure-with-your-cloud-based-service) - 1 comment, 1 upvote
  - [Why are you pricing per contributing developers?](https://www.g2.com/discussions/i-can-t-find-a-plugin-for-my-build-tool-server-does-that-mean-you-cannot-support) - 1 comment, 1 upvote
  - [Do you offer an on-premise option?](https://www.g2.com/discussions/does-whitesource-work-with-all-languages-and-build-tools) - 1 comment, 1 upvote
  - [What is a contributing developer?](https://www.g2.com/discussions/3104-how-does-whitesource-work) - 1 comment, 1 upvote

- [View Mend.io pricing details and edition comparison](https://www.g2.com/products/mend-io/reviews?filters%5Bnps_score%5D%5B%5D=4&section=pricing&secure%5Bexpires_at%5D=2026-08-13+11%3A51%3A28+-0500&secure%5Bsession_id%5D=3413b975-6d34-4679-841a-13d289cd8098&secure%5Btoken%5D=caf32041ce3a9d075f11cb37f53ac70626bd2eb83ee3c57a728f4d9e7f358a34&format=llm_user)
## Mend.io Integrations
  - [Axonius](https://www.g2.com/products/axonius/reviews)
  - [Bitbucket](https://www.g2.com/products/bitbucket/reviews)
  - [GitHub](https://www.g2.com/products/github/reviews)
  - [Jenkins](https://www.g2.com/products/jenkins/reviews)
  - [TeamCity](https://www.g2.com/products/teamcity/reviews)

## Mend.io Features
**Additional Functionality**
- Tagging
- Natural Language Processing
- Data Extraction
- Multi-Language
- Predictive Analytics
- Drag & Drop
- Speech Recognition
- Reporting/Analytics
- Data Storage Management
- Virtual Personal Assistant (VPA)
- AI Copilot
- Customer Segmentation
- Collaboration Tools
- Data Import/Export
- Generative AI
- For eCommerce
- Role-Based Permissions
- Customizable Branding
- Search/Filter
- Monitoring
- Document Management
- API
- Data Visualization
- Trend Analysis
- Machine Learning
- Access Controls/Permissions
- Alerts/Escalation
- Performance Metrics
- Real-Time Data
- Third-Party Integrations
- Mobile App
- Multiple Data Sources
- For Sales Teams/Organizations
- Sentiment Analysis
- Activity Dashboard
- Chatbot
- Workflow Automation

**Administration**
- API / Integrations
- Extensibility

**Administration**
- Risk Scoring
- Security Auditing
- Configuration Management
- Metadata Management
- Policy Management
- Incident Management
- Vulnerability Management
- Compliance Management
- User Management
- Deployment Management
- Audit Management
- Patch Management
- Application Security
- Runtime Container Security

**Performance**
- Issue Tracking
- Detection Rate
- False Positives
- Automated Scans
- Anomaly/Malware Detection

**Functionality - Software Composition Analysis **
- Language Support
- Integration
- Transparency

**Security**
- Malicious Code
- Security Risks

**Risk management - Application Security Posture Management (ASPM)**
- Vulnerability Management
- Risk Assessment and Prioritization
- Compliance Management
- Policy Enforcement

**Functionality - Software Bill of Materials (SBOM)**
- Format Support
- Annotations
- Attestation

**Agentic AI - Static Code Analysis**
- Adaptive Learning
- Natural Language Interaction
- Proactive Assistance

**Analysis**
- Real-Time Analytics
- Issue Tracking
- Static Code Analysis
- Code Analysis
- Integrated Development Environment

**Monitoring**
- Continuous Monitoring
- Real-Time Monitoring

**Network**
- Compliance Testing
- Configuration Monitoring
- Vulnerability Scanning
- Source-Code Scanning
- Web Scanning

**Effectiveness - Software Composition Analysis**
- Remediation Suggestions
- Continuous Monitoring
- Thorough Detection

**Tracking**
- Bill of Materials
- Audit Trails
- Monitoring

**Integration and efficiency - Application Security Posture Management (ASPM)**
- Integration with Development Tools
- Automation and Efficiency

**Management - Software Bill of Materials (SBOM)**
- Monitoring
- Dashboards
- User Provisioning

**Security**
- Security Auditing
- Real-Time Data
- Cloud Application Security
- SSL Security

**Testing**
- Command-Line Tools
- Test Automation
- Compliance Testing
- Source-Code Scanning
- Detection Rate
- False Positives
- Multi-Language Scanning

**Protection**
- Dynamic Image Scanning
- Container Scanning
- Vulnerability Scanning

**Application**
- Static Code Analysis
- Black Box Testing
- Risk Analysis

**Reporting and Analytics - Application Security Posture Management (ASPM)**
- Trend Analysis
- Risk Scoring
- Customizable Dashboards

**Policy Enforcement and Compliance - AI Security Solutions**
- Scalable Governance
- Shadow AI
- Policy‑as‑Code for AI Assets

**Additional Functionality**
- Two-Factor Authentication
- Third-Party Integrations
- Intrusion Detection System
- Continuous Integration
- Customizable Reports
- Continuous Delivery
- Activity Dashboard
- Security Testing
- Audit Trail
- Risk Alerts
- Access Controls/Permissions
- API
- AI Copilot
- Continuous Deployment
- Threat Response
- Reporting & Statistics
- Authentication
- Encryption
- Threat Intelligence
- Risk Analysis
- For DevSecOps
- Generative AI
- Reporting/Analytics
- Container Isolation
- Risk Assessment
- Search/Filter
- Vulnerability/Threat Prioritization

**Identity**
- SSO
- Governance
- User Analytics
- Real-Time Analytics
- Visual Analytics
- Reporting/Analytics

**Agentic AI - Vulnerability Scanner**
- Autonomous Task Execution
- Proactive Assistance

**Agentic AI - Static Application Security Testing (SAST)**
- Autonomous Task Execution

**Agentic AI  - Application Security Posture Management (ASPM)**
- Autonomous Task Execution
- Multi-step Planning

**Additional Functionality**
- Alerts/Notifications
- AI Copilot
- Access Controls/Permissions
- Endpoint Management
- Intrusion Detection System
- Compliance Management
- HIPAA Compliant
- Search/Filter
- API
- Two-Factor Authentication
- Data Visualization
- Risk Assessment
- Real-Time Monitoring
- Event Logs
- Activity Dashboard
- Audit Management
- Cloud Security Policy Management
- Vulnerability Protection
- Anti Virus
- Incident Management
- Threat Intelligence
- Real-Time Reporting
- Reporting & Statistics
- User Management
- Encryption
- Vulnerability Scanning
- Generative AI
- Status Tracking
- Third-Party Integrations
- Real-Time Notifications
- Patch Management
- Monitoring
- Cloud Encryption

**Additional Functionality**
- SSL Security
- HIPAA Compliant
- API
- Threat Response
- Endpoint Protection
- Maintenance Scheduling
- Third-Party Integrations
- Security Auditing
- Application Security
- Encryption
- Network Security
- Real-Time Reporting
- AI Copilot
- Reporting/Analytics
- Authentication
- Financial Data Protection
- Anti Virus
- Secure Data Storage
- Virus Definition Update
- Activity Dashboard
- VPN
- Audit Trail
- Anti Spam
- Access Controls/Permissions
- Data Visualization
- Alerts/Escalation
- Data Security
- Runtime Container Security
- Asset Discovery
- Threat Intelligence
- Vulnerability Protection
- Alerts/Notifications
- Vulnerability/Threat Prioritization
- Generative AI
- SQL Injections
- Real-Time Analytics
- Threat Protection
- Web-Application Security
- Password Protection
- Website Crawling
- Vulnerability Assessment

**Additional Functionality**
- Debugging
- Generative AI
- AI Copilot
- For Developers
- Deployment Management
- Application Security
- Dashboard

## Top Mend.io Alternatives
  - [Snyk](https://www.g2.com/products/snyk/reviews) - 4.5/5.0 (135 reviews)
  - [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews) - 3.8/5.0 (25 reviews)
  - [SonarQube](https://www.g2.com/products/sonarqube/reviews) - 4.4/5.0 (153 reviews)

