Introducing G2.ai, the future of software buying.Try now
Endor Labs
Sponsored
Endor Labs
Visit Website
Product Avatar Image
Mend.io

By Mend

4.3 out of 5 stars

How would you rate your experience with Mend.io?

Endor Labs
Sponsored
Endor Labs
Visit Website
It's been two months since this profile received a new review
Leave a Review

Mend.io Reviews & Product Details

Profile Status

This profile is currently managed by Mend.io but has limited features.

Are you part of the Mend.io team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Value at a Glance

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

16 months

Mend.io Media

Mend.io Demo - Security Dashboard
The Mend Platform Security Dashboard provides a high‑level overview and analytics for SCA, SAST, and IMAGE scan findings across your entire Organization.
Mend.io Demo - Value Dashboard
The Value Dashboard provides clear remediation insights and tracks key security metrics like Mean Time to Remediate (MTTR) and overall Finding Reduction %, so teams can confidently demonstrate progress in securing their applications.
Mend.io Demo - Application List with AI Frameworks
A centralized view of applications across the organization and the AI frameworks they leverage, providing visibility into usage and potential security considerations.
Product Avatar Image

Have you used Mend.io before?

Answer a few questions to help the Mend.io community

Mend.io Reviews (111)

Reviews

Mend.io Reviews (111)

4.3
112 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Mo F.
MF
DevSecOps Consultant
Enterprise (> 1000 emp.)
"Easy integration with CI/CD and powerful shift-left approach"
What do you like best about Mend.io?

It makes it very easy to break down and analyze all the open source packages that are in client's code with reports and dashboards to easily identify Critical, Highs, Med and Low risks. I also like that it easily integrates with Github and Azure DevOps to the point that I don't have to login to another site or console and I can see issues right on my platform for tracking and remediation Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

The commonality with a lot of SAST tools is the amount of false positives. Review collected by and hosted on G2.com.

Roshan K.
RK
Mid-Market (51-1000 emp.)
"Saves time, faster, Amazing customer support"
What do you like best about Mend.io?

Customer support.

Integration for other tools. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

UI: Options on UI is not handy or not much presentable. Review collected by and hosted on G2.com.

SM
Product Security Engineer
Mid-Market (51-1000 emp.)
"Best Open Source Analysis (OSA) at this moment."
What do you like best about Mend.io?

Best Open Source analysis with their In-house and other multiple sources of software vulnerabilities. Also one of the few companies in the market which will give you license & policy violations alert as well.

Pipeline integration of this tools is greatly helpful for the software which are shipped out securely & safely.

Also, Whitesource is a software as a service (SAAS) offering, so there is no need to physically maintain any server at your end or your data center for any implementation.

Mostly such things are helpful in today's world as most of your administration is offloaded to them. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

No downside of using this software in OSA and DEVOPS Pipeline.

Support Team's response is sometimes delayed but sometimes it's prompt.

Need to define an SLA Review collected by and hosted on G2.com.

Rajesh T.
RT
Penetration Tester
Enterprise (> 1000 emp.)
"Makes easy to manage your 3rd party libraries"
What do you like best about Mend.io?

The scans are quick, and a detailed report is provided.

Easy to manage. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

The dashboard/UI would be improved and made more user-friendly. Review collected by and hosted on G2.com.

BK
CTO
Small-Business (50 or fewer emp.)
"Easy to use and fast for getting results"
What do you like best about Mend.io?

Very easy to set up and make it work. Also very easy to modify the set up and add or remove new repos. I really like the fact that after each merge Mend automatically creates issues associated with each problematic dependency, and those are automatically closed if the issue is resolved. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

So far there hasn't been any areas that I disliked. I haven't dig deep into the documentation yet, but it was not immediately clear if Mend will automatically assess PRs before merging and add any comments to them. Review collected by and hosted on G2.com.

John C.
JC
Information Security Architect
Mid-Market (51-1000 emp.)
"Industry-leading SCA, work in progress"
What do you like best about Mend.io?

Quick and accurate scanning, multiple plug-ins for various different build and ci/cd platforms. Prioritize, Whitesource for developers Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

hard to get some features working like

eua, and integration this Jira was challenging Review collected by and hosted on G2.com.

Verified User in Human Resources
UH
Enterprise (> 1000 emp.)
"Overall a good tool for your dev needs"
What do you like best about Mend.io?

comprehensive software composition analysis

provides in-depth visibility into open source components and their vulnerabilities, helping organizations proactively manage security risks. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

pricing structure can be quite complex, making it challenging to determine the most cost-effective plan for specific business needs. Review collected by and hosted on G2.com.

Abhishek K.
AK
Development Architect
Enterprise (> 1000 emp.)
"Good tool but UI is clunky"
What do you like best about Mend.io?

The information about vulnerabilities is generally up to date. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

The UI is very clunky. Doesn't integrate well into development workflow. as we need to come to this tool to audit the findings. Would be nice to have it as a github plugin from where we can directly audit the findings. Review collected by and hosted on G2.com.

Verified User in Telecommunications
AT
Mid-Market (51-1000 emp.)
"Mend makes security issue fixing and reporting really simple."
What do you like best about Mend.io?

Mend's integration with source control systems and IDEs is simply outstanding. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

Nothing I dislike as of now. But I wish mend had a chat feature or something for quick resolution of small issues without needing to open support cases. Review collected by and hosted on G2.com.

JB
CTO
Mid-Market (51-1000 emp.)
"Great Tool for Managing 3rd party libraries"
What do you like best about Mend.io?

Mend eases the process of keeping track of all the used 3rd party dependencies within a product. It not only scans for the pure occurrence (also transitively) but takes also care of license and vulnerabilities. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

In the beginning, it is a steep learning curve to configure the tool and integrate it into custom pipelines. With the help of a succeess manager, this also works out. Since the usage of renovate, we have up-to-date libraries across all our projects, but not all versions are known immediately by the dashboard. Review collected by and hosted on G2.com.

Pricing Insights

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

16 months

Average Discount

12%

Perceived Cost

$$$$$

How much does Mend.io cost?

Data powered by BetterCloud.

Estimated Price

$$k - $$k

Per Year

Based on data from 6 purchases.

Mend.io Comparisons
Product Avatar Image
Snyk
Compare Now
Product Avatar Image
Black Duck
Compare Now
Product Avatar Image
SonarQube
Compare Now
Mend.io Features
Configuration Management
Reporting and Analytics
Issue Tracking
Static Code Analysis
Command-Line Tools
Compliance Testing
Language Support
Integration
Transparency