Introducing G2.ai, the future of software buying.Try now
OX Security
Sponsored
OX Security
Visit Website
Product Avatar Image
Socket

By Socket

4.6 out of 5 stars
3 star
0%
2 star
0%
1 star
0%

How would you rate your experience with Socket?

OX Security
Sponsored
OX Security
Visit Website

Socket Reviews & Product Details

Profile Status

This profile is currently managed by Socket but has limited features.

Are you part of the Socket team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Socket Integrations

(1)
Integration information sourced from real user reviews.

Socket Media

Socket Demo - Socket GitHub Alerts
Socket watches for changes to “package manifest” files such as package.json, package-lock.json, and yarn.lock. Whenever a new dependency is added in a pull request, Socket analyzes the package's behavior and leaves a comment if it is a security risk.
Socket Demo - Socket Repository Scans
This feature provides the ability to view and analyze the entire state of a repository so you can ask specific questions like "Which of our packages use the network?" or "Which of our packages contain install scripts"
Socket Demo - Socket Dashboard
The Socket dashboard is the easiest way to not have to go digging around in the depths of APIs and emails to manage security policies and alerts.
Socket Demo - Set 'Organization Wide Policies'
The Socket dashboard allows configuring security policies at an organization level and avoids putting files in every repository. At the same time, having this organization level setting allows security teams to quickly change organization level settings without needing to send pull requests to al...
Socket Demo - Shift Left with Socket.dev package searching capabilities
Visit Socket.dev at any time to search the contents of a package. Socket will give you a health score for that package and tell you about the issues that are existent within so that you can choose the right package for your business.
Socket Demo - Socket Dependency Overview
Socket Dependency Overview provides in-depth insights into added, updated, or removed dependencies, equipping you with critical information to make informed decisions about the impact of changes.
Product Avatar Image

Have you used Socket before?

Answer a few questions to help the Socket community

Socket Reviews (9)

Reviews

Socket Reviews (9)

4.6
9 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Sindhoor H.
SH
"Unique Approach to Supply Chain Security Problem and Does It Really Well"
What do you like best about Socket?

I love the approach Socket has taken towards solving open source security problems with their subjective analysis and the 70 plus signals they use in analyzing each different package. It's quite unheard of across other vendors in the space, making their analysis quite accurate and simplifying our work. Socket helps us save time in manual reviews of open source packages. It also assists developers in evaluating our existing inventory of open source packages for necessary upgrades or changes. The initial setup was pretty straightforward and easy due to the use of GitHub's connection, making it much easier to roll out across multiple repositories. Review collected by and hosted on G2.com.

What do you dislike about Socket?

The UI is quite slow and takes a bit of time to load. Apart from that, I don't have much of an issue. Review collected by and hosted on G2.com.

Brewin V.
BV
VP of Engineering
Mid-Market (51-1000 emp.)
"A modern, developer-friendly approach to software supply chain security"
What do you like best about Socket?

Socket has been a game-changer for our team. It stands out in the SCA space thanks to its developer-centric design and seamless integration into our development workflow. It fits naturally into how we build and ship software - really easy to use!

What I appreciate most is how noise-free the alerts are, especially now with the acquisition of Coana. We're getting real, actionable insights instead of being overwhelmed by false positives.

Additionally, the Socket team has been a fantastic partner - responsive, knowledgeable, and ready to help. We’re excited to see how the platform evolves and continues to push the envelope in this space. Review collected by and hosted on G2.com.

What do you dislike about Socket?

So far, we haven’t encountered any significant drawbacks. The platform has met our expectations and worked well for our needs. Review collected by and hosted on G2.com.

IM
Manager, Software Supply Chain Security
Enterprise (> 1000 emp.)
"An Innovative SCA Approach for Software Supply Chain Risk"
What do you like best about Socket?

Socket.dev is a high-leverage part of a software supply-chain risk program. It reliably surfaces integrity and operational risks in third-party libraries and helps our teams make better decisions, faster.

Its source-first analysis surfaces real operational and supply-chain risks, well beyond CVE lists, and enables acting both proactively and reactively. Deployment scales cleanly, ROI is clear for security and engineering, and the product roadmap is impressively aligned with industry direction. Review collected by and hosted on G2.com.

What do you dislike about Socket?

We have not encountered any material issues to date. The few issues observed, consistent with early-stage growth, are addressed promptly and transparently, and reliability continues trending upward. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Enterprise (> 1000 emp.)
"Broad coverage and rapidly emerging capabilities"
What do you like best about Socket?

We first started to take an interest in Socket thanks to its industry-leading malware detection and blocking capabilities in the supply chain security space. However, with how much they've been adding to the product, it's quickly becoming our tool of choice for all supply chain vulnerability management. They have a lot coming that I'm excited about, they've been responsive to feedback, and they've been iterating pretty quickly. I'm optimistic about the ability to auto-fix vulnerabilities. Review collected by and hosted on G2.com.

What do you dislike about Socket?

I use the product as the head of an application security team. Setting up the tool and getting it to cover PRs was been really easy, but using the console to follow up on the things that developers AREN'T fixing is still burdensome. While tools like `socket fix` are excellent in theory for fixing many issues at once, we still spend a lot of time confirming which alerts are actually worth prioritizing, and the user journey for someone like me here hasn't improved a lot since we started using it earlier this year. Changes are coming, but in the meantime getting its reports into our not-Jira ticketing system and using them for specific triage recommendations has required a lot more effort than expected. This whole experience, from triage to resolution, could be smoother. Review collected by and hosted on G2.com.

Ayush M.
AM
Director
Mid-Market (51-1000 emp.)
"Great Product"
What do you like best about Socket?

It's a great product with an awesome team. We've deployed Socket to our entire GitHub organization Review collected by and hosted on G2.com.

What do you dislike about Socket?

Nothing as of now. waiting for 2-way Jira integration Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Enterprise (> 1000 emp.)
"Next-generation supply chain security"
What do you like best about Socket?

We consume Socket's package scanning APIs as part of an internal supply chain security platform. Socket has been a fantastic partner: they are reliable, responsive, and the product provides high-signal malware detections in open source packages. Review collected by and hosted on G2.com.

What do you dislike about Socket?

No significant drawbacks or compliants about the platform. We'd love more coverage over additional package ecosystems! Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
EI
Mid-Market (51-1000 emp.)
"Strong supply chain monitoring, great customer service"
What do you like best about Socket?

Socket has many security features, but they're especially strong at monitoring for supply chain attacks. They are also very proactive in customer support, responding very quickly to our needs. Review collected by and hosted on G2.com.

What do you dislike about Socket?

There is an overall pain in having so many SAST and other tools. It would be nice for Socket to cover more use cases and thus allow us to consolidate more use cases. Review collected by and hosted on G2.com.

Verified User in Telecommunications
CT
Mid-Market (51-1000 emp.)
"Socket helps keep our software secure"
What do you like best about Socket?

Awesome product. Awesome customers. Awesome team. We've deployed Socket to our whole GitHub organization – love their product , take on supply chain security for us/the world Review collected by and hosted on G2.com.

What do you dislike about Socket?

Nothing as of now.it is providing all the functions which required. Review collected by and hosted on G2.com.

Ivan C.
IC
Assistant System Engineer
Small-Business (50 or fewer emp.)
"Socket review"
What do you like best about Socket?

the tools to safely secure your work are relatively extensive in its use Review collected by and hosted on G2.com.

What do you dislike about Socket?

it can be hard to understand , it's latency, and resource nature gets intensive Review collected by and hosted on G2.com.

Pricing

Pricing details for this product isn’t currently available. Visit the vendor’s website to learn more.