Socket Pros and Cons: Top Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users value the strong security features of Socket, especially its effective monitoring for supply chain attacks. (3 mentions)
Users value the accurate open source security analysis provided by Socket, which simplifies package evaluations and saves time. (2 mentions)
Users appreciate Socket's accurate analysis, simplifying open source security and enhancing efficiency in package evaluations. (1 mentions)
Users value the quick response to alerts, enhancing security and support during supply chain monitoring. (1 mentions)
Users value the comprehensive security of Socket, enhancing decision-making and mitigating risks in third-party libraries. (1 mentions)
Users find the missing features in Socket limiting, wishing for more use case coverage to consolidate tools. (1 mentions)
Users experience system slowness, particularly with the UI taking time to load, affecting their overall experience. (1 mentions)

Top Pros or Advantages of Socket

1. Security
Users value the strong security features of Socket, especially its effective monitoring for supply chain attacks.
See 3 mentions

See Related User Reviews

Verified User
A

Verified User

Enterprise (> 1000 emp.)

5.0/5

"Next-generation supply chain security"

What do you like about Socket?

We consume Socket's package scanning APIs as part of an internal supply chain security platform. Socket has been a fantastic partner: they are reliabl

Verified User
E

Verified User

Mid-Market (51-1000 emp.)

5.0/5

"Strong supply chain monitoring, great customer service"

What do you like about Socket?

Socket has many security features, but they're especially strong at monitoring for supply chain attacks. They are also very proactive in customer supp

2. Open Source
Users value the accurate open source security analysis provided by Socket, which simplifies package evaluations and saves time.
See 2 mentions

See Related User Reviews

Sindhoor H.
SH

Sindhoor H.

5.0/5

"Unique Approach to Supply Chain Security Problem and Does It Really Well"

What do you like about Socket?

I love the approach Socket has taken towards solving open source security problems with their subjective analysis and the 70 plus signals they use in

Verified User
A

Verified User

Enterprise (> 1000 emp.)

5.0/5

"Next-generation supply chain security"

What do you like about Socket?

We consume Socket's package scanning APIs as part of an internal supply chain security platform. Socket has been a fantastic partner: they are reliabl

3. Accuracy of Findings
Users appreciate Socket's accurate analysis, simplifying open source security and enhancing efficiency in package evaluations.
See 1 mentions

See Related User Reviews

Sindhoor H.
SH

Sindhoor H.

5.0/5

"Unique Approach to Supply Chain Security Problem and Does It Really Well"

What do you like about Socket?

I love the approach Socket has taken towards solving open source security problems with their subjective analysis and the 70 plus signals they use in

4. Alerts
Users value the quick response to alerts, enhancing security and support during supply chain monitoring.
See 1 mentions

See Related User Reviews

Verified User
E

Verified User

Mid-Market (51-1000 emp.)

5.0/5

"Strong supply chain monitoring, great customer service"

What do you like about Socket?

Socket has many security features, but they're especially strong at monitoring for supply chain attacks. They are also very proactive in customer supp

5. Comprehensive Security
Users value the comprehensive security of Socket, enhancing decision-making and mitigating risks in third-party libraries.
See 1 mentions

See Related User Reviews

IM

Itai M.

Enterprise (> 1000 emp.)

4.5/5

"An Innovative SCA Approach for Software Supply Chain Risk"

What do you like about Socket?

Socket.dev is a high-leverage part of a software supply-chain risk program. It reliably surfaces integrity and operational risks in third-party librar

Top Cons or Disadvantages of Socket

1. Missing Features
Users find the missing features in Socket limiting, wishing for more use case coverage to consolidate tools.
See 1 mentions

See Related User Reviews

Verified User
E

Verified User

Mid-Market (51-1000 emp.)

5.0/5

"Strong supply chain monitoring, great customer service"

What do you dislike about Socket?

There is an overall pain in having so many SAST and other tools. It would be nice for Socket to cover more use cases and thus allow us to consolidate

2. System Slowness
Users experience system slowness, particularly with the UI taking time to load, affecting their overall experience.
See 1 mentions

See Related User Reviews

Sindhoor H.
SH

Sindhoor H.

5.0/5

"Unique Approach to Supply Chain Security Problem and Does It Really Well"

What do you dislike about Socket?

The UI is quite slow and takes a bit of time to load. Apart from that, I don't have much of an issue.

Socket Reviews (10)

Reviews

Socket Reviews (10)

4.7
10 reviews
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Shreejal M.
SM
Full-stack Developer
Retail
Small-Business (50 or fewer emp.)
"Essential Tool for Application Security with Stellar MCP Feature"
What do you like best about Socket?

I like using Socket for everything in regards to my application security. It's the exact tool we need to make sure we don't download anything nefarious, especially in the age of vulnerable libraries. I appreciate the MCP feature, which allows AI agents to check the packages in advance so we don't download anything insecure or malicious. The initial setup was as easy as chips. Review collected by and hosted on G2.com.

What do you dislike about Socket?

N/A Review collected by and hosted on G2.com.

Sindhoor H.
SH
"Unique Approach to Supply Chain Security Problem and Does It Really Well"
What do you like best about Socket?

I love the approach Socket has taken towards solving open source security problems with their subjective analysis and the 70 plus signals they use in analyzing each different package. It's quite unheard of across other vendors in the space, making their analysis quite accurate and simplifying our work. Socket helps us save time in manual reviews of open source packages. It also assists developers in evaluating our existing inventory of open source packages for necessary upgrades or changes. The initial setup was pretty straightforward and easy due to the use of GitHub's connection, making it much easier to roll out across multiple repositories. Review collected by and hosted on G2.com.

What do you dislike about Socket?

The UI is quite slow and takes a bit of time to load. Apart from that, I don't have much of an issue. Review collected by and hosted on G2.com.

Brewin V.
BV
VP of Engineering
Mid-Market (51-1000 emp.)
"A modern, developer-friendly approach to software supply chain security"
What do you like best about Socket?

Socket has been a game-changer for our team. It stands out in the SCA space thanks to its developer-centric design and seamless integration into our development workflow. It fits naturally into how we build and ship software - really easy to use!

What I appreciate most is how noise-free the alerts are, especially now with the acquisition of Coana. We're getting real, actionable insights instead of being overwhelmed by false positives.

Additionally, the Socket team has been a fantastic partner - responsive, knowledgeable, and ready to help. We’re excited to see how the platform evolves and continues to push the envelope in this space. Review collected by and hosted on G2.com.

What do you dislike about Socket?

So far, we haven’t encountered any significant drawbacks. The platform has met our expectations and worked well for our needs. Review collected by and hosted on G2.com.

IM
Manager, Software Supply Chain Security
Enterprise (> 1000 emp.)
"An Innovative SCA Approach for Software Supply Chain Risk"
What do you like best about Socket?

Socket.dev is a high-leverage part of a software supply-chain risk program. It reliably surfaces integrity and operational risks in third-party libraries and helps our teams make better decisions, faster.

Its source-first analysis surfaces real operational and supply-chain risks, well beyond CVE lists, and enables acting both proactively and reactively. Deployment scales cleanly, ROI is clear for security and engineering, and the product roadmap is impressively aligned with industry direction. Review collected by and hosted on G2.com.

What do you dislike about Socket?

We have not encountered any material issues to date. The few issues observed, consistent with early-stage growth, are addressed promptly and transparently, and reliability continues trending upward. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Enterprise (> 1000 emp.)
"Broad coverage and rapidly emerging capabilities"
What do you like best about Socket?

We first started to take an interest in Socket thanks to its industry-leading malware detection and blocking capabilities in the supply chain security space. However, with how much they've been adding to the product, it's quickly becoming our tool of choice for all supply chain vulnerability management. They have a lot coming that I'm excited about, they've been responsive to feedback, and they've been iterating pretty quickly. I'm optimistic about the ability to auto-fix vulnerabilities. Review collected by and hosted on G2.com.

What do you dislike about Socket?

I use the product as the head of an application security team. Setting up the tool and getting it to cover PRs was been really easy, but using the console to follow up on the things that developers AREN'T fixing is still burdensome. While tools like `socket fix` are excellent in theory for fixing many issues at once, we still spend a lot of time confirming which alerts are actually worth prioritizing, and the user journey for someone like me here hasn't improved a lot since we started using it earlier this year. Changes are coming, but in the meantime getting its reports into our not-Jira ticketing system and using them for specific triage recommendations has required a lot more effort than expected. This whole experience, from triage to resolution, could be smoother. Review collected by and hosted on G2.com.

Ayush M.
AM
Director
Mid-Market (51-1000 emp.)
"Great Product"
What do you like best about Socket?

It's a great product with an awesome team. We've deployed Socket to our entire GitHub organization Review collected by and hosted on G2.com.

What do you dislike about Socket?

Nothing as of now. waiting for 2-way Jira integration Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Enterprise (> 1000 emp.)
"Next-generation supply chain security"
What do you like best about Socket?

We consume Socket's package scanning APIs as part of an internal supply chain security platform. Socket has been a fantastic partner: they are reliable, responsive, and the product provides high-signal malware detections in open source packages. Review collected by and hosted on G2.com.

What do you dislike about Socket?

No significant drawbacks or compliants about the platform. We'd love more coverage over additional package ecosystems! Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
EI
Mid-Market (51-1000 emp.)
"Strong supply chain monitoring, great customer service"
What do you like best about Socket?

Socket has many security features, but they're especially strong at monitoring for supply chain attacks. They are also very proactive in customer support, responding very quickly to our needs. Review collected by and hosted on G2.com.

What do you dislike about Socket?

There is an overall pain in having so many SAST and other tools. It would be nice for Socket to cover more use cases and thus allow us to consolidate more use cases. Review collected by and hosted on G2.com.

Verified User in Telecommunications
CT
Mid-Market (51-1000 emp.)
"Socket helps keep our software secure"
What do you like best about Socket?

Awesome product. Awesome customers. Awesome team. We've deployed Socket to our whole GitHub organization – love their product , take on supply chain security for us/the world Review collected by and hosted on G2.com.

What do you dislike about Socket?

Nothing as of now.it is providing all the functions which required. Review collected by and hosted on G2.com.

Ivan C.
IC
Assistant System Engineer
Small-Business (50 or fewer emp.)
"Socket review"
What do you like best about Socket?

the tools to safely secure your work are relatively extensive in its use Review collected by and hosted on G2.com.

What do you dislike about Socket?

it can be hard to understand , it's latency, and resource nature gets intensive Review collected by and hosted on G2.com.

Product Avatar Image
Socket