Product Avatar Image

Socket

Show rating breakdown
10 reviews
  • 1 profiles
  • 3 categories
Average star rating
4.7
Serving customers since
2020

Profile Name

Star Rating

8
2
0
0
0

Socket Reviews

Review Filters
Profile Name
Star Rating
8
2
0
0
0
Shreejal M.
SM
Shreejal M.
Full Stack Developer
04/24/2026
Validated Reviewer
Review source: Organic

Essential Tool for Application Security with Stellar MCP Feature

I like using Socket for everything in regards to my application security. It's the exact tool we need to make sure we don't download anything nefarious, especially in the age of vulnerable libraries. I appreciate the MCP feature, which allows AI agents to check the packages in advance so we don't download anything insecure or malicious. The initial setup was as easy as chips.
Sindhoor H.
SH
Sindhoor H.
12/05/2025
Validated Reviewer
Review source: Organic

Unique Approach to Supply Chain Security Problem and Does It Really Well

I love the approach Socket has taken towards solving open source security problems with their subjective analysis and the 70 plus signals they use in analyzing each different package. It's quite unheard of across other vendors in the space, making their analysis quite accurate and simplifying our work. Socket helps us save time in manual reviews of open source packages. It also assists developers in evaluating our existing inventory of open source packages for necessary upgrades or changes. The initial setup was pretty straightforward and easy due to the use of GitHub's connection, making it much easier to roll out across multiple repositories.
Verified User in Computer Software
AC
Verified User in Computer Software
10/17/2025
Validated Reviewer
Verified Current User
Review source: Organic

Next-generation supply chain security

We consume Socket's package scanning APIs as part of an internal supply chain security platform. Socket has been a fantastic partner: they are reliable, responsive, and the product provides high-signal malware detections in open source packages.

About

Contact

HQ Location:
San Francisco, US

Social

@SocketSecurity

What is Socket?

Languages and Ecosystem Support JavaScript/TypeScript Python Go Ruby Java .NET Scala Kotlin Rust (in progress) GitHub Actions (in progress) (Additional registry and ecosystem support is continuously expanding.) Major Features Real-Time Malicious Package Detection: Flags malware within minutes of publication across major registries (npm, PyPI, etc.). LLM-Powered Code Analysis: Uses AI to understand package intent and catch obfuscated or zero-day threats that traditional tools miss. Reachability Analysis: Reduces vulnerability triage time by up to 10× with precomputed reachability and function-level static analysis, focusing on truly exploitable CVEs. Automated Remediation: Delivers ready-to-merge PRs with backported patches and automatically resolves vulnerabilities. License Compliance: Enforces open source license policies with detailed provenance tracking. Full Lifecycle Protection: Monitors every pull request, package install, and dependency update—across IDEs, CI/CD pipelines, AI coding assistants, and CLIs. Privacy-First and Developer-Friendly: No source code leaves your environment; fast scanning with no performance impact on large monorepos. Fast Facts 8,500+ organizations protected 750,000+ code repositories monitored 100,000+ malicious or risky packages flagged 500+ supply chain attacks prevented weekly

Details

Year Founded
2020
Website
socket.dev