Product Avatar Image

Socket

Show rating breakdown
10 reviews
  • 1 profiles
  • 3 categories
Average star rating
4.7
Serving customers since
2020

Profile Name

Star Rating

8
2
0
0
0

Socket Reviews

Review Filters
Profile Name
Star Rating
8
2
0
0
0
Ayush M.
AM
Ayush M.
10/10/2025
Validated Reviewer
Verified Current User
Review source: Organic

Great Product

It's a great product with an awesome team. We've deployed Socket to our entire GitHub organization
Verified User in Information Technology and Services
EI
Verified User in Information Technology and Services
09/10/2025
Validated Reviewer
Review source: Organic

Strong supply chain monitoring, great customer service

Socket has many security features, but they're especially strong at monitoring for supply chain attacks. They are also very proactive in customer support, responding very quickly to our needs.
IM
Itai M.
08/19/2025
Validated Reviewer
Verified Current User
Review source: Organic

An Innovative SCA Approach for Software Supply Chain Risk

Socket.dev is a high-leverage part of a software supply-chain risk program. It reliably surfaces integrity and operational risks in third-party libraries and helps our teams make better decisions, faster. Its source-first analysis surfaces real operational and supply-chain risks, well beyond CVE lists, and enables acting both proactively and reactively. Deployment scales cleanly, ROI is clear for security and engineering, and the product roadmap is impressively aligned with industry direction.

About

Contact

HQ Location:
San Francisco, US

Social

@SocketSecurity

What is Socket?

Languages and Ecosystem Support JavaScript/TypeScript Python Go Ruby Java .NET Scala Kotlin Rust (in progress) GitHub Actions (in progress) (Additional registry and ecosystem support is continuously expanding.) Major Features Real-Time Malicious Package Detection: Flags malware within minutes of publication across major registries (npm, PyPI, etc.). LLM-Powered Code Analysis: Uses AI to understand package intent and catch obfuscated or zero-day threats that traditional tools miss. Reachability Analysis: Reduces vulnerability triage time by up to 10× with precomputed reachability and function-level static analysis, focusing on truly exploitable CVEs. Automated Remediation: Delivers ready-to-merge PRs with backported patches and automatically resolves vulnerabilities. License Compliance: Enforces open source license policies with detailed provenance tracking. Full Lifecycle Protection: Monitors every pull request, package install, and dependency update—across IDEs, CI/CD pipelines, AI coding assistants, and CLIs. Privacy-First and Developer-Friendly: No source code leaves your environment; fast scanning with no performance impact on large monorepos. Fast Facts 8,500+ organizations protected 750,000+ code repositories monitored 100,000+ malicious or risky packages flagged 500+ supply chain attacks prevented weekly

Details

Year Founded
2020
Website
socket.dev