Introducing G2.ai, the future of software buying.Try now
Product Avatar Image

Socket

Show rating breakdown
9 reviews
  • 1 profiles
  • 3 categories
Average star rating
4.6
Serving customers since
2020

Profile Name

Star Rating

7
2
0
0
0

Socket Reviews

Review Filters
Profile Name
Star Rating
7
2
0
0
0
Brewin V.
BV
Brewin V.
07/23/2025
Validated Reviewer
Verified Current User
Review source: Organic

A modern, developer-friendly approach to software supply chain security

Socket has been a game-changer for our team. It stands out in the SCA space thanks to its developer-centric design and seamless integration into our development workflow. It fits naturally into how we build and ship software - really easy to use! What I appreciate most is how noise-free the alerts are, especially now with the acquisition of Coana. We're getting real, actionable insights instead of being overwhelmed by false positives. Additionally, the Socket team has been a fantastic partner - responsive, knowledgeable, and ready to help. We’re excited to see how the platform evolves and continues to push the envelope in this space.
Verified User in Telecommunications
CT
Verified User in Telecommunications
10/21/2023
Validated Reviewer
Review source: G2 invite
Incentivized Review

Socket helps keep our software secure

Awesome product. Awesome customers. Awesome team. We've deployed Socket to our whole GitHub organization – love their product , take on supply chain security for us/the world
Ivan C.
IC
Ivan C.
Assistant Systems Engineer at Tata Consultancy Services
10/12/2023
Validated Reviewer
Review source: G2 invite
Incentivized Review

Socket review

the tools to safely secure your work are relatively extensive in its use

About

Contact

HQ Location:
San Francisco, US

Social

@SocketSecurity

What is Socket?

Languages and Ecosystem Support JavaScript/TypeScript Python Go Ruby Java .NET Scala Kotlin Rust (in progress) GitHub Actions (in progress) (Additional registry and ecosystem support is continuously expanding.) Major Features Real-Time Malicious Package Detection: Flags malware within minutes of publication across major registries (npm, PyPI, etc.). LLM-Powered Code Analysis: Uses AI to understand package intent and catch obfuscated or zero-day threats that traditional tools miss. Reachability Analysis: Reduces vulnerability triage time by up to 10× with precomputed reachability and function-level static analysis, focusing on truly exploitable CVEs. Automated Remediation: Delivers ready-to-merge PRs with backported patches and automatically resolves vulnerabilities. License Compliance: Enforces open source license policies with detailed provenance tracking. Full Lifecycle Protection: Monitors every pull request, package install, and dependency update—across IDEs, CI/CD pipelines, AI coding assistants, and CLIs. Privacy-First and Developer-Friendly: No source code leaves your environment; fast scanning with no performance impact on large monorepos. Fast Facts 8,500+ organizations protected 750,000+ code repositories monitored 100,000+ malicious or risky packages flagged 500+ supply chain attacks prevented weekly

Details

Year Founded
2020
Website
socket.dev