Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cycode
Ranking in Software Composition Analysis (SCA)
19th
Ranking in Software Supply Chain Security
9th
Average Rating
0.0
Number of Reviews
0
Ranking in other categories
Static Application Security Testing (SAST) (34th), Application Security Posture Management (ASPM) (4th)
Mend.io
Ranking in Software Composition Analysis (SCA)
4th
Ranking in Software Supply Chain Security
1st
Average Rating
8.4
Number of Reviews
29
Ranking in other categories
Application Security Tools (13th)
 

Market share comparison

As of June 2024, in the Software Composition Analysis (SCA) category, the market share of Cycode is 1.3% and it increased by 869.3% compared to the previous year. The market share of Mend.io is 7.6% and it decreased by 23.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Composition Analysis (SCA)
Unique Categories:
Static Application Security Testing (SAST)
0.3%
Software Supply Chain Security
22.5%
Application Security Tools
3.6%
 

Featured Reviews

GP
Jul 17, 2022
Provides threat detection and an excellent UI in a highly stable solution, with outstanding technical support
We have been looking at how we could improve the automation to human involvement ratio from 60:40 to 70:30, or even potentially 80:20, as there is room for improvement here. We are discussing this internally and with Mend; they are very accommodating to us. We think they openly receive our feedback and do their best to implement our thoughts into the roadmap. I consider scan reports to be another area for improvement, but this is also an area of improvement for user management on our end. We need to train end users on how to deal with alerts and the best approach to take for new projects. We have weekly meetings with Mend and encourage all users who integrate the solution into their product life cycle to attend. This has been very useful, as these technical meetings assist our staff in the best use practices and improving their interpretation of reports, which allows us to leverage the product to our greatest advantage. We are also able to ask for solutions adaptations to suit our requirements, as we produce hardware as a company, not virtual products.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pricing and Cost Advice

Information not available
"Over the last two years, they have tried to add more and more features to their license packages, but the price is a little bit high, comparatively."
"As we were using an SaaS-based service, the solution must be scalable, although my understanding is that this is based on the licensing model one is using."
"WhiteSource is much more affordable than Veracode."
"This is an expensive solution."
"The version that we are using, WhiteSource Bolt, is a free integration with Azure DevOps."
"Pricing is competitive."
"It is fairly priced."
"The solution involves a yearly licensing fee."
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
15%
Financial Services Firm
10%
Computer Software Company
9%
Real Estate/Law Firm
6%
Financial Services Firm
17%
Computer Software Company
16%
Manufacturing Company
11%
Insurance Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Ask a question
Earn 20 points
How does WhiteSource compare with SonarQube?
Red Hat Ceph does well in simplifying storage integration by replacing the need for numerous storage solutions. This solution allows for multiple copies of replicated and coded pools to be kept, ea...
How does WhiteSource compare with Black Duck?
We researched Black Duck but ultimately chose WhiteSource when looking for an application security tool. WhiteSource is a software solution that enables agile open source security and license compl...
What do you like most about Mend.io?
The best feature is that the Mend R&D team does their due diligence for all the vulnerabilities. In case they observe any important or critical vulnerabilities, such as the Log4j-related vulner...
 

Comparisons

 

Also Known As

No data available
WhiteSource, Mend SCA, Mend.io Supply Chain Defender
 

Learn More

Video not available
 

Overview

 

Sample Customers

Information Not Available
Microsoft, Autodesk, NCR, Target, IBM, vodafone, Siemens, GE digital, KPMG, LivePerson, Jack Henry and Associates
Find out what your peers are saying about Synopsys, Veracode, Snyk and others in Software Composition Analysis (SCA). Updated: May 2024.
787,061 professionals have used our research since 2012.