JFrog Xray vs Tenable Nessus comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

JFrog Xray
Ranking in Vulnerability Management
17th
Average Rating
8.2
Number of Reviews
7
Ranking in other categories
Container Security (19th), Software Composition Analysis (SCA) (7th), Software Supply Chain Security (3rd)
Tenable Nessus
Ranking in Vulnerability Management
3rd
Average Rating
8.4
Number of Reviews
75
Ranking in other categories
No ranking in other categories
 

Market share comparison

As of June 2024, in the Vulnerability Management category, the market share of JFrog Xray is 1.4% and it increased by Infinity% compared to the previous year. The market share of Tenable Nessus is 22.0% and it increased by 27.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management
Unique Categories:
Container Security
3.7%
Software Composition Analysis (SCA)
13.3%
No other categories found
 

Featured Reviews

HS
Feb 21, 2024
A stable solution to identify vulnerabilities with embedded rules
JFrog Xray has many policies, settings, and rules embedded. JFrog's Artifactory contains all the dependency files. For instance, if a team is developing an application using Java, they might require certain dependency files. They can obtain all the artifacts from JFrog's Artifactory without accessing the internet, which securely stores these files. The application can retrieve the necessary files from there. Xray is a tool designed to ensure that all artifacts within JFrog's Artifactory are clean. It scans for vulnerabilities and flags them. Based on predefined rules that could potentially harbor vulnerabilities, the Accelerator tool notifies the development team, enabling them to review and fix any issues in the library.
AmardeepSingh - PeerSpot reviewer
Aug 11, 2022
Quick new vulnerabilities support, reliable, but security assessment could improve
We use Tenable Nessus internally for our vulnerability scan and dynamic vulnerability assessments Tenable Nessus has helped us with better visibility of the current security posture of our infrastructure and helped us be proactive about remediating those findings. The most valuable feature of…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I would say that this solution has helped our organization by allowing us to automate a lot of the processes."
"The most valuable feature of JFrog Xray is the display of the entire internal dependencies hierarchy."
"The solution is stable and reliable."
"JFrog Xray shows us a list of vulnerabilities that can impact our code."
"Good reporting functionalities."
"If multiple dependencies and vulnerabilities are found in a project, JFrog Xray is intelligent enough to tell you which vulnerability to target first."
"JFrog Xray's reporting feature has a lot of options in it, including scanning."
"The solution is very stable."
"Tenable Nessus is one of the best vulnerability assessment tools, that I know."
"A valuable feature of the solution is that it is easy to understand."
"User friendly and good dashboards."
"The stability is very good."
"The most valuable feature of Tenable Nessus is the GUI and user-friendliness. Additionally, the environment is easy to work with."
"The ease of use is the primary valuable feature. This specific version is very straightforward. I like the ability to modify it and configure it based on the different policies."
"The results are not that bad, but the key selling point is that it is an affordable tool set."
 

Cons

"JFrog Xray's documentation and error logging could be improved."
"Reporting is crucial, but it is lacking in the current tool. Every organization seeks specific data points rather than general information. Therefore, we require customized reports from the Xray tool."
"Lacks deeper reporting, the ability to compare things."
"Since we have been using the solution via APIs, there are some limitations in the APIs."
"JFrog Xray does not have a dashboard."
"The speed of JFrog Xray should improve. Other solutions have better performance."
"I think that the user interface should be expanded to provide customers with a better dashboard for reviewing their feedback regarding their images and the vulnerabilities that are associated with the images."
"Tenable Nessus could improve the reporting by adding some dashboards. The reports are a hassle at this time. Tenable.io has more detailed reports. Having a better dashboard that can show where the vulnerabilities are and be categorized would be helpful. We then could present them to upper management for a deep overview of our network posture which they do not see."
"The reports should be improved in Tenable Nessus. For example, when you are auditing compliance with CIS standards. It provides very poor reports."
"There could be an integration between Tenable Nessus and other Tenable products. It will help us manage all the solutions using one dashboard."
"To be honest, I haven't used it much to tell you that these are the things that should be improved. But I believe the UI should be enhanced somewhat. For example, there are two ways to find a report, and people are frequently confused as to which is the correct method for locating a full report. Sometimes they go in the opposite direction, so this is an area that may be improved."
"In Nessus Professional, the main drawback was that we could have a single-user login password. So it could be better in terms of security."
"I have found it is sometimes difficult to control the Zoom meeting sessions. For example, it is difficult to know who is talking and when trying to mute everyone but the speaker you end up muting everyone. When using multiple screens it is laborious to find the control buttons, such as to start a session. Additionally, when a recording is done I have found it difficult to find them, there should be an easier way to retrieve them."
"Consumes more system resources when it's running."
"They should improve the I/O reporting and the customized spreadsheet export feature."
 

Pricing and Cost Advice

Information not available
"There is an annual license required to use this solution."
"The solution has free options."
"The price is high for the solution. There are free tools with similar functionality available. The solution cost approximately $3,500."
"I would like to see better discounts."
"We incurred a single cost for a perpetual license, although I cannot comment on the price as this is above my management level."
"The pricing is much more manageable versus other products."
"One problem with Tenable is its pricing policy. Optimal results can be achieved with Greenbone Solutions which has much more friendly pricing policies."
"Its price is high for Libya. The companies here in Libya don't have the awareness of and a good budget for cybersecurity services. If you want them to go for a product, you need to provide something different. This differentiation is related to the price. They should give about 40% to 45% discount per person on the current cost."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
24%
Manufacturing Company
15%
Computer Software Company
12%
Insurance Company
5%
Educational Organization
35%
Computer Software Company
11%
Government
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about JFrog Xray?
JFrog Xray shows us a list of vulnerabilities that can impact our code.
What needs improvement with JFrog Xray?
There is a tool called DefectDojo for reporting. Reporting is crucial, but it is lacking in the current tool. Every organization seeks specific data points rather than general information. Therefor...
What is your primary use case for JFrog Xray?
We use this solution to identify vulnerabilities in the dependency file. We have the Artifactory package which integrates with Xray-like plugins. We can automatically plug this tool into Xray to co...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the program is such that if a company should desire to handle the installation t...
What do you like most about Tenable Nessus?
We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to address identified vulnerabilities. These scans cover the servers, other network equi...
 

Comparisons

 

Also Known As

JFrog Security Essentials
No data available
 

Learn More

 

Overview

 

Sample Customers

google, amazon, cisco, netflix, oracle, vmware, facebook
Bitbrains, Tesla, Just Eat, Crosskey Banking Solutions, Covenant Health, Youngstown State University
Find out what your peers are saying about JFrog Xray vs. Tenable Nessus and other solutions. Updated: June 2024.
787,061 professionals have used our research since 2012.