Try our new research platform with insights from 80,000+ expert users

Mend.io vs OpenText Static Application Security Testing comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 28, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.7
Mend.io enhances ROI by automating security, improving efficiency, and integrating seamlessly into workflows, saving time and costs.
Sentiment score
6.8
OpenText Static Application Security Testing received mixed reviews, praising cost savings and partnerships, but highlighting challenges in quantifying ROI.
Mend.io has provided a good return on investment by significantly reducing vulnerabilities.
CEO at a computer software company with 10,001+ employees
 

Customer Service

Sentiment score
6.6
Mend.io customer service is proactive and responsive, praised for timely solutions, technical expertise, and efficient issue resolution.
Sentiment score
6.7
Generally positive with dedicated teams, though some seek improvements in ticket system and responsiveness for OpenText support.
They prioritize providing the best experience to large organizations like ours, belonging to the Fortune 100.
CEO at a computer software company with 10,001+ employees
I have noticed that the speed to respond has decreased over time.
VP at a tech vendor with 5,001-10,000 employees
Mend.io provides pretty good support.
CEO at a computer software company with 10,001+ employees
The customer service and support for Fortify Static Code Analyzer are better than those for LoadRunner.
CTO at Marco Technology
The technical support has been good because we always received answers to our questions.
Manager at DTEK
 

Scalability Issues

Sentiment score
7.5
Mend.io scales seamlessly with organizational growth, integrating into workflows and DevOps tools, enhancing security and collaboration effortlessly.
Sentiment score
7.8
OpenText SAST is scalable for various project sizes but needs improvement in speed and infrastructure management.
 

Stability Issues

Sentiment score
7.7
Mend.io is stable with occasional slowdowns, recommended on Chrome/Firefox, and improved by ongoing enhancements and updates.
Sentiment score
7.5
OpenText Static Application Security Testing is reliable and stable, with improvements since version 19.10, and benefits from proper training.
Mend.io is very stable; we did not have any issues.
CEO at a computer software company with 10,001+ employees
AI integration in code security tools like Mend.io is still in its early stages and relatively immature.
CEO at a computer software company with 10,001+ employees
The stability of Fortify Static Code Analyzer is generally good.
CTO at Marco Technology
I would rate the product stability as an eight.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
 

Room For Improvement

Mend.io users request better notifications, improved container scanning, clearer documentation, enhanced UI, flexible pricing, and reduced false positives.
OpenText SAST faces high costs, complex use, false positives, and needs better integration, language support, and feature enhancements.
That's not a limitation of Mend.io; I think that's a general problem with any tool in the market because no tool in the market will actually know what portion of the code I'm actually using from that particular library if it is vulnerable or not.
CEO at a computer software company with 10,001+ employees
I strongly recommend that they start working with AI for the reporting part.
VP at a tech vendor with 5,001-10,000 employees
The actual challenge is how easy it is to integrate it in the early phase of the software development life cycle.
Principal Architect at a consultancy with 11-50 employees
We are not ready to transfer our code without control to AI instruments.
Manager at DTEK
While it includes all the OWASP top factors, AI has come into the picture, so those updates should also be considered.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers.
CTO at Marco Technology
 

Setup Cost

Mend.io's pricing is seen as affordable and clear, yet varies by developer count, posing challenges for startups.
Enterprise users find OpenText Static Application Security Testing's pricing high but consider it economical compared to other major solutions.
The cost of Mend.io is competitive, being quite low compared to others.
CEO at a computer software company with 10,001+ employees
My experience with the pricing, setup costs, and licensing has been good.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs.
CTO at Marco Technology
 

Valuable Features

Mend.io provides comprehensive vulnerability detection, license management, and integration tools to enhance security and decision-making practices effectively.
OpenText SAST enhances security by automating vulnerability detection, integrating across tools, and providing detailed remediation and compliance guidance.
We find it 100% accurate in detecting vulnerabilities.
CEO at a computer software company with 10,001+ employees
Mend.io is very efficient, highly efficient, and it is the best scanning tool for SCA.
CEO at a computer software company with 10,001+ employees
Mend.io's reporting tools are beneficial for my use case; from a UI perspective and generation of reports, including the SBOM, it has the flexibility and is easy to generate and share with the developer teams.
VP at a tech vendor with 5,001-10,000 employees
Fortify Static Code Analyzer has the capability of giving fewer false positives compared to other tools.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
The most impactful feature of Fortify Static Code Analyzer in identifying vulnerabilities is the ratio of total number of vulnerabilities to false positives.
Manager at DTEK
The most valuable feature of Fortify Static Code Analyzer is its extensive language support, covering many languages from legacy ones to the newest.
CTO at Marco Technology
 

Categories and Ranking

Mend.io
Ranking in Static Code Analysis
5th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
33
Ranking in other categories
Application Security Tools (19th), Software Composition Analysis (SCA) (7th), Software Supply Chain Security (2nd)
OpenText Static Application...
Ranking in Static Code Analysis
3rd
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
19
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of December 2025, in the Static Code Analysis category, the mindshare of Mend.io is 6.5%, down from 9.8% compared to the previous year. The mindshare of OpenText Static Application Security Testing is 8.3%, down from 10.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Code Analysis Market Share Distribution
ProductMarket Share (%)
OpenText Static Application Security Testing8.3%
Mend.io6.5%
Other85.2%
Static Code Analysis
 

Featured Reviews

meetharoon - PeerSpot reviewer
CEO at a computer software company with 10,001+ employees
Centralized security monitoring has reduced false positives and improves dependency governance
The only area for improvement I would say is that the false positives are nearly zero; everything is mostly like 99 to 99.99% or we can say 100% accurate. There were a few areas for improvement just from the last time I saw; I think the user experience had a little problem. We wanted to have certain reports based on our kind of scenario, but the tool did not allow us to create custom reports. We had asked for some facility and some ability for us to create some custom reports. That would be awesome if they allow us to create custom reports the way we wanted. There is one small area which I don't know whether we should call a tool limitation or a wish list; if I use a library and I don't use all the capabilities of the library but only a portion of it and that portion is not vulnerable, but there is a component which is outdated, that is a problem, even though I don't use that component. Mend.io will discover there is a problem in the whole library; that is correct. That's a valid discovery, but in my case, for example, if I don't use that particular portion, then it actually is not making sense for me, but that's not a limitation of Mend.io; I think that's a general problem with any tool in the market because no tool in the market will actually know what portion of the code I'm actually using from that particular library if it is vulnerable or not.
DK
Lead Information Security Analyst at a financial services firm with 10,001+ employees
Focuses on detailed scans to find critical vulnerabilities while ensuring minimal false positives
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less than the current latest version. It would be really helpful to include trending vulnerabilities and how to manage them. While it includes all the OWASP top factors, AI has come into the picture, so those updates should also be considered. I haven't thought much about additional features for improvement since I am using it daily. Most of our work revolves around scanning and providing the results, which sometimes feels like a crunch. However, I believe rule pack updates should be implemented. It feels easy to upgrade to the latest version as well.
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
879,310 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
13%
Manufacturing Company
13%
Energy/Utilities Company
5%
Financial Services Firm
28%
Computer Software Company
11%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise20
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise3
Large Enterprise11
 

Questions from the Community

How does WhiteSource compare with SonarQube?
Red Hat Ceph does well in simplifying storage integration by replacing the need for numerous storage solutions. This solution allows for multiple copies of replicated and coded pools to be kept, ea...
How does WhiteSource compare with Black Duck?
We researched Black Duck but ultimately chose WhiteSource when looking for an application security tool. WhiteSource is a software solution that enables agile open source security and license compl...
What is your experience regarding pricing and costs for Mend.io?
Mend.io SCA offers a competitive pricing structure that is relatively affordable compared to similar solutions in the market. This makes it an attractive option for organizations looking to enhance...
What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
My experience with the pricing, setup costs, and licensing has been good. We have the scan machines, and we are planning to request more from Micro Focus now. We have calls every month or every oth...
What needs improvement with Fortify Static Code Analyzer?
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less ...
 

Also Known As

WhiteSource, Mend SCA, Mend.io Supply Chain Defender, Mend SAST
Fortify Static Code Analysis SAST
 

Overview

 

Sample Customers

Microsoft, Autodesk, NCR, Target, IBM, vodafone, Siemens, GE digital, KPMG, LivePerson, Jack Henry and Associates
Information Not Available
Find out what your peers are saying about Mend.io vs. OpenText Static Application Security Testing and other solutions. Updated: December 2025.
879,310 professionals have used our research since 2012.