Try our new research platform with insights from 80,000+ expert users
Black Duck SCA Logo

Black Duck SCA Reviews

Vendor: Black Duck
3.8 out of 5
Badge Ranked 1

What is Black Duck SCA?

Featured Black Duck SCA reviews

Black Duck SCA mindshare

As of September 2025, the mindshare of Black Duck SCA in the Software Composition Analysis (SCA) category stands at 16.7%, down from 22.4% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Software Composition Analysis (SCA) Market Share Distribution
ProductMarket Share (%)
Black Duck16.7%
Snyk13.1%
JFrog Xray10.1%
Other60.1%
Software Composition Analysis (SCA)

PeerResearch reports based on Black Duck SCA reviews

TypeTitleDate
CategorySoftware Composition Analysis (SCA)Sep 15, 2025Download
ProductReviews, tips, and advice from real usersSep 15, 2025Download
ComparisonBlack Duck SCA vs SnykSep 15, 2025Download
ComparisonBlack Duck SCA vs VeracodeSep 15, 2025Download
ComparisonBlack Duck SCA vs Sonatype LifecycleSep 15, 2025Download
Suggested products
TitleRatingMindshareRecommending
GitLab4.24.3%97%86 interviewsAdd to research
Snyk4.013.1%100%48 interviewsAdd to research
 
 
Key learnings from peers

Valuable Features

Room for Improvement

ROI

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
Company SizeCount
Small Business6
Large Enterprise13
By reviewers
By visitors reading reviews
Company SizeCount
Small Business442
Midsize Enterprise264
Large Enterprise1638
By visitors reading reviews

Top industries

By visitors reading reviews
Financial Services Firm
18%
Manufacturing Company
15%
Computer Software Company
13%
Insurance Company
5%
Healthcare Company
4%
Retailer
4%
Educational Organization
3%
University
3%
Real Estate/Law Firm
3%
Comms Service Provider
3%
Energy/Utilities Company
3%
Government
3%
Media Company
2%
Construction Company
2%
Consumer Goods Company
2%
Transportation Company
2%
Non Profit
2%
Performing Arts
2%
Outsourcing Company
1%
Legal Firm
1%
Recreational Facilities/Services Company
1%
Hospitality Company
1%
Marketing Services Firm
1%
Wholesaler/Distributor
1%
Logistics Company
1%
Pharma/Biotech Company
1%
Aerospace/Defense Firm
1%
Security Firm
1%

Compare Black Duck SCA with alternative products

Learn more about Black Duck SCA

Black Duck SCA customers

Related questions

 
Black Duck SCA Reviews Summary
Author infoRatingReview Summary
IP Head at a tech services company with 10,001+ employees3.5I find Black Duck to be robust and accurate, particularly in identifying dependencies and licenses, but it needs improvement in security vulnerability identification. It's pricier and complex to set up, impacting direct ROI assessment in some cases.
Director at a healthcare company with 10,001+ employees3.0I recommend Black Duck for its ability to identify software components and manage security, operational, and license risks effectively. While it excels in risk management, improvements are needed in addressing false positives, reporting, and container scanning.
Director at a healthcare company with 10,001+ employees4.0I use Black Duck primarily for software composition analysis. Its composition analysis and automated code scanning features are valuable for managing security risks and audit readiness. However, the absence of SBOM management is a notable drawback for me.
DevOps Engineer at a manufacturing company with 1,001-5,000 employees3.5As a DevOps engineer, I integrate Black Duck in our CI/CD pipeline for product vulnerability scans. The UI is valuable for easy integration, but improvements are needed in pricing, documentation, and scalability. Debugging can be challenging without adequate documentation.
Senior Manager at Happiest Minds Technologies3.5We use Black Duck for open-source security management in DevOps and DevSecOps, appreciating its integration capabilities and community resources. It effectively secures 400 to 500 applications, although more open APIs would enhance its functionality further.
Solutions Architect at a tech services company with 10,001+ employees4.0I use Synopsys Black Duck for security-focused project scans, identifying vulnerabilities through source code and binary analysis. It provides precise fixes and dependency insights, but sometimes lacks consistency, particularly in differentiating between direct and transitive vulnerabilities.
Project Manager at a manufacturing company with 11-50 employees4.5I use Black Duck to detect vulnerabilities in open-source software, valuing its effective binary file scanning. However, its reporting capabilities need improvement for clarity and comprehensiveness. Compared to competitors, it's superior in deployment, scalability, and its comprehensive vulnerability database.
Senior Quality Manager at a financial services firm with 11-50 employees4.0I use Black Duck to check open source software in our products. It efficiently scans for license compliance but can be cumbersome due to hold times and sometimes gives ambiguous results. I don't have experience with other solutions.