Try our new research platform with insights from 80,000+ expert users

Black Duck vs JFrog Xray comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 27, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.2
Black Duck improved efficiency by identifying vulnerabilities early, saving time, streamlining audits, reducing manual effort, and enhancing code security.
Sentiment score
4.3
JFrog Xray improved efficiency, security, and compliance, reduced downtime, and sped up release cycles with enhanced vulnerability detection and reporting.
If you're using it on critical external programs where there is regulatory compliance on ensuring that the source code is clean from open-source, there's substantial ROI.
 

Customer Service

Sentiment score
9.3
Black Duck support is praised for professionalism and speed, but faces inconsistent feedback, response delays, and suggests chatbot integration improvements.
Sentiment score
3.3
JFrog Xray's customer service is generally well-received, with positive technical support, though not all users engage directly.
There are some pain points with the response time and first-level support quality.
When we need clarifications, we contact our account manager, and they arrange demos.
 

Scalability Issues

Sentiment score
8.0
Black Duck is scalable, praised for cloud support and integration, but pricing may deter smaller firms despite versatility.
Sentiment score
7.5
JFrog Xray is scalable and suitable for multiple applications, despite PostgreSQL limitations and some performance challenges.
I would rate the scalability of Black Duck 8 or 9.
According to my use case, it is highly scalable.
 

Stability Issues

Sentiment score
8.0
Black Duck is highly stable, reliable, with minimal issues; users recommend against transitioning to Hub due to potential problems.
Sentiment score
7.8
JFrog Xray is praised for stability and security, compared favorably to competitors, with minor concerns about PostgreSQL support.
I use JFrog Xray primarily for security purposes, and I find it reliable.
 

Room For Improvement

Black Duck needs better integration, speed, UI, documentation, pricing, security, scalability, and support for improved user experience.
Users demand better reporting, documentation, UI, site performance, API limits, custom reports, vulnerability management, and integration support.
It can improve on the security side of it, specifically vulnerabilities identification.
There are areas for improvement such as false positives and the scanning of containers.
Black Duck does not have the SBOM management part.
When we have given a very long tag, it doesn't work as expected and requires excessive scrolling.
X-ray needs improvement in supporting more than one database, as it currently only supports PostgreSQL.
 

Setup Cost

Black Duck's pricing ranges from $10,000 to $70,000, with unlimited users for code size, though some find it expensive.
JFrog Xray provides a free trial of 14 days.
The basic scanning capabilities come with Artifactory, however, curation requires additional licenses.
 

Valuable Features

Black Duck excels in vulnerability scanning, license management, and policy management, offering strong UI and seamless Docker integration.
JFrog Xray offers deep scanning, seamless integration with Artifactory, robust vulnerabilities management, flexible deployment, and attractive pricing.
The most valuable feature of Black Duck is the composition analysis feature, which is effective for security risk management.
Black Duck's ability to identify dependencies very accurately has been most valuable in identifying and mitigating risks.
The software composition analysis is most effective for security risk management.
The most valuable features of JFrog Xray are its curation capabilities, its native integration with Artifactory, scanning for vulnerabilities, and license compliance features.
With other registries such as ECR, we can use the images only in the AWS cloud. With JFrog, we can use this registry from any cloud or work locally as well.
 

Categories and Ranking

Black Duck
Ranking in Software Composition Analysis (SCA)
1st
Average Rating
7.6
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
No ranking in other categories
JFrog Xray
Ranking in Software Composition Analysis (SCA)
6th
Average Rating
7.8
Reviews Sentiment
6.4
Number of Reviews
9
Ranking in other categories
Vulnerability Management (32nd), Container Security (19th), Software Supply Chain Security (2nd)
 

Mindshare comparison

As of August 2025, in the Software Composition Analysis (SCA) category, the mindshare of Black Duck is 17.8%, down from 22.5% compared to the previous year. The mindshare of JFrog Xray is 10.3%, up from 8.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Composition Analysis (SCA) Market Share Distribution
ProductMarket Share (%)
Black Duck17.8%
JFrog Xray10.3%
Other71.9%
Software Composition Analysis (SCA)
 

Featured Reviews

Aaron  P - PeerSpot reviewer
A tool with a great UI to conduct a vulnerability scan that needs to provide better scalability options
The only thing I don't like about the product is that it is quite expensive and it is not very feasible as an open-source platform. One of the other things that I hate about the product stems from my dislike of contacting the support team of Black Duck to know if there are some issues since debugging some issues can be quite difficult. I don't find reliable or feasible documents to help me debug all those issues. The solution's pricing model and documentation areas of concern where improvement is needed. In our company, we get some issues or errors when we run a pipeline, and debugging those errors can be tedious and time-consuming. To minimize the time for debugging errors, I feel that Black Duck needs to add some documentation or something that will make it easy for users to debug the errors instead of seeking help from Black Duck's support team every time. Black Duck can add features, like viewing the vulnerability, to help users figure out the next step if they detect some vulnerability while also providing them some steps to help them follow some remedial steps, along with an explanation of measures to mitigate such issues. Black Duck's UI or server doesn't provide functionality to help users view the vulnerability, which is a process that needs to be automated. The solution's scalability is an area that needs to improve.
Anand Nanwana - PeerSpot reviewer
Offers flexibility across clouds and easy credential management while interface improvements are needed
For JFrog Xray, the Artifactory and package repositories are valuable features. There are many benefits from JFrog Xray. For example, with other registries such as ECR, we can use the images only in the AWS cloud. With JFrog, we can use this registry from any cloud or work locally as well. JFrog can support multiple packages, such as NuGet package, pip, and other technologies. It can be used for Terraform as well. The credential management is very easy in JFrog. For instance, when using GitHub action as a CI/CD tool, I just need to create a token and set up JFrog CLI there and give access to the repository. With multiple repositories, I can generate a token for a specific repository, add that token in the GitHub secret, fetch from the CI/CD, run the command JFrog CLI, and authenticate through the token. Then we can push the images into JFrog.
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
866,088 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Manufacturing Company
15%
Computer Software Company
13%
Insurance Company
5%
Financial Services Firm
25%
Manufacturing Company
12%
Computer Software Company
11%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Large Enterprise16
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise2
Large Enterprise6
 

Questions from the Community

How does WhiteSource compare with Black Duck?
We researched Black Duck but ultimately chose WhiteSource when looking for an application security tool. WhiteSource is a software solution that enables agile open source security and license compl...
What do you like most about Black Duck?
The cloud option of the product is always available and a positive aspect of the solution.
What is your experience regarding pricing and costs for Black Duck?
The price charged by Black Duck is exorbitant. For the features provided by the product, I would not want to pay a high price. There are many other products in the market that offer better features...
What do you like most about JFrog Xray?
JFrog Xray shows us a list of vulnerabilities that can impact our code.
What needs improvement with JFrog Xray?
X-ray needs improvement in supporting more than one database, as it currently only supports PostgreSQL. More support during troubleshooting sessions would also be beneficial.
What is your primary use case for JFrog Xray?
Our primary use case for X-ray includes multiple activities such as security and vulnerability scanning. We already use Black Duck for these purposes, and we are evaluating how JFrog Xray can offer...
 

Comparisons

 

Also Known As

Blackduck Hub, Black Duck Protex, Black Duck Security Checker
JFrog Security Essentials
 

Overview

 

Sample Customers

Samsung, Siemens, ScienceLogic, BryterCX, Dynatrace
google, amazon, cisco, netflix, oracle, vmware, facebook
Find out what your peers are saying about Black Duck vs. JFrog Xray and other solutions. Updated: July 2025.
866,088 professionals have used our research since 2012.