No more typing reviews! Try our Samantha, our new voice AI agent.

CAST Application Intelligence Platform vs Mend.io comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CAST Application Intelligen...
Average Rating
7.0
Reviews Sentiment
8.0
Number of Reviews
4
Ranking in other categories
Software Development Analytics (7th)
Mend.io
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
35
Ranking in other categories
Application Security Tools (10th), Software Composition Analysis (SCA) (5th), Static Code Analysis (4th), Software Supply Chain Security (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. CAST Application Intelligence Platform is designed for Software Development Analytics and holds a mindshare of 6.6%, down 10.7% compared to last year.
Mend.io, on the other hand, focuses on Software Composition Analysis (SCA), holds 4.4% mindshare, down 7.7% since last year.
Software Development Analytics Mindshare Distribution
ProductMindshare (%)
CAST Application Intelligence Platform6.6%
SonarQube33.6%
Snyk26.6%
Other33.19999999999999%
Software Development Analytics
Software Composition Analysis (SCA) Mindshare Distribution
ProductMindshare (%)
Mend.io4.4%
Snyk11.3%
Black Duck SCA9.0%
Other75.3%
Software Composition Analysis (SCA)
 

Featured Reviews

Vishal-Goyal - PeerSpot reviewer
Chief Architect at Persistent Systems
Has a security dashboard that's helpful because it gives compliance checks based on some of the leading frameworks in the industry
The overall coverage of rules could be improved in the CAST Application Intelligence Platform because it does not cater to or cover all. For example, 2022 CWE coverage is still not available in the CAST Application Intelligence Platform. The solution also covers some NIST rules, but it does not cater to all rules. An additional feature I'd like to see in the next update of the CAST Application Intelligence Platform is for it to provide source code developer and contributor details, especially information on which areas of code were touched. This would be a good insight as the CAST Application Intelligence Platform looks into the source code.
meetharoon - PeerSpot reviewer
CEO at a computer software company with 10,001+ employees
Centralized security monitoring has reduced false positives and improves dependency governance
The only area for improvement I would say is that the false positives are nearly zero; everything is mostly like 99 to 99.99% or we can say 100% accurate. There were a few areas for improvement just from the last time I saw; I think the user experience had a little problem. We wanted to have certain reports based on our kind of scenario, but the tool did not allow us to create custom reports. We had asked for some facility and some ability for us to create some custom reports. That would be awesome if they allow us to create custom reports the way we wanted. There is one small area which I don't know whether we should call a tool limitation or a wish list; if I use a library and I don't use all the capabilities of the library but only a portion of it and that portion is not vulnerable, but there is a component which is outdated, that is a problem, even though I don't use that component. Mend.io will discover there is a problem in the whole library; that is correct. That's a valid discovery, but in my case, for example, if I don't use that particular portion, then it actually is not making sense for me, but that's not a limitation of Mend.io; I think that's a general problem with any tool in the market because no tool in the market will actually know what portion of the code I'm actually using from that particular library if it is vulnerable or not.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Our clients use CAST Highlight for cloud migration. This allows them to remove or remediate the blockers which are highlighted. This part of the solution shows improvement in quality and captures feedback for our clients."
"We've seen ROI from CAST Application Intelligence Platform because we've been able to leverage it for doing multiple customer engagements and we've been able to win more business for our organization by leveraging the product."
"It supports most programming languages."
"CAST's risk and security flow detection capabilities are highly effective, particularly in identifying security vulnerabilities. It is one of the most important and valuable features of the platform."
"Used for controlling the technical debt and code quality."
"The most valuable feature of the CAST Application Intelligence Platform is its security dashboard which is a dedicated dashboard that's pretty helpful because it gives compliance checks based on some of the leading frameworks in the industry, such as ISO 5055, OWASP, CWE Top 25, and NIST security guidelines. I find the security dashboard of the solution and the information it provides pretty useful. The security dashboard of the CAST Application Intelligence Platform is a feature that stands out."
"Hourly, daily, and monthly static code analysis before making a project live, therefore controlling the technical debt and code quality."
"Mend.io is very robust in terms of managing third-party dependencies."
"Overall, Mend (formerly WhiteSource) helped dramatically reduce the number of open-source software vulnerabilities running in our production at any given point in time."
"The dashboard view and the management view are most valuable."
"With WhiteSource in place, we are going to be able to do the whole process automatically and it will be confident that we removed the vulnerabilities and license violations."
"The solution boasts a broad range of features and covers much of what an ideal SCA tool should."
"With the fix suggestions feature, not only do you get the specific trace back to where the vulnerability is within your code, but you also get fix suggestions."
"The integration with Azure DevOps was good, and the results and the dashboard they provide are good."
"WhiteSource is unique in the scanning of open-source licenses. Additionally, the vulnerabilities aspect of the solution is a benefit. We don't use WhiteSource in the whole organization, but we use it for some projects. There we receive a sense of the vulnerabilities of the open-source components, which improves our security work. The reports are automated which is useful."
 

Cons

"It has very few plugins to access different code repositories, so source code has to be fed."
"The overall coverage of rules could be improved in the CAST Application Intelligence Platform because it does not cater to or cover all."
"Areas for improvement in CAST AIP include enhancing support for implementation in complex environments and improving technical support to address organizational challenges alongside engineering issues."
"The integration of this solution could be improved."
"Implementation could be made more simpler as it is complex."
"The overall coverage of rules could be improved in the CAST Application Intelligence Platform because it does not cater to or cover all. For example, 2022 CWE coverage is still not available in the CAST Application Intelligence Platform. The solution also covers some NIST rules, but it does not cater to all rules. An additional feature I'd like to see in the next update of the CAST Application Intelligence Platform is for it to provide source code developer and contributor details, especially information on which areas of code were touched. This would be a good insight as the CAST Application Intelligence Platform looks into the source code."
"The tools need to bring down the pricing because software in SaaS or on-prem is becoming a more expensive affair."
"I rated the solution an eight out of ten because WhiteSource hasn't built in a couple of features that we would have loved to use and they say they're on their roadmap. I'm hoping that they'll be able to build and deliver in 2022."
"The agent usage was not as smooth as the online experience."
"The turnaround time for upgrading databases for this tool as well as the accuracy could be improved."
"WhiteSource is working on a UI refresh. That's probably been one of the pain points for us as it feels like a really old application."
"The dashboard UI and UX are problematic."
"Up until now, we were convinced that the return of investment was not really the case."
"WhiteSource needs improvement in the scanning of the containers and images with distinguishing the layers."
 

Pricing and Cost Advice

"I do know how the CAST Application Intelligence Platform is licensed, but I'm not able to give the cost because the price is not listed. My company works with individual vendors, so pricing is on a case-to-case basis, but the vendors give specialized pricing because of the enterprise deployment, though my team is aware of product pricing based on lines of code, based on the number of applications, etc., I'm unable to give the exact licensing costs of the CAST Application Intelligence Platform. My company doesn't have to pay extra for some features or services because all are included as part of the enterprise license. On a scale of one to five, with five being very cheap and one being very expensive, I would rate the CAST Application Intelligence Platform as three out of five."
"Its pricing model is per developer. It depends on the number of developers in the company. The license is for a minimum of 20 developers. So, even if you are a small startup with less than 10 developers, you have to buy a license for 20 developers on a yearly subscription, which makes it quite expensive for startup customers. I provide consultation to startup accelerators. They're small at the beginning, and only once they grow to 20 developers, they can afford this tool. As a result, WhiteSource is missing this target audience. Their licensing is not flexible."
"This is an expensive solution."
"WhiteSource is much more affordable than Veracode."
"Over the last two years, they have tried to add more and more features to their license packages, but the price is a little bit high, comparatively."
"When comparing the price of WhiteSource to the competition it is priced well. The cost for 50 users is approximately $18,000 annually."
"The solution involves a yearly licensing fee."
"As we were using an SaaS-based service, the solution must be scalable, although my understanding is that this is based on the licensing model one is using."
"Pricing and licensing are comparable to other tools. When we started, it was less than our existing solution. I can't go into specifics, but it isn't cheap."
report
Use our free recommendation engine to learn which Software Development Analytics solutions are best for your needs.
908,834 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Outsourcing Company
12%
Government
9%
Construction Company
9%
Financial Services Firm
14%
Manufacturing Company
12%
Computer Software Company
10%
Construction Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise22
 

Questions from the Community

Ask a question
Earn 20 points
How does WhiteSource compare with SonarQube?
Red Hat Ceph does well in simplifying storage integration by replacing the need for numerous storage solutions. This solution allows for multiple copies of replicated and coded pools to be kept, ea...
How does WhiteSource compare with Black Duck?
We researched Black Duck but ultimately chose WhiteSource when looking for an application security tool. WhiteSource is a software solution that enables agile open source security and license compl...
What is your experience regarding pricing and costs for Mend.io?
Mend.io SCA offers a competitive pricing structure that is relatively affordable compared to similar solutions in the market. This makes it an attractive option for organizations looking to enhance...
 

Also Known As

CAST AIP
WhiteSource, Mend SCA, Mend.io Supply Chain Defender, Mend SAST
 

Overview

 

Sample Customers

Steria, T-Systems MMS, Atos Origin, Accenture, Capgemini
Microsoft, Autodesk, NCR, Target, IBM, vodafone, Siemens, GE digital, KPMG, LivePerson, Jack Henry and Associates
Find out what your peers are saying about SonarSource Sàrl, Snyk, Allstacks and others in Software Development Analytics. Updated: July 2026.
908,834 professionals have used our research since 2012.