JFrog Xray vs Legit Security comparison

Cancel
You must select at least 2 products to compare!
JFrog Logo
1,041 views|784 comparisons
100% willing to recommend
Legit Security Logo
324 views|161 comparisons
100% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between JFrog Xray and Legit Security based on real PeerSpot user reviews.

Find out in this report how the two Software Supply Chain Security solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
To learn more, read our detailed JFrog Xray vs. Legit Security Report (Updated: March 2024).
770,616 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The solution is stable and reliable.""I would say that this solution has helped our organization by allowing us to automate a lot of the processes.""Good reporting functionalities.""JFrog Xray shows us a list of vulnerabilities that can impact our code.""JFrog Xray's reporting feature has a lot of options in it, including scanning.""The most valuable feature of JFrog Xray is the display of the entire internal dependencies hierarchy.""If multiple dependencies and vulnerabilities are found in a project, JFrog Xray is intelligent enough to tell you which vulnerability to target first."

More JFrog Xray Pros →

"Legit has increased my security posture to a level I couldn't achieve before. I don't need to worry as much about what's happening within my developer environments. I can rest assured that my vulnerabilities are being detected.""Legit has had a positive effect on our overall security posture.""We implemented Legit Security to gain visibility into all development teams and ensure that consistent controls are in place and accounted for on every route.""The true value proposition of Legit lies not in its features but in its ability to support our product security program's focus on creating guardrails instead of toll gates."

More Legit Security Pros →

Cons
"JFrog Xray's documentation and error logging could be improved.""The speed of JFrog Xray should improve. Other solutions have better performance.""JFrog Xray does not have a dashboard.""Reporting is crucial, but it is lacking in the current tool. Every organization seeks specific data points rather than general information. Therefore, we require customized reports from the Xray tool.""Lacks deeper reporting, the ability to compare things.""Since we have been using the solution via APIs, there are some limitations in the APIs.""I think that the user interface should be expanded to provide customers with a better dashboard for reviewing their feedback regarding their images and the vulnerabilities that are associated with the images."

More JFrog Xray Cons →

"The one we're working on right now is the ability to dynamically rerun development teams and groups.""One issue is that engineering teams don't always embed secrets in the same way, making it difficult for the tool to consistently identify them.""Legit Security could do a little better with detecting publicly exposed keys. It's not bad. The detections that they are running get to everything eventually, but it would be great if they could increase some of that awareness.""I would like them to have their own static code scanner, and I'd like them to have their own open-source software scanners."

More Legit Security Cons →

Pricing and Cost Advice
Information Not Available
report
Use our free recommendation engine to learn which Software Supply Chain Security solutions are best for your needs.
770,616 professionals have used our research since 2012.
Questions from the Community
Top Answer:JFrog Xray shows us a list of vulnerabilities that can impact our code.
Top Answer:There is a tool called DefectDojo for reporting. Reporting is crucial, but it is lacking in the current tool. Every organization seeks specific data points rather than general information. Therefore… more »
Top Answer:We use this solution to identify vulnerabilities in the dependency file. We have the Artifactory package which integrates with Xray-like plugins. We can automatically plug this tool into Xray to… more »
Top Answer:The true value proposition of Legit lies not in its features but in its ability to support our product security program's focus on creating guardrails instead of toll gates.
Top Answer:Legit Security's secret detection works. However, there are some limitations to its effectiveness. One issue is that engineering teams don't always embed secrets in the same way, making it difficult… more »
Ranking
Views
1,041
Comparisons
784
Reviews
6
Average Words per Review
495
Rating
8.2
Views
324
Comparisons
161
Reviews
4
Average Words per Review
1,416
Rating
10.0
Comparisons
Black Duck logo
Compared 29% of the time.
Snyk logo
Compared 10% of the time.
Mend.io logo
Compared 8% of the time.
Veracode logo
Compared 8% of the time.
Trivy logo
Compared 6% of the time.
Snyk logo
Compared 42% of the time.
Ox Security logo
Compared 25% of the time.
Cycode logo
Compared 15% of the time.
Docker logo
Compared 9% of the time.
Cider logo
Compared 9% of the time.
Also Known As
JFrog Security Essentials
Learn More
Legit Security
Video Not Available
Overview

JFrog is on a mission to enable continuous updates through Liquid Software, empowering developers to code high-quality applications that securely flow to end-users with zero downtime. The world’s top brands such as Amazon, Facebook, Google, Netflix, Uber, VMware, and Spotify are among the 4500 companies that already depend on JFrog to manage binaries for their mission-critical applications. JFrog is a privately-held, global company, and is a proud sponsor of the Cloud Native Computing Foundation [CNCF].

If you are a team player and you care and you play to WIN, we have just the job you're looking for.

As we say at JFrog: "Once You Leap Forward You Won't Go Back!"​

Legit Security provides application security posture management platform that secures application delivery from code to cloud and protects an organization's software supply chain from attack. The platform’s unified application security control plane and automated SDLC discovery and analysis capabilities provide visibility and security control over rapidly changing environments and allow security issues to be prioritized based on context and business criticality to improve security team efficiency and effectiveness.

Sample Customers
google, amazon, cisco, netflix, oracle, vmware, facebook
Google, NYSE, Kraft-Hienz, Takeda Pharmaceuticals, and many other large enterprise and Fortune 500 customers. Learn more by going to: https://www.legitsecurity.com/...
Top Industries
VISITORS READING REVIEWS
Financial Services Firm24%
Manufacturing Company14%
Computer Software Company12%
Insurance Company5%
VISITORS READING REVIEWS
Computer Software Company23%
Financial Services Firm12%
Pharma/Biotech Company12%
University10%
Company Size
REVIEWERS
Midsize Enterprise29%
Large Enterprise71%
VISITORS READING REVIEWS
Small Business14%
Midsize Enterprise10%
Large Enterprise76%
VISITORS READING REVIEWS
Small Business34%
Midsize Enterprise16%
Large Enterprise50%
Buyer's Guide
JFrog Xray vs. Legit Security
March 2024
Find out what your peers are saying about JFrog Xray vs. Legit Security and other solutions. Updated: March 2024.
770,616 professionals have used our research since 2012.

JFrog Xray is ranked 3rd in Software Supply Chain Security with 7 reviews while Legit Security is ranked 7th in Software Supply Chain Security with 4 reviews. JFrog Xray is rated 8.2, while Legit Security is rated 10.0. The top reviewer of JFrog Xray writes "An intelligent solution that prioritizes which vulnerability to target first in your project". On the other hand, the top reviewer of Legit Security writes "Correlates information based on the integrations I have, which is extremely helpful". JFrog Xray is most compared with Black Duck, Snyk, Mend.io, Veracode and Trivy, whereas Legit Security is most compared with Snyk, Ox Security, Cycode, Docker and Cider. See our JFrog Xray vs. Legit Security report.

See our list of best Software Supply Chain Security vendors.

We monitor all Software Supply Chain Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.