No more typing reviews! Try our Samantha, our new voice AI agent.

JFrog Xray vs Software Risk Manager ASPM comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 22, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

JFrog Xray
Ranking in Software Composition Analysis (SCA)
7th
Average Rating
7.8
Reviews Sentiment
6.3
Number of Reviews
10
Ranking in other categories
Vulnerability Management (48th), Container Security (18th), Software Supply Chain Security (3rd)
Software Risk Manager ASPM
Ranking in Software Composition Analysis (SCA)
23rd
Average Rating
0.0
Reviews Sentiment
7.0
Number of Reviews
1
Ranking in other categories
Static Application Security Testing (SAST) (30th), Application Security Posture Management (ASPM) (17th)
 

Mindshare comparison

As of September 2026, in the Software Composition Analysis (SCA) category, the mindshare of JFrog Xray is 5.2%, down from 9.8% compared to the previous year. The mindshare of Software Risk Manager ASPM is 1.9%, up from 0.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Composition Analysis (SCA) Mindshare Distribution
ProductMindshare (%)
JFrog Xray5.2%
Software Risk Manager ASPM1.9%
Other92.9%
Software Composition Analysis (SCA)
 

Featured Reviews

reviewer2757060 - PeerSpot reviewer
DevSecOps Engineer at a tech services company with 501-1,000 employees
Has supported compliance and threat detection but suffers from poor user experience and CI integration
I would assess the integration of JFrog Xray with CI/CD tools as the weak point. You have two means to do that: one is using the API, or the other is using the command line from JFrog. That part is a bit of a sensitive topic because somehow you need to adapt your GitLab pipeline and turn them into JFrog pipeline, and this is something they don't really advertise at first—you're obliged to use the JFrog CLI. Apart from this integration aspect, JFrog Xray does the job, but the user experience is not very good. The documentation is really poor. It's not the design; it's not user-friendly at all. You can't find the items in the menus. I think the UI needs improvement. It's not user-friendly, but it works very effectively. Regarding the metrics and dashboards in JFrog Xray, the dashboard is fine, but it's about how you share that dashboard—you need extra permission. You can say each project can have its own dashboard and is responsible for the mistakes or the level of security they want, or you can have a person dedicated to security. At the moment, it's more a permission issue—how you set the permission properly, how do you give access to the dashboard or delegate. This needs improvement.
Saravanan_Radhakrishnan - PeerSpot reviewer
Senior Manager at Happiest Minds Technologies
Facilitates continuous assessment of applications, covering both static and dynamic security aspects
Code Dx lacks one aspect, the dynamic security part, known as DAST. It's not an on-premise solution; it's in the cloud now. There are compliance standards and data standards where the customer might need to have the data on-premises for dynamic security testing. So that is one shortfall. An area of improvement could be developing an on-premise DAST solution. The current one is a complete cloud-based solution, and that can be one of the areas of improvement.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I would say that this solution has helped our organization by allowing us to automate a lot of the processes."
"JFrog Xray shows us a list of vulnerabilities that can impact our code."
"With JFrog, we can use this registry from any cloud or work locally as well, and it can support multiple packages such as NuGet, pip, and other technologies including Terraform, making credential management very easy."
"I am utilizing the deep scanning capabilities in JFrog Xray product, and this feature is very handy because with other software, you don't know where the bad dependencies come from."
"I would say the reporting functionalities are pretty good as are the policy watches."
"The most valuable feature of JFrog Xray is the display of the entire internal dependencies hierarchy."
"The most valuable features of JFrog Xray are its curation capabilities, its native integration with Artifactory, scanning for vulnerabilities, and license compliance features."
"Good reporting functionalities."
"The customers were looking for something around static security and dynamic security, and in all those areas, they were looking for an industry leader with a proven solution. Synopsys is a Gartner leader, so I position this particular technology for the technical pre-sales part of it."
 

Cons

"Apart from this integration aspect, JFrog Xray does the job, but the user experience is not very good."
"Lacks deeper reporting, the ability to compare things."
"I think that the user interface should be expanded to provide customers with a better dashboard for reviewing their feedback regarding their images and the vulnerabilities that are associated with the images."
"JFrog Xray does not have a dashboard."
"X-ray needs improvement in supporting more than one database, as it currently only supports PostgreSQL."
"The out-of-the-box PostgreSQL provided is not stable, which is why we are considering enterprise support."
"Reporting is crucial, but it is lacking in the current tool. Every organization seeks specific data points rather than general information. Therefore, we require customized reports from the Xray tool."
"The speed of JFrog Xray should improve. Other solutions have better performance."
"The initial setup is a bit challenging because things are not easy. It needs a lot of technology adaptability plus the customer's environment-specific use cases."
 

Pricing and Cost Advice

Information not available
"It is more of an enterprise solution for budget-conscious customers. So, it's moderately priced. It's not for everybody."
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
913,349 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
25%
Manufacturing Company
11%
Computer Software Company
6%
University
5%
Manufacturing Company
14%
Financial Services Firm
13%
Comms Service Provider
11%
Construction Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise3
Large Enterprise6
No data available
 

Questions from the Community

What needs improvement with JFrog Xray?
I would assess the integration of JFrog Xray with CI/CD tools as the weak point. You have two means to do that: one is using the API, or the other is using the command line from JFrog. That part is...
What is your primary use case for JFrog Xray?
For JFrog Xray product, you can use it for two main goals: compliance and security. You can use it to check if your licenses are compliant, and you can check if your dependencies you want to use ar...
What is your experience regarding pricing and costs for JFrog Xray?
It is affordable because JFrog Xray provides a free trial of 14 days. We can explore all the features of JFrog in the free trial. The pricing is reasonable because we can manage all the images in a...
Ask a question
Earn 20 points
 

Also Known As

JFrog Security Essentials
Code Dx
 

Overview

 

Sample Customers

google, amazon, cisco, netflix, oracle, vmware, facebook
Discover why companies like: CGI said, "Synopsys and Software Risk Manager have provided the results we’re looking for".
Find out what your peers are saying about Snyk, Veracode, Black Duck and others in Software Composition Analysis (SCA). Updated: September 2026.
913,349 professionals have used our research since 2012.