Veracode and Mend.io compete in the application security testing market. Mend.io appears to have an edge in open-source security management and pricing flexibility.
Features: Veracode distinguishes itself with comprehensive static and dynamic application security testing and ease of integration across various software development lifecycles. It provides detailed vulnerability management insights and robust support for multiple programming languages. Mend.io, on the other hand, shines with robust support for open-source security and flexibility in analyzing third-party components. It offers detailed licensing reports and excels in integration capabilities across CI/CD frameworks.
Room for Improvement: For Veracode, improving user interface complexity, reducing false positives, and expanding language support could enhance user experience. There's also a need for faster scanning speeds for larger applications. Mend.io could benefit from a more responsive user interface and added support for niche package managers. Enhancing automation to reduce manual intervention in remediation processes would also be beneficial.
Ease of Deployment and Customer Service: Veracode offers diverse deployment models, including public and private cloud options and on-premises solutions. Its technical support is rated highly for depth of knowledge and prompt resolutions. Mend.io, primarily cloud-based, integrates smoothly within developer workflows and is vouched for good customer service, despite occasional support response delays.
Pricing and ROI: Veracode is noted for its higher cost, which is justified by its extensive features and security assurance benefits. It provides substantial ROI through reduced vulnerabilities and operational efficiencies. Mend.io offers competitive pricing and flexible licensing, catering to both startups and enterprises. It is valued for its open-source management focus, ensuring a favorable return on investment.
Mend.io has provided a good return on investment by significantly reducing vulnerabilities.
The scanners of Veracode bring status of the weaknesses in the current infrastructure. It scans and provides reports regarding the servers, the network, and the applications running on those servers.
They prioritize providing the best experience to large organizations like ours, belonging to the Fortune 100.
The responsiveness and quality of documentation from Veracode are notable compared to other tools we are currently using.
They are very responsive and quick to help with queries within our scope.
They respond very quickly since security is something critical.
It has a good capacity to scale effectively.
Cloud solutions are easier to scale than on-premise solutions.
AI integration in code security tools like Mend.io is still in its early stages and relatively immature.
If the Veracode server is down, we experience many issues during the scan.
The organization decided to consolidate tools and chose Snyk since it provides multiple functionalities in one solution.
If it could be integrated directly with code repositories such as Bitbucket or GitHub, without the need to create a pipeline to upload and decode code, it would simplify the code scan process significantly.
We had issues with scanning large applications. Scanning took a lot of time, so we kept it outside the DevOps pipeline to avoid delaying deployments.
Veracode can improve the licensing model as it is a bit confusing.
The cost of Mend.io is competitive, being quite low compared to others.
It's not the most expensive solution.
If there's a security gap, you'll never know the cost or effect.
Pricing-wise, I find it a bit expensive because it's based on the number of users requesting access to Veracode.
We find it 100% accurate in detecting vulnerabilities.
The best features in Veracode include static analysis and the early detection of vulnerable libraries; it integrates with tools such as Jenkins.
It offers confidence by preventing exposure to vulnerabilities and helps ensure that we are not deploying vulnerable code into production.
If there are any security flaws or vulnerabilities identified, they are able to provide sufficient justification or details about the security flaws.
Mend.io is a software composition analysis tool that secures what developers create. The solution provides an automated reduction of the software attack surface, reduces developer burdens, and accelerates app delivery. Mend.io provides open-source analysis with its in-house and other multiple sources of software vulnerabilities. In addition, the solution offers license and policy violation alerts, has great pipeline integration, and, since it is a SaaS (software as a service), it doesn’t require you to physically maintain servers or data centers for any implementation. Not only does Mend.io reduce enterprise application security risk, it also helps developers meet deadlines faster.
Mend.io Features
Mend.io has many valuable key features. Some of the most useful ones include:
Mend.io Benefits
There are many benefits to implementing Mend.io. Some of the biggest advantages the solution offers include:
Reviews from Real Users
Below are some reviews and helpful feedback written by PeerSpot users currently using the Mend.io solution.
Jeffrey H., System Manager of Cloud Engineering at Common Spirit, says, “Finding vulnerabilities is pretty easy. Mend.io (formerly WhiteSource) does a great job of that and we had quite a few when we first put this in place. Mend.io does a very good job of finding the open-source, checking the versions, and making sure they're secure. They notify us of critical high, medium, and low impacts, and if anything is wrong. We find the product very easy to use and we use it as a core part of our strategy for scanning product code moving toward release.”
PeerSpot reviewer Ben D., Head of Software Engineering at a legal firm, mentions, “The way WhiteSource scans the code is great. It’s easy to identify and remediate open source vulnerabilities using this solution. WhiteSource helped reduce our mean time to resolution since we adopted the product. In terms of integration, it's pretty easy.”
An IT Service Manager at a wholesaler/distributor comments, “Mend.io provides threat detection and an excellent UI in a highly stable solution, with outstanding technical support.”
Another reviewer, Kevin D., Intramural OfficialIntramural at Northeastern University, states, "The vulnerability analysis is the best aspect of the solution."
Veracode is a leading provider of application security solutions, offering tools to identify, mitigate, and prevent vulnerabilities across the software development lifecycle. Its cloud-based platform integrates security into DevOps workflows, helping organizations ensure that their code remains secure and compliant with industry standards.
Veracode supports multiple application security testing types, including static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), and manual penetration testing. These tools are designed to help developers detect vulnerabilities early in development while maintaining speed in deployment. Veracode also emphasizes scalability, offering features for enterprises that manage a large number of applications across different teams. Its robust reporting and analytics capabilities allow organizations to continuously monitor their security posture and track progress toward remediation.
What are the key features of Veracode?
What benefits should users consider in Veracode reviews?
Veracode is widely adopted in industries like finance, healthcare, and government, where compliance and security are critical. It helps these organizations maintain strict security standards while enabling rapid development through its integration with Agile and DevOps methodologies.
Veracode helps businesses secure their applications efficiently, ensuring they can deliver safe and compliant software at scale.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.