No more typing reviews! Try our Samantha, our new voice AI agent.

Sonatype Nexus Repository vs Sonatype Repository Firewall comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Sonatype Nexus Repository
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
18
Ranking in other categories
Software Distribution (2nd), Repository Managers (1st)
Sonatype Repository Firewall
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
4
Ranking in other categories
Application Security Tools (27th), Software Composition Analysis (SCA) (15th), AI Software Development (138th)
 

Featured Reviews

Daniele Palumbo - PeerSpot reviewer
Enterprise System Architect at Value Transformation Services
Granular access and geo-disaster recovery have simplified managing internal repositories
Sonatype Nexus Repository's repository function is definitely the most valuable feature I have found. I did not test it extensively versus other options, but I can tell you that Sonatype Nexus Repository works in a stable manner. It allows us to have geographical disaster recovery, which was one feature that we needed. We are using Sonatype Nexus Repository's granular access controls, and we needed to use them because we have several teams. Therefore, it is essential for us, and it is one of the features that we are using by design.
JK
CEO at VIVANS
Accurate database support blocks malicious code with excellent support
Many companies, including ours, use Nexus Repository due to concerns about malware and critical vulnerabilities. There should be a specific method to prevent malicious packages from entering the internal network, so our company uses Nexus Repository. We usually consider adding the firewall feature…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Sonatype Nexus Repository has a valuable internal scanner feature."
"In comparison to solutions like JFrog, Nexus provides ease of use."
"If there are any issues in build security, it can pick them up straight away."
"I have found managing the artifact features very useful."
"The key benefit we get from it is speed to delivery. It has improved our overall time to get new applications out with new code. That's true whether from a platform perspective, where we are quickly deploying up-to-date docker containers, or whether we are looking to deploy new code out to deliver a new application."
"On the hosted repository, if a team inserts a version of a library, say a Spring library, it becomes available across the organization, which helps the speed of development and improves productivity."
"The customer service and support are good ."
"The key benefit we get from it is speed to delivery, as it has improved our overall time to get new applications out with new code, whether from a platform perspective, where we are quickly deploying up-to-date Docker containers, or when we are looking to deploy new code to deliver a new application."
"The customer service is fantastic."
"The product's network and intrusion protection features are valuable. It also has rules and compliance features for security."
"Another thing that I like about Sonatype is that if you download something today, and five days from today it becomes vulnerable, it will notify you."
"Nexus Firewall has also significantly improved the time it takes us to release secure apps to market."
"You will get clean code every time, and that's a great achievement."
"The firewall is the only solution that supports Nexus Repository."
 

Cons

"We had some issues with the container platform, but we raised a support ticket and it was sorted out for us."
"They could improve the user interface and REST APIs. I found that JFrog has multiple features as compared to Nexus Artifactory."
"They should provide automation for adding container images and artifacts in compliance with security requirements."
"Lacks an end-to-end solution for developers to sign and store an image."
"The only thing that I would like to see is multifactor authentication. This is a critical feature that must be included."
"We had some issues with the container platform, but we raised a support ticket and it was sorted out for us."
"One of our main concerns would be about plugging Nexus IQ into JIRA to be able to automatically raise issues whenever we have a policy violation in a scan."
"We feel that if the product could be configured more easily through configuration files, instead of API calls and databases, that would make it easier to integrate with other DevOps tools."
"The tool needs to improve its file systems. The product should also include zero test feature."
"What I don't like is the lack of an option to pick up the phone and call someone for support."
"There are several features lacking in the current offering, particularly concerning container support and AI packages."
"What I don't like is the lack of an option to pick up the phone and call someone for support. That is something they need to improve on. They need to have a professional services package, or they need to include that option with their services."
"I think we posted one or two queries on the development side, but the response was not that great."
"There are several features lacking in the current offering, particularly concerning container support and AI packages, like humming phase support."
 

Pricing and Cost Advice

"In my opinion, the pricing is very fair and very customer-oriented. It's much better than any other tool I have used so far."
"It's quite expensive. They are charging around $110 or $120 per user, per year. It's quite expensive in comparison to the other tools available in the market."
"Nexus Repository Manager Pro is quite affordable because it's about €100, per user, per year. Purchasing licenses was not really a big issue for us. Regarding Nexus IQ, it's much more expensive. We purchased 250 licenses and they cost us about €120,000."
"I use the open-source version of the product, which is free of cost."
"It seems like a fair price, based on other software solutions I've purchased."
"The cost is managed by the client."
"There were costs in addition to the standard licensing fees. The standard is free."
"One of the challenges we had around licensing was how to deal with anonymous requests. According to the letter of the contract, an anonymous request consumes a license. We had to do some work to get over the fact that any anonymous interactions with the Repository product had to be put back to an end-user account."
"The pricing is reasonable if you're a large enterprise developing code. It's not super-expensive."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
889,855 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
14%
Manufacturing Company
9%
Government
7%
Financial Services Firm
18%
Construction Company
9%
Insurance Company
9%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise3
Large Enterprise10
No data available
 

Questions from the Community

What needs improvement with Sonatype Nexus Repository?
I think what can be eventually improved is to introduce as a standard the additional security features that Sonatype Nexus Repository offers, which are basically plugins for the repository itself.
What is your primary use case for Sonatype Nexus Repository?
We use Sonatype Nexus Repository for our internal repository, for image caching, registry caching, and our custom registry. Sonatype Nexus Repository's repository function is definitely the most va...
What is your experience regarding pricing and costs for Sonatype Nexus Firewall?
Also, I consider it average. Some people might consider it expensive, however, since it supports many beautiful features, I would say it is worth it.
What is your primary use case for Sonatype Nexus Firewall?
Many companies, including ours, use Nexus Repository due to concerns about malware and critical vulnerabilities. There should be a specific method to prevent malicious packages from entering the in...
What advice do you have for others considering Sonatype Nexus Firewall?
I would give the solution eight out of ten. I would look at the comparison of Sonatype to some other firewalls. There is room for improvement, especially mentioning container support and AI packages.
 

Also Known As

Nexus Repository, Nexus Repository Manager
Sonatype Nexus Firewall, Nexus Firewall
 

Overview

 

Sample Customers

Goldman Sachs, Toyota, Disney, Deutsche Bank
EDF, Tomitribe, Crosskey, Blackboard, Travel audience
Find out what your peers are saying about SonarSource Sàrl, Veracode, Checkmarx and others in Application Security Tools. Updated: April 2026.
889,855 professionals have used our research since 2012.