Our primary use case is for artifact storage, a repository, and image management. We also utilize JFROG X-ray for vulnerability scans.
Lead Vulnerability Analyst/ DevSec Ops Specialist at a government with 201-500 employees
Solid watch policies; blocks vulnerabilities well
Pros and Cons
- "I would say that this solution has helped our organization by allowing us to automate a lot of the processes."
- "I think that the user interface should be expanded to provide customers with a better dashboard for reviewing their feedback regarding their images and the vulnerabilities that are associated with the images."
What is our primary use case?
How has it helped my organization?
I would say that this solution has helped our organization by allowing us to automate a lot of the processes.
What is most valuable?
The features I found most valuable are the watch policies and the ability to block vulnerabilities from getting into our environment.
What needs improvement?
I think that the user interface should be expanded to provide customers with a better dashboard for reviewing their feedback regarding their images and the vulnerabilities that are associated with the images. There should be a better user experience for customers. Also, site performance sometimes is really slow and this causes issues with automation.
Buyer's Guide
JFrog Xray
October 2025

Learn what your peers think about JFrog Xray. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,469 professionals have used our research since 2012.
For how long have I used the solution?
I have been using this solution for a bit over one year.
What do I think about the stability of the solution?
I would rate the stability of this solution a seven, on a scale from one to 10, with one being the worst and 10 being the best.
What do I think about the scalability of the solution?
I would say that automating the configuration when it comes to the watch policies or data itself is definitely scalable, but when it comes to performance, the solution is maybe not as scalable.
How was the initial setup?
The initial setup process depends largely on the experience of the person doing the implementation. In our case, it was straightforward as the API docs are well outlined and they provide good documentation.
What other advice do I have?
Regarding other people looking into this solution, I would definitely recommend this product.
Overall, I would rate this solution an eight, on a scale from one to 10, with one being the worst and 10 being the best.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

DevOps Engineer Intern at University of Nebraska at Omaha
Stable, scalable and offers great reporting functionalities
Pros and Cons
- "Good reporting functionalities."
- "Lacks deeper reporting, the ability to compare things."
What is our primary use case?
I'm using this solution for scanning artifacts related to the Jfrog Artifactory. I'm scanning them, checking licenses and things like that. I'm a DevOps engineer intern and we are customers of JFrog.
What is most valuable?
I would say the reporting functionalities are pretty good as are the policy watches. I like them a lot.
What needs improvement?
I'd like to see deeper reporting, they're pretty basic and there are no categories for comparing things. I'd also like to see an improvement with the documentation, there's not much available on their website.
For how long have I used the solution?
I've been using this solution for a couple of months.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How was the initial setup?
I wasn't involved in the setup but I heard from my team that they faced some issues although I don't know what they were. We had a great consultant working with us and they solved the problems.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free JFrog Xray Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2025
Product Categories
Vulnerability Management Container Security Software Composition Analysis (SCA) Software Supply Chain SecurityPopular Comparisons
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
GitLab
SentinelOne Singularity Cloud Security
Checkmarx One
Veracode
Qualys VMDR
Tenable Nessus
Tanium
Black Duck SCA
CrowdStrike Falcon Cloud Security
Mend.io
Tenable Vulnerability Management
Buyer's Guide
Download our free JFrog Xray Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?
- What are your recommended automated penetration testing tools?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- Can you recommend API for Tenable Connector into ServiceNow
- What penetration testing tool (or tools) do you recommend for SMB/SME?