Mend.io is a software composition analysis tool that secures what developers create. The solution provides an automated reduction of the software attack surface, reduces developer burdens, and accelerates app delivery. Mend.io provides open-source analysis with its in-house and other multiple sources of software vulnerabilities. In addition, the solution offers license and policy violation alerts, has great pipeline integration, and, since it is a SaaS (software as a service), it doesn’t require you to physically maintain servers or data centers for any implementation. Not only does Mend.io reduce enterprise application security risk, it also helps developers meet deadlines faster.



| Product | Market Share (%) | 
|---|---|
| Mend.io | 7.3% | 
| Black Duck SCA | 15.7% | 
| Snyk | 13.2% | 
| Other | 63.8% | 
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| SonarQube Server (formerly SonarQube) | 4.0 | N/A | 81% | 117 interviewsAdd to research | 
| Snyk | 4.0 | 13.2% | 100% | 49 interviewsAdd to research | 
| Company Size | Count | 
|---|---|
| Small Business | 10 | 
| Midsize Enterprise | 3 | 
| Large Enterprise | 17 | 
| Company Size | Count | 
|---|---|
| Small Business | 392 | 
| Midsize Enterprise | 260 | 
| Large Enterprise | 1323 | 
Mend.io Features
Mend.io has many valuable key features. Some of the most useful ones include:
Mend.io Benefits
There are many benefits to implementing Mend.io. Some of the biggest advantages the solution offers include:
Reviews from Real Users
Below are some reviews and helpful feedback written by PeerSpot users currently using the Mend.io solution.
Jeffrey H., System Manager of Cloud Engineering at Common Spirit, says, “Finding vulnerabilities is pretty easy. Mend.io (formerly WhiteSource) does a great job of that and we had quite a few when we first put this in place. Mend.io does a very good job of finding the open-source, checking the versions, and making sure they're secure. They notify us of critical high, medium, and low impacts, and if anything is wrong. We find the product very easy to use and we use it as a core part of our strategy for scanning product code moving toward release.”
PeerSpot reviewer Ben D., Head of Software Engineering at a legal firm, mentions, “The way WhiteSource scans the code is great. It’s easy to identify and remediate open source vulnerabilities using this solution. WhiteSource helped reduce our mean time to resolution since we adopted the product. In terms of integration, it's pretty easy.”
An IT Service Manager at a wholesaler/distributor comments, “Mend.io provides threat detection and an excellent UI in a highly stable solution, with outstanding technical support.”
Another reviewer, Kevin D., Intramural OfficialIntramural at Northeastern University, states, "The vulnerability analysis is the best aspect of the solution."
Mend.io was previously known as WhiteSource, Mend SCA, Mend.io Supply Chain Defender, Mend SAST.
Microsoft, Autodesk, NCR, Target, IBM, vodafone, Siemens, GE digital, KPMG, LivePerson, Jack Henry and Associates
| Author info | Rating | Review Summary | 
|---|---|---|
| CEO at a computer software company with 10,001+ employees | 4.5 | We use Mend.io with our CI/CD tools like Concourse and Jenkins for managing dependencies and detecting vulnerabilities across multiple languages. While the tool is low-cost and effective, we considered consolidating tools with Snyk for broader functionality. | 
| Principal Architect at a consultancy with 11-50 employees | 4.5 | I work with Mend.io in industries like retail and hospitality. It's a security tool offering feedback on tests and supports Application Security, SCA, SAST, and container scanning. The main challenge is cost and integration in early software development stages. | 
| Product Security Architect at Pitney Bowes Inc. | 5.0 | I use Mend.io to identify open-source library vulnerabilities and licensing issues. Its notification feature for critical vulnerabilities is valuable. I'd like a compliance pack for frameworks like CIS or NIST. The ROI is evident in enhanced security. | 
| Release Manager at a tech vendor with 501-1,000 employees | 4.5 | We use Mend.io to efficiently detect and fix vulnerabilities in our products, benefiting from its ease of setup and numerous integrations. Improvements are needed in reporting features and UI, but overall, it provides significant time and resource savings. | 
| Principal Security Engineer at Texthelp Ltd. | 4.0 | Mend is a seamless SaaS solution for managing open-source libraries and vulnerabilities, integrating well with our developer tools like Visual Studio and Azure. While effective, improvements could include preconfigured policies and a cleaner dashboard. It offers reliable security with no breaches. | 
| Sr. Manager at a financial services firm with 10,001+ employees | 4.0 | No summary available | 
| System Manager of Cloud Engineering at Common Spirit | 4.5 | No summary available | 
| Intramural OfficialIntramural at Northeastern University | 4.5 | No summary available |