Checkmarx Software Composition Analysis vs JFrog Xray comparison

Cancel
You must select at least 2 products to compare!
Checkmarx Logo
1,672 views|1,257 comparisons
100% willing to recommend
JFrog Logo
5,811 views|4,307 comparisons
100% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Checkmarx Software Composition Analysis and JFrog Xray based on real PeerSpot user reviews.

Find out in this report how the two Software Composition Analysis (SCA) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
To learn more, read our detailed Checkmarx Software Composition Analysis vs. JFrog Xray Report (Updated: March 2024).
767,847 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"What's most valuable in Checkmarx Software Composition Analysis is its ability to identify vulnerabilities in open-source components, especially if some critical issues exist.""The tool's visual scan analysis shows me all the libraries' vulnerabilities and license types. It helps identify the most complex issues with licenses. It provides good visibility. SCA shows me all libraries that are vulnerable and the extent of their vulnerability.""It is a stable solution...It is a scalable solution.""The product is stable and scalable.""One of the strong points of this solution is that it allows you to incorporate it into a CICB pipeline. It has the ability to do incremental scans. If you scan a very large application, it might take two hours to do the initial scan. The subsequent scans, as people are making changes to the app, scan the Delta and are very fast. That's a really nice implementation. The way they have incorporated the functionality of the incremental scans is something to be aware of. It is quite good. It has been very solid. We haven't really had any issues, and it does what it advertises to do very nicely.""What's most valuable in Checkmarx Software Composition Analysis is that it provides security from the start. In the traditional approach, an enterprise or company validates the solution before launching to a production environment, but in the modern approach, security must be checked and provided from the beginning and from the design, and this is where Checkmarx Software Composition Analysis comes in. The solution helps you make sure that every open-source application that you use is secure, and that there's no vulnerability inside that open-source application.""The most valuable feature of Checkmarx Software Composition Analysis is the comprehensive security scan.""I appreciate the user-friendly interface. The GUI is excellent, providing detailed information on outdated versions, including version numbers and the flow of library calls. This allows me to plan and prioritize library changes based on potential vulnerabilities, even if the affected library is indirectly used in my project. The tool offers specific guidance on addressing these issues."

More Checkmarx Software Composition Analysis Pros →

"JFrog Xray's reporting feature has a lot of options in it, including scanning.""I would say that this solution has helped our organization by allowing us to automate a lot of the processes.""The solution is stable and reliable.""Good reporting functionalities.""If multiple dependencies and vulnerabilities are found in a project, JFrog Xray is intelligent enough to tell you which vulnerability to target first.""JFrog Xray shows us a list of vulnerabilities that can impact our code.""The most valuable feature of JFrog Xray is the display of the entire internal dependencies hierarchy."

More JFrog Xray Pros →

Cons
"I have received complaints from my customers that the pricing could be improved.""The quality of technical support has decreased over time, and it is not as good as it used to be.""Some of the recommendations provided by the product are generic. Even if the recommendations provided by the product are of low level, the appropriate ones can help users deal with vulnerabilities.""I would rate the scalability a seven out of ten.""Checkmarx Software Composition Analysis should improve dynamic analysis.""Instant updates for end users to identify vulnerabilities as soon as possible will make Checkmarx Software Composition Analysis better. The UI of the solution could also be improved.""It can have better licensing models.""API security is an area with shortcomings that needs improvement."

More Checkmarx Software Composition Analysis Cons →

"Reporting is crucial, but it is lacking in the current tool. Every organization seeks specific data points rather than general information. Therefore, we require customized reports from the Xray tool.""Lacks deeper reporting, the ability to compare things.""JFrog Xray does not have a dashboard.""JFrog Xray's documentation and error logging could be improved.""I think that the user interface should be expanded to provide customers with a better dashboard for reviewing their feedback regarding their images and the vulnerabilities that are associated with the images.""Since we have been using the solution via APIs, there are some limitations in the APIs.""The speed of JFrog Xray should improve. Other solutions have better performance."

More JFrog Xray Cons →

Pricing and Cost Advice
  • "It is a little bit high priced. It would be better if it was a little less expensive."
  • "Pricing for Checkmarx Software Composition Analysis needs to be competitive."
  • "The license model is somewhat perplexing as it comprises multiple aspects that can be confusing for customers. The model is determined by the number of registered users and the number of projects being scanned, along with a third component that adds to the complexity."
  • "My customers need to pay for the licensing part, and they need to opt for an annual subscription."
  • "We don't have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage."
  • More Checkmarx Software Composition Analysis Pricing and Cost Advice →

    Information Not Available
    report
    Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
    767,847 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:It is a stable solution...It is a scalable solution.
    Top Answer:We have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage.
    Top Answer:The DAST component of the tool requires some improvements. The tool's DAST component is not much required in the integration processes with the CI/CD pipelines. IDE plugins to scan codes should be… more »
    Top Answer:JFrog Xray shows us a list of vulnerabilities that can impact our code.
    Top Answer:There is a tool called DefectDojo for reporting. Reporting is crucial, but it is lacking in the current tool. Every organization seeks specific data points rather than general information. Therefore… more »
    Top Answer:We use this solution to identify vulnerabilities in the dependency file. We have the Artifactory package which integrates with Xray-like plugins. We can automatically plug this tool into Xray to… more »
    Ranking
    Views
    1,672
    Comparisons
    1,257
    Reviews
    8
    Average Words per Review
    485
    Rating
    9.0
    Views
    5,811
    Comparisons
    4,307
    Reviews
    6
    Average Words per Review
    495
    Rating
    8.2
    Comparisons
    Also Known As
    CxSCA
    JFrog Security Essentials
    Learn More
    Overview

    Today's software is constructed using open source components and third-party libraries, tied together with custom code. Hackers target vulnerable open source components to access sensitive and valuable data, while data protection regulations become more stringent in an effort to encourage better software security practices. While all this is happening, DevOps is taking the world by storm and the burden of securing software is rapidly expanding under the purview of the developers who create it.

    Trust us, we get it. You're caught between a strong desire to innovate and a sincere dislike of having your company’s name on the news as “the most recent data breach.”

    That's why we made CxSCA, the most effective next-gen software composition analysis solution designed to help development teams ship secure software quickly while giving AppSec teams the insight and control they need to improve your software security risk posture.

    JFrog is on a mission to enable continuous updates through Liquid Software, empowering developers to code high-quality applications that securely flow to end-users with zero downtime. The world’s top brands such as Amazon, Facebook, Google, Netflix, Uber, VMware, and Spotify are among the 4500 companies that already depend on JFrog to manage binaries for their mission-critical applications. JFrog is a privately-held, global company, and is a proud sponsor of the Cloud Native Computing Foundation [CNCF].

    If you are a team player and you care and you play to WIN, we have just the job you're looking for.

    As we say at JFrog: "Once You Leap Forward You Won't Go Back!"​

    Sample Customers
    AXA, Liveperson, Aaron's, Playtech, Morningstar
    google, amazon, cisco, netflix, oracle, vmware, facebook
    Top Industries
    REVIEWERS
    Energy/Utilities Company22%
    Manufacturing Company22%
    Outsourcing Company11%
    Financial Services Firm11%
    VISITORS READING REVIEWS
    Financial Services Firm37%
    Manufacturing Company12%
    Computer Software Company12%
    Healthcare Company4%
    VISITORS READING REVIEWS
    Financial Services Firm23%
    Manufacturing Company14%
    Computer Software Company13%
    Insurance Company5%
    Company Size
    REVIEWERS
    Small Business57%
    Large Enterprise43%
    VISITORS READING REVIEWS
    Small Business13%
    Midsize Enterprise8%
    Large Enterprise79%
    REVIEWERS
    Midsize Enterprise29%
    Large Enterprise71%
    VISITORS READING REVIEWS
    Small Business14%
    Midsize Enterprise11%
    Large Enterprise75%
    Buyer's Guide
    Checkmarx Software Composition Analysis vs. JFrog Xray
    March 2024
    Find out what your peers are saying about Checkmarx Software Composition Analysis vs. JFrog Xray and other solutions. Updated: March 2024.
    767,847 professionals have used our research since 2012.

    Checkmarx Software Composition Analysis is ranked 8th in Software Composition Analysis (SCA) with 12 reviews while JFrog Xray is ranked 7th in Software Composition Analysis (SCA) with 7 reviews. Checkmarx Software Composition Analysis is rated 9.2, while JFrog Xray is rated 8.2. The top reviewer of Checkmarx Software Composition Analysis writes "Comprehensive security scan, helpful support, and high availability". On the other hand, the top reviewer of JFrog Xray writes "An intelligent solution that prioritizes which vulnerability to target first in your project". Checkmarx Software Composition Analysis is most compared with Black Duck, Semgrep Supply Chain, Fortify Static Code Analyzer, Snyk and FOSSA, whereas JFrog Xray is most compared with Black Duck, Snyk, Veracode, Mend.io and Sonatype Lifecycle. See our Checkmarx Software Composition Analysis vs. JFrog Xray report.

    See our list of best Software Composition Analysis (SCA) vendors.

    We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.