Mend.io AppSec Platform logo

    Mend.io AppSec Platform

    Sold by
    Mend.io offers the first AI Native AppSec Platform, purpose-built to help organizations secure AI-generated code, embedded AI components, and traditional application elements, so they can move beyond chasing vulnerabilities and start proactively reducing real application risk.

    Ratings and reviews

    4.4
    128 ratings
    64%
    31%
    4%
    0%
    1%
    4 AWS reviews
    |
    124 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (128)
    Internet

    Robust AppSec Platform with Automated Dependency Scanning and CI/CD Integration

    Reviewed on Aug 16, 2026
    Review provided by G2
    What do you like best about the product?
    It offers a robust application security platform that helps development teams identify and manage open-source vulnerabilities, license risks, and other security issues directly within the software development lifecycle. With automated dependency scanning, clear vulnerability prioritization, and smooth integration into CI/CD pipelines, it becomes easier to address risks promptly without slowing down development.
    What do you dislike about the product?
    The platform can generate a high volume of findings on projects with extensive dependencies, so teams may need to invest time in tuning policies and prioritizing remediation work. Some of the more advanced configuration options also come with a learning curve, and having more granular customization for vulnerability reports would make it easier to tailor security insights for different teams.
    What problems is the product solving and how is that benefiting you?
    This helps development and security teams identify open-source vulnerabilities and license-compliance risks before they reach production. By automating dependency scanning and integrating security checks into CI/CD workflows, it cuts down on manual security reviews, speeds up remediation, strengthens software supply-chain security, and helps developers catch and address vulnerabilities earlier in the development process.
    Review E.

    Easy-to-Use Helpful Security Tool for Finding and Fixing VulnerabilitiesSecurity Scanning

    Reviewed on Aug 14, 2026
    Review provided by G2
    What do you like best about the product?
    Mend.io is easy to use, helps me find security issues quickly, and makes it simpler to fix vulnerabilities. My favorite features are the automated fixes and the clear, easy-to-understand reports..
    What do you dislike about the product?
    The main things I dislike about Mend.io are that it can sometimes generate too many alerts, it takes time to learn, and some of the more advanced features can be expensive.
    What problems is the product solving and how is that benefiting you?
    Mend.io helps identify security vulnerabilities and outdated software dependencies before they become bigger problems. It saves me time by prioritizing issues and making it easier to fix them quickly.
    LOKESH G.

    Easy Dependency Vulnerability Management That Keeps Our Codebase Secure

    Reviewed on Aug 09, 2026
    Review provided by G2
    What do you like best about the product?
    What I like about Mend.io is that it makes it easy to find and manage security vulnerabilities in dependencies, helping keep the codebase secure without adding too much extra work.
    What do you dislike about the product?
    The main thing I dislike is that it can sometimes generate a lot of alerts, and it takes time to go through them and prioritize which issues actually need attention.
    What problems is the product solving and how is that benefiting you?
    Mend.io helps me spot vulnerabilities and outdated dependencies across my projects. By automating security checks, it saves me time and lowers the chance that security issues make it into production.
    Atharva S.

    Comprehensive AppSec Platform with Fast Scans and Clear Remediation Guidance

    Reviewed on Aug 04, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Mend.io is its comprehensive approach to application security, particularly its ability to identify open-source vulnerabilities, license compliance issues, and supply chain risks in a single platform. The interface is intuitive, scans are fast, and the detailed remediation guidance makes it much easier to prioritize and resolve security issues. I also appreciate its seamless integrations with CI/CD pipelines, version control systems, and developer workflows, allowing security to be incorporated early in the development lifecycle. Overall, Mend.io helps strengthen software security while reducing the effort required to manage vulnerabilities and compliance.
    What do you dislike about the product?
    One area where Mend.io could improve is offering more granular reporting customization and deeper analytics for large-scale security programs. While the platform is feature-rich and reliable, the volume of vulnerability data can sometimes feel overwhelming without additional filtering or prioritization options. I'd also like to see broader integrations with more developer tools, enhanced dashboard customization, and richer onboarding resources for advanced capabilities. Overall, the experience has been very positive, but improved reporting flexibility, expanded integrations, and enhanced usability would make Mend.io even more effective for enterprise security teams.
    What problems is the product solving and how is that benefiting you?
    Mend.io solves the challenge of securing modern software by continuously identifying open-source vulnerabilities, license compliance risks, and software supply chain issues throughout the development lifecycle. Instead of relying on manual security reviews or multiple disconnected tools, it provides centralized vulnerability management, automated scanning, and actionable remediation guidance that integrates directly into development workflows. This helps detect risks earlier, reduces the time required to address security issues, improves compliance, and enables teams to release software with greater confidence. As a result, it has strengthened application security, streamlined vulnerability management, and reduced operational overhead for development and security teams.
    Varun K.

    Seamless Pipeline Integration with Fast, Actionable Vulnerability Fixes

    Reviewed on Aug 04, 2026
    Review provided by G2
    What do you like best about the product?
    What stands out most about Mend.io is how seamlessly it integrates into the development pipeline without disrupting existing workflows. The fast feedback loop enables developers to respond rapidly to any vulnerability or license issues ,catching problems early rather than at the end of the release cycle. The open-source dependency management with CVE detection, detailed vulnerability and license reports, and fix suggestions make it genuinely useful day-to-day, not just a compliance checkbox. The automated remediation saves hours of manual triage.
    What do you dislike about the product?
    The initial setup and configuration can be overwhelming, especially for teams new to SCA tooling. The sheer volume of vulnerability alerts early on can lead to alert fatigue ,without proper policy tuning, developers tend to ignore notifications rather than act on them. The dashboard, while feature-rich, has a steep learning curve and could benefit from a more intuitive onboarding experience. Pricing is also a concern, as SaaS and on-prem software costs continue to rise, the per-developer pricing model can become expensive at scale , making it harder to justify for smaller teams or budget-conscious organizations.
    What problems is the product solving and how is that benefiting you?
    One of the core problems Mend.io solves is the lack of visibility into open-source dependencies and the security risks they introduce. Before using a tool like Mend.io, identifying vulnerable libraries across multiple applications was a largely manual, time-consuming process. Mend.io identifies, prioritises, and remediates security and license risks in open-source components automatically which means our team spends less time hunting for vulnerabilities and more time building. The CI/CD integration ensures that security checks happen continuously rather than as a last-minute gate before release, shifting security left in the development lifecycle. This has directly reduced the time it takes to detect and respond to newly disclosed CVEs, which previously could go unnoticed for weeks.
    Ratna P.

    Mend.io Makes Vulnerability Scanning and Prioritization Easy

    Reviewed on Jul 30, 2026
    Review provided by G2
    What do you like best about the product?
    I like Mend.io mainly because it can scan for vulnerabilities. I used it mostly as a test case: I created a test project, ran a vulnerability scan, and then used the dashboard, which listed everything across multiple repositories. That view makes it easier to prioritize what to fix first.

    I also like the support it gives developers by providing visibility into threats when it comes to open source. Onboarding and integrating it with third-party applications is also quite easy. In one of my test cases, when I was working as a developer, it initially took me a lot of time to identify vulnerabilities, but after using Mend.io it became less time-consuming.

    Also, when it comes to compliance, it helps there too by license compliance and prevents manual work.
    What do you dislike about the product?
    Let’s first talk about the UI. The initial setup for the policy takes some time, and it would be easier with an onboarding guide to improve the user experience.

    On performance, the dashboard has a lot of information, which may feel overwhelming for an engineer.

    The pricing also seemed a bit high to me, and it may be challenging for a smaller startup.

    When it comes to reporting, it could be customized further to be more useful.
    What problems is the product solving and how is that benefiting you?
    Now the world is changing for the better with AI. With Mend.io, I think the process becomes more efficient and reduces manual work. As I mentioned, I created a test environment and it was able to identify vulnerabilities that might otherwise take a lot of time to find.

    In a production scenario, when it comes to vulnerabilities, it can take a long time to detect them and then mitigate them. With Mend.io, there is a comprehensive report that is useful for maintaining compliance as well, and it reduces a lot of manual work while being less time-consuming overall.

    This is helping improve the security posture of the organisation.
    Vern H.

    Fast GitHub Scanning and Helpful Automation, but UI and False Positives Need Work

    Reviewed on Jul 30, 2026
    Review provided by G2
    What do you like best about the product?
    Easy setup: It integrates quickly with GitHub and fits smoothly into CI/CD workflows. Effective scanning: It rapidly tracks open-source dependencies and helps with license compliance. Helpful automation: The Renovate feature supports automated dependency updates. Good support: Customer service is often described as fast and helpful.
    What do you dislike about the product?
    Interface: Parts of the UI clunky or a bit outdated. False Positives: It can generate noise, which then requires extra manual triage. Pricing: It’s sometimes considered a little high for smaller teams or mid-market buyers. Integrations: Third-party tool connections, like Jira, can occasionally bug out.
    What problems is the product solving and how is that benefiting you?
    Used to resolve issues with SCA
    Computer Software

    Accurate Prioritization, Intuitive UI, and Phenomenal Support

    Reviewed on Jul 29, 2026
    Review provided by G2
    What do you like best about the product?
    Its accurate prioritization and ability to cut through security noise are really impressive. The user interface is intuitive, even for a new user. It also provides options to integrate Mend Renovate, which is a great option. Finally the support is phenomenal.
    What do you dislike about the product?
    Performance-wise, it could be better, with less lag during processes. Another issue is the lack of online documentation, which causes users to spend a lot of time resolving an issue or to reach out to support for small queries.
    What problems is the product solving and how is that benefiting you?
    It helps address software supply chain risk, reduces developer alert fatigue, and lowers compliance overhead. It saves a lot of developer time across the organization thanks to its accurate identification of vulnerabilities and its active approach to fixing those vulnerabilities. It also helps eliminate legal and compliance headaches.
    Mohit B.

    Great for Vulnerability Management

    Reviewed on Jul 29, 2026
    Review provided by G2
    What do you like best about the product?
    I like Mend.io's smart vulnerability prioritization and seamless CI/CD integration. It helps developers fix the most critical security issues faster.
    What do you dislike about the product?
    Sometimes it generates too many alerts, and initial setup and policy configuration can be a bit complex for new users.
    What problems is the product solving and how is that benefiting you?
    Mend.io helps identify and fix open-source security vulnerabilities and license risks early in the development process, improving application security while saving time and reducing manual effort."
    Ram K.

    Real-Time Security Analysis in Modern Code Editors

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    Offer real time security analysis inside modern code editors like cursor and support for governing AI components.
    What do you dislike about the product?
    Configurating policies for large enterprise codebases requires significant initial overhead
    What problems is the product solving and how is that benefiting you?
    Finds hidden security bugs in third-party software packages.Malicious Packages: Blocks open-source supply chain attacks before they enter codebases.License Non-Compliance: Identifies legal risks from restrictive open-source licenses.AI Security Risks: Secures AI applications by tracking vulnerabilities in open-source AI models and datasets.
    Saves Developer Time: Uses automated pull requests to fix code bugs automatically.Reduces Noise: Uses reachability analysis to tell developers if a bug is actually operational, eliminating up to 85% of false alerts.Accelerates Shipping: Integrates directly into repositories (like GitHub) so security happens during development, avoiding last-minute launch delays.