Mend.io AppSec Platform logo

    Mend.io AppSec Platform

    Sold by
    Mend.io offers the first AI Native AppSec Platform, purpose-built to help organizations secure AI-generated code, embedded AI components, and traditional application elements, so they can move beyond chasing vulnerabilities and start proactively reducing real application risk.

    Ratings and reviews

    4.4
    126 ratings
    64%
    31%
    4%
    0%
    1%
    4 AWS reviews
    |
    122 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (126)
    LOKESH G.

    Easy Dependency Vulnerability Management That Keeps Our Codebase Secure

    Reviewed on Aug 09, 2026
    Review provided by G2
    What do you like best about the product?
    What I like about Mend.io is that it makes it easy to find and manage security vulnerabilities in dependencies, helping keep the codebase secure without adding too much extra work.
    What do you dislike about the product?
    The main thing I dislike is that it can sometimes generate a lot of alerts, and it takes time to go through them and prioritize which issues actually need attention.
    What problems is the product solving and how is that benefiting you?
    Mend.io helps me spot vulnerabilities and outdated dependencies across my projects. By automating security checks, it saves me time and lowers the chance that security issues make it into production.
    Atharva S.

    Comprehensive AppSec Platform with Fast Scans and Clear Remediation Guidance

    Reviewed on Aug 04, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Mend.io is its comprehensive approach to application security, particularly its ability to identify open-source vulnerabilities, license compliance issues, and supply chain risks in a single platform. The interface is intuitive, scans are fast, and the detailed remediation guidance makes it much easier to prioritize and resolve security issues. I also appreciate its seamless integrations with CI/CD pipelines, version control systems, and developer workflows, allowing security to be incorporated early in the development lifecycle. Overall, Mend.io helps strengthen software security while reducing the effort required to manage vulnerabilities and compliance.
    What do you dislike about the product?
    One area where Mend.io could improve is offering more granular reporting customization and deeper analytics for large-scale security programs. While the platform is feature-rich and reliable, the volume of vulnerability data can sometimes feel overwhelming without additional filtering or prioritization options. I'd also like to see broader integrations with more developer tools, enhanced dashboard customization, and richer onboarding resources for advanced capabilities. Overall, the experience has been very positive, but improved reporting flexibility, expanded integrations, and enhanced usability would make Mend.io even more effective for enterprise security teams.
    What problems is the product solving and how is that benefiting you?
    Mend.io solves the challenge of securing modern software by continuously identifying open-source vulnerabilities, license compliance risks, and software supply chain issues throughout the development lifecycle. Instead of relying on manual security reviews or multiple disconnected tools, it provides centralized vulnerability management, automated scanning, and actionable remediation guidance that integrates directly into development workflows. This helps detect risks earlier, reduces the time required to address security issues, improves compliance, and enables teams to release software with greater confidence. As a result, it has strengthened application security, streamlined vulnerability management, and reduced operational overhead for development and security teams.
    Varun K.

    Seamless Pipeline Integration with Fast, Actionable Vulnerability Fixes

    Reviewed on Aug 04, 2026
    Review provided by G2
    What do you like best about the product?
    What stands out most about Mend.io is how seamlessly it integrates into the development pipeline without disrupting existing workflows. The fast feedback loop enables developers to respond rapidly to any vulnerability or license issues ,catching problems early rather than at the end of the release cycle. The open-source dependency management with CVE detection, detailed vulnerability and license reports, and fix suggestions make it genuinely useful day-to-day, not just a compliance checkbox. The automated remediation saves hours of manual triage.
    What do you dislike about the product?
    The initial setup and configuration can be overwhelming, especially for teams new to SCA tooling. The sheer volume of vulnerability alerts early on can lead to alert fatigue ,without proper policy tuning, developers tend to ignore notifications rather than act on them. The dashboard, while feature-rich, has a steep learning curve and could benefit from a more intuitive onboarding experience. Pricing is also a concern, as SaaS and on-prem software costs continue to rise, the per-developer pricing model can become expensive at scale , making it harder to justify for smaller teams or budget-conscious organizations.
    What problems is the product solving and how is that benefiting you?
    One of the core problems Mend.io solves is the lack of visibility into open-source dependencies and the security risks they introduce. Before using a tool like Mend.io, identifying vulnerable libraries across multiple applications was a largely manual, time-consuming process. Mend.io identifies, prioritises, and remediates security and license risks in open-source components automatically which means our team spends less time hunting for vulnerabilities and more time building. The CI/CD integration ensures that security checks happen continuously rather than as a last-minute gate before release, shifting security left in the development lifecycle. This has directly reduced the time it takes to detect and respond to newly disclosed CVEs, which previously could go unnoticed for weeks.
    Ratna P.

    Mend.io Makes Vulnerability Scanning and Prioritization Easy

    Reviewed on Jul 30, 2026
    Review provided by G2
    What do you like best about the product?
    I like Mend.io mainly because it can scan for vulnerabilities. I used it mostly as a test case: I created a test project, ran a vulnerability scan, and then used the dashboard, which listed everything across multiple repositories. That view makes it easier to prioritize what to fix first.

    I also like the support it gives developers by providing visibility into threats when it comes to open source. Onboarding and integrating it with third-party applications is also quite easy. In one of my test cases, when I was working as a developer, it initially took me a lot of time to identify vulnerabilities, but after using Mend.io it became less time-consuming.

    Also, when it comes to compliance, it helps there too by license compliance and prevents manual work.
    What do you dislike about the product?
    Let’s first talk about the UI. The initial setup for the policy takes some time, and it would be easier with an onboarding guide to improve the user experience.

    On performance, the dashboard has a lot of information, which may feel overwhelming for an engineer.

    The pricing also seemed a bit high to me, and it may be challenging for a smaller startup.

    When it comes to reporting, it could be customized further to be more useful.
    What problems is the product solving and how is that benefiting you?
    Now the world is changing for the better with AI. With Mend.io, I think the process becomes more efficient and reduces manual work. As I mentioned, I created a test environment and it was able to identify vulnerabilities that might otherwise take a lot of time to find.

    In a production scenario, when it comes to vulnerabilities, it can take a long time to detect them and then mitigate them. With Mend.io, there is a comprehensive report that is useful for maintaining compliance as well, and it reduces a lot of manual work while being less time-consuming overall.

    This is helping improve the security posture of the organisation.
    Vern H.

    Fast GitHub Scanning and Helpful Automation, but UI and False Positives Need Work

    Reviewed on Jul 30, 2026
    Review provided by G2
    What do you like best about the product?
    Easy setup: It integrates quickly with GitHub and fits smoothly into CI/CD workflows. Effective scanning: It rapidly tracks open-source dependencies and helps with license compliance. Helpful automation: The Renovate feature supports automated dependency updates. Good support: Customer service is often described as fast and helpful.
    What do you dislike about the product?
    Interface: Parts of the UI clunky or a bit outdated. False Positives: It can generate noise, which then requires extra manual triage. Pricing: It’s sometimes considered a little high for smaller teams or mid-market buyers. Integrations: Third-party tool connections, like Jira, can occasionally bug out.
    What problems is the product solving and how is that benefiting you?
    Used to resolve issues with SCA
    Computer Software

    Accurate Prioritization, Intuitive UI, and Phenomenal Support

    Reviewed on Jul 29, 2026
    Review provided by G2
    What do you like best about the product?
    Its accurate prioritization and ability to cut through security noise are really impressive. The user interface is intuitive, even for a new user. It also provides options to integrate Mend Renovate, which is a great option. Finally the support is phenomenal.
    What do you dislike about the product?
    Performance-wise, it could be better, with less lag during processes. Another issue is the lack of online documentation, which causes users to spend a lot of time resolving an issue or to reach out to support for small queries.
    What problems is the product solving and how is that benefiting you?
    It helps address software supply chain risk, reduces developer alert fatigue, and lowers compliance overhead. It saves a lot of developer time across the organization thanks to its accurate identification of vulnerabilities and its active approach to fixing those vulnerabilities. It also helps eliminate legal and compliance headaches.
    Mohit B.

    Great for Vulnerability Management

    Reviewed on Jul 29, 2026
    Review provided by G2
    What do you like best about the product?
    I like Mend.io's smart vulnerability prioritization and seamless CI/CD integration. It helps developers fix the most critical security issues faster.
    What do you dislike about the product?
    Sometimes it generates too many alerts, and initial setup and policy configuration can be a bit complex for new users.
    What problems is the product solving and how is that benefiting you?
    Mend.io helps identify and fix open-source security vulnerabilities and license risks early in the development process, improving application security while saving time and reducing manual effort."
    Ram K.

    Real-Time Security Analysis in Modern Code Editors

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    Offer real time security analysis inside modern code editors like cursor and support for governing AI components.
    What do you dislike about the product?
    Configurating policies for large enterprise codebases requires significant initial overhead
    What problems is the product solving and how is that benefiting you?
    Finds hidden security bugs in third-party software packages.Malicious Packages: Blocks open-source supply chain attacks before they enter codebases.License Non-Compliance: Identifies legal risks from restrictive open-source licenses.AI Security Risks: Secures AI applications by tracking vulnerabilities in open-source AI models and datasets.
    Saves Developer Time: Uses automated pull requests to fix code bugs automatically.Reduces Noise: Uses reachability analysis to tell developers if a bug is actually operational, eliminating up to 85% of false alerts.Accelerates Shipping: Integrates directly into repositories (like GitHub) so security happens during development, avoiding last-minute launch delays.
    reviewer2196063

    Automation in our pipelines has improved supply chain security and reduces open source risk

    Reviewed on Jul 27, 2026
    Review from a verified AWS customer

    What is our primary use case?

    We are using Mend.io for open-source component scanning mainly, all third-party open-source components. This is especially for the software composition analysis. We do have a large number of supply chain-related vulnerabilities from the AppSec aspect. Using Mend.io, we scan all the dependency risk, and then we are able to understand the outdated packages. We are able to get the CVEs with respect to the open-source components. According to that, we will apply updating the packages to the latest patch. Then we clear all the dependency checks and identify all the libraries to which component is communicating to which component, whether we have a direct dependency or a transitive dependency. Then we update the software bill of materials for the vulnerability. The main purpose of using Mend.io is for the software supply chain security to identify and remediate the vulnerabilities which come across the open-source software components, especially dependency checks.

    In my opinion, it is the best because with respect to the scan coverage. It is giving basically all the components whatever we are looking for and all the requirements we basically required. Comparatively to other tools, especially in terms of identifying and integrating into our DevSecOps primarily into our security, Mend.io is compatible with respect to integrating with our CI/CD, and then using that, we will be able to detect and fix the vulnerabilities. The coverage of integration is good across all the technologies it is supporting. In terms of noise ratio, comparatively it is less and gives a good, accurate number of issues. There are some gaps with respect to giving an exact vulnerability. However, we were doing some tuning of the tool with respect to helping to understand basically what we are expecting to scan, then what could be the output. In that aspect, the tool also has the option to tune the tool, and we can customize what our requirement is, and based on that, we can pull the scan. That is good.

    We were able to integrate with our CI/CD pipelines. That is totally automated with respect to scan as well as updating the remediation.

    At this moment, I would say Mend.io is working based on our requirements. But in future, if we start exploring more and moving towards the AI side, AI technologies, and then obviously the threats based on the vulnerabilities, the vulnerabilities which we identified in the past and the same vulnerability or CVE is repeating in the future, then how the data is analyzed by the tool and how it is giving the threat intelligence reports. That is more towards the AI apps. Obviously we need to look for that because at this moment we are not using for that purpose. But we need to explore that analytics part, how much it is capable of in terms of having the correct data and how much the capability the tool has so that it can give the threat intelligence reports, looking at the previous past data to get the results driven for the future requirements. We need to explore that. At this moment, without experimenting, I could not say whether this tool will be good or bad, but I am hoping this could support the analytics as well.

    What is most valuable?

    The key benefit of Mend.io is that we were able to automate and integrate this tool into our CI/CD, and we can scan. Basically, it can reduce the cybersecurity risk by identifying the risk and then fixing the vulnerable open-source components before they get exploited. We can integrate them into our CI/CD, and we can identify and fix the issues. It improves the compliance with respect to not only the component but also we can look at the license management aspect, policy enforcement aspect, then updating the bill of materials, generating the SBOM, and making sure that the vulnerability information is stored and that can give a future aspect of detecting early and giving the good results. Obviously, it can reduce our cost by lowering the remediation cost by finding and fixing the issue during the early stage of our SDLC. During the development life cycle itself, we can integrate these into pipelines as part of our DevSecOps integration. It will have a capability to support all the integrations within our DevSecOps. That will give us faster results and the ability to quickly find out the vulnerabilities and then fix them so that way we can reduce the cost. Proactively, we can pick up the vulnerabilities and then fix them rather than moving to the later stage of the software development life cycle.

    With respect to the end-user perspective, we can directly integrate these into, for example, IDEs or maybe Git repositories and then CI/CD pipelines. We can automate all the dependencies. We can identify the issue and fix it, so that obviously reduces the manual effort. Based on the severity which it is giving, we can prioritize the exploitability of the vulnerability. We can understand the risk context. It will help us to focus on what matters most. That way, basically, both from the end-user perspective and as well as the business perspective, leveraging this tool definitely helps us to identify the vulnerability at the early stage of the software development life cycle and also be able to get it fixed. All the ways of development aspect as well as the business aspect, it is helping us as a tool to proactively manage vulnerability management very effectively to minimize the risk from the software supply chain.

    What needs improvement?

    With respect to improvements with Mend.io, as I mentioned, today it is not supporting the threat intelligence. Most of the time, basically, we are embracing the vulnerability and the software supply chain. But if we can have a more stronger threat intelligence integration, for example, more real-time exploit intelligence or maybe more attack campaign correlation, that would help us better understand how we can leverage this tool. This would help our teams to better understand the vulnerabilities being actively exploited in the wild. That intelligence if we can build up in Mend.io, we can accommodate it.

    With respect to scoring, while leveraging Mend.io and we are scanning and doing all the exploitability analysis, the improvements would be how whether that given score is really meaningful, if it is flagging as a critical or high, whether that is really a meaningful severity, or do we need based on the asset criticality scoring to understand. And what is the business impact scoring? Those things basically, we need to feed the data so that we can prioritize. It is more important to understand how much priority I need to give to fix the issue. That prioritization we need to develop.

    Then enhancing cloud-native security. For example, especially in the Kubernetes environment, we do have a large number of even open-source packages. In a container environment also, in a broader coverage model, how we can leverage the different type of scanners in the modern cloud environment. Leveraging Mend.io, how basically we can integrate this enhanced capabilities to integrate with the cloud-native security. That and all basically we need to build up into the tool.

    The last but not least is AI security capabilities. Since organizations are increasingly adopting the AI, how Mend.io could help us further. For example, AI model security assessment, maybe LLM risk-related analysis, how it can, AI supply chain security. How we can leverage this tool and what kind of the aspects and the features Mend.io has, building a deeper AI security capabilities, so that should align with my business requirements. That aspect basically we need to improve the tool.

    Then obviously reducing false positives. Obviously we need to see real defects instead of giving a large number of noise where actually my effectiveness and efficiency will get hampered. We need to improve more and more to reduce the false positive and give real threats. These and all basically we need to have some improvements on Mend.io.

    For how long have I used the solution?

    I am working with Mend.io for four years now.

    What do I think about the stability of the solution?

    It is not complex. I could say it is user-friendly.

    What do I think about the scalability of the solution?

    We have both cloud as well as on-prem.

    How are customer service and support?

    I would rate it as a ten. We always used to get the right support.

    How was the initial setup?

    Of course.

    What about the implementation team?

    To be honest, I don't know how much pricing actually my organization is spending leveraging the tool, but what I got to know compared to other tools, this is good.

    What was our ROI?

    I would rate it as nine.

    What other advice do I have?

    In terms of threat intelligence, at this moment, whatever the bill of materials we are giving, based on that, actually, with respect to enrichment, for example, looking at the CVE database and looking at the National Vulnerability Database, then some CVSS related information, that way basically it is giving us some vulnerabilities. But with respect to more on threat intelligence perspective, we also need to understand, it is important to understand that Mend.io is not a dedicated threat intelligence platform. If you look at the Microsoft Defender, maybe CrowdStrike intelligence or some other tools, maybe those are actually really threat intelligence platforms. Whereas Mend.io is not a really threat intelligence platform. But instead, we need to see how we can consume the vulnerability intelligence to improve our software supply chain security based on our decision so that we can leverage the tool. To conclude, the strengths of Mend.io that can give the threat intelligence, especially looking at the CVE database, looking at the National Vulnerability Database, then EPSS, for example, Exploit Prediction Scoring System, CVSS scoring system. Based on these, actually it is giving us the threats and as well as giving us the report. But really, we cannot completely say it is purely, at this moment we do have a threat intelligence capabilities, but we need to explore more on that aspect. I would rate this review as a ten overall.

    Dave M.

    Easy-to-Use Open-Source Library Reviews with Handy Renovate Feature

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    Ease of use. Because it reviews open-source libraries at the source code management platform level (like GitHub), we’re able to identify and mitigate issues more effectively. The “Renovate” feature is also a handy tool when it comes to resolution.
    What do you dislike about the product?
    As of now, I do not have much to dislike.
    What problems is the product solving and how is that benefiting you?
    Mend produces SBOMs, which is important for meeting our compliance requirements. In addition, its connection with our SCM (GitHub) lets remediation happen directly in the UI where our software engineers spend most of their time. We’re also working on bringing in IDE-level integration.