Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Claimed
Claimed

Top Rated Endor Labs Alternatives

Endor Labs Reviews & Product Details

Endor Labs Overview

What is Endor Labs?

Endor Labs secures everything your code depends on throughout the SDLC. Start by creating a more efficient and effective dependency management program with consolidated reachability-based SCA, SAST, container scanning, artifact signing, and CI/CD security. Reduce security tool noise by 90% by focusing on the risks that matter, when they matter the most. Accelerate remediation by understanding upgrade impacts and pushing out backported security patches when risk of upgrading is too high. Achieve compliance with global standards including CIS, NIST, SSDF, FedRamp, PCI DSS v4, SLSA, NIST, SOC2, and more. Code— Help your developers select “good” OSS & AI models, and fix effectively Build— Prevent “bad” OSS, vulnerable container images, and leaked secrets from entering production Deploy— Harden your pipelines against supply chain attacks Run— Trace CNAPP alerts to the source repo and release artifact to accelerate remediation

Endor Labs Details
Languages Supported
English
Show LessShow More
Product Description

Endor Labs gives DevSecOps teams the context they need to prioritize open source risk, secure CI/CD pipelines, and meet compliance objectives like SBOMs.


Seller Details
Year Founded
2021
HQ Location
Palo Alto, California
Twitter
@EndorLabs
339 Twitter followers
LinkedIn® Page
www.linkedin.com
64 employees on LinkedIn®

Ron H.
RH
Overview Provided by:

Recent Endor Labs Reviews

James K.
JK
James K.Mid-Market (51-1000 emp.)
5.0 out of 5
"Jellyfish Enables Data-Driven AppSec with Endor Labs"
Endor Labs is, in a good way, simplistic. The data we care about is quickly available to us. Our prior SCA tooling reachability analysis wasn't ro...
João P.
JP
João P.Mid-Market (51-1000 emp.)
5.0 out of 5
"The best reachability analysis I've tested, with an intuitive yet powerful UI"
The way SCA is performed on projects is the best I've seen from all products I've tested. Function-level reachability for many languages/technologi...
Young Jin K.
YK
Young Jin K.Mid-Market (51-1000 emp.)
5.0 out of 5
"Endor Labs is an industry leader in the SCA space"
Endor Labs has revolutionized our approach to managing our OSS dependency & securitization of our software supply chain. SCA solution goes beyond t...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

Endor Labs Media

Answer a few questions to help the Endor Labs community
Have you used Endor Labs before?
Yes

5 Endor Labs Reviews

4.9 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
5 Endor Labs Reviews
4.9 out of 5
5 Endor Labs Reviews
4.9 out of 5

Endor Labs Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons
G2 reviews are authentic and verified.
James K.
JK
Head of Security and Privacy
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Endor Labs?

Endor Labs is, in a good way, simplistic. The data we care about is quickly available to us. Our prior SCA tooling reachability analysis wasn't robust and we couldn't determine which vulnerabilities could truly threaten our business, so we couldn't manually research reachability or perform upgrades without knowing if they mattered. Our risk models were overly aggressive to compensate, which has now been dramatically improved by using Endor Labs. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

Endor Labs is a new entrant into the SCA space, and has only been around for a short period of time (2022). There is always a risk of engaging with a critical vendor that you depend on for Security and Compliance, when they are a relatively new business.

We are happy with all of their current features. Review collected by and hosted on G2.com.

What problems is Endor Labs solving and how is that benefiting you?

Software Composition and reachability analysis. Our prior tooling had limitations in reachability, which Endor has solved for. Review collected by and hosted on G2.com.

Alex O.
AO
DevSecOps Engineer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Endor Labs?

Endor Labs is scrappy company that has left me with the impression that they will do what it takes to see their customers succeed. For software composition and reachabiity analysis, it was difficult to find a competing product in the current market that is as fully featured as their platform. They place a big emphasis on methodology (and have SMEs that write about this) and are also capable of performing reachability analysis on transitive dependencies, which was a big selling point for us.

Implementation and ease of integration were also a big selling point. All the basics are there - a CLI tool, an optional Github application, and a well-maintained github action with all the features of the CLI tool. Members of the team, outside of customer support, were ready and able to help whenever we ran into issues in one of our many Java / Maven repositories. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

UI/UX could use some fine tuning. For example, users authenticating via a custom IdP sometimes show up as have an "unknown provider" in the access control tab, despite it being clear that they are sourced from the IdP. It would also be nice to be able to set a default monitored branch from the console (this is currently only possible via a CLI flag). Review collected by and hosted on G2.com.

What problems is Endor Labs solving and how is that benefiting you?

Endor Labs is our go-to platform for software composition and reachability analysis. They are able to perform reachability analysis on transitive dependencies - a big selling point. Review collected by and hosted on G2.com.

Young Jin K.
YK
DevSecOps Lead
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about Endor Labs?

Endor Labs has revolutionized our approach to managing our OSS dependency & securitization of our software supply chain. SCA solution goes beyond traditional vulnerability scanning, offering deep reachbility that has dramatically reduced not only our risk exposure but developer productivity while addressing such issues.

Really loved how they do the same with all the verticals. They are expanding to including container scanning where they link vulnerability found in container level back to source code and OSS scan results.

In a few years we have used Endor we have found them to be rapid in reflecting our needs and continually syncing to deliver on our requests throughout the Journey. Customer sympathy is truly a factor to highlight when we think of Endor Labs as a partner. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

It would be great if Endor Labs continue to expand their vertical all the way to runtime analysis of containers to truly make it an end to end software lifecycle vulnerability/security platform. Review collected by and hosted on G2.com.

What problems is Endor Labs solving and how is that benefiting you?

Streamlining security and vulnerability management in software supply chain while optimizing not only the accuracy but time to value via deep reachability/tracing analysis.

Ultimately translates to substantial cost and quicker safe delivery of our service. Review collected by and hosted on G2.com.

João P.
JP
Application Security Engineer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about Endor Labs?

The way SCA is performed on projects is the best I've seen from all products I've tested. Function-level reachability for many languages/technologies differentiates it from most, if not all, competitors. The UI easily shows me the findings on all projects, with detailed information on location, call-stack, impact, CVEs...

It also lets us, from the UI, fine-tune policies on when to warn/block/ignore builds on findings. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

The only downside I've come across is setting up Endor Labs for a project could be easier. It's not hard, but some errors or problems could have a more explicit message on how to solve (e.g. some project's dependencies failed to be analysed), but given the large amount of supported technologies, it's understandable. Review collected by and hosted on G2.com.

What problems is Endor Labs solving and how is that benefiting you?

Lack of Software Composition Analysis - using Endor Lab's reachability analysis, we can prioritize the findings to be fixed. Review collected by and hosted on G2.com.

Verified User in Telecommunications
UT
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Endor Labs?

Endor Labs has a very sophisticated engine for function reachability. I would say it is unparallel in the industry as of right now. Review collected by and hosted on G2.com.

What do you dislike about Endor Labs?

The UI/UX experience needs some work. However, it has been getting better in the last two years. I have used this product. Also, it needs better Jira integration. Again, this is something they're actively working on. Review collected by and hosted on G2.com.

What problems is Endor Labs solving and how is that benefiting you?

Endor Labs is helping us prioritize mission critical third-party library vulnerabilities. It is allowing us to target those vulnerabilities we can remediate quickly and then move into vulnerabilities that will take much longer to remediate. Review collected by and hosted on G2.com.