• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Mend
Logo of Mend

Mend

byMend.io
in
4.5
Market Presence: Software Supply Chain Security, Application Security Testing

Overview

Product Information on Mend

Updated 13th October 2025

What is Mend?

The Mend AI Native AppSec Platform is designed to address risks in software created by both human developers and AI systems. The platform unifies static application security testing (SAST), software composition analysis (SCA), container scanning, AI component security and automated AI red teaming, giving teams visibility into risks across the application attack surface. The platform secures AI-generated code, embedded AI components (models, agents, MCPs, RAG pipelines), and conversational AI, while also covering traditional application risks. Mend.io integrates with development workflows to provide real-time alerts, policy enforcement, and ongoing monitoring across the software development lifecycle. Centralized dashboards and reporting deliver visibility into vulnerabilities, risk trends, and remediation progress. AI-assisted remediation and prioritization workflows enable teams to address issues efficiently and reduce overall risk.

Mend Pricing

Mend.io uses a subscription model priced by the number of contributing developers. Customers pay a single price that covers all product capabilities, including SCA, SAST, container security, and AI security, rather than licensing each product separately. Options for standalone purchase includes Mend Renovate Enterprise, which automates dependency updates.

Overall experience with Mend

MANAGER, CUSTOMER SERVICE AND SUPPORT
30B + USD, Software
FAVORABLE

“Integration With Maven Builds Is Simple, but Large Scans May Be Slow”

5.0
Oct 21, 2025
It's very easy to integrate Mend.io into a Maven build and announce builds and consumed libraries for scanning. Findings are colour-coded, and there are easy-to-navigate vulnerability alerts. The vulnerabilities from CVE + NVD are updated every few minutes and are automatically applied to the project.
Manager, IT Security and Risk Management
10B - 30B USD, Energy and Utilities
CRITICAL

“In this era of automation, with its increased cost, Mend is not able to do justice to SCA”

3.0
Sep 20, 2023
The tool is overall good but struggles to fix "Requires Review" items which are unclassified libraries with unknown licenses. There are 1,000 of such items and require manual intervention which could take up to several days. The service was great till 2020 and then suddenly nosedived with poor Customer Success Management(CSM).

About Company

Company Description

Updated 2nd May 2024

Mend.io, previously known as WhiteSource, focusses on building high-grade Application Security (AppSec) programs which aim to mitigate risk while accelerating development. Leveraging cutting-edge automated technology, the company offers protection against threats associated with supply chains, malicious package attacks, and vulnerabilities found in both open source and custom code. Additionally, Mend.io addresses potential risks linked to open-source licenses. The firm is recognized for its record of satisfying complex, large-scale application security demands and is therefore chosen by numerous demanding development and security teams across the globe. Additionally, Mend.io administrates the automated dependency update project, Renovate.

Company Details

Updated 26th February 2025
Company type
Private
Year Founded
2011
Head office location
Boston, United States
Number of employees
201 - 500
Website
https://www.mend.io

Do You Manage Peer Insights at Mend.io?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Reviewer Insights for: Mend
Performance of Mend Across Market Features

Mend Likes & Dislikes

Like

Separation of scans by product. Neat arrangement of CVE ratings and fix recommendations.

Like

Well, the Dashboards are nice, the user interface is also good & some policy enforcement features are nice. If we can ignore the false positives & Requires Review for a minute, then the tool is doing a decent job in the DevSecOps cycle.

Like

ease of seeing all of our vulnerabilities in 1 dashboard

Dislike

With a large number of projects to scan, mend.io can be slow to deliver results. If you have projects with many builds with different version numbers for the same artefact, it can be cumbersome to delete the older versions, as deletion is only possible one artefact at a time.

Dislike

Multifold increase in renewal cost for WhiteSource (Mend) Scans often report lots of false positive alerts (especially source matches - min. 25% of total alerts) A lot of requires review at the end of the scan (min 18-20% of total libraries)

Dislike

if we had how to questions while on the kick off call, our guy would not answer our questions. he pointed us toward documentation. we were trying to set it up and we could have moved faster if he was willing to help.

Top Mend Alternatives

Logo of Veracode
1. Veracode
4.6
(417 Ratings)
Logo of Checkmarx SAST
2. Checkmarx SAST
4.6
(398 Ratings)
Logo of Appknox
3. Appknox
4.8
(246 Ratings)
View All Alternatives

Peer Discussions

Mend Reviews and Ratings

4.5

(167 Ratings)

Rating Distribution

5 Star
41%
4 Star
54%
3 Star
4%
2 Star
1%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.5

Integration & Deployment

4.4

Service & Support

4.6

Product Capabilities

4.3

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • MANAGER, CUSTOMER SERVICE AND SUPPORT
    10B+ USD
    Software
    Review Source

    Integration With Maven Builds Is Simple, but Large Scans May Be Slow

    5.0
    Oct 21, 2025
    It's very easy to integrate Mend.io into a Maven build and announce builds and consumed libraries for scanning. Findings are colour-coded, and there are easy-to-navigate vulnerability alerts. The vulnerabilities from CVE + NVD are updated every few minutes and are automatically applied to the project.
  • Director of IT
    Gov't/PS/Ed
    Education
    Review Source

    Great product that helps our devs code smarter and more secure

    4.0
    Jul 9, 2025
    overall it has been good. the product is great. the training is almost non existent. the hands on from the company could have been better.
  • Technical Manager
    50M-1B USD
    Software
    Review Source

    Mend Shows a Genuine Commitment to Implementing User Feedback and Needs

    5.0
    Jun 6, 2025
    While many vendors in this space offer the same features and capabilities, Mend stood out with their willingness to find a solution that worked for us. No product is perfect but they took any feedback we had and directly implemented it into the product.
  • Senior Engineer
    1B-10B USD
    Hardware
    Review Source

    Mend Scanning Effectively Identifies CVEs but Faces Occasional Issues

    4.0
    May 13, 2025
    Mend scanning works well at identifying CVE's. They have been responsive when we had issues with the product.
  • Manager
    50M-1B USD
    Banking
    Review Source

    Effective FOSS Scans with Excellent UX and Reporting Capabilities

    5.0
    May 29, 2025
    Overall positive experience as qe use it for FOSS scans for target companies
...
Showing Result 1-5 of 167

Recommended Gartner Research

  • Market Guide for Software Supply Chain Security

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.