Overview
Product Information on Mend
What is Mend?
Mend Pricing
Overall experience with Mend
“Efficient Supply Chain Security With Mend”
“Mend Platform Offers Broad Coverage but Faces Documentation and Support Issues”
About Company
Company Description
Mend.io, previously known as WhiteSource, focusses on building high-grade Application Security (AppSec) programs which aim to mitigate risk while accelerating development. Leveraging cutting-edge automated technology, the company offers protection against threats associated with supply chains, malicious package attacks, and vulnerabilities found in both open source and custom code. Additionally, Mend.io addresses potential risks linked to open-source licenses. The firm is recognized for its record of satisfying complex, large-scale application security demands and is therefore chosen by numerous demanding development and security teams across the globe. Additionally, Mend.io administrates the automated dependency update project, Renovate.
Company Details
Do You Manage Peer Insights at Mend.io?
Access Vendor Portal to update and manage your profile.
Key Insights
A Snapshot of What Matters - Based on Validated User Reviews
Reviewer Insights for: Mend
Performance of Mend Across Market Features
Mend Likes & Dislikes
The platform integrates into existing workflows, allowing developers to identify and remediate supply chain vulnerabilities without leaving their environment. The Mend team has been incredibly responsive and quick to remediate any issues we encountered. Automated tools for dependency updates significantly reduce the manual effort required to maintain a secure and up-to-date software supply chain. We also found that they beat other vendors to include new critical zero-day vulnerabilities in their database.
Mend provides broad programming language support, including less common ones, e.g. R language. Strong vulnerability grouping and remediation context Responsive customer-success team (open to questions and feedback), regular product update emails
1) Easy to navigate through the menus. 2) SBoM generation is simple. 3) Plenty of help available online and through AI chatbots.
Scalability. Multi org management i.e.No means to search across multiple Mend orgs. No visibility in UI where scans have errored. No findings reported instead.
Response times and required follow-ups from the Vendor are sometimes slow for priority ticket requests. Documentation can be hard to follow or out-of-date. Transitive dependency scanning requires a lot of manual effort. Some functionality requires deeper validation than the initial Vendor claims. Knowledge, pro-activeness and awareness of deprecated features of third party integrations with Mend is not up-to-date e.g Deprecation of PAT tokens in Azure DevOps
1) When creating a ticket for technical support on an issue I had, response time was slow. 2) For this issue, tech support didn't have a ready answer. 3) They wanted more information from me, but I didn't have time to provide it, so I said they could close issue since I had a manual workaround.
Top Mend Alternatives
Peer Discussions
Mend Reviews and Ratings
- It Security & Risk Management Associate50M-1B USDBankingReview Source
Mend Platform Offers Broad Coverage but Faces Documentation and Support Issues
Mend provides a mature platform with extensive coverage across SCA, SAST and container security which has helped improve visibility across our software supply chain. However, customer communication and out-of-date documentation has been a challenge. - IT Security & Risk Management Associate1B-10B USDSoftwareReview Source
Efficient Supply Chain Security With Mend
Mend is a key partner in securing our software supply chain by automating vulnerability management. While our enterprise volume created some initial scalability challenges, Mend was exceptionally quick to remediate every issue. - IT Associate10B+ USDHealthcare and BiotechReview Source
Nice product for SBoM generation.
Easy to use web interface. Online help is readily available. - IT Security & Risk Management Associate50M-1B USDIT ServicesReview Source
Mend SCA Tool Enhances Dependency Security but Feature Requests Face Delays
My overall experience with mend SCA tool has been positive. The platform provides strong visibilty into open source dependencies vulnerabilties, helping ensure compliance and security across our codebase. It's automated scanning, policy enforcement and integration capabilties - CI/CD, repo integration make it efficient to use with existing workflows. - Technical Manager50M-1B USDSoftwareReview Source
Mend Shows a Genuine Commitment to Implementing User Feedback and Needs
While many vendors in this space offer the same features and capabilities, Mend stood out with their willingness to find a solution that worked for us. No product is perfect but they took any feedback we had and directly implemented it into the product.



