Vulnerabilities.io logo

Vulnerabilities.io

by Vulnerabilities.io
No reviews yet
ActiveCloudFree tier
Quick facts
VendorVulnerabilities.io
Year launchedN/A
StatusActive
LocationN/A
Countries servedN/A
Languages1
Integrations2+
Free tierYES
Free trialNO
Contact salesYES

About Vulnerabilities.io

A platform for identifying and managing software vulnerabilities.

Vulnerabilities.io is a software composition analysis (SCA) platform designed for developers and security teams to manage third-party risks. The tool provides a unified dashboard for identifying vulnerabilities, exposed secrets, end-of-life packages, and license compliance issues across an organization's codebase. Key features include one-click Software Bill of Materials (SBOM) generation for compliance needs (e.g., ISO27001, SOC2) and integrations with GitHub and Azure DevOps. The platform offers a free tier for up to 25 projects, with paid plans available for larger teams that require faster support SLAs. It supports a wide range of programming languages, including Java, Python, and JavaScript. The service is a cloud-based SaaS offering, accessible via a web browser.

Pros & Cons

Pros
  • Provides a single platform for managing vulnerabilities, secrets, and EOL packages.
  • Offers a free tier for up to 25 projects, making it accessible for small teams.
  • Generates Software Bill of Materials (SBOM) to help meet compliance requirements.
  • Integrates with popular source control systems like GitHub and Azure DevOps.
  • Supports a wide variety of programming languages.
Cons
  • Pricing for paid tiers is not publicly listed and requires contacting the company.
  • Live chat and phone support options are not mentioned on the website.

Features

Key features

Vulnerability Identification

Scans projects and their dependencies against a comprehensive vulnerability database to identify risks.

Secrets Detection

Analyzes source code in real-time to find exposed secrets like API keys, certificates, and passwords.

Software Bill of Materials (SBOM) Generation

Creates a complete software supply chain view with one click to meet compliance requirements.

End-of-Life (EOL) Detection

Proactively identifies software dependencies that are out of active support or nearing end of security support.

Compliance Reporting

Generates reports to assist with compliance for standards such as ISO27001:2022, Cyber Essentials, and SOC2.

Additional features

Source Control Integration

Connects with GitHub and Azure DevOps to monitor code.

CLI Tool

Integrates with CI/CD pipelines to scan code as it is being written, preventing secrets from reaching source control.

License Management

Detects and reports on software licenses within dependencies.

Risk Trending

Measures and visualizes vulnerability risk over time to highlight areas needing focus.

Multi-Language Support

Supports analysis for Java, C#, VB.Net, PHP, Python, JavaScript, Elixir, and Rust ecosystems.

Pricing

Free trial
Free version
Request a quote
Promo Offer

Monthly plans

Free
USD 0/mo
flat rate · billed monthly
  • Up to 25 projects
Source: vendor pricing page →
Basic
Custom
contact sales for pricing
  • Everything the platform has to offer
  • Up to 25 projects

Contact sales for pricing.

Source: vendor pricing page →
Standard
Custom
contact sales for pricing
  • End-of-life detection, flagging and alerting
  • Bill of materials generation
  • Secrets detection and alerting
  • Vulnerability identification and management
  • GitHub and Azure DevOps Integrations
  • 48-hour SLA support
  • Up to 200 projects

Contact sales for pricing.

Source: vendor pricing page →
Enterprise
Custom
contact sales for pricing
  • Everything in the Standard Tier
  • Tier based pricing on number of projects
  • 24-hour SLA dedicated support response time
  • 200+ projects

Contact sales for pricing.

Source: vendor pricing page →

Countries & Languages

—
Countries served
1
Interface languages
1
Billing currencies

Interface languages

English

Billing currencies

🇺🇸USD

No reviews yet

Be the first to drop a review

Alternatives to Vulnerabilities.io

Treety logo

Treety

Treety is a compliance software platform from Treety that helps fund managers manage ESG reporting.…

Tempo Manufacturing Cloud logo

Tempo Manufacturing Cloud

Tempo Manufacturing Cloud is a cloud-based software platform from Apprentice.io that focuses on manufacturing operations…

SEON logo

SEON

SEON is a fraud prevention and AML compliance software from SEON that supports smarter risk…

SAMESG logo

SAMESG

SAMESG is a security software platform from SAM Corporate that provides website monitoring and protection.…

RiskGuard Tax logo

RiskGuard Tax

RiskGuard Tax is a tax compliance software from FintechX Co. that supports businesses in managing…

Riskbloq logo

Riskbloq

Riskbloq is a crypto investment platform from Riskbloq that helps users make informed investment decisions.…

Spot something wrong or outdated?

Suggest a correction — a reviewer verifies every change.

Often compared with Vulnerabilities.io

Compare any two tools →
Treety logo
Treety
ESG Reporting
0.0
Tempo Manufacturing Cloud logo
Tempo Manufacturing Cloud
Manufacturing
0.0
SEON logo
SEON
Identity Verification
0.0
SAMESG logo
SAMESG
ESG Reporting
0.0