Socket logo

Socket

Supply-chain security service that flags malicious and risky open-source packages before you install them.

ProprietaryBy Socket

Compare Socket with another product

Read the Socket documentation

Alternatives

See all alternatives

About Socket

Socket checks open-source dependencies for signs of supply-chain attacks, such as malicious or risky packages, and covers JavaScript, Python and Go ecosystems. It works through a GitHub integration, a CLI, a firewall for package installs, and a browser extension.

Alerts can be sent to ticketing and messaging tools, including Microsoft Teams. It suits development teams who want to vet new and updated dependencies, and individual developers checking a package before adding it.

Strengths

  • Looks for malicious package behaviour, not only known CVEs
  • Covers JavaScript, Python and Go dependencies
  • Available as GitHub app, CLI and browser extension

Limitations

  • Hosted service, scanning depends on Socket's platform
  • Most features are aimed at teams and organisations

Details

Pricing
FreemiumFree tier for individuals and open source, with paid plans for organisations.
License
Proprietary
Developer
Socket
Platforms
Web, Browser extension, Command line
How it runs
Downloadable app, Hosted service, Browser extension
Works offline
No
Best suited for
Development teams vetting open-source dependencies
Last verified
Added
Sources

Report a wrong fact or a dead link on this listing