

JFrog Xray and CAST Highlight compete in the software analysis and security space. Users note that CAST Highlight has the advantage due to its advanced features and comprehensive solution offerings.
Features: JFrog Xray offers real-time binary analysis, deep dependency scanning, and integration with development environments. CAST Highlight provides portfolio analysis, open-source risk management, and technical debt estimation.
Room for Improvement: JFrog Xray could improve cloud-native features, expand its architectural analysis tools, and enhance user interface customization. CAST Highlight may benefit from improved integration with more development platforms, a more user-friendly setup process, and enhancing the scope of its vulnerability database.
Ease of Deployment and Customer Service: CAST Highlight's cloud-native deployment and flexible enterprise workflow integration are strong points. Their support is praised for being responsive and knowledgeable. JFrog Xray integrates seamlessly with various repositories, offering efficient problem resolution and trusted customer service.
Pricing and ROI: JFrog Xray is competitive in pricing, offering good ROI through effective vulnerability management. CAST Highlight has a higher setup cost but provides strong ROI by managing technical debt and reducing security risks, aligning closely with strategic IT goals.
Money saved is equal to approximately one FTE worth of manual research time per quarter.
Some support team members are helpful, and others lack in-depth knowledge of the tool, which might cause challenges.
I interacted with customer support regarding one of my project results related to vulnerabilities and license risks, and they explained everything clearly, leaving me very satisfied.
When we need clarifications, we contact our account manager, and they arrange demos.
On a scale of 1 to 10, I would rate the technical support of JFrog Xray an eight because they are very knowledgeable.
The processing time per new report stays consistent, experiencing no slowdowns even when we had over 200 new reports dropped in a week.
According to my use case, it is highly scalable.
CAST Highlight proves reliable in nature.
I use JFrog Xray primarily for security purposes, and I find it reliable.
We did experience crashes, downtimes, and performance issues with JFrog Xray.
Understanding only the OS-specific blockers means I would avoid resolving irrelevant issues, thus saving time.
For example, showing all security quotes from healthcare companies with more than 1,000 employees over the last 90 days would enable better filtering, and exportable dashboards would streamline quarterly reviews.
somehow you need to adapt your GitLab pipeline and turn them into JFrog pipeline, and this is something they don't really advertise at first—you're obliged to use the JFrog CLI.
When we have given a very long tag, it doesn't work as expected and requires excessive scrolling.
X-ray needs improvement in supporting more than one database, as it currently only supports PostgreSQL.
JFrog Xray provides a free trial of 14 days.
The basic scanning capabilities come with Artifactory, however, curation requires additional licenses.
Sentiment and strength scoring ranks highlights by how specific, emotional, and credible they are.
In cloud migration, I use CAST highlight to identify blockers, which are the negative road patterns, and also the boosters, which are positive code patterns.
The policy-driven approach of JFrog Xray helped me maintain security standards by integrating it in the development pipeline.
The most valuable features of JFrog Xray are its curation capabilities, its native integration with Artifactory, scanning for vulnerabilities, and license compliance features.
With other registries such as ECR, we can use the images only in the AWS cloud. With JFrog, we can use this registry from any cloud or work locally as well.
| Product | Mindshare (%) |
|---|---|
| JFrog Xray | 5.7% |
| CAST Highlight | 1.2% |
| Other | 93.1% |


| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 1 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 1 |
| Midsize Enterprise | 3 |
| Large Enterprise | 6 |
CAST Highlight is a comprehensive platform that integrates with Azure DevOps, offering remote functionalities without direct codebase access. It quickly identifies cloud migration blockers and supports most programming languages with an easy setup.
CAST Highlight stands out with its user-friendly interface and dashboard, enabling efficient scanning for environment quality. Its automation and speed are particularly valued, making it distinct in the software analysis domain. While users encounter challenges with language-specific insights and expensive licensing, they benefit from its capability to assess code base states during mergers, acquisitions, and cloud migration planning. Technical support poses issues, and some users face hurdles with configuration customization and issue reporting clarity. Despite these challenges, CAST Highlight demonstrates effectiveness in identifying application service quality and ensuring legal, security, and IP compliance.
What features define CAST Highlight?CAST Highlight is adopted across industries for tasks such as assessing code during mergers, managing application portfolios, and planning cloud migrations. It facilitates open source safety checks and replatforming architectures, serving roles in firewall and storage management. Users rely on it for service quality verification and distinguishing applications from competitors.
JFrog Xray is a robust solution for managing artifacts and vulnerabilities, integrating with tools like Artifactory to streamline dependency management and ensure security compliance. Recognized for its scalability and stability, it facilitates advanced reporting and license compliance.
JFrog Xray provides a comprehensive approach to artifact security and management, seamlessly integrating with CI/CD pipelines. Its deep scanning capabilities are particularly valuable for containerized applications, offering insights into vulnerabilities and compliance. The tool's policy-driven approach enhances security, while its efficiency in handling multiple package types ensures broad applicability. Despite room for improvement in speed and performance, it's a critical asset for organizations prioritizing secure software delivery.
What are JFrog Xray's key features?JFrog Xray finds application across industries where security and compliance are critical. In sectors reliant on container technology and open-source components, such as finance or technology, Xray aids in deploying secure applications. Through its deep scanning capabilities, companies can ensure that images and artifacts meet compliance standards, mitigating risks associated with dependencies and licenses.
We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.