

Mend.io and CAST Highlight are software solutions in the open-source component management and vulnerability detection category. Mend.io appears to have the upper hand with its comprehensive approach to dependency scanning and vulnerability tracking, making it appealing for holistic open-source governance. CAST Highlight stands out for organizations prioritizing security without full code transparency, offering unique insights without needing codebase access.
Features: Mend.io offers advanced open-source dependency scanning, Common Vulnerabilities and Exposures (CVE) detection, and automated integration of vulnerability reports into workflows. It allows users to customize license selections for improved governance. CAST Highlight provides insights into software quality and cloud readiness without direct codebase access, facilitating automated portfolio analysis.
Room for Improvement: Mend.io could enhance notification features, expand language support, and improve integration with diverse environments. Role definitions could also be refined for better user experience. CAST Highlight might benefit from reducing its abstraction level for clearer issue descriptions, and a unified user experience across products would be advantageous.
Ease of Deployment and Customer Service: Mend.io supports flexible deployment options, compatible with both public and private clouds, and receives high praise for responsive and technically adept customer service. CAST Highlight's deployment is predominantly on-premises, with commendable responsiveness, though facing some challenges in support intricacies.
Pricing and ROI: Mend.io is competitively priced, offering plans for varying team sizes with ROI observed in reduced manual effort and enhanced security. CAST Highlight, while perceived as expensive with pricing based on scans and enterprise features, provides unique insights that some users find justify the cost, though pricing adjustments could better align with customer needs.
In terms of time saved, it went from approximately 3.5 hours per insight report to around 40 minutes, which is 80% faster.
Mend.io has provided a good return on investment by significantly reducing vulnerabilities.
Some support team members are helpful, and others lack in-depth knowledge of the tool, which might cause challenges.
I interacted with customer support regarding one of my project results related to vulnerabilities and license risks, and they explained everything clearly, leaving me very satisfied.
Critical tickets are responded to within an hour.
They prioritize providing the best experience to large organizations like ours, belonging to the Fortune 100.
I have noticed that the speed to respond has decreased over time.
The processing time per new report stays consistent, experiencing no slowdowns even when we had over 200 new reports dropped in a week.
Regarding scalability, I would also rate it a ten because in some cases, I have 500 projects inside a single product, so I think it is quite scalable.
CAST Highlight proves reliable in nature.
Mend.io is very stable; we did not have any issues.
AI integration in code security tools like Mend.io is still in its early stages and relatively immature.
Understanding only the OS-specific blockers means I would avoid resolving irrelevant issues, thus saving time.
CAST Highlight's deduplication is great for avoiding spam, but sometimes we want two similar quotes if they are from very different company sizes, such as SMB versus enterprise perspectives on pricing.
That's not a limitation of Mend.io; I think that's a general problem with any tool in the market because no tool in the market will actually know what portion of the code I'm actually using from that particular library if it is vulnerable or not.
The actual challenge is how easy it is to integrate it in the early phase of the software development life cycle.
I strongly recommend that they start working with AI for the reporting part.
The cost of Mend.io is competitive, being quite low compared to others.
Smart deduplication groups similar quotes and picks the strongest and most significant one. It stops insights from showing eight variations of great UI, giving diverse voices instead of repetition.
In cloud migration, I use CAST highlight to identify blockers, which are the negative road patterns, and also the boosters, which are positive code patterns.
We find it 100% accurate in detecting vulnerabilities.
It handles Application Security, performing SCA SAST and container scanning.
The features I find most valuable in Mend.io are the ease of use; it is very easy to access and integrate.
| Product | Mindshare (%) |
|---|---|
| Mend.io | 4.7% |
| CAST Highlight | 1.2% |
| Other | 94.1% |


| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 1 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 3 |
| Large Enterprise | 21 |
CAST Highlight is a comprehensive platform that integrates with Azure DevOps, offering remote functionalities without direct codebase access. It quickly identifies cloud migration blockers and supports most programming languages with an easy setup.
CAST Highlight stands out with its user-friendly interface and dashboard, enabling efficient scanning for environment quality. Its automation and speed are particularly valued, making it distinct in the software analysis domain. While users encounter challenges with language-specific insights and expensive licensing, they benefit from its capability to assess code base states during mergers, acquisitions, and cloud migration planning. Technical support poses issues, and some users face hurdles with configuration customization and issue reporting clarity. Despite these challenges, CAST Highlight demonstrates effectiveness in identifying application service quality and ensuring legal, security, and IP compliance.
What features define CAST Highlight?CAST Highlight is adopted across industries for tasks such as assessing code during mergers, managing application portfolios, and planning cloud migrations. It facilitates open source safety checks and replatforming architectures, serving roles in firewall and storage management. Users rely on it for service quality verification and distinguishing applications from competitors.
Mend.io integrates seamlessly into development environments, providing open-source dependency scanning, CVE detection, and license management to enhance security and efficiency during code development.
Mend.io delivers comprehensive open-source vulnerability detection and remediation, seamlessly integrating with CI/CD workflows. It equips organizations with tools for software composition analysis and license risk detection, efficiently identifying vulnerabilities and managing policies. Mend.io supports a wide array of programming languages and deployment environments while integrating with developer tools like GitHub, Jenkins, and Azure DevOps to enhance security feedback and decision-making. Its ease of use and rapid setup boost efficiency in managing open-source dependencies and reducing vulnerabilities.
What are Mend.io's Key Features?Mend.io empowers industries such as finance, healthcare, and e-commerce by integrating robust open-source security measures within their development cycles, enhancing their ability to address vulnerabilities swiftly and maintain compliance amidst rigorous regulatory standards.
We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.