

JFrog Xray and Legit Security compete in the security and vulnerability management category. JFrog Xray integrates robustly with DevOps tools, while Legit Security takes a more holistic approach with its infrastructure and code security. Each has strengths and addresses different aspects based on user needs.
Features: JFrog Xray provides comprehensive artifact scanning, deep CI/CD tool integration, and prioritization of vulnerabilities. Its integration with Artifactory allows seamless onboarding and management of dependencies. Legit Security offers continuous security policy monitoring, visibility across the development environment, and integration with multiple tools like GitHub and Jenkins, enhancing its infrastructure security.
Room for Improvement: JFrog Xray could benefit from enhancing its user interface and extending support for more external tools beyond Artifactory. Users have indicated room for improving its scanning speed and reducing false positives. Legit Security can improve its secret detection feature, experiencing a 10-20% false-positive rate. Streamlining the integration process further and enhancing the analysis of unmaintained repositories would help bolster its offering.
Ease of Deployment and Customer Service: JFrog Xray enables efficient deployment within DevOps pipelines with clear documentation and reliable support for troubleshooting. Legit Security provides adaptable deployment options catering to different environments, with a focus on proactive, personalized customer service for an enhanced customer experience.
Pricing and ROI: JFrog Xray offers a competitive structure with lower upfront costs, appealing for budget-conscious users, enhancing ROI by saving time in vulnerability management. Although Legit Security may involve higher initial costs, it provides considerable ROI through extensive security functionality and risk reduction.
| Product | Mindshare (%) |
|---|---|
| JFrog Xray | 11.3% |
| Legit Security | 3.4% |
| Other | 85.3% |


| Company Size | Count |
|---|---|
| Small Business | 1 |
| Midsize Enterprise | 3 |
| Large Enterprise | 6 |
JFrog Xray is a robust solution for managing artifacts and vulnerabilities, integrating with tools like Artifactory to streamline dependency management and ensure security compliance. Recognized for its scalability and stability, it facilitates advanced reporting and license compliance.
JFrog Xray provides a comprehensive approach to artifact security and management, seamlessly integrating with CI/CD pipelines. Its deep scanning capabilities are particularly valuable for containerized applications, offering insights into vulnerabilities and compliance. The tool's policy-driven approach enhances security, while its efficiency in handling multiple package types ensures broad applicability. Despite room for improvement in speed and performance, it's a critical asset for organizations prioritizing secure software delivery.
What are JFrog Xray's key features?JFrog Xray finds application across industries where security and compliance are critical. In sectors reliant on container technology and open-source components, such as finance or technology, Xray aids in deploying secure applications. Through its deep scanning capabilities, companies can ensure that images and artifacts meet compliance standards, mitigating risks associated with dependencies and licenses.
Legit Security offers comprehensive solutions for managing software security risks, ensuring efficient code integration, risk reduction, and policy adherence through centralized controls and robust integration with existing tools.
Legit Security provides organizations with a powerful platform for enhancing software security. It offers a unified control panel that highlights high-risk findings and enhances security posture with risk scoring. By facilitating seamless integration with existing tools, it promotes a security shift-left approach. Centralized management helps enforce policy adherence while secret management capabilities add another layer of security. Despite some false positives in secret detection, Legit collaborates with engineering teams to ensure secure code integration.
What are the key features of Legit Security?In industries dealing with sensitive data and complex code deliveries, Legit Security is implemented to manage the entire software development lifecycle. Organizations utilize it for compliance, integrating it with other scanning tools to bolster code supply chain security and application security management. In the wake of incidents like the SolarWinds breach, the importance of securing the software delivery pipeline has been underscored, positioning Legit Security as a crucial component in protecting against similar threats.
We monitor all Software Supply Chain Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.