No more typing reviews! Try our Samantha, our new voice AI agent.

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

FOSSA integrates easily and quickly into existing workflows, providing rapid feedback on licensing and security issues, which is highly valued by developers.
FOSSA's policy engine is accurate, requires minimal adjustments, and effectively alerts users only when there are compliance issues that need attention.
FOSSA efficiently identifies all components within a build, displaying associated licenses which aids in compliance and risk management.
Support from FOSSA is highly reliable, with a proactive team ready to assist with any queries or issues.
FOSSA's CLI tool respects privacy by only fingerprinting data locally and offers granular control over open-source licenses, helping teams make informed decisions about component usage.

CONS

FOSSA has inaccuracies with distribution acknowledgments needing improvement.
Security scanning only focuses on licenses, not vulnerabilities, requiring external tools.
Dependency approval must be repeated multiple times across the organization.
FOSSA's API requires broader development to reduce reliance on the GUI.
Technical support and understanding of advanced features can be improved.
 

FOSSA Pros review quotes

reviewer2588340 - PeerSpot reviewer
Senior Software Engineer at a manufacturing company with 10,001+ employees
Oct 24, 2024
FOSSA suggests solutions for dependency mismatches.
reviewer1470294 - PeerSpot reviewer
Head of Open Source Engineering and Technology at a financial services firm with 10,001+ employees
Sep 11, 2024
FOSSA is easy to use and set up, provides relatively accurate results, and doesn't require armies of people to get value from its use.
Hanumanth Ramsetty - PeerSpot reviewer
Software Engineer at Tech Mahindra Limited
Oct 24, 2024
FOSSA allows us to keep track of all dependencies to ensure they are up to date and not causing any vulnerabilities.
Learn what your peers think about FOSSA. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,800 professionals have used our research since 2012.
CL
Data Privacy Officer at a healthcare company with 51-200 employees
May 16, 2021
One of the things that I really like about FOSSA is that it allows you to go very granular. For example, if there's a package that's been flagged because it's subject to a license that may be conflicts with or raises a concern with one of the policies that I've set, then FOSSA enables you to go really granular into that package to see which aspects of the package are subject to which licenses. We can ultimately determine with our engineering teams if we really need this part of the package or not. If it's raising this flag, we can make really actionable decisions at a very micro level to enable the build to keep pushing forward.
DONG JOO LEE - PeerSpot reviewer
Owner at UPS Technology
Mar 15, 2023
The scalability is excellent.
Shurjeel Tousif - PeerSpot reviewer
CEO at SeQuenX BV
Mar 14, 2023
I am impressed with the tool’s seamless integration and quick results.
May 19, 2021
Policies and identification of open-source licensing issues are the most valuable features. It reduces the time needed to identify open-source software licensing issues.
JG
Sr. Security Architect at a computer software company with 1,001-5,000 employees
Oct 12, 2020
Their CLI tool is very efficient. It does not send your source code over to their servers. It just does fingerprinting. It is also very easy to integrate into software development practices.
EG
Principal Release Engineer at Puppet
Sep 27, 2020
What I really need from FOSSA, and it does a really good job of this, is to flag me when there are particular open source licenses that cause me or our legal department concern. It points out where a particular issue is, where it comes from, and the chain that brought it in, which is the most important part to me.
BF
Manager of Open Source Program Office at a financial services firm with 5,001-10,000 employees
Oct 5, 2020
The most valuable feature is its ability to identify all of the components in a build, and then surface the licenses that are associated with it, allowing us to make a decision as to whether or not we allow a team to use the components. That eliminates the risk that comes with running consumer software that contains open source components.
 

FOSSA Cons review quotes

reviewer2588340 - PeerSpot reviewer
Senior Software Engineer at a manufacturing company with 10,001+ employees
Oct 24, 2024
FOSSA does not show the exact line of code with vulnerabilities, which adds time to the process as we have to locate these manually.
reviewer1470294 - PeerSpot reviewer
Head of Open Source Engineering and Technology at a financial services firm with 10,001+ employees
Sep 11, 2024
If you have thousands of applications, organizing them all into teams or tags is challenging.
Hanumanth Ramsetty - PeerSpot reviewer
Software Engineer at Tech Mahindra Limited
Oct 24, 2024
While running a FOSSA scan, it takes time for the results to reflect in the FOSSA UI portal.
Learn what your peers think about FOSSA. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,800 professionals have used our research since 2012.
CL
Data Privacy Officer at a healthcare company with 51-200 employees
May 16, 2021
One thing that can sometimes be difficult with FOSSA is understanding all that it can do. One of the ways that I've been able to unlock some of those more advanced features is through conversations with the absolutely awesome customer success team at FOSSA, but it has been a little bit difficult to find some of that information separately on my own through FAQs and other information channels that FOSSA has. The improvement is less about the product itself and more about empowering FOSSA customers to know and understand how to unlock its full potential.
DONG JOO LEE - PeerSpot reviewer
Owner at UPS Technology
Mar 15, 2023
The technical support has room for improvement.
Shurjeel Tousif - PeerSpot reviewer
CEO at SeQuenX BV
Mar 14, 2023
I want the product to include binary scanning which is missing at the moment. Binary scanning includes code and component matching through dependency management. It also includes the actual scanning and reverse engineering of the boundaries and finding out what is inside.
May 19, 2021
For open-source management, FOSSA's out-of-the-box policy engine is easy to use, but the list of licenses is not as complete as we would like it to be. They should add more open-source licenses to the selection.
JG
Sr. Security Architect at a computer software company with 1,001-5,000 employees
Oct 12, 2020
On the legal and policy sides, there is some room for improvement. I know that our legal team has raised complaints about having to approve the same dependency multiple times, as opposed to having them it across the entire organization.
EG
Principal Release Engineer at Puppet
Sep 27, 2020
I would like the FOSSA API to be broader. I would like not to have to interact with the GUI at all, to do the work that I want to do. I would like them to do API-first development, rather than a focus on the GUI.
BF
Manager of Open Source Program Office at a financial services firm with 5,001-10,000 employees
Oct 5, 2020
The solution provides contextualized, actionable, intelligence that alerts us to compliance issues, but there is still a little bit of work to be done on it. One of the issues that I have raised with FOSSA is that when it identifies an issue that is an error, why is it in error? What detail can they give to me? They've improved, but that still needs some work. They could provide more information that helps me to identify the dependencies and then figure out where they originated from.