We primarily use the solution for vulnerability scanning. We're looking for vulnerabilities in open-source components.
Senior Manager at a comms service provider with 5,001-10,000 employees
Reasonably priced with good scanning and reporting capabilities
Pros and Cons
- "The solution is stable and reliable."
- "Since we have been using the solution via APIs, there are some limitations in the APIs."
What is our primary use case?
What is most valuable?
The quality of scanning has been good. Its reporting is good.
It's very clear and understandable.
The solution is stable and reliable.
We find the product the be easy to set up.
It is scalable.
The pricing is reasonable.
What needs improvement?
Since we have been using the solution via APIs, there are some limitations in the APIs.
We've only used it for six months, so we need to explore it more before commenting on any missing features.
For how long have I used the solution?
I've been using the solution for six months.
Buyer's Guide
JFrog Xray
January 2026
Learn what your peers think about JFrog Xray. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,733 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable and reliable. I'd rate it nine out of ten. The performance is good. There are no bugs or glitches.
What do I think about the scalability of the solution?
We have less than 100 users on the solution right now. They are IT specialists and developers.
The scalability is good. I'd rate it eight out of ten. It's hard to estimate how much it can scale.
How are customer service and support?
I have not used technical support.
Which solution did I use previously and why did I switch?
We started with Sonatype and have switched over to JFrog. We were already using another JFrog solution and decided to focus on product synergy.
How was the initial setup?
The implementation is rather straightforward. I was not involved with the team directly. They deployed it themselves, and I didn't hear about any issues, and there were no deployment delays.
The deployment itself took a couple of weeks.
In terms of maintenance, one or two people maintain it. They do not maintain it full-time. They manage other tools as well. It's relatively minimal maintenance.
What about the implementation team?
Our own internal team handled the setup. We did not need the help of consultants or integrators.
What was our ROI?
It's too early to estimate the ROI.
What's my experience with pricing, setup cost, and licensing?
I don't handle the licensing. I don't know the exact cost of the solution. The pricing is likely fair. I've looked at competitive products and recall Xray being among the lower in terms of cost. I'd rate the pricing five out of ten.
What other advice do I have?
I'm an end-user.
We're likely using a version that is the latest or close to the latest.
I'd recommend the solution to others. There haven't been any disappointments so far.
I'd rate the solution eight out of ten. It's done what is expected so far.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
DevOps Engineer Intern at a university with 1,001-5,000 employees
Stable, scalable and offers great reporting functionalities
Pros and Cons
- "Good reporting functionalities."
- "Lacks deeper reporting, the ability to compare things."
What is our primary use case?
I'm using this solution for scanning artifacts related to the Jfrog Artifactory. I'm scanning them, checking licenses and things like that. I'm a DevOps engineer intern and we are customers of JFrog.
What is most valuable?
I would say the reporting functionalities are pretty good as are the policy watches. I like them a lot.
What needs improvement?
I'd like to see deeper reporting, they're pretty basic and there are no categories for comparing things. I'd also like to see an improvement with the documentation, there's not much available on their website.
For how long have I used the solution?
I've been using this solution for a couple of months.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How was the initial setup?
I wasn't involved in the setup but I heard from my team that they faced some issues although I don't know what they were. We had a great consultant working with us and they solved the problems.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free JFrog Xray Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Vulnerability Management Container Security Software Composition Analysis (SCA) Software Supply Chain SecurityPopular Comparisons
Microsoft Defender for Cloud
SentinelOne Singularity Cloud Security
Prisma Cloud by Palo Alto Networks
GitLab
Checkmarx One
Veracode
Qualys VMDR
Tanium
Tenable Nessus
CrowdStrike Falcon Cloud Security
Black Duck SCA
Orca Security
Tenable Vulnerability Management
Buyer's Guide
Download our free JFrog Xray Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?
- What are your recommended automated penetration testing tools?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- Can you recommend API for Tenable Connector into ServiceNow
- What penetration testing tool (or tools) do you recommend for SMB/SME?
















