We are using JFrog Xray for identifying vulnerabilities.
SR IT administrator at a tech services company with 201-500 employees
Useful dependencies hierarchy view and scales well
Pros and Cons
- "The most valuable feature of JFrog Xray is the display of the entire internal dependencies hierarchy."
- "The speed of JFrog Xray should improve. Other solutions have better performance."
What is our primary use case?
How has it helped my organization?
JFrog Xray has helped us improve our architecture.
What is most valuable?
The most valuable feature of JFrog Xray is the display of the entire internal dependencies hierarchy.
What needs improvement?
The speed of JFrog Xray should improve. Other solutions have better performance.
JFrog Xray could improve by offering enhancements in the area of vulnerability management. It includes a more user-friendly interface that presents a detailed list of dependencies, including transitory dependencies. This empowers both developers and management to gain a deeper insight into the software's internal workings.
Buyer's Guide
JFrog Xray
January 2026
Learn what your peers think about JFrog Xray. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
For how long have I used the solution?
I have been using JFrog Xray for approximately three years.
What do I think about the stability of the solution?
JFrog Xray's stability is comparable with other solutions in the market, such as Nexus.
I rate the stability of JFrog Xray an eight out of ten.
What do I think about the scalability of the solution?
We have approximately 900 people using this solution.
I rate the scalability of JFrog Xray a seven out of ten.
How are customer service and support?
I have not used the support from the vendor.
Which solution did I use previously and why did I switch?
I have used JFrog Xray and Nexus, and Nexus has better performance.
What other advice do I have?
This is a good tool but there could be some improvements made. A newer version could be better.
I rate JFrog Xray a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
DevOps Engineer Intern at a university with 1,001-5,000 employees
Stable, scalable and offers great reporting functionalities
Pros and Cons
- "Good reporting functionalities."
- "Lacks deeper reporting, the ability to compare things."
What is our primary use case?
I'm using this solution for scanning artifacts related to the Jfrog Artifactory. I'm scanning them, checking licenses and things like that. I'm a DevOps engineer intern and we are customers of JFrog.
What is most valuable?
I would say the reporting functionalities are pretty good as are the policy watches. I like them a lot.
What needs improvement?
I'd like to see deeper reporting, they're pretty basic and there are no categories for comparing things. I'd also like to see an improvement with the documentation, there's not much available on their website.
For how long have I used the solution?
I've been using this solution for a couple of months.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How was the initial setup?
I wasn't involved in the setup but I heard from my team that they faced some issues although I don't know what they were. We had a great consultant working with us and they solved the problems.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free JFrog Xray Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Vulnerability Management Container Security Software Composition Analysis (SCA) Software Supply Chain SecurityPopular Comparisons
Microsoft Defender for Cloud
SentinelOne Singularity Cloud Security
Prisma Cloud by Palo Alto Networks
GitLab
Checkmarx One
Veracode
Qualys VMDR
Tanium
Tenable Nessus
CrowdStrike Falcon Cloud Security
Black Duck SCA
Orca Security
Tenable Vulnerability Management
Buyer's Guide
Download our free JFrog Xray Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?
- What are your recommended automated penetration testing tools?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- Can you recommend API for Tenable Connector into ServiceNow
- What penetration testing tool (or tools) do you recommend for SMB/SME?

















