Socket is an AI-powered supply chain security tool that detects malicious and risky open-source packages before they enter your codebase. Unlike traditional SCA tools, Socket proactively analyzes package behavior to catch supply chain attacks, typosquatting, and obfuscated malware in real time.

    Category

    Security

    Subcategory

    Vulnerability Scanning

    // ACCESS METHODS

    Web AppAPICLI

    // COMPLIANCE

    SOC2ISO27001GDPRHIPAA

    ● certified · ○ not verified

    // DATA STORAGE

    Region

    Trains on Data

    Self-hostable

    No

    // PRICING DETAIL

    Free Tier

    Free for public repositories

    Paid Plans

    Team from $10/developer/month, Enterprise pricing available

    API Cost

    Not available yet
    >> OPEN TOOL

    // MORE IN VULNERABILITY SCANNING

    C
    CodeQL
    Free
    SecurityVulnerability Scanning
    #code-analysis#security#vulnerability-detection
    G
    GitGuardian
    Freemium
    SecurityVulnerability Scanning
    #secrets detection#credential scanning#code security
    S
    Semgrep
    Freemium
    SecurityVulnerability Scanning
    #static analysis#sast#code security

    // USE CASES

    Malicious package detectionSupply chain attack preventionDependency risk assessmentCI/CD security integrationGitHub PR security checks