Socket

Blocks malicious npm/PyPI packages at PR time.

Security & Safety Freemium
Researched · Published · Reviewed
RECATOOLS Score
8 / 10
Capability
8
Value for money
8
Ease of use
8
ASEAN readiness
6
API quality
8
Founded
HQ
Users
Launched
Developer

Overview

A developer-first supply-chain security tool that flags malicious and risky open-source packages in real time, catching install scripts, obfuscation, and suspicious network access that CVE scanners miss. Free tier plus paid team plans.

Advertisement

Pricing

Pricing shown for reference only. These figures reflect RECATOOLS research as of 13 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.

Free
$0
Unlimited for open-source projects.
  • Unlimited developers and repos
  • Malicious-dependency blocking
  • 70+ risk-type detection
  • Monthly scan cap
Business
$50/dev/mo
Governance and compliance for larger orgs.
  • No scan or API quotas
  • SBOM import/export
  • SSO/SAML
  • Webhook automation
Enterprise
Custom
Full reachability and enterprise controls.
  • Function-level reachability
  • Broader SCM support
  • SCIM provisioning
  • Named account manager

What you can produce with Socket

  • Real-time detection of malicious/risky packages across npm, PyPI, Go, Maven, and more
  • PR-time alerts via one-click GitHub App
  • Behavioral flags for install scripts, obfuscation, and network access
  • 70+ risk-type detection
  • SBOM import/export (Business tier)
  • SSO/SAML, SCIM, and webhook automation on higher tiers
  • Reachability analysis and priority scoring
  • Free tier for open-source projects
Advertisement

ASEAN Perspective

Socket in Southeast Asia

ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).

RECATOOLS Verdict

Socket does the thing CVE scanners can't: it reads what a package actually does, spotting install-script shenanigans, obfuscation, and network calls that signal a supply-chain attack, then flags it in your pull request before it lands. Coverage spans npm, PyPI, Go, Maven, and more, and it's expanding into browser extensions, editor plugins, and even MCP servers and AI skill marketplaces. Adoption is low-friction: a free tier for open source and a one-click GitHub App. The numbers back the momentum, with a $60M Series C at a $1B valuation in 2026, 27,000+ organizations protected, and 10,000+ attacks blocked weekly. Caveats: it's focused on supply-chain risk, not full SAST/SCA breadth, so it complements broader scanners rather than replacing them, and org controls plus advanced reachability sit behind paid tiers. Global English SaaS with no SEA-specific support.

Independent AI-assisted assessment by RECATOOLS.

What people say

Socket has become the reference point for software supply-chain defense, and reviewers on G2 and SourceForge keep circling the same praise: it catches real risk that CVE-based tools miss, and it fits developer workflows without friction. The source-first analysis, actually inspecting package behavior rather than cross-referencing a vulnerability database, is the differentiator people cite, surfacing operational and supply-chain risks with enough signal to act on proactively or reactively.

The adoption story is unusually concrete. Since closing its Series B in October 2024, Socket grew from 7,500 to more than 27,000 organizations, protects 1.5 million repositories, secures over 11.6 million commits monthly, and blocks more than 10,000 supply-chain attacks every week. In 2026 it raised a $60M Series C led by Thrive Capital (with Andreessen Horowitz, Abstract Ventures, and Capital One Ventures), reaching a $1B valuation and bringing total funding to $125M. The new money is aimed at pushing beyond package managers into browser extensions, editor plugins, MCP servers, and AI skills marketplaces.

Pricing is refreshingly public for this category. Four tiers: Free (unlimited for open-source projects, unlimited developers and repos, malicious-dependency blocking, 70+ risk-type detection, monthly scan cap); Team at $25/developer/month (raised scan cap, precomputed reachability, priority scoring, Slack alerts); Business at $50/developer/month (no scan or API quotas, SBOM import/export, SSO/SAML, webhook automation, compliance integrations); and Enterprise (contact sales, full function-level reachability, broader SCM support, SCIM, named account manager). Committed annual plans get roughly 20% off.

Reviewers note clean deployment that scales and clear ROI, with the GitHub App making rollout painless. The honest boundaries: Socket is deliberately scoped to supply-chain risk, so it sits alongside SAST/SCA tooling rather than replacing it, and the richer reachability analysis and org-level governance are gated to paid tiers. It's a global, English-language SaaS with no Southeast-Asia-specific support, which is fine for most engineering teams but a gap for buyers who want local coverage.

Summary of public user & expert reviews, compiled by RECATOOLS.

About this listing

Researched on
Published on
Last reviewed

This entry was compiled from publicly available data including Socket's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Socket unless explicitly stated.

Data accuracy

Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.

For the latest details, please refer to Socket directly →

Spotted something out of date? Suggest an update →

Advertisement