shouldiuse.io

Report

Should I Use JFrog?

jfrog.com·Analyzed 15 hours ago··Based on 16 sources

Software supply chain platform (Artifactory, Xray, security scanning)

Depends

Depends

Buy if you're a mid-to-large engineering org needing scalable, centralized artifact management with built-in security scanning.

Powerful, scalable enterprise DevOps platform — but opaque pricing, ops weight, and a critical exploited CVE. Overkill for small teams.

Confidence: Medium

4.2/5

G2 rating

167 reviews (JFrog Ltd)

$50/mo

Starting price

Pro plan, per G2 listing

Yes

Free trial

Artifactory + Xray trial

4,500+

Customers

Claimed enterprise customers

Value for money2

Opaque pricing; users report tough negotiations

Ease of use3

Powerful but operationally heavy

Feature depth5

Scales extremely well; deep enterprise features

Security posture2

Two 2026 auth-bypass CVEs; one exploited

Pros

  • Scales extremely well with enterprise-grade capabilities¹
  • Users consistently praise centralized artifact management³
  • Xray security scanning called 'definitely worth it' by users
  • Ahead of the game on regulatory/compliance needs
  • Trusted at bank scale — HDFC Bank, SAS, Monster case studies

Cons

  • Critical CVSS 9.8 auth-bypass vulnerability reportedly exploited in the wild
  • Users report painful pricing negotiations and pricing-model changes
  • Self-hosting is operationally heavy enough to spawn managed competitors14
  • Some users find Advanced Security add-on merely 'decent'

Gotchas

  • highPricing is not public; users report hard negotiations and sudden pricing-model changes
  • highCritical auth-bypass CVE (CVSS 9.8) reportedly exploited — patch immediately or use SaaS
  • mediumSelf-hosted means real ops burden — that's why fully-managed alternatives market against it14
  • mediumAdvanced Security is a separate paid module; some reviewers call it just 'decent'

Best for

  • Mid-to-large engineering orgs
  • Multi-language artifact management
  • Compliance-driven, regulated teams
  • Teams wanting built-in supply-chain security

Not for

  • Solo devs and tiny teams — pure overkill
  • Startups needing predictable, transparent pricing
  • Teams without dedicated DevOps/platform staff
  • Anyone who just needs simple package hosting

Companies that use it

  • HDFC Bank
  • SAS Institute
  • Monster
  • Zeta

Pricing

Free trial

$0

  • Trial of Artifactory and Xray
  • Explore full platform

Pro

$50/user/month (per G2)

  • Centralized artifact repository
  • Self-hosted or cloud

Enterprise

Not disclosed

  • Advanced Security add-on
  • Bank-scale deployments

Security

Patch-sensitive: two 2026 Artifactory auth-bypass CVEs, one CVSS 9.8 reportedly exploited in the wild.

  • CVE-2026-82329 — critical authentication bypass (CVSS 9.8)Reportedly exploited; JFrog has released fixes — verify you're on a patched version.
  • CVE-2026-65616 — Artifactory authentication bypassDisclosed July 30, 2026; patch available per JFrog advisories.10

What users say

Users praise JFrog's scale and centralized artifact management while complaining about pricing and add-on value.

Jfrog Xray is definitely worth it
Reddit, r/devops
Scales extremely well
TrustRadius reviewer
JFrog is pretty ahead of the game
Reddit, r/devops

Alternatives

Compare JFrog with each alternative.

GitHub Packages

Bundled with code hosting; enough for lighter needs

Artifact Keeper

Open-source, self-hosted repo for budget teams

Full analysis

Based on 20+ public sources (reviews, CVE databases, pricing aggregators, vendor case studies). Pricing and quote snippets were partially truncated in sources.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. review
  7. review
  8. review
  9. security
  10. security
  11. security
  12. official
  13. news
  14. news
  15. JFrog — Insight Partnersinsightpartners.com
    news
  16. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Ask a follow-up

Ask if a use case fits. Answers stay inside this report and its sources.

    Comments

    One queue. No replies. Give a display name first. Limit: 7 comments per day.

    Save a name to write a comment.

    No comments yet.