4.2/5
G2 rating
167 reviews (JFrog Ltd)
Report
Software supply chain platform (Artifactory, Xray, security scanning)
Depends
DependsBuy if you're a mid-to-large engineering org needing scalable, centralized artifact management with built-in security scanning.
Powerful, scalable enterprise DevOps platform — but opaque pricing, ops weight, and a critical exploited CVE. Overkill for small teams.
4.2/5
G2 rating
167 reviews (JFrog Ltd)
$50/mo
Starting price
Pro plan, per G2 listing
Yes
Free trial
Artifactory + Xray trial
4,500+
Customers
Claimed enterprise customers
Opaque pricing; users report tough negotiations
Powerful but operationally heavy
Scales extremely well; deep enterprise features
Two 2026 auth-bypass CVEs; one exploited
$0
$50/user/month (per G2)
Not disclosed
Patch-sensitive: two 2026 Artifactory auth-bypass CVEs, one CVSS 9.8 reportedly exploited in the wild.
Users praise JFrog's scale and centralized artifact management while complaining about pricing and add-on value.
“Jfrog Xray is definitely worth it”
“Scales extremely well”
“JFrog is pretty ahead of the game”
Compare JFrog with each alternative.
Mature repo manager; some users find it better designed
JFrog vs Sonatype Nexus RepositoryFully-managed Artifactory alternative; far less ops burden
JFrog vs CloudsmithBundled with code hosting; enough for lighter needs
Open-source, self-hosted repo for budget teams
Based on 20+ public sources (reviews, CVE databases, pricing aggregators, vendor case studies). Pricing and quote snippets were partially truncated in sources.
Anonymous. You can change your vote.
Loading votes…
Ask if a use case fits. Answers stay inside this report and its sources.
Comments
One queue. No replies. Give a display name first. Limit: 7 comments per day.
No comments yet.