Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

Vulert

Agentless SCA that monitors dependencies from uploaded manifests or SBOMs

ToolApplication SecurityCloud

Pricing: Trial $0 (1 user, up to 50 apps); Starter $20/month; Pro $45/month; Growth $125/month; Enterprises from $500/month. Annual billing lists $18, $39 and $110 for the three paid tiers. 30-day free trial stated.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed August 2026 · How we review listings

What is Vulert?

Vulert is a software composition analysis service that monitors an application open-source dependencies for known vulnerabilities without access to source code. Projects are added by uploading a manifest or lockfile, for example package-lock.json, yarn.lock, pom.xml, requirements.txt, go.sum, Cargo.lock, composer.lock or Gemfile.lock, or an SBOM in SPDX or CycloneDX format, which Vulert checks against its own vulnerability database. Alerts are delivered through the dashboard and email, with Jira, CI/CD, Slack or Discord and SIEM integrations listed among the platform features, and separately priced modules for Docker image scanning, open-source licence compliance and SBOM export. It is a hosted SaaS product requiring no agent, installation or repository connection, operated by Vulert LTD, a company registered in England.

Best for: Small and mid-sized teams that want continuous open-source dependency and licence monitoring without granting a scanner access to their repositories.

Pros

  • No source code access, agent or repository connection is required. The vendor states that only metadata such as SBOMs and manifests is analysed, which can suit teams whose code cannot leave the organisation.
  • Pricing figures are published on the website rather than quote-only, starting at $20 per month, with a $0 evaluation tier and a stated 30-day free trial.
  • The public scanner runs without signup, so detection output on a real manifest can be inspected before any purchase. The scanner page showed 493,778 vulnerabilities in the database, last updated 3 August 2026.

Key Features

Continuous monitoring of open-source dependencies from uploaded manifest and lockfiles, covering PHP, JavaScript, Java, Python, Go, Ruby, .NET, Rust, Dart, Homebrew, Elixir, Erlang and C++
SBOM ingestion in SPDX and CycloneDX formats, plus SBOM export to CycloneDX as a priced module
Public scanner that accepts a manifest or SBOM without an account or installation
Scheduled rescans with dashboard and email alerts, listed as daily on Starter and hourly on Pro and above
Remediation output showing affected packages, severity, fixed versions and workarounds
Docker image and container vulnerability monitoring as a separate module
Open-source licence discovery with notification of policy-violating licences
Integrations listed by the vendor: Jira issue creation, CI/CD and GitHub Actions, Slack and Discord alerts, SIEM tools including Splunk, LogRhythm and ArcSight, and an API

Do you work at Vulert? to confirm the details or send us a correction.

Add the Cyber Vendor Guide badge to your site

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent Vulert? Request a correction.

Key facts

Pricing
Trial $0 (1 user, up to 50 apps); Starter $20/month; Pro $45/month; Growth $125/month; Enterprises from $500/month. Annual billing lists $18, $39 and $110 for the three paid tiers. 30-day free trial stated.
Model
Per-tier subscription capped by number of applications and users, billed monthly or annually, with extra applications charged monthly. Add-on modules are priced per application per month, including licence compliance, SBOM, container and Docker SBOM export.
Cloud
Yes
Self-hosted
No

Vulert Alternatives

  • SnykDeveloper-first application security platform for finding an...
  • Mend.ioOpen-source security and license compliance platform with co...
  • Black DuckEnterprise SCA platform with deep open-source detection, lic...
  • GitHub Advanced SecurityGitHub-native security scanning with CodeQL SAST, secret sca...
View all alternatives

Where Vulert appears

Guides