Market Opportunity
Scan package.json for CVE'd deps and surface prioritized fixes targets a $6.0B = 1.5M software organizations x $4K avg annual spend on dependency/security tooling total addressable market with high saturation and a year-over-year growth rate of 20%+ annual growth driven by DevSecOps adoption and SCA demand.
Key trends driving demand: Software supply-chain attacks -- High-profile incidents (SolarWinds, Log4Shell) drive procurement and security controls.; SBOM & regulation -- Governments and large enterprises increasingly require SBOMs and vulnerability tracking across components.; Developer-first security -- Teams prefer low-friction, CLI/PR-based fixes embedded in developer workflows over heavy enterprise tooling.; AI-assisted triage -- ML/LLM models reduce noise by mapping CVEs to real exploitability/context and prioritizing fixes..
Key competitors include Snyk, GitHub Dependabot (and GitHub Advanced Security), Sonatype (Nexus Lifecycle), Mend (formerly WhiteSource), npm audit / open-source CLIs (e.g., retire.js).