Market Opportunity
Scan package.json for vulnerable package versions and flag CVEs by severity targets a $4.8B = 2M software organizations x $2.4K ACV (org-wide developer/tooling/security seats/automation) total addressable market with medium saturation and a year-over-year growth rate of 15-25% (developer security & SCA market expansion).
Key trends driving demand: Supply-chain attacks -- rising incidents push teams to integrate dependency scanning into dev workflows; Developer-first security -- security tools must reduce friction and surface actionables in local/dev CI; SBOM / compliance -- demand for SBOMs and traceability increases scanning adoption; AI-assisted triage -- models enable better mapping of vague version ranges to CVEs and recommend fixes.
Key competitors include Snyk, GitHub Dependabot / GitHub Advanced Security, npm audit / Yarn audit (built-in tools), Mend (formerly WhiteSource) / Sonatype Nexus IQ.