Skip to main content
Black Duck SCA Large Header Logo

Black Duck SCA

9.5 / 10

What is Black Duck SCA?

Black Duck software composition analysis (SCA) helps teams manage the security, quality, and license compliance risks that come from the use of open source and third-party code in applications and containers.

Company Details

Need Assistance?

We're here to help you with understanding our reports and the data inside to help you make decisions.

Get Assistance

Black Duck SCA Ratings

Real user data aggregated to summarize the product performance and customer experience.

93 Likeliness to Recommend

100 Plan to Renew

100 Satisfaction of Cost Relative to Value

Emotional Footprint Overview

+99 Net Emotional Footprint

The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.

How much do users love Black Duck SCA?

0% Negative
0% Neutral
100% Positive


  • Helps Innovate
  • Continually Improving Product
  • Reliable
  • Performance Enhancing

Feature Ratings

Average 96

Container Security Testing


Automated Workflow


Policy Engine and Enforcements


Risk Scoring


False Positive Remediation


Vulnerability Scanning


Software Composition Analysis (SCA)


Integrated Development Environment (IDE) plug-in


Vendor Capability Ratings

Average 93

Ease of Customization


Ease of Implementation


Quality of Features


Business Value Created


Ease of IT Administration


Product Strategy and Rate of Improvement


Vendor Support


Breadth of Features


Ease of Data Integration


Availability and Quality of Training


Usability and Intuitiveness


Black Duck SCA Reviews

Darryl B.

  • Role: Information Technology
  • Industry: Technology
  • Involvement: IT Leader or Manager
Validated Review
Verified Reviewer

Submitted Jun 2022

Excellent open source vulnerability detection.

Likeliness to Recommend

9 / 10

What differentiates Black Duck SCA from other similar products?

After using this program for a while, I was able to significantly reduce the amount of rework by finding and analyzing vulnerabilities prior to utilizing any open source code. The support staff is always on hand to address any issues. Rest it enables us to quickly and accurately examine your code by letting us know what's in it.

What is your favorite aspect of this product?

I appreciate how simple it is to find out whether you have a security risk. The tool makes it incredibly easy to enforce security standards. This is a truly exceptional and incredible software that gives us a lot of information and is becoming better every day as time goes on. This wonderful program makes it simple and effective to find hidden flaws and security exposures. Thanks to the user-friendly style and layout they mandated, the open source detection on all cross-platform browsers, and most significantly, dependency information for multiple languages, we were able to grasp them very easily.

What do you dislike most about this product?

The reporting could be enhanced because it doesn't deliver the output in the way that one would anticipate it to, requiring extra effort to better show the data.

What recommendations would you give to someone considering this product?

Fear not, Black Duck is here to the rescue; it handles the license and security requirements for your open source components. Ideally suited Managing open source components may be done without much difficulty. Comprehensive data warehouse knowledge store repository basis that is simple to use and comprehend... I recommend Black Duck.


  • Performance Enhancing
  • Enables Productivity
  • Trustworthy
  • Efficient Service