License Risk

Open source license scanning

Monitor your App & APIs to find vulnerabilities like SQL injection, XSS, and CSRF — both on the surface and via authenticated DAST.

  • Get a full overview of the licenses you’re using
  • Adapt license risk & filter out internal licenses
  • Generate an SBOM (Software Bill Of Materials)
Trusted by 25k+ orgs | See results in 30sec.
Dashboard with autofixes tab

“We had experience with other tools, but we wanted to revisit the market and see what the state of play was. Aikido quickly stood out as a top choice.”

"We actually consider Aikido a bit of a learning platform for our developers, because the issues come with very clear explanations.”

Security is no longer an afterthought. With Aikido, we’re integrating it directly into our DevOps pipeline to ensure it’s a seamless part of our workflow.

Importance of License Risk

Why should you do license scanning?

down arrow

Licenses can have clauses that force you to open-source your code.
It's critical to make sure you're using licenses that don't threaten the value of your company.
By doing license scanning you'll be prepared for SBOM requests during audits.

Vanta

Get an Overview on License Risk

Get a full overview of the licenses you’re using & the risk associated with them.

Vanta

Easily Export SBOMs

Export a CycloneDX SBOM with one click, or just use CSV.

Features

License scanning features

Aikido dashboard
1

Create SBOMs

Security audits typically require providing an SBOM. Aikido makes it easy to analyze this list in advance & generate it whenever required. Export in CycloneDX, SPDX or CSV.

2

License prioritization

License issues are noisy. Aikido cuts through the clutter by analyzing and scoring severity with an LLM-based engine and multiple data sources. High-risk licenses go to the top of your feed, so you can act fast, create tasks, and improve your SBOM quality as you go.

Aikido dashboard
Aikido dashboard
3

Easily adjust & triage license risk

Aikido allows you to easily analyze and adapt the license risk scoring. On top of that, you can mark licenses as internal, to filter them out of the list.

4

Clear license information

Aikido’s extensively vetted license database translates complex legal jargon into plain, actionable language. Understand your software’s obligations, risks, and rights with ease.

Aikido dashboard
Aikido dashboard
5

Scans Containers

Many license scanners will only scan inside of your repos. Aikido gives you full coverage by scanning your containers too.

6

Cover Compliance

Regulatory bodies worldwide are increasing their focus on software transparency. An SBOM (Software Bill of Materials) helps you meet key compliance requirements.

Aikido dashboard

Aikido's other scanners

One security platform, covering you from code to cloud.

Code & Containers

Open source dependency scanning (SCA)

Continuously monitors your code for known vulnerabilities, CVEs and other risks.

Code

Static code analysis (SAST)

Scans your source code for security risks before an issue can be merged.

Domain

Surface monitoring (DAST)

Dynamically tests your web app’s front-end to find vulnerabilities through simulated attacks. Built on ZAP & Nuclei.

Cloud

Cloud posture management (CSPM)

Detects cloud infrastructure risks across major cloud providers.

Code

Secret Detection

Checks your code for leaked and exposed API keys, passwords, certificates, encryption keys, etc...

Code & Containers

Open source license scanning

Monitors your licenses for risks such as dual licensing, restrictive terms, bad reputation, etc..

Code

Malware detection in dependencies

Prevents malicious packages from infiltrating your software supply chain. Powered by Phylum.

Code

Infrastructure as code

Scans Terraform, CloudFormation & Kubernetes infrastructure-as-code for misconfigurations.

Code & Containers

Outdated Software

Checks if any frameworks & runtimes you are using are no longer maintained.

Containers

Container image scanning

Scans your container OS for packages with security issues.

Custom

Connect your own scanner

Imports and auto-triages findings from your current scanner stack.

Aikido dashboard Aikido dashboard alert

Is Aikido's software pentested?

Yes. We run a yearly pentest on our platform and also have an ongoing bug bounty program to ensure our security is continuously tested by a wide range of experts.

Can I also generate an SBOM?

You can create a CycloneDX SBOM or csv export with one click. Just go to the Licenses & SBOM report where you'll get a full overview of all the packages & licenses you're using.

What do you do with my source code?

Aikido does not store your code after analysis has taken place. Some of the analysis jobs such as SAST or Secrets Detection require a git clone operation. More detailed information can be found on docs.aikido.dev.

Do I need to give access to my repos to test out the product?

When you log in with your VCS we don’t get access to any of your repositories. You can manually give access to the repositories you’d like to scan. It’s also possible to test out the platform using sample repositories.

I don’t want to connect my repository. Can I try it with a test account?

Of course! When you sign up with your git, don’t give access to any repo & select the demo repo instead!

Does Aikido make changes to my codebase?

We can’t & won’t, this is guaranteed by read-only access.

Review

“Aikido makes your security one of your USPs thanks to their integrated automated reporting solution, which helps for ISO & SOC2 certification”

Fabrice G

Managing director at Kadonation

Get started for free
No credit card required.
Aikido dashboardAuto Triggered Issues