# Socket vs TruffleHog

**Leader by Vioscale score:** TruffleHog

| Attribute | Socket | TruffleHog |
|---|---|---|
| **Vioscale score** | 49.9 (71% (medium)) | 60.3 (48% (low)) |
| activity.commits_last_30d | - | 52 |
| adoption.dependent_repos | - | 519 |
| adoption.github_stars | - | 27,596 |
| deployment.options | `{"cloud":true,"self_hosted":true}` | `{"cloud":true,"on_prem":true,"self_hosted":true}` |
| description.long | A developer-focused security platform that analyzes the behavior of software dependencies to identify and block malware, mining software, and other supply chain threats. Socket protects against both known and emerging threats with real-time detection across package managers and programming languages. | A security tool that scans code repositories, chat systems, artifact storage, and other SDLC platforms for leaked credentials. It verifies which secrets remain active and provides continuous monitoring and remediation guidance. |
| features.capabilities | `{"sca":true,"sast":true,"hosting":"both","ci_native":true,"ide_plugin":true,"open_source":true,"reachability":true,"secret_scanning":true,"container_scanning":true,"license_compliance":true}` | `{"sca":false,"hosting":"both","ci_native":true,"open_source":true,"reachability":true,"secret_scanning":true,"container_scanning":true}` |
| integrations.count | 6 | 23 |
| integrations.list | `[{"name":"GitHub"},{"name":"npm"},{"name":"PyPI"},{"name":"Cargo"},{"name":"Go packages"},{"name":"VSCode"}]` | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"Bitbucket"},{"name":"Gerrit"},{"name":"Git"},{"name":"Docker"},{"name":"Artifactory"},{"name":"Jenkins"},{"name":"Buildkite"},{"name":"Azure Repos"},{"name":"Travis CI"},{"name":"Circle CI"},{"name":"Slack"},{"name":"Teams"},{"name":"Jira"},{"name":"Vector"},{"name":"Confluence"},{"name":"Google Drive"},{"name":"S3"},{"name":"SharePoint"},{"name":"Splunk"},{"name":"Webhook"},{"name":"Email"}]` |
| language.primary | - | Go |
| license.spdx | - | AGPL-3.0 |
| market.availability | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"hybrid","summary":"Free tier available with GitHub app and Socket Firewall; enterprise pricing available","freeTier":true,"sourceUrl":"https://socket.dev/blog/github-actions-pricing-whiplash","retrievedAt":"2026-08-14T09:21:38.534Z"}` | `{"type":"free","plans":[{"free":true,"name":"Open Source","summary":"Free","features":["GitHub, S3, directory, GCS, and Docker scanning","800+ secret detectors","GitHub actions, pre-commit, and pre-receive hooks","Custom regex and secrets verification","Automatic updates"],"description":"GitHub, S3, directory, GCS, and Docker scanning with 800+ secret detectors","contactSales":false,"includedLimits":{"sources":"GitHub, S3, GCS, Docker, directory","detectors":"800+"}}],"addOns":[{"name":"TruffleHog Analyze for SaaS"},{"name":"TruffleHog Analyze for Cloud"},{"name":"Forager (Public Dataset Monitoring)"}],"summary":"Free core product; enterprise features and add-ons available via contact sales","freeTier":true,"sourceUrl":"https://trufflesecurity.com/pricing","retrievedAt":"2026-08-14T15:25:30.270Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | commercial |
| pricing.price_level | low | free |
| pricing.transparent | - | no |
| release.cadence_days | - | 7 |
| release.history | - | `[{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.97.1","date":"2026-08-24T16:53:20Z","type":"stable","version":"v3.97.1"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.97.0","date":"2026-08-14T18:35:16Z","type":"stable","version":"v3.97.0"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.96.0","date":"2026-07-24T18:23:23Z","type":"stable","version":"v3.96.0"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.9","date":"2026-07-09T23:09:52Z","type":"stable","version":"v3.95.9"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.8","date":"2026-07-02T18:54:37Z","type":"stable","version":"v3.95.8"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.7","date":"2026-06-29T15:50:35Z","type":"stable","version":"v3.95.7"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.6","date":"2026-06-18T14:38:38Z","type":"stable","version":"v3.95.6"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.5","date":"2026-06-02T16:10:06Z","type":"stable","version":"v3.95.5"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.4","date":"2026-06-02T06:20:51Z","type":"stable","version":"v3.95.4"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.3","date":"2026-05-11T18:38:34Z","type":"stable","version":"v3.95.3"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.2","date":"2026-04-21T20:29:49Z","type":"stable","version":"v3.95.2"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.1","date":"2026-04-21T18:12:48Z","type":"stable","version":"v3.95.1"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.0","date":"2026-04-21T17:39:24Z","type":"stable","version":"v3.95.0"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.94.3","date":"2026-04-08T17:02:29Z","type":"stable","version":"v3.94.3"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.94.2","date":"2026-04-01T13:03:44Z","type":"stable","version":"v3.94.2"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.94.1","date":"2026-03-25T16:18:15Z","type":"stable","version":"v3.94.1"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.94.0","date":"2026-03-20T14:51:55Z","type":"stable","version":"v3.94.0"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.93.8","date":"2026-03-09T20:04:03Z","type":"stable","version":"v3.93.8"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.93.7","date":"2026-03-04T15:58:48Z","type":"stable","version":"v3.93.7"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.93.6","date":"2026-02-27T15:09:47Z","type":"stable","version":"v3.93.6"}]` |
| reliability.sla_pct | - | 99 |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | - |
| security.gdpr | - | yes |
| security.scorecard | - | 7.4 |
| security.soc2 | yes | - |

## Capabilities (DevSecOps Tools)

| Capability | Socket | TruffleHog |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | ✓ | - |
| DAST (dynamic analysis) | - | - |
| SCA / dependency scanning | ✓ | ✗ |
| Secret scanning | ✓ | ✓ |
| Container / image scanning | ✓ | ✓ |
| IaC misconfiguration scanning | - | - |
| **Governance** |  |  |
| OSS licence compliance | ✓ | - |
| SBOM generation (SPDX/CycloneDX) | - | - |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | - | - |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | ✓ | ✓ |
| **Deployment** |  |  |
| Hosting | Cloud + self-hosted | Cloud + self-hosted |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | ✓ | - |
| **Licensing** |  |  |
| OSS engine available | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T16:34:35.080Z. "-" = undocumented, not absent.*
