🚀 TG4G
DirectorySecuritymeterian.com
🛡 Security 📍 HQ: United Kingdom
M

meterian.com

Overall Rating
★★★★☆ 8.0/10
China Access
★★★ China direct-connect friendly
Quick Check
Data source
ai_crawl · Last updated 2026-06-08

⚡ Score breakdown

5-dim weighted · /10
Performance25% 8.0
Value20% 8.0
China access20% 10.0
Reputation20% 6.4
Support15% 7.5

Dimension scores are derived from public data and fields; weighted into the composite. Reference only.

Editorial Highlights

Covers dependency, container, and IaC vulnerabilities; suitable for development teams.

In-Depth Review TG4G Review ·2026-06-08 · For reference only

What it is

Meterian is an open-source software supply chain security platform from UK-based Meterian Ltd. Its core focus is open-source vulnerability scanning, software composition analysis (SCA), and license compliance management. The product lineup includes repository scanning with BOSS, container scanning with BOSSC, IaC scanning with ISAAC, the KIWI vulnerability data source, the HEIDI IDE plugin, and the SASHA SAST tool. It is aimed at development, DevSecOps, application security, quality, and risk management teams.

Core capabilities

In terms of protection coverage, Meterian addresses dependency vulnerabilities, outdated components, license risks, container image risks, IaC configuration issues, and static source-code defects. Its SCA reports can generate SBOMs, license and copyright attribution, and upgrade paths, with output formats including HTML, JSON, PDF, and Console. SASHA also provides SARIF output, making it easier to integrate with ecosystems such as GitHub Code Scanning and Azure DevOps. The HEIDI plugin can scan manifest files in IDEs such as VS Code, JetBrains, Cursor, and Windsurf, and integrates with AI coding assistants and MCP, with an emphasis on catching issues early in development.

Deployment, management, and integrations

Meterian’s main scanning capabilities can be integrated into virtually any CI/CD pipeline, with the source text mentioning scenarios such as GitHub Actions, GitLab CI, Jenkins, and Azure DevOps. A key selling point is privacy protection: SCA and HEIDI do not require source code to be uploaded, typically processing only dependency manifests or structured findings. SASHA also states that source-code analysis remains within the local environment. The KIWI vulnerability database can be deployed locally, supports offline use, can be updated daily or more frequently, and provides an unlimited-call API, making it suitable for integration into internal security platforms.

Pricing and limitations

Pricing information is incomplete. The page only shows a Free plan, Enterprise Trial, Book a demo, and HEIDI’s Free / Premium model; no specific prices were captured. In terms of compliance certifications, the source text does not disclose third-party certifications such as SOC 2 or ISO 27001. Another limitation is that SASHA’s language support is still being expanded: the source text states that Node.js and .NET are fully available, while other languages are being rolled out gradually.

Who it is for and access from China

Meterian is suitable for mid-sized to large engineering teams that need continuous governance of open-source dependencies, containers, and IaC risks within CI/CD, and that care about SBOMs, license compliance, and keeping source code in-house. The free version of HEIDI is also suitable for lightweight developer trials. Access from mainland China, payment methods, and local support are not clearly stated, so china_access can only be rated as unknown. If localized procurement or network stability in China is required, alternatives such as Snyk, Mend, Sonatype, GitHub Advanced Security, Checkmarx, Veracode, Semgrep, and JFrog Xray may also be worth evaluating.

⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on meterian.com official site.

About this entry

meterian.com is an United Kingdom Security provider. TG4G tracks its product information, an overall rating of 8.0/10, and a China-accessibility score of China direct-connect friendly. Click "Visit Official Site" to reach meterian.com directly.

Get Started

Price not disclosed
Visit meterian.com official site →
External link · prices subject to vendor site

Frequently Asked Questions

What is meterian.com?
meterian.com is a United Kingdom-based Security provider. Covers dependency, container, and IaC vulnerabilities; suitable for development teams.
Is meterian.com good? Is it worth it?
meterian.com scores 8.0/10 on TG4G — a strong rating, based in 英国. See the in-depth review below for pros, cons and China accessibility.
Is meterian.com usable in China?
meterian.com offers good direct-connect performance in mainland China and works in most regions without a proxy. The provider is headquartered in United Kingdom and primarily serves overseas markets.
How do I sign up for meterian.com?
Visit the meterian.com official site to complete sign-up. Registration typically requires an email (Gmail/Outlook recommended) and a payment method. Most overseas services accept credit card / PayPal / crypto. See the "Visit Official Site" button on this page for the direct link.

Browse Other Categories

View the full directory →