# Socket

> Socket is a San Francisco developer-security company that examines what open-source packages actually do, then warns or blocks them before malicious code reaches a laptop, pull request, CI pipeline, or production system. Its platform combines behavioral package analysis, software composition analysis, reachability, a package-manager firewall, threat intelligence, patches, and workflow integrations. In May 2026, Socket raised a $60 million Series C at a $1 billion valuation after reporting more than 27,000 organizations, 1.5 million protected repositories, and more than 10,000 blocked supply-chain attacks per week.

- **Founded:** 2021
- **Headquarters:** San Francisco, United States
- **Founders:** Feross Aboukhadijeh (Founder and CEO)
- **Products:** Socket for GitHub, Socket Software Composition Analysis, Socket Firewall, Socket Reachability, Socket Certified Patches
- **Notable:** Reached a $1 billion valuation in May 2026 after raising $60 million in Series C funding led by Thrive Capital., Reported more than 27,000 protected organizations and 1.5 million protected repositories by May 2026, up from 7,500 organizations in October 2024., Reported securing more than 11.6 million commits each month and blocking more than 10,000 supply-chain attacks each week in May 2026.

## Products & services

- **Socket for GitHub** — A GitHub App that reviews dependency changes in pull requests, explains behavioral and supply-chain risk, and can warn or block before merge.
- **Socket Software Composition Analysis** — Dependency inventory, vulnerability, license, maintenance, quality, SBOM, and behavioral risk analysis across major package ecosystems.
- **Socket Firewall** — A package-manager proxy that prevents known malicious or policy-violating packages from reaching developer machines, agent sandboxes, and CI systems.
- **Socket Reachability** — Precomputed and full-application function-level analysis that prioritizes CVEs according to whether vulnerable code can actually be reached.
- **Socket Certified Patches** — Human-reviewed, minimal backports for vulnerable dependency versions, intended to let teams remediate without waiting for upstream releases or taking a risky major upgrade.
- **Socket MCP** — Tools for AI assistants to score dependencies, review organization alerts, inspect package files, and investigate the Socket threat feed.
- **Browser and editor extension security** — Behavioral monitoring for Chrome, Firefox, Edge, Open VSX, and VS Code extensions, extending the platform beyond package registries.

## Achievements

- Reached a $1 billion valuation in May 2026 after raising $60 million in Series C funding led by Thrive Capital.
- Reported more than 27,000 protected organizations and 1.5 million protected repositories by May 2026, up from 7,500 organizations in October 2024.
- Reported securing more than 11.6 million commits each month and blocking more than 10,000 supply-chain attacks each week in May 2026.
- Flagged a malicious Axios dependency within six minutes; more than 2,000 organizations onboarded in the following 24 hours, according to Socket.
- Acquired reachability-analysis company Coana in April 2025 and Secure Annex before the May 2026 Series C.
- Holds U.S. patents 12,346,443 and 12,314,394, with other applications pending.
- Was named to the Fortune Cyber 60.

## Latest updates

- **2026-09** — Joined a new OpenJS program to fund Node.js security work and continued publishing rapid research on active package and extension campaigns.
- **2026-09** — Added Microsoft Teams notifications with channel routing and grouped alert digests.
- **2026-08** — Expanded enterprise extension protection to Microsoft Edge after launching Firefox coverage, and released ClickUp and Asana integrations.
- **2026-08** — Joined the AWS Security Hub Extended plan with consolidated procurement and a unique-artifact pricing option for Socket Firewall.
- **2026-08** — Upgraded qualifying public open-source projects from free Team access to the Business plan at no cost.
- **2026-06** — Expanded Socket MCP so AI assistants can review organization alerts, inspect package artifacts, and investigate the threat feed.
- **2026-05** — Raised a $60 million Series C led by Thrive Capital at a $1 billion valuation, bringing total funding to approximately $125 million.

## Links

- Website: https://socket.dev
- LinkedIn: https://www.linkedin.com/company/socketinc
- Twitter/X: https://twitter.com/SocketSecurity
- GitHub: https://github.com/SocketDev

---

Profile page: https://yespress.io/socket
Published by YesPress — https://yespress.io
Last updated: 2026-09-26
