Vigilance vs Endor Labs
Endor Labs. Finds known bugs your code can reach and blocks bad packages at install. Vigilance finds the update that gained a hidden power, before you install it.
Updated 5 Oct 2026
The Catch Endor Labs Cannot Make
Endor Labs blocks malicious packages at install and filters known bugs by whether your code reaches them. Vigilance keeps no list of packages at all. Vigilance keeps no list. It compares the version you trust with the version you install. It reports any file that can suddenly do more.
A real one: axios, March 2026
axios is one of the most-installed packages on the internet. In release 1.14.1, its package.json gained a hidden install step. That step pulls down a remote-control program. No CVE existed for it, so a list of known bugs had nothing to match. One command sees it:
vigi diff --old ./axios-1.14.0 --new ./axios-1.14.1
HEADS UP. 1 file changed. package.json can now run a hidden helper on install and reach the network.
Run both. Endor Labs blocks the packages it flags as bad. Vigilance shows the file that changed, flagged or not. See them side by side below.
What Endor Labs Does Well
Endor Labs is best known for reachability. Its site says it checks reachability from code to image, so vulnerabilities in packages your application never loads stay out of the queue. A team that drowns in alerts about known bugs gets a shorter list. The site presents this as the way to fix what is exploitable and skip what was never a risk.
The site also lists a Package Firewall that blocks malicious packages at install. It describes this as one control point for every dependency that enters the organisation. It also lists AI-based code scanning (SAST) that traces data flow across repositories and pull requests. Other listed parts are secrets detection with one policy from laptop to pipeline, and container scanning. Source: the Endor Labs site.
Endor Labs also lists governance for AI coding agents. It describes a check of every agent action against your policy before it runs, with the choices of allow, block or ask a human. Teams that let agents install and run code will find this relevant.
Endor Labs also offers a free Developer tier that works with AI coding agents. Its pricing page says the tier helps agents scan and fix vulnerabilities and exposed secrets as you work, with no account required.
Where It Falls Short
Reachability answers one question. It asks whether your code calls the vulnerable part of a dependency. That narrows a list of known bugs. It does not describe a check of what a new version can now do. A malicious update has no known bug to narrow.
The Package Firewall depends on Endor Labs knowing that a package is malicious. A brand-new attack is unknown at first. Vigilance asks a different question. It compares the version you trust with the new one and shows any file that gained a capability.
Pricing is by seat and needs a sales conversation for specifics. The unit is the contributing developer, so cost grows with your team and not with your machine count.
Endor Labs is a platform with many parts, and its value grows when you use several of them. A team that needs only one narrow check uses a small share of what it pays for.
Feature Comparison
Endor Labs ranks known bugs by reachability and blocks malicious packages, and Vigilance shows files that gained a capability. The table shows the split.
| Question | Endor Labs | Vigilance |
|---|---|---|
| Finds known bugs, filtered to the ones your code can reach | Yes | No |
| Blocks a malicious package at install | Yes, with the Package Firewall | No. It never blocks a program. |
| Scans your own code with AI-based SAST | Yes | No |
| Spots a file that can do more than the version before | Not described | Yes |
| Covers software that did not come from a public registry | Not described | Yes |
| Runs on your own premises | Yes, with Endor Outpost | Yes |
| Has a free tier | Yes, the Developer tier | Yes, up to 50 machines |
| Works with no internet | Not described | Pro |
When Endor Labs Is the Better Fit
Choose Endor Labs if your pain is a long list of known-bug alerts. Reachability gives a team a way to put the exploitable items first.
Choose Endor Labs if you want one control point at install that blocks malicious packages for every team. The Package Firewall is built for that.
Choose Endor Labs if you also need AI-based code scanning, secrets detection and container scanning from the same vendor, with one policy.
Choose Endor Labs if you want governance for AI coding agents with allow, block and ask-a-human choices. Vigilance gives an agent a clear yes or no on a package it installs, but it does not set policy on every agent action.
Reachability and Capability Are Two Filters
Reachability filters known bugs by your code. It asks whether the vulnerable function is in a path your application runs. If not, the alert drops down the list.
Vigilance filters a different list. It looks at the files in an update and keeps only the ones that gained a capability. If none did, it says nothing.
One filter works on known bugs and the other works on new behaviour. A team can run both without overlap. Reachability makes the known-bug queue shorter. Vigilance adds a check for the case where no bug has been published.
Where Vigilance Adds a Check to an Endor Labs Setup
If you run the Package Firewall, a package that Endor Labs flags is blocked before install. Keep that. Add Vigilance at the step where an update is accepted.
Compare the old files with the new files before you ship. The axios case in the example above shows why. A new hidden install step appeared in a package.json file in one release. A diff shows that file by name.
Vigilance works on software that never passes through a registry as well. Vendor installers, zips and your own build output all work, because it reads files and not package names.
On the Pro plan it runs with no network connection at all, which suits a build host in a locked-down network.
What to Ask Before You Choose
Ask how long your known-bug list is today. If it is long and mostly noise, reachability pays off fast. If the list is short, the benefit is smaller.
Ask whether you want a firewall at install or a check after install. The Package Firewall blocks at install. Vigilance compares files after they land and never blocks.
Ask how you count developers. Endor Labs prices by contributing developer in the last 90 days. A team with many casual committers must count carefully.
Ask what you do with software that does not come from a registry. A vendor installer or a zip has no package record. A file-level compare works on it.
Pricing
Endor Labs prices by seat, with volume discounts. A seat is a contributing developer, meaning someone with commits in monitored repositories in the last 90 days. The pricing page lists a free Developer tier, a paid Core tier and a paid Pro tier. It states fair usage limits based on annual quotas. Endor Labs lists AWS, Azure and Google Cloud marketplaces, and Endor Outpost for on-premises deployments. Specific prices need a call with sales. Source: Endor Labs pricing.
Vigilance has a Free plan at $0 with the full scanner for up to 50 machines. Free needs a network and sends a signed report of hashes and capabilities only. A name, an email or a file is sent only if you opt in, and each one needs its own yes. Pro works with no network at all. It is flat for the whole company, starts at $999 CAD a month, and the price steps with company size, not with the machine count.
Which One Do You Need?
Endor cuts the known-bug list down to what matters. Vigilance catches the change no list has yet.
Read how the two sit among other options in software supply chain security tools, or see real attacks that Vigilance replays.
Known Risk versus New Risk
A bug or a bad package someone already reported, with a name and a number. Most tools work here.
A file that gained a capability it never had, that no report covers yet. Vigilance works here.
Common Questions
Is Vigilance an Endor Labs alternative?
Yes, for one job. Vigilance shows the file that gained a new capability, on your own machine. It does not rank known bugs by reachability or scan your code.
What does Vigilance do that Endor Labs does not?
Vigilance compares the version you trust with a new one for any package, installer or container and reports the file that can now do more, with no list needed.
What does Endor Labs do that Vigilance does not?
Endor Labs filters known bugs by reachability, blocks malicious packages at install, scans code with AI-based SAST and detects secrets. Vigilance does none of these.
Does Endor Labs have a free tier?
Yes. Endor Labs lists a free Developer tier. Core and Pro are paid and priced by seat.
Does Vigilance need the internet or a cloud account?
The Free plan runs online. Pro runs fully offline, with no cloud account.
Try It on Your Own Software.
Show it the version you run today and the one you are about to install.
Talk to Us
A question, a pilot, or a bigger fleet? Send a note. It reaches a person.