Product Feature Research

Replit - Security Scanning

What it does

Automatic vulnerability scanning of dependencies used in the user's apps. CVE tracking. SBOM report generation.

Evidence

Why this is strategically important

๐Ÿ’ญ

SBOM reports are a B2B procurement requirement. Enterprise buyers running vendor assessments need them. Security-conscious verticals (finance, healthcare, government) require them. That Replit sells SBOM inside Core means:

  1. Core is positioned as a B2B-ready SKU, not just a "power-user" upgrade.
  2. Replit is seriously targeting organizations that have procurement processes โ€” i.e., the upper end of Enterprise Developers segment.
  3. This is a concrete moat vs. Anything.com, which has no equivalent surface. Anything.com literally cannot answer "are the dependencies in my app scanned?" with a yes.

Technical implementation signals

Gating

Core-only. Free tier has no security scanning.

Differentiators vs Anything.com

Sources