
Security News
/Company News
Socket Is Sponsoring Composer and Packagist
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

August 4, 2026
3 min read


Amazon Web Services (AWS) customers can now adopt Socket directly through the AWS Security Hub Extended plan, apply committed AWS spend, and start with the first month free. Socket covers supply chain security in the program, with deep behavioral analysis that catches malicious packages signature-based tools miss.
The AWS Security Hub Extended plan brings curated third-party security tools into AWS across 10 security categories, with pay-as-you-go pricing and no required upfront commitment. Socket adds supply chain security to that lineup, with a focus on catching malicious open source packages.
Open source is where most modern applications get built, and it is also where attackers now go first. Malicious packages, compromised maintainer accounts, and typosquats appear in public registries every day, and tools that only match against known vulnerability databases miss them. Socket analyzes the actual behavior of open source packages across the major ecosystems, including npm, PyPI, Maven, Go, NuGet, and RubyGems, to catch malicious and high-risk code before it reaches your developers or your build.
That is where Socket fits alongside the rest of the Extended plan. Other partners secure endpoints, identity, the network, and cloud infrastructure. Socket secures the open source supply chain that feeds every application running on top of them.
Buying Socket through the AWS Security Hub Extended plan changes how procurement and billing work:
For teams that already carry a large AWS commitment, this adds supply chain security without a new procurement cycle.
Socket Firewall blocks malicious and unwanted open source packages and extensions at install time, before they land in an employee laptop, an agent sandbox, or a CI pipeline.
Socket’s Software Composition Analysis (SCA) gives teams full visibility into their open source dependencies and flags risk across the software they already ship. It is priced per user and adjusts month to month as team size changes.
Socket Firewall introduces a pricing model that is new to this space. Instead of charging on bandwidth, data transfer, or raw download counts, Socket bills on unique artifacts checked per month.
A unique artifact is a single de-duplicated package version that passes through the firewall. If a project pins 200 packages in a lockfile and installs it a million times in a month, that counts as 200 artifacts, not a million installs. You pay for the distinct packages you actually check, not for how often your builds run.
Most pricing in this category is still tied to bandwidth or seat counts, which charges teams more for building and shipping more often. Unique artifacts is a cleaner measure of the work being done. It scales with the size of your dependency footprint rather than the frequency of your builds. Because real usage varies from one month to the next, the first month is free while teams get a read on their numbers.
Find Socket in the AWS Security Hub Extended plan and subscribe. You will be redirected to Socket to create an account or sign in, and you can start using the platform right away.
Learn more about Socket Firewall, Socket SCA, and AWS Security Hub.

Subscribe to our newsletter
Get notified when we publish new security blog posts!

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.

Company News
Socket’s first CISO brings deep experience securing high-growth SaaS companies as open source supply chain threats accelerate.

Company News
Replit is integrating Socket Firewall into its AI-powered development experience to help protect builders from malicious open source packages.