Aleksandr K.
AK
Aleksandr K.
Mid-Market (51-1000 emp.)
"Decent product for compliance requirements, not so good for efficient AppSec program"
2/5
What do you like best about Snyk?

The best thing there is the ability to plug it in and play with it almost instantly. Integrations are straightforward to manage; Snyk provides you with all the stats you need for your SOC2. Review collected by and hosted on G2.com.

What do you dislike about Snyk?

Snyk core engine is not very good when it comes down to being able to scan mono repositories. When you have a repo that has multiple languages combine, scan times can be over 1 hour. Review collected by and hosted on G2.com.

YB
Yannick B.
Enterprise (> 1000 emp.)
"Using Snyk as a product to be used by the compamy I work for, and personal projects"
4.5/5
What do you like best about Snyk?

I really like the fact that Snyk is a platform and has support for so many different types of scanning. I really like the IaC scanning. I'm not so experienced in vulnerability scanning on IaC level, but this really feels right. Review collected by and hosted on G2.com.

What do you dislike about Snyk?

On of the biggest downsides to Snyk is the fact that the Github actions plugins don't support PR commenting out of the box. It supports uploading Sarif files, but this is only available to Github Enterprise users. Adding support for PR comments would come in so handy! Review collected by and hosted on G2.com.

Sean P.
SP
Sean P.
Software Development Director
Non-Profit Organization Management
Mid-Market (51-1000 emp.)
"Powerful analysis to reduce risk in your applications"
5/5
What do you like best about Snyk?

I like the comprehensive and detailed reporting structure that Synk provides. When possible, Snyk will provide remediations to issues it finds and allows me to integrate with JIRA or other management tools to ensure I don't lose track of important updates. Setup of Snyk is surprisingly easy and I really appreciate the integrations it provides with Bitbucket to make sure all my code is secure. Beyond third party library scanning, the license, container, and live code tracking features are things that look powerful but haven't had a chance to fully try out yet. Given the quality I've seen in most of the tools, I'm sure they are equally great. Review collected by and hosted on G2.com.

What do you dislike about Snyk?

The biggest downside to Snyk is the pricing point for medium sized businesses. The free tier does a lot and can be used by most small businesses. However, when you are scaling up to that medium tier, the pricing became cost prohibitive to us, so we are remaining on the free plan for the time being. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
UC
Verified User in Computer & Network Security
Mid-Market (51-1000 emp.)
"Snyk is amazing"
5/5
What do you like best about Snyk?

Snyk identifies the library vulnerabilities and give CVSS score right next to it to understand the impact as well as the filters are amazing and easy to use. Review collected by and hosted on G2.com.

What do you dislike about Snyk?

Snyk doesn't have inbuilt support for marking false positives for test suite software directories like cypress. Review collected by and hosted on G2.com.

AK
Artur K.
System Architect
Small-Business (50 or fewer emp.)
"Does not allow you making mistakes you did not know you make"
4.5/5
What do you like best about Snyk?

It is easy to use and developer friendly. You can easily test a project locally or let snyk monitor the project from the ci. The quality gate makes sure, you do not introduce new mistakes in your merge requests. Review collected by and hosted on G2.com.

What do you dislike about Snyk?

The need for a Snyk Broker when working with a self hosted Gitlab instance. We recently moved from the Gitlab SaaS service to a self hosted environment. It was partly our mistake for not reading the Snyk documentation well enough, but now we need a broker for it to monitor our projects Review collected by and hosted on G2.com.

JJ
Jade J.
Product Security Architect
Mid-Market (51-1000 emp.)
"Added Value"
5/5
What do you like best about Snyk?

Snyk helped us shift left and streamline some of our security processes. Within the first few months of implementing Snyk, we could determine the impact and scope of zero-day vulnerabilities within an hour versus a day. The time savings and automation are clear winners for us. Review collected by and hosted on G2.com.

What do you dislike about Snyk?

We are frustrated by some reporting capabilities that need to be enhanced. The updated reporting is a vast improvement, but we have specific use cases that we prefer not to engineer through the APIs. Review collected by and hosted on G2.com.

Verified User in Oil & Energy
AO
Verified User in Oil & Energy
Mid-Market (51-1000 emp.)
"Snyk - Great idea, poor implementation"
0.5/5
What do you like best about Snyk?

The holistic nature of a developer security suite from IDE to app monitoring is a great idea. Review collected by and hosted on G2.com.

What do you dislike about Snyk?

Our Developers loathe it. Many false positives on the code scanning, the tool UI is clunky and slow and the post-sales support is truly awful. There are very few support folks at Snyk that actually seem to have any software development experience or the empathy to understand how development teams would use their tool. Review collected by and hosted on G2.com.

Meghna S.
MS
Meghna S.
Cloud Engineer
Information Technology and Services
Enterprise (> 1000 emp.)
"With Fugue's Unified Policy Engine we can consistently govern security & compliance across our SDLC"
4/5
What do you like best about Snyk?

Fugue is efficient when it comes to defining remediation approaches for every violations. It manages runtime security for our cloud-native applications & detects both regular and complicated vulnerabilities. It also provides one-click compliance reporting, which is fast & convenient for our AWS infrastructure requirements. Review collected by and hosted on G2.com.

What do you dislike about Snyk?

We can easily enable automated remediation features for resources that are deployed in the Production environment. It dramatically reduces various risks, underutilized resource expenditures & compliance governance. We are satisfied with the services offered by Fugue for our security policies & posture management. Review collected by and hosted on G2.com.

Brahim A.
BA
Brahim A.
Software Engineer
Small-Business (50 or fewer emp.)
"very good so far, need a little improvment in the user experience."
4/5
What do you like best about Snyk?

I like how it can analyze the package.json file in a node.js project and the fix pulls. Also, I like that it's free. Review collected by and hosted on G2.com.

What do you dislike about Snyk?

I wish you had added a better way to handle multiple analysis options in a single project. For example, I have a nodeJS project with a package.json and code analysis; they have different pages on the UI, and as I tested, there is no easy way to navigate from one to another. Although they are in the same project, it seems that they are treated as two different projects Review collected by and hosted on G2.com.

CC
Carlos C.
Software Engineer
Small-Business (50 or fewer emp.)
"Easy to use and configure."
5/5
What do you like best about Snyk?

One of the most helpful things, in my opinion, is that Snyk is very easy to use. Moreover, it has very permissive commercial plans. And no one should forgive all the supported integrations. Review collected by and hosted on G2.com.

What do you dislike about Snyk?

Some popular languages are not supported, like Kotlin, and it would be interesting to support popular frameworks. For example Snyk allow the static analysis of Ruby but not an specific subset of rules for Ruby on Rails. Review collected by and hosted on G2.com.