Snyk

Developer security platform covering SAST, SCA, container, IaC, secrets and DAST scanning with risk scoring and automated fix PRs.

Free tier availableLast verified 2026-09-09

Deployment

Cloud · Self-Hosted (partial)

Languages

21+

Pricing model

Per contributing developer, Quote-based / Enterprise

Free tier

Yes

Workflow coverage

Where in the development lifecycle Snyk operates.

Real-Time IDE FeedbackYes

Plugins for VS Code, Visual Studio, Eclipse, JetBrains; real-time Snyk Code and Secrets scanning.

AI Agent Guardrail (MCP)Yes

Snyk Studio hooks and rules for Claude Code, Cursor, Codex CLI, Gemini CLI, Copilot; local MCP server.

Local CLI / Pre-CommitYes

Snyk CLI runs local pre-commit and CI/CD scans across code, deps, container, IaC, secrets.

PR Inline ReviewYes

Per-issue inline PR comments with severity and data flow, capped at 10 per PR.

Merge Gate BlockingYes

PR checks set SCM status and GitLab MR pipeline status; severity and fixability failure conditions.

Full Repo ScanYes

SCM import scans whole repos into Snyk Projects; Free capped at 5 projects.

Scheduled / Continuous RescanYes

Recurring tests never/daily/weekly (default daily Open Source, weekly IaC); scheduled container registry sync.

Runtime / Production MonitoringYesEnterprise

Kubernetes Connector reads live workloads; cloud scans of deployed resources are Enterprise; DAST scans live apps.

Analysis & detection

Every detection and code-analysis capability tracked for Snyk.

SASTYes

Snyk Code semantic SAST (DeepCode AI engine) across IDE, CLI, SCM and CI/CD.

Taint / Data-Flow AnalysisYes

Source-to-sink data flow analysis with AI-learned sources, sinks and sanitizers; data-flow visualization.

Secrets DetectionYes

Snyk Secrets uses entropy, ML semantic analysis and regex; IDE, CLI, SCM and PR checks.

Secrets ValidationNo

Not offered in vendor documentation reviewed as of 2026-09-05.

SCA (Dependencies)Yes

Snyk Open Source builds full dependency graph including transitive deps against Snyk Vulnerability Database.

Reachability AnalysisPartial

Java and JavaScript only; Early Access via Snyk Preview; limits of 300,000 files / 3GB.

Malicious Package DetectionYes

CWE-506 malicious packages flagged Critical; research team monitors typosquatting, dependency confusion, hijacking.

License ComplianceYes

SPDX-aligned catalog, default severities, OR/AND dual licenses, custom license policies, org Licenses tab.

SBOM GenerationPartial

Org-wide BOM view exportable to CSV and AI-BOM generation; CLI `snyk sbom test` consumes SBOMs.

IaC ScanningYes

Terraform, CloudFormation, Kubernetes, Helm, ARM, AWS CDK, Serverless; CCSS severity; custom-rule SDK.

Container ScanningYes

Scans final image OS and app packages; base image upgrade advice; automatic Dockerfile fix PRs.

Cloud Posture (CSPM)YesEnterprise

Cloud scans of live AWS, Azure, Google Cloud resource configurations; Enterprise plan only.

DAST / API ScanningYes

Snyk API & Web scans live apps and APIs; BOLA testing; SAST/DAST correlation to source lines.

Code Smells & MaintainabilityYes

Snyk Code coding-issue detection covers dead code, predefined branches, duplicate branch logic only.

Complexity MetricsNo

Not documented; Snyk Code's 8 AI-engine categories include no complexity metric

Duplication DetectionPartial

Only duplicate branch logic inside Snyk Code coding-issue analysis; no repo duplication metric documented.

Dead / Unused CodeYes

Snyk Code coding-issue detection explicitly includes dead code and predefined branches.

Test Coverage TrackingNo

Snyk's own 'coverage' means scan coverage of assets, not test coverage

Diff / New-Code CoverageNo

Snyk's coverage model has no changed-line/new-code coverage concept

Architecture GovernanceNo

Not documented; Snyk Code's 8 AI-engine categories have no module-boundary rules

Technical Debt QuantificationNo

Remediation reports track MTTR/time-to-resolve history only, no effort/cost estimate

Behavioral Delivery AnalyticsPartialIgnite

Analytics tracks IDE/CLI usage over time, orgs introducing most new issues, repository freshness; Ignite and Enterprise.

AI Logic Bug DetectionYes

DeepCode AI engine finds null dereferences, race conditions, off-by-one, division-by-zero, type mismatches, buffer overruns.

PR Summaries & WalkthroughsPartial

Aggregated issue summary comment per PR by severity and type, updated in place on new commits.

Custom Rule AuthoringYesIgnite

Snyk Code sanitizer Rule Extensions, IaC custom-rule SDK, custom secret regex; custom rules need Ignite or Enterprise.

Autofix SuggestionsYes

Snyk Agent Fix returns up to five AI fix suggestions via `@snyk /fix`, applied with `@snyk /apply #`.

Autofix via Agentic PRsYes

Automatic Fix, backlog, dependency upgrade and Dockerfile base-image PRs; base-image PRs default-on for free accounts.

AI Triage / False-Positive FilteringYes

Triage Assistant checks exploit conditions for Java Gradle/Maven on GitHub only; reachability de-prioritizes unreachable vulns.

Monorepo SupportYes

The CLI's --all-projects flag explicitly documents monorepo scanning, alongside --detection-depth and --exclude for multi-package repos.

AI capabilities

AI Review EngineYes

DeepCode AI semantic engine powers Snyk Code; LLMs used for breakability, Agent Fix, Snyk Assist.

BYO Model / BYOKNo

Not offered in vendor documentation reviewed as of 2026-09-05.

MCP ServerYes

Local MCP server runs the Snyk CLI with scan tools; no hosted or remote MCP server offered.

AI Usage GovernanceNo

No AI-generated-code inventory; Evo AI-BOM inventories models, agents, tools and MCP servers instead.

Chat With ReviewerYes

Evo chat queries inventory and policies; `@snyk /fix` PR commands; Snyk Assist ships in Learning add-on.

Learns From FeedbackYes

Thumbs up/down on breakability PR comments and a SAST/DAST correlation feedback loop improve accuracy.

Code Excluded From TrainingYesFree (all plans)

"Does not use customer proprietary software code to train, optimize, fine-tune, or improve any AI models"

Models used

DeepCode AI (Snyk Code engine; no underlying LLM named)

Compliance & governance

Audit LogsYes

Audit logs exist as platform data and can be scoped to a hosting region.

SSO / SAMLYesIgnite

SSO available on Ignite and Enterprise; SAML not named; Snyk for Government is Okta-managed SSO.

Role-Based Access ControlYesTeam

Fixed roles on Team; Custom Roles require Ignite or Enterprise; dedicated Rule Extensions permissions.

Compliance Reporting ExportsYesIgnite

Auditor-ready PDF (first 50 rows) and CSV compliance reports; Ignite and Enterprise; PCI-DSS v4.0.1 Early Access.

Certifications

FedRAMP/NIST-aligned via Snyk for Government (US)GDPR (documented GDPR-compliant data-deletion workflows)

Standards mapping

OWASP Top 10 (2025)CWE Top 25CWE Top 10 KEV WeaknessesPCI DSS v4.0.1PCI DSS v3.2.1ISO/IEC 27001 (2022 revision)HIPAACVSS v4.0CVSS v3.1CCSSEPSSCISA Known Exploited Vulnerabilities catalogSPDX License List

Integrations

GitHubYes
GitHub Enterprise ServerYes
GitLabYes
GitLab Self-ManagedYes
BitbucketYes
Bitbucket Data CenterYes
Azure DevOpsYes
REST APIPartial
CLIYes
WebhooksPartial

CI/CD systems

GitHub ActionsSnyk IaC GitHub Actionany CI/CD via Snyk CLI

IDEs

Visual Studio CodeVisual StudioEclipseJetBrains IDEs

Issue trackers

Jira

Pricing & plans

$25/month per contributing developer, Team plan (no annual discount published; price varies by product, all products must be purchased within the same plan)

Trial: 14-day self-serve trial sampling Enterprise-plan features (some limited or unavailable); intended to convert to Enterprise

Free$0/monthIndividual developers and small teams evaluating Snyk
  • Snyk Open Source (SCA)
  • Snyk Code (SAST)
  • Snyk IaC
  • Snyk Container
  • Real-time scanning in IDE, CLI and SCM integrations
  • Unlimited Snyk Code scans for open-source projects
  • 5 projects
  • 400 Open Source / 100 Code / 300 IaC / 100 Container tests
  • Personal token only, no API access
  • SNYK-US-01 region only
  • No SSO, Custom Roles, custom rules, analytics or compliance reports
  • Plan table shows no Cloud Repositories support
Team$25/month per contributing developerTeams needing higher scan limits and issue-tracker workflow
  • All Free scanning products with increased test limits
  • Up to 100 projects
  • Jira integration
  • Cloud Repositories support
  • Next business day support
  • No API access
  • Fixed, non-customizable roles
  • No SSO or Custom Roles
  • No custom security rules
  • No Snyk Essentials/AppRisk or Analytics/Reports
  • SNYK-US-01 region only
Ignite$1,260/year per contributing developer (~$105/month)Organizations with fewer than 50 developers wanting enterprise features without enterprise pricing
  • Full platform access with unlimited projects and unlimited tests
  • Custom security rules
  • Risk-based prioritization
  • API access
  • SSO and Custom Roles
  • Snyk Essentials/AppRisk, Analytics/Reports, compliance reports, regional hosting
  • Positioned for organizations under 50 developers
  • Enterprise-only items such as IaC cloud scans and PCI-DSS Early Access remain outside this tier
EnterpriseCustom (contact sales)Large organizations needing platform consolidation and org-wide governance
  • Unlimited Organizations and full REST API, Service Accounts, OAuth 2.0
  • Snyk Essentials (AppRisk) and Snyk Analytics/Reports
  • IaC cloud scans of live AWS/Azure/GCP accounts
  • PCI-DSS v4.0.1 reporting (Early Access)
  • SSO and Custom Roles
  • Regional hosting beyond SNYK-US-01
  • Quote-only pricing
  • Professional-services offerings (Jumpstart, Declining Balance of Hours) sold separately

Who it's for

Ignite is positioned for organizations with fewer than 50 developers; Enterprise for large organizations

Notable strengths

  • Six scanning products (Code, Open Source, Container, IaC, Secrets, API & Web DAST) share one Projects, scoring, policy and reporting model
  • Deep SCA remediation automation: separate Fix, backlog and upgrade PRs, LLM-assessed breakability risk, and automatic closure of obsolete PRs
  • AI-agent governance layer: hooks and rules directives, MCP server/skill risk scoring, AI-BOM discovery, and model risk intelligence
  • Native auditor-ready compliance reports (PCI DSS, ISO 27001, HIPAA, CWE Top 25, OWASP Top 10 2025) generated from scan data
  • Prioritization combines reachability, EPSS, exploit maturity from CISA KEV, business criticality and live Kubernetes deployment context

Notable limitations

  • Snyk Code Local Engine, the only no-upload on-prem SAST option, is deprecated and being phased out
  • API access, SSO, Custom Roles, custom security rules, analytics/reports and non-US regions all require Ignite ($1,260/dev/yr) or Enterprise
  • Free is capped at 5 projects with per-product test caps, and Team still has no API access
  • Reachability analysis is Early Access and limited to Java and JavaScript; Risk Score is Early Access for Open Source and Container only
  • Quality/maintainability facets (complexity metrics, duplication metrics, test coverage) are not documented; inline PR comments cap at 10 per PR

Similar tools

Other Code Security Platform tools in the directory.

FAQ

When should you choose Snyk?

Snyk best fits Startups, Mid-market teams, Enterprise, Regulated industries, Ignite is positioned for organizations with fewer than 50 developers; Enterprise for large organizations. Six scanning products (Code, Open Source, Container, IaC, Secrets, API & Web DAST) share one Projects, scoring, policy and reporting model

What languages does Snyk support?

Snyk supports 21+ languages and frameworks, including Apex, C, C++, C#, COBOL, Dart, Elixir, Go, Groovy, Java, and 11 more.

What does Snyk integrate with?

Snyk integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center, Azure DevOps for source control, CI systems including GitHub Actions, Snyk IaC GitHub Action, any CI/CD via Snyk CLI, and IDEs including Visual Studio Code, Visual Studio, Eclipse, JetBrains IDEs.

What tools are similar to Snyk?

Similar Code Security Platform tools tracked here include Aikido, Checkmarx One, Corgea, GitHub Advanced Security.

What are Snyk's plans and pricing?

Snyk offers a free tier, with paid plans starting around Free tier available; enterprise pricing is quote-only.