Code Security Platform
Snyk
Developer security platform covering SAST, SCA, container, IaC, secrets and DAST scanning with risk scoring and automated fix PRs.
Deployment
Cloud · Self-Hosted (partial)
Languages
21+
Pricing model
Per contributing developer, Quote-based / Enterprise
Free tier
Yes
Workflow coverage
Where in the development lifecycle Snyk operates.
Plugins for VS Code, Visual Studio, Eclipse, JetBrains; real-time Snyk Code and Secrets scanning.
Snyk Studio hooks and rules for Claude Code, Cursor, Codex CLI, Gemini CLI, Copilot; local MCP server.
Snyk CLI runs local pre-commit and CI/CD scans across code, deps, container, IaC, secrets.
Per-issue inline PR comments with severity and data flow, capped at 10 per PR.
PR checks set SCM status and GitLab MR pipeline status; severity and fixability failure conditions.
SCM import scans whole repos into Snyk Projects; Free capped at 5 projects.
Recurring tests never/daily/weekly (default daily Open Source, weekly IaC); scheduled container registry sync.
Kubernetes Connector reads live workloads; cloud scans of deployed resources are Enterprise; DAST scans live apps.
Analysis & detection
Every detection and code-analysis capability tracked for Snyk.
Snyk Code semantic SAST (DeepCode AI engine) across IDE, CLI, SCM and CI/CD.
Source-to-sink data flow analysis with AI-learned sources, sinks and sanitizers; data-flow visualization.
Snyk Secrets uses entropy, ML semantic analysis and regex; IDE, CLI, SCM and PR checks.
Not offered in vendor documentation reviewed as of 2026-09-05.
Snyk Open Source builds full dependency graph including transitive deps against Snyk Vulnerability Database.
Java and JavaScript only; Early Access via Snyk Preview; limits of 300,000 files / 3GB.
CWE-506 malicious packages flagged Critical; research team monitors typosquatting, dependency confusion, hijacking.
SPDX-aligned catalog, default severities, OR/AND dual licenses, custom license policies, org Licenses tab.
Org-wide BOM view exportable to CSV and AI-BOM generation; CLI `snyk sbom test` consumes SBOMs.
Terraform, CloudFormation, Kubernetes, Helm, ARM, AWS CDK, Serverless; CCSS severity; custom-rule SDK.
Scans final image OS and app packages; base image upgrade advice; automatic Dockerfile fix PRs.
Cloud scans of live AWS, Azure, Google Cloud resource configurations; Enterprise plan only.
Snyk API & Web scans live apps and APIs; BOLA testing; SAST/DAST correlation to source lines.
Snyk Code coding-issue detection covers dead code, predefined branches, duplicate branch logic only.
Not documented; Snyk Code's 8 AI-engine categories include no complexity metric
Only duplicate branch logic inside Snyk Code coding-issue analysis; no repo duplication metric documented.
Snyk Code coding-issue detection explicitly includes dead code and predefined branches.
Snyk's own 'coverage' means scan coverage of assets, not test coverage
Snyk's coverage model has no changed-line/new-code coverage concept
Not documented; Snyk Code's 8 AI-engine categories have no module-boundary rules
Remediation reports track MTTR/time-to-resolve history only, no effort/cost estimate
Analytics tracks IDE/CLI usage over time, orgs introducing most new issues, repository freshness; Ignite and Enterprise.
DeepCode AI engine finds null dereferences, race conditions, off-by-one, division-by-zero, type mismatches, buffer overruns.
Aggregated issue summary comment per PR by severity and type, updated in place on new commits.
Snyk Code sanitizer Rule Extensions, IaC custom-rule SDK, custom secret regex; custom rules need Ignite or Enterprise.
Snyk Agent Fix returns up to five AI fix suggestions via `@snyk /fix`, applied with `@snyk /apply #`.
Automatic Fix, backlog, dependency upgrade and Dockerfile base-image PRs; base-image PRs default-on for free accounts.
Triage Assistant checks exploit conditions for Java Gradle/Maven on GitHub only; reachability de-prioritizes unreachable vulns.
The CLI's --all-projects flag explicitly documents monorepo scanning, alongside --detection-depth and --exclude for multi-package repos.
AI capabilities
DeepCode AI semantic engine powers Snyk Code; LLMs used for breakability, Agent Fix, Snyk Assist.
Not offered in vendor documentation reviewed as of 2026-09-05.
Local MCP server runs the Snyk CLI with scan tools; no hosted or remote MCP server offered.
No AI-generated-code inventory; Evo AI-BOM inventories models, agents, tools and MCP servers instead.
Evo chat queries inventory and policies; `@snyk /fix` PR commands; Snyk Assist ships in Learning add-on.
Thumbs up/down on breakability PR comments and a SAST/DAST correlation feedback loop improve accuracy.
"Does not use customer proprietary software code to train, optimize, fine-tune, or improve any AI models"
Models used
Compliance & governance
Audit logs exist as platform data and can be scoped to a hosting region.
SSO available on Ignite and Enterprise; SAML not named; Snyk for Government is Okta-managed SSO.
Fixed roles on Team; Custom Roles require Ignite or Enterprise; dedicated Rule Extensions permissions.
Auditor-ready PDF (first 50 rows) and CSV compliance reports; Ignite and Enterprise; PCI-DSS v4.0.1 Early Access.
Certifications
Standards mapping
Integrations
CI/CD systems
IDEs
Issue trackers
Pricing & plans
$25/month per contributing developer, Team plan (no annual discount published; price varies by product, all products must be purchased within the same plan)
Trial: 14-day self-serve trial sampling Enterprise-plan features (some limited or unavailable); intended to convert to Enterprise
- Snyk Open Source (SCA)
- Snyk Code (SAST)
- Snyk IaC
- Snyk Container
- Real-time scanning in IDE, CLI and SCM integrations
- Unlimited Snyk Code scans for open-source projects
- 5 projects
- 400 Open Source / 100 Code / 300 IaC / 100 Container tests
- Personal token only, no API access
- SNYK-US-01 region only
- No SSO, Custom Roles, custom rules, analytics or compliance reports
- Plan table shows no Cloud Repositories support
- All Free scanning products with increased test limits
- Up to 100 projects
- Jira integration
- Cloud Repositories support
- Next business day support
- No API access
- Fixed, non-customizable roles
- No SSO or Custom Roles
- No custom security rules
- No Snyk Essentials/AppRisk or Analytics/Reports
- SNYK-US-01 region only
- Full platform access with unlimited projects and unlimited tests
- Custom security rules
- Risk-based prioritization
- API access
- SSO and Custom Roles
- Snyk Essentials/AppRisk, Analytics/Reports, compliance reports, regional hosting
- Positioned for organizations under 50 developers
- Enterprise-only items such as IaC cloud scans and PCI-DSS Early Access remain outside this tier
- Unlimited Organizations and full REST API, Service Accounts, OAuth 2.0
- Snyk Essentials (AppRisk) and Snyk Analytics/Reports
- IaC cloud scans of live AWS/Azure/GCP accounts
- PCI-DSS v4.0.1 reporting (Early Access)
- SSO and Custom Roles
- Regional hosting beyond SNYK-US-01
- Quote-only pricing
- Professional-services offerings (Jumpstart, Declining Balance of Hours) sold separately
Who it's for
Ignite is positioned for organizations with fewer than 50 developers; Enterprise for large organizations
Notable strengths
- Six scanning products (Code, Open Source, Container, IaC, Secrets, API & Web DAST) share one Projects, scoring, policy and reporting model
- Deep SCA remediation automation: separate Fix, backlog and upgrade PRs, LLM-assessed breakability risk, and automatic closure of obsolete PRs
- AI-agent governance layer: hooks and rules directives, MCP server/skill risk scoring, AI-BOM discovery, and model risk intelligence
- Native auditor-ready compliance reports (PCI DSS, ISO 27001, HIPAA, CWE Top 25, OWASP Top 10 2025) generated from scan data
- Prioritization combines reachability, EPSS, exploit maturity from CISA KEV, business criticality and live Kubernetes deployment context
Notable limitations
- Snyk Code Local Engine, the only no-upload on-prem SAST option, is deprecated and being phased out
- API access, SSO, Custom Roles, custom security rules, analytics/reports and non-US regions all require Ignite ($1,260/dev/yr) or Enterprise
- Free is capped at 5 projects with per-product test caps, and Team still has no API access
- Reachability analysis is Early Access and limited to Java and JavaScript; Risk Score is Early Access for Open Source and Container only
- Quality/maintainability facets (complexity metrics, duplication metrics, test coverage) are not documented; inline PR comments cap at 10 per PR
Similar tools
Other Code Security Platform tools in the directory.
FAQ
When should you choose Snyk?
Snyk best fits Startups, Mid-market teams, Enterprise, Regulated industries, Ignite is positioned for organizations with fewer than 50 developers; Enterprise for large organizations. Six scanning products (Code, Open Source, Container, IaC, Secrets, API & Web DAST) share one Projects, scoring, policy and reporting model
What languages does Snyk support?
Snyk supports 21+ languages and frameworks, including Apex, C, C++, C#, COBOL, Dart, Elixir, Go, Groovy, Java, and 11 more.
What does Snyk integrate with?
Snyk integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center, Azure DevOps for source control, CI systems including GitHub Actions, Snyk IaC GitHub Action, any CI/CD via Snyk CLI, and IDEs including Visual Studio Code, Visual Studio, Eclipse, JetBrains IDEs.
What tools are similar to Snyk?
Similar Code Security Platform tools tracked here include Aikido, Checkmarx One, Corgea, GitHub Advanced Security.
What are Snyk's plans and pricing?
Snyk offers a free tier, with paid plans starting around Free tier available; enterprise pricing is quote-only.
Opens snyk.io in a new tab. Review Radar is not affiliated with Snyk.