Try our new research platform with insights from 80,000+ expert users
Snyk Logo

Snyk pros and cons

Vendor: Snyk
4.1 out of 5
Badge Ranked 1

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Snyk automates vulnerability detection, providing 24/7 monitoring and auto-mitigation, streamlining the process for developers.
Snyk's comprehensive vulnerability database offers accurate information with a low rate of false positives.
Integration capabilities with platforms like GitLab and JIRA enhance workflow by seamlessly incorporating vulnerability information for developers.
Snyk's AI-powered scanning supports detection across multiple programming languages, improving security practices and code quality.
Snyk offers scalability across large organizations, accommodating extensive applications and repositories, making it suitable for wide-scale deployment.

CONS

Snyk lacks comprehensive documentation, making troubleshooting difficult for users.
Integrations with Snyk can be challenging, as seen with issues involving Gradle, NPM, and Xcode.
Users frequently encounter false positives, affecting the perceived accuracy of vulnerability detection.
Snyk's reporting capabilities can be improved, especially in quality and relevance.
Compared to Veracode and Checkmarx, Snyk's language support and vulnerability precision are seen as weaker.
 

Snyk Pros review quotes

reviewer1258746 - PeerSpot reviewer
Engineering Manager at a comms service provider with 51-200 employees
Jan 16, 2020
What is valuable about Snyk is its simplicity.
AG
Information Security Engineer at a financial services firm with 1,001-5,000 employees
May 13, 2020
Snyk has given us really good results because it is fully automated. We don't have to scan projects every time to find vulnerabilities, as it already stores the dependencies that we are using. It monitors 24/7 to find out if there are any issues that have been reported out on the Internet.
reviewer1354494 - PeerSpot reviewer
Manager, Information Security Architecture at a consultancy with 5,001-10,000 employees
May 21, 2020
It has improved our vulnerability rating and reduced our vulnerabilities through the tool during the time that we've had it. It's definitely made us more aware, as we have removed scoping for existing vulnerabilities and platforms since we rolled it out up until now.
Learn what your peers think about Snyk. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
reviewer1354503 - PeerSpot reviewer
Security Analyst at a tech vendor with 201-500 employees
May 21, 2020
Our overall security has improved. We are running fewer severities and vulnerabilities in our packages. We fixed a lot of the vulnerabilities that we didn't know were there.
SK
Sr. Security Engineer at a tech vendor with 201-500 employees
May 21, 2020
The most valuable features include enriched information around the vulnerabilities for better triaging, in terms of the vulnerability layer origin and vulnerability tree.
reviewer1367229 - PeerSpot reviewer
Senior Manager, Product & Application Security at a computer software company with 1,001-5,000 employees
Jun 10, 2020
The CLI feature is quite useful because it gives us a lot of flexibility in what we want to do. If you use the UI, all the information is there and you can see what Snyk is showing you, but there is nothing else that you can change. However, when you use the CLI, then you can use commands and can get the output or response back from Snyk. You can also take advantage of that output in a different way. For the same reason, we have been using the CLI for the hard gate in the pipeline: Obtain a particular CDSS score for vulnerability. Based on that information, we can then decide if we want to block or allow the build. We have more flexibility if we use the CLI.
DK
Senior Director, Engineering at Zillow Group
Jun 25, 2020
It is one of the best product out there to help developers find and fix vulnerabilities quickly. When we talk about the third-party software vulnerability piece and potentially security issues, it takes the load off the user or developer. They even provide automitigation strategies and an auto-fix feature, which seem to have been adopted pretty well.
NS
Information Security Officer at a tech services company with 51-200 employees
Jul 8, 2020
The dependency checks of the libraries are very valuable, but the licensing part is also very important because, with open source components, licensing can be all over the place. Our project is not an open source project, but we do use quite a lot of open source components and we want to make sure that we don't have surprises in there.
CG
Security Software Engineer at a tech company with 10,001+ employees
Aug 30, 2020
The most valuable features are their GitLab and JIRA integrations. The GitLab integration lets us pull projects in pretty easily, so that it's pretty minimal for developers to get it set up. Using the JIRA integration, it's also pretty easy to get the information that is generated, as a result of that GitLab integration, back to our teams in a non-intrusive way and in a workflow that we are already using.
reviewer1412625 - PeerSpot reviewer
Application Security Engineer at a tech services company with 501-1,000 employees
Aug 31, 2020
The most valuable feature is that they add a lot of their own information to the vulnerabilities. They describe vulnerabilities and suggest their own mitigations or version upgrades. The information was the winning factor when we compared Snyk to others. This is what gave it more impact.
 

Snyk Cons review quotes

reviewer1258746 - PeerSpot reviewer
Engineering Manager at a comms service provider with 51-200 employees
Jan 16, 2020
Could include other types of security scanning and statistical analysis
AG
Information Security Engineer at a financial services firm with 1,001-5,000 employees
May 13, 2020
They were a couple of issues which happened because Snyk lacked some documentation on the integration side. Snyk is lacking a lot of documentation, and I would like to see them improve this. This is where we struggle a bit. For example, if something breaks, we can't figure out how to fix that issue. It may be a very simple thing, but because we don't have the proper documentation around an issue, it takes us a bit longer.
reviewer1354494 - PeerSpot reviewer
Manager, Information Security Architecture at a consultancy with 5,001-10,000 employees
May 21, 2020
There are some new features that we would like to see added, e.g., more visibility into library usage for the code. Something along the lines where it's doing the identification of where vulnerabilities are used, etc. This would cause them to stand out in the market as a much different platform.
Learn what your peers think about Snyk. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
reviewer1354503 - PeerSpot reviewer
Security Analyst at a tech vendor with 201-500 employees
May 21, 2020
Scalability has some issues because we have a lot of code and its use is mandatory. Therefore, it can be slow at times, especially because there are a lot of projects and reporting. Some UI improvements could help with this.
SK
Sr. Security Engineer at a tech vendor with 201-500 employees
May 21, 2020
We've also had technical issues with blocking newly introduced vulnerabilities in PRs and that was creating a lot of extra work for developers in trying to close and reopen the PR to get rid of some areas. We ended up having to disable that feature altogether because it wasn't really working for us and it was actually slowing down developer velocity.
reviewer1367229 - PeerSpot reviewer
Senior Manager, Product & Application Security at a computer software company with 1,001-5,000 employees
Jun 10, 2020
The way Snyk notifies if we have an issue, there are a few options: High vulnerability or medium vulnerability. The problem with that is high vulnerabilities are too broad, because there are too many. If you enable notifications, you get a lot of notifications, When you get many notifications, they become irrelevant because they're not specific. I would prefer to have control over the notifications and somehow decide if I want to get only exploitable vulnerabilities or get a specific score for a vulnerability. Right now, we receive too many high vulnerabilities. If we enable notifications, then we just get a lot of spam message. Therefore, we would like some type of filtering system to be built-in for the system to be more precise.
DK
Senior Director, Engineering at Zillow Group
Jun 25, 2020
We have seen cases where tools didn't find or recognize certain dependencies. These are known issues, to some extent, due to the complexity in the language or stack that you using. There are some certain circumstances where the tool isn't actually finding what it's supposed to be finding, then it could be misleading.
NS
Information Security Officer at a tech services company with 51-200 employees
Jul 8, 2020
Generating reports and visibility through reports are definitely things they can do better.
CG
Security Software Engineer at a tech company with 10,001+ employees
Aug 30, 2020
Because Snyk has so many integrations and so many things it can do, it's hard to really understand all of them and to get that information to each team that needs it... If there were more self-service, perhaps tutorials or overviews for new teams or developers, so that they could click through and see things themselves, that would help.
reviewer1412625 - PeerSpot reviewer
Application Security Engineer at a tech services company with 501-1,000 employees
Aug 31, 2020
We tried to integrate it into our software development environment but it went really badly. It took a lot of time and prevented the developers from using the IDE. Eventually, we didn't use it in the development area... I would like to see better integrations to help the developers get along better with the tool. And the plugin for the IDE is not so good. This is something we would like to have...