

Snyk and CAST Highlight are prominent players in the software security and risk management domain. Snyk holds the upper hand with robust integration capabilities and a focus on developer-centric tools complemented by wide-ranging deployment options.
Features: Snyk provides AI-powered scanning, centralized issue resolution, and effective integration with GitHub and Jira. It also features static code analysis and Software Composition Analysis (SCA), emphasizing risk-based prioritization. CAST Highlight stands out with its ability to operate and integrate remotely without direct access to codebases, offering a fast and simple platform with an intuitive user interface.
Room for Improvement: Snyk needs to improve its reporting capabilities, minimize false positives, and enhance vulnerability detection precision. Better integration with more plugins and broader language support, along with clearer cost structures and reduced complexity, are desired. CAST Highlight could benefit from increased flexibility, reduced costs, improved customization, dedication to technical support, and more detailed context-specific analysis.
Ease of Deployment and Customer Service: Snyk's deployment options across public, private, and hybrid cloud environments show flexibility, combined with positive feedback for proactive and responsive customer support. CAST Highlight is primarily on-premise, with a helpful support team, yet lacks the deployment diversity that Snyk offers, which makes the latter more adaptable for various organizations.
Pricing and ROI: Snyk is viewed as expensive but provides justified ROI through comprehensive solutions and time savings. Its flexible licensing suits organizations of various sizes. CAST Highlight is considered costly, especially concerning professional services, yet delivers an attractive ROI by efficiently addressing vulnerabilities and offering thorough analysis, even though its pricing is generally less favorable compared to Snyk.
In terms of time saved, it went from approximately 3.5 hours per insight report to around 40 minutes, which is 80% faster.
I can see that Snyk saves the costs of hiring security developers for vulnerability scanning and security checks, as that responsibility is now managed by Snyk.
Some support team members are helpful, and others lack in-depth knowledge of the tool, which might cause challenges.
I interacted with customer support regarding one of my project results related to vulnerabilities and license risks, and they explained everything clearly, leaving me very satisfied.
Our long-standing association has ensured smooth communication, resulting in favorable support experiences and satisfactory issue resolution.
Their response time aligns with their SLA commitments.
We could understand the implementation of the product and other features without the need for human interaction.
The processing time per new report stays consistent, experiencing no slowdowns even when we had over 200 new reports dropped in a week.
Snyk allows for scaling across large organizations, accommodating tens of thousands of applications and over 60,000 repositories.
Snyk is very scalable and can handle my organization's growth and changing needs.
Till now, we did not face any scaling issues and I did not hear of any.
CAST Highlight proves reliable in nature.
Understanding only the OS-specific blockers means I would avoid resolving irrelevant issues, thus saving time.
CAST Highlight's deduplication is great for avoiding spam, but sometimes we want two similar quotes if they are from very different company sizes, such as SMB versus enterprise perspectives on pricing.
It lacks the ability to select branches on its Web UI, forcing users to rely on CLI or CI/CD for that functionality.
The inclusion of AI to remove false positives would be beneficial.
As we are moving toward GenAI, we expect Snyk to leverage AI features to improve code scanning findings.
Snyk is recognized as the cheapest option we have evaluated.
After negotiations, we received a special package with a good price point.
Snyk is less expensive.
Smart deduplication groups similar quotes and picks the strongest and most significant one. It stops insights from showing eight variations of great UI, giving diverse voices instead of repetition.
In cloud migration, I use CAST highlight to identify blockers, which are the negative road patterns, and also the boosters, which are positive code patterns.
Our integration of Snyk into GitHub allows us to automatically scan codebases and identify issues, which has improved efficiency.
Snyk helps detect vulnerabilities before code moves to production, allowing for integration with DevOps and providing a shift-left advantage by identifying and fixing bugs before deployment.
Snyk has positively impacted my organization by improving the security posture across all software repositories, resulting in fewer critical vulnerabilities, more confidence in overall product security, and faster security compliance for project clients.
| Product | Mindshare (%) |
|---|---|
| Snyk | 11.1% |
| CAST Highlight | 1.2% |
| Other | 87.7% |


| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 1 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 20 |
| Midsize Enterprise | 10 |
| Large Enterprise | 23 |
CAST Highlight is a comprehensive platform that integrates with Azure DevOps, offering remote functionalities without direct codebase access. It quickly identifies cloud migration blockers and supports most programming languages with an easy setup.
CAST Highlight stands out with its user-friendly interface and dashboard, enabling efficient scanning for environment quality. Its automation and speed are particularly valued, making it distinct in the software analysis domain. While users encounter challenges with language-specific insights and expensive licensing, they benefit from its capability to assess code base states during mergers, acquisitions, and cloud migration planning. Technical support poses issues, and some users face hurdles with configuration customization and issue reporting clarity. Despite these challenges, CAST Highlight demonstrates effectiveness in identifying application service quality and ensuring legal, security, and IP compliance.
What features define CAST Highlight?CAST Highlight is adopted across industries for tasks such as assessing code during mergers, managing application portfolios, and planning cloud migrations. It facilitates open source safety checks and replatforming architectures, serving roles in firewall and storage management. Users rely on it for service quality verification and distinguishing applications from competitors.
Snyk excels in integrating security within the development lifecycle, providing teams with an AI Trust Platform that combines speed with security efficiency, ensuring robust AI application development.
Snyk empowers developers with AI-ready engines offering broad coverage, accuracy, and speed essential for modern development. With AI-powered visibility and security, Snyk allows proactive threat prevention and swift threat remediation. The platform supports shifts toward LLM engineering and AI code analysis, enhancing security and development productivity. Snyk collaborates with GenAI coding assistants for improved productivity and AI application threat management. Platform extensibility supports evolving standards with API access and native integrations, ensuring comprehensive and seamless security embedding in development tools.
What are Snyk's standout features?
What benefits can users expect?
Industries leverage Snyk for security in CI/CD pipelines by automating checks for dependency vulnerabilities and managing open-source licenses. Its Docker and Kubernetes scanning capabilities enhance container security, supporting a proactive security approach. Integrations with platforms like GitHub and Azure DevOps optimize implementation across diverse software environments.
We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.