Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard Code Security vs Snyk comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Check Point CloudGuard Code...
Ranking in DevSecOps
8th
Average Rating
8.4
Reviews Sentiment
8.0
Number of Reviews
12
Ranking in other categories
Data Loss Prevention (DLP) (10th)
Snyk
Ranking in DevSecOps
1st
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
43
Ranking in other categories
Application Security Tools (4th), Container Security (7th), Software Composition Analysis (SCA) (3rd), Software Development Analytics (2nd)
 

Mindshare comparison

As of November 2024, in the DevSecOps category, the mindshare of Check Point CloudGuard Code Security is 3.6%, up from 1.4% compared to the previous year. The mindshare of Snyk is 31.4%, down from 33.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
DevSecOps
 

Featured Reviews

Nagendra Nekkala. - PeerSpot reviewer
Good security and functionality with helpful support
The security on offer is great. It's secure in terms of testing all the workloads. We can test across any workload or multiple clouds. It offers unified prevention. It also offers posture management by verifying proper scanning. We use the GSL builder. It's easy to write customer rules or policies using it. Of course, you do need proper training on the product first. It takes around one week to get trained. We've been able to reduce human error, and you can build the rules for better coverage. It provides functionality across cloud providers. The solution helps us save time. We've reduced the amount of time spent by 25%. Its unified security management console is a very complete dashboard. We can see all security threats and can gain visibility into what is happening. We have access to automation and can monitor the security of IT systems. The product offers role-based access control so that we can set up different privileges for admin users. Cloud Guard Spectrum is good for automating our organization's security across assets, workloads, and multiple clouds. With it, we have advanced pre-prevention across the cloud security network. It works for on-premises also. We can easily determine our organization's security posture. It will ensure my application's availability time across the enterprise. Network security helped us reduce our compliance and audit activities. We've saved about 20% of our time. Having a cloud detection response helps to very quickly identify security threats in our environment. It's automated so it saves us time. That way, people can work on other projects. On any given day, we're spending 20% less time in general worrying about detection and response. Our security operations are saving a lot of time using a unified platform.
Jayashree Acharyya - PeerSpot reviewer
Used for image scanning and identifying vulnerabilities, but its integration with other services could be improved
The solution has improved or streamlined our process a lot for securing container images. We wanted to make sure we are deploying the secure Docker images. Snyk allowed us to check whether it is following our standard of docker images or not. We use Azure DevOps as our platform, and Snyk's integration with Azure DevOps was okay. However, Snyk's integration with JFrog Artifactory didn't go well. We use JFrog Artifactory to store the artifacts we download. We wanted to integrate Snyk with JFrog Artifactory to scan the binary artifacts we downloaded, but that broke our JFrog Artifactory for some reason. Instead of using it there, we are calling it directly from the pipeline. Snyk's automation features significantly reduced remediation times a couple of times. Sometimes, our developers scan the code from the environment and find some Java vulnerabilities. We fixed those vulnerabilities in the lower environment itself. The solution does not require any maintenance. The accuracy of Snyk's vulnerability detection is pretty good compared to other tools. I rate the solution's vulnerability detection feature an eight out of ten. I would recommend Snyk to other users because it is easy to implement and integrate with Azure DevOps and GitHub. Overall, I rate the solution a seven out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Automation has helped a lot to identify and automatically execute policies, rules, and blocks due to its machine learning."
"Its fastest and most outstanding characteristic is ensuring a development line that will not lead to applying applications or code development."
"Compared to what we used before, it's helping us to be more efficient in managing our traffic."
"You can maintain a legal framework structure at all times."
"It helped us to reduce vulnerabilities."
"The data center security system has provided real-time analytics on performance and data configuration processes."
"Having a cloud detection response helps to very quickly identify security threats in our environment."
"Knowing what measures we must take allows us to reduce costs associated with security in the cloud by providing early identification of a risk or a possible security breach."
"The CLI feature is quite useful because it gives us a lot of flexibility in what we want to do. If you use the UI, all the information is there and you can see what Snyk is showing you, but there is nothing else that you can change. However, when you use the CLI, then you can use commands and can get the output or response back from Snyk. You can also take advantage of that output in a different way. For the same reason, we have been using the CLI for the hard gate in the pipeline: Obtain a particular CDSS score for vulnerability. Based on that information, we can then decide if we want to block or allow the build. We have more flexibility if we use the CLI."
"We're loving some of the Kubernetes integration as well. That's really quite cool. It's still in the early days of our use of it, but it looks really exciting. In the Kubernetes world, it's very good at reporting on the areas around the configuration of your platform, rather than the things that you've pulled in. There's some good advice there that allows you to prioritize whether something is important or just worrying. That's very helpful."
"The most valuable features of Snyk are vulnerability scanning and automation. The automation the solution brings around vulnerability scanning is useful."
"The product's most valuable features are an open-source platform, remote functionality, and good pricing."
"Snyk is a good and scalable tool."
"Snyk performs software composition analysis (SCA) similar to other expensive tools."
"What is valuable about Snyk is its simplicity."
"The solution has great features and is quite stable."
 

Cons

"It is generally difficult to find documentation about the product, and there is relatively little to find."
"This is a highly technical solution for users who do not have security experience. It requires specialized knowledge of configurations to use it correctly."
"I am satisfied with the performance and results enhanced by this product since we deployed it."
"We need to have many of the baselines or development guides providing less complex writing or development."
"There are a lot of opportunities for how they can use their technology to do more. That would be more like sensitive data discovery and other things besides Git Repos, but then you are expanding the scope of what necessarily their product is."
"There needs to be better security around API integration."
"The solution should improve false-positives."
"The ease of use could be better."
"There are some new features that we would like to see added, e.g., more visibility into library usage for the code. Something along the lines where it's doing the identification of where vulnerabilities are used, etc. This would cause them to stand out in the market as a much different platform."
"They were a couple of issues which happened because Snyk lacked some documentation on the integration side. Snyk is lacking a lot of documentation, and I would like to see them improve this. This is where we struggle a bit. For example, if something breaks, we can't figure out how to fix that issue. It may be a very simple thing, but because we don't have the proper documentation around an issue, it takes us a bit longer."
"Snyk's API and UI features could work better in terms of speed."
"The solution's reporting and storage could be improved."
"There is always more work to do around managing the volume of information when you've got thousands of vulnerabilities. Trying to get those down to zero is virtually impossible, either through ignoring them all or through fixing them. That filtering or information management is always going to be something that can be improved."
"The product is very expensive."
"The solution's integration with JFrog Artifactory could be improved."
"Compatibility with other products would be great."
 

Pricing and Cost Advice

"It is extremely affordable and high value for cost."
"The solution is less expensive than Black Duck."
"For what Snyk offers, it has the best cost-benefit I have ever seen because you're buying the license per user."
"Pricing-wise, it is not expensive as compared to other tools. If you have a couple of licenses, you can scan a certain number of projects. It just needs to be attached to them."
"Snyk is an expensive solution."
"You can get a good deal with Snyk for pricing. It's a little expensive, but it is worth it."
"We are using the open-source version for the scans."
"Cost-wise, it's similar to Veracode, but I don't know the exact cost."
"Despite Snyk's coverage, scalability, reliability, and stability, it is available at a very competitive price."
report
Use our free recommendation engine to learn which DevSecOps solutions are best for your needs.
816,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
25%
Financial Services Firm
17%
Government
12%
Manufacturing Company
9%
Financial Services Firm
15%
Computer Software Company
15%
Manufacturing Company
9%
Insurance Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Spectral?
We have had a number of real events where developers accidentally made commits of API keys, and we were able to detect and begin response actions in minutes. We had the API key revoked in less than...
What needs improvement with Spectral?
The solution should improve vulnerability in-depth, false-positive reduction, integration with other tools, performance optimization, and the user interface.
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to find any issues reported on the internet. It will store dependencies that you a...
What do you like most about Snyk?
The most effective feature in securing project dependencies stems from its ability to highlight security vulnerabilities.
What needs improvement with Snyk?
I'm not responsible for the tool. As far as I know, there are no major concerns or features that we lack. We had some issues integrating into our pipeline, however, they were resolved.
 

Comparisons

No data available
 

Also Known As

Spectral
No data available
 

Learn More

 

Overview

 

Sample Customers

Doddle, Bangalore International Airport, Grupo financiero ACOBO, DigitalTrack
StartApp, Segment, Skyscanner, DigitalOcean, Comic Relief
Find out what your peers are saying about Check Point CloudGuard Code Security vs. Snyk and other solutions. Updated: October 2024.
816,406 professionals have used our research since 2012.