Try our new research platform with insights from 80,000+ expert users

Fortify Static Code Analyzer vs Snyk comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.3
Fortify Static Code Analyzer delivers cost savings by mitigating risks early, providing returns up to twenty times the investment.
Sentiment score
6.8
Snyk enhances developer efficiency by quickly identifying and fixing vulnerabilities, though ROI varies across organizations.
 

Customer Service

Sentiment score
6.6
Fortify Static Code Analyzer's customer service is praised for helpfulness but needs improvement in response times and efficiency.
Sentiment score
7.5
Snyk’s support is praised for responsiveness and skill, with customers appreciating clear documentation and dedicated Customer Success Managers.
Our long-standing association has ensured smooth communication, resulting in favorable support experiences and satisfactory issue resolution.
 

Scalability Issues

Sentiment score
7.9
Fortify Static Code Analyzer is scalable for large codebases, integrates with DevOps, and supports enterprise software with high satisfaction.
Sentiment score
7.6
Snyk is a scalable, lightweight solution praised for seamless integration and adaptability, despite slower processing with multiple vulnerabilities.
Snyk allows for scaling across large organizations, accommodating tens of thousands of applications and over 60,000 repositories.
 

Stability Issues

Sentiment score
7.5
Fortify Static Code Analyzer is stable with improved reliability; performance depends on hardware, network, and proper training adherence.
Sentiment score
8.0
Snyk is stable with minimal downtime, praised support, though limited documentation and integration can cause minor issues.
 

Room For Improvement

Fortify Static Code Analyzer needs improved language support, integration, configuration, user-friendliness, and prioritization to reduce costs and complexity.
Snyk users seek better language support, UI, integration, documentation, IDE plugins, customer support, cost-efficiency, and compatibility enhancements.
It lacks the ability to select branches on its Web UI, forcing users to rely on CLI or CI/CD for that functionality.
 

Setup Cost

Fortify Static Code Analyzer is costly but offers comprehensive enterprise features, with deployment based on developer count.
Snyk offers competitive enterprise pricing with clear licensing, justified by comprehensive features and flexibility in project usage.
Snyk is recognized as the cheapest option we have evaluated.
 

Valuable Features

Fortify Static Code Analyzer enhances security with seamless integration, intuitive GUI, real-time feedback, and strong support for developers.
Snyk offers seamless integration, accurate vulnerability detection, and automation to enhance security with a strong developer focus.
Our integration of Snyk into GitHub allows us to automatically scan codebases and identify issues, which has improved efficiency.
 

Categories and Ranking

Fortify Static Code Analyzer
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
16
Ranking in other categories
Static Code Analysis (3rd)
Snyk
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
44
Ranking in other categories
Application Security Tools (4th), Container Security (7th), Software Composition Analysis (SCA) (3rd), Software Development Analytics (2nd), DevSecOps (1st)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Fortify Static Code Analyzer is designed for Static Code Analysis and holds a mindshare of 25.1%, up 19.9% compared to last year.
Snyk, on the other hand, focuses on Application Security Tools, holds 7.9% mindshare, down 8.2% since last year.
Static Code Analysis
Application Security Tools
 

Featured Reviews

Vishal Dhamke - PeerSpot reviewer
An expansive platform that comes with a comprehensive set of security rules and patterns to identify vulnerabilities
Setting up Fortify Static Application Security Testing (SAST) involves several steps to ensure that the tool is correctly configured and integrated into your development workflow say for instance Installation, License Activation, User Access and Permissions, Integration with Development Environment, Project Configuration, Custom Rules and Policies, etc. The initial setup is very easy, have used the enterprise version and a standalone version. The enterprise version definitely takes an ample amount of time to deploy because it needs to have a server along with other logistics in place along with a proper RBAC. The enterprise version would take an ample amount of time, but the standard version is just a few clicks. A team of four to five people is required for the maintenance and frequent updates are required to keep all the signatures up to date. I would rate the setup a nine out of ten.
meetharoon - PeerSpot reviewer
Affordable tool boosts code scanning efficiency but faces integration hurdles
The most important feature of Snyk is its cost-effectiveness compared to other solutions such as Check Point. It is easy to consolidate Snyk across multiple entities within a large organization. Additionally, our integration of Snyk into GitHub allows us to automatically scan codebases and identify issues, which has improved efficiency.
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
831,020 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
30%
Computer Software Company
13%
Manufacturing Company
10%
Government
6%
Financial Services Firm
16%
Computer Software Company
15%
Manufacturing Company
9%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
I rate the pricing of Fortify Static Code Analyzer as a seven out of ten since it is a bit expensive.
What needs improvement with Fortify Static Code Analyzer?
False positives need improvement in the future. Fortify's vulnerability remediation guidance helps improve code security, but I think they need to improve the focus of the solution, as it still Con...
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to find any issues reported on the internet. It will store dependencies that you a...
What do you like most about Snyk?
The most effective feature in securing project dependencies stems from its ability to highlight security vulnerabilities.
What needs improvement with Snyk?
Snyk has several limitations, including issues with Gradle, NPM, and Xcode, and trouble with AutoPR. It lacks the ability to select branches on its Web UI, forcing users to rely on CLI or CI/CD for...
 

Also Known As

Fortify Static Code Analysis SAST
No data available
 

Learn More

 

Overview

 

Sample Customers

Information Not Available
StartApp, Segment, Skyscanner, DigitalOcean, Comic Relief
Find out what your peers are saying about Veracode, Checkmarx, OpenText and others in Static Code Analysis. Updated: January 2025.
831,020 professionals have used our research since 2012.