TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Checkmarx

    Score7.6 out of 10
    N/ACheckmarx, an Israeli headquartered company with US offices, provides a suite of application security software delivered via the Checkmarx Software Security Platform. Individual modules and capabilities include Checkmarx Static Application Security Testing, Checkmarx Software Composition Analysis, Checkmarx Interactive Application Security Testing (CxIAST)N/A

    Fortify by OpenText

    Score9 out of 10
    N/AAn AppSec solution formerly from Micro Focus, spanning SCA, SAST and DAST that supports the breadth and management of any application portfolio, used to secure code. Features API discovery and testing for any application, throughout the software lifecycle.N/A

    Snyk

    Score8.4 out of 10
    N/ASnyk’s Developer Security Platform automatically integrates with a developer’s workflow and helps security teams to collaborate with their development teams. It boasts a developer-first approach that ensures organizations can secure all of the critical components of their applications from code to cloud, driving developer productivity, revenue growth, customer satisfaction, cost savings and an improved security posture. The vendor states Snyk is used by 1,200 customers worldwide today, including…

    $0

    Pricing
    CheckmarxFortify by OpenTextSnyk
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Free
    $0
    Team (Snyk Open Source or Snyk Container or Snyk Infrastructure as Code)
    $23
    per month per user
    Business (Snyk Open Source or Snyk Container or Snyk Infrastructure as Code)
    $42
    per month per user
    Team (Snyk Open Source + Snyk Container + Snyk Code + Snyk Infrastructure as Code)
    $98
    per month per user
    Business (Snyk Open Source + Snyk Container + Snyk Code + Snyk Infrastructure as Code)
    $178
    per month per user
    Enterprise
    Contact Sales
    Offerings
    Pricing Offerings
    CheckmarxFortify by OpenTextSnyk
    Free Trial
    NoNoYes
    Free/Freemium Version
    NoNoYes
    Premium Consulting/Integration Services
    NoNoNo
    Entry-level Setup FeeNo setup feeNo setup feeNo setup fee
    Additional DetailsPricing is dependent on the number of developers selected, the number of products selected, and the payment term selected. Please visit the Snyk plans page for an interactive pricing calculator.
    More Pricing Information
    Community Pulse
    CheckmarxFortify by OpenTextSnyk
    Considered Multiple Products
    Checkmarx
    No answer on this topic
    OpenText
    Chose Fortify by OpenText
    Micro Focus Fortify WebInspect is better when it comes to speed, integration and detection capabilities as compared to Insight Appsec. What I loved the most is the broad coverage of vulnerabilities it identified as against Insight Appsec. Apart from detection capabilities the …
    Incentivized
    Snyk
    No answer on this topic
    Key User Insights
    Would buy again
    No answers on this topic
    100%
    Would buy again
    6 Answers
    100%
    Would buy again
    6 Answers
    Delivers good value for the price
    No answers on this topic
    100%
    Delivers good value for the price
    6 Answers
    No answers on this topic
    Happy with the feature set
    No answers on this topic
    100%
    Happy with the feature set
    6 Answers
    100%
    Happy with the feature set
    6 Answers
    Lived up to sales and marketing promises
    No answers on this topic
    100%
    Lived up to sales and marketing promises
    5 Answers
    No answers on this topic
    Implementation went as expected
    No answers on this topic
    100%
    Implementation went as expected
    5 Answers
    No answers on this topic
    Best Alternatives
    CheckmarxFortify by OpenTextSnyk
    Small Businesses
    Rencore Code (SPCAF)
    Score8.8 out of 10
    No answers on this topic
    No answers on this topic
    Medium-sized Companies
    Trend Vision One Email and Collaboration Security
    Score9.9 out of 10
    No answers on this topic
    No answers on this topic
    Enterprises
    Trend Vision One Email and Collaboration Security
    Score9.9 out of 10
    No answers on this topic
    No answers on this topic
    All AlternativesView all alternativesView all alternativesView all alternatives
    User Ratings
    CheckmarxFortify by OpenTextSnyk
    Likelihood to Recommend
    8.3
    (5 ratings)
    9.0
    (6 ratings)
    8.5
    (6 ratings)
    Likelihood to Renew
    -
    (0 ratings)
    10.0
    (1 ratings)
    -
    (0 ratings)
    Usability
    7.7
    (2 ratings)
    7.0
    (1 ratings)
    9.0
    (2 ratings)
    Support Rating
    -
    (0 ratings)
    10.0
    (1 ratings)
    -
    (0 ratings)
    User Testimonials
    CheckmarxFortify by OpenTextSnyk
    Likelihood to Recommend
    Checkmarx
    If you are going with SAST process or want to improve overall security posture then go for it like integrating it with post deployment steps. If you are more concerned about proactive controls better choose other options such as pee-commit hooks and CI security. Also choose other tools for DAST and API scans.
    Incentivized
    Read full review
    OpenText
    It is best suited for runtime application security scanning and very useful for automation. You can seemlessly integrate with pipeline for dynamic scans. Cloud based apps can also be scanned for vulnerabilities, cross site scripting attacks. Basically all OWASP TOP 10. It is less appropriate to use if you have serverless architecture
    Incentivized
    Read full review
    Snyk
    Scenarios Where Snyk Is Well-Suited CI/CD Pipeline Integration (Node.js, Python, etc.) Container Security Open Source License Compliance Infrastructure as Code (IaC) SecurityScenarios Where Snyk May Be Less Appropriate Scanning Proprietary or Custom Code for Unknown Vulnerabilities Complex Monorepos with Custom Build Tools Organizations Requiring Custom Security Rules Advanced Security Teams Needing Correlation and Deep Triage.
    Incentivized
    Read full review
    Pros
    Checkmarx
    • Detects security vulnerabilities in source code with accuracy and detail.
    • Integrates seamlessly with CI/CD pipelines, IDEs, and repositories.
    • Provides clear reports and actionable fix recommendations for developers.
    Incentivized
    Read full review
    OpenText
    • DAST Scanning
    • API Scanning
    • Less detection of false positive
    Incentivized
    Read full review
    Snyk
    • Helps in dependency management
    • SAST - Static Application Security Testing
    • Infra Code Scan ( Terraform , Cloud Formation , Docker image scan)
    • OSSG
    Incentivized
    Read full review
    Cons
    Checkmarx
    • Scan duration
    • False positives
    • Integration with other tools like Jenkins comes with some inconveniences.
    Incentivized
    Read full review
    OpenText
    • Reporting could be better
    • Can be an involved setup if your organization is not using common build tools
    • Users get spammed with a lot of email updates from the service
    Incentivized
    Read full review
    Snyk
    • The tool itself has many capabilities but using them operationally within the platform on a day to day basis for managing vulnerabilities is not a good experience.
    • Our company was in desparate need of a tool to help us manage vulnerabilities so we could achieve a SOC 2 assurance report without findings.
    Incentivized
    Read full review
    Likelihood to Renew
    Checkmarx
    No answers on this topic
    OpenText
    Since every firm needs to perform static code analysis on their applications, I believe Micro Focus Fortify WebInspect would work well for them (they also offer dynamic scanning, although I haven't used it myself). Different static analysis tools scan code in different ways, and Micro Focus Fortify WebInspect asks you to submit a complete build of the application along with debugging files. Depending on how your company builds its apps, this requirement may be simple or challenging.
    Incentivized
    Read full review
    Snyk
    No answers on this topic
    Usability
    Checkmarx
    Their API based customizations which I leveraged to create an ASPM package, which is developer friendly and can extend above the dashboard features, other ones are UI which is great and feels clutter free. Menu and navigation is also good so as support. Only drawback is sometimes scan takes longer which I feel so can be reduced
    Incentivized
    Read full review
    OpenText
    It is a cloud-based platform which can provide us a very useful and unique features like Application Assessment, Scans, Vulnerability Test, Comprehensive Reporting, Monitoring, etc. Fortify by Open Text is also outstanding in various parameters for the support and integration and it is highly adaptable in various DevOps Program where you need secure app testing with all given features.
    Incentivized
    Read full review
    Snyk
    Developer-Centric Design - Snyk integrates directly into IDEs (like VS Code and IntelliJ), CI/CD pipelines, GitHub/GitLab, and container registries. Clear, Actionable Vulnerability report issues are categorized by severity.


    Reports include fix recommendations, pull request suggestions, and links to remediation advice.
    Incentivized
    Read full review
    Support Rating
    Checkmarx
    No answers on this topic
    OpenText
    Always receive excellent support from the vendor. No issues there.
    Incentivized
    Read full review
    Snyk
    No answers on this topic
    Alternatives Considered
    Checkmarx
    Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into our development process, offering faster scans and more useful suggestions for fixing problems
    Incentivized
    Read full review
    OpenText
    Fortify Application Defender is a little more timely and upfront with a lot of their information on cyber security. we like what they provide and how they communicate with our users. I think they have a good understanding and practice in their field. they seem best suited for us and the best fit.
    Incentivized
    Read full review
    Snyk
    Unfortunately, neither cover all of the use cases that we would like so we need to use both but they are both excellent tools as part of our vulnerability management. We find that Snyk helps us better with improving our MTTR of identified vulnerabilities when compared to inspector but that may be more based on how we have implemented both tools
    Incentivized
    Read full review
    Return on Investment
    Checkmarx
    • Improved ability to provide high level of IA confidence
    • Improved confidence in application-level security
    Incentivized
    Read full review
    OpenText
    • DevSecOps helped in reducing efforts
    • License cost was less
    • We could roll out double the count of applications with implementation of WebInspect
    Incentivized
    Read full review
    Snyk
    • Increased developer experience
    • Better productivity due to shift left as Vulnerabilities are caught earlier in the SDLC process
    • Improved Vulnerability Management
    • Common dashboard for various stages in CI/CD
    Incentivized
    Read full review
    ScreenShots