FossID Workbench vs. Snyk

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
FossID Workbench
Score 0.0 out of 10
Enterprise companies (1,001+ employees)
FossID supports software auditing and compliance. FossID’s Software Composition Analysis (SCA) tool, Workbench, and professional services are designed to ensure comprehensive open source compliance and security in software development. Software Composition Analysis (SCA) FossID Workbench enables precise identification of open source components and vulnerabilities. It integrates into software development cycles, providing license recognition, proactive…N/A
Snyk
Score 8.9 out of 10
N/A
Snyk’s Developer Security Platform automatically integrates with a developer’s workflow and helps security teams to collaborate with their development teams. It boasts a developer-first approach that ensures organizations can secure all of the critical components of their applications from code to cloud, driving developer productivity, revenue growth, customer satisfaction, cost savings and an improved security posture. The vendor states Snyk is used by 1,200 customers worldwide today, including…
$0
Pricing
FossID WorkbenchSnyk
Editions & Modules
No answers on this topic
Free
$0
Team (Snyk Open Source or Snyk Container or Snyk Infrastructure as Code)
$23
per month per user
Business (Snyk Open Source or Snyk Container or Snyk Infrastructure as Code)
$42
per month per user
Team (Snyk Open Source + Snyk Container + Snyk Code + Snyk Infrastructure as Code)
$98
per month per user
Business (Snyk Open Source + Snyk Container + Snyk Code + Snyk Infrastructure as Code)
$178
per month per user
Enterprise
Contact Sales
Offerings
Pricing Offerings
FossID WorkbenchSnyk
Free Trial
NoYes
Free/Freemium Version
NoYes
Premium Consulting/Integration Services
YesNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional DetailsFossID pricing considers several factors such as number of contributors, type of deployment, add-ons, and success accelerator services.Pricing is dependent on the number of developers selected, the number of products selected, and the payment term selected. Please visit the Snyk plans page for an interactive pricing calculator.
More Pricing Information
Community Pulse
FossID WorkbenchSnyk
Best Alternatives
FossID WorkbenchSnyk
Small Businesses

No answers on this topic

No answers on this topic

Medium-sized Companies
Veracode
Veracode
Score 9.2 out of 10
Veracode
Veracode
Score 9.2 out of 10
Enterprises
Veracode
Veracode
Score 9.2 out of 10
Veracode
Veracode
Score 9.2 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
FossID WorkbenchSnyk
Likelihood to Recommend
-
(0 ratings)
8.5
(6 ratings)
Usability
-
(0 ratings)
9.0
(2 ratings)
User Testimonials
FossID WorkbenchSnyk
Likelihood to Recommend
FossID
No answers on this topic
Snyk
Scenarios Where Snyk Is Well-Suited CI/CD Pipeline Integration (Node.js, Python, etc.) Container Security Open Source License Compliance Infrastructure as Code (IaC) SecurityScenarios Where Snyk May Be Less Appropriate Scanning Proprietary or Custom Code for Unknown Vulnerabilities Complex Monorepos with Custom Build Tools Organizations Requiring Custom Security Rules Advanced Security Teams Needing Correlation and Deep Triage.
Read full review
Pros
FossID
No answers on this topic
Snyk
  • Helps in dependency management
  • SAST - Static Application Security Testing
  • Infra Code Scan ( Terraform , Cloud Formation , Docker image scan)
  • OSSG
Read full review
Cons
FossID
No answers on this topic
Snyk
  • The tool itself has many capabilities but using them operationally within the platform on a day to day basis for managing vulnerabilities is not a good experience.
  • Our company was in desparate need of a tool to help us manage vulnerabilities so we could achieve a SOC 2 assurance report without findings.
Read full review
Usability
FossID
No answers on this topic
Snyk
Developer-Centric Design - Snyk integrates directly into IDEs (like VS Code and IntelliJ), CI/CD pipelines, GitHub/GitLab, and container registries. Clear, Actionable Vulnerability report issues are categorized by severity.


Reports include fix recommendations, pull request suggestions, and links to remediation advice.
Read full review
Alternatives Considered
FossID
No answers on this topic
Snyk
Unfortunately, neither cover all of the use cases that we would like so we need to use both but they are both excellent tools as part of our vulnerability management. We find that Snyk helps us better with improving our MTTR of identified vulnerabilities when compared to inspector but that may be more based on how we have implemented both tools
Read full review
Return on Investment
FossID
No answers on this topic
Snyk
  • Increased developer experience
  • Better productivity due to shift left as Vulnerabilities are caught earlier in the SDLC process
  • Improved Vulnerability Management
  • Common dashboard for various stages in CI/CD
Read full review
ScreenShots

FossID Workbench Screenshots

Screenshot of a scan of repositories that detects all Free and Open Source Software (FOSS) from complete components, packages, and libraries to small snippets of open source.Screenshot of a Software Bill of Materials (SBOMs). FossID Workbench can automatically export and import Software Package Data Exchange (SPDX) reports containing license text, copyright statements, vulnerabilities and even snippet level information.Screenshot of a presentation of license-related risks in software that helps to remain compliant. Workbench detects over 2000 different licenses encountered overed years of open source auditing from strong/weak copyleft to the most obscure source-available and non-commercial licenses. Workbench helps users to understand all license related risks that could affect your products and services.Screenshot of Workbench’s comprehensive policy management that can prevent usage of strong/weak copyleft or source-available software licenses in products and services.Screenshot of VulnSnippet Finder: Snippet detection for vulnerable open source snippets. FossID’s Knowledge Base snippet detection capabilities include special detection of vulnerable open source snippets. While most security scanners assume open source vulnerabilities based on component and version, VulnSnippet Finder bases its search on the exact lines of code/snippets that make software vulnerable.