Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Coverity
Average Rating
7.8
Number of Reviews
34
Ranking in other categories
Static Application Security Testing (SAST) (4th)
Snyk
Average Rating
8.2
Number of Reviews
42
Ranking in other categories
Application Security Tools (4th), Container Security (5th), Software Composition Analysis (SCA) (3rd), Software Development Analytics (2nd), DevSecOps (1st)
 

Mindshare comparison

As of June 2024, in the Static Application Security Testing (SAST) category, the mindshare of Coverity is 8.1%, up from 6.7% compared to the previous year. The mindshare of Snyk is 4.1%, down from 6.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
Unique Categories:
No other categories found
Application Security Tools
6.2%
Container Security
7.2%
 

Featured Reviews

IC
May 11, 2023
A good and stable solution that has significant software security feature for detecting potential risks
We actually specified several checkers, but we found some checkers had a higher false positive rate. I think this is a problem. Because we have to waste some time is really the issue because the issue is not an issue. I mean, the tool pauses or an issue, but the same issue is the filter now.Some check checkers cannot find some issues, but sometimes they find issues that are not relevant, right, that are not really issues. Some customisation mechanism can be added in the next release so that we can define our Checker. The Modelling feature provided by Coverity helps in finding more information for potential issues but it is not mature enough, it should be mature. The fast testing feature for security testing campaign can be added as well. So if you correctly integrate it with the training team, maybe you can help us to find more potential issues.
NH
May 28, 2024
Supports multiple programming languages for security practices
Snyk protects vulnerabilities in the code as usual, detects abnormal data flow inside the field, and similar tasks The specific feature of Snyk that has significantly improved my vulnerability management is its ability to identify vulnerabilities and suggest solutions to fix them. Snyk's…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We were very comfortable with the initial setup."
"Coverity is easy to set up and has a less lengthy process to find vulnerabilities."
"Provides software security, and helps to find potential security bugs or defects."
"One of the most valuable features is Contributing Events. That particular feature helps the developer understand the root cause of a defect. So you can locate the starting point of the defect and figure out exactly how it is being exploited."
"It's pretty stable. I rate the stability of Coverity nine out of ten."
"The product has deeper scanning capabilities."
"The solution has improved our code quality and security very well."
"I encountered a bug with Coverity, and I opened a ticket. Support provided me with a workaround. So it's working at the moment, or at least it seems to be."
"Snyk is a developer-friendly product."
"Snyk categorizes the level of vulnerability into high, medium, and low, which helps organizations prioritize which issues to tackle first."
"The solution has great features and is quite stable."
"It has an accurate database of vulnerabilities with a low amount of false positives."
"Snyk performs software composition analysis (SCA) similar to other expensive tools."
"We use Snyk to check vulnerabilities and rectify potential leaks in GitHub."
"Snyk's focus on security is a valuable feature. Also Snyk supports multiple programming languages, which has positively affected my security practices. I use only two or three languages, and when I change the language in a file, it detects it in the same suite. I find the AI-powered scanning overall beneficial.Using Snyk's AI-powered scanning, I can detect around ten or twenty errors in my project with about twenty thousand lines of code, so it helps improve my project by identifying a lot of potential vulnerabilities."
"Snyk is a good and scalable tool."
 

Cons

"Coverity takes a lot of time to dereference null pointers."
"SCM integration is very poor in Coverity."
"We actually specified several checkers, but we found some checkers had a higher false positive rate. I think this is a problem. Because we have to waste some time is really the issue because the issue is not an issue. I mean, the tool pauses or an issue, but the same issue is the filter now.Some check checkers cannot find some issues, but sometimes they find issues that are not relevant, right, that are not really issues. Some customisation mechanism can be added in the next release so that we can define our Checker. The Modelling feature provided by Coverity helps in finding more information for potential issues but it is not mature enough, it should be mature. The fast testing feature for security testing campaign can be added as well. So if you correctly integrate it with the training team, maybe you can help us to find more potential issues."
"The setup takes very long."
"Reporting engine needs to be more robust."
"They could improve the usability. For example, how you set things up, even though it's straightforward, it could be still be easier."
"Coverity could improve the ease of use. Sometimes things become difficult and you need to follow the guides from the website but the guides could be better."
"The product should include more customization options. The analytics is not as deep as compared to SonarQube."
"I think Snyk should add more of a vulnerability protection feature in the tool since it is an area where it lacks."
"The documentation sometimes is not relevant. It does not cover the latest updates, scanning, and configurations. The documentation for some things is wrong and does not cover some configuration scannings for the multiple project settings."
"A feature we would like to see is the ability to archive and store historical data, without actually deleting it. It's a problem because it throws my numbers off. When I'm looking at the dashboard's current vulnerabilities, it's not accurate."
"They need to improve the Snyk plugins and make it easier to make your optimizations based on your own needs or features."
"There is always more work to do around managing the volume of information when you've got thousands of vulnerabilities. Trying to get those down to zero is virtually impossible, either through ignoring them all or through fixing them. That filtering or information management is always going to be something that can be improved."
"DAST has shortcomings, and Snyk needs to improve and overcome such shortcomings."
"Snyk's API and UI features could work better in terms of speed."
"The solution's integration with JFrog Artifactory could be improved."
 

Pricing and Cost Advice

"Coverity is quite expensive."
"This is a pretty expensive solution. The overall value of the solution could be improved if the price was reduced. Licensing is done on an annual basis."
"Offers varying prices for different companies"
"I would rate the tool's pricing a one out of ten."
"The tool was fairly priced."
"The pricing is very reasonable compared to other platforms. It is based on a three year license."
"The licensing fees are based on the number of lines of code."
"The price is competitive with other solutions."
"It's good value. That's the primary thing. It's not cheap-cheap, but it's good value."
"Presently, my company uses an open-source version of the solution. The solution's pricing can be considered quite reasonable owing to the features they offer."
"With Snyk, you get what you pay for. It is not a cheap solution, but you get a comprehensiveness and level of coverage that is very good. The dollars in the security budget only go so far. If I can maximize my value and be able to have some funds left over for other initiatives, I want to do that. That is what drives me to continue to say, "What's out there in the market? Snyk's expensive, but it's good. Is there something as good, but more affordable?" Ultimately, I find we could go cheaper, but we would lose the completeness of vision or scope. I am not willing to do that because Snyk does provide a pretty important benefit for us."
"The product has good pricing."
"I didn't think the price was that great, but it wasn't that bad, either. I'd rate their pricing as average in the market."
"We are using the open-source version for the scans."
"The price is good. Snyk had a good price compared to the competition, who had higher pricing than them. Also, their licensing and billing are clear."
"It's inexpensive and easy to license. It comes in standard package sizing, which is straightforward. This information is publicly found on their website."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
29%
Computer Software Company
16%
Financial Services Firm
7%
Government
4%
Computer Software Company
15%
Financial Services Firm
15%
Manufacturing Company
8%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What do you like most about Coverity?
The solution has improved our code quality and security very well.
What is your experience regarding pricing and costs for Coverity?
Coverity offers varying prices for different companies. Our company has a five-year licensing contract with Coverity, so the licensing posture is seamless. As our organization is based in Banglades...
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to find any issues reported on the internet. It will store dependencies that you a...
What do you like most about Snyk?
The most effective feature in securing project dependencies stems from its ability to highlight security vulnerabilities.
What needs improvement with Snyk?
I don't use Snyk anymore. The tool is just used in our company, but not by me anymore. It is important that the solution has the ability to match up with the OWASP Top 10 list, especially consideri...
 

Comparisons

 

Also Known As

Synopsys Static Analysis
No data available
 

Learn More

 

Overview

 

Sample Customers

MStar Semiconductor, Alcatel-Lucent
StartApp, Segment, Skyscanner, DigitalOcean, Comic Relief
Find out what your peers are saying about Coverity vs. Snyk and other solutions. Updated: September 2022.
787,779 professionals have used our research since 2012.