No more typing reviews! Try our Samantha, our new voice AI agent.

OpenText Static Application Security Testing vs Snyk comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.8
OpenText Static Application Security Testing received mixed reviews, praising cost savings and partnerships, but highlighting challenges in quantifying ROI.
Sentiment score
6.3
Snyk users drastically reduced vulnerabilities and improved efficiency, saving costs and enhancing productivity and risk management with minimal expense.
On average, we reduced the mean time to fix security issues by roughly 40 to 50% for the classes of vulnerabilities Snyk surfaced, which shortened our exposure window and reduced rework during upgrades.
Ai Research Enthusiast And Developer at ADP
I can see that Snyk saves the costs of hiring security developers for vulnerability scanning and security checks, as that responsibility is now managed by Snyk.
Software Engineer at a computer software company with 11-50 employees
 

Customer Service

Sentiment score
6.7
Generally positive with dedicated teams, though some seek improvements in ticket system and responsiveness for OpenText support.
Sentiment score
7.5
Snyk's support is effective and responsive, with direct engineer access, but some users desire faster response times.
The customer service and support for Fortify Static Code Analyzer are better than those for LoadRunner.
CTO at Marco Technology
The technical support has been good because we always received answers to our questions.
Manager at DTEK
Our long-standing association has ensured smooth communication, resulting in favorable support experiences and satisfactory issue resolution.
CEO at a computer software company with 10,001+ employees
Their response time aligns with their SLA commitments.
Information Security Strategy at a insurance company with 10,001+ employees
We could understand the implementation of the product and other features without the need for human interaction.
Senior DevSecOps at V8
 

Scalability Issues

Sentiment score
7.8
OpenText SAST is scalable for various project sizes but needs improvement in speed and infrastructure management.
Sentiment score
7.3
Snyk is scalable and adaptable, integrating seamlessly with repositories while supporting large-scale deployments and organizational security needs.
Fortify Static Code Analyzer integrates well and is scalable.
CTO at Marco Technology
Snyk allows for scaling across large organizations, accommodating tens of thousands of applications and over 60,000 repositories.
CEO at a computer software company with 10,001+ employees
Snyk is very scalable and can handle my organization's growth and changing needs.
Software Engineer at a computer software company with 11-50 employees
As the number of applications and upgrades grows, it continues to fit into our workflow without adding much overhead.
Ai Research Enthusiast And Developer at ADP
 

Stability Issues

Sentiment score
7.5
OpenText Static Application Security Testing is reliable and stable, with improvements since version 19.10, and benefits from proper training.
Sentiment score
7.8
Users commend Snyk's stability and reliability, citing minor issues, documentation challenges, and responsive customer support across deployments.
The stability of Fortify Static Code Analyzer is generally good.
CTO at Marco Technology
I would rate the product stability as an eight.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
Snyk has been stable in our environment, and I have used it consistently during upgrades and security remediation work.
Ai Research Enthusiast And Developer at ADP
 

Room For Improvement

OpenText SAST faces high costs, complex use, false positives, and needs better integration, language support, and feature enhancements.
Snyk needs better integration, broader language support, enhanced performance, improved UI, precise detection, and comprehensive documentation and training.
We would appreciate if the AI could give us more information about improvements and reduce the number of false positives, but this solution doesn't have this function yet.
Manager at DTEK
It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers.
CTO at Marco Technology
It would be really helpful to include trending vulnerabilities and how to manage them.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
It lacks the ability to select branches on its Web UI, forcing users to rely on CLI or CI/CD for that functionality.
CEO at a computer software company with 10,001+ employees
The inclusion of AI to remove false positives would be beneficial.
Director at Marsh
As we are moving toward GenAI, we expect Snyk to leverage AI features to improve code scanning findings.
Information Security Strategy at a insurance company with 10,001+ employees
 

Setup Cost

Enterprise users find OpenText Static Application Security Testing's pricing high but consider it economical compared to other major solutions.
Snyk offers competitive enterprise pricing with scalable solutions and negotiable deals, despite being premium compared to similar tools.
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs.
CTO at Marco Technology
My experience with the pricing, setup costs, and licensing has been good.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
Snyk is recognized as the cheapest option we have evaluated.
CEO at a computer software company with 10,001+ employees
After negotiations, we received a special package with a good price point.
Information Security Strategy at a insurance company with 10,001+ employees
Snyk is less expensive.
Senior DevSecOps at V8
 

Valuable Features

OpenText SAST enhances security by automating vulnerability detection, integrating across tools, and providing detailed remediation and compliance guidance.
Snyk efficiently manages vulnerabilities with robust tools, integration, and automation, enhancing security and productivity for organizations.
Fortify Static Code Analyzer has the capability of giving fewer false positives compared to other tools.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
The most valuable feature of Fortify Static Code Analyzer is its extensive language support, covering many languages from legacy ones to the newest.
CTO at Marco Technology
The most impactful feature of Fortify Static Code Analyzer in identifying vulnerabilities is the ratio of total number of vulnerabilities to false positives.
Manager at DTEK
Our integration of Snyk into GitHub allows us to automatically scan codebases and identify issues, which has improved efficiency.
CEO at a computer software company with 10,001+ employees
Snyk helps detect vulnerabilities before code moves to production, allowing for integration with DevOps and providing a shift-left advantage by identifying and fixing bugs before deployment.
Director at Marsh
Snyk has positively impacted my organization by improving the security posture across all software repositories, resulting in fewer critical vulnerabilities, more confidence in overall product security, and faster security compliance for project clients.
Software Engineer at a computer software company with 11-50 employees
 

Categories and Ranking

OpenText Static Application...
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
19
Ranking in other categories
Static Code Analysis (8th)
Snyk
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
52
Ranking in other categories
Application Performance Monitoring (APM) and Observability (19th), Application Security Tools (7th), Static Application Security Testing (SAST) (5th), Container Security (7th), Software Composition Analysis (SCA) (1st), Cloud Security Posture Management (CSPM) (13th), DevSecOps (4th), Application Security Posture Management (ASPM) (1st), AI Security (9th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. OpenText Static Application Security Testing is designed for Static Code Analysis and holds a mindshare of 4.3%, down 10.1% compared to last year.
Snyk, on the other hand, focuses on Application Security Tools, holds 5.0% mindshare, down 6.8% since last year.
Static Code Analysis Mindshare Distribution
ProductMindshare (%)
OpenText Static Application Security Testing4.3%
Veracode10.6%
Checkmarx One8.4%
Other76.7%
Static Code Analysis
Application Security Tools Mindshare Distribution
ProductMindshare (%)
Snyk5.0%
SonarQube10.8%
Checkmarx One7.3%
Other76.9%
Application Security Tools
 

Featured Reviews

DK
Lead Information Security Analyst at a financial services firm with 10,001+ employees
Focuses on detailed scans to find critical vulnerabilities while ensuring minimal false positives
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less than the current latest version. It would be really helpful to include trending vulnerabilities and how to manage them. While it includes all the OWASP top factors, AI has come into the picture, so those updates should also be considered. I haven't thought much about additional features for improvement since I am using it daily. Most of our work revolves around scanning and providing the results, which sometimes feels like a crunch. However, I believe rule pack updates should be implemented. It feels easy to upgrade to the latest version as well.
Abhishek-Goyal - PeerSpot reviewer
Software Engineer at a computer software company with 11-50 employees
Improves security posture by actively reducing critical vulnerabilities and guiding remediation
Snyk's main features include open-source vulnerability scanning, code security, container security, infrastructure as code security, risk-based prioritization, development-first integration, continuous monitoring and alerting, automation, and remediation. The best features I appreciate are the vulnerability checking, vulnerability scanning, and code security capabilities, as Snyk scans all open-source dependencies for known vulnerabilities and helps with license compliance for open-source components. Snyk integrates into IDEs, allowing issues to be caught as they appear in the code dynamically and prioritizes risk while providing remediation advice. Snyk provides actionable remediation advice on where vulnerabilities can exist and where code security is compromised, automatically scanning everything and providing timely alerts. Snyk has positively impacted my organization by improving the security posture across all software repositories, resulting in fewer critical vulnerabilities, more confidence in overall product security, and faster security compliance for project clients. Snyk has helped reduce vulnerabilities significantly. Initially, the repository had 17 to 31 critical and high vulnerabilities, but Snyk has helped manage them down to just five vulnerabilities, which are now lower and not high or critical.
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
911,769 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
25%
Computer Software Company
9%
Manufacturing Company
9%
Government
7%
Financial Services Firm
13%
Manufacturing Company
10%
Computer Software Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise3
Large Enterprise11
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise10
Large Enterprise24
 

Questions from the Community

What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
My experience with the pricing, setup costs, and licensing has been good. We have the scan machines, and we are planning to request more from Micro Focus now. We have calls every month or every oth...
What needs improvement with Fortify Static Code Analyzer?
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less ...
What is your primary use case for Fortify Static Code Analyzer?
Our main use cases for Fortify Static Code Analyzer typically involve trying to figure out the critical vulnerabilities. It depends on the type of scans that we are doing, whether it is a release s...
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to find any issues reported on the internet. It will store dependencies that you a...
What needs improvement with Snyk?
There are a lot of false positives that need to be identified and separated. The inclusion of AI to remove false positives would be beneficial. So far, I've not seen any AI features to enhance vuln...
What is your primary use case for Snyk?
I use Snyk ( /products/snyk-reviews ) in the DevOps pipeline to identify vulnerabilities before deploying the application. It integrates with Jenkins ( /products/jenkins-reviews ).
 

Also Known As

Fortify Static Code Analysis SAST
Fugue, Snyk AppRisk
 

Overview

 

Sample Customers

Information Not Available
StartApp, Segment, Skyscanner, DigitalOcean, Comic Relief
Find out what your peers are saying about Veracode, Checkmarx, Perforce and others in Static Code Analysis. Updated: August 2026.
911,769 professionals have used our research since 2012.