London-based Snyk, which makes tools to help developers fix vulnerabilities in open source code, raises $7M Series A and says it has 350K monthly downloads
Open source libraries provide a tremendously valuable resource for developers, but in today's rapid fire application development environment …
Context & Ripple Effects
This March 2018 round is the bottom rung of one of the steepest valuation ladders in developer security: six months later Snyk raised a $22M Series B led by Accel at a reported $100M valuation, then crossed into unicorn territory with a $150M round led by Stripes at a $1B+ valuation in January 2020.
The through-line across that coverage is constant — fixing vulnerabilities in open source dependencies and containers — while the valuation compounds from $100M to a reported $8.5B by September 2021. The $7M Series A and its 350K monthly downloads mark the moment the developer-adoption flywheel was first quantified.
First-order effects
- With fresh capital and 350K monthly downloads already in hand, Snyk can fund engineering around its core open-source vulnerability fixer and push deeper into the containers work its later rounds formalized.
- Accel's early position sets up its lead role in the September 2018 Series B, converting this seed-stage bet into a repeated franchise across every subsequent round.
Second-order effects
- Enterprise security incumbents face a competitor distributed through the developer's own workflow — npm-style downloads rather than sales-led procurement — forcing them to add open-source scanning to their suites.
- Each successive raise (the $70M Accel-led round, the $200M at $2.6B, the twin $300M rounds) pressures rival dev-security startups to either match the funding pace or consolidate.
Third-order effects
- If the pattern holds, application security migrates from periodic audit to continuous, automated remediation inside the build pipeline — the closed-loop model where detection and fix happen in the same toolchain.
- Open-source dependency risk becomes a board-level budget line, with platforms like Snyk positioned as the default control point between developers and the libraries they ship.
The trend: Developer-first application security is compounding from niche open-source scanners into multi-billion-dollar platforms, with each funding round widening the gap between integrated remediation tools and standalone audit products.