--- title: Semgrep Reviews meta\_title: 'Semgrep Reviews 2026: Details, Pricing, & Features | G2' meta\_description: Filter 56 reviews by the users' company size, role or industry to find out how Semgrep works for a business like yours. aggregate\_rating: rating\_value: 4.6 review\_count: 56 scale: '5' date\_modified: '2026-08-18' parent\_category: name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t" url: https://www.g2.com/categories/devsecops ---

# Semgrep Reviews & Product Details

Claimed

###### Profile Status

This profile is currently managed by Semgrep but has limited features.  
  
Are you part of the Semgrep team? [Upgrade your plan](https://sell.g2.com) to enhance your branding and engage with visitors to your profile!

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

* * *

Seller
 [Semgrep](https://www.g2.com/sellers/semgrep)
Discussions
 [Semgrep Community](https://www.g2.com/products/semgrep/discuss)
Languages Supported
 

English

Solution Type
 
All-in-One

Overview by
 Nav Singh

Show More

## Pricing

Pricing provided by Semgrep.

### Semgrep Code, Supply Chain, and Secrets Detection

Starting at $40.00

1 contributor Per Month

[
View More Pricing Information
](https://www.g2.com/products/semgrep/pricing)

## Top-Rated Alternatives

[

 ![SonarQube](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "SonarQube")

SonarQube

4.4/5(154)

](https://www.g2.com/products/sonarqube/reviews)

[

 ![Snyk](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Snyk")

Snyk

4.5/5(135)

](https://www.g2.com/products/snyk/reviews)

[

 ![GitHub](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "GitHub")

GitHub

4.7/5(2,402)

](https://www.g2.com/products/github/reviews)

[
View All Alternatives
](https://www.g2.com/products/semgrep/competitors/alternatives)

## User Insights

Average based on 56 real user reviews.

Implementation Time

1 month

Perceived Cost

$$$$$

Typical contract price

$0k - $0k

[Sign in to view](/login)

Per Year

[Log in to unlock pricing and user insights](/login)

## Semgrep Integrations
(9)

What do users say about integrations?

Integration information sourced from real user reviews.

  

 ![Milan K.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Milan K.")
MK

Milan K.

Senior Software Engineer

Mid-Market (51-1000 emp.)

7/8/2026

"Fast, Easy-to-Customize Rules That Catch Security and Code-Quality Issues Early"

4.5/5

What do you like best about Semgrep?

What I like most about Semgrep is that it makes security scanning easy to adopt without adding much overhead to the development process. The UI is clean and easy to navigate, the setup and onboarding are straightforward, and it integrates well with GitHub and CI/CD pipelines. Scans are fast, the findings are easy to understand with helpful AI-powered explanations, and customizing rules for different projects is flexible. Overall, it provides good value by helping teams catch security and code quality issues early, reducing time spent fixing problems later. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

have`t found anything like that so far in semgrep Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Semgrep helps catch security issues and code quality problems early in the development process, which reduces the chances of bugs reaching production. The interface is easy to navigate, it integrates smoothly with CI/CD pipelines and GitHub, and the scan results are fast and easy to understand. While there's some initial effort to fine-tune rules, it saves time during code reviews and provides good value by helping developers identify issues before they become expensive to fix. Review collected by and hosted on G2.com.

Show More

7/9/2026
Validated ReviewerIncentivizedSource: G2 invite

  

 ![Shreekanth k.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Shreekanth k.")
SK

Shreekanth k.

Cloud Application Development Engineer

Enterprise (\> 1000 emp.)

11/18/2025

"Streamlined Code Security with Semgrep"

5/5

What do you like best about Semgrep?

I appreciate using Semgrep for its robust security scanning capabilities, particularly in our code security scans for Azure Data Factory, Azure Databricks notebooks, and Python code. The setup was straightforward and integrated seamlessly into our pipeline without much hassle, demonstrating an ease of use that contrasts sharply with other tools. One of the standout features for me is the low false positive rate; it effectively identifies actual security issues without wasting time on false alerts, which makes it incredibly efficient. The built-in rules are comprehensive, covering most major languages we use and providing thorough checks for common vulnerabilities. The scan results are transparent and actionable, pinpointing the exact line in the code where issues arise and offering clear guidance on how to fix them, significantly speeding up remediation. I also find the performance to be solid, not hindering our build processes with delays. Additionally, after investing time in learning how to write custom rules tailored to our specific needs, I realized the powerful flexibility Semgrep offers. Overall, it has markedly enhanced our code review process by focusing attention on genuine issues and aiding in the early detection of security concerns. This has ultimately strengthened our development workflow and reduced the time spent on security risks. I wholeheartedly recommend Semgrep as a practical SAST tool that delivers exceptional results while being manageable to maintain. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

The custom rule syntax took some time to learn and was not intuitive initially. Additionally, sometimes Semgrep misses complex security patterns that span multiple functions or files, necessitating manual reviews for such cases. Furthermore, the rule documentation could be improved with more real-world examples. Better integration with our specific IDE and possibly some AI-assisted rule suggestions based on our code base patterns would also be beneficial. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

I use Semgrep to catch security vulnerabilities and code quality issues early, saving time on manual reviews and reducing security risks. It offers actionable scan results, minimal false positives, and customizable rules, all enhancing our development efficiency. Review collected by and hosted on G2.com.

Show More

11/19/2025
Current UserValidated ReviewerIncentivizedSource: Seller invite

  

 ![Verified User in Information Technology and Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Information Technology and Services")
UI

Verified User in Information Technology and Services

Enterprise (\> 1000 emp.)

11/1/2025

"Powerful Rule Engine and Autofix, but Governance at Scale Needs Work"

4.5/5

What do you like best about Semgrep?

Flexible, transparent rule engine with clear YAML syntax and data‑flow patterns, plus an extensive public registry for quick wins and customization.

• Smooth CI/CD integration and lightweight runtime, enabling frequent scans without major impact on developer velocity.

• Autofix capabilities (deterministic rule‑based and Assistant AI‑assisted) that propose or apply safe code changes, reducing mean time to remediate Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Governance overhead at scale; maintaining org‑wide rule sets, exceptions, and updates across many repos becomes an operational burden without a dedicated owner.

• Autofix and AI noise filtering are helpful but still evolving; effectiveness varies by language and codebase, and some teams remain cautious about applying fixes automatically. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Semgrep is helping embed security into daily development by catching risky patterns early in pull requests and CI, which reduces rework and keeps release velocity high. Transparent, customizable rules let the team encode our own guardrails and quickly add checks for new frameworks, so coverage improves without waiting on vendor updates. AI‑assisted noise filtering and autofix guidance cut triage time and help developers resolve issues faster, which lowers MTTR and helps us meet remediation SLAs more consistently.

Operationally, fast scans and easy CI/SCM integration mean developers see actionable feedback where they work, not in a separate portal, increasing adoption and fixing rates. As a result, we’ve moved from sporadic security reviews to consistent, automated checks across services, with measurable gains in fix rate and fewer high‑risk patterns reaching production. The net benefit is stronger secure‑by‑default practices with minimal productivity tax, plus lower compliance risk thanks to policy‑as‑code rules we can audit and evolve over time. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: Seller invite

  

 ![Deepam .](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Deepam .")
D

Deepam .

Security Engineer

Enterprise (\> 1000 emp.)

9/25/2025

"Semgrep Review"

5/5

What do you like best about Semgrep?

Semgrep is one of the best tools I've used for securing applications. Since it was integrated into our DevSecOps workflow, it has been able to identify a large number of issues much earlier in the development process. Semgrep scans for potentially vulnerable packages or outdated software versions within the codebase and accurately identifies the relevant CVEs. It also provides clear information about the impact and suggests the appropriate remediation steps, so developers don't need to search online for solutions.

I've found it particularly effective at detecting hardcoded secrets, even those that other tools like Trufflehog might miss. Semgrep Supply Chain also does an excellent job of pinpointing vulnerable software versions.

Overall, I consider Semgrep essential for securing CI/CD pipelines in today's environment. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Nothing as such. It works out very well with all functionalities. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Semgrep is great at automation and for earlier identification of security issues, saves a lot of manual effort for developers and pentesters Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: Seller invite

  

 ![Ivo M.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Ivo M.")
IM

Ivo M.

Analista de segurança da informação junior

Enterprise (\> 1000 emp.)

9/5/2025

"Fast, reliable, and developer-friendly static analysis tool"

4.5/5

What do you like best about Semgrep?

Semgrep is lightweight, very fast compared to traditional SAST tools, and integrates smoothly into CI/CD pipelines. I like that it has a strong rule ecosystem (community and Pro rules), and the ability to write custom rules makes it flexible for different coding standards and compliance needs. The dashboard provides great visibility into security findings and code quality issues, helping developers fix problems quickly without slowing them down. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

The initial setup for more advanced use cases can be tricky, especially when fine-tuning custom rules or managing large rule sets across multiple projects. Sometimes, there are false positives that require manual triage, and the learning curve for rule writing is a bit steep for newcomers. I would also like to see deeper integrations with more enterprise security platforms out-of-the-box. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Semgrep helps us detect security vulnerabilities and coding issues early in the development lifecycle. It makes it easier to enforce secure coding standards across multiple teams without adding heavy friction to the developers’ workflow. By integrating directly into CI/CD pipelines, it reduces time-to-detection and prevents risky code from reaching production. This has improved both the security posture and the consistency of our applications while lowering the manual effort needed for code reviews. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: Seller invite

  

 ![Verified User in Manufacturing](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Manufacturing")
UM

Verified User in Manufacturing

Enterprise (\> 1000 emp.)

10/22/2025

"Powerful, Customizable Static Analysis with Fast Scans—Some Learning Curve and Tuning Needed"

5/5

What do you like best about Semgrep?

Semgrep is a static analysis tool that enables developers to create custom rules using an intuitive pattern-matching syntax, which closely mirrors the code being reviewed. It offers support for a variety of programming languages, including Python, JavaScript, Java, and Go, among others. With Semgrep, users can identify security vulnerabilities, address code quality concerns, and enforce coding standards effectively. Many developers value its seamless integration with CI/CD pipelines, the ability to run scans locally during development, and the flexibility to craft rules tailored to their organization's codebase. The tool is known for its rapid scanning capabilities and lower false positive rates when compared to more traditional static analysis solutions. Additionally, Semgrep is available in both open-source and commercial versions, with advanced features such as centralized rule management and options for team collaboration. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Static analysis tools can present certain limitations, such as generating false positives that must be manually reviewed. They may also struggle to identify complex runtime vulnerabilities or logic flaws that only become apparent during execution. Maintaining and tuning rules to keep up with evolving codebases is an ongoing requirement. Some users note that creating custom rules involves a learning curve, particularly when mastering the pattern-matching syntax. Comprehensive scans of large codebases can also affect CI/CD pipeline performance. While these tools are strong in pattern matching, they might overlook context-dependent vulnerabilities that require more advanced semantic analysis. As a result, teams often need to dedicate time to configuring rules in order to minimize noise and prioritize findings relevant to their specific technology stack. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

It lacks the option to manually trigger a code scan, specifically for static scans. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: Seller invite

  

 ![Verified User in Manufacturing](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Manufacturing")
UM

Verified User in Manufacturing

Small-Business (50 or fewer emp.)

10/22/2025

"Fast, Accurate, and Seamless Integration with GitHub"

4.5/5

What do you like best about Semgrep?

The feedback is fast and actionable, which makes it easy to address issues quickly. I also appreciate the reduced number of false positives, as it saves time and effort. Integration with GitHub and Actions is seamless, making the workflow smooth. The accuracy is high, and the support for a wide range of languages is another strong point. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Semgrep is quite narrowly focused, concentrating primarily on security and lacking built-in scanning capabilities for other important areas such as secrets detection, infrastructure as code, or container security. There is also a learning curve to consider; crafting effective and custom rules demands a certain level of expertise, which can be particularly challenging when dealing with more complex vulnerabilities. Additionally, Semgrep on its own provides limited context, so without supplementary tools, it can be difficult to determine if a vulnerability is truly exploitable or reachable at runtime. This limitation can make it harder to properly prioritize issues. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Semgrep helps assisting developers and security teams in identifying bugs, vulnerabilities, and enforcing coding standards. It analyzes source code to detect patterns that correspond to predefined rules, which makes it valuable for code reviews, security audits, and maintaining overall code quality. Semgrep will be our new default SAST tool as we begin to phase out the current tool which is outdated and cumbersome to use. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: Seller invite

  

 ![Verified User in Information Technology and Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Information Technology and Services")
UI

Verified User in Information Technology and Services

Enterprise (\> 1000 emp.)

10/21/2025

"Semgrep: A Powerful and Customizable SAST Solution"

3.5/5

What do you like best about Semgrep?

The most significant advantage of Semgrep is its highly customizable rule engine and ease of rule writing. The ability to define custom rules in YAML, tailored to specific codebases and threat models, sets it apart from many other SAST solutions. This flexibility allows for precise detection of custom vulnerabilities and adherence to specific coding standards. Its lightweight nature and rapid execution in CI/CD pipelines are also highly beneficial, enabling fast feedback loops without significantly impacting build times. Furthermore, the open-source core provides transparency and allows for community contributions and audits of the rule execution. The reachability analysis in Semgrep Supply Chain is also a standout feature, significantly reducing false positives by focusing on truly exploitable vulnerabilities within third-party components. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

While Semgrep excels in static analysis, its narrow focus can be a limitation for organizations seeking a comprehensive application security platform. It does not natively offer integrated scanning for secrets, Infrastructure as Code (IaC), containers, or CI/CD posture, necessitating the use of additional tools for broader coverage. The initial tuning required to reduce false positives and optimize rule sets can also be an upfront investment, especially for new users or complex projects. Finally, while rule writing is a strength, the learning curve for advanced rule creation can be steep for those new to the tool or static analysis in general. The lack of robust, built-in reporting features and export options for detailed vulnerability analysis is also a notable drawback. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Semgrep solves the problem of finding security vulnerabilities, bugs, and enforcing code standards early and quickly in the development lifecycle. It helps shift security left by integrating directly into development workflows, such as CI/CD pipelines and IDEs. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: Seller invite

  

 ![Nagaraju A.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Nagaraju A.")
NA

Nagaraju A.

Delivery Manager

Mid-Market (51-1000 emp.)

10/31/2025

"Easy to Use with Great Functional Testing Capabilities"

5/5

What do you like best about Semgrep?

I appreciate how Semgrep excels in validating and QA testing capabilities, showing good efficacy in performing these tasks. The ease of use is particularly notable, requiring less scripting compared to other alternatives, and the initial setup process was straightforward and effortless. I value its functionality in conducting functional testing, which simplifies my tasks significantly. The test case design and resulting outcomes are particularly pleasing, enhancing my testing process. Whenever I encounter issues that other tools cannot resolve, Semgrep becomes an indispensable resource, allowing me to progress by utilizing its features effectively. Overall, I find Semgrep a worthy exploration for its functionality and user-friendly approach. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Nothing Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

I find Semgrep improves my workflow for functional testing, making it easy to use and reducing scripting. It solves problems when other tools fail, helping me proceed further and block issues effectively. Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: Seller invite

  

MA

Mohammad A.

Product Owner

Enterprise (\> 1000 emp.)

10/22/2025

"Great Experience, But UI Could Be More User-Friendly"

4.5/5

What do you like best about Semgrep?

Semgrep is one of the super easy and most lightweight tools for detecting security vulnerabilities in our codebase. It also enables us to scan our local repositories and can be integrated with our CI/CD pipeline to provide continuous code scanning. We prefer using it with almost all of our applications to feel more confident. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

There isn't much to complain about, but I do think the user interface could be cleaner and more user-friendly. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

The platform offers vulnerability scanning and helps keep applications free of bugs. It also provides automated code scanning through the CI/CD pipeline and supports scanning for multiple programming languages. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: Seller invite

## Pricing Options

Pricing provided by Semgrep.

### Semgrep Code, Supply Chain, and Secrets Detection

Starting at $40.00

1 contributor Per Month

[
View More Pricing Information
](https://www.g2.com/products/semgrep/pricing)

Semgrep Comparisons

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_a4dc620644f85fd7e4f00b0a2267d09c/sonarqube.png "Product Avatar Image")

SonarQube

4.4/5(154)

[
Compare Now
](https://www.g2.com/compare/semgrep-vs-sonarqube)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_630875599869fc792265ba9508dc29e9/snyk.png "Product Avatar Image")

Snyk

4.5/5(135)

[
Compare Now
](https://www.g2.com/compare/semgrep-vs-snyk)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_1690e90d3b34e5682247349555a8ab59/opentext-static-application-security-testing.jpeg "Product Avatar Image")

OpenText Static Application...

4.5/5(24)

[
Compare Now
](https://www.g2.com/compare/opentext-static-application-security-testing-vs-semgrep)

##### ##### Semgrep Features

Administration

API / Integrations

Analysis

Real-Time Analytics

Issue Tracking

Static Code Analysis

Testing

Command-Line Tools

Detection Rate

False Positives

Functionality - Software Composition Analysis 

Language Support

Integration

[
View More Features
](https://www.g2.com/products/semgrep/features)

##### Categories on G2

[Vulnerability Scanner](https://www.g2.com/categories/vulnerability-scanner)[Software Composition Analysis](https://www.g2.com/categories/software-composition-analysis)[Static Application Security Testing (SAST)](https://www.g2.com/categories/static-application-security-testing-sast)

[Secure Code Review](https://www.g2.com/categories/secure-code-review)[Dynamic Application Security Testing (DAST)](https://www.g2.com/categories/dynamic-application-security-testing-dast)[Static Code Analysis](https://www.g2.com/categories/static-code-analysis)[AI AppSec Assistants](https://www.g2.com/categories/ai-appsec-assistants)[Interactive Application Security Testing (IAST)](https://www.g2.com/categories/interactive-application-security-testing-iast)

[Show MoreShow Less](javascript:void(0);)

##### Explore More

[Which display advertising platforms offer the best budget pacing transparency and spend reporting?](https://www.g2.com/discussions/which-display-advertising-platforms-offer-the-best-budget-pacing-transparency-and-spend-reporting)[What is the best earned wage access software for a mid-size company that wants fast employee payouts without waiting for a full payroll cycle to close?](https://www.g2.com/discussions/what-is-the-best-earned-wage-access-software-for-a-mid-size-company-that-wants-fast-employee-payouts-without-waiting-for-a-full-payroll-cycle-to-close)[What earned wage access software options exist for employers and what are the main differences between providers?](https://www.g2.com/discussions/what-earned-wage-access-software-options-exist-for-employers-and-what-are-the-main-differences-between-providers)

[Which application release orchestration tools integrate well with existing Kubernetes and Helm-based infrastructure so teams do not have to choose between their orchestration tool and their deployment platform?](https://www.g2.com/discussions/which-application-release-orchestration-tools-integrate-well-with-existing-kubernetes-and-helm-based-infrastructure-so-teams-do-not-have-to-choose-between-their-orchestration-tool-and-their-deployment-platform)[User-friendly project management software for teams](https://www.g2.com/discussions/user-friendly-project-management-software-for-teams)[Pros and Cons Details](https://www.g2.com/products/semgrep/reviews?qs=pros-and-cons)

[Show MoreShow Less](javascript:void(0);)