Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Claimed
Claimed

Top Rated Semgrep Alternatives

Semgrep Reviews & Product Details

Avinash S.
AS
Security Lead
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Semgrep?

It is the most efficient and simple to use integration for SAST.

Free, and community-driven

Discussions on Slack channels provide valuable help and insights. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Nothing major. It is evolving in right direction.

But A trial version would be good. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Mostly eliminating the use of multiple SAST scanners into one. Review collected by and hosted on G2.com.

Semgrep Overview

What is Semgrep?

Semgrep is a highly customizable application security platform built for security engineers and developers. Semgrep scans first and third-party code to find security issues unique to an organization, with an emphasis on surfacing actionable, low-noise, and developer friendly results at lightning speed. Semgrep's focus on confidence rating and reachability means that security teams can feel comfortable engaging developers directly in their workflows (e.g surfacing findings in PR comments), and Semgrep integrates seamlessly with CI and SCM tooling to automate these policies. With Semgrep, security teams can shift left and scale their programs with zero impact on developer velocity. With 3400+ out-of-the-box rules and the ability to easily create custom rules, Semgrep accelerates the time it takes to implement and scale a best-in-class AppSec program - all while adding value from Day 1.

Semgrep Details
Languages Supported
English
Show LessShow More
Product Description

Find bugs, run security scans in CI, and enforce security standards across your organization. Scale your security team. Actionable, low-noise, and developer-friendly results let you scale your security and ship with high velocity. Enable developers to be more productive. Reduce friction between security engineers and developers by finding and sharing vulnerabilities in your code and in open source dependencies. Easily write custom rules. Easily write rules to find bugs specific to your organization — rules look like source code, so there’s no need to learn a new proprietary language.

How do you position yourself against your competitors?

Developer-first - Fast scans, policies based on confidence rating, and the ability to run locally or in CI/CD environments mean Semgrep can integrate into dev workflows with minimal friction

Easy to customize - Rules are easy to write and their effectiveness is simple to monitor at scale, making it easy for security teams to tailor Semgrep to their organization's needs

Reachability analysis - Triage and prioritize the 2% of SCA vulnerabilities that are actually reachable

Wide language coverage - Supports more than 25 languages for SAST, making it a one-stop shop for multi-language software teams


Seller Details
Seller
Semgrep
Year Founded
2017
HQ Location
San Francisco, US
Twitter
@semgrep
3,492 Twitter followers
LinkedIn® Page
www.linkedin.com
170 employees on LinkedIn®

Nav S.
NS
Overview Provided by:

Recent Semgrep Reviews

Verified User
C
Verified UserSmall-Business (50 or fewer emp.)
4.5 out of 5
"An easy to use and fun to customize SAST tool"
That the SAST engine returns a very small number of false positives. And the rules are fun to write. I also like the reachability analysis of the s...
Verified User
U
Verified UserEnterprise (> 1000 emp.)
5.0 out of 5
"Semgrep experience"
The easy customisation, custom rule creation and fast feedback for devs
Shivam J.
SJ
Shivam J.Mid-Market (51-1000 emp.)
4.5 out of 5
"Perfect code security analysis tool to check and eliminate vulnerabilities"
The sast engine and the wholesome dashboard makes everything looks great and crisp
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

Semgrep Media

Semgrep Demo - Findings in PR comments
Semgrep displays findings in pull request (PR) comments so that developers can see and triage issues within their workflow.
Semgrep Demo - Prioritize findings you want to fix
Semgrep helps you triage the findings that are important for your organization.
Answer a few questions to help the Semgrep community
Have you used Semgrep before?
Yes

30 out of 31 Total Reviews for Semgrep

4.6 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
30 out of 31 Total Reviews for Semgrep
4.6 out of 5
30 out of 31 Total Reviews for Semgrep
4.6 out of 5

Semgrep Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for SemgrepQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Verified User in Computer Software
CC
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Semgrep?

That the SAST engine returns a very small number of false positives. And the rules are fun to write. I also like the reachability analysis of the supply chain tool so you don't get overwhelmed by false positives Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

There is no export report feature. Moreover it would be useful a toggle to tell the supply chain tool to report all the vulnerable dependencies, regardless of their reachability. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Helping to build secure products by writing more secure code Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
UC
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Semgrep?

The easy customisation, custom rule creation and fast feedback for devs Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

More products like IaC scanning or DAST, I would love to have full capabilities to scan apps Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Shifting left vulnerabilities Review collected by and hosted on G2.com.

Abhineet S.
AS
Senior Consultant - I
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Semgrep?

I like the SAST engine, it is powerful and capable alongwith less % of false positives. Apart from it, the pro and lot other built rules make it easy to integrate with any DevSecOps process. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Currently the newer offering like SEMGREP AI and secrets manager does not add up perfectly Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

It is catching the essential, critical and tainted in nature vulnerabilities in day to day code making it is good way to follow shift left practices. Review collected by and hosted on G2.com.

Shivam J.
SJ
QA Engineer
Information Technology and Services
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Semgrep?

The sast engine and the wholesome dashboard makes everything looks great and crisp Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

I am not satisfied with the accuracy of the integration tools with it Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Making it easy to go shift left in security and in supply chain management security Review collected by and hosted on G2.com.

Verified User in Computer Games
UC
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Semgrep?

- Easy to integrate in CICD and custom workflows

- CLI configurations are simple

- Powerful scanning capabilities

- Supports many languages

- Reachability analysis is helpful

- Stable and reliable Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

- Doesn't handle unicode chars properly at many places, if there are unicodes in your code then semgrep can crash

- No GUI for OSS version, they should atleast provide a basic GUI for OSS version Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Semgrep is helping us identify vulnerabilities at the early stages of the development by continously identifying the vulnerabilities in our codebase and highlighting the vulnerable OSS libraries being used. Review collected by and hosted on G2.com.

Kiko E.
KE
Engineering Manager
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Semgrep?

One of the things that I love most about Semgrep is how easy it is to use. As a static analysis tool, it has a reputation for being intimidating or difficult to integrate into existing workflows. But with Semgrep, developers don't have to worry about that at all. It seamlessly integrates with many popular code editors, version control systems, and continuous integration tools. This means that it's a breeze to set up and start using to detect potential security vulnerabilities, performance issues, and other code quality problems.

But what's really cool about Semgrep is how it feels like a tool that's designed with developers in mind. The pre-built rules are incredibly comprehensive and cover a wide range of potential issues. But if you need to customize them for your project, it's easy to do so. And if you ever get stuck, the community is always there to help you out.

All in all, Semgrep is a powerful tool that can help developers improve the quality of their code. But more importantly, it feels like a tool that was designed to make our lives easier. And who doesn't love that? Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

As with any tool, Semgrep has some potential downsides to consider. Here are a few:

Learning curve: While Semgrep is generally considered to be user-friendly and easy to use, there is still a learning curve to using any new tool. Some developers may need to spend some time getting familiar with Semgrep's syntax and how to write and modify rules.

False positives/negatives: Like any static analysis tool, Semgrep can generate false positives (i.e., flagging code as problematic when it's not) or false negatives (i.e., failing to flag problematic code). This can be frustrating and may require some additional time and effort to sort out.

Resource-intensive: Depending on the size of your codebase, running Semgrep can be resource-intensive and may slow down your development process. It's important to consider this when integrating Semgrep into your workflow and ensure that your hardware and infrastructure can handle it.

Overall, these potential downsides are relatively minor compared to the benefits that Semgrep can provide. However, it's important to consider these factors when deciding whether or not Semgrep is the right tool for your project. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

The problem that Semgrep is solving is that it can be difficult for developers to manually review code for potential issues. With codebases that are constantly growing and changing, it can be easy to miss potential issues or introduce new ones. Semgrep automates this process and enables developers to quickly identify and address potential issues before they become larger problems. Review collected by and hosted on G2.com.

DD
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about Semgrep?

-Installation is pretty straightforward

-Supports almost all programming languages

-Scans are relatively faster than other static code analysis tool

-In certain cases, I have noticed results/findings from Semgrep were more accurate Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

-There were quite a few false positives as well

-Other tools such as Sonarqube has more features and provides thorough reports

-Troubleshooting can be difficult Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

In my case, I use Semgrep to find initial bugs in my code and it works almost perfectly in almost all cases and pass on the report to tester to debug more and fix the same issues. Review collected by and hosted on G2.com.

SS
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Semgrep?

Semgrep helped us in no time narrowing down important vulnerabilities and focusing on what matters thanks to Semgrep Supply Chain.

It is the product with the best ROI I would recommend to add to your SSDLC. it fast, extendable and customizable, with a handy CLI. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Less advanced Bitbucket / Jira integration compared to GitHub but catching up fast! Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

Making sure we maintain cybersecurity compliance and ensure safety of the data we process. Semgrep Supply Chain ensure we are focusing the most important security issues first. Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Semgrep?

Semgrep is an easy-to-use and highly customizable static code analysis tool. Its intuitive interface and flexible rules library make running scans on any codebase effortless, big or small. With its active community of contributors and open-source nature, Semgrep is an essential tool for developers looking to enhance code quality and security quickly and efficiently. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

I have not encountered any major issues while using the product so far. During onboarding, I experienced some minor UI issues, but they did not significantly impact my overall experience. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

It helps identify potential issues before they become major problems, saving time and resources in the long run. By finding and fixing issues early on in the development process, developers can improve the overall quality of the codebase and reduce the likelihood of future problems. Review collected by and hosted on G2.com.

Aleksandr K.
AK
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Semgrep?

context aware scanning that allows a security engineer to see true metrics on vulnerabilities in the code. Its offering of IaC shows how much context aware it can be with its custom data flows. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

It's hard to name anything in particular, but the one thing that is challenging is to get onboarded with this. There is definitely a learning curve to get started with writing your own rules. Review collected by and hosted on G2.com.

What problems is Semgrep solving and how is that benefiting you?

All things related to code security: putting security guardrails for developers in pre-commit stage, ensuring no secrets are ever committed, keeping our lockfiles with libraries up to date. Review collected by and hosted on G2.com.