Semgrep

By Semgrep

4.6 out of 5 stars

How would you rate your experience with Semgrep?

Compare this with other toolsSave it to your board and evaluate your options side by side.
Save to board

Semgrep Reviews & Product Details

Pricing

Pricing provided by Semgrep.

Semgrep Code, Supply Chain, and Secrets Detection

Starting at $40.00
1 contributor Per Month

Semgrep Integrations

(9)
Verified by Semgrep

Semgrep Media

Semgrep Demo - Semgrep Supply Chain (SCA)
Semgrep Supply Chain makes it easy to find and remediate the 2% of dependency vulnerabilities that are actually reachable in your code.
Semgrep Demo - Semgrep Code (SAST)
A SAST solution where developers actually fix the majority of issues they see. Make fix rate the north star metric of your AppSec program with Semgrep Code.
Semgrep Demo - Semgrep Secrets
Go beyond regex: leverage Semantic Analysis, entropy analysis, and validation to accurately detect and fix secrets.
Semgrep Demo - Dashboard
The Semgrep dashboard provides clear, actionable insights into code security and quality, helping teams quickly identify, prioritize, and remediate issues across their projects.
Semgrep is a code security solution that enables organizations to scale their security programs quickly and easily.
Play Semgrep Video
Semgrep is a code security solution that enables organizations to scale their security programs quickly and easily.
Interactive Demo
Try an interactive demo created by the software seller (right here on G2).
Product Avatar Image

Have you used Semgrep before?

Answer a few questions to help the Semgrep community

Semgrep Reviews (55)

Reviews

Semgrep Reviews (55)

4.6
55 reviews

Review Summary

Generated using AI from real user reviews
Users consistently praise Semgrep for its ease of use and customizability, allowing developers to quickly integrate it into their workflows and create tailored rules for their specific needs. The tool's fast scanning capabilities and low false positive rates enhance productivity, making it a valuable asset for maintaining code quality and security. However, some users note a common limitation with the learning curve associated with crafting complex rules.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Mahmoud H.
MH
Information Security Intern
Mid-Market (51-1000 emp.)
"I think Semgrep is a must have for every Software Company"
What do you like best about Semgrep?

The fact that it can scan dependencies and has so many rules configured on the spot, with a very friendly and easy to use UI for the SemGrep pro. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

I think what semgrep needs is a feature that summarizes the overall security standing of a repository/project. And to allow the user to be able to tell the platform the links between different repos/ if there are any. Review collected by and hosted on G2.com.

Nitish U.
NU
Product Security Lead
Computer & Network Security
Mid-Market (51-1000 emp.)
"Accurate Results and a Polished UI from Semgrep"
What do you like best about Semgrep?

Accuracy, UI. Semgrep AI assistant. Semgrep SCA reachability matrix Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Bugs, Crashes. Frequent issues in PR scans. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Mid-Market (51-1000 emp.)
"Enhancing Security with Semgrep"
What do you like best about Semgrep?

Since it runs fast and integrates directly into CI/CD, my team can surface issues early — from insecure function use to misconfigured patterns — before they ever hit production. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Filter limitations and changing some settings at the global level using UI. Having more advanced filtering and project-level controls would make it easier to manage findings across different environments, prioritize risks. Review collected by and hosted on G2.com.

SJ
Senior Security Analyst & Consultant
Information Technology and Services
Mid-Market (51-1000 emp.)
"Fast and positive results"
What do you like best about Semgrep?

There are multiple things which is great in the SemGrep tool, 1st easy integration with GSM and CI-CD pipeline, 2nd is easy terminal based code scan which save lot of time and intergration if Code is small. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Not specific as such, since everything is good in right price. Review collected by and hosted on G2.com.

Andrew K.
AK
Systems Administrator
Enterprise (> 1000 emp.)
"Effortless Code Scanning, But Dynamic Issues Can Slip Through"
What do you like best about Semgrep?

Our company has it automatically enabled to scan our code. We can click a link and see what items need to be addressed. I get a review of my code every commit. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

I can hide security issues with dynamically loaded variables and methods Review collected by and hosted on G2.com.

Verified User in Computer Software
EC
Small-Business (50 or fewer emp.)
"Hands-off setup could not be easier"
What do you like best about Semgrep?

Very little had to be done on our end to set up managed scans for the entire GitHub organization. Aside from Semgrep staff adjusting things to get a scan to complete, or large codebase was running SAST scans in a few days.

Github PR comments show users what to do, and AI can classify many reports correctly as not needing mitigation. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Semgrep's features are designed around preventing new problems from being introduced in pull requests, but those same features are not available for issues found on trunk branches - these have to be dealt with manually. Review collected by and hosted on G2.com.

Verified User in Semiconductors
US
Enterprise (> 1000 emp.)
"Insightful Vulnerability Analysis, But Needs Automatic Analysis"
What do you like best about Semgrep?

The tool provides an analysis of detected vulnerabilities in the code and also offers suggested fixes. This feature is helpful for identifying potential issues and understanding how to address them. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Currently, I have to manually trigger the analysis each time a new detection occurs, but I would prefer if the analysis happened automatically as soon as something is detected. Review collected by and hosted on G2.com.

Verified User in International Affairs
UI
Enterprise (> 1000 emp.)
"Speeds Up Bug Detection, But Rule Syntax Can Be Limiting for Complex Code"
What do you like best about Semgrep?

The best thing about Semgrep is that it helps catch bugs and enforce code standards early in development, without slowing engineers down. It’s quick, understandable, and fits naturally into the developer workflow. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

My main dislike is that Semgrep’s rule syntax can feel restrictive when dealing with dynamic code or frameworks that rely heavily on metaprogramming. It’s great for straightforward patterns, but deeper semantic analysis sometimes needs more manual effort. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
UH
Enterprise (> 1000 emp.)
"Flexible Rules and GitHub Integration Shine, But Needs Better Product Segmentation"
What do you like best about Semgrep?

Semgrep offers a single platform for SAST and SCA solutions which is good, but the best part is semgrep rules they are so flexible and easy to write that you dont need to manually do filtering or removing.

The tool has another feature I personally like is github actions that will show bugs in git itself with an AI reviewed fixed version. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Semgrep doesnt have Product wise segmentation like for organizations with multiple products you will have only projects and have to use labels to categorise those products. Review collected by and hosted on G2.com.

Shuiab S.
SS
EDA hardwarw engineer
Enterprise (> 1000 emp.)
"Clean Interface and Clear Insights, But Setup Can Be Frustrating"
What do you like best about Semgrep?

The interface is extremely clean, and all vulnerabilities are clearly highlighted. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Setting up the system for the first time was quite frustrating, as I found myself needing assistance from the IT agent on several occasions. Review collected by and hosted on G2.com.

People Icons

Start a Discussion about Semgrep

Have a software question? Get answers from real users and experts.

Start a Discussion

Pricing Options

Pricing provided by Semgrep.

Semgrep Code, Supply Chain, and Secrets Detection

Starting at $40.00
1 contributor Per Month
Semgrep Comparisons
Product Avatar Image
SonarQube
Compare Now
Product Avatar Image
Snyk
Compare Now
Product Avatar Image
OpenText Static Application...
Compare Now
Semgrep Features
API / Integrations
Reporting and Analytics
Issue Tracking
Static Code Analysis
Command-Line Tools
Detection Rate
False Positives
Transparency
Product Avatar Image
Semgrep