Introducing G2.ai, the future of software buying.Try now

Semgrep Pricing Overview

Free Trial

Semgrep Pricing Reviews

(2)
Verified User in Manufacturing
UM
Enterprise (> 1000 emp.)
"Powerful, Customizable Static Analysis with Fast Scans—Some Learning Curve and Tuning Needed"
What do you like best about Semgrep?

Semgrep is a static analysis tool that enables developers to create custom rules using an intuitive pattern-matching syntax, which closely mirrors the code being reviewed. It offers support for a variety of programming languages, including Python, JavaScript, Java, and Go, among others. With Semgrep, users can identify security vulnerabilities, address code quality concerns, and enforce coding standards effectively. Many developers value its seamless integration with CI/CD pipelines, the ability to run scans locally during development, and the flexibility to craft rules tailored to their organization's codebase. The tool is known for its rapid scanning capabilities and lower false positive rates when compared to more traditional static analysis solutions. Additionally, Semgrep is available in both open-source and commercial versions, with advanced features such as centralized rule management and options for team collaboration. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Static analysis tools can present certain limitations, such as generating false positives that must be manually reviewed. They may also struggle to identify complex runtime vulnerabilities or logic flaws that only become apparent during execution. Maintaining and tuning rules to keep up with evolving codebases is an ongoing requirement. Some users note that creating custom rules involves a learning curve, particularly when mastering the pattern-matching syntax. Comprehensive scans of large codebases can also affect CI/CD pipeline performance. While these tools are strong in pattern matching, they might overlook context-dependent vulnerabilities that require more advanced semantic analysis. As a result, teams often need to dedicate time to configuring rules in order to minimize noise and prioritize findings relevant to their specific technology stack. Review collected by and hosted on G2.com.

SJ
Senior Security Analyst & Consultant
Information Technology and Services
Mid-Market (51-1000 emp.)
"Fast and positive results"
What do you like best about Semgrep?

There are multiple things which is great in the SemGrep tool, 1st easy integration with GSM and CI-CD pipeline, 2nd is easy terminal based code scan which save lot of time and intergration if Code is small. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Not specific as such, since everything is good in right price. Review collected by and hosted on G2.com.

Semgrep Comparisons
Product Avatar Image
SonarQube
Compare Now
Product Avatar Image
Snyk
Compare Now
Product Avatar Image
OpenText Static Application Security Testing
Compare Now
Product Avatar Image
Product Avatar Image