--- title: Semgrep Reviews meta_title: 'Semgrep Reviews 2026: Details, Pricing, & Features | G2' meta_description: Filter 56 reviews by the users' company size, role or industry to find out how Semgrep works for a business like yours. aggregate_rating: rating_value: 4.6 review_count: 56 scale: '5' date_modified: '2026-09-22' parent_category: name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t" url: https://www.g2.com/categories/devsecops ---

Semgrep Pros and Cons: Top 5 Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users appreciate the ease of use of Semgrep, enabled by its intuitive syntax and smooth integration with CI/CD. (16 mentions)
Users appreciate the flexibility and speed of Semgrep in enforcing coding standards and catching vulnerabilities effectively. (14 mentions)
Users appreciate the effective vulnerability detection of Semgrep, facilitating quick identification and resolution of security issues. (13 mentions)
Users appreciate the scanning efficiency of Semgrep, benefiting from rapid scans and streamlined CI/CD integration. (12 mentions)
Users value Semgrep for its effective security vulnerability detection, enabling quick resolutions without hindering development speed. (12 mentions)
Users find Semgrep not user-friendly due to a steep learning curve and complex initial setup requirements. (7 mentions)
Users find the limited features of Semgrep restrict its usability and complicate effective vulnerability management. (6 mentions)
Users find the difficult learning curve for Semgrep daunting, especially for creating advanced rules and setups. (5 mentions)
Users express concerns about the lack of guidance in creating custom rules, complicating effective use of Semgrep. (5 mentions)
Users note a steep learning curve for Semgrep's rule syntax, making it challenging for newcomers to master. (5 mentions)

5 Pros or Advantages of Semgrep

5 Cons or Disadvantages of Semgrep

AJ
Avneesh J.
Engineering manager-DevOps
Enterprise (> 1000 emp.)
"Effortless Code Scanning—Much Easier Than Our Old Tool"
5/5
What do you like best about Semgrep?

It's a very user-friendly tool for scanning code repositories, and I find it much easier to use compared to our previous Checkmarx scan.

Its quiet easy to integrate with our existing code repository and can also be filtered based on the need. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Since we have only recently started using this tool, there is nothing we dislike about it so far. Review collected by and hosted on G2.com.

Mahmoud H.
MH
Mahmoud H.
Information Security Intern
Mid-Market (51-1000 emp.)
"I think Semgrep is a must have for every Software Company"
4.5/5
What do you like best about Semgrep?

The fact that it can scan dependencies and has so many rules configured on the spot, with a very friendly and easy to use UI for the SemGrep pro. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

I think what semgrep needs is a feature that summarizes the overall security standing of a repository/project. And to allow the user to be able to tell the platform the links between different repos/ if there are any. Review collected by and hosted on G2.com.

Nitish U.
NU
Nitish U.
Product Security Lead
Computer & Network Security
Mid-Market (51-1000 emp.)
"Accurate Results and a Polished UI from Semgrep"
4.5/5
What do you like best about Semgrep?

Accuracy, UI. Semgrep AI assistant. Semgrep SCA reachability matrix Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Bugs, Crashes. Frequent issues in PR scans. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Verified User in Computer Software
Mid-Market (51-1000 emp.)
"Enhancing Security with Semgrep"
4/5
What do you like best about Semgrep?

Since it runs fast and integrates directly into CI/CD, my team can surface issues early — from insecure function use to misconfigured patterns — before they ever hit production. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Filter limitations and changing some settings at the global level using UI. Having more advanced filtering and project-level controls would make it easier to manage findings across different environments, prioritize risks. Review collected by and hosted on G2.com.

SJ
Siddhesh J.
Senior Security Analyst & Consultant
Information Technology and Services
Mid-Market (51-1000 emp.)
"Fast and positive results"
4.5/5
What do you like best about Semgrep?

There are multiple things which is great in the SemGrep tool, 1st easy integration with GSM and CI-CD pipeline, 2nd is easy terminal based code scan which save lot of time and intergration if Code is small. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Not specific as such, since everything is good in right price. Review collected by and hosted on G2.com.

Andrew K.
AK
Andrew K.
Systems Administrator
Enterprise (> 1000 emp.)
"Effortless Code Scanning, But Dynamic Issues Can Slip Through"
2.5/5
What do you like best about Semgrep?

Our company has it automatically enabled to scan our code. We can click a link and see what items need to be addressed. I get a review of my code every commit. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

I can hide security issues with dynamically loaded variables and methods Review collected by and hosted on G2.com.

Verified User in Computer Software
EC
Verified User in Computer Software
Small-Business (50 or fewer emp.)
"Hands-off setup could not be easier"
4.5/5
What do you like best about Semgrep?

Very little had to be done on our end to set up managed scans for the entire GitHub organization. Aside from Semgrep staff adjusting things to get a scan to complete, or large codebase was running SAST scans in a few days. Github PR comments show users what to do, and AI can classify many reports correctly as not needing mitigation. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Semgrep's features are designed around preventing new problems from being introduced in pull requests, but those same features are not available for issues found on trunk branches - these have to be dealt with manually. Review collected by and hosted on G2.com.

Verified User in Semiconductors
US
Verified User in Semiconductors
Enterprise (> 1000 emp.)
"Insightful Vulnerability Analysis, But Needs Automatic Analysis"
5/5
What do you like best about Semgrep?

The tool provides an analysis of detected vulnerabilities in the code and also offers suggested fixes. This feature is helpful for identifying potential issues and understanding how to address them. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Currently, I have to manually trigger the analysis each time a new detection occurs, but I would prefer if the analysis happened automatically as soon as something is detected. Review collected by and hosted on G2.com.

Verified User in International Affairs
UI
Verified User in International Affairs
Enterprise (> 1000 emp.)
"Speeds Up Bug Detection, But Rule Syntax Can Be Limiting for Complex Code"
4/5
What do you like best about Semgrep?

The best thing about Semgrep is that it helps catch bugs and enforce code standards early in development, without slowing engineers down. It’s quick, understandable, and fits naturally into the developer workflow. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

My main dislike is that Semgrep’s rule syntax can feel restrictive when dealing with dynamic code or frameworks that rely heavily on metaprogramming. It’s great for straightforward patterns, but deeper semantic analysis sometimes needs more manual effort. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
UH
Verified User in Hospital & Health Care
Enterprise (> 1000 emp.)
"Flexible Rules and GitHub Integration Shine, But Needs Better Product Segmentation"
4.5/5
What do you like best about Semgrep?

Semgrep offers a single platform for SAST and SCA solutions which is good, but the best part is semgrep rules they are so flexible and easy to write that you dont need to manually do filtering or removing.

The tool has another feature I personally like is github actions that will show bugs in git itself with an AI reviewed fixed version. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Semgrep doesnt have Product wise segmentation like for organizations with multiple products you will have only projects and have to use labels to categorise those products. Review collected by and hosted on G2.com.