AJ
Avneesh J.
Engineering manager-DevOps
Enterprise (> 1000 emp.)
"Effortless Code Scanning—Much Easier Than Our Old Tool"
5/5
What do you like best about Semgrep?

It's a very user-friendly tool for scanning code repositories, and I find it much easier to use compared to our previous Checkmarx scan.

Its quiet easy to integrate with our existing code repository and can also be filtered based on the need. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Since we have only recently started using this tool, there is nothing we dislike about it so far. Review collected by and hosted on G2.com.

Mahmoud H.
MH
Mahmoud H.
Information Security Intern
Mid-Market (51-1000 emp.)
"I think Semgrep is a must have for every Software Company"
4.5/5
What do you like best about Semgrep?

The fact that it can scan dependencies and has so many rules configured on the spot, with a very friendly and easy to use UI for the SemGrep pro. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

I think what semgrep needs is a feature that summarizes the overall security standing of a repository/project. And to allow the user to be able to tell the platform the links between different repos/ if there are any. Review collected by and hosted on G2.com.

Nitish U.
NU
Nitish U.
Product Security Lead
Computer & Network Security
Mid-Market (51-1000 emp.)
"Accurate Results and a Polished UI from Semgrep"
4.5/5
What do you like best about Semgrep?

Accuracy, UI. Semgrep AI assistant. Semgrep SCA reachability matrix Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Bugs, Crashes. Frequent issues in PR scans. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Verified User in Computer Software
Mid-Market (51-1000 emp.)
"Enhancing Security with Semgrep"
4/5
What do you like best about Semgrep?

Since it runs fast and integrates directly into CI/CD, my team can surface issues early — from insecure function use to misconfigured patterns — before they ever hit production. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Filter limitations and changing some settings at the global level using UI. Having more advanced filtering and project-level controls would make it easier to manage findings across different environments, prioritize risks. Review collected by and hosted on G2.com.

SJ
Siddhesh J.
Senior Security Analyst & Consultant
Information Technology and Services
Mid-Market (51-1000 emp.)
"Fast and positive results"
4.5/5
What do you like best about Semgrep?

There are multiple things which is great in the SemGrep tool, 1st easy integration with GSM and CI-CD pipeline, 2nd is easy terminal based code scan which save lot of time and intergration if Code is small. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Not specific as such, since everything is good in right price. Review collected by and hosted on G2.com.

Andrew K.
AK
Andrew K.
Systems Administrator
Enterprise (> 1000 emp.)
"Effortless Code Scanning, But Dynamic Issues Can Slip Through"
2.5/5
What do you like best about Semgrep?

Our company has it automatically enabled to scan our code. We can click a link and see what items need to be addressed. I get a review of my code every commit. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

I can hide security issues with dynamically loaded variables and methods Review collected by and hosted on G2.com.

Verified User in Computer Software
EC
Verified User in Computer Software
Small-Business (50 or fewer emp.)
"Hands-off setup could not be easier"
4.5/5
What do you like best about Semgrep?

Very little had to be done on our end to set up managed scans for the entire GitHub organization. Aside from Semgrep staff adjusting things to get a scan to complete, or large codebase was running SAST scans in a few days.

Github PR comments show users what to do, and AI can classify many reports correctly as not needing mitigation. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Semgrep's features are designed around preventing new problems from being introduced in pull requests, but those same features are not available for issues found on trunk branches - these have to be dealt with manually. Review collected by and hosted on G2.com.

Verified User in Semiconductors
US
Verified User in Semiconductors
Enterprise (> 1000 emp.)
"Insightful Vulnerability Analysis, But Needs Automatic Analysis"
5/5
What do you like best about Semgrep?

The tool provides an analysis of detected vulnerabilities in the code and also offers suggested fixes. This feature is helpful for identifying potential issues and understanding how to address them. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Currently, I have to manually trigger the analysis each time a new detection occurs, but I would prefer if the analysis happened automatically as soon as something is detected. Review collected by and hosted on G2.com.

Verified User in International Affairs
UI
Verified User in International Affairs
Enterprise (> 1000 emp.)
"Speeds Up Bug Detection, But Rule Syntax Can Be Limiting for Complex Code"
4/5
What do you like best about Semgrep?

The best thing about Semgrep is that it helps catch bugs and enforce code standards early in development, without slowing engineers down. It’s quick, understandable, and fits naturally into the developer workflow. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

My main dislike is that Semgrep’s rule syntax can feel restrictive when dealing with dynamic code or frameworks that rely heavily on metaprogramming. It’s great for straightforward patterns, but deeper semantic analysis sometimes needs more manual effort. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
UH
Verified User in Hospital & Health Care
Enterprise (> 1000 emp.)
"Flexible Rules and GitHub Integration Shine, But Needs Better Product Segmentation"
4.5/5
What do you like best about Semgrep?

Semgrep offers a single platform for SAST and SCA solutions which is good, but the best part is semgrep rules they are so flexible and easy to write that you dont need to manually do filtering or removing.

The tool has another feature I personally like is github actions that will show bugs in git itself with an AI reviewed fixed version. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Semgrep doesnt have Product wise segmentation like for organizations with multiple products you will have only projects and have to use labels to categorise those products. Review collected by and hosted on G2.com.