Garry P.
GP
Garry P.
Staff Software Engineer
Mid-Market (51-1000 emp.)
"Way better than any other tool *cough* verracode *cough*"
4.5/5
What do you like best about Semgrep?

It's super easy to use and doesn't get in the way. The ability to create custom rules and easily ignore existing rules makes this tool standout above any of the other "static analysis" tools I've used to date. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Honestly, there isn't much I dislike. Perhaps having buttons directly interact with the github comments would be nice? Review collected by and hosted on G2.com.

Verified User in Financial Services
CF
Verified User in Financial Services
Enterprise (> 1000 emp.)
"Semgrep is a plus with continuous management & tracking of open vulnerabilities."
4.5/5
What do you like best about Semgrep?

Useful for tracking the open vulnerabilities, repository wise, until they're closed. I find the ability to create custom vulnerability config manually to be very useful, to extend the functionality beyond the vulnerabilities that could be picked up by existing available config templates. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

I think the findings could be improved. There's a limit to what static analysis tools can dig out from the code, and probably it's the limitation of technology itself, rather than semgrep. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Enterprise (> 1000 emp.)
"Easy to use and powerful"
4.5/5
What do you like best about Semgrep?

Very easy to use, no matter which language you are using. Unlike more legacy static code analysis tools, there is no need to spend a lot of time learning rule types and syntaxes; new rules can be spun up and tested very quickly. Also, results are of high quality. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Community support is not as developed as they are pretty new. The breadth of rules and integrations is not as extensive as some other tools. However, this is improving rapidly and the rules that are present have much lesser false positives. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Verified User in Computer Software
Enterprise (> 1000 emp.)
"Semgrep helped us catch security bugs while scaling and supporting our code review processes"
5/5
What do you like best about Semgrep?

Semgrep's powerful rule language and engine blends usability with flexibility. Developers being able to write their own rules in Semgrep without knowing exactly how Semgrep works has helped us scale our deployment. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Without fine-tuning, Semgrep (like any SAST) can be pretty noisy. I know they've been working on surfacing developer feedback to rule writers and maintainers, but I still wish there was a more scalable way to reduce noise (e.g. rule change suggestions based on where developers report false positives). Review collected by and hosted on G2.com.

Verified User in Financial Services
UF
Verified User in Financial Services
Mid-Market (51-1000 emp.)
"Great community driven SAST"
5/5
What do you like best about Semgrep?

We were sold on the idea that Semgrep was Python based and detections were community driven. While still providing us with the ability to write custom detections. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Nothing in particular. If anything, I'd like Semgrep to add GitHub Dependabot / Snyk like features so we can manage more controls around our source code through a single vendor. The latest Supply Chain feature is a new addition. Review collected by and hosted on G2.com.

Avinash S.
AS
Avinash S.
Security Lead
Mid-Market (51-1000 emp.)
"No place for False Positives"
5/5
What do you like best about Semgrep?

It is the most efficient and simple to use integration for SAST.

Free, and community-driven

Discussions on Slack channels provide valuable help and insights. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Nothing major. It is evolving in right direction.

But A trial version would be good. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Enterprise (> 1000 emp.)
"Semgrep is best in class for customizability, ease of use, and support"
4/5
What do you like best about Semgrep?

Semgrep makes it really easy to write rules. It's really straightforward and the UI also allows you to easily get feedback on rules as well. The dashboard is also convenient and simple to use. The customer support is also pretty amazing, in that they will help you over a meeting with issues you may have with implementation. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

The binary has been buggy in the past, and has required some debugging and patching to get working correctly. However, the Semgrep team was helpful with the entire process. Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Verified User in Financial Services
Mid-Market (51-1000 emp.)
"Quick and effective SAST and Dependency Checking"
4.5/5
What do you like best about Semgrep?

Super easy to implement and manage. Seamless integration into our CI pipeline, and only gets in the developers' way when it needs to. Reachability testing of depenencies is nice. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Not too much to dislike. The Supply Chain/dependency scanning is new and will need more rules for reachability, but these are gradually being built. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Verified User in Computer Software
Enterprise (> 1000 emp.)
"Good set of rules, but a bunch of false positives"
3.5/5
What do you like best about Semgrep?

The upsides are that code scanning is very fast, and the ruleset is complete. Rule management on the rule board is also very easy. Integrations and webhooks are a plus. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

The downsides are that the number of false positives for some of the rules is enormous due to the lack of taint tracking support for PHP. Improving this ruleset, or adding taint tracking for PHP would be most helpful. Review collected by and hosted on G2.com.

Verified User in Biotechnology
UB
Verified User in Biotechnology
Mid-Market (51-1000 emp.)
"Excellent tool for outlining security vulnerabilities within your application"
4/5
What do you like best about Semgrep?

Great analysis of vulnerabilities with ability to review, rank and update status of each incident Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

It would be great if Semgrep did further static analysis to cover code smells and code coverage, in addition to security. Review collected by and hosted on G2.com.