Introducing G2.ai, the future of software buying.Try now
Product Avatar Image

Semgrep

Show rating breakdown
54 reviews
  • 4 profiles
  • 9 categories
Average star rating
4.6
Serving customers since
2017
Profile Filters

All Products & Services

Product Avatar Image
Semgrep

54 reviews

Find bugs, run security scans in CI, and enforce security standards across your organization. Scale your security team. Actionable, low-noise, and developer-friendly results let you scale your security and ship with high velocity. Enable developers to be more productive. Reduce friction between security engineers and developers by finding and sharing vulnerabilities in your code and in open source dependencies. Easily write custom rules. Easily write rules to find bugs specific to your organization — rules look like source code, so there’s no need to learn a new proprietary language.

Product Avatar Image
Semgrep Secrets

0 reviews

Semgrep Secrets is an advanced security tool designed to detect and remediate hardcoded secrets, such as API keys and passwords, within your codebase. By employing semantic analysis, entropy analysis, and validation techniques, it accurately identifies sensitive credentials that traditional regex-based scanners might miss. This ensures that potential security vulnerabilities are addressed promptly, safeguarding your systems and data from unauthorized access.

Product Avatar Image
Semgrep Supply Chain

0 reviews

Semgrep Supply Chain is a software composition analysis (SCA) tool designed to identify and remediate security vulnerabilities introduced by open-source dependencies within your codebase. By leveraging high-signal rules and reachability analysis, it effectively filters out false positives, allowing development teams to focus on the most critical and actionable issues.

Product Avatar Image
Semgrep Code

0 reviews

Semgrep Code is a static application security testing (SAST) solution designed to help developers identify and remediate security vulnerabilities within their codebases. By integrating seamlessly into development workflows, Semgrep Code enables continuous scanning of code repositories, providing actionable insights to enhance code security. Supporting over 30 programming languages, it offers high-confidence rules that facilitate efficient and effective vulnerability detection and resolution.

Profile Name

Star Rating

43
9
2
0
0

Semgrep Reviews

Review Filters
Profile Name
Star Rating
43
9
2
0
0
Shreekanth k.
SK
Shreekanth k.
11/19/2025
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review

Streamlined Code Security with Semgrep

I appreciate using Semgrep for its robust security scanning capabilities, particularly in our code security scans for Azure Data Factory, Azure Databricks notebooks, and Python code. The setup was straightforward and integrated seamlessly into our pipeline without much hassle, demonstrating an ease of use that contrasts sharply with other tools. One of the standout features for me is the low false positive rate; it effectively identifies actual security issues without wasting time on false alerts, which makes it incredibly efficient. The built-in rules are comprehensive, covering most major languages we use and providing thorough checks for common vulnerabilities. The scan results are transparent and actionable, pinpointing the exact line in the code where issues arise and offering clear guidance on how to fix them, significantly speeding up remediation. I also find the performance to be solid, not hindering our build processes with delays. Additionally, after investing time in learning how to write custom rules tailored to our specific needs, I realized the powerful flexibility Semgrep offers. Overall, it has markedly enhanced our code review process by focusing attention on genuine issues and aiding in the early detection of security concerns. This has ultimately strengthened our development workflow and reduced the time spent on security risks. I wholeheartedly recommend Semgrep as a practical SAST tool that delivers exceptional results while being manageable to maintain.
Anupam J.
AJ
Anupam J.
Java, Spring Boot, Microservices & Backend Systems | Adobe Commerce & FinTech Expert | Google Cloud Certified | PG in AI/ML(IIITB) | MS (Pursuing)
11/01/2025
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review

Powerful Rule Engine and Autofix, but Governance at Scale Needs Work

Flexible, transparent rule engine with clear YAML syntax and data‑flow patterns, plus an extensive public registry for quick wins and customization. • Smooth CI/CD integration and lightweight runtime, enabling frequent scans without major impact on developer velocity. • Autofix capabilities (deterministic rule‑based and Assistant AI‑assisted) that propose or apply safe code changes, reducing mean time to remediate
Nagaraju A.
NA
Nagaraju A.
Delivery Manager @ Enhops (A ProArch Company) | ISTQB Certified tester
10/31/2025
Validated Reviewer
Review source: Seller invite
Incentivized Review

Easy to Use with Great Functional Testing Capabilities

I appreciate how Semgrep excels in validating and QA testing capabilities, showing good efficacy in performing these tasks. The ease of use is particularly notable, requiring less scripting compared to other alternatives, and the initial setup process was straightforward and effortless. I value its functionality in conducting functional testing, which simplifies my tasks significantly. The test case design and resulting outcomes are particularly pleasing, enhancing my testing process. Whenever I encounter issues that other tools cannot resolve, Semgrep becomes an indispensable resource, allowing me to progress by utilizing its features effectively. Overall, I find Semgrep a worthy exploration for its functionality and user-friendly approach.

About

Contact

HQ Location:
San Francisco, US

Social

@semgrep

What is Semgrep?

Semgrep is a powerful, open-source static analysis tool designed to help developers identify bugs, enforce code standards, and find security vulnerabilities. Utilizing a syntax-aware code pattern search for several programming languages, Semgrep allows for more precise and comprehensive analyses than traditional regex-based approaches. Its rules can be customized to fit specific project needs, making it highly adaptable for individual or organizational use.Semgrep supports a wide range of programming languages, including Java, JavaScript, Python, Go, Ruby, and more, ensuring its usefulness across various software projects. The tool is also known for its speed and efficiency, providing real-time feedback that integrates seamlessly into the development workflow.Developers and teams can explore the capabilities of Semgrep and access its extensive rule sets by visiting [Semgrep.dev](https://semgrep.dev), where they can also contribute to its growing community and access further documentation and support.Whether you are looking to improve code quality, enhance security, or enforce coding standards, Semgrep provides a robust framework that can be tailored to meet diverse development needs.

Details

Year Founded
2017