Product Avatar Image

Semgrep

Show rating breakdown
56 reviews
  • 4 profiles
  • 9 categories
Average star rating
4.6
Serving customers since
2017
Profile Filters

All Products & Services

Product Avatar Image
Semgrep

56 reviews

Find bugs, run security scans in CI, and enforce security standards across your organization. Scale your security team. Actionable, low-noise, and developer-friendly results let you scale your security and ship with high velocity. Enable developers to be more productive. Reduce friction between security engineers and developers by finding and sharing vulnerabilities in your code and in open source dependencies. Easily write custom rules. Easily write rules to find bugs specific to your organization — rules look like source code, so there’s no need to learn a new proprietary language.

Product Avatar Image
Semgrep Secrets

0 reviews

Semgrep Secrets is an advanced security tool designed to detect and remediate hardcoded secrets, such as API keys and passwords, within your codebase. By employing semantic analysis, entropy analysis, and validation techniques, it accurately identifies sensitive credentials that traditional regex-based scanners might miss. This ensures that potential security vulnerabilities are addressed promptly, safeguarding your systems and data from unauthorized access.

Product Avatar Image
Semgrep Supply Chain

0 reviews

Semgrep Supply Chain is a software composition analysis (SCA) tool designed to identify and remediate security vulnerabilities introduced by open-source dependencies within your codebase. By leveraging high-signal rules and reachability analysis, it effectively filters out false positives, allowing development teams to focus on the most critical and actionable issues.

Product Avatar Image
Semgrep Code

0 reviews

Semgrep Code is a static application security testing (SAST) solution designed to help developers identify and remediate security vulnerabilities within their codebases. By integrating seamlessly into development workflows, Semgrep Code enables continuous scanning of code repositories, providing actionable insights to enhance code security. Supporting over 30 programming languages, it offers high-confidence rules that facilitate efficient and effective vulnerability detection and resolution.

Profile Name

Star Rating

45
9
2
0
0

Semgrep Reviews

Review Filters
Profile Name
Star Rating
45
9
2
0
0
Verified User in Manufacturing
UM
Verified User in Manufacturing
10/22/2025
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review

Powerful, Customizable Static Analysis with Fast Scans—Some Learning Curve and Tuning Needed

Semgrep is a static analysis tool that enables developers to create custom rules using an intuitive pattern-matching syntax, which closely mirrors the code being reviewed. It offers support for a variety of programming languages, including Python, JavaScript, Java, and Go, among others. With Semgrep, users can identify security vulnerabilities, address code quality concerns, and enforce coding standards effectively. Many developers value its seamless integration with CI/CD pipelines, the ability to run scans locally during development, and the flexibility to craft rules tailored to their organization's codebase. The tool is known for its rapid scanning capabilities and lower false positive rates when compared to more traditional static analysis solutions. Additionally, Semgrep is available in both open-source and commercial versions, with advanced features such as centralized rule management and options for team collaboration.
Verified User in Manufacturing
UM
Verified User in Manufacturing
10/22/2025
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review

Fast, Accurate, and Seamless Integration with GitHub

The feedback is fast and actionable, which makes it easy to address issues quickly. I also appreciate the reduced number of false positives, as it saves time and effort. Integration with GitHub and Actions is seamless, making the workflow smooth. The accuracy is high, and the support for a wide range of languages is another strong point.
MA
Mohammad A.
10/22/2025
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review

Great Experience, But UI Could Be More User-Friendly

Semgrep is one of the super easy and most lightweight tools for detecting security vulnerabilities in our codebase. It also enables us to scan our local repositories and can be integrated with our CI/CD pipeline to provide continuous code scanning. We prefer using it with almost all of our applications to feel more confident.

About

Contact

HQ Location:
San Francisco, US

Social

@semgrep

What is Semgrep?

Semgrep is a powerful, open-source static analysis tool designed to help developers identify bugs, enforce code standards, and find security vulnerabilities. Utilizing a syntax-aware code pattern search for several programming languages, Semgrep allows for more precise and comprehensive analyses than traditional regex-based approaches. Its rules can be customized to fit specific project needs, making it highly adaptable for individual or organizational use.Semgrep supports a wide range of programming languages, including Java, JavaScript, Python, Go, Ruby, and more, ensuring its usefulness across various software projects. The tool is also known for its speed and efficiency, providing real-time feedback that integrates seamlessly into the development workflow.Developers and teams can explore the capabilities of Semgrep and access its extensive rule sets by visiting [Semgrep.dev](https://semgrep.dev), where they can also contribute to its growing community and access further documentation and support.Whether you are looking to improve code quality, enhance security, or enforce coding standards, Semgrep provides a robust framework that can be tailored to meet diverse development needs.

Details

Year Founded
2017
Website
semgrep.dev