Product Avatar Image

Semgrep

Show rating breakdown
56 reviews
  • 4 profiles
  • 9 categories
Average star rating
4.6
Serving customers since
2017
Profile Filters

All Products & Services

Product Avatar Image
Semgrep

56 reviews

Find bugs, run security scans in CI, and enforce security standards across your organization. Scale your security team. Actionable, low-noise, and developer-friendly results let you scale your security and ship with high velocity. Enable developers to be more productive. Reduce friction between security engineers and developers by finding and sharing vulnerabilities in your code and in open source dependencies. Easily write custom rules. Easily write rules to find bugs specific to your organization — rules look like source code, so there’s no need to learn a new proprietary language.

Product Avatar Image
Semgrep Secrets

0 reviews

Semgrep Secrets is an advanced security tool designed to detect and remediate hardcoded secrets, such as API keys and passwords, within your codebase. By employing semantic analysis, entropy analysis, and validation techniques, it accurately identifies sensitive credentials that traditional regex-based scanners might miss. This ensures that potential security vulnerabilities are addressed promptly, safeguarding your systems and data from unauthorized access.

Product Avatar Image
Semgrep Supply Chain

0 reviews

Semgrep Supply Chain is a software composition analysis (SCA) tool designed to identify and remediate security vulnerabilities introduced by open-source dependencies within your codebase. By leveraging high-signal rules and reachability analysis, it effectively filters out false positives, allowing development teams to focus on the most critical and actionable issues.

Product Avatar Image
Semgrep Code

0 reviews

Semgrep Code is a static application security testing (SAST) solution designed to help developers identify and remediate security vulnerabilities within their codebases. By integrating seamlessly into development workflows, Semgrep Code enables continuous scanning of code repositories, providing actionable insights to enhance code security. Supporting over 30 programming languages, it offers high-confidence rules that facilitate efficient and effective vulnerability detection and resolution.

Profile Name

Star Rating

45
9
2
0
0

Semgrep Reviews

Review Filters
Profile Name
Star Rating
45
9
2
0
0
Verified User in International Affairs
UI
Verified User in International Affairs
10/21/2025
Validated Reviewer
Review source: Seller invite
Incentivized Review

Speeds Up Bug Detection, But Rule Syntax Can Be Limiting for Complex Code

The best thing about Semgrep is that it helps catch bugs and enforce code standards early in development, without slowing engineers down. It’s quick, understandable, and fits naturally into the developer workflow.
Shuiab S.
SS
Shuiab S.
10/21/2025
Validated Reviewer
Review source: Seller invite
Incentivized Review

Clean Interface and Clear Insights, But Setup Can Be Frustrating

The interface is extremely clean, and all vulnerabilities are clearly highlighted.
Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
10/21/2025
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review

Semgrep: A Powerful and Customizable SAST Solution

The most significant advantage of Semgrep is its highly customizable rule engine and ease of rule writing. The ability to define custom rules in YAML, tailored to specific codebases and threat models, sets it apart from many other SAST solutions. This flexibility allows for precise detection of custom vulnerabilities and adherence to specific coding standards. Its lightweight nature and rapid execution in CI/CD pipelines are also highly beneficial, enabling fast feedback loops without significantly impacting build times. Furthermore, the open-source core provides transparency and allows for community contributions and audits of the rule execution. The reachability analysis in Semgrep Supply Chain is also a standout feature, significantly reducing false positives by focusing on truly exploitable vulnerabilities within third-party components.

About

Contact

HQ Location:
San Francisco, US

Social

@semgrep

What is Semgrep?

Semgrep is a powerful, open-source static analysis tool designed to help developers identify bugs, enforce code standards, and find security vulnerabilities. Utilizing a syntax-aware code pattern search for several programming languages, Semgrep allows for more precise and comprehensive analyses than traditional regex-based approaches. Its rules can be customized to fit specific project needs, making it highly adaptable for individual or organizational use.Semgrep supports a wide range of programming languages, including Java, JavaScript, Python, Go, Ruby, and more, ensuring its usefulness across various software projects. The tool is also known for its speed and efficiency, providing real-time feedback that integrates seamlessly into the development workflow.Developers and teams can explore the capabilities of Semgrep and access its extensive rule sets by visiting [Semgrep.dev](https://semgrep.dev), where they can also contribute to its growing community and access further documentation and support.Whether you are looking to improve code quality, enhance security, or enforce coding standards, Semgrep provides a robust framework that can be tailored to meet diverse development needs.

Details

Year Founded
2017
Website
semgrep.dev