# Checkmarx vs Semgrep

**Leader by vioscaleAI score:** Semgrep

| Attribute | Checkmarx | Semgrep |
|---|---|---|
| **vioscaleAI score** | 53.6 (46% (low)) | 62.1 (71% (medium)) |
| activity.commits_last_30d | - | 46 |
| adoption.dependent_repos | - | 375 |
| adoption.github_stars | - | 16,630 |
| adoption.package_downloads_weekly | - | 4,480,997 |
| content.faq | `[{"answer":"Checkmarx integrates static analysis (SAST), dynamic analysis (DAST), dependency scanning (SCA), and specialized AI-based analysis to detect vulnerabilities across code, dependencies, and AI components. It prioritizes findings by exploitability and reachability while embedding directly into development tools and CI/CD pipelines. It is indexed under DevSecOps Tools.","source":"https://checkmarx.com","question":"What is Checkmarx?","confidence":0.6},{"answer":"Checkmarx does not publish its prices. Pricing is quoted on request, across 3 plans (Essentials, Professional and Enterprise), so the figure depends on your seat count and requirements. We record this as a pricing-transparency signal rather than guessing a number. Pricing changes often, so verify at source before relying on it.","source":"https://checkmarx.com","question":"How much does Checkmarx cost?","confidence":0.6},{"answer":"We have confirmed browser-based access to Checkmarx. That is the extent of what we could verify from public sources, so it may well offer desktop or mobile clients we have not indexed.","source":"https://checkmarx.com","question":"What platforms does Checkmarx support?","confidence":0.6},{"answer":"We have only confirmed a cloud / SaaS deployment for Checkmarx, so it appears to be vendor-hosted. If a self-hosted option exists we have not found it documented publicly.","source":"https://checkmarx.com","question":"Can Checkmarx be self-hosted?","confidence":0.6},{"answer":"We have independently confirmed SOC 2, ISO 27001 and GDPR for Checkmarx. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Checkmarx not holding them. Always confirm compliance directly before you rely on it.","source":"https://checkmarx.com/blog/security-in-vibe-coding/","question":"What security certifications does Checkmarx have?","confidence":0.7},{"answer":"Checkmarx is available in Australia, Germany, France, the United Kingdom, Israel, India, Portugal and Singapore. The vendor is headquartered in Israel.","source":"https://checkmarx.com","question":"Where is Checkmarx available?","confidence":0.75}]` | `[{"answer":"A SaaS application security platform combining static code analysis, software composition analysis, and secrets detection in one tool. Uses AI to reduce false positives and prioritize exploitable vulnerabilities discovered during development. It is indexed under DevSecOps Tools.","source":"https://semgrep.dev/pricing/","question":"What is Semgrep?","confidence":0.6},{"answer":"Semgrep is open source, so it can be self-hosted and used at no licence cost. It is released under the LGPL-2.1 licence. A commercial or hosted edition starts at $15 per contributor per month. Prices are published openly on the vendor's own pricing page. Pricing changes often, so verify at source before relying on it.","source":"https://semgrep.dev/pricing/","question":"Is Semgrep free to use?","confidence":0.6},{"answer":"Semgrep supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.","source":"https://semgrep.dev/pricing/","question":"What platforms does Semgrep support?","confidence":0.6},{"answer":"Yes. Semgrep can be deployed cloud / SaaS, hybrid, on-premise and self-hosted, so it does not have to run on the vendor's infrastructure.","source":"https://semgrep.dev/pricing/","question":"Can Semgrep be self-hosted?","confidence":0.6},{"answer":"We have confirmed 24 integrations for Semgrep, including GitHub, GitLab, Bitbucket, Jenkins, CircleCI, Azure, Buildkite and HackerOne, plus 16 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.","source":"https://semgrep.dev/pricing/","question":"What does Semgrep integrate with?","confidence":0.6},{"answer":"We have independently confirmed SOC 2 and GDPR for Semgrep. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Semgrep not holding them. Always confirm compliance directly before you rely on it.","source":"https://trust.semgrep.dev","question":"What security certifications does Semgrep have?","confidence":0.7},{"answer":"Yes. Semgrep is published under the LGPL-2.1 licence, a copyleft licence, so check its terms before embedding it in a closed-source product. Licence terms can change between releases, so verify against the repository for the version you intend to use.","source":"https://github.com/semgrep/semgrep","question":"Is Semgrep open source?","confidence":0.95},{"answer":"Semgrep is available worldwide. Its primary market is the United States. The vendor is headquartered in the United States.","source":"https://semgrep.dev/pricing/","question":"Where is Semgrep available?","confidence":0.75}]` |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"self_hosted":true}` |
| description.long | Checkmarx integrates static analysis (SAST), dynamic analysis (DAST), dependency scanning (SCA), and specialized AI-based analysis to detect vulnerabilities across code, dependencies, and AI components. It prioritizes findings by exploitability and reachability while embedding directly into development tools and CI/CD pipelines. | Analyzes code, dependencies, and configuration for security issues, providing developers with actionable findings integrated into their development tools. |
| features.capabilities | `{"sca":true,"dast":true,"sast":true,"sbom":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"iac_scanning":true,"reachability":true,"secret_scanning":true}` | `{"sca":true,"dast":false,"sast":true,"sbom":true,"hosting":"both","ci_native":true,"iso_27001":false,"ide_plugin":true,"auto_fix_pr":true,"open_source":true,"iac_scanning":true,"reachability":true,"soc2_type_ii":false,"pricing_model":"per_developer_seat","secret_scanning":true,"deployment_model":"hybrid","container_scanning":false,"license_compliance":true,"slack_teams_jira_scanning":true,"compliance_audit_reporting":true,"custom_regex_rules_support":true,"pre_commit_developer_hooks":true,"high_entropy_regex_detection":true,"automated_key_revocation_apis":false,"ci_cd_pipeline_build_blocking":true,"active_token_validation_engine":true,"git_repository_historical_scanning":true}` |
| integrations.count | 1 | 20 |
| integrations.list | `[{"name":"Wiz"}]` | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"Bitbucket"},{"name":"Jenkins"},{"name":"CircleCI"},{"name":"Azure"},{"name":"Buildkite"},{"name":"HackerOne"},{"name":"Slack"},{"name":"Email"},{"name":"Webhooks"},{"name":"VS Code"},{"name":"IntelliJ"},{"name":"Jira"},{"name":"Wiz"},{"name":"Palo Alto Networks Cortex"},{"name":"REST API"},{"name":"Cursor"},{"name":"Replit"},{"name":"Codacy"},{"name":"OpenID Connect"},{"name":"SAML"},{"name":"GitHub OAuth"},{"name":"GitLab OAuth"},{"name":"Azure AD"},{"name":"Azure DevOps"},{"name":"Jetbrains"},{"name":"OAuth2"}]` |
| language.primary | - | C |
| license.spdx | - | LGPL-2.1 |
| market.availability | `{"hqCountry":"IL","primaryMarkets":[],"availabilityScope":"global","availableCountries":["AU","DE","FR","GB","IL","IN","PT","SG","US"],"notAvailableCountries":[]}` | `{"hqCountry":"US","primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"cli":true,"mac":true,"web":true}` |
| pricing | `{"type":"quote","plans":[{"free":false,"name":"Essentials","summary":"Custom quote required","features":["SAST","SCA","API Security","ASPM visibility","Core reporting"],"description":"Core application security coverage. Establish a unified foundation for identifying, managing, and reporting application risk.","contactSales":true},{"free":false,"name":"Professional","summary":"Custom quote required","features":["Everything in Essentials","DAST","IaC Security","AI Security","Advanced ASPM","PR Decorations"],"description":"Advanced protection and AI-powered security. Scale your AppSec program with AI-assisted remediation and deeper multi-layer coverage.","contactSales":true},{"free":false,"name":"Enterprise","summary":"Custom quote required","features":["Everything in Professional","Supply Chain Security","Container Security","Runtime Protection","Custom Policies","Executive Reporting"],"description":"Complete coverage and full compliance. Maximum coverage and control for organizations with the most demanding security requirements.","contactSales":true}],"summary":"All three tiers require custom quote. No published per-seat or usage-based pricing.","freeTier":false,"sourceUrl":"https://checkmarx.com","retrievedAt":"2026-08-05T14:23:25.473Z"}` | `{"type":"subscription","plans":[{"free":true,"name":"Free Edition","summary":"Free","features":["Cross-file analysis with Pro rules","AI-powered detection, triage, and remediation","Code scanning","Supply Chain scanning","60 AI credits","Fast CI/CD deploy via Semgrep infrastructure","Authentication via GitHub/GitLab"],"components":[{"kind":"fixed","amount":0,"period":"month","currency":"USD"}],"description":"Get started with core scanning capabilities and AI credits","contactSales":false,"includedLimits":{"ai_credits":"60","contributors":"10 max","repositories":"10 max"}},{"free":false,"name":"Teams","summary":"$30/contributor/mo (Code or Supply Chain) or $15/contributor/mo (Secrets)","features":["One-click CI/CD deploy using Semgrep infrastructure","Single sign-on (SSO)","Award-winning support","Pro Engine with 35+ supported languages","Cross-function Taint Analysis","Cross-file Analysis","Reachability Analysis","Malicious Dependency Detection","SBOM Generation","License Compliance Checking","Semantic and Entropy Analysis","Secret Validation","Pre-Commit Hook","AI-powered detection and remediation","Slack and Email notifications","Jira Ticketing","REST API","OIDC + SAML","RBAC"],"components":[{"kind":"per_unit","unit":"contributor","amount":30,"period":"month","currency":"USD"},{"kind":"per_unit","unit":"contributor","amount":15,"period":"month","currency":"USD"}],"description":"Choose from Code (SAST), Supply Chain (SCA), or Secrets detection modules","contactSales":false,"includedLimits":{"public_repositories":"500 max","ai_credits_per_developer":"20 per month"}},{"free":false,"name":"Enterprise","summary":"Custom pricing. Starts at $30/contributor/mo with volume discounts","features":["Everything in Teams, plus:","Support for on-prem source code management","Support for custom CI/CD integrations","Optional deployment in dedicated infrastructure","Unlimited repositories and contributors","Dedicated account manager","Tailored onboarding","Volume pricing","AI coding agent plugin","Wiz Integration","Palo Alto Networks Cortex Integration"],"description":"Customized solution with dedicated support and flexible deployment options","contactSales":true,"includedLimits":{"contributors":"Unlimited","repositories":"Unlimited","ai_credits_per_developer":"50 per month"}}],"summary":"Free tier available. Teams start at $30/contributor/mo. Enterprise custom pricing with volume discounts.","currency":"USD","freeTier":true,"sourceUrl":"https://semgrep.dev/pricing/","retrievedAt":"2026-08-24T22:43:17.889Z","startingPrice":{"unit":"contributor","amount":15,"period":"month","currency":"USD"},"billingPeriods":["month"]}` |
| pricing.free_tier | no | yes |
| pricing.model | commercial | freemium |
| pricing.price_level | unknown | low |
| pricing.starting_price | - | `{"amount":15,"currency":"USD"}` |
| pricing.transparent | no | no |
| release.cadence_days | - | 7 |
| release.history | - | `[{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.177.0","date":"2026-09-10T19:37:56Z","type":"stable","version":"v1.177.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.176.0","date":"2026-09-01T19:52:12Z","type":"stable","version":"v1.176.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.175.0","date":"2026-08-26T17:08:58Z","type":"stable","version":"v1.175.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.174.0","date":"2026-08-20T15:58:17Z","type":"stable","version":"v1.174.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.173.0","date":"2026-08-13T16:49:55Z","type":"stable","version":"v1.173.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.172.0","date":"2026-07-28T22:40:28Z","type":"stable","version":"v1.172.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.171.0","date":"2026-07-22T23:05:43Z","type":"stable","version":"v1.171.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.170.0","date":"2026-07-15T17:02:36Z","type":"stable","version":"v1.170.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.169.0","date":"2026-07-08T22:47:29Z","type":"stable","version":"v1.169.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.168.0","date":"2026-06-24T19:37:09Z","type":"stable","version":"v1.168.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.167.0","date":"2026-06-17T18:21:17Z","type":"stable","version":"v1.167.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.166.0","date":"2026-06-11T14:00:10Z","type":"stable","version":"v1.166.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.165.0","date":"2026-06-03T22:02:47Z","type":"stable","version":"v1.165.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.164.0","date":"2026-05-27T14:35:42Z","type":"stable","version":"v1.164.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.163.0","date":"2026-05-15T16:06:24Z","type":"stable","version":"v1.163.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.162.0","date":"2026-05-07T16:03:28Z","type":"stable","version":"v1.162.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.161.0","date":"2026-04-22T20:28:49Z","type":"stable","version":"v1.161.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.160.0","date":"2026-04-16T18:11:46Z","type":"stable","version":"v1.160.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.159.0","date":"2026-04-10T21:00:33Z","type":"stable","version":"v1.159.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.158.0","date":"2026-04-10T01:46:48Z","type":"stable","version":"v1.158.0"}]` |
| reliability.status_page | - | yes |
| security.certifications | `[{"name":"SOC 2 Type II","status":"active"},{"name":"ISO 27001","status":"active"}]` | - |
| security.disclosure_policy | - | yes |
| security.fedramp | yes | - |
| security.gdpr | yes | yes |
| security.iso27001 | yes | - |
| security.soc2 | yes | yes |
| security.trust_center | https://checkmarx.com/blog/security-in-vibe-coding/ | - |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=semgrep&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (DevSecOps Tools)

| Capability | Checkmarx | Semgrep |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | ✓ | ✓ |
| DAST (dynamic analysis) | ✓ | ✗ |
| SCA / dependency scanning | ✓ | ✓ |
| Secret scanning | ✓ | ✓ |
| Container / image scanning | - | ✗ |
| IaC misconfiguration scanning | ✓ | ✓ |
| **Governance** |  |  |
| OSS licence compliance | - | ✓ |
| SBOM generation (SPDX/CycloneDX) | ✓ | ✓ |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | - | ✓ |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | ✓ | ✓ |
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | ✓ | ✓ |
| **Licensing** |  |  |
| OSS engine available | - | ✓ |

*Source: vioscaleAI. Generated 2026-09-21T03:35:13.431Z. "-" = undocumented, not absent.*
