# Mend vs Semgrep

| Attribute | Mend | Semgrep |
|---|---|---|
| **Vioscale score** | 59.9 (75% (high)) | 64.7 (76% (high)) |
| activity.commits_last_30d | - | 42 |
| adoption.dependent_repos | - | 375 |
| adoption.github_stars | - | 16,407 |
| adoption.package_downloads_weekly | - | 6,990,780 |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"hybrid":true,"on_prem":true,"self_hosted":true}` |
| description.long | Unified security platform combining static code analysis and open source component scanning to automatically identify, prioritize, and remediate vulnerabilities in custom code and dependencies, with integrated compliance governance and fix automation. | A SaaS application security platform combining static code analysis, software composition analysis, and secrets detection in one tool. Uses AI to reduce false positives and prioritize exploitable vulnerabilities discovered during development. |
| features.capabilities | `{"sca":true,"dast":true,"sast":true,"sbom":true,"hosting":"both","ci_native":true,"ide_plugin":false,"auto_fix_pr":true,"open_source":true,"iac_scanning":false,"reachability":true,"pricing_model":"enterprise_quote","secret_scanning":false,"deployment_model":"cloud_web_app","container_scanning":false,"license_compliance":true}` | `{"sca":true,"dast":false,"sast":true,"sbom":true,"hosting":"both","ci_native":true,"iso_27001":false,"ide_plugin":true,"auto_fix_pr":true,"open_source":true,"iac_scanning":true,"reachability":true,"soc2_type_ii":false,"pricing_model":"per_developer_seat","secret_scanning":true,"deployment_model":"hybrid","container_scanning":false,"license_compliance":true,"slack_teams_jira_scanning":true,"compliance_audit_reporting":true,"custom_regex_rules_support":true,"pre_commit_developer_hooks":true,"high_entropy_regex_detection":true,"automated_key_revocation_apis":false,"ci_cd_pipeline_build_blocking":true,"active_token_validation_engine":true,"git_repository_historical_scanning":true}` |
| integrations.count | 4 | 20 |
| integrations.list | `[{"name":"GitHub"},{"name":"Azure DevOps"},{"name":"GitHub Marketplace"},{"name":"Bitbucket Cloud"},{"name":"Jenkins"},{"name":"Atlassian Bamboo"}]` | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"Bitbucket"},{"name":"Jenkins"},{"name":"CircleCI"},{"name":"Azure"},{"name":"Buildkite"},{"name":"HackerOne"},{"name":"Slack"},{"name":"Email"},{"name":"Webhooks"},{"name":"VS Code"},{"name":"IntelliJ"},{"name":"Jira"},{"name":"Wiz"},{"name":"Palo Alto Networks Cortex"},{"name":"REST API"},{"name":"Cursor"},{"name":"Replit"},{"name":"Codacy"},{"name":"OpenID Connect"},{"name":"SAML"},{"name":"GitHub OAuth"},{"name":"GitLab OAuth"},{"name":"Azure AD"},{"name":"Azure DevOps"},{"name":"Jetbrains"},{"name":"OAuth2"}]` |
| language.primary | - | OCaml |
| license.spdx | - | LGPL-2.1 |
| market.availability | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"hqCountry":"US","primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"enterprise_quote","plans":[{"free":false,"name":"Teams","contactSales":false},{"free":false,"name":"Enterprise","contactSales":true},{"free":true,"name":"Renovate Cloud OSS","description":"Free tier for open source projects and maintainers","contactSales":false}],"summary":"Teams and Enterprise editions; free tier for open source. Contact sales for pricing.","currency":"USD","freeTier":true,"sourceUrl":"https://www.mend.io","retrievedAt":"2026-08-24T22:41:27.445Z"}` | `{"type":"subscription","plans":[{"free":true,"name":"Free Edition","summary":"Free","features":["Cross-file analysis with Pro rules","AI-powered detection, triage, and remediation","Code scanning","Supply Chain scanning","60 AI credits","Fast CI/CD deploy via Semgrep infrastructure","Authentication via GitHub/GitLab"],"components":[{"kind":"fixed","amount":0,"period":"month","currency":"USD"}],"description":"Get started with core scanning capabilities and AI credits","contactSales":false,"includedLimits":{"ai_credits":"60","contributors":"10 max","repositories":"10 max"}},{"free":false,"name":"Teams","summary":"$30/contributor/mo (Code or Supply Chain) or $15/contributor/mo (Secrets)","features":["One-click CI/CD deploy using Semgrep infrastructure","Single sign-on (SSO)","Award-winning support","Pro Engine with 35+ supported languages","Cross-function Taint Analysis","Cross-file Analysis","Reachability Analysis","Malicious Dependency Detection","SBOM Generation","License Compliance Checking","Semantic and Entropy Analysis","Secret Validation","Pre-Commit Hook","AI-powered detection and remediation","Slack and Email notifications","Jira Ticketing","REST API","OIDC + SAML","RBAC"],"components":[{"kind":"per_unit","unit":"contributor","amount":30,"period":"month","currency":"USD"},{"kind":"per_unit","unit":"contributor","amount":15,"period":"month","currency":"USD"}],"description":"Choose from Code (SAST), Supply Chain (SCA), or Secrets detection modules","contactSales":false,"includedLimits":{"public_repositories":"500 max","ai_credits_per_developer":"20 per month"}},{"free":false,"name":"Enterprise","summary":"Custom pricing. Starts at $30/contributor/mo with volume discounts","features":["Everything in Teams, plus:","Support for on-prem source code management","Support for custom CI/CD integrations","Optional deployment in dedicated infrastructure","Unlimited repositories and contributors","Dedicated account manager","Tailored onboarding","Volume pricing","AI coding agent plugin","Wiz Integration","Palo Alto Networks Cortex Integration"],"description":"Customized solution with dedicated support and flexible deployment options","contactSales":true,"includedLimits":{"contributors":"Unlimited","repositories":"Unlimited","ai_credits_per_developer":"50 per month"}}],"summary":"Free tier available. Teams start at $30/contributor/mo. Enterprise custom pricing with volume discounts.","currency":"USD","freeTier":true,"sourceUrl":"https://semgrep.dev/pricing/","retrievedAt":"2026-08-24T22:43:17.889Z","startingPrice":{"unit":"contributor","amount":15,"period":"month","currency":"USD"},"billingPeriods":["month"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | freemium |
| pricing.price_level | low | mid |
| pricing.starting_price | - | `{"amount":15,"currency":"USD"}` |
| pricing.transparent | no | yes |
| release.cadence_days | - | 7 |
| release.history | - | `[{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.175.0","date":"2026-08-26T17:08:58Z","type":"stable","version":"v1.175.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.174.0","date":"2026-08-20T15:58:17Z","type":"stable","version":"v1.174.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.173.0","date":"2026-08-13T16:49:55Z","type":"stable","version":"v1.173.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.172.0","date":"2026-07-28T22:40:28Z","type":"stable","version":"v1.172.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.171.0","date":"2026-07-22T23:05:43Z","type":"stable","version":"v1.171.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.170.0","date":"2026-07-15T17:02:36Z","type":"stable","version":"v1.170.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.169.0","date":"2026-07-08T22:47:29Z","type":"stable","version":"v1.169.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.168.0","date":"2026-06-24T19:37:09Z","type":"stable","version":"v1.168.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.167.0","date":"2026-06-17T18:21:17Z","type":"stable","version":"v1.167.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.166.0","date":"2026-06-11T14:00:10Z","type":"stable","version":"v1.166.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.165.0","date":"2026-06-03T22:02:47Z","type":"stable","version":"v1.165.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.164.0","date":"2026-05-27T14:35:42Z","type":"stable","version":"v1.164.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.163.0","date":"2026-05-15T16:06:24Z","type":"stable","version":"v1.163.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.162.0","date":"2026-05-07T16:03:28Z","type":"stable","version":"v1.162.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.161.0","date":"2026-04-22T20:28:49Z","type":"stable","version":"v1.161.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.160.0","date":"2026-04-16T18:11:46Z","type":"stable","version":"v1.160.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.159.0","date":"2026-04-10T21:00:33Z","type":"stable","version":"v1.159.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.158.0","date":"2026-04-10T01:46:48Z","type":"stable","version":"v1.158.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.157.0","date":"2026-03-31T22:51:26Z","type":"stable","version":"v1.157.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.156.0","date":"2026-03-17T21:18:25Z","type":"stable","version":"v1.156.0"}]` |
| reliability.status_page | yes | yes |
| security.disclosure_policy | - | yes |
| security.gdpr | yes | yes |
| security.iso27001 | yes | - |
| security.soc2 | yes | yes |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=semgrep&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (DevSecOps Tools)

| Capability | Mend | Semgrep |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | ✓ | ✓ |
| DAST (dynamic analysis) | ✓ | ✗ |
| SCA / dependency scanning | ✓ | ✓ |
| Secret scanning | ✗ | ✓ |
| Container / image scanning | ✗ | ✗ |
| IaC misconfiguration scanning | ✗ | ✓ |
| **Governance** |  |  |
| OSS licence compliance | ✓ | ✓ |
| SBOM generation (SPDX/CycloneDX) | ✓ | ✓ |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | ✓ | ✓ |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | ✓ | ✓ |
| **Deployment** |  |  |
| Hosting | Cloud + self-hosted | Cloud + self-hosted |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | ✗ | ✓ |
| **Licensing** |  |  |
| OSS engine available | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T17:15:41.161Z. "-" = undocumented, not absent.*
