# OWASP ZAP vs Semgrep

**Leader by Vioscale score:** Semgrep

| Attribute | OWASP ZAP | Semgrep |
|---|---|---|
| **Vioscale score** | 51.1 (41% (low)) | 64.7 (76% (high)) |
| activity.commits_last_30d | 34 | 42 |
| adoption.dependent_repos | 30 | 375 |
| adoption.github_stars | 15,685 | 16,407 |
| adoption.package_downloads_weekly | - | 6,990,780 |
| deployment.options | `{"self_hosted":true}` | `{"cloud":true,"hybrid":true,"on_prem":true,"self_hosted":true}` |
| description.long | An open-source security scanner that performs dynamic analysis on web applications to detect potential vulnerabilities. It supports automation, extensibility through community add-ons, and integrates with CI/CD pipelines. | A SaaS application security platform combining static code analysis, software composition analysis, and secrets detection in one tool. Uses AI to reduce false positives and prioritize exploitable vulnerabilities discovered during development. |
| features.capabilities | `{"dast":true,"hosting":"self","ci_native":true,"open_source":true}` | `{"sca":true,"dast":false,"sast":true,"sbom":true,"hosting":"both","ci_native":true,"iso_27001":false,"ide_plugin":true,"auto_fix_pr":true,"open_source":true,"iac_scanning":true,"reachability":true,"soc2_type_ii":false,"pricing_model":"per_developer_seat","secret_scanning":true,"deployment_model":"hybrid","container_scanning":false,"license_compliance":true,"slack_teams_jira_scanning":true,"compliance_audit_reporting":true,"custom_regex_rules_support":true,"pre_commit_developer_hooks":true,"high_entropy_regex_detection":true,"automated_key_revocation_apis":false,"ci_cd_pipeline_build_blocking":true,"active_token_validation_engine":true,"git_repository_historical_scanning":true}` |
| integrations.count | 2 | 20 |
| integrations.list | `[{"name":"GitHub"},{"name":"GitHub Actions"}]` | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"Bitbucket"},{"name":"Jenkins"},{"name":"CircleCI"},{"name":"Azure"},{"name":"Buildkite"},{"name":"HackerOne"},{"name":"Slack"},{"name":"Email"},{"name":"Webhooks"},{"name":"VS Code"},{"name":"IntelliJ"},{"name":"Jira"},{"name":"Wiz"},{"name":"Palo Alto Networks Cortex"},{"name":"REST API"},{"name":"Cursor"},{"name":"Replit"},{"name":"Codacy"},{"name":"OpenID Connect"},{"name":"SAML"},{"name":"GitHub OAuth"},{"name":"GitLab OAuth"},{"name":"Azure AD"},{"name":"Azure DevOps"},{"name":"Jetbrains"},{"name":"OAuth2"}]` |
| language.primary | Java | OCaml |
| license.spdx | Apache-2.0 | LGPL-2.1 |
| market.availability | - | `{"hqCountry":"US","primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | - | `{"cli":true,"web":true}` |
| pricing | `{"type":"open_source","freeTier":true,"sourceUrl":"https://www.zaproxy.org","retrievedAt":"2026-08-14T15:30:17.577Z"}` | `{"type":"subscription","plans":[{"free":true,"name":"Free Edition","summary":"Free","features":["Cross-file analysis with Pro rules","AI-powered detection, triage, and remediation","Code scanning","Supply Chain scanning","60 AI credits","Fast CI/CD deploy via Semgrep infrastructure","Authentication via GitHub/GitLab"],"components":[{"kind":"fixed","amount":0,"period":"month","currency":"USD"}],"description":"Get started with core scanning capabilities and AI credits","contactSales":false,"includedLimits":{"ai_credits":"60","contributors":"10 max","repositories":"10 max"}},{"free":false,"name":"Teams","summary":"$30/contributor/mo (Code or Supply Chain) or $15/contributor/mo (Secrets)","features":["One-click CI/CD deploy using Semgrep infrastructure","Single sign-on (SSO)","Award-winning support","Pro Engine with 35+ supported languages","Cross-function Taint Analysis","Cross-file Analysis","Reachability Analysis","Malicious Dependency Detection","SBOM Generation","License Compliance Checking","Semantic and Entropy Analysis","Secret Validation","Pre-Commit Hook","AI-powered detection and remediation","Slack and Email notifications","Jira Ticketing","REST API","OIDC + SAML","RBAC"],"components":[{"kind":"per_unit","unit":"contributor","amount":30,"period":"month","currency":"USD"},{"kind":"per_unit","unit":"contributor","amount":15,"period":"month","currency":"USD"}],"description":"Choose from Code (SAST), Supply Chain (SCA), or Secrets detection modules","contactSales":false,"includedLimits":{"public_repositories":"500 max","ai_credits_per_developer":"20 per month"}},{"free":false,"name":"Enterprise","summary":"Custom pricing. Starts at $30/contributor/mo with volume discounts","features":["Everything in Teams, plus:","Support for on-prem source code management","Support for custom CI/CD integrations","Optional deployment in dedicated infrastructure","Unlimited repositories and contributors","Dedicated account manager","Tailored onboarding","Volume pricing","AI coding agent plugin","Wiz Integration","Palo Alto Networks Cortex Integration"],"description":"Customized solution with dedicated support and flexible deployment options","contactSales":true,"includedLimits":{"contributors":"Unlimited","repositories":"Unlimited","ai_credits_per_developer":"50 per month"}}],"summary":"Free tier available. Teams start at $30/contributor/mo. Enterprise custom pricing with volume discounts.","currency":"USD","freeTier":true,"sourceUrl":"https://semgrep.dev/pricing/","retrievedAt":"2026-08-24T22:43:17.889Z","startingPrice":{"unit":"contributor","amount":15,"period":"month","currency":"USD"},"billingPeriods":["month"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | open_source | freemium |
| pricing.price_level | free | mid |
| pricing.starting_price | - | `{"amount":15,"currency":"USD"}` |
| pricing.transparent | - | yes |
| release.cadence_days | 6 | 7 |
| release.history | `[{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-26","date":"2026-08-26T08:35:57Z","type":"prerelease","version":"w2026-08-26"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-19","date":"2026-08-19T10:51:56Z","type":"prerelease","version":"w2026-08-19"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-11","date":"2026-08-11T14:53:54Z","type":"prerelease","version":"w2026-08-11"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-06","date":"2026-08-06T14:19:52Z","type":"prerelease","version":"w2026-08-06"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-28","date":"2026-07-28T11:12:43Z","type":"prerelease","version":"w2026-07-28"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-21","date":"2026-07-21T16:10:37Z","type":"prerelease","version":"w2026-07-21"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-14","date":"2026-07-14T13:46:09Z","type":"prerelease","version":"w2026-07-14"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-13","date":"2026-07-13T15:29:09Z","type":"prerelease","version":"w2026-07-13"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-06","date":"2026-07-06T14:25:44Z","type":"prerelease","version":"w2026-07-06"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-30","date":"2026-06-30T14:30:23Z","type":"prerelease","version":"w2026-06-30"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-29","date":"2026-06-29T14:01:46Z","type":"prerelease","version":"w2026-06-29"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-24","date":"2026-06-24T16:56:19Z","type":"prerelease","version":"w2026-06-24"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-23","date":"2026-06-23T16:18:04Z","type":"prerelease","version":"w2026-06-23"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-16","date":"2026-06-16T16:08:49Z","type":"prerelease","version":"w2026-06-16"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-09","date":"2026-06-09T13:57:54Z","type":"prerelease","version":"w2026-06-09"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-01","date":"2026-06-01T18:13:38Z","type":"prerelease","version":"w2026-06-01"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-27","date":"2026-05-27T16:59:12Z","type":"prerelease","version":"w2026-05-27"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-18","date":"2026-05-18T16:47:20Z","type":"prerelease","version":"w2026-05-18"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-12","date":"2026-05-12T13:45:04Z","type":"prerelease","version":"w2026-05-12"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-05","date":"2026-05-05T16:56:04Z","type":"prerelease","version":"w2026-05-05"}]` | `[{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.175.0","date":"2026-08-26T17:08:58Z","type":"stable","version":"v1.175.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.174.0","date":"2026-08-20T15:58:17Z","type":"stable","version":"v1.174.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.173.0","date":"2026-08-13T16:49:55Z","type":"stable","version":"v1.173.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.172.0","date":"2026-07-28T22:40:28Z","type":"stable","version":"v1.172.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.171.0","date":"2026-07-22T23:05:43Z","type":"stable","version":"v1.171.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.170.0","date":"2026-07-15T17:02:36Z","type":"stable","version":"v1.170.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.169.0","date":"2026-07-08T22:47:29Z","type":"stable","version":"v1.169.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.168.0","date":"2026-06-24T19:37:09Z","type":"stable","version":"v1.168.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.167.0","date":"2026-06-17T18:21:17Z","type":"stable","version":"v1.167.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.166.0","date":"2026-06-11T14:00:10Z","type":"stable","version":"v1.166.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.165.0","date":"2026-06-03T22:02:47Z","type":"stable","version":"v1.165.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.164.0","date":"2026-05-27T14:35:42Z","type":"stable","version":"v1.164.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.163.0","date":"2026-05-15T16:06:24Z","type":"stable","version":"v1.163.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.162.0","date":"2026-05-07T16:03:28Z","type":"stable","version":"v1.162.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.161.0","date":"2026-04-22T20:28:49Z","type":"stable","version":"v1.161.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.160.0","date":"2026-04-16T18:11:46Z","type":"stable","version":"v1.160.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.159.0","date":"2026-04-10T21:00:33Z","type":"stable","version":"v1.159.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.158.0","date":"2026-04-10T01:46:48Z","type":"stable","version":"v1.158.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.157.0","date":"2026-03-31T22:51:26Z","type":"stable","version":"v1.157.0"},{"url":"https://github.com/semgrep/semgrep/releases/tag/v1.156.0","date":"2026-03-17T21:18:25Z","type":"stable","version":"v1.156.0"}]` |
| reliability.status_page | - | yes |
| security.disclosure_policy | yes | yes |
| security.gdpr | - | yes |
| security.scorecard | 6.8 | - |
| security.soc2 | - | yes |
| security.vulnerabilities | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.zaproxy%3Azap&per_page=100","last_12m":0,"max_severity":"MODERATE"}` | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=semgrep&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (DevSecOps Tools)

| Capability | OWASP ZAP | Semgrep |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | - | ✓ |
| DAST (dynamic analysis) | ✓ | ✗ |
| SCA / dependency scanning | - | ✓ |
| Secret scanning | - | ✓ |
| Container / image scanning | - | ✗ |
| IaC misconfiguration scanning | - | ✓ |
| **Governance** |  |  |
| OSS licence compliance | - | ✓ |
| SBOM generation (SPDX/CycloneDX) | - | ✓ |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | - | ✓ |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | - | ✓ |
| **Deployment** |  |  |
| Hosting | Self-hosted only | Cloud + self-hosted |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | - | ✓ |
| **Licensing** |  |  |
| OSS engine available | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T14:47:04.288Z. "-" = undocumented, not absent.*
