Available worldwide · Popular in: US
What is Semgrep?
Analyzes code, dependencies, and configuration for security issues, providing developers with actionable findings integrated into their development tools.
Semgrep pricing
Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.
Free tier available. Teams start at $30/contributor/mo. Enterprise custom pricing with volume discounts.
Free Edition
FreeGet started with core scanning capabilities and AI credits
- ai_credits
- 60
- contributors
- 10 max
- repositories
- 10 max
- Cross-file analysis with Pro rules
- AI-powered detection, triage, and remediation
- Code scanning
- Supply Chain scanning
- 60 AI credits
- Fast CI/CD deploy via Semgrep infrastructure
- Authentication via GitHub/GitLab
Teams
Choose from Code (SAST), Supply Chain (SCA), or Secrets detection modules
- public_repositories
- 500 max
- ai_credits_per_developer
- 20 per month
- One-click CI/CD deploy using Semgrep infrastructure
- Single sign-on (SSO)
- Award-winning support
- Pro Engine with 35+ supported languages
- Cross-function Taint Analysis
- Cross-file Analysis
- Reachability Analysis
- Malicious Dependency Detection
- SBOM Generation
- License Compliance Checking
- Semantic and Entropy Analysis
- Secret Validation
- Pre-Commit Hook
- AI-powered detection and remediation
- Slack and Email notifications
- Jira Ticketing
- REST API
- OIDC + SAML
- RBAC
Enterprise
Contact salesCustomized solution with dedicated support and flexible deployment options
- contributors
- Unlimited
- repositories
- Unlimited
- ai_credits_per_developer
- 50 per month
- Everything in Teams, plus:
- Support for on-prem source code management
- Support for custom CI/CD integrations
- Optional deployment in dedicated infrastructure
- Unlimited repositories and contributors
- Dedicated account manager
- Tailored onboarding
- Volume pricing
- AI coding agent plugin
- Wiz Integration
- Palo Alto Networks Cortex Integration
What Semgrep does
The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- SAST (static analysis)
- ✓
- DAST (dynamic analysis)
- ✗
- SCA / dependency scanning
- ✓
- Secret scanning
- ✓
- Container / image scanning
- ✗
- IaC misconfiguration scanning
- ✓
- OSS licence compliance
- ✓
- SBOM generation (SPDX/CycloneDX)
- ✓
- Automated fix / upgrade PRs
- ✓
- Reachability / exploitability prioritisation
- ✓
- Hosting
- Cloud + self-hosted
- First-class CI / pipeline integration
- ✓
- In-editor / IDE scanning
- ✓
- OSS engine available
- ✓
Platform & deployment
Independently observed- CLI
- macOS
- Web
- Cloud / SaaS
- Self-hosted
Integrations (28)
Independently observed- GitHub
- GitLab
- Bitbucket
- Jenkins
- CircleCI
- Azure
- Buildkite
- HackerOne
- Slack
- Webhooks
- VS Code
- IntelliJ
- Jira
- Wiz
- Palo Alto Networks Cortex
- REST API
- Cursor
- Replit
- Codacy
- OpenID Connect
- SAML
- GitHub OAuth
- GitLab OAuth
- Azure AD
- Azure DevOps
- Jetbrains
- OAuth2
Security & compliance
Known vulnerabilities: 0 (0 in the last 12 months) sourcea count reflects scale & disclosure, not quality
Semgrep FAQ
Common questions about Semgrep, answered from independent, dated evidence.
What is Semgrep?
A SaaS application security platform combining static code analysis, software composition analysis, and secrets detection in one tool. Uses AI to reduce false positives and prioritize exploitable vulnerabilities discovered during development. It is indexed under DevSecOps Tools.
Source: https://semgrep.dev/pricing/
Is Semgrep free to use?
Semgrep is open source, so it can be self-hosted and used at no licence cost. It is released under the LGPL-2.1 licence. A commercial or hosted edition starts at $15 per contributor per month. Prices are published openly on the vendor's own pricing page. Pricing changes often, so verify at source before relying on it.
Source: https://semgrep.dev/pricing/
What platforms does Semgrep support?
Semgrep supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.
Source: https://semgrep.dev/pricing/
Can Semgrep be self-hosted?
Yes. Semgrep can be deployed cloud / SaaS, hybrid, on-premise and self-hosted, so it does not have to run on the vendor's infrastructure.
Source: https://semgrep.dev/pricing/
What does Semgrep integrate with?
We have confirmed 24 integrations for Semgrep, including GitHub, GitLab, Bitbucket, Jenkins, CircleCI, Azure, Buildkite and HackerOne, plus 16 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.
Source: https://semgrep.dev/pricing/
What security certifications does Semgrep have?
We have independently confirmed SOC 2 and GDPR for Semgrep. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Semgrep not holding them. Always confirm compliance directly before you rely on it.
Source: https://trust.semgrep.dev
Is Semgrep open source?
Yes. Semgrep is published under the LGPL-2.1 licence, a copyleft licence, so check its terms before embedding it in a closed-source product. Licence terms can change between releases, so verify against the repository for the version you intend to use.
Where is Semgrep available?
Semgrep is available worldwide. Its primary market is the United States. The vendor is headquartered in the United States.
Source: https://semgrep.dev/pricing/
Semgrep alternatives
Other devsecops tools we track, ranked by the same independent score.
- SnykContinuous validation layer for AI-generated code and development agentshigh · 75%
- SonarQubeAutomated static analysis platform that identifies and helps fix code quality issues, security vulnerabilities, and bugs throughout the development lifecyclehigh · 76%
- GitGuardianDetect and prevent credential exposure across your code and infrastructuremedium · 72%
- Endor LabsAutomates vulnerability detection and remediation using AI agents integrated into developer workflowsmedium · 71%
- MendUnified platform for securing custom code, open source dependencies, and AI with automated governance and remediationmedium · 74%
- TruffleHogA tool that finds and helps remediate exposed secrets and credentials across your entire infrastructure and development pipeline.low · 41%
Compare Semgrep
Side by side against other devsecops tools, attribute by attribute, with a source on every value.
The vioscaleAI score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Semgrep, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Package downloads | 86 | 0.14 | 11.7 | ✓ |
| Security posture | 50 | 0.21 | 10.5 | ✓ |
| Capabilities | 100 | 0.06 | 6.3 | ✓ |
| Release cadence | 96 | 0.05 | 5.0 | ✓ |
| Development activity | 53 | 0.09 | 4.9 | ✓ |
| Reliability | 50 | 0.09 | 4.7 | ✓ |
| Price level | 80 | 0.04 | 3.4 | ✓ |
| Dependent projects | 43 | 0.06 | 2.7 | ✓ |
| Integrations | 38 | 0.06 | 2.4 | ✓ |
| Pricing transparency | 45 | 0.05 | 2.3 | ✓ |
| Stars | 80 | 0.03 | 2.1 | ✓ |
| Security score | 0 | 0.04 | 0.0 | - |
| Developer Q&A activity | 0 | 0.06 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 46 | mediumsource · 2026-09-14 · 65% |
Adoption
Content
| Attribute | Value | Evidence |
|---|---|---|
| Faq | 8 items | mediumsource · 2026-09-10 · 68% |
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | Sca: Yes · Dast: No · Sast: Yes · Sbom: Yes · Hosting: both · Ci native: Yes | mediumsource · 2026-09-14 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 20 | mediumsource · 2026-08-24 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | C | mediumsource · 2026-09-14 · 63% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | LGPL-2.1 | highsource · 2026-09-14 · 95% |
Market
| Attribute | Value | Evidence |
|---|---|---|
| Availability | HqCountry: US · PrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: … | highsource · 2026-08-24 · 75% |
Pricing
Release
Reliability
| Attribute | Value | Evidence |
|---|---|---|
| Status page | Yes | mediumsource · 2026-09-14 · 60% |
Security
| Attribute | Value | Evidence |
|---|---|---|
| Disclosure policy | Yes | mediumsource · 2026-08-01 · 60% |
| Gdpr | Yes | highsource · 2026-08-24 · 75% |
| Soc2 | Yes | highsource · 2026-08-01 · 75% |
| Vulnerabilities | Count: 0 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=semgrep&per_page=100 · Last 12m: 0 | highsource · 2026-09-14 · 90% |
Is Semgrep the right choice for you?
Tell us the job, the constraints and what you weigh most, and we will rank Semgrep against the rest of the devsecops tools we index, using the same dated evidence weighted your way.
Free to run, no account needed to start. How the evaluation works
Is this your product?
This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Semgrep up or down: nobody can buy rank here, including you.
Take the badge
Live, always current, and free to use on your own site. It shows Semgrep's independent score and links back to this profile.
<a href="https://www.vioscale.ai/software/semgrep" target="_blank" rel="noopener">
<img src="https://www.vioscale.ai/badge/software/semgrep.svg" alt="Semgrep, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>Markdown, for a README →
[](https://www.vioscale.ai/software/semgrep)Claim the profile
Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Semgrep. Free, and it does not change the score.
- Correct anything wrong, with evidence
- Point our crawler at the pages that matter
- See which AI systems are reading this profile
Not the owner? How vendor profiles work