# Semgrep

> AI-assisted SAST, SCA and Secrets Detection

- **Canonical URI:** https://www.vioscale.ai/software/semgrep
- **Category:** DevSecOps Tools
- **Homepage:** https://semgrep.dev
- **Also known as:** semgrep
- **Profile claimed by vendor:** no
- **Last updated:** 2026-08-01T16:08:31.434Z

## Vioscale score

**63.5 / 100**, confidence 60% (medium).

Composite of weighted, independently-sourced signals (no user reviews, no vendor payment).

| Signal | Score | Weight | Contribution | Evidence present |
|---|--:|--:|--:|:--:|
| price_level | 50 | 8 | 400 | ✓ |
| reliability | 50 | 18 | 900 | ✓ |
| capabilities | 81.2 | 12 | 973.8 | ✓ |
| github_stars | 79.3 | 5 | 396.7 | ✓ |
| integrations | 13.7 | 12 | 164.7 | ✓ |
| github_activity | 53.8 | 18 | 967.7 | ✓ |
| release_cadence | 96.1 | 10 | 961.1 | ✓ |
| security_posture | 50 | 40 | 2000 | ✓ |
| package_downloads | 89.5 | 26 | 2326.3 | ✓ |
| pricing_transparency | 100 | 10 | 1000 | ✓ |
| stackoverflow_activity | 0 | 12 | 0 | - |

## Pricing

_As of 2026-08-01, [verify at source](https://semgrep.dev). Independently observed._

from $30/mo · Subscription · Free tier

> Free tier available. Teams starting at $30/month per contributor. Enterprise pricing upon request.

| Plan | Price | Free | Commitment |
|---|---|:--:|---|
| Free Edition | Free | ✓ | monthly |
| Teams | From $30/month per contributor (Code or Supply Chain); $15/month per contributor (Secrets) | - | monthly |
| Enterprise | Contact sales | - | - |

### Free Edition

Get started for free with the most popular code scanning engine

**Included limits:** ai_credits: 60, contributors: 10, repositories: 10

- Cross-file analysis with Pro rules
- AI-powered detection, triage, and remediation
- 60 AI credits included
- Fast CI/CD deploy via Semgrep infrastructure
- Scan up to 10 repositories
- Maximum 10 contributors
- Authentication via GitHub/GitLab
- Code and Supply Chain included

### Teams

Choose from Code (SAST), Supply Chain (SCA), or Secrets with AI-powered detection, triage, and remediation

**Included limits:** ai_credits_per_developer: 20

- Cross-file analysis with Pro rules
- AI-powered detection, triage, and remediation
- 20 AI credits per developer per month
- One-click CI/CD deploy using Semgrep infrastructure
- Single sign-on (SSO)
- Award-winning support

### Enterprise (Contact sales)

Built for impact and scale

## About

AppSec platform providing static application security testing (SAST), software composition analysis (SCA), and secrets detection with AI-powered detection, triage, and remediation capabilities.

_Independently observed._

## Platform & deployment

- **Platforms:** CLI, Web
- **Deployment:** Cloud / SaaS

## Integrations (2)

_Independently observed._

- GitHub
- GitLab

## Capabilities

_The capabilities that matter for DevSecOps Tools. "-" = undocumented, not absent._

| Capability | Supported |
|---|:--:|
| **Scan types** | |
| SAST (static analysis) | ✓ |
| DAST (dynamic analysis) | - |
| SCA / dependency scanning | ✓ |
| Secret scanning | ✓ |
| Container / image scanning | - |
| IaC misconfiguration scanning | - |
| **Governance** | |
| OSS licence compliance | - |
| SBOM generation (SPDX/CycloneDX) | - |
| **Remediation** | |
| Automated fix / upgrade PRs | ✓ |
| **Prioritisation** | |
| Reachability / exploitability prioritisation | ✓ |
| **Deployment** | |
| Hosting | Cloud only |
| **Integration** | |
| First-class CI / pipeline integration | ✓ |
| In-editor / IDE scanning | - |
| **Licensing** | |
| OSS engine available | - |

## Facts

Every value below carries its source and our confidence. Facts are re-crawled on a freshness schedule.

### adoption

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| adoption.github_stars | 16,074 | [link](https://github.com/semgrep/semgrep) | 2026-08-01 | 90% (high) |
| adoption.package_downloads_weekly | 7,736,635 | [link](https://pypistats.org/packages/semgrep) | 2026-08-01 | 85% (high) |

### language

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| language.primary | OCaml | [link](https://github.com/semgrep/semgrep) | 2026-08-01 | 90% (high) |

### license

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| license.spdx | LGPL-2.1 | [link](https://github.com/semgrep/semgrep) | 2026-08-01 | 95% (high) |

### pricing

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| pricing.model | commercial | [link](https://semgrep.dev) | 2026-08-01 | 60% (medium) |
| pricing.free_tier | yes | [link](https://semgrep.dev) | 2026-08-01 | 60% (medium) |
| pricing.price_level | mid | [link](https://semgrep.dev) | 2026-08-01 | 60% (medium) |
| pricing.starting_gbp | 30 | [link](https://semgrep.dev) | 2026-08-01 | 60% (medium) |
| pricing.transparent | yes | [link](https://semgrep.dev) | 2026-08-01 | 60% (medium) |

### release

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| release.cadence_days | 7 | [link](https://github.com/semgrep/semgrep/releases) | 2026-08-01 | 70% (medium) |

### integrations

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| integrations.count | 2 | [link](https://semgrep.dev) | 2026-08-01 | 60% (medium) |

### reliability

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| reliability.status_page | yes | [link](https://status.semgrep.dev) | 2026-08-01 | 60% (medium) |

### security

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| security.disclosure_policy | yes | [link](https://semgrep.dev/.well-known/security.txt) | 2026-08-01 | 60% (medium) |
| security.gdpr | yes | [link](https://trust.semgrep.dev) | 2026-08-01 | 75% (high) |
| security.soc2 | yes | [link](https://trust.semgrep.dev) | 2026-08-01 | 75% (high) |

### activity

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| activity.commits_last_30d | 50 | [link](https://github.com/semgrep/semgrep/pulse) | 2026-08-01 | 65% (medium) |

---
*Source: Vioscale (https://www.vioscale.ai/software/semgrep). Independent, evidence-based software intelligence. Cite the canonical URI.*
