Semgrep
Security · #1 of 3 in category · #8 of 27 overall
Open-source static analysis engine with a commercial AppSec Platform adding cross-file analysis and an AI assistant for triage.
[ Where it fits ]
On the documented evidence, Semgrep suits teams that need the reviewer inside their own infrastructure, teams that want to read and fork the source.
[ Documented strengths ]
- Rule-Centric & Default Quiet. Fully rule-centric: custom rules, registry, and policy modes (Monitor/Comment/Block) control PR noise.
- Dual-Workflow: Local vs. PR. CLI, IDE extension, and pre-commit locally; policy-managed PR/MR comments in CI.
[ Documented gaps ]
- Business Logic Validation. No validation against issue trackers or requirements.
- Sandbox Validation. Static analysis only; no sandbox or runtime validation.
[ Facts ]
- Category
- Security
- Open source
- Yes — LGPL-2.1 (CE engine); AppSec Platform proprietary
- Pricing
- Free for up to 10 contributors; Teams from $30/contributor/mo per product (Code SAST; Secrets $15) with 20 AI credits/dev/mo; Enterprise custom with 50 AI credits/dev/mo source ↗
- Self-hosted
- Yes — full stack — CE engine (LGPL-2.1) runs fully local or in your CI; the AppSec Platform and Assistant are SaaS-only.
- Platforms
- GitHub GitLab Bitbucket AD Azure DevOps
- Model control
- Assistant uses OpenAI with Amazon Bedrock fallback; custom AI model provider available on Enterprise
- Last verified
- 2026-08-11
[ Against the 9 standards ]
Based on public documentation as of 2026-08-11. ✓ documented · ~ partial · ✗ not offered · ? undocumented. Undocumented scores zero — see the methodology.
Cross-file, cross-function dataflow in the Pro engine; Assistant memories add project context; no ticket context.
Fully rule-centric: custom rules, registry, and policy modes (Monitor/Comment/Block) control PR noise.
CLI, IDE extension, and pre-commit locally; policy-managed PR/MR comments in CI.
Assistant Memories store triage decisions and per-project instructions; the core engine does not learn.
LGPL engine is free to run; Assistant is credit-metered on vendor models, custom provider Enterprise-only.
Assistant autofix posts suggested code changes in PR/MR comments; coverage varies by rule and language.
Platform dashboards track findings, fix rates, and remediation times; no dev-cycle ROI attribution.
[ Closest alternatives ]
[ In our coverage ]
[ FAQ ]
Is Semgrep open source?
Yes. Semgrep publishes its source under LGPL-2.1 (CE engine); AppSec Platform proprietary, so you can read it, audit it and fork it.
Can Semgrep be self-hosted?
Yes — full stack. CE engine (LGPL-2.1) runs fully local or in your CI; the AppSec Platform and Assistant are SaaS-only. Verified against the vendor's own documentation on 2026-08-11.
How much does Semgrep cost?
Free for up to 10 contributors; Teams from $30/contributor/mo per product (Code SAST; Secrets $15) with 20 AI credits/dev/mo; Enterprise custom with 50 AI credits/dev/mo. Seat price is only part of the bill: Semgrep handles models as assistant uses openai with amazon bedrock fallback; custom ai model provider available on enterprise, which is what usually decides the real monthly cost.
How does Semgrep score against the 9-pillar AI code review standard?
4.5 out of 9. It fully documents 2 standards, partially documents 5, does not offer 2, and leaves 0 undocumented. The score is coverage of documented capability, not a measure of review quality.
What are the alternatives to Semgrep?
The closest tools in this directory are Snyk Code, Aikido Security, Greptile, Tabnine. Each is scored against the same 9 standards, so the matrices are directly comparable.
Evaluating Semgrep?
Run it through the two-week trial protocol before you commit a team to it.