Skip to content
[ aicodereview.io ]

Semgrep

Security · #1 of 3 in category · #8 of 27 overall

Open-source static analysis engine with a commercial AppSec Platform adding cross-file analysis and an AI assistant for triage.

[ Where it fits ]

On the documented evidence, Semgrep suits teams that need the reviewer inside their own infrastructure, teams that want to read and fork the source.

[ Documented strengths ]

  • Rule-Centric & Default Quiet. Fully rule-centric: custom rules, registry, and policy modes (Monitor/Comment/Block) control PR noise.
  • Dual-Workflow: Local vs. PR. CLI, IDE extension, and pre-commit locally; policy-managed PR/MR comments in CI.

[ Documented gaps ]

  • Business Logic Validation. No validation against issue trackers or requirements.
  • Sandbox Validation. Static analysis only; no sandbox or runtime validation.

[ Facts ]

Category
Security
Open source
Yes — LGPL-2.1 (CE engine); AppSec Platform proprietary
Pricing
Free for up to 10 contributors; Teams from $30/contributor/mo per product (Code SAST; Secrets $15) with 20 AI credits/dev/mo; Enterprise custom with 50 AI credits/dev/mo source ↗
Self-hosted
Yes — full stack — CE engine (LGPL-2.1) runs fully local or in your CI; the AppSec Platform and Assistant are SaaS-only.
Model control
Assistant uses OpenAI with Amazon Bedrock fallback; custom AI model provider available on Enterprise
Last verified
2026-08-11

[ Against the 9 standards ]

Based on public documentation as of 2026-08-11. ✓ documented · ~ partial · ✗ not offered · ? undocumented. Undocumented scores zero — see the methodology.

~ Multi-dimensional Context

Cross-file, cross-function dataflow in the Pro engine; Assistant memories add project context; no ticket context.

Rule-Centric & Default Quiet

Fully rule-centric: custom rules, registry, and policy modes (Monitor/Comment/Block) control PR noise.

Dual-Workflow: Local vs. PR

CLI, IDE extension, and pre-commit locally; policy-managed PR/MR comments in CI.

Business Logic Validation

No validation against issue trackers or requirements.

~ Continuous Learning

Assistant Memories store triage decisions and per-project instructions; the core engine does not learn.

Sandbox Validation

Static analysis only; no sandbox or runtime validation.

~ Economic Transparency

LGPL engine is free to run; Assistant is credit-metered on vendor models, custom provider Enterprise-only.

~ Actionability

Assistant autofix posts suggested code changes in PR/MR comments; coverage varies by rule and language.

~ Measurable ROI

Platform dashboards track findings, fix rates, and remediation times; no dev-cycle ROI attribution.

[ Closest alternatives ]

[ In our coverage ]

[ FAQ ]

Is Semgrep open source?

Yes. Semgrep publishes its source under LGPL-2.1 (CE engine); AppSec Platform proprietary, so you can read it, audit it and fork it.

Can Semgrep be self-hosted?

Yes — full stack. CE engine (LGPL-2.1) runs fully local or in your CI; the AppSec Platform and Assistant are SaaS-only. Verified against the vendor's own documentation on 2026-08-11.

How much does Semgrep cost?

Free for up to 10 contributors; Teams from $30/contributor/mo per product (Code SAST; Secrets $15) with 20 AI credits/dev/mo; Enterprise custom with 50 AI credits/dev/mo. Seat price is only part of the bill: Semgrep handles models as assistant uses openai with amazon bedrock fallback; custom ai model provider available on enterprise, which is what usually decides the real monthly cost.

How does Semgrep score against the 9-pillar AI code review standard?

4.5 out of 9. It fully documents 2 standards, partially documents 5, does not offer 2, and leaves 0 undocumented. The score is coverage of documented capability, not a measure of review quality.

What are the alternatives to Semgrep?

The closest tools in this directory are Snyk Code, Aikido Security, Greptile, Tabnine. Each is scored against the same 9 standards, so the matrices are directly comparable.

Evaluating Semgrep?

Run it through the two-week trial protocol before you commit a team to it.

Evaluation guide [↗]