[go: up one dir, main page]

Introducing G2.ai, the future of software buying.Try now
Share your insights with Semgrep

Thousands of people like you come to G2 to find out whether solutions like Semgrep are the right fit for them. Share your real experiences with Semgrep and the G2 community and help someone make the right decision about their software.

Semgrep Reviews & Product Details

Semgrep Product Details

Pricing

Pricing provided by Semgrep.

Semgrep Code, Supply Chain, and Secrets Detection

Starting at $40.00
1 contributor Per Month

Semgrep Integrations

(8)
Verified by Semgrep

Semgrep Media

Semgrep Demo - Semgrep Supply Chain (SCA)
Semgrep Supply Chain makes it easy to find and remediate the 2% of dependency vulnerabilities that are actually reachable in your code.
Semgrep Demo - Semgrep Code (SAST)
A SAST solution where developers actually fix the majority of issues they see. Make fix rate the north star metric of your AppSec program with Semgrep Code.
Semgrep Demo - Semgrep Secrets
Go beyond regex: leverage Semantic Analysis, entropy analysis, and validation to accurately detect and fix secrets.
Semgrep Demo - Dashboard
The Semgrep dashboard provides clear, actionable insights into code security and quality, helping teams quickly identify, prioritize, and remediate issues across their projects.
Semgrep is a code security solution that enables organizations to scale their security programs quickly and easily.
Play Semgrep Video
Semgrep is a code security solution that enables organizations to scale their security programs quickly and easily.
Interactive Demo
Try an interactive demo created by the software seller (right here on G2).
Product Avatar Image

Have you used Semgrep before?

Answer a few questions to help the Semgrep community

Semgrep Reviews (38)

Reviews

Semgrep Reviews (38)

4.6
38 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
View Filters
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Deepam .
D
Security Engineer
Enterprise (> 1000 emp.)
"Semgrep Review"
What do you like best about Semgrep?

Semgrep is one of the best tools I've used for securing applications. Since it was integrated into our DevSecOps workflow, it has been able to identify a large number of issues much earlier in the development process. Semgrep scans for potentially vulnerable packages or outdated software versions within the codebase and accurately identifies the relevant CVEs. It also provides clear information about the impact and suggests the appropriate remediation steps, so developers don't need to search online for solutions.

I've found it particularly effective at detecting hardcoded secrets, even those that other tools like Trufflehog might miss. Semgrep Supply Chain also does an excellent job of pinpointing vulnerable software versions.

Overall, I consider Semgrep essential for securing CI/CD pipelines in today's environment. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Nothing as such. It works out very well with all functionalities. Review collected by and hosted on G2.com.

Ivo M.
IM
Analista de segurança da informação junior
Enterprise (> 1000 emp.)
"Fast, reliable, and developer-friendly static analysis tool"
What do you like best about Semgrep?

Semgrep is lightweight, very fast compared to traditional SAST tools, and integrates smoothly into CI/CD pipelines. I like that it has a strong rule ecosystem (community and Pro rules), and the ability to write custom rules makes it flexible for different coding standards and compliance needs. The dashboard provides great visibility into security findings and code quality issues, helping developers fix problems quickly without slowing them down. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

The initial setup for more advanced use cases can be tricky, especially when fine-tuning custom rules or managing large rule sets across multiple projects. Sometimes, there are false positives that require manual triage, and the learning curve for rule writing is a bit steep for newcomers. I would also like to see deeper integrations with more enterprise security platforms out-of-the-box. Review collected by and hosted on G2.com.

Mahmoud H.
MH
Information Security Intern
Mid-Market (51-1000 emp.)
"I think Semgrep is a must have for every Software Company"
What do you like best about Semgrep?

The fact that it can scan dependencies and has so many rules configured on the spot, with a very friendly and easy to use UI for the SemGrep pro. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

I think what semgrep needs is a feature that summarizes the overall security standing of a repository/project. And to allow the user to be able to tell the platform the links between different repos/ if there are any. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Mid-Market (51-1000 emp.)
"Enhancing Security with Semgrep"
What do you like best about Semgrep?

Since it runs fast and integrates directly into CI/CD, my team can surface issues early — from insecure function use to misconfigured patterns — before they ever hit production. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Filter limitations and changing some settings at the global level using UI. Having more advanced filtering and project-level controls would make it easier to manage findings across different environments, prioritize risks. Review collected by and hosted on G2.com.

SJ
Senior Security Analyst & Consultant
Information Technology and Services
Mid-Market (51-1000 emp.)
"Fast and positive results"
What do you like best about Semgrep?

There are multiple things which is great in the SemGrep tool, 1st easy integration with GSM and CI-CD pipeline, 2nd is easy terminal based code scan which save lot of time and intergration if Code is small. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Not specific as such, since everything is good in right price. Review collected by and hosted on G2.com.

Verified User in Computer Software
EC
Small-Business (50 or fewer emp.)
"Hands-off setup could not be easier"
What do you like best about Semgrep?

Very little had to be done on our end to set up managed scans for the entire GitHub organization. Aside from Semgrep staff adjusting things to get a scan to complete, or large codebase was running SAST scans in a few days.

Github PR comments show users what to do, and AI can classify many reports correctly as not needing mitigation. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Semgrep's features are designed around preventing new problems from being introduced in pull requests, but those same features are not available for issues found on trunk branches - these have to be dealt with manually. Review collected by and hosted on G2.com.

Verified User in Electrical/Electronic Manufacturing
UE
Enterprise (> 1000 emp.)
"Amazing tool"
What do you like best about Semgrep?

The tool offers all the necessary features to track and manage security vulnerabilities. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

The tool is extremely useful, with all its features working exactly as intended. Review collected by and hosted on G2.com.

Verified User in Computer Software
CC
Small-Business (50 or fewer emp.)
"An easy to use and fun to customize SAST tool"
What do you like best about Semgrep?

That the SAST engine returns a very small number of false positives. And the rules are fun to write. I also like the reachability analysis of the supply chain tool so you don't get overwhelmed by false positives Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

There is no export report feature. Moreover it would be useful a toggle to tell the supply chain tool to report all the vulnerable dependencies, regardless of their reachability. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
UC
Enterprise (> 1000 emp.)
"Semgrep experience"
What do you like best about Semgrep?

The easy customisation, custom rule creation and fast feedback for devs Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

More products like IaC scanning or DAST, I would love to have full capabilities to scan apps Review collected by and hosted on G2.com.

Abhineet S.
AS
DevSecOps Engineer II
Mid-Market (51-1000 emp.)
"Just a right way to test and catch your code vulnerability"
What do you like best about Semgrep?

I like the SAST engine, it is powerful and capable alongwith less % of false positives. Apart from it, the pro and lot other built rules make it easy to integrate with any DevSecOps process. Review collected by and hosted on G2.com.

What do you dislike about Semgrep?

Currently the newer offering like SEMGREP AI and secrets manager does not add up perfectly Review collected by and hosted on G2.com.

Pricing Options

Pricing provided by Semgrep.

Semgrep Code, Supply Chain, and Secrets Detection

Starting at $40.00
1 contributor Per Month
Semgrep Comparisons
Product Avatar Image
SonarQube
Compare Now
Product Avatar Image
Snyk
Compare Now
Product Avatar Image
Fortify Static Code Analyzer
Compare Now
Semgrep Features
API / Integrations
Reporting and Analytics
Issue Tracking
Static Code Analysis
Command-Line Tools
Black-Box Scanning
Detection Rate
Feedback
Prioritization
Remediation Suggestions
Product Avatar Image
Product Avatar Image