About Semgrep
Semgrep is an open-source static application security testing engine built around a lightweight pattern-matching approach, letting security teams write custom rules in a syntax close to the target programming language rather than learning a separate rules DSL. This makes it especially popular with security teams enforcing organization-specific policies across many repositories. It is free to self-host with unlimited use for the open-source engine, and free for hosted Teams plans under 10 developers, with paid tiers running roughly $30-40 per contributor per month for Semgrep Code or Supply Chain, plus a separate $15/contributor/month Secrets add-on. Independent benchmarks show Semgrep leads specifically on security-finding accuracy, with its AI-assisted triage agreeing with human security researchers on true positives about 96% of the time, though it explicitly does not cover code quality metrics, complexity analysis, or duplication detection the way SonarQube does.
Key features
Pros and cons
Best for
Why this score
Leading open-source SAST engine for custom security rules, free for teams under 10 developers