7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Semgrep

Open source

Semgrep is a fast, open-source static analysis tool that finds bugs and enforces security and coding standards across 30+ languages.

semgrep.dev
Semgrep homepage screenshot
GitHub stars
17k
Last commit
yesterday
Repository age
6 years
Version
v1.179.0
Licence
LGPL-2.1
Self-hosted
Yes

About Semgrep

Semgrep is a lightweight static analysis tool that searches code, finds bugs and enforces secure guardrails and coding standards. It supports more than 30 languages and can run in an IDE, as a pre-commit check or inside CI/CD workflows. The core engine is released under the LGPL-2.1 license.

It works like a semantic grep for code. Rules are written to look like the source code developers already write, so matching a pattern does not require abstract syntax trees, regular expressions or a separate query language, and a search for a value can match code that computes it. The aim is to find variants of a known bug quickly.

The Community Edition analyzes code within a single function or file, which the maintainers note means it will miss many true positives for security work. For SAST, software composition analysis and secrets scanning they recommend the commercial Semgrep AppSec Platform, which adds cross-file and data-flow analysis, AI-assisted triage and managed rule sets.

Key features

  • Pattern-based code search that looks like code
  • Support for 30+ programming languages
  • Runs in IDEs, pre-commit hooks and CI/CD
  • Custom rules without ASTs or regex
  • SAST, SCA and secrets scanning via AppSec Platform

Good fit for

  • →Finding variants of known bugs
  • →Enforcing coding standards in CI
Tags
static-analysis
sast
security
code-scanning
linting
ci-cd
devsecops
code-quality

Semgrep: questions and answers

What is Semgrep used for?
Semgrep is a fast, open-source static analysis tool that finds bugs and enforces security and coding standards across 30+ languages. It is a good fit for finding variants of known bugs and enforcing coding standards in CI.
Is Semgrep open source?
Yes. Semgrep is open source under the LGPL-2.1 licence. Its source code is on GitHub at semgrep/semgrep and is written mainly in C.
Is Semgrep free?
Yes. Semgrep is open source, so the software itself is free to use. A managed cloud version is also available, with paid plans from $30 per seat per month.
What is Semgrep an alternative to?
Semgrep is an open-source alternative to Snyk, Checkmarx, Veracode and SonarQube Cloud. Other open-source alternatives to Snyk include Horusec, Grype and Trivy.
Is Semgrep actively maintained?
Yes. The most recent commit to Semgrep was on 2 October 2026, and the latest release is v1.179.0, published on 2 October 2026. The project has 17k stars on GitHub.

Open-source alternatives to Semgrep

See all

SaaS alternatives to Semgrep

See all