About Semgrep
Semgrep is a lightweight static analysis tool that searches code, finds bugs and enforces secure guardrails and coding standards. It supports more than 30 languages and can run in an IDE, as a pre-commit check or inside CI/CD workflows. The core engine is released under the LGPL-2.1 license.
It works like a semantic grep for code. Rules are written to look like the source code developers already write, so matching a pattern does not require abstract syntax trees, regular expressions or a separate query language, and a search for a value can match code that computes it. The aim is to find variants of a known bug quickly.
The Community Edition analyzes code within a single function or file, which the maintainers note means it will miss many true positives for security work. For SAST, software composition analysis and secrets scanning they recommend the commercial Semgrep AppSec Platform, which adds cross-file and data-flow analysis, AI-assisted triage and managed rule sets.
Key features
- Pattern-based code search that looks like code
- Support for 30+ programming languages
- Runs in IDEs, pre-commit hooks and CI/CD
- Custom rules without ASTs or regex
- SAST, SCA and secrets scanning via AppSec Platform
Good fit for
- →Finding variants of known bugs
- →Enforcing coding standards in CI
- Tags
- static-analysis
- sast
- security
- code-scanning
- linting
- ci-cd
- devsecops
- code-quality
Semgrep: questions and answers
- What is Semgrep used for?
- Semgrep is a fast, open-source static analysis tool that finds bugs and enforces security and coding standards across 30+ languages. It is a good fit for finding variants of known bugs and enforcing coding standards in CI.
- Is Semgrep open source?
- Yes. Semgrep is open source under the LGPL-2.1 licence. Its source code is on GitHub at semgrep/semgrep and is written mainly in C.
- Is Semgrep free?
- Yes. Semgrep is open source, so the software itself is free to use. A managed cloud version is also available, with paid plans from $30 per seat per month.
- What is Semgrep an alternative to?
- Semgrep is an open-source alternative to Snyk, Checkmarx, Veracode and SonarQube Cloud. Other open-source alternatives to Snyk include Horusec, Grype and Trivy.
- Is Semgrep actively maintained?
- Yes. The most recent commit to Semgrep was on 2 October 2026, and the latest release is v1.179.0, published on 2 October 2026. The project has 17k stars on GitHub.
Open-source alternatives to Semgrep
See all
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
Dependency-Track
Security
Dependency-Track is an intelligent Component Analysis platform that allows organizations t
Apache-2.0vs Snyk★ 4.3k
SonarQube
Developer Tools
Continuous Inspection
LGPL-3.0vs Codacy★ 11k
Gitleaks
Security
Find secrets with Gitleaks 🔑
MITvs GitGuardian★ 30k
SaaS alternatives to Semgrep
See all
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaS
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaSVeracode
Security
Application security testing platform covering static, dynamic and software composition
SaaS
SonarQube Cloud
Developer Tools
Hosted code quality and security analysis for pull requests, from Sonar
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Mend
Security
Application security platform for software composition analysis and code scanning
SaaS

