No more typing reviews! Try our Samantha, our new voice AI agent.

CAST Highlight vs Semgrep comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
9.4
CAST Highlight users saved time and costs significantly, boosting productivity by doubling report output without extra resources.
Sentiment score
6.6
Users reported improved ROI with Semgrep due to time savings, better code quality, reduced labor, and early vulnerability detection.
In terms of time saved, it went from approximately 3.5 hours per insight report to around 40 minutes, which is 80% faster.
Senior Data Engineer at LTM
This can be translated to being able to do the same amount of work with less technicians.
SecOps Engineer at a real estate/law firm with 501-1,000 employees
Tasks that previously took days are completed in significantly less time.
DevOps Engineer at Exponential Craft
I can say it saves us time related to coding and also saves money, making it a very reliable tool for our organization with great features.
Angular Developer at Flourish Software
 

Customer Service

Sentiment score
7.8
CAST Highlight's customer service receives mixed reviews, with effective technical support but issues in problem resolution and knowledge gaps.
Sentiment score
6.4
Semgrep's comprehensive documentation and active community reduce the need for direct customer support, despite occasional communication issues.
Some support team members are helpful, and others lack in-depth knowledge of the tool, which might cause challenges.
Technical Associate Manager at Accenture
I interacted with customer support regarding one of my project results related to vulnerabilities and license risks, and they explained everything clearly, leaving me very satisfied.
Senior Data Engineer at LTM
When I created custom rules, I had some doubts, and the documentation was very helpful, simple, and easy to understand.
Senior Software Engineer 2 at Porch
Their documentation and community are very active, so most of the time when problems occur, I get a solution.
Security Researcher at a tech vendor with 10,001+ employees
Customer support and services for Semgrep are very reliable and good.
Angular Developer at Flourish Software
 

Scalability Issues

Sentiment score
7.3
CAST Highlight efficiently handles large codebases, supports many users, and seamlessly manages complex tasks across different environments.
Sentiment score
8.2
Semgrep efficiently manages small and large projects, integrating well in microservices, though some prefer other tools for enterprises.
The processing time per new report stays consistent, experiencing no slowdowns even when we had over 200 new reports dropped in a week.
Senior Data Engineer at LTM
I was able to control it from 10 repositories or 10 services to thousands of repositories in a couple of minutes very simply.
Cloud & Application Security at Sixt SE
This is an open-source tool, so it absolutely does the job, but if you were to implement a tool such as this in an enterprise, this would probably not be scalable.
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
Semgrep makes it easy to integrate and grow within any environment without concern for crashes.
DevOps Engineer at Exponential Craft
 

Stability Issues

Sentiment score
8.0
CAST Highlight is reliable with minor bugs, facing challenges in data transfer and complex .NET framework compatibility.
Sentiment score
7.8
Semgrep is stable but needs improvements in scan completion, integration, and resources, especially for AI-based and large repos.
CAST Highlight proves reliable in nature.
Senior Data Engineer at LTM
If there is no master branch or default branch, the tool fails to identify it and will never scan it unless manually somebody looks into it and fixes the issue.
Cloud & Application Security at Sixt SE
Since I have been using it, I have not experienced any downtime.
Angular Developer at Flourish Software
Semgrep is stable, as far as my experience indicates.
Senior Software Engineer 2 at Porch
 

Room For Improvement

CAST Highlight users seek better configuration, support, reporting, and integration while desiring enhanced abstraction, descriptions, and language insights.
Enhancing Semgrep with better AI, reduced false positives, clear guidance, integration, and business logic focus boosts user experience and utility.
Understanding only the OS-specific blockers means I would avoid resolving irrelevant issues, thus saving time.
Technical Associate Manager at Accenture
CAST Highlight's deduplication is great for avoiding spam, but sometimes we want two similar quotes if they are from very different company sizes, such as SMB versus enterprise perspectives on pricing.
Senior Data Engineer at LTM
The UI and additional dashboarding and other details would definitely make the tool more user-friendly and more of a candidate to be implemented in an enterprise.
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
Currently, they are working on identifying business logic vulnerabilities or privilege escalation vulnerabilities by looking at the code, and they should continue to focus on and improve this effort.
Cloud & Application Security at Sixt SE
More advanced dependency analysis features in the SCA part and deeper vulnerability databases would be beneficial.
SecOps Engineer at a real estate/law firm with 501-1,000 employees
 

Setup Cost

CAST Highlight charges by scan number with optional support upgrades; costs vary in perception and are often compared to CAST AIP.
Once we fully integrated it into our company, it has proven to be price-efficient at around $30 a month.
Senior Software Engineer 2 at Porch
It is basically open-source, so the cost to set up is no cost.
Security Researcher at a tech vendor with 10,001+ employees
It offers very reasonable pricing and costs.
Angular Developer at Flourish Software
 

Valuable Features

CAST Highlight excels in user-friendliness, integration, fast automation, and insightful code analysis, enhancing productivity with intuitive tools.
Semgrep enhances code quality and security with multi-language integration, custom rules, IDE support, and AI-driven rapid scanning.
Smart deduplication groups similar quotes and picks the strongest and most significant one. It stops insights from showing eight variations of great UI, giving diverse voices instead of repetition.
Senior Data Engineer at LTM
In cloud migration, I use CAST highlight to identify blockers, which are the negative road patterns, and also the boosters, which are positive code patterns.
Technical Associate Manager at Accenture
When you triage with AI, it gathers context around the finding and reduces the noise about 80 to 90 percent of the time, asking you to focus only on findings that really matter.
Cloud & Application Security at Sixt SE
The Software Composition Analysis is the most valuable feature in Semgrep.
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
The best feature of Semgrep is its ability to highlight high priority issues during scanning, making it critical for developers to address these vulnerabilities promptly.
DevOps Engineer at Exponential Craft
 

Categories and Ranking

CAST Highlight
Ranking in Software Composition Analysis (SCA)
16th
Average Rating
7.8
Reviews Sentiment
7.3
Number of Reviews
8
Ranking in other categories
No ranking in other categories
Semgrep
Ranking in Software Composition Analysis (SCA)
9th
Average Rating
7.8
Reviews Sentiment
7.3
Number of Reviews
8
Ranking in other categories
Static Application Security Testing (SAST) (13th), Supply Chain Management Software (4th), Static Code Analysis (5th)
 

Mindshare comparison

As of August 2026, in the Software Composition Analysis (SCA) category, the mindshare of CAST Highlight is 1.3%, up from 1.0% compared to the previous year. The mindshare of Semgrep is 3.3%, up from 2.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Composition Analysis (SCA) Mindshare Distribution
ProductMindshare (%)
Semgrep3.3%
CAST Highlight1.3%
Other95.4%
Software Composition Analysis (SCA)
 

Featured Reviews

Nishant Chauhan - PeerSpot reviewer
Senior Data Engineer at LTM
Automated code insights have improved security checks and made review workflows more consistent
If I talk about improvements for CAST Highlight, I would suggest three things. The first is better understanding or niche understanding. Right now, the intent matching is strong for general topics such as ease of use, but for niche B2B terms such as HIPAA compliance or multi-tenant architecture, it sometimes misses context. Improving the domain-specific models would make highlights more accurate for these verticals. The second improvement is more control over the deduplication logic. CAST Highlight's deduplication is great for avoiding spam, but sometimes we want two similar quotes if they are from very different company sizes, such as SMB versus enterprise perspectives on pricing. A slider to adjust deduplication strictness would help. The third suggestion I would like to give is deeper sentiment and outcome tagging. While it has core sentiment capabilities, it does not tag outcomes automatically. For instance, if a quote mentions saved $50,000 per year, tagging that as cost savings $50,000 would let us build ROI charts instantly instead of reading each quote manually. Regarding user experience, integrations, and reporting, I think there is room to enhance those aspects. Regarding user experience, I would suggest improving user actions in terms of bulk actions and keyboard shortcuts. Day-to-day analysts review 50-plus suggested quotes, and currently it is mostly clicking to approve one by one. Adding bulk approve or reject options and keyboard shortcuts would significantly reduce the time taken. A small UX change can lead to a big speed boost. The second point is integrations when pushing to the CMS and Slack alerts. Right now, we export approved highlights manually from CAST Highlight. If CAST Highlight could push directly to our CMS or send Slack alerts for high-strength quotes that hit trending topics, it would close the loop faster, reducing copy-pasting. The third improvement relates to reporting, specifically custom insight dashboards. The tool displays which topics have the most highlights, but we cannot build custom dashboards yet. For example, showing all security quotes from healthcare companies with more than 1,000 employees over the last 90 days would enable better filtering, and exportable dashboards would streamline quarterly reviews.
Manjunath Maneppagol - PeerSpot reviewer
Cloud & Application Security at Sixt SE
Context-aware code analysis has reduced noise and now improves developer experience with actionable security findings
I have consistently observed that their scan time is an issue for mono repos. Sometimes with their AI-based scanning, when you triage that scan, the scan never completes or finishes(, which makes it difficult. Another consistent issue is that whenever you have a new repo to onboard to the platform, the tool ideally should detect the master branch by default. However, sometimes the tool fails to identify it and will never scan it unless manually somebody looks into it and fixes the issue. Although their support team is really good, this issue was present six or eight months ago during the POC and is still present now. If it is affecting multiple customers, it should be prioritized and fixed. I would say that their integration aspects could have been improved. I see a lot of different security solutions that provide flexibility to the security teams based on Jira project, team divisions, Slack, and all those can be very much easily customized. Semgrep needs to work on the enhancement of their notification capabilities. Currently, they are working on identifying business logic vulnerabilities or privilege escalation vulnerabilities by looking at the code, and they should continue to focus on and improve this effort. Regarding stability, whenever you have a mono-repo which is a very large repository, the scan never finishes or the scan never kicks in. At that time, you have to reach out to the support team and ask them to expand the resources in the back end to fix it. This is an issue I keep seeing often on that platform.
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
14%
Financial Services Firm
14%
Government
8%
Educational Organization
6%
Financial Services Firm
14%
Manufacturing Company
11%
Comms Service Provider
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise6
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise2
Large Enterprise5
 

Questions from the Community

What is your experience regarding pricing and costs for CAST Highlight?
The pricing of CAST Highlight was not considered expensive or cheap, and no specific comment was made about the setup cost.
What needs improvement with CAST Highlight?
If I talk about improvements for CAST Highlight, I would suggest three things. The first is better understanding or niche understanding. Right now, the intent matching is strong for general topics ...
What is your primary use case for CAST Highlight?
I have been using CAST Highlight for the last four years. In my company, we use CAST Highlight to perform testing for our code to find vulnerabilities and license risks. We also use CAST Highlight ...
What needs improvement with Semgrep?
Semgrep can be improved by making it more user-friendly. There are tools in the market, such as Aqua Security, that have features worth utilizing. However, there are some comprehensive scanning cap...
What is your primary use case for Semgrep?
My main use case is to perform SAST, static application security testing. I have been using it for the last 10 months. Initially, I was planning to use it just for the code review part so that deve...
What advice do you have for others considering Semgrep?
It streamlines with the governance and compliance of the country where the company operates. It follows GDPR guidelines and EU guidelines. In India, I follow certain guidelines, so it also passes t...
 

Comparisons

 

Also Known As

No data available
Semgrep Code, Semgrep Supply Chain, Semgrep AppSec Platform
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Liberty Mutual, Barclays, Microsoft, Amazon, IBM, US Army, US Air Force, US Navy, Marsh & McLennan, Ernst & Young, PwC, Boston Consulting Group, Telefonica, Total Energies France, SNCF, Broadridge, Sirius XM
Policygenius, Tide, Lyft, Thinkific, FloQast, Vanta, and Fareportal
Find out what your peers are saying about CAST Highlight vs. Semgrep and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.