No more typing reviews! Try our Samantha, our new voice AI agent.

OpenText Static Application Security Testing vs Semgrep comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.8
OpenText Static Application Security Testing received mixed reviews, praising cost savings and partnerships, but highlighting challenges in quantifying ROI.
Sentiment score
6.3
Semgrep improves ROI by accelerating development, reducing manual labor, and addressing vulnerabilities early, enhancing efficiency and profitability.
This can be translated to being able to do the same amount of work with less technicians.
SecOps Engineer at IriusRisk
Tasks that previously took days are completed in significantly less time.
DevOps Engineer at Exponential Craft
I can say it saves us time related to coding and also saves money, making it a very reliable tool for our organization with great features.
Angular Developer at Flourish Software
 

Customer Service

Sentiment score
6.7
Generally positive with dedicated teams, though some seek improvements in ticket system and responsiveness for OpenText support.
Sentiment score
6.1
Semgrep's customer service is efficient, with comprehensive documentation and community support reducing the need for direct assistance.
The customer service and support for Fortify Static Code Analyzer are better than those for LoadRunner.
CTO at Marco Technology
The technical support has been good because we always received answers to our questions.
Manager at DTEK
When I created custom rules, I had some doubts, and the documentation was very helpful, simple, and easy to understand.
Senior Software Engineer 2 at Porch
Their documentation and community are very active, so most of the time when problems occur, I get a solution.
Security Researcher at a tech vendor with 10,001+ employees
Customer support and services for Semgrep are very reliable and good.
Angular Developer at Flourish Software
 

Scalability Issues

Sentiment score
7.8
OpenText SAST is scalable for various project sizes but needs improvement in speed and infrastructure management.
Sentiment score
8.1
Semgrep scales efficiently for both small and large teams, adapting well to diverse environments with cloud-native features.
Fortify Static Code Analyzer integrates well and is scalable.
CTO at Marco Technology
I was able to control it from 10 repositories or 10 services to thousands of repositories in a couple of minutes very simply.
Cloud & Application Security at Sixt SE
This is an open-source tool, so it absolutely does the job, but if you were to implement a tool such as this in an enterprise, this would probably not be scalable.
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
Semgrep makes it easy to integrate and grow within any environment without concern for crashes.
DevOps Engineer at Exponential Craft
 

Stability Issues

Sentiment score
7.5
OpenText Static Application Security Testing is reliable and stable, with improvements since version 19.10, and benefits from proper training.
Sentiment score
7.8
Semgrep generally operates stably, though AI scanning limitations and integration improvements are needed for large repositories.
The stability of Fortify Static Code Analyzer is generally good.
CTO at Marco Technology
I would rate the product stability as an eight.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
If there is no master branch or default branch, the tool fails to identify it and will never scan it unless manually somebody looks into it and fixes the issue.
Cloud & Application Security at Sixt SE
Since I have been using it, I have not experienced any downtime.
Angular Developer at Flourish Software
Semgrep is stable, as far as my experience indicates.
Senior Software Engineer 2 at Porch
 

Room For Improvement

OpenText SAST faces high costs, complex use, false positives, and needs better integration, language support, and feature enhancements.
Semgrep needs user-friendly enhancements, better documentation, efficient scanning, integration flexibility, AI advancements, and improved notifications and databases.
We would appreciate if the AI could give us more information about improvements and reduce the number of false positives, but this solution doesn't have this function yet.
Manager at DTEK
It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers.
CTO at Marco Technology
It would be really helpful to include trending vulnerabilities and how to manage them.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
The UI and additional dashboarding and other details would definitely make the tool more user-friendly and more of a candidate to be implemented in an enterprise.
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
Currently, they are working on identifying business logic vulnerabilities or privilege escalation vulnerabilities by looking at the code, and they should continue to focus on and improve this effort.
Cloud & Application Security at Sixt SE
More advanced dependency analysis features in the SCA part and deeper vulnerability databases would be beneficial.
SecOps Engineer at IriusRisk
 

Setup Cost

Enterprise users find OpenText Static Application Security Testing's pricing high but consider it economical compared to other major solutions.
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs.
CTO at Marco Technology
My experience with the pricing, setup costs, and licensing has been good.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
Once we fully integrated it into our company, it has proven to be price-efficient at around $30 a month.
Senior Software Engineer 2 at Porch
It is basically open-source, so the cost to set up is no cost.
Security Researcher at a tech vendor with 10,001+ employees
It offers very reasonable pricing and costs.
Angular Developer at Flourish Software
 

Valuable Features

OpenText SAST enhances security by automating vulnerability detection, integrating across tools, and providing detailed remediation and compliance guidance.
Semgrep enhances security and efficiency with customizable rules, seamless integration, and user-friendly interfaces for rapid issue detection.
Fortify Static Code Analyzer has the capability of giving fewer false positives compared to other tools.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
The most valuable feature of Fortify Static Code Analyzer is its extensive language support, covering many languages from legacy ones to the newest.
CTO at Marco Technology
The most impactful feature of Fortify Static Code Analyzer in identifying vulnerabilities is the ratio of total number of vulnerabilities to false positives.
Manager at DTEK
When you triage with AI, it gathers context around the finding and reduces the noise about 80 to 90 percent of the time, asking you to focus only on findings that really matter.
Cloud & Application Security at Sixt SE
The Software Composition Analysis is the most valuable feature in Semgrep.
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
The best feature of Semgrep is its ability to highlight high priority issues during scanning, making it critical for developers to address these vulnerabilities promptly.
DevOps Engineer at Exponential Craft
 

Categories and Ranking

OpenText Static Application...
Ranking in Static Code Analysis
7th
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
19
Ranking in other categories
No ranking in other categories
Semgrep
Ranking in Static Code Analysis
5th
Average Rating
7.8
Reviews Sentiment
7.2
Number of Reviews
8
Ranking in other categories
Static Application Security Testing (SAST) (13th), Supply Chain Management Software (4th), Software Composition Analysis (SCA) (9th)
 

Mindshare comparison

As of August 2026, in the Static Code Analysis category, the mindshare of OpenText Static Application Security Testing is 4.5%, down from 10.9% compared to the previous year. The mindshare of Semgrep is 5.5%, down from 5.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Code Analysis Mindshare Distribution
ProductMindshare (%)
Semgrep5.5%
OpenText Static Application Security Testing4.5%
Other90.0%
Static Code Analysis
 

Featured Reviews

DK
Lead Information Security Analyst at a financial services firm with 10,001+ employees
Focuses on detailed scans to find critical vulnerabilities while ensuring minimal false positives
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less than the current latest version. It would be really helpful to include trending vulnerabilities and how to manage them. While it includes all the OWASP top factors, AI has come into the picture, so those updates should also be considered. I haven't thought much about additional features for improvement since I am using it daily. Most of our work revolves around scanning and providing the results, which sometimes feels like a crunch. However, I believe rule pack updates should be implemented. It feels easy to upgrade to the latest version as well.
Manjunath Maneppagol - PeerSpot reviewer
Cloud & Application Security at Sixt SE
Context-aware code analysis has reduced noise and now improves developer experience with actionable security findings
I have consistently observed that their scan time is an issue for mono repos. Sometimes with their AI-based scanning, when you triage that scan, the scan never completes or finishes(, which makes it difficult. Another consistent issue is that whenever you have a new repo to onboard to the platform, the tool ideally should detect the master branch by default. However, sometimes the tool fails to identify it and will never scan it unless manually somebody looks into it and fixes the issue. Although their support team is really good, this issue was present six or eight months ago during the POC and is still present now. If it is affecting multiple customers, it should be prioritized and fixed. I would say that their integration aspects could have been improved. I see a lot of different security solutions that provide flexibility to the security teams based on Jira project, team divisions, Slack, and all those can be very much easily customized. Semgrep needs to work on the enhancement of their notification capabilities. Currently, they are working on identifying business logic vulnerabilities or privilege escalation vulnerabilities by looking at the code, and they should continue to focus on and improve this effort. Regarding stability, whenever you have a mono-repo which is a very large repository, the scan never finishes or the scan never kicks in. At that time, you have to reach out to the support team and ask them to expand the resources in the back end to fix it. This is an issue I keep seeing often on that platform.
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
26%
Manufacturing Company
9%
Computer Software Company
9%
Government
7%
Financial Services Firm
14%
Manufacturing Company
11%
Comms Service Provider
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise3
Large Enterprise11
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise1
Large Enterprise5
 

Questions from the Community

What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
My experience with the pricing, setup costs, and licensing has been good. We have the scan machines, and we are planning to request more from Micro Focus now. We have calls every month or every oth...
What needs improvement with Fortify Static Code Analyzer?
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less ...
What is your primary use case for Fortify Static Code Analyzer?
Our main use cases for Fortify Static Code Analyzer typically involve trying to figure out the critical vulnerabilities. It depends on the type of scans that we are doing, whether it is a release s...
What needs improvement with Semgrep?
Semgrep can be improved by making it more user-friendly. There are tools in the market, such as Aqua Security, that have features worth utilizing. However, there are some comprehensive scanning cap...
What is your primary use case for Semgrep?
My main use case is to perform SAST, static application security testing. I have been using it for the last 10 months. Initially, I was planning to use it just for the code review part so that deve...
What advice do you have for others considering Semgrep?
It streamlines with the governance and compliance of the country where the company operates. It follows GDPR guidelines and EU guidelines. In India, I follow certain guidelines, so it also passes t...
 

Also Known As

Fortify Static Code Analysis SAST
Semgrep Code, Semgrep Supply Chain, Semgrep AppSec Platform
 

Overview

 

Sample Customers

Information Not Available
Policygenius, Tide, Lyft, Thinkific, FloQast, Vanta, and Fareportal
Find out what your peers are saying about OpenText Static Application Security Testing vs. Semgrep and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.