No more typing reviews! Try our Samantha, our new voice AI agent.

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Semgrep improves code quality and helps eliminate vulnerabilities in the code.
Its most valuable feature is the ability to write custom rules.
Semgrep integrates easily with CI/CD pipelines and is developer-friendly.
It excels in SAST, secret scanning, and Software Composition Analysis.
Semgrep's AI-backed capability is a significant strength compared to competitors.

CONS

Semgrep occasionally provides false positive results, although inconsistently.
There is insufficient information for beginners on how to acquire Semgrep, impacting user-friendliness.
Semgrep is complex to maintain and use, paired with a substantial price tag.
Other tools on the market are considered more effective than Semgrep, receiving a score of six out of ten in a review.
Scan time is an issue with Semgrep, as sometimes AI-based scanning never completes, complicating the triage process.
 

Semgrep Pros review quotes

Manjunath Maneppagol - PeerSpot reviewer
Cloud & Application Security at Sixt SE
Nov 29, 2025
Compared to other competitors in the market, the AI-backed capability is the biggest strength of Semgrep.
Akashkhurana Hirana - PeerSpot reviewer
Senior Software Engineer 2 at Porch
Aug 7, 2026
Semgrep has positively impacted our organization by improving code quality and helping us eliminate vulnerabilities in our code.
reviewer2873715 - PeerSpot reviewer
Security Researcher at a tech vendor with 10,001+ employees
Jun 21, 2026
The feature is easy to use, saves a lot of time, and is streamlined in nature.
Learn what your peers think about Semgrep. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,454 professionals have used our research since 2012.
Francisco Pulido - PeerSpot reviewer
SecOps Engineer at a real estate/law firm with 501-1,000 employees
Mar 20, 2026
The best part of Semgrep is its ease of integration with CI/CD pipelines and how it is a developer-friendly tool.
reviewer2014131 - PeerSpot reviewer
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
May 31, 2026
Semgrep flourishes with the SAST, secret scanning, and Software Composition Analysis types of scanning.
Henry Mwawai - PeerSpot reviewer
Security Consultant | Application Security at a consultancy with 11-50 employees
Sep 23, 2024
The most valuable feature is the ability to write our custom rules.
 

Semgrep Cons review quotes

Manjunath Maneppagol - PeerSpot reviewer
Cloud & Application Security at Sixt SE
Nov 29, 2025
I have consistently observed that their scan time is an issue; sometimes with their AI-based scanning, when you triage that scan, the scan never completes or finishes, which makes it difficult.
Akashkhurana Hirana - PeerSpot reviewer
Senior Software Engineer 2 at Porch
Aug 7, 2026
Regarding improvements for Semgrep, I have noticed that it occasionally provides false positive results, although it does not happen consistently.
reviewer2873715 - PeerSpot reviewer
Security Researcher at a tech vendor with 10,001+ employees
Jun 21, 2026
Semgrep can be improved by making it more user-friendly.
Learn what your peers think about Semgrep. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,454 professionals have used our research since 2012.
Francisco Pulido - PeerSpot reviewer
SecOps Engineer at a real estate/law firm with 501-1,000 employees
Mar 20, 2026
However, as a tool it is really complex to maintain and to use, and it has a huge price tag.
reviewer2014131 - PeerSpot reviewer
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
May 31, 2026
I give Semgrep a six out of 10 simply because there are other tools that are better than this out there.
Henry Mwawai - PeerSpot reviewer
Security Consultant | Application Security at a consultancy with 11-50 employees
Sep 23, 2024
There should be more information on how to acquire the system, catering to beginners in application security, to make it more user-friendly.