No more typing reviews! Try our Samantha, our new voice AI agent.

What is Semgrep?

Featured Semgrep reviews

Semgrep mindshare

As of June 2026, the mindshare of Semgrep in the Static Application Security Testing (SAST) category stands at 2.4%, down from 2.5% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Semgrep2.4%
SonarQube14.5%
Checkmarx One9.2%
Other73.9%
Static Application Security Testing (SAST)
 
 
Key learnings from peers
Last updated Jun 7, 2026

Valuable Features

Room for Improvement

Popular Use Cases

Scalability

Top industries

By visitors reading reviews
Financial Services Firm
16%
Manufacturing Company
11%
Computer Software Company
8%
Comms Service Provider
7%
Outsourcing Company
5%
University
5%
Retailer
4%
Government
4%
Construction Company
3%
Educational Organization
3%
Healthcare Company
3%
Media Company
3%
Insurance Company
3%
Legal Firm
2%
Transportation Company
2%
Wholesaler/Distributor
2%
Leisure / Travel Company
2%
Hospitality Company
2%
Real Estate/Law Firm
2%
Pharma/Biotech Company
2%
Performing Arts
1%
Recreational Facilities/Services Company
1%
Energy/Utilities Company
1%
Non Profit
1%
Marketing Services Firm
1%
Agriculture
1%
Consumer Goods Company
1%
Aerospace/Defense Firm
1%
Religious Institution
1%

Compare Semgrep with alternative products

Learn more about Semgrep

Semgrep customers

Related questions

 
Semgrep Reviews Summary
Author infoRatingReview Summary
Cloud & Application Security at Sixt SE4.0I've used Semgrep for several months and value its contextual analysis, seamless IDE integration, and minimal noise, though scan time and integration limitations persist; overall, it’s a strong, scalable tool improving developer experience and application security.
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees3.0I use Semgrep for POCs in SAST, secret scanning, and SCA, valuable for benchmarking. It excels in SCA, but its open-source version has false positives and lacks enterprise UI/scalability. I rated it 6.5/10.
SecOps Engineer at IriusRisk3.0I primarily use Semgrep for SCA in CI/CD, finding its easy integration and automated checks reduce manual effort. However, its coverage, advanced features, and high price are areas for improvement, and it's complex to maintain.
Security Consultant | Application Security at Jowatechs4.0We use Semgrep to check custom user pipelines for vulnerabilities, benefiting from its ability to write custom rules. It improves our development speed and cost efficiency, although more beginner-friendly information is needed. We didn't switch from another product.