EveryDev.ai
Subscribe
Home
Tools

3,697+ AI tools

  • New
  • Trending
  • Featured
  • Compare
  • Arena
Categories
  • Agents2189
  • Coding1574
  • Infrastructure698
  • Marketing534
  • Projects498
  • Research456
  • Design416
  • Analytics389
  • Testing296
  • MCP290
  • Security286
  • Data262
  • Integration197
  • Prompts189
  • Communication183
  • Extensions173
  • Learning170
  • Voice151
  • Commerce135
  • DevOps123
  • Web86
  • Finance26
AI Tools by Topic
  • AI Coding Assistants
  • Agent Frameworks
  • MCP Servers
  • AI Prompt Tools
  • Vibe Coding Tools
  • AI Design Tools
  • AI Database Tools
  • AI Website Builders
  • AI Testing Tools
  • LLM Evaluations
Follow Us
  • X / Twitter
  • LinkedIn
  • Reddit
  • Discord
  • Threads
  • Bluesky
  • Mastodon
  • YouTube
  • GitHub
  • Instagram
Get Started
  • About
  • Editorial Standards
  • Corrections & Disclosures
  • Community Guidelines
  • Advertise
  • Contact Us
  • Newsletter
  • Submit a Tool
  • Start a Discussion
  • Write A Blog
  • Share A Build
  • Terms of Service
  • Privacy Policy
Explore with AI
  • ChatGPT
  • Gemini
  • Claude
  • Grok
  • Perplexity
Agent Experience
  • llms.txt
Theme
With AI, Everyone is a Dev. EveryDev.ai © 2026
    1. Home
    2. Tools
    3. Opengrep
    Opengrep icon

    Opengrep

    Code Security

    An open-source SAST engine forked from Semgrep under LGPL 2.1, providing advanced static code analysis for security vulnerabilities across 30+ languages.

    Visit Website

    At a Glance

    Pricing
    Open Source

    Fully open-source SAST engine available under LGPL 2.1 with no cost.

    Engagement

    Available On

    Windows
    macOS
    Linux
    API
    CLI

    Resources

    WebsiteDocsGitHubllms.txt

    Topics

    Code SecurityApplication SecurityBug Detection

    Alternatives

    CodeQLdeepsecEndor Labs
    Developer
    OpengrepOpengrep develops and maintains an open-source SAST engine f…

    Listed Aug 2026

    About Opengrep

    Opengrep is an open-source static application security testing (SAST) engine, forked from Semgrep v1.100.0 and released under the LGPL 2.1 license. It is backed by a consortium of AppSec organizations including Aikido, Amplify, Endor Labs, Kodem, and Orca Security. The project was created in December 2024 in response to Semgrep moving critical features behind a commercial license.

    What It Is

    Opengrep is a command-line static analysis tool that searches code for security vulnerabilities and bug patterns using semantic grep-style rules. It supports 30+ programming languages and is fully compatible with existing Semgrep rules and rulesets, making migration straightforward. The tool outputs results in standard JSON and SARIF formats for easy integration into CI/CD pipelines and security toolchains.

    Why It Was Forked

    The README states that Opengrep was created when Semgrep moved critical features behind a commercial licence. The project's manifesto at opengrep.dev frames the fork as a commitment to keeping advanced static analysis open and accessible. Key governance principles include accepting contributions on merit rather than commercial interest and a long-term commitment to the LGPL 2.1 license.

    Key Technical Improvements Over Semgrep CE

    Since the fork, Opengrep has introduced several capabilities not available in Semgrep Community Edition:

    • Superior taint analysis via --taint-intrafile: constructor and field assignment tracking, inter-method taint flow, higher-order function support across 12 languages, and collection method tainting (map, filter, reduce, etc.)
    • Visual Basic support — not available in Semgrep CE or Pro
    • Apex and Elixir support — not in Semgrep CE
    • Improved language support: Clojure (tainting), PHP 8.4, C# 14
    • Self-contained binaries built with Nuitka (no Python runtime required)
    • Signed releases with Cosign for supply chain security

    Language and Integration Coverage

    Opengrep supports over 30 languages including Apex, Bash, C, C++, C#, Clojure, Crystal, Dart, Dockerfile, Elixir, Go, HTML, Java, JavaScript, JSON, Jsonnet, JSX, Julia, Kotlin, Lisp, Lua, OCaml, PHP, Python, R, Ruby, Rust, Scala, Scheme, Solidity, Swift, Terraform, TSX, TypeScript, Visual Basic, XML, YAML, and generic templating formats like ERB and Jinja. Standard SARIF output enables direct integration with GitHub Advanced Security, Azure DevOps, and other SARIF-compatible platforms.

    Setup Path

    Installation is designed to be frictionless. A one-line curl script handles Linux and macOS installs, and a PowerShell equivalent covers Windows. Pre-built self-contained binaries are available on the GitHub releases page, requiring no Python environment. Users write YAML rule files specifying patterns, messages, and severity levels, then run opengrep scan against a codebase.

    Update: v1.28.0

    The latest release is v1.28.0, published on August 25, 2026, according to the GitHub repository metadata. The project has been actively maintained since its creation in December 2024, with the repository showing regular pushes and a growing issue tracker. The open roadmap sessions hosted on lu.ma and the Reddit community at r/opengrep indicate an active contributor and user base.

    Opengrep - 1

    Community Discussions

    Be the first to start a conversation about Opengrep

    Share your experience with Opengrep, ask questions, or help others learn from your insights.

    Pricing

    OPEN SOURCE

    Open Source

    Fully open-source SAST engine available under LGPL 2.1 with no cost.

    • Full static analysis engine
    • 30+ language support
    • Compatible with Semgrep rules
    • JSON and SARIF output
    • Advanced taint analysis

    Capabilities

    Key Features

    • Static application security testing (SAST)
    • Semantic code pattern matching
    • 30+ language support
    • Compatible with Semgrep rules and rulesets
    • JSON and SARIF output formats
    • Advanced taint analysis (--taint-intrafile)
    • Constructor and field assignment tracking
    • Inter-method taint flow
    • Higher-order function taint support across 12 languages
    • Collection method tainting (map, filter, reduce)
    • Visual Basic support
    • Apex and Elixir support
    • C# 14 and PHP 8.4 support
    • Self-contained binaries via Nuitka (no Python required)
    • Signed releases with Cosign
    • CI/CD pipeline integration
    • Custom rule authoring in YAML
    • Open governance model

    Integrations

    GitHub Advanced Security
    Azure DevOps
    SARIF-compatible platforms
    CI/CD pipelines
    JSON toolchains
    API Available
    View Docs

    Ratings & Reviews

    No ratings yet

    Be the first to rate Opengrep and help others make informed decisions.

    Developer

    Opengrep Team

    Opengrep develops and maintains an open-source SAST engine forked from Semgrep under the LGPL 2.1 license. The project is backed by a consortium of AppSec organizations including Aikido, Amplify, Endor Labs, Kodem, and Orca Security. Opengrep accepts contributions on merit and is committed to keeping advanced static analysis open and accessible to all developers and organizations.

    Read more about Opengrep Team
    WebsiteGitHubX / Twitter
    1 tool in directory

    Similar Tools

    CodeQL icon

    CodeQL

    An open-source semantic code analysis engine that lets security researchers write queries to find vulnerabilities across codebases, powering GitHub Advanced Security's code scanning.

    deepsec icon

    deepsec

    An open-source, agent-powered vulnerability scanner that runs on your own infrastructure to find hard-to-detect security issues in large codebases.

    Endor Labs icon

    Endor Labs

    AI-powered application security platform that pinpoints and fixes critical risks across code, open source dependencies, and container images.

    Browse all tools

    Related Topics

    Code Security

    Tools that analyze code for security vulnerabilities and issues.

    49 tools

    Application Security

    AI tools for securing software applications and identifying vulnerabilities.

    111 tools

    Bug Detection

    Intelligent tools that leverage AI to identify, classify, and prioritize software defects and vulnerabilities before they reach production environments.

    47 tools
    Browse all topics
    Back to all toolsSuggest an edit
    ratings
    discussions