Main Menu
  • Tools
  • Developers
  • Topics
  • Discussions
  • News
  • Blogs
  • Builds
  • Contests
  • Compare
Create
    EveryDev.ai
    Sign inSubscribe
    Home
    Tools

    1,944+ AI tools

    • New
    • Trending
    • Featured
    • Compare
    Categories
    • Agents1038
    • Coding971
    • Infrastructure415
    • Marketing398
    • Design335
    • Projects313
    • Analytics299
    • Research290
    • Testing183
    • Integration167
    • Data163
    • Security156
    • MCP145
    • Learning135
    • Communication120
    • Extensions114
    • Prompts110
    • Commerce106
    • Voice102
    • DevOps84
    • Web71
    • Finance18
    1. Home
    2. Tools
    3. Semgrep
    Semgrep icon

    Semgrep

    Code Security

    Static application security testing and AppSec platform that provides SAST, SCA, and secrets detection with AI-assisted triage, a rules registry, CLI/CI integration, and IDE plugins.

    Visit Website

    At a Glance

    Pricing
    Free tier available

    Open-source local SAST engine for individual developers and projects.

    Teams: $40/mo
    Enterprise: Custom/contact

    Engagement

    Available On

    Windows
    macOS
    Linux
    Web
    API

    Resources

    WebsiteDocsGitHubllms.txt

    Topics

    Code SecurityCI/CD ToolsIDE Plugins

    Alternatives

    CodeAnt AISourceryEndor Labs
    Developer
    Semgrep, Inc.San Francisco, CAEst. 2017$204M raised

    Updated Feb 2026

    About Semgrep

    Semgrep delivers a developer-friendly application security platform that combines an open-source local SAST engine with a paid AppSec platform for teams and enterprises. It supports static code analysis, supply-chain (SCA) checks, and semantic secrets detection, and includes an AI Assistant for triage and remediation guidance. Semgrep runs locally via a CLI or as a managed platform and integrates with CI/CD and developer tools to surface findings in native workflows.

    • Open-source Community Edition — use the CLI to run local SAST scans, access community rules, and export findings in SARIF/JSON to integrate with CI systems.
    • Teams & Enterprise tiers — subscribe to team or enterprise plans for Pro rules, cross-file analysis, managed scanning, dashboards, RBAC and SSO; contact sales for custom enterprise pricing.
    • Semgrep Assistant (AI) — AI-assisted triage, remediation guidance, auto-triage and auto-fix capabilities, and AI Memories to codify policy context for better results.
    • Rule Registry & Pro Engine — share and reuse rules from the registry; upgrade for dataflow/reachability analysis to reduce false positives.
    • Developer integrations — integrate with GitHub/GitLab/Bitbucket, CI systems, IDEs (VS Code, JetBrains), Slack, Jira, and REST APIs to surface findings where developers work.

    Getting started: install the Semgrep CLI to scan code locally or sign up for the Semgrep AppSec Platform to onboard repositories, enable Pro rules and the Assistant, and connect CI/CD and SCM integrations.

    Semgrep - 1

    Community Discussions

    Be the first to start a conversation about Semgrep

    Share your experience with Semgrep, ask questions, or help others learn from your insights.

    Pricing

    FREE

    Community Edition

    Open-source local SAST engine for individual developers and projects.

    • Open-source SAST engine (LGPL 2.1)
    • Community-managed rules and registry
    • CLI for local scans and CI integration
    • Cross-platform support: macOS, Windows, Linux
    • SARIF/JSON output and rule authoring

    Teams

    Popular

    Extensible AppSec for growing teams; pricing is per contributor and starts at $40/month per contributor.

    $40
    per month
    • Pro rules and cross-file analysis
    • Semgrep Assistant (AI) for triage and fixes
    • Managed scanning, dashboards, and policy engine
    • Single sign-on (SSO) and role-based access control (RBAC)

    Enterprise

    Custom pricing and deployment options for large organizations; contact sales for details.

    Custom
    contact sales
    • Everything in Teams plus dedicated account manager and white-glove onboarding
    • Volume pricing, roadmap access, and feature prioritization
    • Extended support and SLAs
    View official pricing

    Capabilities

    Key Features

    • Open-source CLI SAST engine (Semgrep CE)
    • Supply-chain scanning (SCA) and secrets detection
    • AI-assisted triage and remediation with Semgrep Assistant
    • Pro Engine with cross-file and dataflow/reachability analysis
    • Registry of community and private rules
    • CI/CD and SCM integrations with SARIF/JSON output
    • IDE plugins for VS Code and JetBrains
    • Managed AppSec Platform with dashboards, policies, and RBAC

    Integrations

    GitHub
    GitLab
    Bitbucket
    CircleCI
    Jenkins
    Azure Repos
    Slack
    Jira
    Wiz
    Pre-commit
    REST API
    API Available
    View Docs

    Demo Video

    Semgrep Demo Video
    Watch on YouTube

    Reviews & Ratings

    No ratings yet

    Be the first to rate Semgrep and help others make informed decisions.

    Developer

    Semgrep, Inc.

    Semgrep, Inc. builds developer-first application security tools that combine an open-source static analysis engine with a managed AppSec platform. The company grows and maintains the Semgrep engine and rule registry while developing AI-assisted triage, remediation, and Pro analysis features. The team includes security researchers and engineers who focus on making high-accuracy security scanning accessible in developer workflows.

    Founded 2017
    San Francisco, CA
    $204M raised
    240 employees

    Used by

    Lyft
    Snowflake
    Figma
    Dropbox
    +18 more
    Read more about Semgrep, Inc.
    WebsiteGitHubX / Twitter
    1 tool in directory

    Similar Tools

    CodeAnt AI icon

    CodeAnt AI

    AI-powered code review platform that automates code quality, security, and compliance checks and integrates with CI/CD and IDEs for faster, safer pull request reviews.

    Sourcery icon

    Sourcery

    Automated code review and security scanning platform that provides real-time suggestions in IDEs and continuous reviews on pull requests to help teams catch bugs, enforce standards, and fix vulnerabilities.

    Endor Labs icon

    Endor Labs

    AI-powered application security platform that pinpoints and fixes critical risks across code, open source dependencies, and container images.

    Browse all tools

    Related Topics

    Code Security

    Tools that analyze code for security vulnerabilities and issues.

    30 tools

    CI/CD Tools

    AI-powered continuous integration and continuous deployment platforms that automate testing, building, and releasing software with intelligent insights and optimization.

    24 tools

    IDE Plugins

    AI-enhanced plugins for integrated development environments.

    24 tools
    Browse all topics
    Back to all tools
    Explore AI Tools
    • AI Coding Assistants
    • Agent Frameworks
    • MCP Servers
    • AI Prompt Tools
    • Vibe Coding Tools
    • AI Design Tools
    • AI Database Tools
    • AI Website Builders
    • AI Testing Tools
    • LLM Evaluations
    Follow Us
    • X / Twitter
    • LinkedIn
    • Reddit
    • Discord
    • Threads
    • Bluesky
    • Mastodon
    • YouTube
    • GitHub
    • Instagram
    Get Started
    • About
    • Editorial Standards
    • Corrections & Disclosures
    • Community Guidelines
    • Advertise
    • Contact Us
    • Newsletter
    • Submit a Tool
    • Start a Discussion
    • Write A Blog
    • Share A Build
    • Terms of Service
    • Privacy Policy
    Explore with AI
    • ChatGPT
    • Gemini
    • Claude
    • Grok
    • Perplexity
    Agent Experience
    • llms.txt
    Theme
    With AI, Everyone is a Dev. EveryDev.ai © 2026
    38views
    Discussions