Pattern-based static analysis where rules look like the code they match.
Semgrep lets you write rules that resemble the source code being matched rather than AST queries, which makes custom rules genuinely writable by ordinary developers. It ships thousands of community rules for security and correctness across many languages, and adds supply-chain and secrets scanning in the commercial tiers.
Best for
From $40 per contributor/month (indicative)
Free tierFree tier: Open-source CLI is free and complete; hosted platform free for up to 10 contributors.
What drives the bill: The CLI plus community rules costs nothing and covers a lot; paid tiers add the platform, supply chain and secrets.
Check current pricing on Semgrep’s siteFigures are indicative and were last reviewed August 2026. Vendors change pricing often; confirm before you commit.
No reviews of Semgrep yet. If you have used it in anger, yours would be the first.
If Semgrep is not the right fit, these solve the same problem differently.
Security Testing
Developer-first security across dependencies, code, containers and infrastructure.
Code Quality
The static-analysis standard: 30+ languages, quality gates, clean-as-you-code.
Security Testing
Enterprise application security platform: SAST, SCA, DAST, IaC and API security.
Security Testing
Query your codebase like a database to find vulnerability patterns across the whole repo.