Audience

Developer teams that want to ensure security on every code commit

About Semgrep

Modern security teams are “paving the road” for developers — enforcing code guardrails on every commit. r2c’s Semgrep can eliminate vulnerability classes organization-wide. Scale your security team with lightweight static analysis. Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early in the development flow. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or wrestling with regexes. Start right away with 900+ rules and SaaS infrastructure to get fast results in your editor, at commit-time, or in CI. When off-the-shelf rules aren’t enough, quickly and intuitively write custom rules to express your unique code standards. Rules look like the code you’re searching. For example, rules for Go look like Go. Find function calls, class or method definitions, and more without having to understand abstract syntax trees or wrestle with regexes.

Pricing

Starting Price:
$40 per month
Free Version:
Free Version available.

Integrations

API:
Yes, Semgrep offers API access

Ratings/Reviews

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Company Information

r2c
Founded: 2003
United Kingdom
r2c.dev/

Videos and Screen Captures

Semgrep Screenshot 1
Other Useful Business Software
Powerful App Monitoring Without Surprise Bills Icon
Powerful App Monitoring Without Surprise Bills

AppSignal starts at $23/month with all features included. No overages, no hidden fees. 30-day free trial.

Tired of monitoring tools that punish you for scaling? AppSignal offers transparent, predictable pricing with every feature unlocked on every plan. Track errors, monitor performance, detect anomalies, and manage logs across Ruby, Python, Node.js, and more. Trusted by developers since 2012 with free dev-to-dev support. No credit card required to start your 30-day trial.
Try AppSignal Free

Product Details

Platforms Supported
Cloud
Training
Documentation
Support
Online

Semgrep Frequently Asked Questions

Q: What kinds of users and organization types does Semgrep work with?
Q: What languages does Semgrep support in their product?
Q: What other applications or services does Semgrep integrate with?
Q: Does Semgrep have an API?
Q: What type of training does Semgrep provide?
Q: How much does Semgrep cost?

Semgrep Product Features

Application Security

Source Code Analysis
Open Source Component Monitoring
Vulnerability Detection
Vulnerability Remediation
Third-Party Tools Integration
Training Resources
Analytics / Reporting

Bug Tracking

Filtering
Workflow Management
Issue Tracking
Task Management
Backlog Management
Release Management
Ticket Management

Static Code Analysis

Multiple Programming Language Support
Standard Security/Industry Libraries
Code Standardization / Validation
Analytics / Reporting
Provides Recommendations
Vulnerability Management