Try our new research platform with insights from 80,000+ expert users

What is Semgrep?

Featured Semgrep reviews

Semgrep mindshare

As of March 2026, the mindshare of Semgrep in the Static Application Security Testing (SAST) category stands at 2.6%, up from 1.6% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Semgrep2.6%
SonarQube17.7%
Checkmarx One10.4%
Other69.3%
Static Application Security Testing (SAST)
 
 
Key learnings from peers
Last updated Mar 23, 2026

Valuable Features

Room for Improvement

Top industries

By visitors reading reviews
Financial Services Firm
17%
Manufacturing Company
12%
Computer Software Company
9%
Comms Service Provider
6%
University
5%
Outsourcing Company
5%
Retailer
4%
Government
4%
Media Company
4%
Healthcare Company
4%
Educational Organization
3%
Construction Company
3%
Insurance Company
3%
Legal Firm
2%
Wholesaler/Distributor
2%
Leisure / Travel Company
2%
Transportation Company
2%
Recreational Facilities/Services Company
2%
Hospitality Company
2%
Performing Arts
2%
Pharma/Biotech Company
2%
Non Profit
1%
Energy/Utilities Company
1%
Real Estate/Law Firm
1%
Consumer Goods Company
1%
Aerospace/Defense Firm
1%
Marketing Services Firm
1%

Compare Semgrep with alternative products

Learn more about Semgrep

Semgrep customers

Related questions

 
Semgrep Reviews Summary
Author infoRatingReview Summary
Cloud & Application Security at Sixt SE4.0I've used Semgrep for several months and value its contextual analysis, seamless IDE integration, and minimal noise, though scan time and integration limitations persist; overall, it’s a strong, scalable tool improving developer experience and application security.
SecOps Engineer at Iriusrisk3.0I primarily use Semgrep for SCA in CI/CD, finding its easy integration and automated checks reduce manual effort. However, its coverage, advanced features, and high price are areas for improvement, and it's complex to maintain.
Security Consultant | Application Security at Jowatechs4.0We use Semgrep to check custom user pipelines for vulnerabilities, benefiting from its ability to write custom rules. It improves our development speed and cost efficiency, although more beginner-friendly information is needed. We didn't switch from another product.