The Semgrep Code homepage
Score7.2
Rank#7 of 38
From$30/mo
Free planYes
Runs onAPI, Browser extension, Linux, macOS, Self-hosted, Web, Windows

Summary

Semgrep Code is a static application security testing product that scans source code for vulnerabilities and helps developers fix them. Its detection combines deterministic analysis for issues such as cross-site scripting and SQL injection with AI analysis for more complex flaws, including insecure direct object references and business logic vulnerabilities. Pull requests can include tailored, step-by-step remediation instructions. The product supports 35+ programming languages and integrates with source-control and CI tools including GitHub, GitLab, Bitbucket, Jenkins, CircleCI, Azure and Buildkite. IDE extensions are listed for VS Code and IntelliJ, with Slack, email and webhooks available for notifications. The Free Edition includes Code and Supply Chain, scans up to 10 repositories and allows a maximum of 10 contributors. Teams supports up to 500 private repositories; Enterprise has no repository or contributor limit. Local or fully CI-based scans keep source code in the user's environment, while opting into AI processing sends part of a file containing a finding to a model. A free edition is available; paid pricing is listed from $15/user/mo.

Who it is for

Semgrep Code suits development teams looking for source-code vulnerability scanning within pull request, IDE or CI workflows. The listed Free Edition is for teams within its repository and contributor limits; larger teams can consider the paid tiers.

What is good

  • Combines deterministic SAST and AI analysis.
  • Supports 35+ programming languages.
  • Provides step-by-step remediation instructions in pull requests.
  • Local or fully CI-based scans keep code in the user's environment.

What to know first

  • Free Edition is limited to 10 repositories.
  • Free Edition allows a maximum of 10 contributors.
  • Opting into AI processing sends part of a finding file to a model.
  • Enterprise pricing is custom and not listed.

Verdict

Semgrep Code combines source scanning, developer workflow integrations and remediation guidance, with a free tier and paid pricing listed from $15/user/mo. Review repository and contributor caps, and whether AI processing fits your code-handling requirements.

Semgrep Code plans and pricing

All plans
Free Edition Free Free Code and Supply Chain included · up to 10 repositories · maximum 10 contributors · 60 AI credits semgrep.dev · 30 Sept 2026
Teams — Code $30/mo $30/month/contributor Code (SAST) · 20 AI credits per developer per month · 500 private repositories maximum semgrep.dev · 30 Sept 2026
Enterprise Not published Custom No limit on repositories or contributors · 50 AI credits per developer per month · dedicated account manager semgrep.dev · 30 Sept 2026

Compared on static analysis tools

Free plan
Yessemgrep.dev

Facts

Purpose
Semgrep Code is a static application security testing product that finds code vulnerabilities and helps developers fix them.semgrep.dev · 30 Sept 2026
Detection
Its multimodal detection combines deterministic SAST for issues such as XSS and SQL injection with AI analysis for complex flaws such as IDOR and business logic vulnerabilities.semgrep.dev · 30 Sept 2026
Languages
The pricing comparison lists support for 35+ programming languages.semgrep.dev · 30 Sept 2026
Triage
Semgrep says Multimodal can reduce findings requiring triage by 20% on activation and improve as it learns from triage decisions.semgrep.dev · 30 Sept 2026
Remediation
The product provides tailored, step-by-step remediation instructions in pull requests.semgrep.dev · 30 Sept 2026
Integrations
The integrations page lists GitHub, GitLab, Bitbucket, Jenkins, CircleCI, Azure, and Buildkite among supported SCM and CI tools.semgrep.dev · 30 Sept 2026
Developer workflow
The integrations page lists VS Code and IntelliJ IDE extensions, and Slack, email, and webhooks for notifications.semgrep.dev · 30 Sept 2026
Free tier limits
The Free Edition includes Code and Supply Chain, allows scanning up to 10 repositories, and has a maximum of 10 contributors.semgrep.dev · 30 Sept 2026
Paid tier limits
Teams supports up to 500 private repositories, while Enterprise has no repository or contributor limit.semgrep.dev · 30 Sept 2026
Code handling
For local or fully CI-based scans, Semgrep says source code stays on the user's computer or CI environment; opting into AI processing sends part of a file containing a finding to a model.semgrep.dev · 30 Sept 2026
Compliance
Semgrep's trust portal describes a SOC 2 Type II report and a full-scope third-party penetration test covering the Semgrep AppSec Platform, including Semgrep Code.trust.semgrep.dev · 30 Sept 2026
Support
The pricing page lists community-based support for Free Edition, award-winning support for Teams, and dedicated account management and tailored onboarding for Enterprise.semgrep.dev · 30 Sept 2026

Company

Founded
2017semgrep.dev · 23 Sept 2026
Headquarters
San Francisco, California, United Statessemgrep.dev · 23 Sept 2026

Best Semgrep Code alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Semgrep Code yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources