Semgrep

Open source static analysis platform for code security, secrets, and supply chain across 30+ languages

Development & no-code

Overview

Semgrep is an open source cloud and on-premises static analysis platform for scanning security vulnerabilities, detecting exposed secrets, managing supply chain risk, and enforcing code quality across 30+ programming languages. It natively integrates into GitHub, GitLab, Bitbucket with PR checks and runs locally or in CI/CD (Jenkins, CircleCI, Azure). Three independent modules: Semgrep Code (SAST), Semgrep Secrets (API key/token/credential detection), and Semgrep Supply Chain (dependency scanning). The free plan includes up to 10 active contributors and 60 AI credits per month; Teams costs $30/contributor/month per selected module (billable independently); Enterprise by request adds on-premise, SSO, and dedicated support.

Semgrep is available entirely in English, as is its documentation. A documented REST API (OpenAPI) enables integration into custom automation workflows. The tool integrates with Slack for alerts and Jira for automatic ticket creation. The per-active-contributor pricing model (commits in the last 90 days) can shift actual costs: a nominal 10-person team may have 15-20 active contributors depending on Git activity. Highly valued for its modular approach (pay only for modules used), speed, and frictionless CI/CD integration, but the free plan limited to 10 contributors may be restrictive for SMEs with more than 10-15 people.

Our verdict

Best for SMEs with development teams up to 10 active contributors seeking an economical, modular, open source solution for code security in CI/CD. Avoid if team exceeds 20 active contributors: Teams pricing across multiple modules can escalate, and comparison with aggressive per-volume SAST pricing is warranted.

← Back to all tools
Semgrep: pricing, review and alternatives — librairy.io