---
description: Discover the benefits and disadvantages of Semgrep.  Learn the software price, see the description, and read the most helpful reviews for UK business users. 
image: https://gdm-localsites-assets-gfprod.imgix.net/images/capterra/og_logo-e5a8c001ed0bd1bb922639230fcea71a.png?auto=format%2Cenhance%2Ccompress
title: Semgrep Pricing, Cost & Reviews - Capterra UK 2026
---

Breadcrumb: [Home](/) > [Static Application Security Testing (SAST) Software](/directory/32818/static-application-security-testing-%28sast%29/software) > [Semgrep](/software/1160058/Semgrep)

# Semgrep

Canonical: https://www.capterra.co.uk/software/1160058/Semgrep

> Cloud-based application security platform offering SAST, SCA, and secrets detection to find vulnerabilities in source code across 35+.
> 
> Verdict: Rated \*\*\*\* by 0 users. Top-rated for **Overall Quality**.

-----

## Overview

### Who Uses Semgrep?

Small to large businesses in technology, software development, and regulated industries such as those with SOC 2 requirements. Also used by independent security consultants.

## About the vendor

- **Company**: Semgrep
- **Location**: San Francisco, US
- **Founded**: 2017

## Commercial Context

- **Target Audience**: Self Employed, 2–10, 11–50, 51–200, 201–500, 501–1,000, 1,001–5,000, 5,001–10,000, 10,000+
- **Supported Languages**: English
- **Available Countries**: United States

## Integrations (9 total)

- Azure DevOps Labs
- Azure Pipelines
- Bitbucket
- Cursor
- Elsevier Pure
- Git
- Jira
- Slack
- Visual Studio Code

## Support Options

- Email/Help Desk
- FAQs/Forum
- Knowledge Base
- Chat

## Category

- [Static Application Security Testing (SAST) Software](https://www.capterra.co.uk/directory/32818/static-application-security-testing-%28sast%29/software)

## Related Categories

- [Static Application Security Testing (SAST) Software](https://www.capterra.co.uk/directory/32818/static-application-security-testing-%28sast%29/software)
- [Vulnerability Scanner Tools](https://www.capterra.co.uk/directory/32775/vulnerability-scanner/software)
- [Generative AI Tools](https://www.capterra.co.uk/directory/34155/generative-ai/software)

## Alternatives

1. [GitHub](https://www.capterra.co.uk/software/129067/github) — 4.8/5 (6206 reviews)
2. [GitLab](https://www.capterra.co.uk/software/159806/gitlab) — 4.6/5 (1226 reviews)
3. [Mend.io](https://www.capterra.co.uk/software/165634/mend-app) — 4.6/5 (920 reviews)
4. [Dynatrace](https://www.capterra.co.uk/software/81932/dynatrace) — 4.6/5 (86 reviews)
5. [SonarQube](https://www.capterra.co.uk/software/210481/sonarqube) — 4.5/5 (68 reviews)

## Links

- [View on Capterra](https://www.capterra.co.uk/software/1160058/Semgrep)

## This page is available in the following languages

| Locale | URL |
| en | <https://www.capterra.com/p/10106824/Semgrep/> |
| en-AE | <https://www.capterra.ae/software/1160058/Semgrep> |
| en-AU | <https://www.capterra.com.au/software/1160058/Semgrep> |
| en-CA | <https://www.capterra.ca/software/1160058/Semgrep> |
| en-GB | <https://www.capterra.co.uk/software/1160058/Semgrep> |
| en-IE | <https://www.capterra.ie/software/1160058/Semgrep> |
| en-IL | <https://www.capterra.co.il/software/1160058/Semgrep> |
| en-IN | <https://www.capterra.in/software/1160058/Semgrep> |
| en-NZ | <https://www.capterra.co.nz/software/1160058/Semgrep> |
| en-SG | <https://www.capterra.com.sg/software/1160058/Semgrep> |
| en-ZA | <https://www.capterra.co.za/software/1160058/Semgrep> |

-----

## Structured Data

<script type="application/ld+json">
  {"@context":"https://schema.org","@graph":[{"name":"Capterra UK","address":{"@type":"PostalAddress","addressLocality":"Egham","addressRegion":"ENG","postalCode":"TW20 9AH","streetAddress":"Tamesis, The Glanty, Staines-upon-Thames Egham TW20 9AH United Kingdom"},"description":"Capterra UK helps millions of people find the best business software. With software reviews, ratings, infographics, and the most comprehensive list of business software.","email":"info@capterra.co.uk","url":"https://www.capterra.co.uk/","logo":"https://dm-localsites-assets-prod.imgix.net/images/capterra/logo-a9b3b18653bd44e574e5108c22ab4d3c.svg","@id":"https://www.capterra.co.uk/#organization","@type":"Organization","parentOrganization":"G2.com, Inc.","sameAs":["https://twitter.com/Capterra","https://www.facebook.com/Capterra/","https://www.linkedin.com/company/capterra/","https://www.youtube.com/channel/UCEt7vQSPiPlPAblHdhJAqnA"]},{"name":"Semgrep","description":"Semgrep is a cloud-based application security platform that scans source code to find security vulnerabilities without running the code. It covers three main areas: static code analysis (SAST), open source dependency scanning (SCA), and secrets detection. Teams can run scans through a CI/CD pipeline, directly in their code editor, or via managed cloud scans with no setup required.\n\nSecurity and development teams use Semgrep to catch issues like SQL injection, cross-site scripting, hardcoded credentials, and vulnerable dependencies before code reaches production. Findings and fix guidance are delivered directly in pull requests, so developers can act without switching tools.\n\nKey features include reachability analysis to confirm whether a dependency flaw is actually exploitable, automated pull request generation for fixes, and a unified dashboard for managing rules and findings across all repositories.","url":"https://www.capterra.co.uk/software/1160058/Semgrep","@id":"https://www.capterra.co.uk/software/1160058/Semgrep#software","@type":"SoftwareApplication","publisher":{"@id":"https://www.capterra.co.uk/#organization"},"applicationCategory":"BusinessApplication"},{"@id":"https://www.capterra.co.uk/software/1160058/Semgrep#faqs","@type":"FAQPage","mainEntity":[{"name":"What is Semgrep?","@type":"Question","acceptedAnswer":{"text":"Semgrep is a cloud-based application security platform that scans source code to find security vulnerabilities without running the code. It covers three main areas: static code analysis (SAST), open source dependency scanning (SCA), and secrets detection. Teams can run scans through a CI/CD pipeline, directly in their code editor, or via managed cloud scans with no setup required.Security and development teams use Semgrep to catch issues like SQL injection, cross-site scripting, hardcoded credentials, and vulnerable dependencies before code reaches production. Findings and fix guidance are delivered directly in pull requests, so developers can act without switching tools.Key features include reachability analysis to confirm whether a dependency flaw is actually exploitable, automated pull request generation for fixes, and a unified dashboard for managing rules and findings across all repositories.","@type":"Answer"}},{"name":"Who Uses Semgrep?","@type":"Question","acceptedAnswer":{"text":"Small to large businesses in technology, software development, and regulated industries such as those with SOC 2 requirements. Also used by independent security consultants.","@type":"Answer"}}]},{"@id":"https://www.capterra.co.uk/software/1160058/Semgrep#breadcrumblist","@type":"BreadcrumbList","itemListElement":[{"name":"Home","position":1,"item":"/","@type":"ListItem"},{"name":"Static Application Security Testing (SAST) Software","position":2,"item":"/directory/32818/static-application-security-testing-%28sast%29/software","@type":"ListItem"},{"name":"Semgrep","position":3,"item":"/software/1160058/Semgrep","@type":"ListItem"}]}]}
</script>
