[ aicodereview.io ]
All Tools

Semgrep

Open-source static analysis engine with a commercial AppSec Platform adding cross-file analysis and an AI assistant for triage.

Visit Website [↗]

[ Facts ]

Category
Security
Open source
Yes (LGPL-2.1 (CE engine); AppSec Platform proprietary)
Pricing
Free for up to 10 contributors; Teams from $30/contributor/mo per product (Code SAST; Secrets $15) with 20 AI credits/dev/mo; Enterprise custom with 50 AI credits/dev/mo source
Self-hosted
Yes — full stack — CE engine (LGPL-2.1) runs fully local or in your CI; the AppSec Platform and Assistant are SaaS-only.
Platforms
github, gitlab, bitbucket, azure-devops
Model control
Assistant uses OpenAI with Amazon Bedrock fallback; custom AI model provider available on Enterprise
Last verified
2026-08-11

[ Against the 9 Standards ]

Based on public documentation as of 2026-08-11. ✓ documented · ~ partial · ✗ not offered · ? unknown. Methodology on the about page.

~ Multi-dimensional Context

Cross-file, cross-function dataflow in the Pro engine; Assistant memories add project context; no ticket context.

Rule-Centric & Default Quiet

Fully rule-centric: custom rules, registry, and policy modes (Monitor/Comment/Block) control PR noise.

Dual-Workflow: Local vs. PR

CLI, IDE extension, and pre-commit locally; policy-managed PR/MR comments in CI.

Business Logic Validation

No validation against issue trackers or requirements.

~ Continuous Learning

Assistant Memories store triage decisions and per-project instructions; the core engine does not learn.

Sandbox Validation

Static analysis only; no sandbox or runtime validation.

~ Economic Transparency

LGPL engine is free to run; Assistant is credit-metered on vendor models, custom provider Enterprise-only.

~ Actionability

Assistant autofix posts suggested code changes in PR/MR comments; coverage varies by rule and language.

~ Measurable ROI

Platform dashboards track findings, fix rates, and remediation times; no dev-cycle ROI attribution.

[ In Our Coverage ]

Evaluating Semgrep?

Run it through the two-week trial protocol before you commit.

Evaluation Guide [↗]