Semgrep Alternatives

Semgrep is described as 'Fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or' and is an app in the security & privacy category. There are more than 25 alternatives to Semgrep for a variety of platforms, including Windows, Web-based, Linux, SaaS and Self-Hosted apps. The best Semgrep alternative is SonarQube, which is both free and Open Source. Other great apps like Semgrep are Shellcheck, Codacy, Cppcheck and Coverity Scan.

Semgrep iconSemgrep
  0
  • FreemiumOpen Source
  • ...

Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries...

More about Semgrep
Semgrep alternatives page was last updated Jan 3, 2023
Copy a direct link to this comment to your clipboard
  1. SonarQube icon
     26 likes
    Copy a direct link to this comment to your clipboard

    SonarQube is an open source quality management platform, dedicated to continuously analyze and measure source code quality, from the portfolio to the method. Static code analysis is available in the "Community Edition" (free / open source) for:

    30 SonarQube alternatives

    License model

    • FreemiumOpen Source

    Country of Origin

    • CH flagSwitzerland

    Platforms

    • Mac
    • Windows
    • Linux
    • Online

    SonarQube Features

    1.  Static Code Analysis
    2.  Continuous Integration
    3.  Metrics

    SonarQube VS Semgrep

     
    • SonarQube is the most popular Web-based, Windows, Mac & Linux alternative to Semgrep.

    • SonarQube is the most popular Open Source & free alternative to Semgrep.

    • SonarQube is Freemium and Open SourceSemgrep is also Freemium and Open Source
  2. Shellcheck icon
     4 likes
    Copy a direct link to this comment to your clipboard

    A simple tool for finding bugs in shell scripts.

    License model

    • FreeOpen Source

    Country of Origin

    • NO flagNorway

    Platforms

    • Online
    • Visual Studio Code
    • Vim
    • Sublime Text
    • GNU Emacs
    • Atom

    Shellcheck Features

    1.  Static Code Analysis
    2.  Security Testing
    3.  Metrics
    4.  Coding

    Shellcheck VS Semgrep

     
  3. Codacy icon
     24 likes
    Copy a direct link to this comment to your clipboard

    Automatically reviews code style, security, duplication, complexity, and coverage on every change while tracking code quality throughout your sprints.

    License model

    • Free PersonalOpen Source

    Country of Origin

    • PT flagPortugal
    • European Union flagEU

    Platforms

    • Online
    • Self-Hosted
    • Software as a Service (SaaS)

    Codacy Features

    1.  Code Quality
    2.  Static analysis
    3.  Reporting

    Codacy VS Semgrep

     
    • Codacy is the most popular SaaS & Self-Hosted alternative to Semgrep.

    • Codacy is Free Personal and Open SourceSemgrep is Freemium and Open Source
  4. Cppcheck icon
     23 likes
    Copy a direct link to this comment to your clipboard

    Cppcheck is an static analysis tool for C/C++ code. Unlike C/C++ compilers and many other analysis tools it does not detect syntax errors in the code. Cppcheck primarily detects the types of bugs that the compilers normally do not detect.

    License model

    • FreeOpen Source

    Country of Origin

    • SE flagSweden
    • European Union flagEU

    Platforms

    • Windows
    • Linux
    • PortableApps.com
    • Eclipse

    Properties

    1.  Lightweight

    Features

    1.  Portable
    2.  C++

    Cppcheck VS Semgrep

     
  5.  4 likes
    Copy a direct link to this comment to your clipboard

    Coverity Scan Static Analysis allows to find and fix defects in your Java, C/C++ or C# open source project for free.

    17 Coverity Scan alternatives

    License model

    • FreemiumProprietary

    Country of Origin

    • US flagUnited States

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • BSD

    Coverity Scan Features

    1.  Debugging
    2.  C++
    3.  Static Code Analysis

    Coverity Scan VS Semgrep

     
  6. Copy a direct link to this comment to your clipboard

    Betterscan is a simple and powerful software to automate thousands of checks (orchestration) and eliminate human errors in Code and Cloud Infrastructure. Our software uses multiple very known and state of the art Open Source components as plugins (in that sense it is a...

    License model

    Platforms

    • Self-Hosted

    Betterscan.io Features

    1.  Static Code Analysis
    2.  Code Quality
    3.  Static analysis

    Betterscan.io VS Semgrep

     
    • Betterscan.io is the most popular commercial alternative to Semgrep.

    • Betterscan.io is Paid and Open SourceSemgrep is Freemium and Open Source
  7. Flawfinder icon
     3 likes
    Copy a direct link to this comment to your clipboard

    Flawfinder examines C/C++ source code and reports possible security weaknesses ("flaws'') sorted by risk level. It's very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public.

    13 Flawfinder alternatives

    License model

    • FreeOpen Source

    Country of Origin

    • US flagUnited States

    Platforms

    • Windows
    • Linux

    Flawfinder Features

    1.  C++

    Flawfinder VS Semgrep

     
  8. Code Climate icon
     5 likes
    Copy a direct link to this comment to your clipboard

    Code Climate’s engineering process insights and automated code review for GitHub and GitHub Enterprise help you ship better software, faster.

    License model

    • FreemiumProprietary

    Country of Origin

    • US flagUnited States

    Platforms

    • Online

    Code Climate Features

    1.  C++ support
    2.  Code Quality

    Code Climate VS Semgrep

     
  9. SQuORE icon
     2 likes
    Copy a direct link to this comment to your clipboard

    SQuORE is a business intelligence and static code analysis tool for software projects. It gathers information from different artefacts types (e.g. source code, test results, bug tracking system) and tools (reads outputs of Checkstyle, PMD, FindBugs, Polyspace, Coverity or...

    License model

    Platforms

    • Windows
    • Linux

    SQuORE Features

    1.  Metrics

    SQuORE VS Semgrep

     
  10. Copy a direct link to this comment to your clipboard

    ProjectCodeMeter Is a professional software tool for project managers to measure and estimate the Time, Cost, Complexity, Quality Metrics and Maintainability of software projects as well as Development Team Productivity by analyzing their source code.

    License model

    Platforms

    • Windows

    ProjectCodeMeter Features

    1.  Metrics
    2.  Static analysis
    3.  Static Code Analysis
    4.  Automated code review

    ProjectCodeMeter VS Semgrep

     
  11. Copy a direct link to this comment to your clipboard

    SensioLabsInsight is a quality assurance tool that analyzes your source code to find problems that degrade the overall quality of your projects. It can analyze any application developed with PHP, but it's specially designed to perform advanced analysis of Symfony2...

    License model

    • FreemiumProprietary

    Country of Origin

    • FR flagFrance
    • European Union flagEU

    Platforms

    • Online

    SensioLabs Insight Features

    1.  Code Quality
    2.  Security Testing

    SensioLabs Insight VS Semgrep

     
  12. DeepSource icon
     1 like
    Copy a direct link to this comment to your clipboard

    Find and fix bug risks, anti-patterns, performance issues, security flaws automatically during code reviews. In addition, DeepSource automatically fixes some of the most commonly occurring issues. It works for Python, Go, Ruby, and JavaScript.

    License model

    • FreemiumProprietary

    Application type

    Platforms

    • Online
    • Software as a Service (SaaS)
    • CircleCI
    • Bitbucket
    • GitHub
    • Travis CI
    • GitLab

    DeepSource Features

    1.  Automated reviews
    2.  Static Code Analysis

    DeepSource VS Semgrep

     
12 of 28 Semgrep alternatives