Semgrep Alternatives

Semgrep is described as 'Fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or' and is an app in the security & privacy category. There are more than 25 alternatives to Semgrep for a variety of platforms, including Windows, Web-based, Linux, SaaS and Mac apps. The best Semgrep alternative is SonarQube, which is both free and Open Source. Other great apps like Semgrep are Codacy, Shellcheck, Cppcheck and Coverity Scan.

Copy a direct link to this comment to your clipboard
Semgrep alternatives page was last updated

Alternatives list

  1. PhpMetrics icon
     1 like
    Copy a direct link to this comment to your clipboard

    PhpMetrics provides metrics about PHP project and classes, with beautiful and readable HTML report.

    Cost / License

    • Free
    • Open Source

    Platforms

    • Self-Hosted
     
  2. Teamscale icon
     1 like
    Copy a direct link to this comment to your clipboard

    Teamscale analyzes the quality of your code. Analyze your code with a variety of static and dynamic analyses to identify specific maintainability constraints and avoid unexpected maintenance costs in the future.

    9 Teamscale alternatives

    Cost / License

    • Subscription
    • Proprietary

    Platforms

    • Mac
    • Windows
    • Linux
     
  3. Semmle icon
     1 like
    Copy a direct link to this comment to your clipboard

    Code analysis tool, including breakdown of developer contributions, and a clear breakdown of different types of problems with trends over time.

    Cost / License

    • Pay once
    • Proprietary

    Platforms

    • Windows
    • Linux
     
  4. Copy a direct link to this comment to your clipboard

    VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:

    Cost / License

    • Free
    • Open Source

    Platforms

    • Windows
     
  5. Codegrip icon
     Like
    Copy a direct link to this comment to your clipboard

    Codegrip is an automated code review SaaS platform that helps developers to save time in code reviews and to tackle technical debt efficiently.

    Cost / License

    • Freemium (Subscription)
    • Proprietary

    Platforms

    • Software as a Service (SaaS)
     
  6. Opengrep icon
     Like
    Copy a direct link to this comment to your clipboard

    We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀

    Cost / License

    • Free
    • Open Source

    Platforms

    • Mac
    • Linux
     
  7. Exlint icon
     Like
    Copy a direct link to this comment to your clipboard

    Exlint is a an open source project that enables developers to centralize their open source coding standards and policies, so that configuring repositories becomes as easy as typing one command.

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Self-Hosted
    • Software as a Service (SaaS)
     
  8. Copy a direct link to this comment to your clipboard

    Kiuwan Application Security is an end-to-end Appsec platform. Monitoring, action plans and seamless integration within unlocalized teams are but a few of the features offered by Kiuwan.

    Cost / License

    • Pay once
    • Proprietary

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • Android
     
    • Kiuwan Application Security is the most popular Android alternative to Semgrep.

    • Kiuwan Application Security is Paid and ProprietarySemgrep is Freemium and Open Source
  9. Copy a direct link to this comment to your clipboard

    DefenseCode ThunderScan® is a SAST (Static Application Security Testing, WhiteBox Testing) solution for performing deep and extensive security analysis of application source code.

    Cost / License

    • Pay once
    • Proprietary

    Platforms

    • Windows
    • Linux
    • Online
    • Software as a Service (SaaS)
     
  10. Qodana icon
     Like
    Copy a direct link to this comment to your clipboard

    Qodana is a smart code quality platform by JetBrains best suited for working in teams. It can analyze code written in 60+ languages including Java, JavaScript, TypeScript, PHP, Kotlin, Python, Go, and C#.

    28 Qodana alternatives

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Visual Studio Code
    • Online
    • Self-Hosted
     
  11. CodeSonar icon
     Like
    Copy a direct link to this comment to your clipboard

    Improve quality, reduce risk, and ship with confidence. GrammaTech's static analysis SAST tool as part of your secure SDLC identifies bugs that can result in system crashes, unexpected behavior, and security breaches.

    Cost / License

    • Pay once
    • Proprietary

    Platforms

    • Online
     
  12. Copy a direct link to this comment to your clipboard

    Code Inspector is a platform that helps developers and managers to deliver better code. Main features:

    • Automated Code Review
    • Historical values of software metrics
    • Evaluation of technical debt

    Cost / License

    • Freemium (Subscription)
    • Proprietary

    Platforms

    • Software as a Service (SaaS)
     
You are at page 2 of Semgrep alternatives