Semgrep Alternatives

Semgrep is described as 'Fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or' and is an app in the security & privacy category. There are more than 25 alternatives to Semgrep for a variety of platforms, including Windows, Web-based, Linux, SaaS and Mac apps. The best Semgrep alternative is SonarQube, which is both free and Open Source. Other great apps like Semgrep are Codacy, Shellcheck, Cppcheck and Coverity Scan.

Copy a direct link to this comment to your clipboard
Semgrep alternatives page was last updated

Alternatives list

  1. PhpMetrics icon
     1 like

    PhpMetrics provides metrics about PHP project and classes, with beautiful and readable HTML report.

    Cost / License

    • Free
    • Open Source (MIT)

    Platforms

    • Self-Hosted
     
  2. DeepSource icon
     1 like

    Find and fix bug risks, anti-patterns, performance issues, security flaws automatically during code reviews. In addition, DeepSource automatically fixes some of the most commonly occurring issues. It works for Python, Go, Ruby, and JavaScript.

    Cost / License

    • Freemium
    • Proprietary

    Platforms

    • Online
    • Software as a Service (SaaS)
    • CircleCI
    • Bitbucket
    • GitHub
    • Travis CI
    • GitLab
     
  3. Teamscale icon
     1 like

    Teamscale analyzes the quality of your code. Analyze your code with a variety of static and dynamic analyses to identify specific maintainability constraints and avoid unexpected maintenance costs in the future.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Mac
    • Windows
    • Linux
     
  4. Semmle icon
     1 like

    Code analysis tool, including breakdown of developer contributions, and a clear breakdown of different types of problems with trends over time.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Windows
    • Linux
     
  5. VCG is an automated code security review tool that handles C/C++, Java, C#, VB and PL/SQL. It has a few features that should hopefully make it useful to anyone conducting code security reviews, particularly where time is at a premium:

    Cost / License

    Platforms

    • Windows
     
  6. Codegrip icon
     Like

    Codegrip is an automated code review SaaS platform that helps developers to save time in code reviews and to tackle technical debt efficiently.

    Cost / License

    • Freemium
    • Proprietary

    Platforms

    • Software as a Service (SaaS)
     
  7. Opengrep icon
     Like

    We’re excited to introduce Opengrep, an open-source static code analysis engine built to ensure code security testing remains truly open and accessible to everyone. 🚀

    27 Opengrep alternatives

    Cost / License

    Platforms

    • Mac
    • Linux
     
  8. Exlint icon
     Like

    Exlint is a an open source project that enables developers to centralize their open source coding standards and policies, so that configuring repositories becomes as easy as typing one command.

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Self-Hosted
    • Software as a Service (SaaS)
     
  9. Kiuwan Application Security is an end-to-end Appsec platform. Monitoring, action plans and seamless integration within unlocalized teams are but a few of the features offered by Kiuwan.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • Android
     
  10. DefenseCode ThunderScan® is a SAST (Static Application Security Testing, WhiteBox Testing) solution for performing deep and extensive security analysis of application source code.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Windows
    • Linux
    • Online
    • Software as a Service (SaaS)
     
  11. Go from prototype to production with AI-driven code quality, security, compliance, orchestration, testing and documentation.

    Cost / License

    • Freemium
    • Proprietary

    Platforms

    • Online
     
  12. Qodana icon
     Like

    Qodana is a smart code quality platform by JetBrains best suited for working in teams. It can analyze code written in 60+ languages including Java, JavaScript, TypeScript, PHP, Kotlin, Python, Go, and C#.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Visual Studio Code
    • Online
    • Self-Hosted
     
You are at page 2 of Semgrep alternatives