Skip to main content
World Wide TechnologyBenchAI tool benchmarks
Workflow Tool
StatusEmerging
SignalTracked
EvidenceGrade B

Semgrep

64
C+ 0 vs last quarter

CAUTION: Qilin ransomware group publicly listed Semgrep as a victim (claimed May 22, 2026; tracker-reported discovery May 25) alleging data exfiltration — unconfirmed by Semgrep, absent from status.semgrep.dev, scope unknown.

UX / DXCapabilityReliabilityValueCommunityEnterpriseAutonomyIntegration

Dimension breakdown

Score · confidence
UX / DX
77% conf54
Capability
77% conf66
Reliability
75% conf45
Value
50% conf80
Community
75% conf55
Enterprise / Compliance
50% conf70
Autonomy
50% conf60
Integration
50% conf80
Sources blend review platforms, community sentiment, the Signal Radar and practitioner ratings. Scores re-blend each quarter.
Caution

Qilin ransomware group publicly listed Semgrep as a victim (claimed May 22, 2026; tracker-reported discovery May 25) alleging data exfiltration — unconfirmed by Semgrep, absent from status.semgrep.dev, scope unknown.

AI-augmented AppSec platform combining deterministic SAST/SCA/Secrets with LLM reasoning (Semgrep Multimodal GA, March 2026, built on Semgrep Workflows). AI-powered Detection GA-track (March beta → April findings API + Jira ticketing + AI-credits dashboard) for IDOR/broken-auth; Autotriage cuts ~60% of backlog on first use.

MCP server (Hooks + Skills) scans every file from Claude Code/Cursor/Windsurf/Codex. Vendor-reported (not independently validated) 8x true positives / 50% fewer false positives vs foundation models alone.

SOC 2 Type II, SAML/OIDC SSO, RBAC, audit logs, AI training opt-out. 18K+ orgs, 257 employees (+22% YoY), Series D $100M / ~$204M total (Sequoia, Menlo, Lightspeed). Named refs: Snowflake, Figma, Lyft, Dropbox, GitLab, Vanta; LinkedIn runs it as one of several scanners (GitHub Actions + CodeQL + Semgrep, InfoQ Feb 2026).

G2 4.6/55; SAST mindshare 2.8% (2x YoY).

Monitor

unresolved breach claim; Custom Workflows gated; IntelliJ extension CE-only (no Pro/Supply Chain/Secrets); SCIM unconfirmed; US-only residency; Opengrep fork (Codacy migrated).

Recommended

Use cases

Not yet assessed — this section fills in as ACES research covers the tool.

Score caps

Risk flags

No active caps — no risk flags apply to this tool right now.

Assessment

Status rationale

Tracked because Semgrep has a strong research-based baseline (extensive vendor docs, multiple independent SAST comparisons, third-party case studies via InfoQ/Gartner Peer Insights, G2 4.6/55) but no internal hands-on testing has been performed — and an unresolved, publicly-claimed (Qilin, unverified by Semgrep) ransomware/data-exfiltration listing is itself a reason not to elevate until clarified. Rating 71 with evidence grade B (depth=thorough full-research pass, handsOn=not_tested).

Re-baselined under evalModel claude-opus-4-8. Upgrade to Assessed when WWT pilots Semgrep on a sample codebase and independently validates the Multimodal accuracy claims (which remain vendor-reported), or when an internal evaluation captures real-world false-positive rates against our code patterns — and after the breach claim is resolved with no confirmed customer-data exposure.

Watch for

Movement triggers

Upgrade if: Semgrep confirms the May 2026 breach claim was contained with no customer source-code/scan-data exposure (post-mortem published) and trust signals recover; Custom Workflows exits gating with documented enterprise adoption; SCIM ships; IntelliJ extension reaches Pro/Supply-Chain/Secrets parity; EU data residency launches; independent (non-vendor) benchmark validates the 8x TP / 50% FP Multimodal claims; named Fortune 500 customer goes on-record with deployment metrics. Downgrade if: Qilin leak materializes with confirmed customer data/source-code exposure (would trigger critical-security-vuln cap → compliance ≤5 and cap signal to Tracked); Opengrep captures additional named platform/enterprise migrations beyond Codacy; AI Detection accuracy complaints surface in community; a second material outage within 90 days; GitHub Advanced Security closes the feature gap with bundled AI detection.

Caution

Risks & limitations

Not yet assessed — this section fills in as ACES research covers the tool.

Capabilities

Integration surface

Not yet assessed — this section fills in as ACES research covers the tool.

Proof points

Adoption & benchmarks

Not yet assessed — this section fills in as ACES research covers the tool.

Spotted something wrong or missing here? Suggest a change →

Per-source contributions

Click any dimension to see the underlying sources and citations.