Semgrep
Static analysis that finds bugs and insecure patterns using rules written like the code itself.
why this verdict
Downgrade — pay for the workflow, not the AI
CodeQL and Snyk Code cover the headline feature free, so the $40/mo is now paying for the workflow around it.
- A named launch, not a vibe named, unlinked
- Claude reading a diff and flagging injection bugs without any rule pack. Anthropic, May 22, 2025 — no announcement link recorded yet.
- How much of the job it covers headline only editorial call
- The headline feature, but not the workflow, data or integrations around it.
- Is there a free way to do it? yes
- 3 of 3 listed replacements have a usable free tier: CodeQL, Snyk Code and Aikido Security.
- What the call is worth $480/yr
- $40/mo at the entry paid tier — $480 a year per seat.
- Threatened by
- Anthropic
- Since
- May 22, 2025
- List price
- $40/mo
- Per year
- $480
The backstory
Semgrep scans source with pattern rules that look like the language being checked, which made custom rules unusually easy to write. Writing and tuning those rules was the skilled part, and a model asked to review a diff now finds many of the same classes of bug with no rules at all. Semgrep answers with its own AI triage layer. Deterministic scanning, reproducible CI gates and the shared rule registry remain things a chat model cannot promise, so it holds a defensible core.
Escape hatches
switching could free up $480/yrGitHub's query-based analysis, free for public repositories
codeql.github.com open_in_newCommercial SAST with IDE and pull request integration
snyk.io open_in_newBundles SAST, dependency and cloud scanning for smaller teams
aikido.dev open_in_new3 of 3 replacements have a usable free tier.