Semgrep
Semgrep is a static analysis tool that helps developers and security teams find bugs and enforce code standards across codebases.
About this data
Updated June 29, 2026
Overall Pulse Score
+15 over this period
A 0-100 index summarizing the tone of 452 relevant public mentions gathered from public online communities across 16 weeks in the selected period. It measures online sentiment, not a rating of the product's quality.
Weekly Sentiment Trend
Pulse Score by week over the selected period. Each point is one complete week of mentions.
This week in public discussion
Discussion around Semgrep over the recent period was dominated by bug reports and reliability concerns, with commenters raising repeated issues around path handling errors in hook scripts across WSL, Windows, and git worktree environments. Several mentions flagged silent scan failures as a particular frustration. On the positive side, some discussion focused on integration work and CI pipeline improvements. The overall tone skewed negative, with bug and reliability complaints outnumbering praise themes by a considerable margin.
Read the deeper analysisAI-generated summary of public online discussion during this period. It reflects the tone of that discussion, not facts about the product or our views.
Sentiment mix by week
How the tone of public discussion splits each week.
Ringed points mark weeks with unusually high discussion volume, more than double this product's typical week.
Most-discussed praise
Most-discussed complaints
Themes across the selected period, with mention counts.
How Semgrep compares
Pulse Score over the selected period versus the top tracked competitors in Security.
Where the mentions come from
Share of the 452 relevant public mentions in the selected period, by source.
Sample public mentions
Showing 5 of 452 analyzed public mentions in this period, with links to the original source. We do not reproduce full threads.
“We're open-sourcing Sighthound today, our rules-based static security scanner. What makes it special is that it's coded in rust and uses tree-sitter as it's AST making it very fast and easily extensible.Why build another scanner in 2026? We wanted to improve some of our detection...”
“semgrep scan generates findings for ignored code blocks if the --sarif-output option is specified. **Describe the bug** According to the documentation, an inline comment followed by the nosemgrep word can be used to ignore blocks of code. However, if the --sarif-output option is ...”
“Hook binary doubles absolute file_path (no IsAbs check) → open: no such file noise + silent SAST no-op in git worktrees. ## Summary The hook registered for Write|Edit|Bash (Pre/PostToolUse) joins the current working directory onto tool_input.file_path **without checking whether f...”
“Semgrep plugin commands not recognized — nested plugin/ directory not resolved. ## Bug After installing the **semgrep** plugin via /plugin, the command /semgrep-plugin:setup_semgrep_plugin fails with: The plugin shows as **installed and enabled** in the /plugin UI. Root Cause The...”
“Tracking: GitHub Actions / CI Pipeline Improvements. ## Summary This issue tracks ongoing work to tighten the GitHub Actions CI pipeline. As long poles get cut, new ones emerge. This issue catalogs the current state, prior work, and a backlog of improvements grouped into three bu...”
447+ more analyzed mentions, full history, and theme breakdowns are part of Pro.
Get ProDeeper analysis
- Bug reports and reliability complaints dominated the conversation, outnumbering praise themes by a wide margin over the four-week window.
- Sentiment climbed briefly in mid-May then fell back as mention volume spiked in June, ending the period in a flat, middling range without clear recovery.
- Opinion was divided on dependency pinning strictness, with some commenters expressing friction while others appeared to accept the constraints.
- Silent failure modes in security scanning contexts drew notably sharper negative tone than bugs that surfaced visible errors.
| Praise theme | Mentions |
|---|---|
| Strong features | 80 |
| Good integrations | 48 |
| Compared to rivals | 21 |
| Security praise | 13 |
| Feature requests | 11 |
| Complaint theme | Mentions |
|---|---|
| Bugs | 126 |
| Reliability | 83 |
| Missing features | 59 |
| Feature requests | 32 |
| Lacking integrations | 8 |
Public discussion around Semgrep over the past four weeks was dominated by a persistent undercurrent of frustration, with bug reports and reliability concerns accounting for the largest share of complaint-side mentions by a considerable margin. Commenters surfaced a recurring class of path-handling errors, with several mentions describing hook scripts that incorrectly prepend working directory paths to already-absolute file paths, producing doubled paths and silent scan failures across Windows, WSL, and git worktree environments. This pattern of quiet, hard-to-detect breakdowns seemed to heighten irritation, as discussion suggested that a tool failing silently in a security context is treated as a more serious offense than one that fails loudly.
Sentiment trajectory across the window was unsteady. Early weeks showed very low scores on minimal mention volume, then climbed into the low-to-mid fifties around mid-May before sliding back as mention counts surged in early and mid-June. The largest bursts of activity coincided with score dips, which discussion suggested reflects moments when a wider audience encountered reproducible problems and brought them into public view at once. By the final tracked week sentiment had settled into a narrow, middling band without meaningful recovery.
On the praise side, feature appreciation and integration quality drew the most positive attention, and competitor comparison threads occasionally framed Semgrep favorably, though those threads were a small slice of overall volume. Divided opinion was clearest around dependency management, where commenters expressed frustration with tight version pinning on transitive dependencies while others appeared neutral or sympathetic to the maintenance rationale. Feature-bucketing and workflow classification decisions also drew split reactions, with some discussion questioning whether current categorization choices matched user mental models. Overall tone leaned skeptical, with reliability concerns outweighing positive signals across the window.
AI-generated summary of public online discussion during this period. It reflects the tone of that discussion, not facts about the product or our views.
Member perspectives
Individual opinions from Pro members, posted over time. These are personal member views, not aggregated sentiment data.
Overall Pulse Score
+15 over this period
A 0-100 index summarizing the tone of 452 relevant public mentions gathered from public online communities across 16 weeks in the selected period. It measures online sentiment, not a rating of the product's quality.
Data summary
Compare with another tool
Semgrep
46
Trainual
88
Score-level preview from live weekly tracking.
Are you Semgrep?
Get a private enterprise dashboard for your product - full history, every source, theme deep-dives, and weekly alerts. You can also respond to the data shown here.
Explore the enterprise dashboardAffiliate disclosure
Some links on this site may be affiliate links. If you click one and make a purchase, we may earn a commission at no extra cost to you. Learn more.
Is Semgrep your product?
See everything behind this page - full history, every source, theme deep-dives, and weekly alerts - in a private enterprise dashboard.
Request early accessCompare with similar tools
Airia
Airia is an AI platform designed to help enterprise security and IT teams manage and govern AI usage across their organization.
Custom pricing
View DetailsAdguard
Ad blocking and privacy protection software that filters ads, trackers, and malware across browsers and applications.
Free / Pro from $2.49/mo
View Details