Application & API security

Semgrep

United States · semgrep.dev
Official address, recorded by DBSE. Everything on this page that talks about domains uses these.

Fast, rule-based static analysis with an open-source core.

Community rating

4.3 3 ratings
5 ★
1
4 ★
2
3 ★
0
2 ★
0
1 ★
0

Sign in to rate.

Scorecard from 1 structured review

Deployment effort
4.0
Support quality
4.0
Features vs promises
4.0
Pricing transparency
5.0
Return on investment
5.0

All reviews and filters → · Compare

Exposure signal

None observed

An objective, third-party reading of this vendor's own credential hygiene. It is not part of the community scorecard and does not affect any rating on DBSE.

Staff credentials in infostealer logs
0
Third-party services their staff use
0

No staff credential theft is visible in this data set for this vendor. That is a good sign but not a guarantee: it also depends on how much of the vendor is visible to infostealer telemetry at all.

Customer-side infections: 3 (not counted in the band)

These are infections on the machines of people who log in to this vendor's service. They reflect those users' own endpoint hygiene, and a vendor with a large consumer or partner login footprint will always show more of them. Counting that against the vendor would penalise popularity, so this platform does not.

Source: FireIntel (xti.fireintel.net), public domain summary. Source: Hudson Rock (hudsonrock.com), free infostealer intelligence API. About this data. Read 16 hours ago. DBSE does not collect, hold, or sell this data.

Public vulnerability record

1 CVE across 1 product

What the public CVE catalogue holds against this vendor's products. A higher number here is not a worse vendor, and this is scored into nothing at all.

ProductCatalogued underCVEs
Semgrep Semgrep 1
Why this is shown and not scored

Counting CVEs punishes the vendors who tell you about them. A company that runs a bug bounty, works with researchers and files CVEs properly will always show more than one that fixes things quietly in a point release. Reading the bigger number as the worse product gets it exactly backwards.

The count also tracks how much software a vendor ships and how long they have shipped it. A vendor with forty products will out-score a vendor with one, whatever either does about security.

And a zero here usually means "not in this catalogue", not "no vulnerabilities found". Absence of a record is not a clean record.

What the list is genuinely good for is specifics: whether the product you are buying appears, and what has been disclosed about it. That is a question for the vendor in a security review, and their answer tells you more than the number does.

Matched in the catalogue as Semgrep. Matching is by name, so it can pick up a namesake or miss a brand filed differently.

Source: CVEFeed (cvefeed.io), public CVE catalogue. About this data. Read 16 hours ago. It is not part of the community scorecard, the star rating, or the exposure signal.

Discussions about Semgrep