Find security vulnerabilities and code quality issues with semantic code analysis. 2,000+ rules across 30+ languages.
Detect SQL injection, XSS, command injection, insecure deserialization, and all OWASP Top 10 vulnerabilities.
JavaScript, TypeScript, Python, Java, Go, Ruby, PHP, C#, Kotlin, Swift, Rust, and more.
Comprehensive rule library covering common vulnerabilities, misconfigurations, and insecure patterns.
Add your own Semgrep rules to enforce team-specific security policies and coding standards.
diffray AI layer filters false positives, adds context, and suggests specific fixes.
Security findings appear directly on the affected code lines with remediation guidance.
And more languages supported...
Semgrep is part of diffray's security toolkit. Combine it with TruffleHog for comprehensive protection.
Semgrep is included in all diffray plans. Start scanning your PRs for free.