
Snyk
SonarQube
Aikido Security
ESLint
Codacy
Checkmarx
Veracode
Semgrep is a fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time.

Intruder
Pentest-Tools
Nessus
Acunetix
Probe.ly
Aikido Security
Snyk
Detectify provides a user friendly and thorough web security scan that allows you to focus 100% on web development.

Which is more popular?
Based on our record, Semgrep should be more popular than Detectify. It has been mentioned 26 times since March 2021.
Website, pricing, platforms and company facts side by side.
|
|
|
|
|---|---|---|
| Website | semgrep.dev | detectify.com |
| Pricing | ||
| Company | — | Startup from Sweden · 10 - 19 employees · 2012 |
| Listed in |
What each product offers, as listed by its team.


Possible disadvantages
Possible disadvantages
Walkthroughs and reviews on video.
Semgrep: a lightweight static analysis tool for security consultant and hackers
More videos
How often each product is chosen within a category, 0–100% relative to the other.


Share your experience with using Semgrep and Detectify. For example, how are they different and which one is better?
Recommendations tracked on public social media and blogs since March 2021.


For static analysis there's PHPStan for PHP and Mypy for Python. For formatting, Prettier and gofmt are the cheapest guardrail there Is, with zero excuse not to run one. For security, Semgrep Covers the same principle at higher stakes. - Source: dev.to / 4 days ago
Static Analysis & Semgrep: Do not rely on LLM alignment to write clean code. Enforce it. Write Semgrep rules to ban specific anti-patterns. If your standard dictates no default mutable values in Python methods, codify it. When the agent... - Source: dev.to / 26 days ago
I have noticed this in myself and in teams I have worked with: as output volume rises, review time does not rise with it. If anything, it compresses. The productivity gains are real. So is the risk they paper over. Tools like Semgrep and... - Source: dev.to / about 1 month ago
Detectify once made an offer of making free scans which I took them up on. There are plenty of free Content Security Policy (CSP) and other vulnerability checkers around such as Observatory or Pentest. Shields UP!! Will identify which... Source: almost 3 years ago
Detectify | Community Manager, Crowdsource | REMOTE (Offices in Boston, US & Stockholm, Sweden. We help with relocation if wanted) https://detectify.com/ We are a cyber security company in the industry, and more specifically the EASM... - Source: Hacker News / over 4 years ago
A concept-level idea would be this: 1) For your staging/UAT environment pipeline stages, add a "DAST scan" step, eg. With Detectify (which also has an API accommodating this need) 2) I'd assume, independently from the DAST scan, you... Source: about 5 years ago
When comparing Semgrep and Detectify, you can also consider the following products.

Snyk helps you use open source and stay secure. Continuously find and fix vulnerabilities for npm, Maven, NuGet, RubyGems, PyPI and much more.
Compare Snyk to Semgrep or Detectify:

Intruder is a security monitoring platform for internet-facing systems.
Compare Intruder to Semgrep or Detectify:

SonarQube, a core component of the Sonar solution, is an open source, self-managed tool that systematically helps developers and organizations deliver Clean Code.
Compare SonarQube to Semgrep or Detectify:

Pentest-Tools.com is your ready-to-use setup for security testing
Compare Pentest-Tools to Semgrep or Detectify:

Secure your code, cloud, and runtime in one central system. Find and fix vulnerabilities fast and automatically.
Compare Aikido Security to Semgrep or Detectify:

Nessus Professional is a security platform designed for businesses who want to protect the security of themselves, their clients, and their customers.
Compare Nessus to Semgrep or Detectify: