
Snyk
SonarQube
Aikido Security
ESLint
Codacy
Checkmarx
Veracode
Semgrep is a fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time.

Snyk
Codacy
Checkmarx
SonarQube
GitHub Actions
Codiga.io
Shipcheck by Tateprograms
Enhance your workflow with continuous code quality, SonarCloud automatically analyzes and decorates pull requests on GitHub, Bitbucket, Azure DevOps and GitLab on major languages.

Which is more popular?
Based on our record, Semgrep should be more popular than SonarCloud. It has been mentioned 26 times since March 2021.
Website, pricing, platforms and company facts side by side.
|
|
|
|
|---|---|---|
| Website | semgrep.dev | sonarsource.com |
| Pricing | ||
| Platforms | — | |
| Listed in |
In their own words, as submitted to SaaSHub.


No description of Semgrep yet.
SonarCloud, a core component of the Sonar solution, is a Software-as-a-Service (SaaS) tool that systematically helps developers and organizations deliver Clean Code. SonarCloud easily integrates into the cloud DevOps platforms and extends the CI/CD workflow to perform automated code reviews to...
What each product offers, as listed by its team.


Possible disadvantages
Walkthroughs and reviews on video.
Semgrep: a lightweight static analysis tool for security consultant and hackers
More videos
No SonarCloud videos yet. You could help us improve this page by suggesting one.
How often each product is chosen within a category, 0–100% relative to the other.


Share your experience with using Semgrep and SonarCloud. For example, how are they different and which one is better?
External articles and on-site reviews we used to compare the two products.


We have no reviews of Semgrep yet. Be the first one to post
This software is not free but SonarCloud can be as little as €10/month. SonarQube is software that you can license and run on your own hardware, whereas SonarCloud is Software as a Service (SaaS).
Recommendations tracked on public social media and blogs since March 2021.


For static analysis there's PHPStan for PHP and Mypy for Python. For formatting, Prettier and gofmt are the cheapest guardrail there Is, with zero excuse not to run one. For security, Semgrep Covers the same principle at higher stakes. - Source: dev.to / 13 days ago
Static Analysis & Semgrep: Do not rely on LLM alignment to write clean code. Enforce it. Write Semgrep rules to ban specific anti-patterns. If your standard dictates no default mutable values in Python methods, codify it. When the agent... - Source: dev.to / about 1 month ago
I have noticed this in myself and in teams I have worked with: as output volume rises, review time does not rise with it. If anything, it compresses. The productivity gains are real. So is the risk they paper over. Tools like Semgrep and... - Source: dev.to / about 2 months ago
Sonarcloud.io — Automated source code analysis for Java, JavaScript, C/C++, C#, VB.NET, PHP, Objective-C, Swift, Python, Groovy and even more languages, free for Open Source. - Source: dev.to / almost 4 years ago
Website has been improved with a lot of UI enhancements and updated content. On CI side, dependabot is now enabled as well as SonarCloud. Source: almost 4 years ago
I am also using [SonarCloud](https://sonarcloud.io/) for static code analysis to minimize the chances of bugs. Source: over 4 years ago
When comparing Semgrep and SonarCloud, you can also consider the following products.

Snyk helps you use open source and stay secure. Continuously find and fix vulnerabilities for npm, Maven, NuGet, RubyGems, PyPI and much more.
Compare Snyk to Semgrep or SonarCloud:

SonarQube, a core component of the Sonar solution, is an open source, self-managed tool that systematically helps developers and organizations deliver Clean Code.
Compare SonarQube to Semgrep or SonarCloud:

Automatically reviews code style, security, duplication, complexity, and coverage on every change while tracking code quality throughout your sprints.
Compare Codacy to Semgrep or SonarCloud:

Secure your code, cloud, and runtime in one central system. Find and fix vulnerabilities fast and automatically.
Compare Aikido Security to Semgrep or SonarCloud:

The industry’s most comprehensive AppSec platform, Checkmarx One is fast, accurate, and accelerates your business.
Compare Checkmarx to Semgrep or SonarCloud:
