Opengrep
by Opengrep · Open-source static analysis engine forked from Semgrep CE
22.1 — BenchRank score out of 100
Screenshots of Opengrep
Homepage
Overview
Opengrep is a fork of Semgrep CE that provides an open-source static analysis engine for scanning source code (SAST). It runs as a CLI distributed on GitHub and produces JSON and SARIF output so results fit existing workflows. Development is funded by a consortium of application security companies and a full-time developer team.
- Best for
- Security teams wanting an open-source SAST engine with no features locked behind a licence.
- Pricing
- No prices are shown; the page states the project is free and open-source, obtained from its GitHub repository.
Strengths and trade-offs
Strengths
- Fully open-source, with no login needed for scan metadata
- Backward compatible; supports JSON and SARIF output
- Built by a full-time team backed by an industry consortium
- PRs judged on merit, not one vendor's commercial interest
Trade-offs
- Cross-file, inter-procedural and Windows support are stated as roadmap
- Only a CLI is described; no hosted UI or dashboard is mentioned
- A recent fork of Semgrep CE, so it has little track record
- The site gives no docs, rule library or supported-language list
How this score is made up
Each dimension is scored out of 100 and combined into the headline score using fixed weights.
- MCP support
- 0 out of 100
- API quality
- 0 out of 100
- Documentation
- 0 out of 100
- Agent friendliness
- 59 out of 100
- Changelog
- 100 out of 100
- Marketing site structure
- 35 out of 100
- Operational trust
- 0 out of 100
Measured, but not part of the score
Useful to know, but not a mark for or against the product — so these do not affect the ranking.
- Openness
- 40 out of 100
- Maintenance
- 100 out of 100
This doesn’t look right — report a problem with Opengrep’s score
Alternatives in Application Security
Ranked 1
81.6 — BenchRank score out of 100Sentry
Sentry · Error tracking and application performance monitoring for developers
Best for: Development teams wanting error monitoring, tracing and session replay tied to one trace
Ranked 2
81.2 — BenchRank score out of 100GrowthBook
GrowthBook · Warehouse-native feature flags, experimentation and product analytics
Best for: Product and engineering teams running feature flags and experiments on their own data warehouse.
Ranked 3
77.5 — BenchRank score out of 100Temps
Temps · Self-hosted deploy platform with built-in analytics, errors and monitoring
Best for: Teams self-hosting deployments who also want analytics, error tracking and uptime on their own server


