BenchRank
#51 in Application SecurityUpdated 2026-08

Opengrep

by Opengrep · Open-source static analysis engine forked from Semgrep CE

BenchRank score

24 — BenchRank score out of 100

Screenshots of Opengrep

Homepage · Opengrep

Homepage of Opengrep

Overview

Opengrep is a fork of Semgrep CE that provides an open-source static analysis engine for scanning source code (SAST). It runs as a CLI distributed on GitHub and produces JSON and SARIF output so results fit existing workflows. Development is funded by a consortium of application security companies and a full-time developer team.

Best for
Security teams wanting an open-source SAST engine with no features locked behind a licence.
Pricing
No prices are shown; the page states the project is free and open-source, obtained from its GitHub repository.

Strengths and trade-offs

Strengths

  • Fully open-source, with no login needed for scan metadata
  • Backward compatible; supports JSON and SARIF output
  • Built by a full-time team backed by an industry consortium
  • PRs judged on merit, not one vendor's commercial interest

Trade-offs

  • Cross-file, inter-procedural and Windows support are stated as roadmap
  • Only a CLI is described; no hosted UI or dashboard is mentioned
  • A recent fork of Semgrep CE, so it has little track record
  • The site gives no docs, rule library or supported-language list

Pricing

Published plans and prices from Opengrep’s own pricing page.

How this score is made up

Each dimension is scored out of 100 and combined into the headline score using fixed weights.

  • MCP support

    Whether an agent can drive the product through the Model Context Protocol, and how much setup that takes.

  • API quality

    Public API surface: machine-readable spec, official SDKs, documented auth, errors, rate limits and versioning.

  • Documentation

    Publicly reachable docs — coverage, freshness, code samples and machine readability.

  • Agent friendliness

    How readable the site is to an automated client: llms.txt, structured data, server-rendered content, crawler access.

  • Changelog

    A public, dated record of what shipped and when — the clearest signal that a product is still alive.

  • Marketing site structure

    Whether the site answers a buyer's questions: clear positioning, the pages that matter, and accessibility.

  • Page speed

    How fast the site loads for real visitors: Chrome UX Report 75th-percentile LCP, INP and CLS, with a Lighthouse mobile run standing in where a site has too little traffic for field data.

  • Operational trust

    Status page and incident history, security disclosure, compliance and data-processing documentation.

Measured, but not part of the score

Useful to know, but not a mark for or against the product — so these do not affect the ranking.

  • Openness

    Source availability, self-hosting, data export and open standards. Scored and shown, but not part of the composite — paid SaaS is not worse for being paid SaaS.

  • Maintenance

    Release cadence and repository activity. Scored and shown, but not part of the composite — it is only measurable for open repositories.

This doesn’t look right — report a problem with Opengrep’s score

Where this comes from

The Opengrep pages BenchRank reads when it scores the product — its documentation, release notes, status and security pages, and its repository where there is one.

Alternatives in Application Security

  • Ranked 1

    83.1 — BenchRank score out of 100

    Sentry

    Sentry · Error tracking and application performance monitoring for developers

    Best for: Development teams wanting error monitoring, tracing and session replay tied to one trace

  • Ranked 2

    80.8 — BenchRank score out of 100

    GrowthBook

    GrowthBook · Warehouse-native feature flags, experimentation and product analytics

    Best for: Product and engineering teams running feature flags and experiments on their own data warehouse.

  • Ranked 3

    79.4 — BenchRank score out of 100

    Temps

    Temps · Self-hosted deploy platform with built-in analytics, errors and monitoring

    Best for: Teams self-hosting deployments who also want analytics, error tracking and uptime on their own server

See all 53 alternatives to Opengrep

Is this your product?

Claim Opengrep to manage its profile. Claiming lets you suggest edits to the descriptive fields — it never changes scores or rankings.

Claim this business

Report a problem with this page

Report an issue with Opengrep