IT AI Index
Index Developer platform SAST › Semgrep vs SonarQube
Static application security testing · September 2026 Edition

Semgrep vs SonarQube

Four of twelve models named Semgrep first on the direct prompt; two named SonarQube. Both were named by all twelve models and Semgrep carries 56 labels and SonarQube 48, so the shares are not directly comparable.

Semgrep

endorsed leader

Named in three categories this edition.

SonarQube

accepted challenger

Named in two categories this edition.

First-choice share47%22%Of first choices across the direct, paraphrase, budget and scale prompts, 0 to 100.
Negative rate0%10%Negative labels as a share of the product's labels, 0 to 100.
Rank in category#1#2A position in a field of 11; printed, not drawn.
Labels5648A count; the two differ.
The two percentage rows are drawn on one 0 to 100 track, Semgrep reading right to left. Rank and label count are printed, not drawn.Snyk Code was named alongside these two in seven of the twelve direct answers. Semgrep vs Snyk Code · SonarQube vs Snyk Code

Share is the count of first choices across the direct, paraphrase, budget and scale prompts over all twelve models, for a mid-market B2B company; rank is within the category; every quote names the model and the prompt it came from. Both figures come from the static application security testing page.

By framing

How many of the twelve models made each the first choice, per way of asking, and how many argued against it.
SemgrepFirst choices, of twelve modelsSonarQube
Direct42
Paraphrase471 against SonarQube
Comparative40
Budget-constrained111
Scale-constrained20
Negative404 against SonarQube
Bars are first choices, 0 to 12 each sideModels that argued againstA model can name both, so the two sides of a row do not sum to twelve.

The direct prompt

The plain question, one answer per model, grouped by where Semgrep and SonarQube stood in it.

Semgrep first, SonarQube an alternative

4 of 12 modelsSonarQube was named in the answer but not as the choice, or not at all.
Grok 4.1 FastSemgrep alternatives: Snyk Code, SonarQube
Mistral SmallSemgrep alternatives: CodeAnt AI, SonarQube
DeepSeek V4 FlashSemgrep alternatives: Checkmarx One, GitHub Advanced Security, Snyk Code, SonarQube, Veracode
Kimi K2Semgrep, Snyk Code alternatives: SonarQube

SonarQube first, Semgrep an alternative

2 of 12 modelsSemgrep was named in the answer but not as the choice, or not at all.
Qwen 3.7 FlashSnyk, SonarQube alternatives: GitHub Advanced Security, GitLab SAST
MiniMax M2.5Snyk Code, SonarQube alternatives: Checkmarx One, Semgrep

Neither was the first choice, one was named

4 of 12 modelsThe answer put something else first and named one of the two as an alternative.
Gemini 3.5 FlashAikido Security alternatives: GitHub Advanced Security, GitLab SAST, Semgrep, Snyk
Perplexity SonarCodeAnt AI alternatives: Aikido Security, Semgrep
Llama 4 MaverickSnyk Code alternatives: SonarQube
GLM 4.7 FlashXSnyk Code alternatives: CodeAnt AI, Semgrep, SonarQube

Neither was named

2 of 12 modelsThe answer made no first choice from these two in this category.
Claude Haiku 4.5no first choice
GPT-5.4 miniSnyk Code alternatives: Checkmarx One, GitHub Advanced Security / CodeQL, Veracode

Bold names in an answer are the products the judge labeled a first choice; a model naming several gives each of them that label. The full answer text for every row is in the record.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment and they are never added together. The figures above are the mid-market standing, which is the one the category orders by.
Small business
Semgrep leads by sixty-eight points.
Semgrep70%#1 of 12
SonarQube2%#5 of 12
The full small business standing →
Mid-marketThe figures above
Semgrep leads by twenty-four points.
Semgrep47%#1 of 11
SonarQube22%#2 of 11
The full mid-market standing →
Enterprise
The order flips: SonarQube leads at enterprise.
SonarQube10%#3 of 9
Semgrep2%#5 of 9
The full enterprise standing →

What the models said about Semgrep

Every negative label with a quote, up to three, then the highest-weighted positives, up to three. Three of four in this category shown.

“For Developer-First Speed & Flexibility: Semgrep Code or Snyk Code. They are incredibly fast, have great PR integration, and are built around developer workflows.” Gemini 3.5 Flash · scale prompt · first choice
“The best SAST tool for a company with a limited budget is Semgrep CE, which is a free SAST scanner that supports 30+ languages” Llama 4 Maverick · budget prompt · first choice
“I recommend Semgrep (specifically the Semgrep AppSec Platform) as your primary static code security scanner.” GLM 4.7 FlashX · paraphrase prompt · first choice

What the models said about SonarQube

Every negative label with a quote, up to three, then the highest-weighted positives, up to three. Six of seven in this category shown.

“SonarQube: High false positive rates out-of-the-box (40-82% ...) ... Tune heavily or pair with security-specific tools.” Grok 4.1 Fast · negative prompt · soft negative
“SonarQube on default settings flags 40‑60 % of findings as non‑issues on typical Java or TypeScript codebases” GLM 4.7 FlashX · negative prompt · soft negative
“Mature platform, 40+ languages, strong for governance — but noisier out of the box and requires tuning.” DeepSeek V4 Flash · paraphrase prompt · soft negative
“Choose SonarQube if you treat security as a subset of quality, need to reduce technical debt, and want better control over costs at scale.” Qwen 3.7 Flash · direct prompt · first choice
“Widely used, supports multiple languages, integrates well with CI/CD... making it a solid choice for mid-sized teams” Mistral Small · paraphrase prompt · first choice
“SonarQube or Snyk Code would be the best starting points. SonarQube offers the best overall value” MiniMax M2.5 · direct prompt · first choice
Also compared

Comparisons are drawn for the top three products in each category. The output is the models' output; nothing here is a recommendation by the index.