Back to feed
Dev.to
Dev.to
7/16/2026
The original title is 10 words: "We Planted 10 Vulnerabilities to Test Free Semgrep. It Reported 3."

The original title is 10 words: "We Planted 10 Vulnerabilities to Test Free Semgrep. It Reported 3."

Original: We Planted 10 Vulnerabilities to Test Free Semgrep. It Reported 3.

Short summary

A small team planted 10 deliberate vulnerabilities in a React/TypeScript app and ran free Semgrep with zero custom rules, finding only 3 of 10. The gap reflects static analysis limitations: pattern-matching catches present bad code but misses absent security checks like missing authorization. The post details each vulnerability, CI pipeline failures, and practical lessons for teams relying on free SAST scanning.

  • Free Semgrep with --config=auto found 3 of 10 planted vulnerabilities
  • Static analysis catches present bad code but misses absent security controls
  • Detailed breakdown of each CWE, CI setup failures, and lessons learned

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more