Semmle

Semmle was a semantic code-analysis company whose engine let developers write queries (in its QL query language) to find security vulnerabilities and their variants across large codebases, and which powered the free open-source code review platform LGTM.com. Its technology was adopted by Uber, NASA, Microsoft, and Google. GitHub acquired Semmle in September 2019 and folded the QL engine into what is now CodeQL and GitHub code scanning; the standalone Semmle and LGTM.com products were retired and www.semmle.com now redirects to the GitHub acquisition announcement. This profile is retained as a historical (acquired) company lead in the API Evangelist network.

Semmle is profiled on the APIs.io network. Tagged areas include Company, Enterprise, Code Analysis, Application Security, and Static Analysis.

6.8/100 minimal ▬ flat Agent 0/100 human only Full breakdown ↓
scored 2026-07-27 · rubric v0.5
0 APIs
CompanyEnterpriseCode AnalysisApplication SecurityStatic AnalysisDeveloper ToolsAcquired

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 6.8/100 · minimal
Contract Quality 0.0 / 25
Developer Ergonomics 0.0 / 20
Commercial Clarity 0.0 / 20
Operational Transparency 0.0 / 13
Governance 0.0 / 12
Discoverability 6.8 / 10
Agent readiness — 0/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/semmle: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Semmle Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Resources

Access & Security 1

Authentication, authorization, and security posture

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: semmle
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/semmle.png
name: Semmle
description: Semmle was a semantic code-analysis company whose engine let developers write queries (in its QL query language)
  to find security vulnerabilities and their variants across large codebases, and which powered the free open-source code
  review platform LGTM.com. Its technology was adopted by Uber, NASA, Microsoft, and Google. GitHub acquired Semmle in September
  2019 and folded the QL engine into what is now CodeQL and GitHub code scanning; the standalone Semmle and LGTM.com products
  were retired and www.semmle.com now redirects to the GitHub acquisition announcement. This profile is retained as a historical
  (acquired) company lead in the API Evangelist network.
url: https://raw.githubusercontent.com/api-evangelist/semmle/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- accel
x-tier: stub
x-tier-reason: portfolio-lead
x-status: acquired
x-acquired-by: github
x-acquired-date: '2019-09-18'
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-21'
tags:
- Company
- Enterprise
- Code Analysis
- Application Security
- Static Analysis
- Developer Tools
- Acquired
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: DomainSecurity
  url: security/semmle-domain-security.yml
- type: Website
  url: http://www.semmle.com
x-enrichment:
  date: '2026-07-21'
  status: minimal
  artifacts_added: 1
  pass: local-v1