Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Semmle
Semmle HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Semmle? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 4 Oct 2026.

What it pays, by severity

Critical amount not published 4 reports
High amount not published 2 reports
Medium amount not published 5 reports
Low amount not published 16 reports

$14,000 paid to researchers in total. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
0
in 90 days
Resolved
27
all time, last one 7 years ago
Participants
23
hunters engaged
Response efficiency
100%
meeting its targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 0–0
6 Sep 0 reports 4 Oct

Response targets it sets itself

First response
5 days
Triage
10 days
Bounty
10 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

submissions disabled

Over 44 days (23 snapshots): no change on the figures worth watching.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

25 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 testanull 146 3 / 4 75%
2 kushagra 57 1 / 1 100%
3 gujjuboy10x00 44 2 / 6 33%
3 thehackerish 44 2 / 2 100%
3 todayisnew 44 2 / 2 100%
6 flamezzz 32 1 / 1 100%
7 vulnh0lic 29 2 / 2 100%
8 the_krisk 27 1 / 1 100%
9 aiacobelli 22 1 / 1 100%
9 ashish_r_padelkar 22 1 / 1 100%
9 cybertiger 22 1 / 1 100%
9 dustinboi 22 1 / 1 100%
9 dxaxpanda 22 1 / 1 100%
9 en0ne 22 1 / 2 50%
9 ephreet 22 1 / 1 100%
9 haxta4ok00 22 1 / 1 100%
9 hunter_pyc 22 1 / 1 100%
9 vishakh_b 22 1 / 1 100%
9 xel 22 1 / 1 100%
20 alpha66 12 1 / 4 25%
21 akashmethani 7 1 / 1 100%
21 bugschopper 7 1 / 1 100%
23 dawidczagan 2 1 / 3 33%
23 jhgrfgh 2 1 / 1 100%
23 tefa_ 2 1 / 1 100%
Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 1 Oct 2026.

Semmle's engineering analytics platform helps leading technology companies and open-source developers build secure, reliable software.

Responsiveness
100% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Disabled
Launched
Feb 2019
Scope entries
8 HackerOne’s count

Scope

8 assets
AssetTypeEligibilityMax severity
89.16.163.96/28 CIDR ✓ bounty Critical
backend-dot-lgtm-penetration-testing.appspot.com URL ✓ bounty Critical
lgtm-com.pentesting.semmle.net URL ✓ bounty Critical
*.lgtm.com WILDCARD out None
*.semmle.com WILDCARD out None
Show all 8 assets
AssetTypeEligibilityMax severity
discuss.lgtm.com URL out None
help.semmle.com URL out None
semmle.com URL out None