Invicti vs Qualys Web Application Scanning comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Invicti
Ranking in Application Security Tools
20th
Ranking in Static Application Security Testing (SAST)
15th
Average Rating
8.2
Number of Reviews
26
Ranking in other categories
No ranking in other categories
Qualys Web Application Scan...
Ranking in Application Security Tools
19th
Ranking in Static Application Security Testing (SAST)
14th
Average Rating
7.8
Number of Reviews
31
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2024, in the Application Security Tools category, the mindshare of Invicti is 1.2%, down from 1.3% compared to the previous year. The mindshare of Qualys Web Application Scanning is 2.4%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
Unique Categories:
Static Application Security Testing (SAST)
1.1%
 

Featured Reviews

AY
May 10, 2020
Very high level of accuracy and speedy scanning
Our primary use case is for web applications but rather than being in a production environment, it's in a testing environment. We check for vulnerabilities found in the test environment and remediate them. Following that, we publish the web application for web production. We are customers of…
Brammadevan K - PeerSpot reviewer
Feb 22, 2024
Operates as a DAST tool, examining the application from an external perspective to identify security issues
One area for improvement is the application scan interface. Although recent updates have introduced some features, there's a gap in supporting standards beyond OWASP. Currently, there isn't an option to select or integrate other security standards directly within the platform, which limits the scope of scans to primarily OWASP. For broader compliance, custom integrations are required, which is a cumbersome process. The platform primarily supports OWASP standards for scanning. If an organization needs to comply with other standards, such as ISO or NIST, there's no straightforward option to select these within the scanning interface. This limitation requires custom solutions to meet other compliance requirements, which is not ideal. Qualys should enhance its interface to allow users to easily select and scan according to multiple standards, not just OWASP. This includes both internal and external scans, providing a more flexible and comprehensive approach to web application security. In addition to choosing standards, there's a distinction between internal and external scanning processes that could be streamlined. Currently, for internal scanning, specific configurations and scanner appliances need to be deployed within the network, which differs from the simpler setup for external scans. This dual process complicates the setup for comprehensive scanning coverage. The process should be simplified to eliminate the need for two distinct setups for internal and external scans within Qualys.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Scan, proxify the application, and then detailed report along with evidence and remediations to problems."
"This tool is really fast and the information that they provide on vulnerabilities is pretty good."
"Crawling feature: Netsparker has very detail crawling steps and mechanisms. This feature expands the attack surface."
"It correctly parses DOM and JS and has really good support for URL Rewrite rules, which is important for today's websites."
"The dashboard is really cool, and the features are really good. It tells you about the software version you're using in your web application. It gives you the entire technology stack, and that really helps. Both web and desktop apps are good in terms of application scanning. It has a lot of security checks that are easily customizable as per your requirements. It also has good customer support."
"The scanner and the result generator are valuable features for us."
"Invicti is a good product, and its API testing is also good."
"I like that it's stable and technical support is great."
"Key features include: Cloud-based, so the installation is not so tedious. Easily deployed. Highly scalable. Comprehensive reporting."
"By using QualysGuard, we are able to finish external scans with assured results in half the time.​"
"Its most valuable features are patch management, vulnerability management, and PCI compliance."
"It combines both web application vulnerability management and internal vulnerability management on one platform and dashboard. Usually, you have to purchase separate tools."
"It is a cloud-based solution, so it is easy to scale."
"It is a very stable solution."
"It is easy to use."
"Qualys WAS' most valuable features are the navigation flow of the UI and the option for a different layer of security (identification and operation through email and mobile)."
 

Cons

"The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them."
"Invicti takes too long with big applications, and there are issues with the login portal."
"Asset scanning could be better. Once, it couldn't scan assets, and the issue was strange. The price doesn't fit the budget of small and medium-sized businesses."
"The solution's false positive analysis and vulnerability analysis libraries could be improved."
"They could enhance the support for data swap testing for the platform."
"I think that it freezes without any specific reason at times. This needs to be looked into."
"The solution needs to make a more specific report."
"The licensing model should be improved to be more cost-effective. There are URL restrictions that consume our license. Compared to other DAST solutions and task tools like WebInspect and Burp Enterprise, Invicti is very expensive. The solution’s scanning time is also very long compared to other DAST tools. It might be due to proof-based scanning."
"The reporting contains too many false positives."
"The virus code updates are not frequent enough."
"Qualys Web Application Scanning is very complex to use, and its graphical interface is not very user-friendly."
"The software’s pricing could be improved."
"There's a distinction between internal and external scanning processes that could be streamlined. Currently, for internal scanning, specific configurations and scanner appliances need to be deployed within the network, which differs from the simpler setup for external scans. This dual process complicates the setup for comprehensive scanning coverage."
"Sometimes the response time is low because the handshake fails, and then you have to re-login and start again."
"They should try to include business logic vulnerabilities in the scanner testing."
"Deployment can be complicated."
 

Pricing and Cost Advice

"OWASP Zap is free and it has live updates, so that's a big plus."
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
"We never had any issues with the licensing; the price was within our assigned limits."
"The price should be 20% lower"
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
"The solution is very expensive. It comes with a yearly subscription. We were paying 6000 dollars yearly for unlimited scans. We have three licenses; basic, business, and ultimate. We need ultimate because it has unlimited scan numbers."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"The product has a very good licensing model."
"Qualys has an IT-based licensing based on a yearly license, which is a good way of handling it. However, in some cases, when we do the PCI scanning, the host will not like the scanning and we lose the IT license. So, this could be improved."
"Qualys Web Application Scanning's pricing is a bit expensive compared to other solutions available in the market."
"We are on an annual license for the solution and the pricing could be more affordable."
"Qualys WAS' pricing is competitive."
"Pricing was reasonable and competitive. It was not too far above the other products."
"There are different options available with respect to licensing."
"The cost is $30,000 USD for one year to cover WAS (Web Application Security) and the VM (Virtual Machine) security in a company with 200 employees."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
52%
Financial Services Firm
8%
Computer Software Company
7%
Manufacturing Company
5%
Computer Software Company
15%
Financial Services Firm
15%
Manufacturing Company
9%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
The solution is very expensive. It comes with a yearly subscription. We were paying 6000 dollars yearly for unlimited scans. We have three licenses; basic, business, and ultimate. We need ultimate ...
What do you like most about Invicti?
The most valuable feature of Invicti is getting baseline scanning and incremental scan.
What needs improvement with Invicti?
The solution's false positive analysis and vulnerability analysis libraries could be improved.
What do you like most about Qualys Web Application Scanning?
The vulnerability management feature is a strong one. And also the patch management feature.
What is your experience regarding pricing and costs for Qualys Web Application Scanning?
From my perspective, it is a budget-friendly option. Qualys offers good value for the features and protection it provides. The pricing seems reasonable, considering the comprehensive security solut...
What needs improvement with Qualys Web Application Scanning?
One area for improvement is the application scan interface. Although recent updates have introduced some features, there's a gap in supporting standards beyond OWASP. Currently, there isn't an opti...
 

Also Known As

Mavituna Netsparker
Qualys WAS
 

Learn More

 

Overview

 

Sample Customers

Samsung, The Walt Disney Company, T-Systems, ING Bank
BskyB, Cartagena, ClearPoint Learning Systems, Connect Group, du, Fortrex Technologies, HBOR, HDI, Highlights for Children, The Lithuanian State Enterprise Centre of Registers, City of Miami Beach, Microsoft, MidlandHR, MSCI Inc., Northern Arizona University, Ofgem, Olympus Europa, PhoneFactor, RTL Nederland, ThousandEyes, VGZ Organisatie B.V.
Find out what your peers are saying about Invicti vs. Qualys Web Application Scanning and other solutions. Updated: May 2024.
787,779 professionals have used our research since 2012.