Try our new research platform with insights from 80,000+ expert users

What is Invicti?

Featured Invicti reviews

Invicti mindshare

As of December 2025, the mindshare of Invicti in the Dynamic Application Security Testing (DAST) category stands at 7.9%, up from 5.0% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST) Market Share Distribution
ProductMarket Share (%)
Invicti7.9%
Veracode21.2%
Checkmarx One18.0%
Other52.9%
Dynamic Application Security Testing (DAST)

PeerResearch reports based on Invicti reviews

TypeTitleDate
CategoryDynamic Application Security Testing (DAST)Dec 30, 2025Download
ProductReviews, tips, and advice from real usersDec 30, 2025Download
ComparisonInvicti vs VeracodeDec 30, 2025Download
ComparisonInvicti vs Checkmarx OneDec 30, 2025Download
ComparisonInvicti vs HCL AppScanDec 30, 2025Download
Suggested products
TitleRatingMindshareRecommending
SonarQube4.0N/A83%134 interviewsAdd to research
Snyk4.1N/A100%50 interviewsAdd to research
 
 
Key learnings from peers
Last updated Dec 28, 2025

Valuable Features

Room for Improvement

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
Company SizeCount
Small Business11
Midsize Enterprise3
Large Enterprise12
By reviewers
By visitors reading reviews
Company SizeCount
Small Business113
Midsize Enterprise100
Large Enterprise220
By visitors reading reviews

Top industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
13%
Manufacturing Company
8%
Government
7%
Retailer
6%
Educational Organization
5%
Comms Service Provider
4%
Legal Firm
3%
University
3%
Healthcare Company
3%
Construction Company
3%
Real Estate/Law Firm
3%
Recreational Facilities/Services Company
2%
Transportation Company
2%
Energy/Utilities Company
2%
Performing Arts
2%
Insurance Company
2%
Outsourcing Company
2%
Wholesaler/Distributor
1%
Security Firm
1%
Consumer Goods Company
1%
Leisure / Travel Company
1%
Media Company
1%
Non Tech Company
1%
Wellness & Fitness Company
1%
Non Profit
1%
Hospitality Company
1%
Logistics Company
1%
 
Invicti Reviews Summary
Author infoRatingReview Summary
Senior Manager, Security Engineering at ESS4.0I've used Invicti for over three years for web and API testing; it's reliable in identifying vulnerabilities, though scan performance needs improvement. Setup is easy, support is good, and it's well-suited to our SSDLC and technology stack.
Solution Architect at a tech services company with 51-200 employees4.0I've used Invicti for three years to secure web applications; it’s easy to deploy, scalable, and offers effective SAST and DAST scanning, with solid vulnerability detection and good support, especially for SMBs in hybrid environments.
Capability Center Leader, ETRM Platforms at Shell4.0I use Invicti for code scans to identify vulnerabilities and secrets, aiding our development teams in prioritizing tasks. Its proactive scanning is valuable, though its reporting needs improvement for enterprise-level insights. Invicti was my first such tool.
Cyber Security Engineer at Spartec5.0I primarily use Netsparker for website scanning, appreciating its interactive interface and scalability for securing large-scale applications. Previously, I used Tenable.io but found Netsparker more engaging. There's currently nothing I wish to improve about it.
CEO at Xcelliti3.5We use Invicti for vulnerability testing, especially in fintech. It excels in proof-based scanning with minimal false positives, integrates well with CI/CD pipelines, and offers good scalability. However, improvements are needed in user interface, documentation, and support.
Presales Consultant at Cyberwise4.0We use Invicti to detect vulnerabilities and ensure compliance with regulations like PCI DSS and GDPR. Its proof-based scanning reduces false positives and saves time. However, the costly licensing, lengthy scan times, and need for more integrations are drawbacks.
Senior Manager, Security Engineering at ESS4.0I use Invicti primarily for web application and API testing. I find its API testing and false positive checks valuable, though improvements in scanning time and authentication features are needed. I also use Burp Suite and HCL AppScan for specific tasks.
Senior Information Security Analyst at EastNets Holding Ltd.4.5We use Invicti to initialize applications before client release, deploying and scanning for specific server issues, language, and vulnerabilities. Its strengths are confirming access and SSL injection vulnerabilities and connecting with other security tools. However, report specificity needs improvement.