We are a consultant company.
Cyber Security Engineer at a tech services company with 11-50 employees
Provides proof of exploit, gives the specific code affected and enables a shift-left approach in the development process
Pros and Cons
- "By integrating with CI/CD tools, it enables a shift-left approach in the development process."
- "There is room for improvement in the pricing."
What is our primary use case?
How has it helped my organization?
Just by scanning, Acunetix provides proof of exploit and gives the specific code affected. You can also see a categorized list of vulnerabilities. From there, you can easily create a report.
It integrates with multiple tools in the CI/CD pipeline, like Jira and web application firewalls.
Acunetix automation improved our customer's security testing process. By integrating with CI/CD tools, it enables a shift-left approach in the development process. This helps find vulnerabilities earlier rather than after the application is published.
What is most valuable?
The interactive transaction feature is a winning point for us. It's a great selling point. Also, the ability to provide an inventory of currently used APIs is very helpful.
What needs improvement?
There is room for improvement in the pricing.
Tenable is better integrated and offers many tools in a bundle. I would like to see the same thing in Acunetix. Otherwise, I'm satisfied with Acunetix's performance.
Buyer's Guide
Acunetix
December 2025
Learn what your peers think about Acunetix. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
For how long have I used the solution?
I have been using it for three years.
What do I think about the scalability of the solution?
We propose this product for smaller or bigger businesses.
But mostly to bigger enterprises. It's because of the reputation it has with bigger companies.
How are customer service and support?
Acunetix provides good support. No complaints.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Acunetix stands out with its metrics, features, and Proof of Exploit. Other solutions we've used don't have those.
There is also Tenable.io Web App Scanning. Tenable's advantage is how it handles vulnerability management. For example, if you have Ansible vulnerability management, you can see both sets of information in a single pane. The only other difference might be pricing, but I'm not entirely sure about that.
How was the initial setup?
The initial setup is straightforward. Considering everything is in place, it will take about two weeks.
What about the implementation team?
We usually help our customers implement the product.
What's my experience with pricing, setup cost, and licensing?
The price is reasonable. We don't have many complaints from customers.
What other advice do I have?
I would recommend Acunetix to others for their web vulnerability scanning needs.
Overall, I would rate it a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Hardware Engineer
Scalable and efficient web security and vulnerability management
Pros and Cons
- "It comes equipped with an internal applicator, which automatically identifies and addresses vulnerabilities within the program."
- "There's a clear need for a reduction in pricing to make the service more accessible."
What is our primary use case?
It is top-rated and widely employed for conducting security assessments on networks, websites, and applications. It is considered the gold standard for evaluating security measures and identifying vulnerabilities in websites, networks, and applications. The tool's extensive capabilities make it a go-to choice for ensuring security. It is renowned for its comprehensive scanning and assessment of networks and websites, but it is also known for its significant cost, particularly for deploying it on large clusters.
What is most valuable?
One of its primary features is its ability to offer automated solutions for application security. It comes equipped with an internal applicator, which automatically identifies and addresses vulnerabilities within the program. It then provides insights on how to rectify these issues, even showcasing the payloads and other relevant information in the report. Occasionally, it may generate some false positives, but for the most part, it delivers reports that are approximately 80% accurate. This allows users to manually test the function and ascertain its functionality. It also allows for communication with external entities, vendors, and servers used by the application. This information encompasses server hosting details, the status of open or closed ports, and insights into Indian Palantir, among others. These features make it an invaluable resource for those seeking to comprehensively understand their website's infrastructure and potential vulnerabilities.
What needs improvement?
The initial concern that comes to mind is the cost as the pricing structure is significantly high, especially for the average user. It amounts to approximately $2,000 per year, excluding additional expenses. There's a clear need for a reduction in pricing to make the service more accessible. Another critical enhancement should focus on the tool's ability to bypass Web Application Firewalls. Currently, it falls short in this aspect, which can be a significant limitation.
For how long have I used the solution?
I have been working with it for nine years now.
What do I think about the stability of the solution?
It provides good stability abilities.
What do I think about the scalability of the solution?
It offers excellent scalability capabilities. You have the flexibility to adjust your usage based on workload demands and it becomes a valuable and frequently used tool to accommodate the increased workload when multiple projects come in. I would rate it nine out of ten.
How are customer service and support?
I am not very satisfied with the customer support they provide. It tends to be quite time-consuming. When I raised a ticket seeking assistance with a simple issue, their response time was notably delayed. They mentioned having a backlog of inquiries, and it took a while for them to address my specific question. There seems to be a disconnect between the amount of money they charge for their support services and the level of support they provide.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup was straightforward. I would rate it nine out of ten.
What about the implementation team?
You can easily download the application and install it on your desktop. The setup algorithm simplifies the application installation on your computer, it automatically configures itself on your system, eliminating the need for any manual configuration. It's a quick and hassle-free installation, taking just about five minutes to set up and configure. The deployment management is quite efficient and it can be handled by a single individual.
What's my experience with pricing, setup cost, and licensing?
The price is exceptionally high. They offer various categories of services, but the problem lies in the lack of transparency. Before purchasing, they don't clearly outline the available versions or their limitations, and they don't display their pricing on the website. They should have a standardized pricing structure readily available on their website for all potential users to see. This lack of pricing information is a rarity and an issue that needs to be addressed.
What other advice do I have?
To effectively utilize this tool on a monthly basis, users must possess a certain level of expertise. It is crucial that individuals who wish to employ this tool have experience in both programming and networking to make the most of its functionalities. I would rate it eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Acunetix
December 2025
Learn what your peers think about Acunetix. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
Compliance Manager at a recruiting/HR firm with 1,001-5,000 employees
Attractive automated reports with boost user productivity and an easy setup
Pros and Cons
- "It generates automated reports."
- "The cost can be reduced as management has noted it to be on the higher side."
What is our primary use case?
The primary use is mainly related to vulnerability assessment, including both public and internal IP addresses.
How has it helped my organization?
By using this tool, we have reduced the workload and increased the productivity of users.
What is most valuable?
It generates automated reports. This feature is beneficial when sharing reports with clients as it works as a unique selling point due to how attractive and descriptive the reports are.
What needs improvement?
The interface API and other functionalities are very good. However, the cost can be reduced as management has noted it to be on the higher side.
For how long have I used the solution?
I have been working with Acunetix for almost two years.
How are customer service and support?
The technical support provided by Acunetix is absolutely great. We received support from them at every point in time.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I used Nessus in one of my previous organizations due to cost reasons. However, my current organization decided to go with Acunetix.
How was the initial setup?
The initial setup was easy because we had a proper software team consisting of developers, database administrators, and application teams. With the help of the vendor, we were able to implement it successfully. It took approximately three to four months.
What about the implementation team?
The implementation was carried out with the help of a consultant.
What's my experience with pricing, setup cost, and licensing?
The cost is being handled by the procurement team, yet it is on the higher side, and there is a recommendation to reduce it.
What other advice do I have?
I would generally recommend Acunetix to any organization in the IT-enabled sector. However, I have not worked for a non-IT organization, so I cannot comment on that.
I'd rate the solution nine out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Team Lead, Application Security at a financial services firm with 1,001-5,000 employees
Helps to scan web applications but needs to include agent analysis
Pros and Cons
- "The tool's most valuable feature is scan configurations. We use it for external physical applications. The scanning time depends on the application's code."
- "Acunetix needs to include agent analysis."
What is our primary use case?
We use the product for dynamic analysis. It also helps us to scan web applications.
What is most valuable?
The tool's most valuable feature is scan configurations. We use it for external physical applications. The scanning time depends on the application's code.
What needs improvement?
Acunetix needs to include agent analysis.
For how long have I used the solution?
I have been using the product for four years.
What do I think about the stability of the solution?
I rate the tool's stability a nine out of ten.
What do I think about the scalability of the solution?
I rate Acunetix's scalability a seven out of ten. My company has five to four users.
How was the initial setup?
I rate the tool's deployment a nine out of ten.
What was our ROI?
We have seen good ROI with the tool's use.
What other advice do I have?
Acunetix is good and helps to scan properly. I rate it a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Executive Manager at a tech services company with 11-50 employees
You can scan multiple domains in just a few hours compared to the competition
Pros and Cons
- "The most valuable feature of the solution is the speed at which it can scan multiple domains in just a few hours."
- "The solution can be improved by adding the ability to scan subdomains automatically, and by providing reports that can be exported to external databases to share with other solutions."
What is our primary use case?
The primary use case of the solution is to scan our web applications for vulnerabilities.
What is most valuable?
The most valuable feature of the solution is the speed at which it can scan multiple domains in just a few hours.
What needs improvement?
The solution can be improved by adding the ability to scan subdomains automatically, and by providing reports that can be exported to external databases to share with other solutions. The solution is also costly and can use a price reduction.
For how long have I used the solution?
I have been using the solution for two years.
How was the initial setup?
The initial setup is not complex. You can be set up and start your first scan within an hour.
What about the implementation team?
The implementation was done in-house.
What's my experience with pricing, setup cost, and licensing?
The cost is based on two types of licenses, ConsultLite, and ConsultPlus, as well as the number of domains that are scanned. The minimum package is five domains or subdomains.
Which other solutions did I evaluate?
The other options I evaluated are AppSpider, Netsparker, and HCL AppScan.
What other advice do I have?
I give the solution nine out of ten.
The solution is faster than AppSpider when scanning primary domains but it does not scan subdomains. If you require a solution that does a more in-depth scan I don't recommend the solution.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
VP Business Development at a tech services company with 11-50 employees
Provides a lot of information, comes with good support, and is easy to manage
Pros and Cons
- "Acunetix is the best service in the world. It is easy to manage. It gives a lot of information to the users to see and identify problems in their site or applications. It works very well."
- "The only problem that they have is the price. It is a bit expensive, and you cannot change the number of applications for the whole year."
What is most valuable?
Acunetix is the best service in the world. It is easy to manage. It gives a lot of information to the users to see and identify problems in their site or applications. It works very well.
What needs improvement?
The only problem that they have is the price. It is a bit expensive, and you cannot change the number of applications for the whole year.
For how long have I used the solution?
We have been partners for two years.
What do I think about the scalability of the solution?
For such services, scalability is not relevant because you just scan your service and make a document of the problems that you have. After that, you have to take care of them and fix them. So, it's not like other services that have to be working 24/7. You only run it and receive information.
Its users vary because in some companies, the web is under the IT team, and in some companies, the web is under security, CISO, or something like this. It depends on how much personnel the company has to manage these tools.
How are customer service and support?
The Acunetix team is in Malta. They are very good, and they provide support over the phone. They are available 24 hours a day, and they answer your queries very fast. They're very active and good.
How was the initial setup?
It is a bit complicated, but their support is very good in case of any issues. It can be on-prem or on the cloud. It depends on what the customer wants.
You don't need more than one person for its maintenance.
What's my experience with pricing, setup cost, and licensing?
It is a bit expensive. If you need to check five applications, you have to pay almost 14,000. It is an agreement for two years at 7,000 per year for only five applications. You cannot change the applications in the license. So, you are stuck with the same license for the five applications for one full year.
In terms of additional costs, you may need an expert in applications/sites to write the code and fix the code problems. You can do all the things by yourself because it tells you what to do, how to fix, and what to change, but you have to give your people time to take care of those things.
What other advice do I have?
For SMB customers, it is a good tool to take care of the applications and the website of the company. It works well, but it is a bit expensive. I would advise others to prepare the money for it.
I would rate it a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Security Engineer at a tech services company with 11-50 employees
Very easy to set up because they give you an installer that does everything
Pros and Cons
- "Acunetix has an awesome crawler. It gives a referral site map of near targets and also goes really deep to find all the inputs without issues. This was valuable because it helped me find some files or directories, like web admin panels without authentication, which were hidden."
- "I had some issues with the JSON parameters where it found some strange vulnerabilities, but it didn't alert the person using it or me about these vulnerabilities, e.g., an error for SQL injection."
What is our primary use case?
We needed it to scan our internal network and web applications.
Our security team of five people used it. We scheduled some monthly scans for web applications, which were not being used, to check for vulnerabilities and also vulnerabilities on new features.
How has it helped my organization?
Where I worked was a big group where there were many agencies under it, and we did the security for all other agencies. With Acunetix, we cut the time to make infrastructures and web applications (for our colleagues) more secure.
For one application with two or three critical vulnerabilities and some other vulnerabilities, it took like a week to remediate issues because the scan and findings were really fast.
What is most valuable?
What I found to be valuable was the fully automated scanner because it is really fast.
Acunetix has an awesome crawler. It gives a referral site map of near targets and also goes really deep to find all the inputs without issues. This was valuable because it helped me find some files or directories, like web admin panels without authentication, which were hidden.
Acunetix saves on the cost of time because it is fast.
When Acunetix finds a vulnerability, it also checks for a false positive so it can be a 100 percent sure about the issue that it found. The false positives are really low, maybe one percent.
What needs improvement?
I had some issues with the JSON parameters where it found some strange vulnerabilities, but it didn't alert the person using it or me about these vulnerabilities, e.g., an error for SQL injection.
They need more customized scans along with a way to edit their default payloads. While you can select which check to do, you can't add which payload to use.
For how long have I used the solution?
I used Acunetix 20 months ago at the last agency where I worked.
What do I think about the scalability of the solution?
The scalability was okay. We didn't need to do much work to implement it into the network or some web applications, so I think it's really easy to scale. We didn't need to do work on it because the solution is adaptable to every environment.
There were about 20 websites and other web applications.
How are customer service and technical support?
I never needed to talk to the Acunetix technical support.
Which solution did I use previously and why did I switch?
They were previously using Fortify WebInspect, which was good, but very costly.
How was the initial setup?
It was very easy to set up Acunetix, as they give you an installer that does everything. You just need to click: "Install".
It takes a maximum of 10 minutes to deploy, if you want to read everything.
We did other configurations to enable the IP address to talk to all the networks.
We also used Acunetix on a Linux server. The deployment process was the same as Windows. It was just another installer, but for Linux.
What was our ROI?
It saved us many weeks of work.
We didn't sell anything with Acunetix, so it was just an improvement for ourselves.
If someone would have hacked us, they probably would have caused much damage. However, now with Acunetix, they shouldn't be able to cause to damage.
What's my experience with pricing, setup cost, and licensing?
I think all the scanners, except Burp Suite, are a bit costly.
Implementing Acunetix needs a medium or larger business agency, because you need some money to get Acunetix. It is costly, but if you care about your agency's security, then maybe it's a cost that might help you in the future.
Which other solutions did I evaluate?
Acunetix is the fastest scanner available compared to applications like Netsparker and Fortify WebInspect. The longest scan with Acunetix, and it was for a huge web application, took only four hours. Other scanners did the job in six to eight hours.
While I like Netsparker, it is really slow compared to other scanners.
What other advice do I have?
We found 50 unexpected, high vulnerabilities for three web applications. This made our principal a bit mad.
We found three or four DOM-based XSS vulnerabilities using this solution.
It did not require maintenance on our part. We just needed to give it some credentials.
I would rate it as a nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Comes with good performance but pricing is expensive
Pros and Cons
- "The tool's most valuable feature is performance."
- "Acunetix needs to improve its cost."
What is our primary use case?
We use the product for application security.
What is most valuable?
The tool's most valuable feature is performance.
What needs improvement?
Acunetix needs to improve its cost.
For how long have I used the solution?
I have been using the product for a year.
What do I think about the stability of the solution?
The tool is stable.
What do I think about the scalability of the solution?
Acunetix is scalable.
How are customer service and support?
The tool's support is good.
How would you rate customer service and support?
Positive
What other advice do I have?
I rate the product a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Acunetix Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Vulnerability Management DevSecOpsPopular Comparisons
SonarQube
Snyk
GitLab
Checkmarx One
Veracode
Qualys VMDR
Tenable Nessus
Coverity Static
JFrog Xray
Tenable Security Center
Tenable Vulnerability Management
OWASP Zap
OpenText Core Application Security
Mend.io
Sonatype Lifecycle
Buyer's Guide
Download our free Acunetix Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?
- Which application security solutions include both vulnerability scans and quality checks?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- SAST vs. DAST: Which is better for application security testing?



















