Try our new research platform with insights from 80,000+ expert users

GitHub Advanced Security vs Invicti comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

GitHub Advanced Security
Average Rating
8.6
Reviews Sentiment
7.6
Number of Reviews
9
Ranking in other categories
Application Security Tools (11th)
Invicti
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
29
Ranking in other categories
Static Application Security Testing (SAST) (15th), API Security (6th), Dynamic Application Security Testing (DAST) (3rd)
 

Mindshare comparison

GitHub Advanced Security and Invicti aren’t in the same category and serve different purposes. GitHub Advanced Security is designed for Application Security Tools and holds a mindshare of 8.8%, up 3.4% compared to last year.
Invicti, on the other hand, focuses on Dynamic Application Security Testing (DAST), holds 13.9% mindshare, down 14.7% since last year.
Application Security Tools
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Sabna Sainudeen - PeerSpot reviewer
Seamlessly integrates into developer environment for streamlined code scanning
GitHub Advanced Security should look into API security issues, which they currently do not. Additionally, open-source security vulnerabilities are not getting updated in a timely manner. There are features in GitHub Advanced Security that cannot be used within Microsoft, which is strange since they are the same company. It should also focus on developing a software bill of materials (SBOM) to see all open software used in one place.
Kunal M - PeerSpot reviewer
Proactive scanning measures and realistic audit recommendations enhance development focus
Invicti's proactive scanning measures vulnerabilities each time we deploy or push code to a new environment. This feature helps us focus on priorities and prioritize the development team's effort, integrating seamlessly with DevOps to facilitate proactive scans of environments. Invicti also provides audit recommendations that are quite realistic, making it easy to discuss plans with developers.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product's most valuable features are security scan, dependency scan, and cost-effectiveness."
"The initial setup was straightforward and completed in a matter of minutes."
"GitHub Advanced Security is a very developer-friendly solution that is integrated within my development environment."
"GitHub Advanced Security uses artificial intelligence in the backend, specifically CodeQL, to analyze code and provide fewer but more reliable findings, so there are less false positives."
"Dependency scanning is a valuable feature."
"I have not experienced any performance or stability issues with GitHub Advanced Security."
"It is a stable solution...It is a scalable solution as it can handle new applications along with the analysis part."
"GitHub provides advanced security, which is why the customers choose this tool; it allows them to rely solely on GitHub as one platform for everything they need."
"Its ability to crawl a web application is quite different than another similar scanner."
"Netsparker has valuable features, including the ability to scan our website, an interactive approach, and security data integration."
"The most valuable feature of Invicti is getting baseline scanning and incremental scan."
"It has very good integration with the CI/CD pipeline."
"Crawling feature: Netsparker has very detail crawling steps and mechanisms. This feature expands the attack surface."
"Invicti's proactive scanning measures vulnerabilities each time we deploy or push code to a new environment."
"Scan, proxify the application, and then detailed report along with evidence and remediations to problems."
"The scanner and the result generator are valuable features for us."
 

Cons

"For GitHub Advanced Security, I would like to see more support for various programming languages."
"Open-source security vulnerabilities are not getting updated in a timely manner."
"GitHub Advanced Security should look into API security issues, which they currently do not. Additionally, open-source security vulnerabilities are not getting updated in a timely manner."
"A more refined approach, categorizing and emphasizing specific vulnerabilities, would be beneficial."
"Maybe make it compatible with more programming languages. Have a customized ruleset where the end-user can create their own rules for scanning."
"There could be DST features included in the product."
"The report limitations are the main issue."
"The deployment part of the product is an area of concern that needs to be made easier from an improvement perspective."
"The higher level vulnerabilities like Cross-Site Scripting, SQL Injection, and other higher level injection attacks are difficult to highlight using Netsparker."
"The solution's false positive analysis and vulnerability analysis libraries could be improved."
"The support's response time could be faster since we are in different time zones."
"The scanning time, complexity, and authentication features of Invicti could be improved."
"I think that it freezes without any specific reason at times. This needs to be looked into."
"The scanner itself should be improved because it is a little bit slow."
"Currently, there is nothing I would like to improve."
"The custom attack preparation screen might be improved."
 

Pricing and Cost Advice

"The solution is expensive."
"The current licensing model, which relies on active commitments, poses challenges, particularly in predicting and managing growth."
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
"We never had any issues with the licensing; the price was within our assigned limits."
"The solution is very expensive. It comes with a yearly subscription. We were paying 6000 dollars yearly for unlimited scans. We have three licenses; basic, business, and ultimate. We need ultimate because it has unlimited scan numbers."
"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
"It is competitive in the security market."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"The price should be 20% lower"
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
850,349 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
11%
Manufacturing Company
8%
Government
7%
Educational Organization
47%
Financial Services Firm
10%
Computer Software Company
8%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about GitHub Advanced Security?
It is a stable solution...It is a scalable solution as it can handle new applications along with the analysis part.
What needs improvement with GitHub Advanced Security?
For GitHub Advanced Security, I would like to see more support for various programming languages. Additionally, it would be beneficial to have more control at an organizational level rather than ha...
What is your primary use case for GitHub Advanced Security?
I use GitHub Advanced Security ( /products/github-advanced-security-reviews ) at my workplace to scan for code vulnerabilities and secrets in our software development workflow. It is used across mu...
What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
As a technical user, I do not handle pricing or licensing, but I am aware that Invicti offers flexible licensing models based on organizational needs.
What do you like most about Invicti?
The most valuable feature of Invicti is getting baseline scanning and incremental scan.
What needs improvement with Invicti?
Invicti's reporting capabilities need enhancement. We need enterprise-level information instead of repo-level details. Unlike Appiro, Invicti does not provide portfolio-level insights into vulnerab...
 

Also Known As

No data available
Netsparker
 

Overview

 

Sample Customers

Information Not Available
Samsung, The Walt Disney Company, T-Systems, ING Bank
Find out what your peers are saying about GitHub Advanced Security vs. Invicti and other solutions. Updated: October 2024.
850,349 professionals have used our research since 2012.