

Acunetix and Klocwork are leaders in web application security and static code analysis, respectively. Acunetix holds an advantage in web application security due to its comprehensive reporting and ease of use, while Klocwork excels in early error detection and integration capabilities.
Features: Acunetix offers automated vulnerability scanning, integration options with CI/CD tools, and detailed security reports, making it valuable for web application security by identifying cross-site scripting and SQL injection vulnerabilities efficiently. Klocwork provides static code analysis, on-the-fly analysis for early error detection, and robust integration with continuous integration (CI) tools, helping to improve code quality and reduce development cycle errors.
Room for Improvement: Users suggest Acunetix could improve scanning speed, interaction with JavaScript, and language support. Its pricing is also seen as a limitation with calls for better false positive reduction. Klocwork needs to address licensing concerns and improve support for modern programming languages. Processing large codebases and dashboard enhancements are also areas for improvement.
Ease of Deployment and Customer Service: Acunetix is versatile, supporting both on-premises and cloud deployments, with smooth onboarding and effective ongoing technical support, though response times could be faster. Klocwork integrates easily within development workflows and offers responsive customer support, though navigating complex setups and upgrades may pose challenges.
Pricing and ROI: Acunetix is considered a higher-cost solution, though its ability to reduce manual testing efforts leads to strong security returns. Klocwork offers more competitive pricing, beneficial for organizations focused on static code analysis, providing a positive ROI by enhancing code quality and early defect detection.
It saves a significant amount of time by covering attack surfaces.
I have seen a return on investment, as Acunetix helps reduce the man-days and effort needed for scanning bulk applications through automated assessments.
The main ROI factors include efficiency and how we meet compliance standards for various automotive requirements.
For high-severity issues, they reach out within two to three hours, and for critical issues, a response is received within 15 minutes.
The technical support from Invicti is very good and fast.
Support staff not being familiar with the problem.
The customer support team is very responsive, proactive, and engages in conversations to ensure our needs are met.
The issue is not about the knowledge of the support but about the prioritization of the tickets they handle.
During the initial phase, there was a need for follow-ups and clarifications.
Acunetix can handle increasing workloads and more applications easily.
Klocwork supports our scalability needs without issues, even as project volumes increase.
The program-to-program enablement is scalable.
Installation is easy, and the solution is stable.
The main concern is related to false positives; Acunetix needs to work on identifying valid and invalid findings.
I could supply it with maybe a Swagger file or a JSON file, and Acunetix would pick it up, scan all the endpoints according to the OWASP Top Ten, and give me remediation and actionable remediation reports.
Acunetix should have better integration with newer tools such as GitHub and Azure DevOps.
There are too many warnings, and it requires expertise to determine the correct category for them.
Klocwork sometimes provides too many additional warnings which require expertise to manage.
We would like Klocwork to connect to Git and notify developers of issues tied to specific commits.
The pricing cost is affordable for small and mid-sized organizations, and when compared to Checkmarx, it is significantly affordable, as Checkmarx is quite expensive.
We secured a special licensing model for penetration testing companies, which is cost-effective.
The pricing of Acunetix is pretty expensive and could be improved.
It is less expensive than Coverity.
The solution is not very cheap, however, it is less expensive than Coverity.
Klocwork was competitively priced, making it a cost-effective solution for us.
Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.
The solution is excellent at detecting SQL injection and cross-site scripting vulnerabilities.
The best feature Acunetix offers is the centralized dashboard and the quality of reports it generates, which includes various options for selecting reports and developer options for directly sharing the reports with developers.
The most valuable feature of Klocwork is the static analysis tools, which help identify potential security threats and errors.
Its integration with the CI/CD pipeline has helped streamline the software development process.
It takes just half a day to set up.
| Product | Mindshare (%) |
|---|---|
| Acunetix | 2.4% |
| Klocwork | 1.5% |
| Other | 96.1% |

| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 7 |
| Large Enterprise | 19 |
| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 2 |
| Large Enterprise | 13 |
Acunetix is a robust web application security testing tool offering rapid scanning, user-friendly interfaces, and accurate vulnerability detection with minimal false positives. It supports both cloud and on-premises deployment, making it versatile for various security needs.
Acunetix is distinguished by its capability to identify critical vulnerabilities such as cross-site scripting and SQL injection with high precision. It integrates seamlessly with CI/CD tools, supporting continuous scanning and large-scale application management. The centralized dashboard and detailed automated reporting streamline operations. Despite its benefits, users suggest improvements like reducing false positives, flexible pricing, and enhanced API scanning. Better integration with platforms like GitHub and Azure DevOps is sought, alongside more comprehensive customization and faster scanning. Mobile application scanning and improved team collaboration tools are also desired.
What features make Acunetix stand out?Acunetix is widely implemented across industries undertaking web application security assessments, including those requiring penetration testing and vulnerability assessment. It ensures applications meet security protocols and complies with standards while fitting into CI/CD workflows for secure pre-release checks.
Klocwork offers advanced static code analysis with integration capabilities for enhanced development efficiency, supporting various development environments and providing clear defect reports. It streamlines software development by reducing defects and improving code quality.
Klocwork integrates seamlessly into CI/CD pipelines, providing real-time and incremental analysis to identify and rectify code defects quickly. It supports multiple integrated development environments (IDEs) and minimizes false positives in its analysis. While primarily supporting C/C++, Java, and C#, there is a need to expand language support and enhance its static analysis engine. The tool assists in adhering to industry standards with features like automated code parsing and MISRA compliance checks. Ease of setup and collaboration capabilities further promotes efficiency, although the dashboard could benefit from user-friendly updates and better integration with Agile tools.
What are the primary features of Klocwork?Klocwork is extensively implemented in industries that prioritize software quality and security standards, particularly in environments focused on C/C++ development on Linux systems. Its capabilities in automated code parsing, traffic analysis, and support for DevOps integration make it invaluable for industries requiring strict MISRA compliance and internal standards adherence. By aiding refactoring and detecting memory-related vulnerabilities, Klocwork contributes to the maintainability and security standards in these sectors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.