No more typing reviews! Try our Samantha, our new voice AI agent.

Invicti Web + API vs OWASP Zap comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 6, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Invicti Web + API
Ranking in Static Application Security Testing (SAST)
11th
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
36
Ranking in other categories
Application Security Tools (16th), Vulnerability Management (30th), DevSecOps (7th)
OWASP Zap
Ranking in Static Application Security Testing (SAST)
15th
Average Rating
7.6
Reviews Sentiment
7.3
Number of Reviews
41
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Static Application Security Testing (SAST) category, the mindshare of Invicti Web + API is 2.6%, down from 3.3% compared to the previous year. The mindshare of OWASP Zap is 2.5%, down from 4.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Acunetix2.6%
OWASP Zap2.5%
Other94.9%
Static Application Security Testing (SAST)
 

Featured Reviews

Rahul Kumar - PeerSpot reviewer
Senior Engineer - Penetration Tester at a government with 10,001+ employees
Identifies vulnerabilities across bulk web applications but needs better support and cleaner reports
The best feature Acunetix offers is the centralized dashboard and the quality of reports it generates, which includes various options for selecting reports and developer options for directly sharing the reports with developers. The centralized dashboard of Acunetix gives visibility into the security aspects of mass applications; for instance, with more than 200 applications, it provides a valuable overview of findings and necessary fixes, along with a high-level summary that helps us achieve compliance through monthly and sometimes weekly scanning. In terms of reporting, Acunetix is excellent because it can generate different types of reports, such as an executive summary report, detailed reports, and developer reports that can be shared directly with developers. Acunetix positively impacts my organization by helping identify outdated libraries and applications, including legacy applications vulnerable to old attacks based on OWASP Top 10, thus aiding in compliance checks for PCI DSS and OWASP. Acunetix provides a centralized report with compliance-related aspects and a vulnerability timeline, effectively helping reduce vulnerabilities and save time.
Amit Beniwal - PeerSpot reviewer
Project Manager at Al Hassan LLC
Simplifies vulnerability discovery and has high quality support
There are areas for improvement with OWASP Zap, particularly in the alignment of vulnerabilities concerning CVSS scores. Sometimes, a vulnerability initially categorized as high severity may be reduced to medium or low over time after security patches are applied. This alignment with the present severity score and CVSS score could be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Acunetix is the best service in the world."
"Acunetix is the best service in the world. It is easy to manage. It gives a lot of information to the users to see and identify problems in their site or applications. It works very well."
"It's very user-friendly for the testing teams. It's very easy for them to understand things and to fix vulnerabilities."
"The automated approach to these repetitive discovery attempts would take days to do manually and therefore it helps reduce the time needed to do an assessment."
"The tool's most valuable feature is scan configurations. We use it for external physical applications. The scanning time depends on the application's code."
"The most valuable feature of the solution is the speed at which it can scan multiple domains in just a few hours."
"I appreciate the features that Acunetix has for the speed and the fact that it is in the cloud, which does not put any resources in my network, so I can set up a scan, go to bed, come back, and see the reports in my email."
"Acunetix has an awesome crawler. It gives a referral site map of near targets and also goes really deep to find all the inputs without issues. This was valuable because it helped me find some files or directories, like web admin panels without authentication, which were hidden."
"They offer free access to some other tools."
"The application scanning feature is the most valuable feature."
"The API is exceptional."
"Automatic updates and pull request analysis."
"It has evolved over the years and recently in the last year they have added, HUD (Heads Up Display)."
"The community edition updates services regularly. They add new vulnerabilities into the scanning list."
"The community support that ZAP provides me, as an open source, provides me flexibility and is convenient to use."
"The product discovers more vulnerabilities compared to other tools."
 

Cons

"It would be nice to have a feature to "retest" only a single vulnerability that the customer reports as patched, and delete it from the next scans since it has already been patched."
"In terms of additional features, we are currently missing some tools that would allow us to work more efficiently with the mobile environment, with Android and iOS."
"Integration into other tools is very limited for Acunetix. While we're trying to incorporate a CI/CD process where we're integrating with JIRA and we're integrating with Jenkins and Chef, it becomes problematic. Other tools give you a high integration capability to connect into different solutions that you may already have, like JIRA."
"The Acunetix licensing and pricing model is somewhat complicated. If we calculated all of our domains and sub-domains, the sum would be huge; that's why we thought of leaving Acunetix."
"When monitoring the traffic we always have issues with the bandwidth consumption and the throttling of traffic."
"Our experience with Acunetix has not been good, so we are in the process of switching solutions."
"However, their response is too slow."
"Acunetix needs to improve its cost."
"We have had stability issues a few times."
"The forced browse has been incorporated into the program and it is resource-intensive."
"As security evolves, we would like DevOps built into it. As of now, Zap does not provide this."
"If there was an easier to understand exactly what has been checked and what has not been checked, it would make this solution better. We have to trust that it has checked all known vulnerabilities but it's a bit hard to see after the scanning."
"The documentation is lacking and out-of-date, it really needs more love."
"I would recommend this product to people although I think it is very difficult to deploy and we also have issues with maintenance."
"The technical support team must be proactive."
"I'd also like to see an improvement in test reports because we get too many false positives."
 

Pricing and Cost Advice

"The pricing is a little high, and moreover, it's kind of domain-based."
"I would say that Acunetix is expensive because there are products on the market with similar features that are equally or better-priced."
"The pricing and licensing are reasonable to a point. In order to run multiple scans at a time, we are going to have to purchase a 100 count license, which is an overkill. Though, compared to what we were paying for, the cost seems reasonable."
"When compared with other products, the pricing is a little bit high. But it gives value for the price. It serves the purpose and is worthwhile for the price we pay."
"The price is exceptionally high."
"The costs aren't very expensive. It costs around $3000 or $4000."
"Acunetix was around the same price as all the other vendors we looked at, nothing special."
"Implementing Acunetix needs a medium or larger business agency, because you need some money to get Acunetix. It is costly, but if you care about your agency's security, then maybe it's a cost that might help you in the future."
"This app is completely free and open source. So there is no question about any pricing."
"It is highly recommended as it is an open source tool."
"The tool is open source."
"It's free and open, currently under the Apache 2 license. If ZAP does what you need it to do, selling a free solution is a very easy."
"The solution’s pricing is high."
"The tool is open-source."
"This solution is open source and free."
"This is an open-source solution and can be used free of charge."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
915,533 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
12%
Financial Services Firm
11%
Comms Service Provider
9%
Computer Software Company
9%
University
10%
Computer Software Company
9%
Comms Service Provider
8%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise7
Large Enterprise19
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise11
Large Enterprise22
 

Questions from the Community

What is your primary use case for Acunetix Vulnerability Scanner?
In a typical enterprise environment, Acunetix is mainly used for visibility, detection, and investigation across network traffic. The main use cases usually fall into a few core areas, with primary...
What advice do you have for others considering Acunetix Vulnerability Scanner?
I advise that Acunetix is the best option. Invest time in proper initial configuration and scope definitions. The tool is powerful, but its effectiveness depends heavily on how the authenticated ar...
What is your experience regarding pricing and costs for Acunetix?
Everything is perfect and good, including the pricing and all related aspects.
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What is your experience regarding pricing and costs for OWASP Zap?
OWASP might be cost-effective, however, people prefer to use the free edition available as open source.
What needs improvement with OWASP Zap?
The improvement that has to be done for APIs focuses on manual activities where the feature exists, but it is not at the same level as what Burp Suite does with intercepting and tools such as Postm...
 

Also Known As

AcuSensor
No data available
 

Overview

 

Sample Customers

Joomla!, Digicure, Team Random, Credit Suisse, Samsung, Air New Zealand
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Find out what your peers are saying about Invicti Web + API vs. OWASP Zap and other solutions. Updated: September 2026.
915,533 professionals have used our research since 2012.