

Acunetix and Qualys Web Application Scanning (WAS) compete in the web application security space. Acunetix seems to have the upper hand due to its notable accuracy and integration in CI/CD environments.
Features: Acunetix is effective in detecting vulnerabilities such as SQL injection and cross-site scripting, offers strong integration with CI/CD environments, and supports cloud and on-premises deployments. It also features impressive reporting capabilities and advanced options for managing scanning targets. Qualys WAS offers excellent monitoring, robust integration with various tools, and strong vulnerability and patch management. Its scheduled scanning and PCI compliance features add to its comprehensive capabilities.
Room for Improvement: Qualys WAS could reduce its integration complexities and simplify its user interface. Users note longer scan times and integration challenges in certain environments, with pricing being a concern for some. Acunetix would benefit from faster scan times and enhanced customization of scan settings. Users are frustrated by false positives and find the cost and licensing model to be complex or expensive.
Ease of Deployment and Customer Service: Qualys offers flexible deployment options across public, private, and hybrid clouds with stable deployment experiences and is praised for its ease of use. Acunetix supports a range of environments, predominantly focusing on on-premises solutions with some cloud capabilities. Qualys is generally seen as responsive in customer service, though there's room for improved customer engagement. Acunetix provides comprehensive support but is noted for its complex initial setup and ongoing support challenges.
Pricing and ROI: Qualys WAS is perceived as costly compared to peers but offers a positive ROI due to its scalability and operational efficiencies, featuring flexible licensing options. Acunetix is noted for its higher price, with concerns over recent cost increases, though it provides a good ROI by automating security processes. Its pricing model based on targets or domains may be restrictive for some users, yet both tools ensure a comprehensive security feature set for their cost.
It saves a significant amount of time by covering attack surfaces.
I have seen a return on investment, as Acunetix helps reduce the man-days and effort needed for scanning bulk applications through automated assessments.
For high-severity issues, they reach out within two to three hours, and for critical issues, a response is received within 15 minutes.
The technical support from Invicti is very good and fast.
Support staff not being familiar with the problem.
They have various options in the vulnerability management process, and when we initially bought our license, we didn't realize we needed PCI for better results, which isn't included in the default configurations.
Once we purchase the license, we have access to top-notch support.
I have dealt with Qualys's technical support, and any enhancements are challenging.
Acunetix can handle increasing workloads and more applications easily.
My concern remains the lack of deep dive analysis and that it produces similar vulnerability results as other tools such as Nessus based on version checks instead of real impact checks.
It is licensed for assets, so we just contact the team for additional licenses if needed.
At one point, there was a limitation on reporting for 100,000 assets at a time.
The main concern is related to false positives; Acunetix needs to work on identifying valid and invalid findings.
I could supply it with maybe a Swagger file or a JSON file, and Acunetix would pick it up, scan all the endpoints according to the OWASP Top Ten, and give me remediation and actionable remediation reports.
Acunetix should have better integration with newer tools such as GitHub and Azure DevOps.
With the growing reliance on AI, Qualys Web Application Scanning should be updated to handle AI-based applications and LLM-based attacks.
Qualys Web Application Scanning does IP-level testing, requiring direct input of credentials, and can only scan a few pages to provide known generic vulnerabilities.
I would like it to be cheaper because it is a bit expensive compared to competitors like Tenable Nessus.
The pricing cost is affordable for small and mid-sized organizations, and when compared to Checkmarx, it is significantly affordable, as Checkmarx is quite expensive.
We secured a special licensing model for penetration testing companies, which is cost-effective.
The pricing of Acunetix is pretty expensive and could be improved.
They offer discounts on bulk licenses, making it cheaper compared to competitors like Veracode DAST.
I find it a bit expensive compared to other competitors.
Regarding pricing, I think for personal use, it is costly, but if organizations are ready to pay, then it is fine as they are using it.
Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.
The solution is excellent at detecting SQL injection and cross-site scripting vulnerabilities.
The best feature Acunetix offers is the centralized dashboard and the quality of reports it generates, which includes various options for selecting reports and developer options for directly sharing the reports with developers.
It effectively detects vulnerabilities like the OWASP Top 10 without any issues in reporting.
Credential scanning is very effective because it goes in-depth into the system, crawling the pages, and reporting on vulnerabilities.
Qualys Web Application Scanning is accurate and provides minimal false positives.
| Product | Mindshare (%) |
|---|---|
| Acunetix | 2.4% |
| Qualys Web Application Scanning | 1.8% |
| Other | 95.8% |


| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 7 |
| Large Enterprise | 19 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 6 |
| Large Enterprise | 27 |
Acunetix is a robust web application security testing tool offering rapid scanning, user-friendly interfaces, and accurate vulnerability detection with minimal false positives. It supports both cloud and on-premises deployment, making it versatile for various security needs.
Acunetix is distinguished by its capability to identify critical vulnerabilities such as cross-site scripting and SQL injection with high precision. It integrates seamlessly with CI/CD tools, supporting continuous scanning and large-scale application management. The centralized dashboard and detailed automated reporting streamline operations. Despite its benefits, users suggest improvements like reducing false positives, flexible pricing, and enhanced API scanning. Better integration with platforms like GitHub and Azure DevOps is sought, alongside more comprehensive customization and faster scanning. Mobile application scanning and improved team collaboration tools are also desired.
What features make Acunetix stand out?Acunetix is widely implemented across industries undertaking web application security assessments, including those requiring penetration testing and vulnerability assessment. It ensures applications meet security protocols and complies with standards while fitting into CI/CD workflows for secure pre-release checks.
Qualys Web Application Scanning offers advanced vulnerability management, progressive scheduling, and seamless integration with DevOps environments. Its user-friendly design enables enterprises to enhance security with comprehensive scanning and detailed forensic insights.
Qualys Web Application Scanning addresses enterprise-level security challenges by providing robust solutions for vulnerability management, penetration testing, and compliance checks. While easing the navigation process, it supports risk mitigation with precise risk ratings, minimal false positives, and detailed reporting. However, it faces challenges with its complex interface, authenticated scanning, and automation features. Integrating smoothly with CI/CD pipelines, it is suitable for continuous and automated scanning, adapting to diverse company requirements.
What are the standout features of Qualys Web Application Scanning?Organizations across sectors like education, banking, and international data centers leverage Qualys Web Application Scanning for conducting penetration testing, scanning web applications, and managing vulnerabilities. It aids in audit security and compliance, identifying threats, and generating user-friendly reports, making it a valuable asset for maintaining strong security postures.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.