

Acunetix and Invicti compete in the web application security testing space. Acunetix may have the upper hand with its continuous scanning and integration capabilities, but Invicti's proof-based scanning provides fewer false positives, giving it a precision edge.
Features: Acunetix offers continuous scanning, diverse deployment options, and seamless integration with CI/CD pipelines, enhancing security measures. Invicti features proof-based scanning, zero false positives, and comprehensive result mechanisms specific to identifying vulnerabilities, improving accuracy.
Room for Improvement: Acunetix could benefit from reducing false positives, strengthening API scanning, and lowering costs. Invicti needs to enhance scanning speed, improve licensing flexibility, and address cost-effectiveness concerning URL restrictions.
Ease of Deployment and Customer Service: Acunetix provides versatile deployment options with on-premises and cloud alternatives, backed by reliable customer support, though there can be delays. Invicti offers flexible deployment similar to Acunetix but may improve in terms of responsive technical support.
Pricing and ROI: Acunetix is often viewed as expensive, with possible hidden costs in its licensing model, yet it justifies its price through improved security and time efficiency. Invicti, while also costly, presents licensing flexibility and is suited for larger enterprises, providing positive ROI through better security outcomes and reduced manual effort.
| Product | Mindshare (%) |
|---|---|
| Acunetix | 2.6% |
| Invicti | 2.0% |
| Other | 95.4% |


| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 4 |
| Large Enterprise | 13 |
| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 7 |
| Large Enterprise | 19 |
Invicti offers advanced web application security testing focused on identifying vulnerabilities like SQL injection and cross-site scripting. Its Proof-Based Scanning minimizes false positives and integrates seamlessly with CI/CD pipelines, making it an effective tool for enterprise environments.
Invicti provides comprehensive scanning capabilities that include detecting and verifying critical vulnerabilities and security data consolidation. Its scalable scanning engine and robust API support allow for flexible testing across diverse environments, including web and API testing. Despite some drawbacks like limited single sign-on integration and slow scanning speeds for large applications, Invicti remains a popular choice for automating security assessments, ensuring compliance with standards like OWASP Top 10, PCI DSS, and GDPR.
What are the key features of Invicti?In industries like finance, healthcare, and e-commerce, Invicti is implemented to bolster security through automated vulnerability assessments. Its ability to provide insightful reports and remediation suggestions assists companies in efficiently managing security risks and achieving compliance with critical regulatory standards.
Acunetix is a robust web application security testing tool offering rapid scanning, user-friendly interfaces, and accurate vulnerability detection with minimal false positives. It supports both cloud and on-premises deployment, making it versatile for various security needs.
Acunetix is distinguished by its capability to identify critical vulnerabilities such as cross-site scripting and SQL injection with high precision. It integrates seamlessly with CI/CD tools, supporting continuous scanning and large-scale application management. The centralized dashboard and detailed automated reporting streamline operations. Despite its benefits, users suggest improvements like reducing false positives, flexible pricing, and enhanced API scanning. Better integration with platforms like GitHub and Azure DevOps is sought, alongside more comprehensive customization and faster scanning. Mobile application scanning and improved team collaboration tools are also desired.
What features make Acunetix stand out?Acunetix is widely implemented across industries undertaking web application security assessments, including those requiring penetration testing and vulnerability assessment. It ensures applications meet security protocols and complies with standards while fitting into CI/CD workflows for secure pre-release checks.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.