No more typing reviews! Try our Samantha, our new voice AI agent.

Invicti vs Link11 comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 18, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Invicti
Ranking in API Security
10th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
31
Ranking in other categories
Static Application Security Testing (SAST) (11th), Container Security (24th), Software Composition Analysis (SCA) (10th), Dynamic Application Security Testing (DAST) (4th), Application Security Posture Management (ASPM) (9th)
Link11
Ranking in API Security
23rd
Average Rating
8.8
Reviews Sentiment
7.4
Number of Reviews
10
Ranking in other categories
CDN (19th), Web Application Firewall (WAF) (35th), Distributed Denial-of-Service (DDoS) Protection (23rd), Bot Management (10th)
 

Mindshare comparison

As of August 2026, in the API Security category, the mindshare of Invicti is 4.0%, up from 2.5% compared to the previous year. The mindshare of Link11 is 3.3%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
API Security Mindshare Distribution
ProductMindshare (%)
Invicti4.0%
Link113.3%
Other92.7%
API Security
 

Featured Reviews

PrashantUppuluri - PeerSpot reviewer
Solution Architect at a tech services company with 51-200 employees
Automated scanning has strengthened web application security and supports hybrid protection
A good scanning engine is what I appreciate about Invicti. When you want to find out the vulnerabilities within your web applications, Invicti has done a thorough job with respect to filtering out the vulnerabilities and identifying the risk factors with respect to the security modules within the solution. Invicti does have a segment of the solution which works on the automated scanning engine. As long as the license is active, the scanners that work within the solution are pretty effective. With respect to SAST and DAST, being a real-time scanning engine is one of the portfolios and one of the selling factors of the solution. Invicti is known to be a solution that works within the hybrid environment, be it cloud, on-premises, or a mix and match across multiple marketplaces. It does a thorough job. Most importantly, Invicti is a very good SAST and DAST solution that is very competitive in the market with respect to competitors. Invicti is a part of the Magic Quadrant with respect to Gartner's Magic Quadrant and has made a very good customer database and pipeline within the marketplace locally. With respect to security impacts in terms of support, Invicti is pretty much supportive. With respect to use cases or the POCs I have run on the solution, we have identified a couple of vulnerabilities and Invicti was able to trace them, detect, and quarantine the attacks.
PF
Chief Architect (Consultant) at Personal Consultant
Exceptional resilience and protection well-suited for medium to large businesses
The initial setup process is quite straightforward. Its complexity largely depends on the intricacies of your platform. If your platform spans multiple sites across the globe, requiring configuration of multiple instances and traffic routing, it can become more intricate. From our experience, even in companies with extensive platforms, the configuration process remains relatively simple. Once the instances are spun up and the initial configurations are in place, you can use their console application to set up your site or sites for traffic management. This involves configuring the sites and uploading SSL certificates. Even for those not well-versed in the intricacies of networking layers and rules, the out-of-the-box configurations already provide solid protection.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Netsparker has valuable features, including the ability to scan our website, an interactive approach, and security data integration."
"Netsparker provides a more interactive interface that is more appealing."
"High level of accuracy and quick scanning."
"Invicti's best feature is the ability to identify vulnerabilities and manually verify them."
"I would tell potential users that it's really one of the best products in the market for web application security or Dynamic Application Security Testing (DAST)."
"I am impressed with Invictus’ proof-based scanning. The solution has reduced the incidence of false positive vulnerabilities. It has helped us reduce our time and focus on vulnerabilities."
"Netsparker offers some pretty features: Crawling feature: Netsparker has very detail crawling steps and mechanisms, this feature expands the attack surface, Attacking feature: Actually, attacking is not a solo feature, it contains many attack engines, Hawk, and many properties, but Netsparker's attacking mechanism is very flexible, this increases the vulnerability detection rate, also, Netsparker made the Hawk for real-time interactive command-line-based exploit testing, it's very valuable for a vulnerability scanner, and a very useful API for automating the scans."
"The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports."
"The technical support is quite good, as soon as you have an issue you call or send an email and they respond very quickly, and they also provide you with contact details of the CEO."
"The real-time monitoring and reporting are very good. There are information updates in their portal every two minutes. They also have the ability to spill it into Sumo Logic, for example. It's very easy to use."
"Reblaze has saved us money by optimizing server usage and blocking malicious bots."
"The main feature is using the rules and being able to see the traffic. It helps us find malicious traffic."
"We like the website protection, it's really good, and the dashboard is really simple to use."
"The feature I find most valuable is the user-friendly dashboard, as it is easy to understand how everything works and it allows you to make decisions quickly and efficiently."
"The best thing about Reblaze, for us, is that it has been a game changer because previously, we were using Google's Web Application Firewall, but it wasn't up to the mark."
"Provides mobile app security."
 

Cons

"The licensing model should be improved to be more cost-effective. There are URL restrictions that consume our license. Compared to other DAST solutions and task tools like WebInspect and Burp Enterprise, Invicti is very expensive. The solution’s scanning time is also very long compared to other DAST tools. It might be due to proof-based scanning."
"It is a good tool, as we found out with the Community Edition trial, but the price point is quite expensive for a startup or average-sized company."
"Speed: It spends about one hour on scanning; I would like it to be less than 30 minutes."
"They don't really provide the proof of concept up to the level that we need in our organization. We are a consultancy firm, and we provide consultancy for the implementation and deployment solutions to our customers. When you run the scans and the scan is completed, it only shows the proof of exploit, which really doesn't work because the tool is running the scan and exploiting on the read-only form. You don't really know whether it is actually giving the proof of exploit. We cannot prove it manually to a customer that the exploit is genuine. It is really hard to perform it manually and prove it to the concerned development, remediation, and security teams. It is currently missing the static application security part of the application security, especially web application security. It would be really cool if they can integrate a SAS tool with their dynamic one."
"Perhaps the custom attack preparation screen might be improved."
"The license could be better. It would help if they could allow us to scan multiple URLs on the same license. It's a major hindrance that we are facing while scanning applications, and we have to be sure that the URLs are the same and not different so that we do not end up consuming another license for it. Netsparker is one of the costliest products in the market. The licensing is tied to the URL, and it's restricted. If you have a URL that you scanned once, like a website, you cannot retry that same license. If you are scanning the same website but in a different domain or different URL, you might end up paying for a second license. It would also be better if they provided proper support for multi-factor authentications. In the next release, I would like them to include good multi-factor authentication support."
"The scanner itself should be improved because it is a little bit slow."
"When scanning a large web-based application, it tends to process slow and takes a long time especially on crawling and attacking part."
"Up to now the only cons I could find is sometimes getting change management back on track, because it's a company that evolves, and sometimes I don't have the same needs that they have. But besides that, up until now, I am really pleased with their service and I've also recommended them to some of my clients."
"The WAF features are not as granular as we would expect from a WAF system. There should be more granularity and in-depth rules, out-of-the-box."
"The interface on the dashboard could be improved. Some of the settings are confusing which makes things difficult when you're trying to get a handle on the product."
"It would be beneficial if it had a workflow or a feature that could fine-tune settings based on high-level requirements."
"They have an interface that you have to adjust to. That is a bit of a downfall because I expect an interface to be very intuitive for someone who knows little about security. But if you know about security, the interface is wonderful."
"There is room for improvement in helping us understand session management."
"We have multiple products behind different instances of Reblaze. We have one instance for staging and then we have a production instance for multiple products. One of the things that we have requested is a unified view panel, so that we can see each of the instances in a unified view. That way, we won't have to go bouncing from instance to instance."
"The next release should have next-generation automation."
 

Pricing and Cost Advice

"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
"It is competitive in the security market."
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
"The solution is very expensive. It comes with a yearly subscription. We were paying 6000 dollars yearly for unlimited scans. We have three licenses; basic, business, and ultimate. We need ultimate because it has unlimited scan numbers."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"OWASP Zap is free and it has live updates, so that's a big plus."
"The price should be 20% lower"
"We never had any issues with the licensing; the price was within our assigned limits."
"I believe that for the six instances we have right now, it's costing us $16,000 per month."
"On a monthly basis we pay $750."
"We found the cost to be a bit on the higher side, starting at approximately three to four thousand dollars for a small configuration."
"There is still some room for improvement when it comes to bot management from Reblaze because they are relatively new compared to other vendors in the town."
report
Use our free recommendation engine to learn which API Security solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Manufacturing Company
9%
Construction Company
8%
Government
7%
Financial Services Firm
14%
Construction Company
12%
Comms Service Provider
12%
Educational Organization
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise4
Large Enterprise13
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise2
 

Questions from the Community

What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
The setup cost is pretty competitive. For example, if you want to talk about the SAST license, it comes to about $150 or sometimes less than $100, depending on the conversion or the number of licen...
What needs improvement with Invicti?
At this time, there is nothing that comes to mind. However, most of the products in the market are pretty much neck-to-neck competitors. Speaking about it, there are a couple of factors which they ...
What is your primary use case for Invicti?
I have worked on a couple of products, specifically in web application security. I have worked on Invicti, and with respect to PAM, I have worked with BeyondTrust. I have not worked specifically fo...
Ask a question
Earn 20 points
 

Comparisons

 

Also Known As

Netsparker
Reblaze
 

Overview

 

Sample Customers

Samsung, The Walt Disney Company, T-Systems, ING Bank
CBC, Hermes, Gartner
Find out what your peers are saying about Invicti vs. Link11 and other solutions. Updated: June 2026.
909,725 professionals have used our research since 2012.