Try our new research platform with insights from 80,000+ expert users

Invicti vs NGINX App Protect comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Invicti
Ranking in API Security
6th
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
29
Ranking in other categories
Static Application Security Testing (SAST) (15th), Dynamic Application Security Testing (DAST) (3rd)
NGINX App Protect
Ranking in API Security
2nd
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
24
Ranking in other categories
Web Application Firewall (WAF) (15th), Container Security (17th)
 

Mindshare comparison

As of May 2025, in the API Security category, the mindshare of Invicti is 2.3%, up from 2.0% compared to the previous year. The mindshare of NGINX App Protect is 2.9%, down from 5.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
API Security
 

Featured Reviews

Kunal M - PeerSpot reviewer
Proactive scanning measures and realistic audit recommendations enhance development focus
Invicti's proactive scanning measures vulnerabilities each time we deploy or push code to a new environment. This feature helps us focus on priorities and prioritize the development team's effort, integrating seamlessly with DevOps to facilitate proactive scans of environments. Invicti also provides audit recommendations that are quite realistic, making it easy to discuss plans with developers.
Saurav Kumar - PeerSpot reviewer
Offers protection to users from external threats
NGINX App Protect secures our company's application, and it has helped me a lot, considering that we have critical infrastructure in India where we see how lots of attacks come onto our organization's servers. The tool offers protection against multiple threats present in India's IT ecosystem. The tool helps our company to make our payments secure, meaning it has the ability to provide a secure payment environment in India. Speaking about the improvements in our company's application performance since implementing NGINX App Protect, the gRPC support for the solution is very low. My company is not getting any proper documentation on how to deploy gRPC over NGINX App Protect. I recommend the product to those who plan to use it. People can use the product as their company's base server, WAF, or for its proxy manager, depending on the business requirements. My company follows PCI DSS compliance because we operate in a payment-related industry. Right now, my company follows all the standards, so we comply with all the requirements and policies. I rate the tool an eight out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports."
"Scan, proxify the application, and then detailed report along with evidence and remediations to problems."
"I would rate the stability as ten out of ten."
"Attacking feature: Actually, attacking is not a solo feature. It contains many attack engines, Hawk, and many properties. But Netsparker's attacking mechanism is very flexible. This increases the vulnerability detection rate. Also, Netsparker made the Hawk for real-time interactive command-line-based exploit testing. It's very valuable for a vulnerability scanner."
"The scanner is light on the network and does not impact the network when scans are running."
"It has very good integration with the CI/CD pipeline."
"I am impressed by the whole technology that they are using in this solution. It is really fast. When using netscan, the confirmation that it gives on the vulnerabilities is pretty cool. It is really easy to configure a scan in Netsparker Web Application Security Scanner. It is also really easy to deploy."
"It correctly parses DOM and JS and has really good support for URL Rewrite rules, which is important for today's websites."
"The tool is not complex and is very user-friendly."
"Overall, I rate NGINX App Protect between eight and nine."
"The stability of the product is very impressive since it handles 60,000 to 70,000 requests or transactions per second."
"The most valuable feature of NGINX App Protect is its flexibility."
"The initial setup was simple and took three to four days."
"The most valuable feature of NGINX App Protect is its open source."
"It is a stable solution."
"The tool's most valuable feature is the OWASP certification. Additionally, the tool's ability to enforce strong passwords and OTP within minutes is impressive. With its analytics and recommendations, it is a very good solution."
 

Cons

"It would be better for listing and attacking Java-based web applications to exploit vulnerabilities."
"I think that it freezes without any specific reason at times. This needs to be looked into."
"Invicti's reporting capabilities need enhancement."
"The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them."
"Maybe the ability to make a good reporting format is needed."
"They need to improve their support in the documentation. Their support mechanism is missing. Their responsiveness, technical staff, and these types of things need to be improved, and comprehensive documentation is required. They should have good self-service portal enhancement"
"They don't really provide the proof of concept up to the level that we need in our organization. We are a consultancy firm, and we provide consultancy for the implementation and deployment solutions to our customers. When you run the scans and the scan is completed, it only shows the proof of exploit, which really doesn't work because the tool is running the scan and exploiting on the read-only form. You don't really know whether it is actually giving the proof of exploit. We cannot prove it manually to a customer that the exploit is genuine. It is really hard to perform it manually and prove it to the concerned development, remediation, and security teams. It is currently missing the static application security part of the application security, especially web application security. It would be really cool if they can integrate a SAS tool with their dynamic one."
"The higher level vulnerabilities like Cross-Site Scripting, SQL Injection, and other higher level injection attacks are difficult to highlight using Netsparker."
"The dashboard could provide a more comprehensive view of the status of the connections."
"The solution needs to be improved in the e-commerce portal."
"The product's user interface is an area with shortcomings as it can be quite confusing for users, making it an area where improvements are required."
"Right now, the tool doesn't provide an option revolving around update feeds, specifically the signature update option in the UI."
"The setup of NGINX App Protect is complex. The full process took one week to complete. Additionally, we had to change the network infrastructure platform which took one month."
"The configuration needs to be more flexible because it is difficult to do things that are outside of the ordinary."
"It would be better if it were easier to implement and if there was more information from F5 regarding hardware requirements and specifications to deploy the service, to avoid disruptions after implementation."
"It doesn't have more advanced features like no false-positive security, which you can configure in Advanced WAF."
 

Pricing and Cost Advice

"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"We never had any issues with the licensing; the price was within our assigned limits."
"The price should be 20% lower"
"The solution is very expensive. It comes with a yearly subscription. We were paying 6000 dollars yearly for unlimited scans. We have three licenses; basic, business, and ultimate. We need ultimate because it has unlimited scan numbers."
"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
"It is competitive in the security market."
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
"OWASP Zap is free and it has live updates, so that's a big plus."
"The product's price is high."
"NGINX App Protect is expensive."
"There is a monthly or annual subscription to use NGINX App Protect. There are not any additional costs to the subscription."
"The price of NGINX App Protect is not much different from the products that fall under the leader category of Gartner Magic Quadrant."
"The solution's price is reasonable."
"Our licensing costs are about $40,000 a year."
"The licensing fees for this solution are pretty expensive for what it does, but there is no alternative."
"The price of NGINX App Protect is approximately $3,000 annually. All of our licenses are observed by a managed service partner."
report
Use our free recommendation engine to learn which API Security solutions are best for your needs.
851,471 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
46%
Financial Services Firm
11%
Computer Software Company
8%
Manufacturing Company
6%
Computer Software Company
18%
Financial Services Firm
14%
Comms Service Provider
9%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
As a technical user, I do not handle pricing or licensing, but I am aware that Invicti offers flexible licensing models based on organizational needs.
What do you like most about Invicti?
The most valuable feature of Invicti is getting baseline scanning and incremental scan.
What needs improvement with Invicti?
Invicti's reporting capabilities need enhancement. We need enterprise-level information instead of repo-level details. Unlike Appiro, Invicti does not provide portfolio-level insights into vulnerab...
What is your experience regarding pricing and costs for NGINX App Protect?
I don't know the pricing yet because in my other project, I was not part of the buying side and I was just starting to look at options.
What needs improvement with NGINX App Protect?
It would be better if it were easier to implement and if there was more information from F5 regarding hardware requirements and specifications to deploy the service, to avoid disruptions after impl...
 

Also Known As

Netsparker
NGINX WAF, NGINX Web Application Firewall
 

Overview

 

Sample Customers

Samsung, The Walt Disney Company, T-Systems, ING Bank
Information Not Available
Find out what your peers are saying about Invicti vs. NGINX App Protect and other solutions. Updated: April 2025.
851,471 professionals have used our research since 2012.