Try our new research platform with insights from 80,000+ expert users

Invicti vs NGINX App Protect comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Invicti
Ranking in API Security
6th
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
29
Ranking in other categories
Static Application Security Testing (SAST) (14th), Dynamic Application Security Testing (DAST) (4th)
NGINX App Protect
Ranking in API Security
3rd
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
24
Ranking in other categories
Web Application Firewall (WAF) (16th), Container Security (22nd)
 

Mindshare comparison

As of July 2025, in the API Security category, the mindshare of Invicti is 2.5%, up from 1.5% compared to the previous year. The mindshare of NGINX App Protect is 2.6%, down from 4.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
API Security
 

Featured Reviews

Kunal M - PeerSpot reviewer
Proactive scanning measures and realistic audit recommendations enhance development focus
Invicti's proactive scanning measures vulnerabilities each time we deploy or push code to a new environment. This feature helps us focus on priorities and prioritize the development team's effort, integrating seamlessly with DevOps to facilitate proactive scans of environments. Invicti also provides audit recommendations that are quite realistic, making it easy to discuss plans with developers.
Tomaz Sobczak - PeerSpot reviewer
Signature-based detection, DOS protection, and bot protection
NGINX App Protect is easier to automate and configure, or manage from an API. This is good for securing applications. However, it's not suitable for more complex tasks. NGINX App Protect positively impacted performance changes. There's a cache or it works like a proxy, so it can speed up applications. It can also offload some functions from servers, which NGINX can handle faster.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The scanner is light on the network and does not impact the network when scans are running."
"Crawling feature: Netsparker has very detail crawling steps and mechanisms. This feature expands the attack surface."
"It has very good integration with the CI/CD pipeline."
"The solution generates reports automatically and quickly."
"I would rate the stability as ten out of ten."
"Invicti's best feature is the ability to identify vulnerabilities and manually verify them."
"Its ability to crawl a web application is quite different than another similar scanner."
"This tool is really fast and the information that they provide on vulnerabilities is pretty good."
"NGINX App Protect is stable."
"Overall, I rate NGINX App Protect between eight and nine."
"The most valuable feature of NGINX App Protect is the reverse proxy."
"There's a cache, or it works like a proxy, so it can speed up applications."
"It has the best documentation features."
"The tool is not complex and is very user-friendly."
"The most valuable feature is that there is a link in the system that will help to analyze the security of an application when something abnormal is found."
"We were looking for a product that is capable of complete automation and a container based solution. It's working."
 

Cons

"They could enhance the support for data swap testing for the platform."
"The license could be better. It would help if they could allow us to scan multiple URLs on the same license. It's a major hindrance that we are facing while scanning applications, and we have to be sure that the URLs are the same and not different so that we do not end up consuming another license for it. Netsparker is one of the costliest products in the market. The licensing is tied to the URL, and it's restricted. If you have a URL that you scanned once, like a website, you cannot retry that same license. If you are scanning the same website but in a different domain or different URL, you might end up paying for a second license. It would also be better if they provided proper support for multi-factor authentications. In the next release, I would like them to include good multi-factor authentication support."
"Invicti's reporting capabilities need enhancement. We need enterprise-level information instead of repo-level details. Unlike Appiro, Invicti does not provide portfolio-level insights into vulnerability remediation over time."
"The support's response time could be faster since we are in different time zones."
"It would be better for listing and attacking Java-based web applications to exploit vulnerabilities."
"The higher level vulnerabilities like Cross-Site Scripting, SQL Injection, and other higher level injection attacks are difficult to highlight using Netsparker."
"The scanner itself should be improved because it is a little bit slow."
"Netsparker doesn't provide the source code of the static application security testing."
"As far as scalability, it takes a long time for deployment."
"The integration of NGINX App Protect could improve."
"NGINX App Protect could improve security."
"The solution needs to be improved in the e-commerce portal."
"NGINX App Protect would be improved with integration with Shape and F5 WAF, which would make it easy for users to manage all their web application security with a single solution."
"They could provide a better user interface."
"I encountered issues with NGINX App Protect while trying to upgrade custom rules."
"The setup of NGINX App Protect is complex. The full process took one week to complete. Additionally, we had to change the network infrastructure platform which took one month."
 

Pricing and Cost Advice

"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
"The price should be 20% lower"
"It is competitive in the security market."
"We never had any issues with the licensing; the price was within our assigned limits."
"OWASP Zap is free and it has live updates, so that's a big plus."
"There is a monthly or annual subscription to use NGINX App Protect. There are not any additional costs to the subscription."
"Really understand the licensing model, because we underestimated that."
"NGINX App Protect is expensive."
"The price of NGINX App Protect is not much different from the products that fall under the leader category of Gartner Magic Quadrant."
"The licensing fees for this solution are pretty expensive for what it does, but there is no alternative."
"There are not any additional costs we had to pay to use NGINX App Protect."
"The price of NGINX App Protect is approximately $3,000 annually. All of our licenses are observed by a managed service partner."
"The solution's price is reasonable."
report
Use our free recommendation engine to learn which API Security solutions are best for your needs.
860,168 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Financial Services Firm
14%
Computer Software Company
11%
Manufacturing Company
8%
Computer Software Company
17%
Financial Services Firm
14%
Comms Service Provider
9%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
As a technical user, I do not handle pricing or licensing, but I am aware that Invicti offers flexible licensing models based on organizational needs.
What do you like most about Invicti?
The most valuable feature of Invicti is getting baseline scanning and incremental scan.
What needs improvement with Invicti?
Invicti's reporting capabilities need enhancement. We need enterprise-level information instead of repo-level details. Unlike Appiro, Invicti does not provide portfolio-level insights into vulnerab...
What is your experience regarding pricing and costs for NGINX App Protect?
I don't know the pricing yet because in my other project, I was not part of the buying side and I was just starting to look at options.
What needs improvement with NGINX App Protect?
It would be better if it were easier to implement and if there was more information from F5 regarding hardware requirements and specifications to deploy the service, to avoid disruptions after impl...
 

Also Known As

Netsparker
NGINX WAF, NGINX Web Application Firewall
 

Overview

 

Sample Customers

Samsung, The Walt Disney Company, T-Systems, ING Bank
Information Not Available
Find out what your peers are saying about Invicti vs. NGINX App Protect and other solutions. Updated: June 2025.
860,168 professionals have used our research since 2012.