

OpenText Core Application Security and Invicti are key players in the application security category. OpenText stands out with its robust compliance features, while Invicti has an edge with its proof-based scanning and user-friendly interface.
Features: OpenText Core Application Security offers cloud-based on-demand testing, detailed vulnerability analysis, and integration with development platforms for SAST and DAST. Invicti features proof-based scanning, enhanced reporting capabilities, and an intuitive interface, which help in reducing false positives and managing vulnerabilities efficiently.
Room for Improvement: OpenText could improve its incident management integration and reporting capabilities for better visualization. Invicti might benefit from decreasing scan times, improving integration with other tools, and enhancing its API support.
Ease of Deployment and Customer Service: OpenText supports on-premises, public, and hybrid cloud deployments but faces customer service challenges with response times. Invicti offers similar deployment options and receives favorable feedback for its responsive support teams, despite some technical issue resolution needs.
Pricing and ROI: OpenText's pricing may be high for smaller organizations, though it is justified for enterprises seeking comprehensive security. Invicti's pricing is competitive for larger enterprises with flexible options, promising significant ROI through enhanced security and risk management.
| Product | Market Share (%) |
|---|---|
| Invicti | 1.5% |
| OpenText Core Application Security | 3.1% |
| Other | 95.4% |


| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 4 |
| Large Enterprise | 13 |
| Company Size | Count |
|---|---|
| Small Business | 17 |
| Midsize Enterprise | 8 |
| Large Enterprise | 44 |
Invicti helps DevSecOps teams automate security tasks and save hundreds of hours each month by identifying web vulnerabilities that matter. Combining dynamic with interactive testing (DAST + IAST) and software composition analysis (SCA), Invicti scans every corner of an app to find what other tools miss with 99.98% accuracy, delivering on the promise of Zero Noise AppSec. Invicti helps discover all web assets — even ones that are lost, forgotten, or created by rogue departments. With an array of out-of-the-box integrations, DevSecOps teams can get ahead of their workloads to hit critical deadlines, improve processes, and communicate more effectively while reducing risk and hitting the ROI goals.
OpenText Core Application Security offers robust features like static and dynamic scanning, real-time vulnerability tracking, and seamless integration with development platforms, designed to enhance code security and reduce operational costs.
OpenText Core Application Security is a cloud-based, on-demand service providing accurate and deep scanning capabilities with detailed reporting. Its integrations with development platforms ensure an enhanced security layer in the development lifecycle, benefiting users by lowering operational costs and facilitating efficient remediation. The platform addresses needs for intuitive interfaces, API support, and comprehensive vulnerability assessments, helping improve code security and accelerate time-to-market. Despite its strengths, challenges exist around false positives, report clarity, and language support, alongside confusing pricing and package options. Enhancements are sought in areas like CI/CD pipeline configuration, report visualization, scan times, and integration with third-party tools such as GitLab, container scanning, and software composition analysis.
What features define OpenText Core Application Security?Industries like mobile applications, e-commerce, and banking leverage OpenText Core Application Security for its ability to identify vulnerabilities such as SQL injections. Integrating seamlessly with DevSecOps and security auditing processes, this tool supports developers in writing safer code, ensuring secure application deployment and enhancing software assurance.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.