Try our new research platform with insights from 80,000+ expert users

Invicti vs Rapid7 InsightAppSec comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Invicti
Ranking in Dynamic Application Security Testing (DAST)
3rd
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
29
Ranking in other categories
Static Application Security Testing (SAST) (15th), API Security (5th)
Rapid7 InsightAppSec
Ranking in Dynamic Application Security Testing (DAST)
4th
Average Rating
8.2
Reviews Sentiment
7.7
Number of Reviews
18
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Dynamic Application Security Testing (DAST) category, the mindshare of Invicti is 13.9%, down from 14.7% compared to the previous year. The mindshare of Rapid7 InsightAppSec is 12.0%, down from 13.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Kunal M - PeerSpot reviewer
Proactive scanning measures and realistic audit recommendations enhance development focus
Invicti's proactive scanning measures vulnerabilities each time we deploy or push code to a new environment. This feature helps us focus on priorities and prioritize the development team's effort, integrating seamlessly with DevOps to facilitate proactive scans of environments. Invicti also provides audit recommendations that are quite realistic, making it easy to discuss plans with developers.
Krzysztof Witko - PeerSpot reviewer
Automated authorization streamlines security processes
The previous product, AppSpyder, had a virtual patching module where we could generate patches for third-party web application firewalls, such as Imperva or F5. Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version. Virtual patching could help protect web pages shortly after finishing the scan process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the features I like about this program is the low number of false positives and the support it offers."
"I like that it's stable and technical support is great."
"The dashboard is really cool, and the features are really good. It tells you about the software version you're using in your web application. It gives you the entire technology stack, and that really helps. Both web and desktop apps are good in terms of application scanning. It has a lot of security checks that are easily customizable as per your requirements. It also has good customer support."
"The most valuable feature of Invicti is getting baseline scanning and incremental scan."
"Its ability to crawl a web application is quite different than another similar scanner."
"Invicti is a good product, and its API testing is also good."
"Scan, proxify the application, and then detailed report along with evidence and remediations to problems."
"High level of accuracy and quick scanning."
"The product’s most valuable feature is UI. It is easy to manage and find vulnerabilities in the application."
"The automatic automation of the automated authorization to the SCANNET environment is valuable."
"It's very easy to use and user-friendly. It does the job."
"It uses a signature-based method to check for problems with your code and will provide an alert if anything is found."
"The most valuable feature of this solution is the graphical interface."
"Rapid7 InsightAppSec helps us in both regulatory compliance and in strengthening our security posture."
"We have seen measurable decrease in the mean time to respond to threats by 20 percent."
"The templates feature is very easy. You just choose the kind of attack you want on your web application, and you run it against that template and receive a report. It's great."
 

Cons

"Maybe the ability to make a good reporting format is needed."
"The scanner itself should be improved because it is a little bit slow."
"Right now, they are missing the static application security part, especially web application security."
"Currently, there is nothing I would like to improve."
"The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them."
"Asset scanning could be better. Once, it couldn't scan assets, and the issue was strange. The price doesn't fit the budget of small and medium-sized businesses."
"The custom attack preparation screen might be improved."
"The scanning time, complexity, and authentication features of Invicti could be improved."
"The product’s pricing could be flexible."
"I required a solution to manage on-premises, but I was not as satisfied as expected."
"I would like more details of what the product can do."
"The interface should be a little bit easier to manage. Sometimes, the logic that they use is kind of strange. They need to work a little bit more on their interface to make it more understandable. The interface is the only problem. I'm using Rapid7, which is very intuitive. There are other applications available in the market with a better interface. They can include more techniques or options to test different types of security because the templates are limited. It would be great to see them follow the MITRE ATT&CK framework or what is there in tools like Veracode and Synopsys."
"Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version."
"They should add more features. I would like to see them do a little more on static analysis and also interactivity analysis. Currently, it does very basic static analysis. It could do a little more static analysis, which is something that would help. A lot more interactivity analysis should also be there. It should basically look at security during interactivity."
"The reporting feature of Rapid7 InsightAppSec needs improvement as it currently provides basic reports."
"The dynamic scanning feature has simplified and improved the security testing process. I suggest adding a SaaS feature to the solution to support scanning SaaS applications, making it more comprehensive. It would be beneficial if the solution could also scan mobile applications. It only scans web applications and should also cover mobile applications, including firmware recommendations."
 

Pricing and Cost Advice

"The price should be 20% lower"
"It is competitive in the security market."
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
"OWASP Zap is free and it has live updates, so that's a big plus."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"We never had any issues with the licensing; the price was within our assigned limits."
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
"The price of this product is very cheap."
"I rate Rapid7 InsightAppSec’s pricing an eight out of ten."
"They offer a good price, but I don't remember its cost. It is fair as compared to the competition. We have opted for project-based licensing, not user-based. We can add any number of users. That doesn't matter. It is worth the money."
"Rapid7 InsightAppSec is cheap."
"Its price is competitive. It is not expensive."
"I'm not sure how much it costs exactly, but I know it's expensive."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
849,686 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
47%
Financial Services Firm
10%
Computer Software Company
7%
Manufacturing Company
5%
Computer Software Company
16%
Financial Services Firm
15%
Manufacturing Company
11%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
As a technical user, I do not handle pricing or licensing, but I am aware that Invicti offers flexible licensing models based on organizational needs.
What do you like most about Invicti?
The most valuable feature of Invicti is getting baseline scanning and incremental scan.
What needs improvement with Invicti?
Invicti's reporting capabilities need enhancement. We need enterprise-level information instead of repo-level details. Unlike Appiro, Invicti does not provide portfolio-level insights into vulnerab...
What do you like most about Rapid7 InsightAppSec?
In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to p...
What needs improvement with Rapid7 InsightAppSec?
Currently, I do not see any specific areas for improvement except for possibly lowering the price.
What is your primary use case for Rapid7 InsightAppSec?
I use Rapid7 InsightAppSec ( /products/rapid7-insightappsec-reviews ) for dynamic application security testing. My main focus is on the quality of detection, specifically detecting vulnerabilities ...
 

Also Known As

Netsparker
InsightAppSec
 

Overview

 

Sample Customers

Samsung, The Walt Disney Company, T-Systems, ING Bank
CenterPoint Energy, CPA Australia, Hypertherm, First American Financial Corporation, Rackspace
Find out what your peers are saying about Invicti vs. Rapid7 InsightAppSec and other solutions. Updated: April 2025.
849,686 professionals have used our research since 2012.