We performed a comparison between Invicti and SonarQube based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."When we try to manually exploit the vulnerabilities, it often takes time to realize what's going on and what needs to be done."
"The dashboard is really cool, and the features are really good. It tells you about the software version you're using in your web application. It gives you the entire technology stack, and that really helps. Both web and desktop apps are good in terms of application scanning. It has a lot of security checks that are easily customizable as per your requirements. It also has good customer support."
"High level of accuracy and quick scanning."
"I am impressed with Invictus’ proof-based scanning. The solution has reduced the incidence of false positive vulnerabilities. It has helped us reduce our time and focus on vulnerabilities."
"It correctly parses DOM and JS and has really good support for URL Rewrite rules, which is important for today's websites."
"The scanner is light on the network and does not impact the network when scans are running."
"The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports."
"One of the features I like about this program is the low number of false positives and the support it offers."
"The solution is stable."
"SonarQube is good in terms of code review and to report on basic vulnerabilities in your applications."
"The solution can verify vulnerabilities, code smells, and hotspots. It makes the software more secure and it helps make a junior or novice developer sharper."
"The features of SonarQube that I find most valuable for identifying code smells are its comprehensive code analysis capabilities, which cover various aspects of code sustainability."
"It is a very good tool for analysis and security vulnerability checking."
"It assists during the development with SonarLint and helps the developer to change his approach or rather improve his coding pattern or style. That's one advantage I've seen. Another advantage is that we can customize the rules."
"It provides you with many features, as it does with the premium model, but there are still extra features that can be purchased if needed."
"We are using the Community edition. So, we don't have to incur any licensing costs. This is the best part."
"Reporting should be improved. The reporting options should be made better for end-users. Currently, it is possible, but it's not the best. Being able to choose what I want to see in my reports rather than being given prefixed information would make my life easier. I had to depend on the API for getting the content that I wanted. If they could fix the reporting feature to make it more comprehensive and user-friendly, it would help a lot of end-users. Everything else was good about this product."
"The scanning time, complexity, and authentication features of Invicti could be improved."
"Netsparker doesn't provide the source code of the static application security testing."
"The custom attack preparation screen might be improved."
"The support's response time could be faster since we are in different time zones."
"Invicti takes too long with big applications, and there are issues with the login portal."
"Asset scanning could be better. Once, it couldn't scan assets, and the issue was strange. The price doesn't fit the budget of small and medium-sized businesses."
"Maybe the ability to make a good reporting format is needed."
"I don't believe you can have metrics of code quality based upon code analysis. I don't think it's possible for a computer to do it."
"There could be better integration with other products."
"It would be a great add-on if SonarQube could update its database for vulnerabilities or plugging parts."
"The product's pricing could be lower."
"I would like to see SonarQube implement a good amount of improvements to the product's security features. Another aspect of SonarQube that could be improved is the search functionality."
"A little bit more emphasis on security and a bit more security scanning features would be nice."
"Expression of common vulnerabilities and exposures is not always current."
"Ease of use/interface."
Invicti is ranked 20th in Application Security Tools with 25 reviews while SonarQube is ranked 1st in Application Security Tools with 108 reviews. Invicti is rated 8.2, while SonarQube is rated 8.0. The top reviewer of Invicti writes "A customizable security testing solution with good tech support, but the price could be better". On the other hand, the top reviewer of SonarQube writes "Easy to integrate and has a plug-in that supports both C and C++ languages". Invicti is most compared with OWASP Zap, Acunetix, PortSwigger Burp Suite Professional, Tenable.io Web Application Scanning and Synopsys Defensics, whereas SonarQube is most compared with Checkmarx One, SonarCloud, Coverity, Veracode and Snyk. See our Invicti vs. SonarQube report.
See our list of best Application Security Tools vendors and best Application Security Testing (AST) vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.