Try our new research platform with insights from 80,000+ expert users
JoelGeorge - PeerSpot reviewer
Associate at Tata Consultancy
Real User
A comprehensive solution for all of your security testing needs
Pros and Cons
  • "It has a comprehensive resulting mechanism. It is a one-stop solution for all your security testing mechanisms."
  • "Reporting should be improved. The reporting options should be made better for end-users. Currently, it is possible, but it's not the best. Being able to choose what I want to see in my reports rather than being given prefixed information would make my life easier. I had to depend on the API for getting the content that I wanted. If they could fix the reporting feature to make it more comprehensive and user-friendly, it would help a lot of end-users. Everything else was good about this product."

What is most valuable?

It has a comprehensive resulting mechanism. It is a one-stop solution for all your security testing mechanisms.

What needs improvement?

Reporting should be improved. The reporting options should be made better for end-users. Currently, it is possible, but it's not the best. Being able to choose what I want to see in my reports rather than being given prefixed information would make my life easier. I had to depend on the API for getting the content that I wanted. If they could fix the reporting feature to make it more comprehensive and user-friendly, it would help a lot of end-users. Everything else was good about this product.

For how long have I used the solution?

I used this solution for around 16 months. We were using its latest version. 

It was a cloud deployment. It was an internal cloud. The company bought the cloud version and then hosted it internally.

What do I think about the stability of the solution?

It's good. I believe it went down only once in 16 months. It never had any other problem.

Buyer's Guide
Invicti
June 2025
Learn what your peers think about Invicti. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.

How are customer service and support?

Their support was good. They were quite prompt with their responses. When we had any issues, we reached out, and they did respond quickly.

How was the initial setup?

It was done by my company's IT team, and I was not involved in that.

What about the implementation team?

We basically had them implement it in-house for us. So, it was done in-house, but it was done by Netsparker's team. It was not done by our team.

In terms of maintenance, it was being managed by a team, but I don't know how many people were managing it in that team.

What other advice do I have?

It is a very good tool. It has an API segment that makes up for the lack of reporting options. You can execute commands on Netsparker by using your command-line interface. By using the API, you will be able to get the kind of information that you are looking for. It'll help you in getting the results that you want.

I would rate it an eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Information Security Engineer at Tübitak Bilgem
Real User
Top 5Leaderboard
Has robust automation features with an efficient ability to detect vulnerabilities
Pros and Cons
  • "The platform is stable."
  • "They could enhance the support for data swap testing for the platform."

What is our primary use case?

My primary use of Invicti revolves around supporting my vulnerability testing efforts. As part of my role in overseeing security for various companies, Invicti aids in generating reports to bolster security measures.

What is most valuable?

I find the product's zero false positive feature quite valuable, as does its array of authentication options, which provide flexibility in testing various web applications.

What needs improvement?

They could enhance the support for data swap testing for the platform. 

For how long have I used the solution?

I've been utilizing Invicti for approximately three years now.

What do I think about the stability of the solution?

The platform is stable.

How are customer service and support?

The technical support services are good. 

Which solution did I use previously and why did I switch?

Invicti's robust authentication options stand out as a significant advantage compared to other solutions.

What other advice do I have?

The product plays a crucial role in our organization's security posture by identifying vulnerabilities. Once I deliver my reports, the identified issues are promptly addressed, significantly improving our overall security stance.

The automation capabilities streamline our security testing processes, especially concerning web application authentication. It ensures compatibility with different authentication solutions, facilitating automatic testing.

I value the robust reporting capabilities. The diverse range of report options allows for detailed insights, which assists in effectively addressing security issues.

I would recommend Invicti to others and rate it a nine. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Invicti
June 2025
Learn what your peers think about Invicti. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
UmeshKumar2 - PeerSpot reviewer
Senior System Administrator at a tech vendor with 10,001+ employees
Real User
Excellent solution for identifying and verifying vulnerabilities
Pros and Cons
  • "Invicti's best feature is the ability to identify vulnerabilities and manually verify them."
  • "Invicti takes too long with big applications, and there are issues with the login portal."

What is our primary use case?

I primarily use Invicti for onboarding on the performance side.

What is most valuable?

Invicti's best feature is the ability to identify vulnerabilities and manually verify them.

What needs improvement?

Invicti takes too long with big applications, and there are issues with the login portal.

For how long have I used the solution?

I've been using Invicti for four to five years.

What do I think about the stability of the solution?

Invicti sometimes stops working when dealing with large applications.

How was the initial setup?

The initial setup was easy.

What other advice do I have?

I would give Invicti a rating of nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PrashantPatil - PeerSpot reviewer
Senior Security Consultant at Verve Square Technologies
Consultant
Great active and passive scanning, and reports are generated automatically
Pros and Cons
  • "The solution generates reports automatically and quickly."
  • "The scannings are not sufficiently updated."

What is our primary use case?

We use this product for vulnerability assessment and penetration testing of any web application in addition to API testing. The solution generates reports for us. I'm a security consultant and we are end-users. 

What is most valuable?

The solution generates reports automatically and quickly and it's a very user-friendly product. I like the active and passive scanning, which is a good feature from my perspective.

What needs improvement?

I find that the scannings are not sufficiently updated. 

For how long have I used the solution?

I've been using this solution for four years. 

What do I think about the stability of the solution?

The stability is good, up to the mark. 

What do I think about the scalability of the solution?

The scalability is good and we're likely going to increase usage of Netsparker. 

How are customer service and support?

We contact technical support all the time and they are great. They resolve issues quickly and efficiently. 

Which solution did I use previously and why did I switch?

We also use Burp Suite which is a UI-based tool that I also find to be user-friendly. We use both products so that in the case of false positives we can compare and verify. 

How was the initial setup?

The initial setup is straightforward and the solution doesn't require any maintenance. We currently have 15 users and that number is likely to expand to around 20 in the near future. 

What's my experience with pricing, setup cost, and licensing?

The pricing of the license is compatible with our budget. 

What other advice do I have?

I highly recommend Netsparker and rate it eight out of 10. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1286490 - PeerSpot reviewer
Consultant Cyber Security at a tech services company with 51-200 employees
Consultant
A fast solution that is easy to deploy, configure, and use
Pros and Cons
  • "I am impressed by the whole technology that they are using in this solution. It is really fast. When using netscan, the confirmation that it gives on the vulnerabilities is pretty cool. It is really easy to configure a scan in Netsparker Web Application Security Scanner. It is also really easy to deploy."
  • "They don't really provide the proof of concept up to the level that we need in our organization. We are a consultancy firm, and we provide consultancy for the implementation and deployment solutions to our customers. When you run the scans and the scan is completed, it only shows the proof of exploit, which really doesn't work because the tool is running the scan and exploiting on the read-only form. You don't really know whether it is actually giving the proof of exploit. We cannot prove it manually to a customer that the exploit is genuine. It is really hard to perform it manually and prove it to the concerned development, remediation, and security teams. It is currently missing the static application security part of the application security, especially web application security. It would be really cool if they can integrate a SAS tool with their dynamic one."

What is most valuable?

I am impressed by the whole technology that they are using in this solution. It is really fast. When using netscan, the confirmation that it gives on the vulnerabilities is pretty cool.

It is really easy to configure a scan in Netsparker Web Application Security Scanner. It is also really easy to deploy.

What needs improvement?

They don't really provide the proof of concept up to the level that we need in our organization. We are a consultancy firm, and we provide consultancy for the implementation and deployment solutions to our customers. When you run the scans and the scan is completed, it only shows the proof of exploit, which really doesn't work because the tool is running the scan and exploiting on the read-only form. You don't really know whether it is actually giving the proof of exploit. We cannot prove it manually to a customer that the exploit is genuine. It is really hard to perform it manually and prove it to the concerned development, remediation, and security teams.

It is currently missing the static application security part of the application security, especially web application security. It would be really cool if they can integrate a SAS tool with their dynamic one.

For how long have I used the solution?

We started to use Netsparker Web Application Security Scanner in February of this year. We are using its latest version.

What do I think about the stability of the solution?

It is pretty stable. 

What do I think about the scalability of the solution?

It is scalable.

How are customer service and technical support?

We engage with the local partner and the distributor here for support. We are satisfied with the support here.

How was the initial setup?

The initial setup wasn't a problem for me. I have been using these security tools for a while now.

Which other solutions did I evaluate?

I also use Micro Focus Fortify. The difference is mainly in the UI. I haven't really got into the comparison between the output of the scans, but I was really impressed by the UI and the ease of use of Netsparker Web Application Security Scanner.

What other advice do I have?

I would recommend this solution. I haven't really researched other products, but for me, Netsparker Web Application Security Scanner is a benchmark right now.

I would rate Netsparker Web Application Security Scanner an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1286490 - PeerSpot reviewer
Consultant Cyber Security at a tech services company with 51-200 employees
Consultant
A good interface that makes it easy to use, and the tool is really fast
Pros and Cons
  • "This tool is really fast and the information that they provide on vulnerabilities is pretty good."
  • "Right now, they are missing the static application security part, especially web application security."

What is our primary use case?

We are a consulting firm and we provide implementation and deployment of solutions to our customers.

What is most valuable?

I am very much impressed by the whole technology.

This tool is really fast and the information that they provide on vulnerabilities is pretty good.

The UI is good and it is really easy to use.

What needs improvement?

With respect to the algorithm that Netsparker is running, they don't really provide the proof of concept up to the level that we need, here in the organization. Specifically, because the tool is running the scan and exploiting the read-only version, it doesn't prove to the customer that the exploit is genuine. We have to perform this manually, but it is difficult to prove to the concerned team, whether it is the development team, the remediation team, or the security team.

Right now, they are missing the static application security part, especially web application security. If they can integrate a SaaS tool with their dynamic one then it would be really helpful.

For how long have I used the solution?

I have been working with Netsparker for several months.

What do I think about the stability of the solution?

We have not experienced any bugs or glitches, so it seems stable.

What do I think about the scalability of the solution?

Scalability-wise, it is pretty good.

How are customer service and technical support?

We have been engaged with the local partner and we get a good level of support.

Which solution did I use previously and why did I switch?

We also use Micro Focus Fortify and I have not had a chance to compare the scans, but I prefer the interface and ease of use with Netsparker. It is really easy to configure and deploy, as well as communicate this to the client.

How was the initial setup?

The initial setup was not a problem for me, as I have been using these security tools for a while.

What other advice do I have?

Overall, I am satisfied with Netsparker. However, I cannot say at this point that I would recommend it because although it is good, I will now be using it as a benchmark for evaluating other products.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Retail Services Senior Manager at e-finance
Real User
Very high level of accuracy and speedy scanning
Pros and Cons
  • "High level of accuracy and quick scanning."

    What is our primary use case?

    Our primary use case is for web applications but rather than being in a production environment, it's in a testing environment. We check for vulnerabilities found in the test environment and remediate them. Following that, we publish the web application for web production. We are customers of Netsparker and I'm the retail services senior manager.

    What is most valuable?

    The most valuable features that I've found in this solution was the level of accuracy and also that the process of scanning was very quick and we're easily able to change the frame of a scan. I use the many applications and security management tools and the accuracy is important for me. Other solutions like NetBus don't have such an accurate timeline. 

    What needs improvement?

    Improvement could be made in the area of production. Features like macro recording that I've used in other solutions would improve this product. Recording macro for complex applications, especially web applications where there is a complex web application for login or logout format. We could record the macro for login to make a dynamic scanning process, which makes it easier to scan methodology. We need to be able to record the macro. I think a feature like that would add a lot to the solution. 

    For how long have I used the solution?

    I've been using this solution for three months.

    What do I think about the stability of the solution?

    I think the stability of Netsparker enterprise product is very cool. And the application scanning was very successful. No time outs, no downtime the stability and the service was very, very good. 

    How are customer service and technical support?

    I'm satisfied with the technical support. 

    How was the initial setup?

    Initial setup was straightforward and didn't take much time. It was smooth and successful. 

    What other advice do I have?

    This is not a simple solution, there is a complexity there. A lot of companies here don't like the idea of using a cloud provider or cloud application for scanning. We prefer to have stand-alone applications and not use the cloud. It's something they could offer, like Qualys.

    I would rate this solution an eight out of 10.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user1188708 - PeerSpot reviewer
    Senior Quality Control Manager at a insurance company with 51-200 employees
    Real User
    Great reporting review tool and very stable with an easy initial setup
    Pros and Cons
    • "The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports."
    • "The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them."

    What is our primary use case?

    We're primarily used the solution as a proof of concept using it for assessing the security of one of our web applications.

    What is most valuable?

    The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports.

    What needs improvement?

    The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them.

    For how long have I used the solution?

    I've been using the solution for about two months.

    What do I think about the stability of the solution?

    The solution is very stable.

    What do I think about the scalability of the solution?

    As I was only working on the demo version of the solution, I can't speak to how scalable it would be.

    How are customer service and technical support?

    The technical support team was very helpful. They offered me a demo before I started using the tool, and the demo was very impressive.

    Which solution did I use previously and why did I switch?

    We previously used a different tool, but it was also a demo, like Netsparker. We wanted to try Netsparker, so we moved to their demo.

    How was the initial setup?

    The initial setup was straightforward.

    What about the implementation team?

    I handled the implementation myself.

    Which other solutions did I evaluate?

    I tried some different tools. Some of them were full versions whereas others were demo versions like Netsparker.

    What other advice do I have?

    We're using a demo of the latest version for a POC. We used the on-premises deployment model.

    I'd recommend Netsparker for anyone who wants to make a security assessment for web applications.

    I'd rate the solution nine out of ten. The tool is full of useful features. However, the intercepting reviews in terms of web requests need some enhancements to be more usable.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Invicti Report and get advice and tips from experienced pros sharing their opinions.
    Updated: June 2025
    Buyer's Guide
    Download our free Invicti Report and get advice and tips from experienced pros sharing their opinions.