I like the way Netsparker provides the comprehensive reports in various formats such as PDF, HTML, etc., which are enough to understand what's going on with our web application.
Software Quality Assurance Engineer at ITONICS GmbH
It provides the comprehensive reports in various formats such as PDF and HTML.
What is most valuable?
How has it helped my organization?
When we try to manually exploit the vulnerabilities, it often takes time to realize what's going on and what needs to be done. By using this wonderful tool, we can easily see on the outstanding reports "Important", "Medium", "Low", and "Information" vulnerabilities. Apart from that, it also visualizes what's wrong with a server such as an outdated version, authorization, version disclosure, etc.
What needs improvement?
Sometimes, it is slow; when we are running this application and browsing other applications concurrently, it makes other applications work slow. Besides that, it seems fine.
When I use Netsparker along with other applications such as testing web apps on browsers like Chrome or Firefox for a little longer than normal, there are issues that might be due to the CPU high usage. I'm unable to work on other applications (mainly browsers such as Chrome/Firefox) and ultimately it hangs and takes time to browse on browsers.
For how long have I used the solution?
I have used it for most of the cases when I have to check vulnerabilities and other security exploitation. So, it's been like six months.
Buyer's Guide
Invicti
June 2025

Learn what your peers think about Invicti. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
What was my experience with deployment of the solution?
I have not use this feature. I will let you know when i am done with deployment.
What do I think about the stability of the solution?
Until now, I have not encountered any stability issues.
What do I think about the scalability of the solution?
It sometimes hangs when running large web-based applications.
How are customer service and support?
The way they are communicating with users like us, yeah, we can give them 9 out of 10. :)
Which solution did I use previously and why did I switch?
I have used Acunetix. The reason I switched to Netsparker would be that the performance I found on Acunetix was very slow. It would take something like a day if I had to scan our web-based application product. That is not reliable when you are working with clients who want a quick response regarding how the application performs.
How was the initial setup?
I found initial setup to be straightforward; anyone can set up this solution.
What about the implementation team?
Not from a vendor team.
What's my experience with pricing, setup cost, and licensing?
Price seem to be reliable.
Which other solutions did I evaluate?
No i did not evaluate other options.
What other advice do I have?
I would definitely recommend it to those who really want to know in-depth details of their applications/products regarding security.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Software Quality Assurance Analyst at a real estate/law firm with 5,001-10,000 employees
It has improved the security of our code by scanning it and finding security defects.
Valuable Features
The product’s most valuable features are its security scanning features.
Improvements to My Organization
It has improved the security of our code by scanning it and finding security defects.
Room for Improvement
Speed: It spends about one hour on scanning; I would like it to be less than 30 minutes. Because our solution is large, NetSparker spends about one hour on scanning our code. It also depends on network speed, and just like anti-virus software, the scan time is a key performance requirement for NetSparker. The less the better. Thank you.
Use of Solution
I have used it for two years.
Stability Issues
I did not encounter any stability issues.
Scalability Issues
I did not encounter any scalability issues.
Customer Service and Technical Support
Technical support is good.
Initial Setup
Initial setup is not complex. Just follow the instructions.
Pricing, Setup Cost and Licensing
Price is not the key point.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Invicti
June 2025

Learn what your peers think about Invicti. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
IT Engineer at a aerospace/defense firm with 1,001-5,000 employees
It searches for a lot of updated vulnerabilities. A lot of the security tests are now automated.
What is most valuable?
- It has a very user-friendly page.
- Creating custom policies is very easy.
- It searches for a lot of updated vulnerabilities.
How has it helped my organization?
Before Netsparker, we were opening internal web pages to the outside for manual tests. Health tests were limited by a system admin’s capabilities. After Netsparker, a lot of the security tests became automated. We added a step in our policy document to scan pages with Netsparker before opening a site to the outside.
What needs improvement?
Maybe supported clients can be improved. It still does not search vulnerabilities in DB2 databases, for example. In NetSparker you can modify your scan for specifik target database type, programming language and web server type. And there isn’t DB2 database option for database target in scan Editor.
For how long have I used the solution?
I have been using it for about two years.
What do I think about the stability of the solution?
On early versions, scanning for vulnerabilities didn’t complete. But now it takes an acceptable amount of time.
What do I think about the scalability of the solution?
I did not encounter any scalability issues. With a licence, you can install and run multiple instances of Netsparker at the same time, of course on different targets. Also, you can restrict network access or requests to the page.
How are customer service and technical support?
Technical support is very professional, 10/10. They know what they are doing.
Which solution did I use previously and why did I switch?
We did not previously use a different solution. We started with Netsparker.
How was the initial setup?
Setting up and updating Netsparker is very easy; only one click.
What's my experience with pricing, setup cost, and licensing?
Actually, I am a technical guy; I don’t know exactly the price, but I do know that if the product was expensive, our manager wouldn’t have bought it. J
Which other solutions did I evaluate?
We tried Acunetix, but Netsparker has one up on it.
What other advice do I have?
You must work on your environment first. List the web applications’ background: the systems they are using, web server type, database type, programming language. Netsparker supports lots of them, but there are still some restrictions. If they know their environment, the decision is easier.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Quality Assurance Specialist at a computer software company with 51-200 employees
Its web crawler introduced us to many security vulnerabilities and information we had not known before. Netsparker does not integrate SSO functionality.
What is most valuable?
- Simple, easy and straightforward to start.
- eader information is displayed in an easy to ready way which can be interpreted separately.
- Vulnerabilities categorization, along with the suggestions, is pretty helpful.
- Command line tool did seem interesting, but I couldn’t do much with it. It was a bit hard to learn its usage.
- Crawling websites is one of its best features.
NetSparker is a very easy to use and understand product. Its web crawler feature has benefitted us the most. And introduced us to many security vulnerabilities and information we had not known before. I really like how we can tune the number of concurrent sessions as well, which allows us to do some performance testing as well.
How has it helped my organization?
It covers basic-intermediate web attacks and presents the information in a very descriptive way. This enhances knowledge and also helps to identify which areas are lacking attention.
Other than that, it helps you start looking for the attack vectors and points of weakness.
What needs improvement?
Login functionality: Netsparker does not integrate single-sign-on functionality, which makes it very difficult to use for such websites. SSO has become an essential part of web security testing over the last few years. I would love to see this feature in new releases.
For how long have I used the solution?
I have been using it for ~6 months.
What do I think about the stability of the solution?
It is a resource-intensive program, and while it is running, other processes get very slow.
What do I think about the scalability of the solution?
I did not encounter any scalability issues.
Which solution did I use previously and why did I switch?
This was the starting point. We chose this because Troy Hunt (security advisor) had provided a positive and thorough review of this product on his blog.
We used this product along with some others (SkipFish, NMap, etc.) to fully test the security of our products.
How was the initial setup?
As I mentioned before, installing and using Netsparker is pretty easy compared to other products available.
What's my experience with pricing, setup cost, and licensing?
It is a good tool, as we found out with the Community Edition trial. But the price point is quite expensive for a startup or average-sized company.
Other than what I’ve written, it is a fine product but it cannot be used alone. It covers most of the basic-intermediate level attacks, which is really good as a starting point. But for the high-level and advanced analysis, other (similar) tools are needed, which is why I think its price point is very high.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Engineer at a computer software company with 11-50 employees
An automated application security testing tool with great technical support, but asset scanning could be better
Pros and Cons
- "I like that it's stable and technical support is great."
- "Asset scanning could be better. Once, it couldn't scan assets, and the issue was strange. The price doesn't fit the budget of small and medium-sized businesses."
What is most valuable?
I like that it's stable and technical support is great.
What needs improvement?
Asset scanning could be better. Once, it couldn't scan assets, and the issue was strange. The price doesn't fit the budget of small and medium-sized businesses.
For how long have I used the solution?
I have been working with Invicti for less than six months.
What do I think about the stability of the solution?
Invicti is a stable solution.
On a scale from one to ten, I would give stability an eight.
What do I think about the scalability of the solution?
I think Invicti is a scalable solution.
On a scale from one to ten, I would give scalability an eight.
How are customer service and support?
Technical support was great.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was straightforward. I deployed this solution in about two hours.
What about the implementation team?
I implemented this solution.
What's my experience with pricing, setup cost, and licensing?
Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great.
What other advice do I have?
On a scale from one to ten, I would give Invicti a six.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller

Buyer's Guide
Download our free Invicti Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Dynamic Application Security Testing (DAST) Static Application Security Testing (SAST) API SecurityPopular Comparisons
SonarQube Server (formerly SonarQube)
Snyk
Checkmarx One
Veracode
Coverity
OWASP Zap
Fortify on Demand
SonarQube Cloud (formerly SonarCloud)
Acunetix
HCL AppScan
PortSwigger Burp Suite Professional
Qualys Web Application Scanning
Fortify WebInspect
Rapid7 InsightAppSec
Kiuwan
Buyer's Guide
Download our free Invicti Report and get advice and tips from experienced pros
sharing their opinions.
I too find Netsparker the perfect tool when i compare to other vulnerability scanner tool such as Acunetix. Thanks for the review on this tool though. Also i am still using this tool for security testing.
Cheers.