

Qualys Web Application Scanning and Acunetix compete in the vulnerability management category, each offering distinct advantages. Based on features, Qualys has the upper hand with its dual functionality for web and internal vulnerability management. In room for improvement, both face challenges, but Acunetix has fewer false positives noted. For deployment and customer service, Qualys offers a more extensive cloud-based deployment, but Acunetix's customer service is often praised for being direct. In pricing and ROI, Qualys tends to be more expensive, but Acunetix's recent price increases affect cost-effectiveness.
Features: Qualys integrates with Selenium IDE to automate logins, offers cloud-based deployment for flexibility, and reports fewer false positives, enhancing reliability. Acunetix features high-speed detection, detailed crawl capabilities, and can manage login sequences and record sessions effectively.
Room for Improvement: Qualys could enhance XSS detection, prioritize more integration options, and improve its user interface and scanning accuracy. Acunetix should address false positives, improve scan speed, and expand integration capabilities.
Ease of Deployment and Customer Service: Qualys can be deployed across various cloud environments and on-premises, though customer service varies from supportive to transactional. Acunetix primarily deploys on-premises and has received positive feedback for direct technical support despite some customer service criticisms.
Pricing and ROI: Qualys is seen as expensive with asset-based pricing but offers good potential ROI through scalability. Acunetix was initially cost-effective, but recent price increases and its domain-based licensing may impact organizations with many sub-domains. Discounts for bulk purchases are available for Qualys.
It saves a significant amount of time by covering attack surfaces.
I have seen a return on investment, as Acunetix helps reduce the man-days and effort needed for scanning bulk applications through automated assessments.
I have seen a return on investment with Acunetix, including time saved and cost reduction, because it provides us threats on our web application servers.
For high-severity issues, they reach out within two to three hours, and for critical issues, a response is received within 15 minutes.
The technical support from Invicti is very good and fast.
Support staff not being familiar with the problem.
They have various options in the vulnerability management process, and when we initially bought our license, we didn't realize we needed PCI for better results, which isn't included in the default configurations.
Once we purchase the license, we have access to top-notch support.
I have dealt with Qualys's technical support, and any enhancements are challenging.
Acunetix can handle increasing workloads and more applications easily.
Acunetix's scalability for my growing needs is great; it is a very scalable product compared to others.
My concern remains the lack of deep dive analysis and that it produces similar vulnerability results as other tools such as Nessus based on version checks instead of real impact checks.
It is licensed for assets, so we just contact the team for additional licenses if needed.
At one point, there was a limitation on reporting for 100,000 assets at a time.
I did not need to reach customer support because the product is very stable.
The main concern is related to false positives; Acunetix needs to work on identifying valid and invalid findings.
Acunetix should have better integration with newer tools such as GitHub and Azure DevOps.
I believe Acunetix can improve customer support, as the dedicated support staff are often unfamiliar with problems and troubleshooting, leading to communication gaps that delay issue resolution.
With the growing reliance on AI, Qualys Web Application Scanning should be updated to handle AI-based applications and LLM-based attacks.
Qualys Web Application Scanning does IP-level testing, requiring direct input of credentials, and can only scan a few pages to provide known generic vulnerabilities.
I would like it to be cheaper because it is a bit expensive compared to competitors like Tenable Nessus.
The pricing cost is affordable for small and mid-sized organizations, and when compared to Checkmarx, it is significantly affordable, as Checkmarx is quite expensive.
We secured a special licensing model for penetration testing companies, which is cost-effective.
The pricing of Acunetix is pretty expensive and could be improved.
They offer discounts on bulk licenses, making it cheaper compared to competitors like Veracode DAST.
I find it a bit expensive compared to other competitors.
Regarding pricing, I think for personal use, it is costly, but if organizations are ready to pay, then it is fine as they are using it.
Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.
The solution is excellent at detecting SQL injection and cross-site scripting vulnerabilities.
The best feature Acunetix offers is the centralized dashboard and the quality of reports it generates, which includes various options for selecting reports and developer options for directly sharing the reports with developers.
It effectively detects vulnerabilities like the OWASP Top 10 without any issues in reporting.
Credential scanning is very effective because it goes in-depth into the system, crawling the pages, and reporting on vulnerabilities.
Qualys Web Application Scanning is accurate and provides minimal false positives.
| Product | Market Share (%) |
|---|---|
| Acunetix | 2.3% |
| Qualys Web Application Scanning | 1.8% |
| Other | 95.9% |


| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 7 |
| Large Enterprise | 17 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 6 |
| Large Enterprise | 27 |
Acunetix Web Vulnerability Scanner is an automated web application security testing tool that audits your web applications by checking for vulnerabilities like SQL Injection, Cross site scripting, and other exploitable vulnerabilities.
Qualys Web Application Scanning (WAS) is a fully cloud-based web application security scanner. The scanner will automatically crawl periodically and test web applications to discover potential vulnerabilities, including cross-site scripting (XSS) and SQL injection. The consistent testing equips the automated service to generate consistent results, lessen false positives, and offer the ability to scale to protect thousands of websites effortlessly.
Qualys Web Application Scanning is bundled with different scanning technology to carefully scan websites for malware infections and will send notifications to website owners to assist in preventing blacklisting and brand reputation damage. As digital transformation takes place in various organizations, Qualys WAS gives organizations the ability to track and document their web app security status through its interactive reporting capabilities.
Qualys WAS empowers organizations to remediate any web application vulnerabilities quickly. Some of the key tools offered are:
Benefits of Qualys Web Application Scanning
Qualys Web Application Scanning offers many benefits, including:
Reviews from Real Users
Qualys Web Application Scanning stands out among its competitors for a variety of reasons. Two of those reasons are its progressive scan and quick detection of vulnerabilities.
P.K., a senior software developer at a tech vendor, writes, "The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours."
Nagaraj S., lead cybersecurity engineer at a tech service company, notes, "I have found the detection of vulnerabilities tool thorough with good results and the graphical display output to be wonderful and full of colors. It allows many types of outputs, such as bar and chart previews."
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.