Try our new research platform with insights from 80,000+ expert users

Akamai API Security vs Invicti comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Akamai API Security
Ranking in API Security
1st
Average Rating
7.8
Reviews Sentiment
6.4
Number of Reviews
10
Ranking in other categories
No ranking in other categories
Invicti
Ranking in API Security
8th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
31
Ranking in other categories
Static Application Security Testing (SAST) (11th), Container Security (25th), Software Composition Analysis (SCA) (8th), Dynamic Application Security Testing (DAST) (4th), Application Security Posture Management (ASPM) (5th)
 

Mindshare comparison

As of March 2026, in the API Security category, the mindshare of Akamai API Security is 9.1%, down from 20.3% compared to the previous year. The mindshare of Invicti is 3.0%, up from 2.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
API Security Mindshare Distribution
ProductMindshare (%)
Akamai API Security9.1%
Invicti3.0%
Other87.9%
API Security
 

Featured Reviews

Ronald Paz - PeerSpot reviewer
Consulting Systems Engineer at Boomslang Tech
Increased API visibility has reduced shadow endpoints and improved data protection
The most impactful feature Akamai API Security offers has been automated API discovery and behavior anomaly detection. The automatic API discovery has worked well for me by helping me identify APIs that were not formally documented, detect risky data exposure patterns, and flag abnormal traffic behavior early. This has reduced blind spots significantly.
Valavan Sivgalingam - PeerSpot reviewer
Senior Manager, Security Engineering at ESS
Dynamic testing regularly identifies web vulnerabilities and has strong false positive confirmations
It has good false positive confirmations, confirmed issues identification, and proof of exploit-related features as part of it. We use Invicti for these things in our portfolios. The solution includes Proof-Based Scanning technology. Invicti is part of our SSDLC portfolio, and DAST dynamic testing is very important for our web applications and portfolios. For both the API endpoints and web applications, we do regular testing on a monthly basis for all our releases. Invicti does a good job. The only concern is on the performance side, but other than that, we find it really helpful in identifying web vulnerabilities. A full scan takes more time based on your website and other factors, but for us, it takes more than two to three days. The scan performance can be improved upon. When we check with them, they discuss proof-based scanning and related aspects. However, there could be intermittent results that could help us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Akamai API Security has positively impacted my organization by increasing visibility into the API attack surface, reducing exposure of undocumented endpoints, better aligning with zero-trust and security-by-design principles, and improving governance over the API life cycle."
"Akamai API Security has positively impacted my organization by increasing visibility into the API attack surface, reducing exposure of undocumented endpoints, better aligning with zero-trust and security-by-design principles, and improving governance over the API life cycle."
"The most valuable feature of this solution is its integration with API gateways, WAP and with part of their SDLC."
"The API part is effective."
"If I had to say something positive about the product that brings me the biggest benefit, I would say visibility."
"The support from Akamai API Security is good, the employment and support are of excellent quality."
"What I already appreciate about Akamai API Security is that initially we were struggling with how to get this configured, but after that everything went smoothly."
"API throttling is the most valuable feature of Akamai API Security."
"Invicti has done a commendable job with respect to ROI, and with respect to being a cost-effective solution and one of the market leaders as an effective solution for SAST and DAST, Invicti has performed very well."
"The scanner is light on the network and does not impact the network when scans are running."
"The dashboard is really cool, and the features are really good. It tells you about the software version you're using in your web application. It gives you the entire technology stack, and that really helps. Both web and desktop apps are good in terms of application scanning. It has a lot of security checks that are easily customizable as per your requirements. It also has good customer support."
"Invicti is part of our SSDLC portfolio, and DAST dynamic testing is very important for our web applications and portfolios."
"Netsparker provides a more interactive interface that is more appealing."
"Its ability to crawl a web application is quite different than another similar scanner."
"Invicti's best feature is the ability to identify vulnerabilities and manually verify them."
"The most valuable feature of Invicti is getting baseline scanning and incremental scan."
 

Cons

"A potential improvement for Akamai API Security would be more granular risk scoring per API asset."
"The main challenges we had with Akamai API Security were how to set it up on the AWS cloud environment and how to access this portal."
"The challenge I found was with contextualization and how analytics are generated."
"It would be beneficial to use machine learning and API throttling together to identify how the APIs are called and whether it's coming from the right person or the wrong person."
"I think it would be good if they can integrate more with API gateways as this is currently limited."
"More features would be beneficial."
"I see some areas for improvement in Akamai API Security because the adoption is not easy since it takes time to learn and configure."
"However, this solution is quite costly as it comes with the content delivery network, providing both content delivery and security."
"Right now, they are missing the static application security part, especially web application security."
"Currently, there is nothing I would like to improve."
"Invicti's reporting capabilities need enhancement. We need enterprise-level information instead of repo-level details. Unlike Appiro, Invicti does not provide portfolio-level insights into vulnerability remediation over time."
"Netsparker doesn't provide the source code of the static application security testing."
"They don't really provide the proof of concept up to the level that we need in our organization. We are a consultancy firm, and we provide consultancy for the implementation and deployment solutions to our customers. When you run the scans and the scan is completed, it only shows the proof of exploit, which really doesn't work because the tool is running the scan and exploiting on the read-only form. You don't really know whether it is actually giving the proof of exploit. We cannot prove it manually to a customer that the exploit is genuine. It is really hard to perform it manually and prove it to the concerned development, remediation, and security teams. It is currently missing the static application security part of the application security, especially web application security. It would be really cool if they can integrate a SAS tool with their dynamic one."
"Invicti's reporting capabilities need enhancement."
"The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them."
"It would be better for listing and attacking Java-based web applications to exploit vulnerabilities."
 

Pricing and Cost Advice

"We have a limit to the number of APIs we can use inside a bundle, and we have to pay extra if we exceed that limit."
"It is competitive in the security market."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"OWASP Zap is free and it has live updates, so that's a big plus."
"We never had any issues with the licensing; the price was within our assigned limits."
"The price should be 20% lower"
"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
report
Use our free recommendation engine to learn which API Security solutions are best for your needs.
884,797 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
13%
Manufacturing Company
9%
Retailer
6%
Financial Services Firm
15%
Manufacturing Company
9%
Computer Software Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Large Enterprise6
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise4
Large Enterprise13
 

Questions from the Community

What is your experience regarding pricing and costs for Akamai API Security?
It is not expensive. It is practical to use and represents an excellent solution.
What needs improvement with Akamai API Security?
The tool is blocking and only the person who has access to the tool can actually see how many DDoS attacks were blocked. Since I do not log in to the portal myself, I am unaware of this capability....
What is your primary use case for Akamai API Security?
Since multiple teams were involved in issue resolving, at least ten plus people from our side were involved in the implementation process. Everyone was contributing, even if we consider two per tea...
What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
The setup cost is pretty competitive. For example, if you want to talk about the SAST license, it comes to about $150 or sometimes less than $100, depending on the conversion or the number of licen...
What needs improvement with Invicti?
At this time, there is nothing that comes to mind. However, most of the products in the market are pretty much neck-to-neck competitors. Speaking about it, there are a couple of factors which they ...
What is your primary use case for Invicti?
I have worked on a couple of products, specifically in web application security. I have worked on Invicti, and with respect to PAM, I have worked with BeyondTrust. I have not worked specifically fo...
 

Also Known As

Noname Security
Netsparker
 

Overview

 

Sample Customers

Information Not Available
Samsung, The Walt Disney Company, T-Systems, ING Bank
Find out what your peers are saying about Akamai API Security vs. Invicti and other solutions. Updated: February 2026.
884,797 professionals have used our research since 2012.