Try our new research platform with insights from 80,000+ expert users

Akamai API Security vs Invicti comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Akamai API Security
Ranking in API Security
1st
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
6
Ranking in other categories
No ranking in other categories
Invicti
Ranking in API Security
9th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
31
Ranking in other categories
Static Application Security Testing (SAST) (11th), Container Security (26th), Software Composition Analysis (SCA) (8th), Dynamic Application Security Testing (DAST) (4th), Application Security Posture Management (ASPM) (5th)
 

Mindshare comparison

As of February 2026, in the API Security category, the mindshare of Akamai API Security is 9.5%, down from 20.5% compared to the previous year. The mindshare of Invicti is 2.8%, up from 2.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
API Security Market Share Distribution
ProductMarket Share (%)
Akamai API Security9.5%
Invicti2.8%
Other87.7%
API Security
 

Featured Reviews

RR
Incident Manager at a computer software company with 1,001-5,000 employees
Unified API visibility has transformed governance and now supports compliance reporting
The tool is blocking and only the person who has access to the tool can actually see how many DDoS attacks were blocked. Since I do not log in to the portal myself, I am unaware of this capability. I heard the word Akamai's anomaly detection from my team that they use this, but I don't know about it on the technical aspect. I am unaware of Akamai API Security's ability to adjust security policies in real-time. I am also unaware of which feature of Akamai API Security has helped us monitor API usage trends. Someone who is actually hands-on using Akamai API Security might know this.
Valavan Sivgalingam - PeerSpot reviewer
Senior Manager, Security Engineering at ESS
Dynamic testing regularly identifies web vulnerabilities and has strong false positive confirmations
It has good false positive confirmations, confirmed issues identification, and proof of exploit-related features as part of it. We use Invicti for these things in our portfolios. The solution includes Proof-Based Scanning technology. Invicti is part of our SSDLC portfolio, and DAST dynamic testing is very important for our web applications and portfolios. For both the API endpoints and web applications, we do regular testing on a monthly basis for all our releases. Invicti does a good job. The only concern is on the performance side, but other than that, we find it really helpful in identifying web vulnerabilities. A full scan takes more time based on your website and other factors, but for us, it takes more than two to three days. The scan performance can be improved upon. When we check with them, they discuss proof-based scanning and related aspects. However, there could be intermittent results that could help us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Akamai API Security has made a positive difference for our organization by improving our security posture and saving our team time, as we can actually prioritize tasks unless there are some false positives, but it is definitely saving a lot of time."
"The most valuable feature of this solution is its integration with API gateways, WAP and with part of their SDLC."
"API throttling is the most valuable feature of Akamai API Security."
"The API part is effective."
"The support from Akamai API Security is good, the employment and support are of excellent quality."
"What I already appreciate about Akamai API Security is that initially we were struggling with how to get this configured, but after that everything went smoothly."
"Invicti is a good product, and its API testing is also good."
"Netsparker provides a more interactive interface that is more appealing."
"Invicti has done a commendable job with respect to ROI, and with respect to being a cost-effective solution and one of the market leaders as an effective solution for SAST and DAST, Invicti has performed very well."
"I would rate the stability as ten out of ten."
"Its ability to crawl a web application is quite different than another similar scanner."
"It has very good integration with the CI/CD pipeline."
"Scan, proxify the application, and then detailed report along with evidence and remediations to problems."
"Invicti's best feature is the ability to identify vulnerabilities and manually verify them."
 

Cons

"It would be beneficial to use machine learning and API throttling together to identify how the APIs are called and whether it's coming from the right person or the wrong person."
"More features would be beneficial."
"The main challenges we had with Akamai API Security were how to set it up on the AWS cloud environment and how to access this portal."
"I think it would be good if they can integrate more with API gateways as this is currently limited."
"The challenge I found was with contextualization and how analytics are generated."
"The custom attack preparation screen might be improved."
"They need to improve their support in the documentation. Their support mechanism is missing. Their responsiveness, technical staff, and these types of things need to be improved, and comprehensive documentation is required. They should have good self-service portal enhancement"
"Invicti takes too long with big applications, and there are issues with the login portal."
"The license could be better. It would help if they could allow us to scan multiple URLs on the same license. It's a major hindrance that we are facing while scanning applications, and we have to be sure that the URLs are the same and not different so that we do not end up consuming another license for it. Netsparker is one of the costliest products in the market. The licensing is tied to the URL, and it's restricted. If you have a URL that you scanned once, like a website, you cannot retry that same license. If you are scanning the same website but in a different domain or different URL, you might end up paying for a second license. It would also be better if they provided proper support for multi-factor authentications. In the next release, I would like them to include good multi-factor authentication support."
"They don't really provide the proof of concept up to the level that we need in our organization. We are a consultancy firm, and we provide consultancy for the implementation and deployment solutions to our customers. When you run the scans and the scan is completed, it only shows the proof of exploit, which really doesn't work because the tool is running the scan and exploiting on the read-only form. You don't really know whether it is actually giving the proof of exploit. We cannot prove it manually to a customer that the exploit is genuine. It is really hard to perform it manually and prove it to the concerned development, remediation, and security teams. It is currently missing the static application security part of the application security, especially web application security. It would be really cool if they can integrate a SAS tool with their dynamic one."
"The solution's false positive analysis and vulnerability analysis libraries could be improved."
"They could enhance the support for data swap testing for the platform."
"The support's response time could be faster since we are in different time zones."
 

Pricing and Cost Advice

"We have a limit to the number of APIs we can use inside a bundle, and we have to pay extra if we exceed that limit."
"OWASP Zap is free and it has live updates, so that's a big plus."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
"The solution is very expensive. It comes with a yearly subscription. We were paying 6000 dollars yearly for unlimited scans. We have three licenses; basic, business, and ultimate. We need ultimate because it has unlimited scan numbers."
"The price should be 20% lower"
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
"It is competitive in the security market."
report
Use our free recommendation engine to learn which API Security solutions are best for your needs.
881,665 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Computer Software Company
14%
Manufacturing Company
8%
Retailer
6%
Financial Services Firm
17%
Computer Software Company
11%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise4
Large Enterprise13
 

Questions from the Community

What is your experience regarding pricing and costs for Akamai API Security?
It is not expensive. It is practical to use and represents an excellent solution.
What is your primary use case for Akamai API Security?
I use Akamai API Security. I downloaded a report comparing WAF Akamai and WAF Azure to understand the real differences. I studied the solution to comprehend how it detects bots. For example, with A...
What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
The setup cost is pretty competitive. For example, if you want to talk about the SAST license, it comes to about $150 or sometimes less than $100, depending on the conversion or the number of licen...
What needs improvement with Invicti?
At this time, there is nothing that comes to mind. However, most of the products in the market are pretty much neck-to-neck competitors. Speaking about it, there are a couple of factors which they ...
What is your primary use case for Invicti?
I have worked on a couple of products, specifically in web application security. I have worked on Invicti, and with respect to PAM, I have worked with BeyondTrust. I have not worked specifically fo...
 

Also Known As

Noname Security
Netsparker
 

Overview

 

Sample Customers

Information Not Available
Samsung, The Walt Disney Company, T-Systems, ING Bank
Find out what your peers are saying about Akamai API Security vs. Invicti and other solutions. Updated: December 2025.
881,665 professionals have used our research since 2012.