No more typing reviews! Try our Samantha, our new voice AI agent.

Imperva Application Security Platform vs Invicti comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 22, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Imperva Application Securit...
Ranking in API Security
2nd
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
144
Ranking in other categories
CDN (2nd), Web Application Firewall (WAF) (1st), Distributed Denial-of-Service (DDoS) Protection (4th), Bot Management (1st)
Invicti
Ranking in API Security
9th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
31
Ranking in other categories
Static Application Security Testing (SAST) (10th), Container Security (24th), Software Composition Analysis (SCA) (8th), Dynamic Application Security Testing (DAST) (4th), Application Security Posture Management (ASPM) (5th)
 

Mindshare comparison

As of May 2026, in the API Security category, the mindshare of Imperva Application Security Platform is 9.6%, up from 5.5% compared to the previous year. The mindshare of Invicti is 3.6%, up from 2.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
API Security Mindshare Distribution
ProductMindshare (%)
Imperva Application Security Platform9.6%
Invicti3.6%
Other86.8%
API Security
 

Featured Reviews

ST
Senior Cybersecurity Consultant at Cyberoutcome Limited
Strong policies and bot defenses have secured critical APIs and have reduced attack noise
From my research regarding the IAM space that Imperva Application Security Platform is trying to look into, I believe they still need to do a lot of modeling and modification to make sure that also helps. There are several competitors in the IAM space, so Imperva would do well if they can do some basic modeling and modifications from my own personal research and my own experience in the IAM space. Alternatively, they could actually just focus on trying to be stronger in the web application space and the database activity monitoring space.The main reason it is not a perfect ten is regarding support. At times, having to reach the support team takes eight hours to ten hours maximum. There are times when clients could have urgent issues to attend to. The support team could do more by having a faster response rate.
Valavan Sivgalingam - PeerSpot reviewer
Senior Manager, Security Engineering at ESS
Dynamic testing regularly identifies web vulnerabilities and has strong false positive confirmations
It has good false positive confirmations, confirmed issues identification, and proof of exploit-related features as part of it. We use Invicti for these things in our portfolios. The solution includes Proof-Based Scanning technology. Invicti is part of our SSDLC portfolio, and DAST dynamic testing is very important for our web applications and portfolios. For both the API endpoints and web applications, we do regular testing on a monthly basis for all our releases. Invicti does a good job. The only concern is on the performance side, but other than that, we find it really helpful in identifying web vulnerabilities. A full scan takes more time based on your website and other factors, but for us, it takes more than two to three days. The scan performance can be improved upon. When we check with them, they discuss proof-based scanning and related aspects. However, there could be intermittent results that could help us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This implementation helped our organization a lot in handling web attacks by hackers and other malicious intruders."
"Incapsula’s DDoS Protection and Load Balancing really helped maximize our security."
"As a system, it's very effective at blocking potentially malicious items."
"Imperva is a Gartner leader, so its scalability, performance, and features are excellent."
"After moving to Imperva Application Security Platform, these attacks have been prevented significantly, and the attacks on the initial level have been considerably reduced."
"Real-time monitoring is also a great tool, as you may watch several parameters in real time."
"The solution is really stable; it's a product that I can stand by and recommend because I know it's going to work for the customer."
"The valuable features of Imperva WAF include its effective security breach prevention through automatically updating rules."
"Netsparker provides a more interactive interface that is more appealing."
"The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports."
"I would tell potential users that it's really one of the best products in the market for web application security or Dynamic Application Security Testing (DAST)."
"I like that it's stable and technical support is great."
"Netsparker has valuable features, including the ability to scan our website, an interactive approach, and security data integration."
"Its ability to crawl a web application is quite different than another similar scanner."
"Scan, proxify the application, and then detailed report along with evidence and remediations to problems."
"Its ability to crawl a web application is quite different than another similar scanner, and sometimes it can find more vulnerabilities that another scanner can’t."
 

Cons

"Imperva Application Security Platform could be improved by providing a more user-friendly dashboard."
"It would be better if we were able to manage and apply changes to multiple websites/web applications, and search WAF logs for multiple websites, via the Incapsula dashboard."
"Sometimes, the SSL setup can be a bit slow/inconsistent."
"They can provide an option to create reports, automatically import the entire report, and create rules again. In a real-life crisis, it would be helpful to be able to import a report and generate security rules from that report. I should be able to create a simple query and import the reports automatically. It can maybe also tell us the format of the report."
"Imperva now offers add-ons to add functionality, but I would like to see these included in the product, even if it would cost more."
"The tool needs to include artificial intelligence and machine learning. It also needs to improve profiling."
"Some maintenance must be performed by our IT team."
"The tool needs to improve CPU and storage memory."
"Reporting should be improved. The reporting options should be made better for end-users. Currently, it is possible, but it's not the best. Being able to choose what I want to see in my reports rather than being given prefixed information would make my life easier. I had to depend on the API for getting the content that I wanted. If they could fix the reporting feature to make it more comprehensive and user-friendly, it would help a lot of end-users. Everything else was good about this product."
"Netsparker doesn't provide the source code of the static application security testing."
"Maybe supported clients can be improved. It still does not search vulnerabilities in DB2 databases, for example."
"Improvement could be made in the area of production."
"Invicti's reporting capabilities need enhancement."
"The solution needs to make a more specific report."
"Netsparker doesn't provide the source code of the static application security testing."
"The custom attack preparation screen might be improved."
 

Pricing and Cost Advice

"Imperva charges us based on bandwidth, which is better than other vendors that charge us according to data transfer."
"It is very costly, but the return on investment is very high. Its cost was around $70,000, and we got it back in just six months."
"The tool is expensive."
"Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price."
"There are a couple of different licensing models."
"It is a very affordable solution."
"Imperva Web Application Firewall is expensive."
"It is not expensive compared to the other similar solutions in this category."
"The solution is very expensive. It comes with a yearly subscription. We were paying 6000 dollars yearly for unlimited scans. We have three licenses; basic, business, and ultimate. We need ultimate because it has unlimited scan numbers."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"We never had any issues with the licensing; the price was within our assigned limits."
"The price should be 20% lower"
"OWASP Zap is free and it has live updates, so that's a big plus."
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
"It is competitive in the security market."
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
report
Use our free recommendation engine to learn which API Security solutions are best for your needs.
893,221 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Manufacturing Company
8%
Computer Software Company
7%
Comms Service Provider
6%
Financial Services Firm
16%
Manufacturing Company
9%
Computer Software Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business88
Midsize Enterprise25
Large Enterprise69
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise4
Large Enterprise13
 

Questions from the Community

Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot management.
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provided. I would rate the pricing of Imperva DDoS as five, where one is very cheap a...
What needs improvement with Imperva DDoS?
I would like to see improvements in the pooling of threats and attacks, possibly to enlarge the scale of indicators of compromise. For example, the initiation of an attack on the endpoint level cou...
What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
The setup cost is pretty competitive. For example, if you want to talk about the SAST license, it comes to about $150 or sometimes less than $100, depending on the conversion or the number of licen...
What needs improvement with Invicti?
At this time, there is nothing that comes to mind. However, most of the products in the market are pretty much neck-to-neck competitors. Speaking about it, there are a couple of factors which they ...
What is your primary use case for Invicti?
I have worked on a couple of products, specifically in web application security. I have worked on Invicti, and with respect to PAM, I have worked with BeyondTrust. I have not worked specifically fo...
 

Also Known As

Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
Netsparker
 

Overview

 

Sample Customers

Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Samsung, The Walt Disney Company, T-Systems, ING Bank
Find out what your peers are saying about Imperva Application Security Platform vs. Invicti and other solutions. Updated: April 2026.
893,221 professionals have used our research since 2012.