No more typing reviews! Try our Samantha, our new voice AI agent.

Invicti vs JFrog Xray comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Container Security
11th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Invicti
Ranking in Container Security
24th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
31
Ranking in other categories
Static Application Security Testing (SAST) (12th), Software Composition Analysis (SCA) (10th), API Security (10th), Dynamic Application Security Testing (DAST) (4th), Application Security Posture Management (ASPM) (9th)
JFrog Xray
Ranking in Container Security
18th
Average Rating
7.8
Reviews Sentiment
6.3
Number of Reviews
10
Ranking in other categories
Vulnerability Management (48th), Software Composition Analysis (SCA) (7th), Software Supply Chain Security (3rd)
 

Mindshare comparison

As of September 2026, in the Container Security category, the mindshare of Qualys TotalCloud is 1.7%, up from 1.1% compared to the previous year. The mindshare of Invicti is 1.1%, up from 0.4% compared to the previous year. The mindshare of JFrog Xray is 2.6%, down from 3.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Container Security Mindshare Distribution
ProductMindshare (%)
Qualys TotalCloud1.7%
JFrog Xray2.6%
Invicti1.1%
Other94.6%
Container Security
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
PrashantUppuluri - PeerSpot reviewer
Solution Architect at a tech services company with 51-200 employees
Automated scanning has strengthened web application security and supports hybrid protection
A good scanning engine is what I appreciate about Invicti. When you want to find out the vulnerabilities within your web applications, Invicti has done a thorough job with respect to filtering out the vulnerabilities and identifying the risk factors with respect to the security modules within the solution. Invicti does have a segment of the solution which works on the automated scanning engine. As long as the license is active, the scanners that work within the solution are pretty effective. With respect to SAST and DAST, being a real-time scanning engine is one of the portfolios and one of the selling factors of the solution. Invicti is known to be a solution that works within the hybrid environment, be it cloud, on-premises, or a mix and match across multiple marketplaces. It does a thorough job. Most importantly, Invicti is a very good SAST and DAST solution that is very competitive in the market with respect to competitors. Invicti is a part of the Magic Quadrant with respect to Gartner's Magic Quadrant and has made a very good customer database and pipeline within the marketplace locally. With respect to security impacts in terms of support, Invicti is pretty much supportive. With respect to use cases or the POCs I have run on the solution, we have identified a couple of vulnerabilities and Invicti was able to trace them, detect, and quarantine the attacks.
Anand Nanwana - PeerSpot reviewer
DevOps Engineer at Syvora
Offers flexibility across clouds and easy credential management while interface improvements are needed
For JFrog Xray, the Artifactory and package repositories are valuable features. There are many benefits from JFrog Xray. For example, with other registries such as ECR, we can use the images only in the AWS cloud. With JFrog, we can use this registry from any cloud or work locally as well. JFrog can support multiple packages, such as NuGet package, pip, and other technologies. It can be used for Terraform as well. The credential management is very easy in JFrog. For instance, when using GitHub action as a CI/CD tool, I just need to create a token and set up JFrog CLI there and give access to the repository. With multiple repositories, I can generate a token for a specific repository, add that token in the GitHub secret, fetch from the CI/CD, run the command JFrog CLI, and authenticate through the token. Then we can push the images into JFrog.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors."
"I appreciate Qualys TotalCloud's ability to onboard any type of device with ease, including containers."
"The vulnerability management feature is the one I like the most because it provides a clear picture of all vulnerabilities."
"While automatic inventory detection upon connection is a helpful feature, a truly valuable capability would be assessing an environment's security posture against Azure and CIS best practices."
"Qualys TotalCloud's most valuable feature is its ability to link clusters of assets, providing a clear model of deployments, vulnerabilities, and statuses."
"The dashboards are particularly valuable as they offer a comprehensive view of the environment, highlighting any misconfigurations."
"Qualys TotalCloud is an excellent platform, and the beauty of the platform is that we can get all the vulnerabilities, see all the reports in a single dashboard, view them segregated, and easily learn about critical, high, and medium findings with appropriately provided remediation steps."
"One of the features I appreciate is the ability to generate daily reports without relying on anyone else."
"Netsparker has done an awesome job with its crawler, as it has found all of the links (also thanks to its good DOM parser)."
"The most valuable features that I've found in this solution was the level of accuracy and also that the process of scanning was very quick and we're easily able to change the frame of a scan."
"Scan, proxify the application, and then detailed report along with evidence and remediations to problems."
"It has improved the security of our code by scanning it and finding security defects."
"The dashboard is really cool, and the features are really good. It tells you about the software version you're using in your web application. It gives you the entire technology stack, and that really helps. Both web and desktop apps are good in terms of application scanning. It has a lot of security checks that are easily customizable as per your requirements. It also has good customer support."
"Invicti's best feature is the ability to identify vulnerabilities and manually verify them."
"It has a comprehensive resulting mechanism. It is a one-stop solution for all your security testing mechanisms."
"It is a very good tool."
"I am utilizing the deep scanning capabilities in JFrog Xray product, and this feature is very handy because with other software, you don't know where the bad dependencies come from."
"JFrog Xray's reporting feature has a lot of options in it, including scanning."
"With JFrog, we can use this registry from any cloud or work locally as well, and it can support multiple packages such as NuGet, pip, and other technologies including Terraform, making credential management very easy."
"The most valuable feature of JFrog Xray is the display of the entire internal dependencies hierarchy."
"The solution is stable and reliable."
"The most valuable features of JFrog Xray are its curation capabilities, its native integration with Artifactory, scanning for vulnerabilities, and license compliance features."
"I would say the reporting functionalities are pretty good as are the policy watches."
"I would say that this solution has helped our organization by allowing us to automate a lot of the processes."
 

Cons

"The response part of the Cloud Detection and Response (CDR) module can be improved."
"Regarding technical support from Qualys, they respond, but the response time can be too long. Sometimes we need to wait weeks for solutions to simple questions."
"The cloud licensing unit system is unclear, especially since "units" aren't well-defined."
"To be honest, I would move out from this tool because it does not give a full view of vulnerability."
"The cost of Qualys TotalCloud is high and could be more competitive."
"The patching process with Qualys Patch Management, which is part of TotalCloud, does not cover installing certain prerequisites on the servers or workstations. This shortcoming means we must rely on SCCM when any service stack updates or additional prerequisites are needed."
"The main area needing improvement is integration. Although the team is strengthening TotalCloud, integration can be enhanced with SIEM, SOAR, ITSM, and other sources."
"Areas that need improvement in every solution include the remediation part. The remediation steps should be simple enough for everyone to understand."
"They don't really provide the proof of concept up to the level that we need in our organization."
"Maybe the ability to make a good reporting format is needed."
"The scanner itself should be improved because it is a little bit slow."
"Reporting should be improved. The reporting options should be made better for end-users. Currently, it is possible, but it's not the best. Being able to choose what I want to see in my reports rather than being given prefixed information would make my life easier. I had to depend on the API for getting the content that I wanted. If they could fix the reporting feature to make it more comprehensive and user-friendly, it would help a lot of end-users. Everything else was good about this product."
"I find that the scannings are not sufficiently updated."
"Reporting should be improved. The reporting options should be made better for end-users."
"It would be better for listing and attacking Java-based web applications to exploit vulnerabilities."
"Asset scanning could be better. Once, it couldn't scan assets, and the issue was strange. The price doesn't fit the budget of small and medium-sized businesses."
"Since we have been using the solution via APIs, there are some limitations in the APIs."
"Lacks deeper reporting, the ability to compare things."
"I think that the user interface should be expanded to provide customers with a better dashboard for reviewing their feedback regarding their images and the vulnerabilities that are associated with the images."
"Reporting is crucial, but it is lacking in the current tool. Every organization seeks specific data points rather than general information. Therefore, we require customized reports from the Xray tool."
"X-ray needs improvement in supporting more than one database, as it currently only supports PostgreSQL."
"I'd like to see deeper reporting, they're pretty basic and there are no categories for comparing things."
"The speed of JFrog Xray should improve. Other solutions have better performance."
"The UI of JFrog Xray could be improved. There is a dialogue box in the Xray section that doesn't always work properly."
 

Pricing and Cost Advice

"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"TotalCloud's price is about right where I would expect it to be."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
"The price should be 20% lower"
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"It is competitive in the security market."
"We never had any issues with the licensing; the price was within our assigned limits."
"OWASP Zap is free and it has live updates, so that's a big plus."
"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
Information not available
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Financial Services Firm
13%
Manufacturing Company
10%
Construction Company
8%
Government
7%
Financial Services Firm
25%
Manufacturing Company
11%
Computer Software Company
5%
University
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise5
Large Enterprise34
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise4
Large Enterprise13
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise3
Large Enterprise6
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
The setup cost is pretty competitive. For example, if you want to talk about the SAST license, it comes to about $150...
What needs improvement with Invicti?
At this time, there is nothing that comes to mind. However, most of the products in the market are pretty much neck-t...
What is your primary use case for Invicti?
I have worked on a couple of products, specifically in web application security. I have worked on Invicti, and with r...
What needs improvement with JFrog Xray?
I would assess the integration of JFrog Xray with CI/CD tools as the weak point. You have two means to do that: one i...
What is your primary use case for JFrog Xray?
For JFrog Xray product, you can use it for two main goals: compliance and security. You can use it to check if your l...
What is your experience regarding pricing and costs for JFrog Xray?
It is affordable because JFrog Xray provides a free trial of 14 days. We can explore all the features of JFrog in the...
 

Also Known As

Qualys TotalCloud with FlexScan
Netsparker
JFrog Security Essentials
 

Overview

 

Sample Customers

Information Not Available
Samsung, The Walt Disney Company, T-Systems, ING Bank
google, amazon, cisco, netflix, oracle, vmware, facebook
Find out what your peers are saying about Invicti vs. JFrog Xray and other solutions. Updated: September 2026.
913,683 professionals have used our research since 2012.