No more typing reviews! Try our Samantha, our new voice AI agent.
Akshay Waghmare - PeerSpot reviewer
Manager at a consultancy with 10,001+ employees
Real User
Nov 13, 2023
A stable and user-friendly solution that can be used for dynamic application security testing
Pros and Cons
  • "The most valuable feature of Invicti is getting baseline scanning and incremental scan."
  • "The solution's false positive analysis and vulnerability analysis libraries could be improved."

What is our primary use case?

We use Invicti for dynamic application security testing and to integrate files into the pipeline.

What is most valuable?

The most valuable feature of Invicti is getting baseline scanning and incremental scan.

What needs improvement?

The solution's false positive analysis and vulnerability analysis libraries could be improved.

For how long have I used the solution?

I have been using Invicti for a couple of years.

Buyer's Guide
Invicti
June 2026
Learn what your peers think about Invicti. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.

What do I think about the stability of the solution?

Invicti is a stable solution with no bugs or breakdowns.

What do I think about the scalability of the solution?

Invicti is a scalable solution. Around 18 users are using the solution in our organization.

How are customer service and support?

We regularly contact Invicti's technical support when we face issues. The solution's technical support team is not reliable enough to provide us with solutions.

Which solution did I use previously and why did I switch?

We previously used a different solution called AppScan Standard. We switched to Invicti because Gartner has a good rating for Invicti, and Invicti has a good vulnerability analysis compared to AppScan Standard.

How was the initial setup?

Invicti's initial setup is average and neither easy nor complex.

What other advice do I have?

Invicti is the best user-friendly tool for dynamic application security testing (DAST) compared to other solutions.

Overall, I rate Invicti a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
JoelGeorge - PeerSpot reviewer
Associate at Tata Consultancy
Real User
Apr 27, 2022
A comprehensive solution for all of your security testing needs
Pros and Cons
  • "It has a comprehensive resulting mechanism. It is a one-stop solution for all your security testing mechanisms."
  • "It is a very good tool."
  • "Reporting should be improved. The reporting options should be made better for end-users. Currently, it is possible, but it's not the best. Being able to choose what I want to see in my reports rather than being given prefixed information would make my life easier. I had to depend on the API for getting the content that I wanted. If they could fix the reporting feature to make it more comprehensive and user-friendly, it would help a lot of end-users. Everything else was good about this product."
  • "Reporting should be improved. The reporting options should be made better for end-users."

What is most valuable?

It has a comprehensive resulting mechanism. It is a one-stop solution for all your security testing mechanisms.

What needs improvement?

Reporting should be improved. The reporting options should be made better for end-users. Currently, it is possible, but it's not the best. Being able to choose what I want to see in my reports rather than being given prefixed information would make my life easier. I had to depend on the API for getting the content that I wanted. If they could fix the reporting feature to make it more comprehensive and user-friendly, it would help a lot of end-users. Everything else was good about this product.

For how long have I used the solution?

I used this solution for around 16 months. We were using its latest version. 

It was a cloud deployment. It was an internal cloud. The company bought the cloud version and then hosted it internally.

What do I think about the stability of the solution?

It's good. I believe it went down only once in 16 months. It never had any other problem.

How are customer service and support?

Their support was good. They were quite prompt with their responses. When we had any issues, we reached out, and they did respond quickly.

How was the initial setup?

It was done by my company's IT team, and I was not involved in that.

What about the implementation team?

We basically had them implement it in-house for us. So, it was done in-house, but it was done by Netsparker's team. It was not done by our team.

In terms of maintenance, it was being managed by a team, but I don't know how many people were managing it in that team.

What other advice do I have?

It is a very good tool. It has an API segment that makes up for the lack of reporting options. You can execute commands on Netsparker by using your command-line interface. By using the API, you will be able to get the kind of information that you are looking for. It'll help you in getting the results that you want.

I would rate it an eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Invicti
June 2026
Learn what your peers think about Invicti. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
PrashantPatil - PeerSpot reviewer
Senior Security Consultant at Verve Square Technologies
Consultant
Apr 26, 2022
Great active and passive scanning, and reports are generated automatically
Pros and Cons
  • "The solution generates reports automatically and quickly and it's a very user-friendly product."
  • "I find that the scannings are not sufficiently updated."

What is our primary use case?

We use this product for vulnerability assessment and penetration testing of any web application in addition to API testing. The solution generates reports for us. I'm a security consultant and we are end-users. 

What is most valuable?

The solution generates reports automatically and quickly and it's a very user-friendly product. I like the active and passive scanning, which is a good feature from my perspective.

What needs improvement?

I find that the scannings are not sufficiently updated. 

For how long have I used the solution?

I've been using this solution for four years. 

What do I think about the stability of the solution?

The stability is good, up to the mark. 

What do I think about the scalability of the solution?

The scalability is good and we're likely going to increase usage of Netsparker. 

How are customer service and support?

We contact technical support all the time and they are great. They resolve issues quickly and efficiently. 

Which solution did I use previously and why did I switch?

We also use Burp Suite which is a UI-based tool that I also find to be user-friendly. We use both products so that in the case of false positives we can compare and verify. 

How was the initial setup?

The initial setup is straightforward and the solution doesn't require any maintenance. We currently have 15 users and that number is likely to expand to around 20 in the near future. 

What's my experience with pricing, setup cost, and licensing?

The pricing of the license is compatible with our budget. 

What other advice do I have?

I highly recommend Netsparker and rate it eight out of 10. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
UmeshKumar2 - PeerSpot reviewer
Senior System Administrator at a tech vendor with 10,001+ employees
Real User
Mar 3, 2023
Excellent solution for identifying and verifying vulnerabilities
Pros and Cons
  • "Invicti's best feature is the ability to identify vulnerabilities and manually verify them."
  • "Invicti takes too long with big applications, and there are issues with the login portal."

What is our primary use case?

I primarily use Invicti for onboarding on the performance side.

What is most valuable?

Invicti's best feature is the ability to identify vulnerabilities and manually verify them.

What needs improvement?

Invicti takes too long with big applications, and there are issues with the login portal.

For how long have I used the solution?

I've been using Invicti for four to five years.

What do I think about the stability of the solution?

Invicti sometimes stops working when dealing with large applications.

How was the initial setup?

The initial setup was easy.

What other advice do I have?

I would give Invicti a rating of nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1286490 - PeerSpot reviewer
Consultant Cyber Security at a tech services company with 51-200 employees
Consultant
Oct 7, 2020
A fast solution that is easy to deploy, configure, and use
Pros and Cons
  • "I am impressed by the whole technology that they are using in this solution. It is really fast. When using netscan, the confirmation that it gives on the vulnerabilities is pretty cool. It is really easy to configure a scan in Netsparker Web Application Security Scanner. It is also really easy to deploy."
  • "They don't really provide the proof of concept up to the level that we need in our organization. We are a consultancy firm, and we provide consultancy for the implementation and deployment solutions to our customers. When you run the scans and the scan is completed, it only shows the proof of exploit, which really doesn't work because the tool is running the scan and exploiting on the read-only form. You don't really know whether it is actually giving the proof of exploit. We cannot prove it manually to a customer that the exploit is genuine. It is really hard to perform it manually and prove it to the concerned development, remediation, and security teams. It is currently missing the static application security part of the application security, especially web application security. It would be really cool if they can integrate a SAS tool with their dynamic one."
  • "They don't really provide the proof of concept up to the level that we need in our organization."

What is most valuable?

I am impressed by the whole technology that they are using in this solution. It is really fast. When using netscan, the confirmation that it gives on the vulnerabilities is pretty cool.

It is really easy to configure a scan in Netsparker Web Application Security Scanner. It is also really easy to deploy.

What needs improvement?

They don't really provide the proof of concept up to the level that we need in our organization. We are a consultancy firm, and we provide consultancy for the implementation and deployment solutions to our customers. When you run the scans and the scan is completed, it only shows the proof of exploit, which really doesn't work because the tool is running the scan and exploiting on the read-only form. You don't really know whether it is actually giving the proof of exploit. We cannot prove it manually to a customer that the exploit is genuine. It is really hard to perform it manually and prove it to the concerned development, remediation, and security teams.

It is currently missing the static application security part of the application security, especially web application security. It would be really cool if they can integrate a SAS tool with their dynamic one.

For how long have I used the solution?

We started to use Netsparker Web Application Security Scanner in February of this year. We are using its latest version.

What do I think about the stability of the solution?

It is pretty stable. 

What do I think about the scalability of the solution?

It is scalable.

How are customer service and technical support?

We engage with the local partner and the distributor here for support. We are satisfied with the support here.

How was the initial setup?

The initial setup wasn't a problem for me. I have been using these security tools for a while now.

Which other solutions did I evaluate?

I also use Micro Focus Fortify. The difference is mainly in the UI. I haven't really got into the comparison between the output of the scans, but I was really impressed by the UI and the ease of use of Netsparker Web Application Security Scanner.

What other advice do I have?

I would recommend this solution. I haven't really researched other products, but for me, Netsparker Web Application Security Scanner is a benchmark right now.

I would rate Netsparker Web Application Security Scanner an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1286490 - PeerSpot reviewer
Consultant Cyber Security at a tech services company with 51-200 employees
Consultant
Oct 6, 2020
A good interface that makes it easy to use, and the tool is really fast
Pros and Cons
  • "This tool is really fast and the information that they provide on vulnerabilities is pretty good."
  • "Right now, they are missing the static application security part, especially web application security."

What is our primary use case?

We are a consulting firm and we provide implementation and deployment of solutions to our customers.

What is most valuable?

I am very much impressed by the whole technology.

This tool is really fast and the information that they provide on vulnerabilities is pretty good.

The UI is good and it is really easy to use.

What needs improvement?

With respect to the algorithm that Netsparker is running, they don't really provide the proof of concept up to the level that we need, here in the organization. Specifically, because the tool is running the scan and exploiting the read-only version, it doesn't prove to the customer that the exploit is genuine. We have to perform this manually, but it is difficult to prove to the concerned team, whether it is the development team, the remediation team, or the security team.

Right now, they are missing the static application security part, especially web application security. If they can integrate a SaaS tool with their dynamic one then it would be really helpful.

For how long have I used the solution?

I have been working with Netsparker for several months.

What do I think about the stability of the solution?

We have not experienced any bugs or glitches, so it seems stable.

What do I think about the scalability of the solution?

Scalability-wise, it is pretty good.

How are customer service and technical support?

We have been engaged with the local partner and we get a good level of support.

Which solution did I use previously and why did I switch?

We also use Micro Focus Fortify and I have not had a chance to compare the scans, but I prefer the interface and ease of use with Netsparker. It is really easy to configure and deploy, as well as communicate this to the client.

How was the initial setup?

The initial setup was not a problem for me, as I have been using these security tools for a while.

What other advice do I have?

Overall, I am satisfied with Netsparker. However, I cannot say at this point that I would recommend it because although it is good, I will now be using it as a benchmark for evaluating other products.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Retail Services Senior Manager at e-finance
Real User
May 11, 2020
Very high level of accuracy and speedy scanning
Pros and Cons
  • "High level of accuracy and quick scanning."
  • "The most valuable features that I've found in this solution was the level of accuracy and also that the process of scanning was very quick and we're easily able to change the frame of a scan."
  • "Improvement could be made in the area of production."

What is our primary use case?

Our primary use case is for web applications but rather than being in a production environment, it's in a testing environment. We check for vulnerabilities found in the test environment and remediate them. Following that, we publish the web application for web production. We are customers of Netsparker and I'm the retail services senior manager.

What is most valuable?

The most valuable features that I've found in this solution was the level of accuracy and also that the process of scanning was very quick and we're easily able to change the frame of a scan. I use the many applications and security management tools and the accuracy is important for me. Other solutions like NetBus don't have such an accurate timeline. 

What needs improvement?

Improvement could be made in the area of production. Features like macro recording that I've used in other solutions would improve this product. Recording macro for complex applications, especially web applications where there is a complex web application for login or logout format. We could record the macro for login to make a dynamic scanning process, which makes it easier to scan methodology. We need to be able to record the macro. I think a feature like that would add a lot to the solution. 

For how long have I used the solution?

I've been using this solution for three months.

What do I think about the stability of the solution?

I think the stability of Netsparker enterprise product is very cool. And the application scanning was very successful. No time outs, no downtime the stability and the service was very, very good. 

How are customer service and technical support?

I'm satisfied with the technical support. 

How was the initial setup?

Initial setup was straightforward and didn't take much time. It was smooth and successful. 

What other advice do I have?

This is not a simple solution, there is a complexity there. A lot of companies here don't like the idea of using a cloud provider or cloud application for scanning. We prefer to have stand-alone applications and not use the cloud. It's something they could offer, like Qualys.

I would rate this solution an eight out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1188708 - PeerSpot reviewer
Senior Quality Control Manager at a insurance company with 51-200 employees
Real User
Nov 14, 2019
Great reporting review tool and very stable with an easy initial setup
Pros and Cons
  • "The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports."
  • "I'd recommend Netsparker for anyone who wants to make a security assessment for web applications."
  • "The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them."

What is our primary use case?

We're primarily used the solution as a proof of concept using it for assessing the security of one of our web applications.

What is most valuable?

The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports.

What needs improvement?

The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them.

For how long have I used the solution?

I've been using the solution for about two months.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

As I was only working on the demo version of the solution, I can't speak to how scalable it would be.

How are customer service and technical support?

The technical support team was very helpful. They offered me a demo before I started using the tool, and the demo was very impressive.

Which solution did I use previously and why did I switch?

We previously used a different tool, but it was also a demo, like Netsparker. We wanted to try Netsparker, so we moved to their demo.

How was the initial setup?

The initial setup was straightforward.

What about the implementation team?

I handled the implementation myself.

Which other solutions did I evaluate?

I tried some different tools. Some of them were full versions whereas others were demo versions like Netsparker.

What other advice do I have?

We're using a demo of the latest version for a POC. We used the on-premises deployment model.

I'd recommend Netsparker for anyone who wants to make a security assessment for web applications.

I'd rate the solution nine out of ten. The tool is full of useful features. However, the intercepting reviews in terms of web requests need some enhancements to be more usable.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Founder at a tech services company with self employed
Real User
Aug 21, 2019
Has a low number of false positives but the program should be more affordable
Pros and Cons
  • "One of the features I like about this program is the low number of false positives and the support it offers."
  • "Netsparker doesn't provide the source code of the static application security testing."

What is our primary use case?

Our primary use case of this solution is to assess the security of our web application security.

What is most valuable?

One of the features I like about this program is the low number of false positives and the support it offers. 

What needs improvement?

The program uses technology that is different from application scanners. It's not an incremental solution. It could be a new product, but I'm not that knowledgeable to know which products are part of a suite. Netsparker doesn't provide the source code of the static application security testing. I would love to see a completion of the offering with statistical analysis. 

Every customer has its own nuance, so I don't think it's really an issue when it comes to the user interface. Every customer has something that they would like different because they're used to something different. In my opinion, there is not very much to mention besides changing as little as possible. Something that Microsoft often does, is to change things with every release and users don't like that. 

I would also see the price being at least 20% cheaper because the market is currently very crowded and there are many vendors and clients. A lower price will get more sales. 

For how long have I used the solution?

I have been using Netsparker for almost ten years now.

What do I think about the stability of the solution?

The solution is quite stable.

What do I think about the scalability of the solution?

When it comes to scalability, we tend to do one test at a time. It could be faster but there is always a trade-off between speed and accuracy. Accuracy is more important than speed.

How are customer service and technical support?

I rate the technical support seven out of ten, which is average to me. I don't have special requests that would stress a support team and so far my issues were resolved in a reasonable time. Should I have an emergency, I believe they will be very responsive.

How was the initial setup?

The initial setup is quite straightforward.

What other advice do I have?

There are many average products on the market, but I prefer Netsparker because to me wasting time after false positives is the worst thing that can happen. Accuracy is the most important thing to me. I rate Netsparker eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Specialist at Alfa-A IT
Real User
Jul 15, 2019
Powerful Crawler generates close to a full sitemap, including web services
Pros and Cons
  • "It correctly parses DOM and JS and has really good support for URL Rewrite rules, which is important for today's websites."
  • "Netsparker has done an awesome job with its crawler, as it has found all of the links (also thanks to its good DOM parser)."
  • "The scanner itself should be improved because it is a little bit slow."

What is our primary use case?

I use this solution for automated web application testing, and upon the first sight of the web app. I work alone in my company, so a helping hand is always useful. Netsparker did the job.

I use it principally for mapping the web application attack surface using its really good crawler.

How has it helped my organization?

Netsparker has done an awesome job with its crawler, as it has found all of the links (also thanks to its good DOM parser).

It has helped me a great deal on a first try over websites.

Netsparker made my work a lot easier in mapping web applications.

What is most valuable?

The most valuable feature is the crawler because it can found many links and generate close to a full sitemap.

It correctly parses DOM and JS and has really good support for URL Rewrite rules, which is important for today's websites.

It also parses web services like SOAP, REST API, WSDL, and more.

Another thing I really like about Netsparker is the payload list that covers, including every type of vulnerability.

Netsparker Hawk is another good "tool", as it helped me locate some easy-to-find SSRF and XXE vulnerabilities in production websites. Its technology is really good and works well. OOB (Out Of Band) payloads work well.

What needs improvement?

The scanner itself should be improved because it is a little bit slow.

CPU usage should be improved due to my PC's fan going mad.

RAM usage also should be improved as well.

The attacker part of the scanner should be more fluid and faster.

There should be some option to tune up the scan, like throttling requests or using some WAF/IDS/IPS bypass technique. It needs more than what is currently in the Advanced Options.

The passive analyzer for some vulnerabilities should be improved, as it doesn't get all vulnerabilities. It should also be more efficient.

The scanner should also use some cool techniques to inject payloads, like replacing the entire body and Content-Type header (like for XML input).

For how long have I used the solution?

Several months.

How are customer service and technical support?

The customer service is good.

There are some problems with languages (like for Italian they send you people who can speak Italian just a bit, but it's ok).

Which solution did I use previously and why did I switch?

I have used Burp Suite Professional and Acunetix.

I switched to Netsparker just to try it and understand how it works.

How was the initial setup?

The setup is really easy and straightforward.

What about the implementation team?

For the trial, Netsparker itself contacted me by phone. Their support is really nice and helpful.

What's my experience with pricing, setup cost, and licensing?

I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on.

Which other solutions did I evaluate?

I did not evaluate other options.

What other advice do I have?

You can use Netsparker but use it carefully as some payloads can be dangerous in production. This is the same as Acunetix, WebInspect, and others.

Every scanner should have an option like Burp Suite to use dangerless payloads (with Distribute Damage extension).

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Invicti Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2026
Buyer's Guide
Download our free Invicti Report and get advice and tips from experienced pros sharing their opinions.