Overview
Invicti merged DAST market leaders Netsparker and Acunetix into a new scalable Application Security Platform. By combining both solutions with AI enhancements and expanded capabilities the industrys leading DAST solutions are now a powerful complete AppSec platform featuring:
Dynamic interactive and static security testing within a single platform
Web app shadow API and LLM discovery and scanning
Detection of more high and critical vulnerabilities with the help of AI
All vulnerabilities in a single view with remediation orchestration for complete risk posture management
Invicti combines its industry leading coverage accuracy and speed with visibility and orchestration integrated into every step of your SDLC at the scale you need. With DAST at the center you are not just getting another security tool you are getting a runtime force multiplier for your entire AppSec program.
For Enterprise customers with custom pricing EULA or a private offer please contact tackle@invicti.com .
Highlights
- AI-powered proof-based scanning verifies over 94% of direct-impact vulnerabilities with 99.98% accuracy, eliminating false alarms and enabling teams to fix issues without wasting time on verification.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Acunetix Online Premium | QTY 5 Targets (FQDN = website, web application, API, or web services) | $7,000.00 |
Acunetix MSSP License | Acunetix Managed Security Service Provider License | $15,960.00 |
Invicti Ent On Demand | QTY 50 Targets (FQDN = website, web application, API, or web services) | $37,000.00 |
Invicti Ent On Premise | QTY 50 Targets (FQDN = website, web application, API, or web services) | $37,000.00 |
Premium Support | Premium Support | $150,000.00 |
Prem SPT & Guided Suc | Premium Support and Guided Success | $300,000.00 |
Invicti ASPM | License for Invicti ASPM offering. 150 Users and Targets. | $60,000.00 |
Vendor refund policy
Fees will be due and payable as set forth on the Order Form, and Customer agrees to timely pay all fees. Payment obligations are non-cancelable, and fees paid are non-refundable.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Accurate web scans have reduced attacks and provide actionable vulnerability reports
What is our primary use case?
What is most valuable?
In my opinion, the best feature Acunetix offers is that it provides correct findings. When I say correct findings, I mean the accuracy of its vulnerability detection.
Acunetix provides reporting with many types of reporting options.
Acunetix has positively impacted my organization by providing the web vulnerabilities so we can patch them to stop attacks. By helping me patch vulnerabilities, Acunetix has led to measurable outcomes like time saved and fewer incidents.
What needs improvement?
I think Acunetix needs improvement since it is now working with Invicti , so the price list will need to be reconsidered.
For how long have I used the solution?
I have been using Acunetix for about four years.
What do I think about the stability of the solution?
Acunetix is stable. I did not need to reach customer support because the product is very stable.
What do I think about the scalability of the solution?
Acunetix's scalability for my growing needs is great; it is a very scalable product compared to others.
How are customer service and support?
Acunetix integrates well with other security tools or platforms I use, as we have integrated it with a ticketing system and vulnerability patching system.
Acunetix handles updates and new vulnerability signatures automatically.
The reporting functionality for compliance or audit requirements covers what I need.
I am very satisfied with the frequency and quality of product updates from Acunetix.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Acunetix.
How was the initial setup?
It is easy to set up Acunetix in my environment. I would describe the learning curve for new users on my team as manageable because it provides admin guides and very useful documentation for learning and hands-on training for this product.
What about the implementation team?
I purchased Acunetix through the AWS Marketplace .
What was our ROI?
I have seen a return on investment, as I can share relevant metrics like money or time saved and fewer people needed.
What's my experience with pricing, setup cost, and licensing?
The experience with pricing, setup cost, and licensing has been that the setup cost and pricing need to be reconsidered.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Acunetix.
What other advice do I have?
My advice to others looking into using Acunetix is that it is really helpful to discover the web attacks and have great, powerful reporting so you can have reduced incidents to look at. I have rated this review a 10.
Accurate web vulnerability scans have strengthened our critical application security posture
What is our primary use case?
What is most valuable?
Acunetix's best features are scalability and accuracy on provided vulnerabilities.
The scalability of Acunetix is impressive, and accuracy is one of the best features because I do not waste time verifying each provided vulnerability from Acunetix.
Acunetix has positively impacted my organization by providing updates on vulnerabilities in our web security and web application servers.
Since implementing Acunetix, I have seen improvements as we have discovered real vulnerabilities and threats on our web application server, which is very critical to our organization.
What needs improvement?
Acunetix may need to reconsider the cost or price compared to other vendors.
For how long have I used the solution?
I have been using Acunetix for three years.
What do I think about the stability of the solution?
Acunetix is stable.
What do I think about the scalability of the solution?
Acunetix has great scalability.
How are customer service and support?
I did not need to reach customer support because the product is very effective.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I previously used Nessus, and I stopped using it and switched to Acunetix.
What was our ROI?
I have seen a return on investment with Acunetix, including time saved and cost reduction, because it provides us threats on our web application servers.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it is somewhat high.
What other advice do I have?
I would rate Acunetix a 10 out of 10.
I gave Acunetix a 10 because of its accuracy.
My advice to others looking into using Acunetix is that it will be one of the best web vulnerability scanners, providing accuracy on proposed vulnerabilities and discovered vulnerabilities.
My overall review rating for Acunetix is 10.
Excellent Security Tool with Continuous Improvements
Saves significant assessment time with automated scans but requires manual effort to filter false positives
What is our primary use case?
Acunetix has primarily been used for application security, and it has also been used for vulnerability management, though not as extensively because Qualys Guard Total Cloud solution was being used for scanning cloud assets.
Qualys Total Cloud was used to scan cloud assets. Earlier, when using CLI tools like Troller, there was not much visibility because the reporting section from the CLI tool was not that helpful. However, when using Qualys Guard, the Total Cloud offered advanced reporting features and had the option to share vulnerability reports directly via email, allowing the end participant's email address to be entered for automatic report delivery.
What is most valuable?
The crawling option in Acunetix is really good because whenever a scan is initiated, the crawling option provides good coverage about the vulnerabilities identified in the application. The attack option that comes after crawling is quite good. When the application is configured in authenticated scan mode with Acunetix, it provides good visibility about the security vulnerabilities in the application.
The experience with Qualys Total Cloud was really good, as when Qualys Guard was used to scan cloud security assets, it identified the vulnerabilities and helped differentiate between valid findings and invalid findings. Qualys Guard is called Total Cloud, which means cloud assets are scanned regardless of any environment, whether it is GCP, AWS , or Azure .
What needs improvement?
Improving the handling of false positives would be beneficial because it can be challenging to trust the findings flagged by Acunetix, and those findings must be manually validated. Sometimes the scanner shows a vulnerability count exceeding 100, and manually assessing the findings can be quite a challenge.
The main concern is related to false positives; Acunetix needs to work on identifying valid and invalid findings. While Checkmarx has very good coverage, its pricing is quite high. If Acunetix improves in handling false positives, it will make a significant impact in the security world.
For how long have I used the solution?
Acunetix has been used for a long time, about five to six years, along with Netsparker and other automated scanners.
What do I think about the stability of the solution?
The experience has been pretty smooth without crashes, downtimes, or performance issues with Acunetix.
What do I think about the scalability of the solution?
Acunetix is quite scalable.
How are customer service and support?
The tech support from Invicti for Acunetix is really good. Whenever a support ticket is raised, their SLA is quite nice. For high-severity issues, they reach out within two to three hours, and for critical issues, a response is received within 15 minutes.
The tech support would be rated an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
As far as experience is concerned, only Checkmarx SAST tool has been worked on, and no other Checkmarx products like Checkmarx One are used.
Rapid7 Nexpose has been used, but no other Rapid7 products have been explored. Additionally, Qualys Guard and Qualys VMDR Vulnerability Management Detection Response solution have been worked on.
How was the initial setup?
The setup process for Acunetix is not that complicated, and Acunetix support can always be reached out to. Whenever Acunetix is onboarded in the environment, the Acunetix team assists with the installation, making the setup quite easy.
What's my experience with pricing, setup cost, and licensing?
The pricing cost is affordable for small and mid-sized organizations, and when compared to Checkmarx, it is significantly affordable, as Checkmarx is quite expensive.
The cost-effectiveness is really good because it comes under the budget of organizations looking to use automated scanners, which really helps and saves time.
What other advice do I have?
Currently, work is being done with AWS cloud security and application security tools such as Burp Suite, and various automated scanners such as Netsparker and Acunetix are also being used, along with vulnerability scanning tools such as Nessus Professional and Rapid7 Nexpose.
Acunetix is good, even though there have been some issues related to false positives. Whenever an automated scanner like Netsparker or Acunetix is used, it takes time to run the scan. Once the scan is completed, the false positives flagged by the scan need to be identified. Acunetix is a good tool because if there is less time and the team needs to perform the security assessment, a manual assessment will take almost a week to assess a large application. However, when an automated scanner like Acunetix is used, the same task can be done within three to four days. Authenticated scans are usually preferred with any automated scanner like Acunetix because it provides much visibility about the application on which the scan is initiated, and the results from authenticated scans are very good compared to unauthenticated scans.
Acunetix was used recently, about three months ago.
Acunetix was not used for AWS because various other AWS solutions are available to determine the vulnerabilities for cloud, primarily using AWS Inspector to scan the AWS cloud. Security Hub is also used to measure cloud security posture management, so when it comes to scanning the cloud, AWS Inspector is primarily used.
Acunetix was hosted on the AWS cloud because when the application was scanned, it was not an on-premises solution; the applications hosted in AWS cloud were scanned using Acunetix.
The integration part has not been explored much because other tools are available, but Acunetix supports YAML files that can be used to integrate those scans into the CI/CD pipeline. However, Acunetix scans have not been integrated into the CI/CD pipeline.
The Acunetix network security component has not been used.
If there is less time to perform manual security assessments, Acunetix is a good option because if a manual security assessment takes almost a week, the same task with Acunetix can be completed within three to four days, which really saves time for the entire team. The results are faster and interactive reports generated by the dashboard can be shared. This helps improve the overall security posture.
The features present in Acunetix are quite good and serve the purpose well.
Acunetix is definitely recommended for scanning, and if someone asks whether they should use Acunetix to mitigate the threats identified in their applications hosted in AWS cloud, it would definitely be recommended.
When the continuous scan approach is used for security compliance, it really helps because the scan is not paused for any reason, like if the application goes down. With the continuous scan operation, the application is continuously assessed by the scan engine of Acunetix, and the results from the continuous scan feature are quite good. The continuous scanning feature has been used.
If an organization has 100 plus applications and wants to use an automated scanner, they should definitely go ahead with Acunetix because it is very cost-effective and will save time compared to focusing on other solutions and performing manual security assessments.
The recommendation for other organizations considering Acunetix depends upon their requirements.
This review has been given a rating of 7 out of 10.