Try our new research platform with insights from 80,000+ expert users

Fortify WebInspect vs Invicti comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortify WebInspect
Ranking in Dynamic Application Security Testing (DAST)
2nd
Average Rating
7.2
Reviews Sentiment
6.8
Number of Reviews
20
Ranking in other categories
DevSecOps (8th)
Invicti
Ranking in Dynamic Application Security Testing (DAST)
3rd
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
28
Ranking in other categories
Static Application Security Testing (SAST) (14th), API Security (5th)
 

Mindshare comparison

As of January 2025, in the Dynamic Application Security Testing (DAST) category, the mindshare of Fortify WebInspect is 28.4%, down from 34.1% compared to the previous year. The mindshare of Invicti is 17.1%, up from 13.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Navin N - PeerSpot reviewer
Effective scanning of diverse file extensions with fast reporting and issue resolution
We develop software packages for clients, and these clients are mostly in the BFSI sector. The packages need to be scanned, and we engage Fortify WebInspect for this.  Customers typically perform their own application pen tests, but in some cases, we have engagements where customers want us to scan…
JanetMuhia - PeerSpot reviewer
Streamlined our security efforts by allowing us to integrate with tools like Jira
From my experience, Invicti is an exceptionally stable solution for web application security. Here's what stands out: * Consistent Performance: Over the three years we’ve used it, the solution has demonstrated reliable and consistent performance, even during large-scale scanning operations. * Minimal Downtime: I have not encountered significant downtime or disruptions while using Invicti, which is critical for security tools that organizations rely on continuously. * Robust Architecture: Its ability to handle complex scanning tasks without crashes or lag reflects its well-engineered platform. * Regular Updates: Invicti frequently releases updates and patches, which enhance functionality and address any stability concerns proactively. Rating : I would confidently rate Invicti’s stability at 9.5 out of 10. It ensures uninterrupted operations and supports high-performance demands, which are essential for enterprise environments.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The accuracy of its scans is great."
"When we are integrating it with SSC, we're able to scan and trace and see all of the vulnerabilities. Comparison is easy in SSC."
"It's a well-known platform for doing dynamic application scanning."
"Good at scanning and finding vulnerabilities."
"I've found the centralized dashboard the most valuable. For the management, it helps a lot to have abilities at the central level."
"Reporting, centralized dashboard, and bird's eye view of all vulnerabilities are the most valuable features."
"The solution is able to detect a wide range of vulnerabilities. It's better at it than other products."
"The solution's technical support was very helpful."
"The platform is stable."
"The scanner and the result generator are valuable features for us."
"The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports."
"The scanner is light on the network and does not impact the network when scans are running."
"High level of accuracy and quick scanning."
"When we try to manually exploit the vulnerabilities, it often takes time to realize what's going on and what needs to be done."
"It has very good integration with the CI/CD pipeline."
"I like that it's stable and technical support is great."
 

Cons

"One thing I would like to see them introduce is a cloud-based platform."
"Creating reports is very slow and it is something that should be improved."
"Our biggest complaint about this product is that it freezes up, and literally doesn't work for us."
"There are some file extensions, like .SER, that Fortify WebInspect doesn't scan."
"The solution needs better integration with Microsoft's Azure Cloud or an extension of Azure DevOps. In fact, it should better integrate with any cloud provider. Right now, it's quite difficult to integrate with that solution, from the cloud perspective."
"We have often encountered scanning errors."
"It requires improvement in terms of scanning. The application scan heavily utilizes the resources of an on-premise server. 32 GB RAM is very high for an enterprise web application."
"A localized version, for example, in Korean would be a big improvement to this solution."
"The scanning time, complexity, and authentication features of Invicti could be improved."
"Maybe the ability to make a good reporting format is needed."
"Currently, there is nothing I would like to improve."
"Right now, they are missing the static application security part, especially web application security."
"Invicti takes too long with big applications, and there are issues with the login portal."
"They need to improve their support in the documentation. Their support mechanism is missing. Their responsiveness, technical staff, and these types of things need to be improved, and comprehensive documentation is required. They should have good self-service portal enhancement"
"The scannings are not sufficiently updated."
"Reporting should be improved. The reporting options should be made better for end-users. Currently, it is possible, but it's not the best. Being able to choose what I want to see in my reports rather than being given prefixed information would make my life easier. I had to depend on the API for getting the content that I wanted. If they could fix the reporting feature to make it more comprehensive and user-friendly, it would help a lot of end-users. Everything else was good about this product."
 

Pricing and Cost Advice

"The pricing is not clear and while it is not high, it is difficult to understand."
"This solution is very expensive."
"Our licensing is such that you can only run one scan at a time, which is inconvenient."
"Fortify WebInspect is a very expensive product."
"The price is okay."
"It’s a fair price for the solution."
"Its price is almost similar to the price of AppScan. Both of them are very costly. Its price could be reduced because it can be very costly for unlimited IT scans, etc. I'm not sure, but it can go up to $40,000 to $50,000 or more than that."
"We never had any issues with the licensing; the price was within our assigned limits."
"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
"It is competitive in the security market."
"The price should be 20% lower"
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
"The solution is very expensive. It comes with a yearly subscription. We were paying 6000 dollars yearly for unlimited scans. We have three licenses; basic, business, and ultimate. We need ultimate because it has unlimited scan numbers."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"OWASP Zap is free and it has live updates, so that's a big plus."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
16%
Government
13%
Manufacturing Company
13%
Educational Organization
56%
Financial Services Firm
8%
Computer Software Company
6%
Manufacturing Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortify WebInspect?
The solution's technical support was very helpful.
What is your experience regarding pricing and costs for Fortify WebInspect?
Fortify WebInspect can be a bit expensive. However, considering its stability and reliability in meeting current standards, the cost is justified. Still, making the cost more affordable for multipl...
What needs improvement with Fortify WebInspect?
I would like WebInspect's scanning capability to be quicker. Specifically, being able to scan a particular flow or part of an application more rapidly would be beneficial. Additionally, the cost of...
What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
As a technical user, I do not handle pricing or licensing, but I am aware that Invicti offers flexible licensing models based on organizational needs.
What do you like most about Invicti?
The most valuable feature of Invicti is getting baseline scanning and incremental scan.
What needs improvement with Invicti?
Currently, there is nothing I would like to improve.
 

Also Known As

Micro Focus WebInspect, WebInspect
Netsparker
 

Learn More

 

Overview

 

Sample Customers

Aaron's
Samsung, The Walt Disney Company, T-Systems, ING Bank
Find out what your peers are saying about Fortify WebInspect vs. Invicti and other solutions. Updated: November 2024.
831,158 professionals have used our research since 2012.