Try our new research platform with insights from 80,000+ expert users

Invicti vs NGINX App Protect comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Invicti
Ranking in API Security
5th
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
29
Ranking in other categories
Static Application Security Testing (SAST) (15th), Dynamic Application Security Testing (DAST) (3rd)
NGINX App Protect
Ranking in API Security
2nd
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
24
Ranking in other categories
Web Application Firewall (WAF) (15th), Container Security (18th)
 

Mindshare comparison

As of April 2025, in the API Security category, the mindshare of Invicti is 2.5%, up from 2.0% compared to the previous year. The mindshare of NGINX App Protect is 3.0%, down from 5.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
API Security
 

Featured Reviews

Kunal M - PeerSpot reviewer
Proactive scanning measures and realistic audit recommendations enhance development focus
Invicti's proactive scanning measures vulnerabilities each time we deploy or push code to a new environment. This feature helps us focus on priorities and prioritize the development team's effort, integrating seamlessly with DevOps to facilitate proactive scans of environments. Invicti also provides audit recommendations that are quite realistic, making it easy to discuss plans with developers.
Saurav Kumar - PeerSpot reviewer
Offers protection to users from external threats
NGINX App Protect secures our company's application, and it has helped me a lot, considering that we have critical infrastructure in India where we see how lots of attacks come onto our organization's servers. The tool offers protection against multiple threats present in India's IT ecosystem. The tool helps our company to make our payments secure, meaning it has the ability to provide a secure payment environment in India. Speaking about the improvements in our company's application performance since implementing NGINX App Protect, the gRPC support for the solution is very low. My company is not getting any proper documentation on how to deploy gRPC over NGINX App Protect. I recommend the product to those who plan to use it. People can use the product as their company's base server, WAF, or for its proxy manager, depending on the business requirements. My company follows PCI DSS compliance because we operate in a payment-related industry. Right now, my company follows all the standards, so we comply with all the requirements and policies. I rate the tool an eight out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the features I like about this program is the low number of false positives and the support it offers."
"High level of accuracy and quick scanning."
"Invicti's proactive scanning measures vulnerabilities each time we deploy or push code to a new environment."
"I like that it's stable and technical support is great."
"The most valuable feature of Invicti is getting baseline scanning and incremental scan."
"Its ability to crawl a web application is quite different than another similar scanner."
"The scanner and the result generator are valuable features for us."
"The scanner is light on the network and does not impact the network when scans are running."
"The most valuable feature of NGINX App Protect is the reverse proxy."
"NGINX App Protect is stable."
"The stability of the product is very impressive since it handles 60,000 to 70,000 requests or transactions per second."
"It has the best documentation features."
"NGINX App Protect's best features are auto-learning, which creates a profile of applications that are deployed, bot protection, and force protection, which lets you configure your brute force policy and alert for and prevent brute force attacks."
"The tool is not complex and is very user-friendly."
"The tool's most valuable feature is the OWASP certification. Additionally, the tool's ability to enforce strong passwords and OTP within minutes is impressive. With its analytics and recommendations, it is a very good solution."
"WAF is useful to track mitigation, inclusion, prevention, and the parametric firewall."
 

Cons

"The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them."
"The solution's false positive analysis and vulnerability analysis libraries could be improved."
"The scannings are not sufficiently updated."
"The custom attack preparation screen might be improved."
"Netsparker doesn't provide the source code of the static application security testing."
"The solution needs to make a more specific report."
"Invicti's reporting capabilities need enhancement. We need enterprise-level information instead of repo-level details. Unlike Appiro, Invicti does not provide portfolio-level insights into vulnerability remediation over time."
"The scanner itself should be improved because it is a little bit slow."
"Areas for improvement would be if NGINX could scan for vulnerabilities and learn and update the signatures of DoS attacks."
"It's challenging if you need to go for a high throughput."
"Setting policies and parameters through the UI should be more automated because the process is manual, where we can only edit one rule at a time."
"It would be better if it were easier to implement and if there was more information from F5 regarding hardware requirements and specifications to deploy the service, to avoid disruptions after implementation."
"The product's user interface is an area with shortcomings as it can be quite confusing for users, making it an area where improvements are required."
"The product's price is high, making it an area of concern where improvements are required. The tool's licensing model is also not good."
"Its technical support could be better."
"Right now, the tool doesn't provide an option revolving around update feeds, specifically the signature update option in the UI."
 

Pricing and Cost Advice

"We never had any issues with the licensing; the price was within our assigned limits."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"The solution is very expensive. It comes with a yearly subscription. We were paying 6000 dollars yearly for unlimited scans. We have three licenses; basic, business, and ultimate. We need ultimate because it has unlimited scan numbers."
"It is competitive in the security market."
"The price should be 20% lower"
"OWASP Zap is free and it has live updates, so that's a big plus."
"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
"The product's price is high."
"NGINX App Protect is expensive."
"Our licensing costs are about $40,000 a year."
"There are no additional fees."
"There is a license needed to use NGINX App Protect."
"The licensing fees for this solution are pretty expensive for what it does, but there is no alternative."
"There is a monthly or annual subscription to use NGINX App Protect. There are not any additional costs to the subscription."
"Really understand the licensing model, because we underestimated that."
report
Use our free recommendation engine to learn which API Security solutions are best for your needs.
845,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
52%
Financial Services Firm
9%
Computer Software Company
7%
Manufacturing Company
4%
Computer Software Company
19%
Financial Services Firm
14%
Comms Service Provider
7%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
As a technical user, I do not handle pricing or licensing, but I am aware that Invicti offers flexible licensing models based on organizational needs.
What do you like most about Invicti?
The most valuable feature of Invicti is getting baseline scanning and incremental scan.
What needs improvement with Invicti?
Invicti's reporting capabilities need enhancement. We need enterprise-level information instead of repo-level details. Unlike Appiro, Invicti does not provide portfolio-level insights into vulnerab...
What is your experience regarding pricing and costs for NGINX App Protect?
I don't know the pricing yet because in my other project, I was not part of the buying side and I was just starting to look at options.
What needs improvement with NGINX App Protect?
It would be better if it were easier to implement and if there was more information from F5 regarding hardware requirements and specifications to deploy the service, to avoid disruptions after impl...
 

Also Known As

Netsparker
NGINX WAF, NGINX Web Application Firewall
 

Overview

 

Sample Customers

Samsung, The Walt Disney Company, T-Systems, ING Bank
Information Not Available
Find out what your peers are saying about Invicti vs. NGINX App Protect and other solutions. Updated: March 2025.
845,406 professionals have used our research since 2012.