About Invicti
Invicti is an application security platform, formerly known as Netsparker, that tests websites, web applications and APIs for vulnerabilities. It describes itself as DAST-first, meaning it tests running applications the way an attacker would and tries to prove that findings are exploitable to reduce false alarms.
Around that core, the platform now includes scanning of code before runtime: static analysis, open source dependency analysis, SBOM and license risk tracking, secrets detection, infrastructure as code and container image checks. Runtime testing covers DAST and AI-assisted DAST, agentic pentesting, API security testing, attack surface management and cloud application security. A vulnerability management layer correlates findings from these tools and supports compliance and executive reporting.
Invicti is a commercial enterprise product with pricing and demo pages, plus resources such as documentation, a vulnerability database, training, a savings calculator and managed security provider and partner programs.
Key features
- Dynamic application security testing
- Exploitability proof for scanner findings
- API discovery and security testing
- Static analysis and open source dependency checks
- SBOM and license risk tracking
- Attack surface management
- Vulnerability correlation and compliance reporting
Good fit for
- →Enterprise AppSec teams scanning thousands of web apps
- →Developers verifying API security before release
- →MSSPs offering web application testing
- Tags
- dast
- application-security
- api-security
- vulnerability-scanner
- sast
- sca
- netsparker
Open-source alternatives to Invicti
See all
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
OpenVAS
Security
This repository contains the scanner component for Greenbone Community Edition.
GPL-2.0vs Tenable★ 4.8k
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Infisical
Security
Infisical is the open-source platform for secrets, certificates, and privileged access man
OSSvs Doppler★ 30k
SafeLine
Security
CyberServal open-source WAF is a self-hosted WAF with 20.9K GitHub stars. Block SQL inject
GPL-3.0vs Cloudflare★ 23k
SaaS alternatives to Invicti
See allVeracode
Security
Application security testing platform covering static, dynamic and software composition
SaaS
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaSRapid7
Security
Vulnerability management, SIEM and managed detection tools for security teams
SaaS
Tenable
Security
Vulnerability management and exposure assessment, maker of the Nessus scanner
SaaS
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaS
Intruder
Security
Cloud-based vulnerability scanner for external attack surface
SaaS

