6,598 open-source and SaaS tools, with GitHub stats refreshed every day.

Invicti

SaaS

Invicti, formerly Netsparker, is a web application security platform built around automated DAST scanning, with code, API and attack surface testing.

invicti.com
Invicti homepage screenshot

About Invicti

Invicti is an application security platform, formerly known as Netsparker, that tests websites, web applications and APIs for vulnerabilities. It describes itself as DAST-first, meaning it tests running applications the way an attacker would and tries to prove that findings are exploitable to reduce false alarms.

Around that core, the platform now includes scanning of code before runtime: static analysis, open source dependency analysis, SBOM and license risk tracking, secrets detection, infrastructure as code and container image checks. Runtime testing covers DAST and AI-assisted DAST, agentic pentesting, API security testing, attack surface management and cloud application security. A vulnerability management layer correlates findings from these tools and supports compliance and executive reporting.

Invicti is a commercial enterprise product with pricing and demo pages, plus resources such as documentation, a vulnerability database, training, a savings calculator and managed security provider and partner programs.

Key features

  • Dynamic application security testing
  • Exploitability proof for scanner findings
  • API discovery and security testing
  • Static analysis and open source dependency checks
  • SBOM and license risk tracking
  • Attack surface management
  • Vulnerability correlation and compliance reporting

Good fit for

  • →Enterprise AppSec teams scanning thousands of web apps
  • →Developers verifying API security before release
  • →MSSPs offering web application testing
Tags
dast
application-security
api-security
vulnerability-scanner
sast
sca
netsparker

Open-source alternatives to Invicti

See all

SaaS alternatives to Invicti

See all