← All website monitoring tools
Invicti (formerly Netsparker)
Enterprise DAST + IAST with Proof-Based Scanning — annual contracts, quote-only.
What it does well
- Provides 'Proof-Based Scanning' to automatically confirm many vulnerabilities, reducing false positives.
- Combines both DAST and IAST scanning techniques for broader vulnerability coverage.
- Offers both cloud-based and on-premises deployment options to fit different security policies.
Where it falls short
- Pricing is not public; requires a custom quote and an annual contract commitment.
- No free tier or monthly plan is available for smaller projects or evaluation.
- The feature set is complex and geared towards enterprise use, potentially overwhelming smaller teams.
Alternatives to Invicti (formerly Netsparker)
Checkmarx One
paidUnified AppSec platform consolidating SAST/SCA/IAST/API/IaC. Quote-based, public minimums ~$30,000/yr.
Acunetix
paidMature commercial DAST scanner from Invicti — quote-based, generally $4,500+/yr per target tier.
Astra Pentest
paidContinuous DAST + manual pentest hybrid — published pricing $199-$5,999/yr, popular with SaaS startups.
Probely
paidAPI-first DAST scanner with developer ergonomics — published from $59/mo for a single target.