Invicti (formerly Netsparker) Reviews (72)

Reviews

Invicti (formerly Netsparker) Reviews (72)

4.5
72 reviews

What do users say?

Generated using AI from real user reviews
Users consistently praise the product for its accuracy and ease of use, noting that it effectively identifies real vulnerabilities without generating excessive false positives. The integration with CI/CD tools and the ability to generate detailed reports are also highlighted as significant benefits. However, some users mention that the customer support could be improved, particularly regarding response times.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
ZG
Zach G.
Mid-Market (51-1000 emp.)
"Efficient Scanning, Superb Usability"
4.5/5
What do you like best about Invicti (formerly Netsparker)?

I really appreciate the ease of use that Invicti (formerly Netsparker) offers. The user interface is great, making everything straightforward. The scanning engine stands out for producing high-quality results, especially when compared to competitors. It significantly reduces the manual effort and time needed to perform actions manually. I also found the initial setup to be very easy. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

When automated authentication fails, there is no notification to myself, the user. That would be the only improvement. Review collected by and hosted on G2.com.

Verified User
G
Verified User
Mid-Market (51-1000 emp.)
"Effective Automation with Room for Improvement"
3.5/5
What do you like best about Invicti (formerly Netsparker)?

I appreciate how Invicti (formerly Netsparker) automates external pen tests against our public-facing web applications and reports findings to us. It effectively sorts these findings based on priority, severity, exposure, and other indicators, and displays them in a way that's effective for us. I'm also looking forward to implementing the API security feature, which I find valuable. The automated testing has been effective so far. I like being able to separate our applications logically so we can view risk per application, and I find the UI to be very navigable. It sorts everything out as it should and is clear on priorities and severities. It's useful to see requests and responses that may indicate vulnerabilities, allowing us to validate authenticity and confidence. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

It was a little difficult for us to set up MFA for the automated pen testing for apps that have MFA protection, and that wasn't the smoothest process. There's still a good deal of tuning that needs to happen on those scans. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Mid-Market (51-1000 emp.)
"Scalable Enterprise Security: Deep Endpoint Coverage via Invicti"
4.5/5
What do you like best about Invicti (formerly Netsparker)?

In my experience conducting deep security posture analysis, the most valuable aspect of Invicti is its ability to bridge the gap between active vulnerability scanning and dependency management. While many tools focus only on active threats, Invicti provides the Software Composition Analysis (SCA) depth we need for enterprise portfolios.

In practice, we use it to manage the security implications of complex, nested packages, ensuring we remain accountable for dependencies built on top of other packages in our Java and Spring Boot environments. Its integration with our CI/CD pipelines (such as Jenkins) also lets us automate endpoint testing across the full application interface.

What stands out most is the accuracy with which it discovers available endpoints without requiring significant manual configuration. Rather than spending hours defining what to test, the automated crawling produces a comprehensive report that categorizes issues by severity. This makes it easier to prioritize remediation right away, instead of manually filtering through noise. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

The primary challenge we've encountered involves performance overhead and scalability when integrating multiple scanning agents across a large portfolio of applications. When running concurrent scans for several enterprise-grade microservices, the resource consumption can lead to significantly longer scan times, which occasionally creates a bottleneck in our rapid deployment cycles.

Additionally, while the automation is robust, it can require extensive manual configuration for complex authentication flows (such as custom headers or multi-step SSO). Without this "fine-tuning," the scanner can sometimes struggle with context-awareness, leading to false positives that require manual triage. For a security team managing a high volume of vulnerabilities, investigating these non-exploitable findings can be time-consuming and reduce the overall efficiency of the automated reporting. Review collected by and hosted on G2.com.

Verified User in Retail
AR
Verified User in Retail
Enterprise (> 1000 emp.)
"Accurate, Actionable Scans with Minimal Noise"
4.5/5
What do you like best about Invicti (formerly Netsparker)?

Invicti has provided very accurate dynamic scan results for our enterprise. The findings are confirmed and actionable. The amount of white noise is very minimal. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

There are very few issues we have seen with Invicti, Review collected by and hosted on G2.com.

Chris M.
CM
Chris M.
System Administrator
Mid-Market (51-1000 emp.)
"Effortless Website Testing with Outstanding Support"
4.5/5
What do you like best about Invicti (formerly Netsparker)?

Invicti is simple to use and quick to set up, making it easy for me to carry out monthly website tests with hardly any hassle as each target is saved in its own profile. Over the years Invicti has become a crucial part of our workflow with me carrying out monthly scans. Also, whenever I experience any difficulties with the software, I can reach out to support, and they consistently respond promptly and helpfully to resolve my concerns. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

We have some issues with API scanning and so can not use this app for that purpose. This is something that we do differently to the way Invicti looks at APIs so we could never get it to work even with the great support offered. Review collected by and hosted on G2.com.

Pranav K.
PK
Pranav K.
DevOps Engineer
Mid-Market (51-1000 emp.)
"Simple Reporting Shines, But Needs Better Integration Options"
4/5
What do you like best about Invicti (formerly Netsparker)?

I appreciate the simplicity of the platform, especially the report generation options. These features are particularly helpful when we require different reports for various scenarios. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

When we worked with Qualys scanning, I found the plugin for capturing the login chain to be straightforward to use and set up. I hope we can have a similar experience here. Additionally, integration with Teams or email would be very helpful. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Verified User in Computer Software
Mid-Market (51-1000 emp.)
"Reliable DAST Tool with Proof-Based Accuracy and Automation"
5/5
What do you like best about Invicti (formerly Netsparker)?

Accuracy and integration capabilities. Invicti integrates tightly with DevOps and CI/CD tools such as Jenkins, GitLab, Jira. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

While the tool identifies vulnerabilities effectively, it doesn’t provide detailed, actionable remediation guidance, such as code snippets or contextual fix instructions. Review collected by and hosted on G2.com.

"Essential Tool for Dynamic Application Testing, Needs Better Support"
5/5
What do you like best about Invicti (formerly Netsparker)?

I appreciate that Invicti (formerly Netsparker) offers easy-to-read and well-formatted reports that are particularly presentable for ISO certifications, which simplifies the process significantly. The tool's dynamic application testing capabilities are a vital part of our ISM certification process, which adds considerable value to our operations. Additionally, I am pleased with the reasonable pricing it offers, providing vital certification from an authorized dealer without breaking the bank. The user-friendly setup is another aspect I find valuable. Even a builder can start setting up the security testing software quickly, making it highly efficient for our needs and allowing us to begin operations swiftly. Overall, these elements make Invicti an essential and effective tool for my team's security testing and certification needs. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

I feel the customer support could be improved. While it does allow for some level of screen sharing support, I believe there is room for enhancements in this area. This specific aspect of customer support, like chat support, could benefit from more robust and interactive support features such as effective and seamless screen-sharing capabilities. Review collected by and hosted on G2.com.

Verified User in Insurance
UI
Verified User in Insurance
Enterprise (> 1000 emp.)
"Invicti Delivers Accurate, Efficient DAST with Seamless CI/CD Integration"
3.5/5
What do you like best about Invicti (formerly Netsparker)?

We've been using Invicti (formerly Netsparker) as our primary Dynamic Application Security Testing (DAST) tool, and it has consistently delivered excellent results. As an Information Security Specialist, I rely on tools that are both accurate and efficient—and Invicti checks both boxes.

The scanner is highly effective at identifying real, exploitable vulnerabilities in our web applications without generating excessive false positives. Its automation capabilities have streamlined our testing workflows, and the integration with our CI/CD pipeline has made it easy to embed security into our development lifecycle.

One of the standout features is its proof-based scanning, which provides clear evidence of vulnerabilities, making it easier to prioritize and remediate issues. The reporting is also comprehensive and customizable, which helps in communicating findings to both technical and non-technical stakeholders.

Overall, Invicti has become a trusted part of our security toolkit. I’d recommend it to any team looking for a robust and scalable DAST solution. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

SettingsThe settings and configuration options can feel a bit overwhelming at first. Some menus are nested in ways that make it harder to quickly find what you need, especially when fine-tuning scan profiles or managing integrations. A more streamlined UI for settings would improve the overall experience. Review collected by and hosted on G2.com.

Verified User in Telecommunications
AT
Verified User in Telecommunications
Enterprise (> 1000 emp.)
"Great DAST & API Security Features, But Support Needs Improvement"
4/5
What do you like best about Invicti (formerly Netsparker)?

The product offers valuable features for DAST and API security, and it integrates smoothly with other tools. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

The technical support is quite disappointing. After connecting with them, they attempt to understand the issue, but most of the time they are unable to provide any real solution. Review collected by and hosted on G2.com.