16 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener'>trScore algorithm: Learn more.</a>
Score 7.9 out of 100
6 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener'>trScore algorithm: Learn more.</a>
Score 8.5 out of 100

Attribute Ratings

  • Acunetix by Invicti is rated higher in 1 area: Likelihood to Recommend

Likelihood to Recommend

9.0

Acunetix by Invicti

90%
2 Ratings
8.5

Salt Security API Protection Platform

85%
6 Ratings

Likelihood to Recommend

Invicti Security

Acunetix scales well from a small web development presence like ours to a full-scale enterprise focused on that. The various tools and sensors that provide assurance of the results and can give feedback down to the lines of code in the source are proof of this. Various integrations exist as well. The main thing for us is that it simplifies confirming and remediating potential issues in our code or proving that products we use have issues that we can then take to the vendor for correction.
Read full review

Salt Security

Salt is highly recommended for anyone who wants to discover, monitor and protect their APIs against various types of attacks. Salt should not be used as a SIEM.
Read full review

Pros

Invicti Security

  • Fast.
  • Easy-to-use.
  • Great customer support.
  • Reporting features.
  • Supports importing state files from other popular application testing tools.
  • Has other features built-in beyond just scanning for vulnerabilities.
Read full review

Salt Security

  • PII identification in API traffic.
  • Divergence between API traffic and documentation (swagger files).
  • Potential attacks with information to take counter measures.
Read full review

Cons

Invicti Security

  • Does not support multiple endpoints well (e.g. apps and services that do not reside at the same URL).
  • Has authentication problems with modern enterprise apps which involve a lot of redirects to unrelated endpoints, federated IDs, SSO, etc. This is related to the first point.
  • The vulnerability detection capability is not as robust as Burp Suite Pro + extensions, Metasploit + auxiliary modules, Nmap + scripts, etc.
Read full review

Salt Security

  • The platform could have more options for exporting detailed data from attackers' dashboards.
  • The Attackers dashboard could also have more options of filters in order to support the investigations of the attack.
  • The OAS analysis could present a more detailed view of the found issues.
Read full review

Pricing Details

Acunetix by Invicti

Starting Price

$0

Editions & Modules

Acunetix by Invicti editions and modules pricing
EditionModules
Websites Scanned: 54,5001
Websites Scanned: 6-107,2002
Websites Scanned: 11-2010,8003
Websites Scanned: 21-3522,5404
Websites Scanned: 36-5026,6005
Websites Scanned: Over 50Contact for quote6

Offerings

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services

Entry-level set up fee?

No setup fee

Additional Details

Salt Security API Protection Platform

Starting Price

Editions & Modules

Salt Security API Protection Platform editions and modules pricing
EditionModules

Footnotes

    Offerings

    Free Trial
    Free/Freemium Version
    Premium Consulting/Integration Services

    Entry-level set up fee?

    No setup fee

    Additional Details

    Alternatives Considered

    Invicti Security

    ZAP is a free tool, and adequate. But it is to that extent less friendly. I would not be as confident of the results and it definitely can't produce reports on par with Acunetix. There would be a lot of legwork on our end if we desired to switch to this tool.
    Read full review

    Salt Security

    We tried controls offered by the IaaS providers but these were hard to manage and did not provide the visibility we wanted. We also protected APIs with a normal WAF but this was only helpful for assets we knew about and API attacks were not caught by the WAF.
    Read full review

    Return on Investment

    Invicti Security

    • Saved money compared to other commercial scanners, especially over the long run.
    • Scan speed seems to be pretty good compared to some of the bulkier commercial products out there. However, that largely has to do with proper configuration.
    • A downside is that is requires a bit of extra work just to get it set up to scan APIs, web services, etc.
    Read full review

    Salt Security

    • Salt Security API Protection Platform has provided detailed information that is helping us to identify and investigate attacks in our environment
    Read full review

    Screenshots

    Add comparison