Invicti Web + API

Invicti Web + API

Invicti Security
+
+
Visit Website

About

Secure your code, cloud, and runtime in one central system. Aikido’s all-in-one security platform is loved by developers and security teams alike with full security visibility, insight in what matters most, and fast/automatic vulnerability fixes. Teams get security done with Aikido thanks to: - False-positive reduction - AI Autotriage & AI Autofix - Deep integration into the dev workflow (from IDEs and task managers to CI/CD gating) - AI Pentests - Automated Compliance Aikido covers the entire Software Development Lifecycle (SDLC), including: static application security testing (SAST), dynamic application security testing (DAST), infrastructure-as-code (IaC), container scanning, secrets detection, open source license scanning (SCA), cloud posture management (CSPM), runtime protection, AI pentests, and more.

About

Invicti Web + API, formerly Acunetix, is a dynamic application security testing (DAST) platform for identifying and validating vulnerabilities across web applications, APIs, and other runtime assets. The platform automatically discovers applications, APIs, shadow assets, unlinked pages, and undocumented endpoints while supporting modern JavaScript applications and authenticated workflows. Its scanning engine detects more than 7,000 types of security issues, including vulnerabilities covered by the OWASP Top 10 and OWASP API Top 10 as well as business logic flaws. Invicti combines AI-driven risk scoring with runtime reachability, exploitability, and business context to help security teams prioritize vulnerabilities that represent demonstrable risk.

Platforms Supported

Windows Supported
Mac Supported
Linux Supported
Cloud Supported
On-Premises Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Supported
Mac Not Supported
Linux Supported
Cloud Supported
On-Premises Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

Development teams

Audience

Application security teams, security engineers, penetration testers, DevSecOps teams, developers, CISOs, vulnerability management teams, and enterprises that need automated DAST, API security testing, vulnerability validation, prioritization, and remediation across modern web applications and APIs

Support

Phone Support Not Supported
24/7 Live Support Supported
Online Supported

Support

Phone Support Supported
24/7 Live Support Supported
Online Supported

API

Offers API Supported

API

Offers API Supported

Screenshots and Videos

Screenshots and Videos

Pricing

Free
- Free plan (free forever, incl. 2 users, 10 repos, and more).

- Basic plan (Platform fee: $350/month - 10 users included).

- Pro plan (Platform fee: $700/month - 10 users included).

- Advanced plan ($1050/month - 10 users included) for organizations with advanced needs.
Free Version Supported
Free Trial Not Supported

Pricing

No information available.
Free Version Not Supported
Free Trial Supported

Reviews/Ratings

Overall 5.0 / 5
ease 4.8 / 5
features 4.8 / 5
design 5.0 / 5
support 5.0 / 5

Reviews/Ratings

Overall 4.0 / 5
ease 5.0 / 5
features 5.0 / 5
design 4.0 / 5
support 4.0 / 5

Pros from Real Users

Pros

  • Aikido was clearly designed by people who understand what developers actually need. It strikes the right balance between being feature-rich and genuinely intuitive. Setting up integrations is straightforward, and they work exactly as expected. The platform excels at prioritizing vulnerabilities, breaking down root causes, and providing actionable remediation guidance. The CI/CD gatekeeping has been a game-changer for catching issues before they hit production, and the autofix feature has made tackling our backlog far less daunting. When we were preparing for ISO 27001, we were staring down a mountain of work; without Aikido's auto-ignore, I'm sure we'd still be drowning in false positives...
  • Fantastic support and onboarding process - can speak to someone quickly Very easy to set-up Very easy to use and integrate into existing dev cycle and benefits seen in minutes
  • Instant insights into vulnerabilities CI/CD ensures vulnerabilities get noticed before merging to production Autofix is very accurate and saves time Being able to manage SLA’s Vanta integration for compliance is easy of mind
  • Aikido is a security tool for engineers, built by engineers. It's comprehensive but simple to use. The integrations are easy to set up and are very effective. Aikido does a great job categorizing the severity of issues, explaining the cause of the issue, and how to fix it. The CICD gates are incredibly helpful and effective at preventing new issues from being introduced, while the autofix tool has been useful for cleaning up existing issues.
  • Really easy integration, nice and clean UI, developer-friendly, low false positives, strong GitHub support.
  • The ease of use. The filtered overview that makes you focus on the issues that matter. Integration with Github Actions. The all-in-one aspect of it (Aikido offers a lot of different features). Autofix functionality (automatically creating PRs containing security fixes). Insights into actual security issues within the platform (background information on CVE, best practices, or actual misconfiguration).

Pros & Cons from Real Users

Pros

  • It is the most advanced automated web scanner. The vulnerability management feature works very well. The results are very accurate.

Cons

  • I have not found any cons until now. It works great.

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Not Supported

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Not Supported

Company Information

Aikido Security
Founded: 2022
Belgium
www.aikido.dev

Company Information

Invicti Security
Founded: 2018
United States
acunetix.com

Alternatives

Alternatives

Astra Pentest

Astra Pentest

Astra Security
AppTrana

AppTrana

Indusface
Invicti

Invicti

Invicti Security
PT Application Inspector

PT Application Inspector

Positive Technologies

Categories

AI Code Review Supported

Next-gen code review with AI fixes. Check code quality and resolve vulnerabilities early. Autofix them in your IDE or via PR. From vulnerability management to penetration testing, secure everything you build, host, and run with Aikido. Your software security HQ. Built for teams of any size, Aikido helps organizations ship secure software –trusted by Revolut, Deel, The Premier League, Tines, n8n, SoundCloud, and 50k more organizations. Aikido gets developers back to building.

AI Pentesting Supported

Get an AI pentest done, today. Autonomous AI agents that outperform humans at machine speed. Get a full audit-grade SOC2 or ISO27001 PDF report in hours, not weeks. Aikido Attack is the future of pentesting.

From application security to penetration testing, secure everything you build, host, and run with Aikido. Your software security HQ. Built for teams of any size, Aikido helps organizations ship secure software –trusted by Revolut, Deel, The Premier League, Tines, n8n, SoundCloud, and 50k more organizations. Aikido gets developers back to building.

Secure your stack with Aikido's code-to-cloud security platform. Find and fix vulnerabilities fast & automatically. Aikido's all-in-one approach combines multiple important scanning capabilities. SAST, DAST, SCA, CSPM, IaC, Container scanning and more - making it a true ASPM platform.

Code Quality Supported

Ship quality code, faster. Aikido built AI-native code quality, with instant feedback, smart detection, and clear auto-generated PR comments, so you can focus on building.

Code Review Supported

Next-gen code review with AI fixes. Check code quality and resolve vulnerabilities early. Autofix them in your IDE or via PR. From vulnerability management to penetration testing, secure everything you build, host, and run with Aikido. Your software security HQ. Built for teams of any size, Aikido helps organizations ship secure software –trusted by Revolut, Deel, The Premier League, Tines, n8n, SoundCloud, and 50k more organizations. Aikido gets developers back to building.

Code Security Supported

Secure your stack with Aikido's code-to-cloud security platform. Find and fix vulnerabilities fast & automatically. Aikido’s DAST scanner shows where your app is most vulnerable so you can close security gaps before attackers find them. Monitor your App & APIs to find vulnerabilities like SQL injection, XSS, and CSRF — both on the surface and via authenticated DAST.

Get a pentest done, today. Autonomous AI agents that outperform humans at machine speed. Get a full audit-grade SOC2 or ISO27001 PDF report in hours, not weeks. Aikido Attack is the future of pentesting.

Secure your stack with Aikido's code-to-cloud security platform. Find and fix vulnerabilities, Generate SBOMs and scan licenses. Many SBOM scanners will only scan for licenses inside of your repos. Aikido gives you full coverage by scanning your containers too.

Secure your stack with Aikido's code-to-cloud security platform. Find and fix vulnerabilities fast & automatically. Aikido detects vulnerabilities, malware, end-of-life runtimes & OSS licenses and generates SBOMs. Analyse third-party components such as libraries, frameworks, and dependencies for vulnerabilities. Aikido does reachability analysis, triages to filter out false positives, and provides clear remediation advice. Auto-fix vulnerabilities with one click.

Secure your stack with Aikido's code-to-cloud security platform. Find and fix vulnerabilities fast & automatically. Aikido scans your code for security vulnerabilities such as SQL injection, XSS, buffer overflows and other security risks. Checks against popular CVE databases. It works out-of-the-box and supports all major languages. Aikido combines scanning capabilities like SAST, IaC, DAST, Container Scanning, SCA, CSPM & Secrets Detection, all in one platform.

From vulnerability management to penetration testing, secure everything you build, host, and run with Aikido. Your software security HQ. Built for teams of any size, Aikido helps organizations ship secure software –trusted by Revolut, Deel, The Premier League, Tines, n8n, SoundCloud, and 50k more organizations. Aikido gets developers back to building.

Secure your stack with Aikido's code-to-cloud security platform. Find and fix vulnerabilities fast & automatically. Aikido's all-in-one approach combines multiple important scanning capabilities. SAST, DAST, SCA, CSPM, IaC, Container scanning and more - making it a true ASPM platform.

Categories

Application Security Features

Analytics / Reporting Supported
Open Source Component Monitoring Supported
Source Code Analysis Supported
Third-Party Tools Integration Supported
Training Resources Supported
Vulnerability Detection Supported
Vulnerability Remediation Supported

Vulnerability Management Features

Asset Discovery Not Supported
Asset Tagging Not Supported
Network Scanning Not Supported
Patch Management Not Supported
Policy Management Supported
Prioritization Supported
Risk Management Supported
Vulnerability Assessment Supported
Web Scanning Supported

Vulnerability Scanners Features

Asset Discovery Not Supported
Black Box Scanning Not Supported
Compliance Monitoring Supported
Continuous Monitoring Supported
Defect Tracking Not Supported
Interactive Scanning Not Supported
Logging and Reporting Supported
Network Mapping Not Supported
Perimeter Scanning Not Supported
Risk Analysis Not Supported
Threat Intelligence Not Supported
Web Inspection Supported

Static Application Security Testing (SAST) Features

Application Security Supported
Dashboard Supported
Debugging Not Supported
Deployment Management Not Supported
IDE Supported
Multi-Language Scanning Supported
Real-Time Analytics Not Supported
Source Code Scanning Supported
Vulnerability Scanning Supported

Application Security Features

Analytics / Reporting Supported
Open Source Component Monitoring Not Supported
Source Code Analysis Not Supported
Third-Party Tools Integration Supported
Training Resources Supported
Vulnerability Detection Supported
Vulnerability Remediation Supported

Vulnerability Management Features

Asset Discovery Supported
Asset Tagging Supported
Network Scanning Supported
Patch Management Not Supported
Policy Management Not Supported
Prioritization Supported
Risk Management Supported
Vulnerability Assessment Supported
Web Scanning Supported

Vulnerability Scanners Features

Asset Discovery Supported
Black Box Scanning Supported
Compliance Monitoring Supported
Continuous Monitoring Supported
Defect Tracking Supported
Interactive Scanning Supported
Logging and Reporting Supported
Network Mapping Supported
Perimeter Scanning Supported
Risk Analysis Supported
Threat Intelligence Supported
Web Inspection Supported

Computer Security Features

Anti Spam Not Supported
Antivirus Not Supported
Audit Trail Supported
Compliance Management Supported
Database Security Audit Supported
File Access Control Supported
Financial Data Protection Not Supported
Maintenance Scheduling Not Supported
Real Time Monitoring Not Supported
Security Event Log Not Supported
Virus Definition Update Not Supported
Vulnerability Protection Supported

Cybersecurity Features

AI / Machine Learning Not Supported
Behavioral Analytics Not Supported
Endpoint Management Not Supported
Incident Management Not Supported
IOC Verification Supported
Tokenization Not Supported
Vulnerability Scanning Supported
Whitelisting / Blacklisting Not Supported

IT Security Features

Anti Spam Not Supported
Anti Virus Not Supported
Email Attachment Protection Not Supported
Event Tracking Not Supported
Internet Usage Monitoring Not Supported
Intrusion Detection System Not Supported
IP Protection Not Supported
Spyware Removal Not Supported
Two-Factor Authentication Not Supported
Vulnerability Scanning Supported
Web Threat Management Supported
Web Traffic Reporting Not Supported

Network Security Features

Access Control Not Supported
Analytics / Reporting Not Supported
Compliance Reporting Not Supported
Firewalls Not Supported
Internet Usage Monitoring Not Supported
Intrusion Detection System Not Supported
Threat Response Supported
VPN Not Supported
Vulnerability Scanning Supported

Integrations

GitHub Supported
Jira Supported
Axonius Not Supported
Bitbucket Supported
C# Supported
C++ Supported
Dradis Not Supported
Elixir Supported
Flexagon Not Supported
GitLab Supported
Imperva DDoS Protection Not Supported
Jenkins Not Supported
Kondukto Not Supported
NAVEX IRM Not Supported
Nucleus Not Supported
Phoenix Security Not Supported
Scuba Database Vulnerability Scanner Not Supported
Sprinto Supported
ThreadFix Not Supported
ThreatAdvisor Not Supported

Integrations

GitHub Supported
Jira Supported
Axonius Supported
Bitbucket Not Supported
C# Not Supported
C++ Not Supported
Dradis Supported
Elixir Not Supported
Flexagon Supported
GitLab Not Supported
Imperva DDoS Protection Supported
Jenkins Supported
Kondukto Supported
NAVEX IRM Supported
Nucleus Supported
Phoenix Security Supported
Scuba Database Vulnerability Scanner Supported
Sprinto Not Supported
ThreadFix Supported
ThreatAdvisor Supported
Claim Invicti Web + API and update features and information
Claim Invicti Web + API and update features and information