We performed a comparison between Invicti and ShiftLeft based on real PeerSpot user reviews.
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Tools."It correctly parses DOM and JS and has really good support for URL Rewrite rules, which is important for today's websites."
"I like that it's stable and technical support is great."
"The scanner and the result generator are valuable features for us."
"When we try to manually exploit the vulnerabilities, it often takes time to realize what's going on and what needs to be done."
"Invicti is a good product, and its API testing is also good."
"High level of accuracy and quick scanning."
"It has a comprehensive resulting mechanism. It is a one-stop solution for all your security testing mechanisms."
"The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports."
"When it comes to ShiftLeft, the most valuable feature is definitely its ease of use and cost-effectiveness."
"Invicti takes too long with big applications, and there are issues with the login portal."
"The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them."
"Reporting should be improved. The reporting options should be made better for end-users. Currently, it is possible, but it's not the best. Being able to choose what I want to see in my reports rather than being given prefixed information would make my life easier. I had to depend on the API for getting the content that I wanted. If they could fix the reporting feature to make it more comprehensive and user-friendly, it would help a lot of end-users. Everything else was good about this product."
"It would be better for listing and attacking Java-based web applications to exploit vulnerabilities."
"The higher level vulnerabilities like Cross-Site Scripting, SQL Injection, and other higher level injection attacks are difficult to highlight using Netsparker."
"The license could be better. It would help if they could allow us to scan multiple URLs on the same license. It's a major hindrance that we are facing while scanning applications, and we have to be sure that the URLs are the same and not different so that we do not end up consuming another license for it. Netsparker is one of the costliest products in the market. The licensing is tied to the URL, and it's restricted. If you have a URL that you scanned once, like a website, you cannot retry that same license. If you are scanning the same website but in a different domain or different URL, you might end up paying for a second license. It would also be better if they provided proper support for multi-factor authentications. In the next release, I would like them to include good multi-factor authentication support."
"The solution's false positive analysis and vulnerability analysis libraries could be improved."
"The solution needs to make a more specific report."
"Having support from senior management is crucial in making it mandatory for teams to collaborate with the security team throughout the development process."
Invicti is ranked 20th in Application Security Tools with 25 reviews while ShiftLeft is ranked 26th in Application Security Tools with 1 review. Invicti is rated 8.2, while ShiftLeft is rated 10.0. The top reviewer of Invicti writes "A customizable security testing solution with good tech support, but the price could be better". On the other hand, the top reviewer of ShiftLeft writes "Effectively in identify and fix bugs early in the development lifecycle". Invicti is most compared with OWASP Zap, Acunetix, PortSwigger Burp Suite Professional, Qualys Web Application Scanning and Fortify WebInspect, whereas ShiftLeft is most compared with SonarQube and Black Duck.
See our list of best Application Security Tools vendors and best Static Application Security Testing (SAST) vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.