Compare Acunetix Vulnerability Scanner vs. Netsparker Web Application Security Scanner

Cancel
You must select at least 2 products to compare!
Most Helpful Review
Find out what your peers are saying about Acunetix Vulnerability Scanner vs. Netsparker Web Application Security Scanner and other solutions. Updated: March 2021.
466,017 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
"We are using the Veracode tools to expose the engineers to the security vulnerabilities that were introduced with the new features, i.e. a lot faster or sooner in the development life cycle.""The most valuable feature comes from the fact that it is cloud-based, and I can scale up without having to worry about any other infrastructure needs.""I have used this solution in multiple projects for vulnerability testing and finding security leaks within the code.""We used it for performing security checks. We have many Java applications and Android applications. Essentially it was used for checking the security validations for compliance purposes.""Veracode is a valuable tool in our secure SDLC process.""Integrations into our developer's IDE (Greenlight) and the DevOps Pipeline SAST / SourceClear Integrations has particularly increased our time to market and confidence.""The source composition analysis component is great because it gives our developers some comfort in using new libraries.""Veracode's cloud-based approach, coupled with the appliance that lets us use Veracode to scan internal-only web applications, has provided a seamless, always-up-to-date application security scanning solution."

More Veracode Pros »

"Their technical support has been very active. If I have an issue, I can reach out to them and get an answer pretty quick.""We are able to create a report which shows the PCI DSS scoring and share it with the application teams. Then, they can correlate and see exactly what they need to fix, and why.""The automated approach to these repetitive discovery attempts would take days to do manually and therefore it helps reduce the time needed to do an assessment.""The vulnerability scanning option for analyzing the security loopholes on the websites is the most valuable feature of this solution.""Our developers can run the attacks directly from their environments, desktops.""It can operate both as a standalone and it can be integrated with other applications, which makes it a very versatile solution to have.""For us, the most valuable aspect of the solution is the log-sequence feature.""The scalability is good. The scalability is more than good because it can operate both as a standalone and it can be integrated as part of applications. So that really makes it a very, very versatile solution to have."

More Acunetix Vulnerability Scanner Pros »

"It correctly parses DOM and JS and has really good support for URL Rewrite rules, which is important for today's websites.""One of the features I like about this program is the low number of false positives and the support it offers.""The most attractive feature was the reporting review tool. The reporting review was very impressive and produced very fruitful reports.""High level of accuracy and quick scanning.""This tool is really fast and the information that they provide on vulnerabilities is pretty good.""I am impressed by the whole technology that they are using in this solution. It is really fast. When using netscan, the confirmation that it gives on the vulnerabilities is pretty cool. It is really easy to configure a scan in Netsparker Web Application Security Scanner. It is also really easy to deploy."

More Netsparker Web Application Security Scanner Pros »

Cons
"Veracode should make it easier to navigate between the solutions that they offer, i.e. between dynamic, static, and the source code analysis.""I would like to see expanded coverage for supporting more platforms, frameworks, and languages.""Ideally, I would like better reporting that gives me a more concise and accurate description of what my pain points are, and how to get to them.""One of the things that we have from a reporting point of view, is that we would love to see a graphical report. If you look through a report for something that has come back from Veracode, it takes a whole lot of time to just go through all the pages of the code to figure out exactly what it says. We know certain areas don’t have the greatest security features but those are usually minor and we don’t want to see those types of notifications.""It needs better controls to include/exclude specific sections when creating a report that can be shared externally with customers and prospects.""Improve Mobile Application Dynamic Scanning DAST - .ipa and .apk""I think for us the biggest improvement would be to have an indicator when there's something wrong with a scan.""One feature I would like would be more selectivity in email alerts. While I like getting these, I would like to be able to be more granular in which ones I receive."

More Veracode Cons »

"You can't actually change your password after you've set it unless you go back into the administration account and you change it there. Thus, if you're locked out and don't remember your password, that's a thing.""We have had issues during upgrades where their scans worked on some apps better with previous versions. Then, we had to work with their tech support, who were great, to get it fixed for the next version.""It would be nice to have a feature to "retest" only a single vulnerability that the customer reports as patched, and delete it from the next scans since it has already been patched.""In terms of what needs improvement, the way the licensing model is currently is not very convenient for us because initially, when we bought it, the licensing model was very flexible, but now it restricts us.""Tools that would allow us to work more efficiently with the mobile environment, with Android and iOS.""When monitoring the traffic we always have issues with the bandwidth consumption and the throttling of traffic.""The solution limits the number of scans. It would be much better if we could have unlimited scans.""We want to see how much bandwidth usage it consumes. When we monitor traffic we have issues with the consumption and throttling of the traffic."

More Acunetix Vulnerability Scanner Cons »

"The scanner itself should be improved because it is a little bit slow.""Netsparker doesn't provide the source code of the static application security testing.""The proxy review, the use report views, the current use tool and the subset requests need some improvement. It was hard to understand how to use them.""Right now, they are missing the static application security part, especially web application security.""They don't really provide the proof of concept up to the level that we need in our organization. We are a consultancy firm, and we provide consultancy for the implementation and deployment solutions to our customers. When you run the scans and the scan is completed, it only shows the proof of exploit, which really doesn't work because the tool is running the scan and exploiting on the read-only form. You don't really know whether it is actually giving the proof of exploit. We cannot prove it manually to a customer that the exploit is genuine. It is really hard to perform it manually and prove it to the concerned development, remediation, and security teams. It is currently missing the static application security part of the application security, especially web application security. It would be really cool if they can integrate a SAS tool with their dynamic one."

More Netsparker Web Application Security Scanner Cons »

Pricing and Cost Advice
"They just changed their pricing model two weeks ago. They went from a per-app license to a per-megabyte license. I know that the dynamic scan was $500 per app. Static analysis was about $4500 yearly. The license is only for the number of users, it doesn't matter what data you put in there. That was the old model. I do not know how the new model works.""They have just streamlined the licensing and they have a number of flexible options available, so overall it is quite good, albeit pricey.""For the value we get out of it, coupled with the live defect review sessions, we find it an effective value for the money. We are a larger organization.""I don't really know about the pricing, but I'd say it's worth whatever Veracode is charging, because the solution is that good.""Veracode's price is high. I would like them to better optimize their pricing.""If I compare the pricing with other software tools, then it is quite competitive. Whatever the price is, they have always given us a good discount.""Veracode is expensive. Some of its products are expensive. I don't think it's way more expensive than its competitors. The dynamic is definitely worth it, as I think it's cheaper than the competitors. The static scan is a little bit more expensive, around 20 percent more expensive. The manual pen test is more expensive, but it is an expensive service because it's a manual pen test and we also do retests. I don't think it is way more expensive than the competitors, but it's about 15 to 20 percent more expensive.""We use this product per project rather than per developer... Your development model will really determine what the best fit is for you in terms of licensing, because of the project-based licensing. If you do a few projects, that's more attractive. If you have a large number of developers, that would also make the product a little more attractive."

More Veracode Pricing and Cost Advice »

"The pricing and licensing are reasonable to a point. In order to run multiple scans at a time, we are going to have to purchase a 100 count license, which is an overkill. Though, compared to what we were paying for, the cost seems reasonable.""All things considered, I think it has a good price/value ratio.""The costs aren't very expensive. It costs around $3000 or $4000.""I would say that Acunetix is expensive because there are products on the market with similar features that are equally or better-priced.""The pricing is a little high, and moreover, it's kind of domain-based.""When compared with other products, the pricing is a little bit high. But it gives value for the price. It serves the purpose and is worthwhile for the price we pay.""Implementing Acunetix needs a medium or larger business agency, because you need some money to get Acunetix. It is costly, but if you care about your agency's security, then maybe it's a cost that might help you in the future."

More Acunetix Vulnerability Scanner Pricing and Cost Advice »

"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on.""The price should be 20% lower"

More Netsparker Web Application Security Scanner Pricing and Cost Advice »

report
Use our free recommendation engine to learn which Application Security solutions are best for your needs.
466,017 professionals have used our research since 2012.
Questions from the Community
Top Answer: Veracode has offered a dynamic analysis testing solution for several years, having launched our first offering in 2015… more »
Top Answer: I would recommend them. They have the ability to cover multiple languages and come with all the features you would… more »
Top Answer: SonarQube depends on completely what you configure the Rules. You will have the option of the Profile creation and can… more »
Top Answer: The scalability is good. The scalability is more than good because it can operate both as a standalone and it can be… more »
Top Answer: We want to see how much bandwidth usage it consumes. When we monitor traffic we have issues with the consumption and… more »
Top Answer: Our primary use case is to secure web applications, especially against cross-scripting and other forms of malware that… more »
Top Answer: Improvement could be made in the area of production. Features like macro recording that I've used in other solutions… more »
Top Answer: Our primary use case is for web applications but rather than being in a production environment, it's in a testing… more »
Popular Comparisons
Also Known As
AcuSensor
Mavituna Netsparker
Learn More
Overview

Veracode covers all your Application Security needs in one solution through a combination of five analysis types; static analysis, dynamic analysis, software composition analysis, interactive application security testing, and penetration testing. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline, and empowers developers to find and fix security defects.

Acunetix Web Vulnerability Scanner is an automated web application security testing tool that audits your web applications by checking for vulnerabilities like SQL Injection, Cross site scripting, and other exploitable vulnerabilities.

Netsparker finds and reports web application vulnerabilities such as SQL Injection and Cross-site Scripting (XSS) on all types of web applications, regardless of the platform and technology they are built with. Netsparker's unique and dead accurate Proof-Based scanning technology does not just report vulnerabilities, it also produces a Proof of Concept to confirm they are not false positives, freeing you from having to double check the identified vulnerabilities.

Offer
Learn more about Veracode
Learn more about Acunetix Vulnerability Scanner
Learn more about Netsparker Web Application Security Scanner
Sample Customers
State of Missouri, Rekner
Joomla!, Digicure, Team Random, Credit Suisse, Samsung, Air New Zealand
Samsung, The Walt Disney Company, T-Systems, ING Bank
Top Industries
REVIEWERS
Financial Services Firm31%
Insurance Company10%
Healthcare Company8%
Computer Software Company8%
VISITORS READING REVIEWS
Computer Software Company33%
Comms Service Provider16%
Financial Services Firm9%
Manufacturing Company6%
REVIEWERS
Financial Services Firm42%
Comms Service Provider17%
Non Tech Company8%
Computer Software Company8%
VISITORS READING REVIEWS
Computer Software Company35%
Comms Service Provider19%
Government6%
Financial Services Firm5%
VISITORS READING REVIEWS
Computer Software Company32%
Comms Service Provider18%
Educational Organization7%
Media Company6%
Company Size
REVIEWERS
Small Business23%
Midsize Enterprise25%
Large Enterprise52%
VISITORS READING REVIEWS
Small Business22%
Midsize Enterprise26%
Large Enterprise52%
REVIEWERS
Small Business31%
Midsize Enterprise19%
Large Enterprise50%
VISITORS READING REVIEWS
Small Business23%
Midsize Enterprise12%
Large Enterprise65%
REVIEWERS
Small Business57%
Midsize Enterprise7%
Large Enterprise36%
Find out what your peers are saying about Acunetix Vulnerability Scanner vs. Netsparker Web Application Security Scanner and other solutions. Updated: March 2021.
466,017 professionals have used our research since 2012.

Acunetix Vulnerability Scanner is ranked 9th in Application Security with 13 reviews while Netsparker Web Application Security Scanner is ranked 13th in Application Security with 6 reviews. Acunetix Vulnerability Scanner is rated 7.2, while Netsparker Web Application Security Scanner is rated 8.2. The top reviewer of Acunetix Vulnerability Scanner writes "We are getting notably fewer false positives than previously, but reporting output needs to be simplified". On the other hand, the top reviewer of Netsparker Web Application Security Scanner writes "Powerful Crawler generates close to a full sitemap, including web services". Acunetix Vulnerability Scanner is most compared with OWASP Zap, Fortify WebInspect, PortSwigger Burp Suite Professional, Rapid7 AppSpider and Tenable.io Web Application Scanning, whereas Netsparker Web Application Security Scanner is most compared with OWASP Zap, HCL AppScan, Fortify WebInspect, PortSwigger Burp Suite Professional and Rapid7 InsightAppSec. See our Acunetix Vulnerability Scanner vs. Netsparker Web Application Security Scanner report.

See our list of best Application Security vendors and best Application Security Testing (AST) vendors.

We monitor all Application Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.