Acunetix (Invicti Web + API) review: Features, pros/cons, and pricing

Updated on 14 Sep 2026
16 min read
AppSec

Acunetix is a web application and API security scanner built around dynamic application security testing (DAST), with an internal instrumentation layer called AcuSensor that adds runtime, code level detail for supported languages. As of September 2026, the product has been officially renamed Invicti Web + API , though “Acunetix” remains the name most people search for and the one still used across its documentation and changelogs during the transition.

The rename doesn’t change what the product does day to day. It’s still a scanner for websites, web applications, and APIs, not a general infrastructure vulnerability scanner and not the same thing as the broader Invicti AppSec Platform, which adds SAST, SCA, secrets detection, and ASPM correlation on top of the same DAST engine. Invicti’s own current site describes the Acunetix legacy as part of its broader DAST engine now, not a parallel product sold alongside it, which matters if you’re trying to figure out what you’d actually be buying under either name. This review covers that DAST product specifically: what it tests, how proof based scanning actually works, current pricing, and where a security program built around it will need something else.

How we put this blog together
This article is based entirely on publicly available sources. We aggregated user reviews from G2, Capterra, and similar trusted sources, drew on discussions from Reddit communities, and reviewed vendor documentation and feature pages. Rather than proprietary testing, our evaluation reflects the collective experience of security practitioners who have shared their insights publicly.

TL;DR: Acunetix review

Acunetix, now sold as Invicti Web + API, is a mature DAST scanner with a genuinely strong track record on vulnerability detection and validation. Its proof based scanning safely exploits findings to confirm they’re real before surfacing them, which cuts down on the manual triage that plagues less selective scanners. Current documentation and multiple technical reviews confirm it handles modern JavaScript applications, SPAs, and API architectures, including GraphQL, when given a schema, correcting some of what older reviews of the product used to say.

The trade offs are cost and scope, not outdated technology. Licensing is per FQDN with a five target minimum, which multiplies quickly across dev, staging, and production environments, and the product is a DAST scanner, not a replacement for manual penetration testing when it comes to business logic and access control flaws.

G2 rating4.1 out of 5, based on 105 reviews
Best suited forSecurity teams running scheduled, compliance driven scans across a defined set of web applications and APIs
CoverageWeb applications, APIs (REST, SOAP, GraphQL with schema import), SPAs, authenticated and password protected areas
Pricing modelPer FQDN (target) licensing in bundles of 5, 10, or 20; no public rate card, quote required
Key strengthsProof based validation of findings, AcuSensor's code level detail for supported languages, mature crawling for modern JavaScript apps
Key trade offsTarget based pricing multiplies across environments, resource intensive on large or complex applications, doesn't cover business logic or access control the way manual testing does

Source: Acunetix,

Recent G2 reviews describe the scanning engine as accurate and the reporting as detailed enough to hand to a development team directly. The most consistent criticism isn’t the detection quality, it’s that scans can be resource intensive and slow on large or complex applications, and that the volume of findings on a first scan takes real time to triage.

Key features of Acunetix

  • Automated DAST scanning for web applications and APIs

Acunetix crawls and attacks a running application the way an external attacker would, covering websites, web applications, and APIs from outside the codebase. It handles authenticated scans and session based applications, executing JavaScript to reach application states that a simpler crawler would miss entirely.

  • AcuSensor for code level detail (IAST style instrumentation)

AcuSensor is a lightweight agent deployed alongside a running application (supporting .NET, Java, PHP, and Node.js) that observes how requests are processed internally while the DAST scanner tests from outside. This combination lets Acunetix report the exact file and line number behind a finding and trace a SQL injection back through the application logic to its origin, something a pure black box scanner can’t do. It’s a genuine, vendor documented IAST capability for those specific runtimes, not a marketing relabeling of ordinary DAST output.

  • Proof based scanning

When Acunetix flags a potential vulnerability, it attempts to safely exploit it to confirm the finding is real before surfacing it, attaching that evidence to the report. This meaningfully reduces the false positive triage that eats into a security team’s time on other scanners, though it applies most cleanly to vulnerability classes that can be safely demonstrated automatically, like SQL injection, and doesn’t extend to business logic issues that require human judgment to identify in the first place.

  • API security, including multilayer discovery and GraphQL

Acunetix scans REST, SOAP, and GraphQL APIs when given an OpenAPI, WSDL, or GraphQL schema definition, discovering and testing endpoints from that specification. Invicti’s current materials describe this as multilayer API discovery, finding API endpoints through the web crawl itself as well as through imported specs, plus stateful API security testing that accounts for how a session or workflow changes an API’s behavior across multiple calls rather than testing each endpoint in isolation. This corrects a real gap from a few years ago; GraphQL and API driven architectures are an actively supported, current capability, not an afterthought, though depth still depends on how complete the supplied schema is and how much of the API surface the crawl can actually reach.

  • Crawling for modern, JavaScript heavy applications

The scanner executes JavaScript to crawl single page applications built on React, Angular, and Vue, and supports macro recording for navigating multi step workflows or password protected areas that a standard crawler can’t reach on its own. Coverage still depends on how the application handles state and navigation; unusual client side routing or heavily customized authentication can require manual configuration of the crawl or login sequence.

  • CI/CD integration and compliance reporting

Acunetix integrates with Jenkins, GitHub Actions, GitLab CI, and Azure DevOps, letting teams trigger scans during a build or deployment and route findings into existing issue trackers rather than a separate security queue. It also generates reports mapped to frameworks like PCI DSS, GDPR, HIPAA , and ISO 27001. These reports document what the scan found against a framework’s technical controls; they’re evidence for an audit, not a substitute for one, and running a scan doesn’t by itself make an organization compliant.

Acunetix in 2026: What’s changed?

The headline change is the name itself. Acunetix officially became Invicti Web + API in September 2026, following the same underlying DAST engine and AcuSensor technology forward under new branding, rather than replacing the product. If you evaluated Acunetix a year or two ago, the capability set is largely the same core scanner, with a few real improvements layered on.

The most consequential correction for anyone relying on an older review: GraphQL and modern API architectures are now genuinely supported, not a weak point. Both Acunetix and its sibling Invicti products scan REST, SOAP, and GraphQL endpoints from an imported schema, and SPA crawling for React, Angular, and Vue applications is an actively promoted capability rather than a known gap.

Separately, Invicti has been publishing a broader vision around agentic, AI assisted testing, multi agent attack simulation, predictive risk scoring using signals gathered before a scan even starts, positioned as the direction for its complete AppSec Platform rather than something bundled into the standalone Web + API DAST product today. Worth watching, not yet something to budget around for this specific tool.

Pros of Acunetix

  • Proof based validation that actually saves triage time

Automatically confirming exploitability before surfacing a finding is a real, specific advantage over scanners that report every pattern match and leave verification to the analyst. It’s most valuable on high volume, well understood vulnerability classes, less so on findings that need human judgment to assess.

  • AcuSensor closes a real gap in black box testing

Getting an exact file and line number for a finding, rather than just a URL and a payload, cuts the back and forth between security and development teams that slows down remediation on a lot of DAST tools.

  • Genuinely current on modern application architectures

SPA crawling, macro based authentication, and GraphQL support mean the scanner isn’t limited to traditional server rendered web apps the way some older reviews still describe it.

  • Compliance reporting that saves real documentation time

Pre-built mappings to PCI DSS, GDPR, HIPAA, and ISO 27001 save a security or compliance team from building that documentation from scratch for every audit cycle.

Cons of Acunetix

  • Per FQDN pricing multiplies faster than expected

Licensing by target means dev, staging, and production instances of the same application typically consume separate licenses. Teams estimating cost from a single production URL routinely undercount their actual target count once every environment is added.

  • License slots lock until renewal, even if a target is removed

This is a specific, documented friction point in G2 reviews: deleting a target URL from your scan scope doesn’t free up that license slot until the contract renews, which matters for teams that rotate scan targets during a project.

  • Resource intensive on large or complex applications

Deep scans, particularly with AcuSensor instrumentation and JavaScript execution enabled, can take meaningful time and system resources on large applications. This isn’t a defect so much as the cost of thorough coverage, but it’s worth planning to scan windows around rather than assuming a quick turnaround.

  • Doesn’t cover business logic or access control the way manual testing does

Like any automated DAST tool, Acunetix is strong on injection, XSS, and misconfiguration classes, and weaker on the categories that require understanding what an application is supposed to do: broken access control, authorization chains, and multi-step business logic abuse. These are exactly the vulnerability classes at the top of the current OWASP Top 10, and closing that gap generally requires manual penetration testing alongside automated scanning, not instead of it.

Pricing

Acunetix licenses per FQDN (fully qualified domain name), meaning each distinct website, application, or API endpoint you want scanned counts as a separate target. There’s no public price list; every quote goes through Invicti’s sales team.

Based on current third party pricing data and marketplace listings rather than a single published rate card:

  • Entry level (5 target bundle): commonly cited around $7,000 a year, with some reported deals landing between $4,500 and $7,000 depending on negotiation and contract length.

  • Enterprise and MSSP: custom, quoted based on scale, deployment model, and support requirements.

Multi year contracts (commonly two years, billed annually) are typical and can improve per target pricing, though Invicti doesn’t publish discount tiers. The practical budgeting trap is undercounting targets: dev, staging, and API subdomains of the same application each typically require their own license, so the effective cost of “one application” is often three licenses, not one.

Separately, Acunetix Manual Tools , a suite of standalone manual testing utilities, remains free for both private and commercial use. It’s a companion toolset for manual testing work, not a substitute for the licensed automated scanner.

Summing up: Acunetix review

Acunetix, now branded Invicti Web + API, holds up well against a fresh 2026 evaluation. Proof based scanning genuinely reduces triage overhead, AcuSensor’s code level detail is a real differentiator over pure black box scanners, and the modern application support, SPAs, GraphQL, macro based authentication, corrects what older reviews used to flag as weaknesses. For a security team running scheduled, compliance driven scans across a known set of web applications, it’s a defensible, well supported choice.

The trade offs worth weighing are cost predictability and scope. Per FQDN pricing means the real cost of a portfolio with multiple environments adds up faster than a single quoted number suggests, and no automated DAST scanner, this one included, closes the gap on business logic and access control issues the way a human led penetration test does.

For teams whose priority is testing modern, API driven applications continuously through the development pipeline, including authenticated workflows and business logic that a scheduled DAST scan alone won’t reach, Beagle Security is an agentic AI penetration testing platform built specifically around that layer, with native GraphQL support and pricing that doesn’t scale by counting FQDNs. The two approaches solve different parts of the same problem rather than competing head to head. Start a 14 day free trial or explore the interactive demo to see whether that fits alongside or instead of a scheduled DAST scanner for your team.

FAQs

What is Acunetix used for?

Acunetix is used for automated dynamic application security testing, scanning web applications, websites, and APIs for vulnerabilities like SQL injection, XSS, and other OWASP Top 10 issues. It’s also used to generate compliance mapped reports for frameworks like PCI DSS, HIPAA, and GDPR.

Is Acunetix part of Invicti?

As of September 2026, Acunetix has been renamed Invicti Web + API. It’s no longer accurate to describe Acunetix and Invicti as two separate product lines under a shared parent company; Invicti’s own current site describes the Acunetix legacy as part of its broader DAST engine, not a parallel product. That DAST engine is itself distinct from the wider Invicti AppSec Platform, which adds SAST, SCA, and other capabilities on top of it.

Is Acunetix a DAST or IAST tool?

Primarily DAST. Its AcuSensor component adds genuine IAST style capability, runtime instrumentation and code level correlation, for applications running .NET, Java, PHP, or Node.js. For other languages or when AcuSensor isn’t deployed, it functions as a standard external DAST scanner.

How much does Acunetix cost in 2026?

There’s no public price list; Acunetix licenses per FQDN in bundles of 5, 10, or 20 targets, with entry pricing commonly cited around $7,000 a year for a 5 target bundle. Actual cost depends on target count, contract length, and deployment requirements, so a direct quote from Invicti’s sales team is necessary for an accurate number.

Sufiyan Said Sha
Written by
Cyber Security Engineer

Sufiyan once spent an entire lunch break trying to prove he was right about something nobody else cared about. Guess what, he was right. Unfortunately, everyone else had already moved on. That stubborn attention to getting things right now comes in handy in cybersecurity, where he spends his days uncovering vulnerabilities and making applications harder to break.

Pooja B
Reviewed by
Product Marketing Specialist

Pooja believes a good outfit can fix a bad day, and a good story can fix a boring topic. Between chasing creative ideas, styling things just right, and convincing herself one more edit won't hurt, she spends her days creating content at Beagle, turning creative energy into blogs, social posts, and stories that bring cybersecurity closer to people.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo