Acunetix (Invicti Web + API) review: Features, pros/cons, and pricing

Acunetix is a web application and API security scanner built around dynamic application security testing (DAST), with an internal instrumentation layer called AcuSensor that adds runtime, code level detail for supported languages. As of September 2026, the product has been officially renamed Invicti Web + API , though “Acunetix” remains the name most people search for and the one still used across its documentation and changelogs during the transition.
The rename doesn’t change what the product does day to day. It’s still a scanner for websites, web applications, and APIs, not a general infrastructure vulnerability scanner and not the same thing as the broader Invicti AppSec Platform, which adds SAST, SCA, secrets detection, and ASPM correlation on top of the same DAST engine. Invicti’s own current site describes the Acunetix legacy as part of its broader DAST engine now, not a parallel product sold alongside it, which matters if you’re trying to figure out what you’d actually be buying under either name. This review covers that DAST product specifically: what it tests, how proof based scanning actually works, current pricing, and where a security program built around it will need something else.
TL;DR: Acunetix review
Acunetix, now sold as Invicti Web + API, is a mature DAST scanner with a genuinely strong track record on vulnerability detection and validation. Its proof based scanning safely exploits findings to confirm they’re real before surfacing them, which cuts down on the manual triage that plagues less selective scanners. Current documentation and multiple technical reviews confirm it handles modern JavaScript applications, SPAs, and API architectures, including GraphQL, when given a schema, correcting some of what older reviews of the product used to say.
The trade offs are cost and scope, not outdated technology. Licensing is per FQDN with a five target minimum, which multiplies quickly across dev, staging, and production environments, and the product is a DAST scanner, not a replacement for manual penetration testing when it comes to business logic and access control flaws.
| G2 rating | 4.1 out of 5, based on 105 reviews |
| Best suited for | Security teams running scheduled, compliance driven scans across a defined set of web applications and APIs |
| Coverage | Web applications, APIs (REST, SOAP, GraphQL with schema import), SPAs, authenticated and password protected areas |
| Pricing model | Per FQDN (target) licensing in bundles of 5, 10, or 20; no public rate card, quote required |
| Key strengths | Proof based validation of findings, AcuSensor's code level detail for supported languages, mature crawling for modern JavaScript apps |
| Key trade offs | Target based pricing multiplies across environments, resource intensive on large or complex applications, doesn't cover business logic or access control the way manual testing does |

Recent G2 reviews describe the scanning engine as accurate and the reporting as detailed enough to hand to a development team directly. The most consistent criticism isn’t the detection quality, it’s that scans can be resource intensive and slow on large or complex applications, and that the volume of findings on a first scan takes real time to triage.
Key features of Acunetix

- Automated DAST scanning for web applications and APIs
Acunetix crawls and attacks a running application the way an external attacker would, covering websites, web applications, and APIs from outside the codebase. It handles authenticated scans and session based applications, executing JavaScript to reach application states that a simpler crawler would miss entirely.
- AcuSensor for code level detail (IAST style instrumentation)
AcuSensor is a lightweight agent deployed alongside a running application (supporting .NET, Java, PHP, and Node.js) that observes how requests are processed internally while the DAST scanner tests from outside. This combination lets Acunetix report the exact file and line number behind a finding and trace a SQL injection back through the application logic to its origin, something a pure black box scanner can’t do. It’s a genuine, vendor documented IAST capability for those specific runtimes, not a marketing relabeling of ordinary DAST output.
- Proof based scanning
When Acunetix flags a potential vulnerability, it attempts to safely exploit it to confirm the finding is real before surfacing it, attaching that evidence to the report. This meaningfully reduces the false positive triage that eats into a security team’s time on other scanners, though it applies most cleanly to vulnerability classes that can be safely demonstrated automatically, like SQL injection, and doesn’t extend to business logic issues that require human judgment to identify in the first place.
- API security, including multilayer discovery and GraphQL
Acunetix scans REST, SOAP, and GraphQL APIs when given an OpenAPI, WSDL, or GraphQL schema definition, discovering and testing endpoints from that specification. Invicti’s current materials describe this as multilayer API discovery, finding API endpoints through the web crawl itself as well as through imported specs, plus stateful API security testing that accounts for how a session or workflow changes an API’s behavior across multiple calls rather than testing each endpoint in isolation. This corrects a real gap from a few years ago; GraphQL and API driven architectures are an actively supported, current capability, not an afterthought, though depth still depends on how complete the supplied schema is and how much of the API surface the crawl can actually reach.
- Crawling for modern, JavaScript heavy applications
The scanner executes JavaScript to crawl single page applications built on React, Angular, and Vue, and supports macro recording for navigating multi step workflows or password protected areas that a standard crawler can’t reach on its own. Coverage still depends on how the application handles state and navigation; unusual client side routing or heavily customized authentication can require manual configuration of the crawl or login sequence.
- CI/CD integration and compliance reporting
Acunetix integrates with Jenkins, GitHub Actions, GitLab CI, and Azure DevOps, letting teams trigger scans during a build or deployment and route findings into existing issue trackers rather than a separate security queue. It also generates reports mapped to frameworks like PCI DSS, GDPR, HIPAA , and ISO 27001. These reports document what the scan found against a framework’s technical controls; they’re evidence for an audit, not a substitute for one, and running a scan doesn’t by itself make an organization compliant.
Acunetix in 2026: What’s changed?
The headline change is the name itself. Acunetix officially became Invicti Web + API in September 2026, following the same underlying DAST engine and AcuSensor technology forward under new branding, rather than replacing the product. If you evaluated Acunetix a year or two ago, the capability set is largely the same core scanner, with a few real improvements layered on.
The most consequential correction for anyone relying on an older review: GraphQL and modern API architectures are now genuinely supported, not a weak point. Both Acunetix and its sibling Invicti products scan REST, SOAP, and GraphQL endpoints from an imported schema, and SPA crawling for React, Angular, and Vue applications is an actively promoted capability rather than a known gap.
Separately, Invicti has been publishing a broader vision around agentic, AI assisted testing, multi agent attack simulation, predictive risk scoring using signals gathered before a scan even starts, positioned as the direction for its complete AppSec Platform rather than something bundled into the standalone Web + API DAST product today. Worth watching, not yet something to budget around for this specific tool.
Pros of Acunetix
- Proof based validation that actually saves triage time
Automatically confirming exploitability before surfacing a finding is a real, specific advantage over scanners that report every pattern match and leave verification to the analyst. It’s most valuable on high volume, well understood vulnerability classes, less so on findings that need human judgment to assess.
- AcuSensor closes a real gap in black box testing
Getting an exact file and line number for a finding, rather than just a URL and a payload, cuts the back and forth between security and development teams that slows down remediation on a lot of DAST tools.
- Genuinely current on modern application architectures
SPA crawling, macro based authentication, and GraphQL support mean the scanner isn’t limited to traditional server rendered web apps the way some older reviews still describe it.
- Compliance reporting that saves real documentation time
Pre-built mappings to PCI DSS, GDPR, HIPAA, and ISO 27001 save a security or compliance team from building that documentation from scratch for every audit cycle.
Cons of Acunetix
- Per FQDN pricing multiplies faster than expected
Licensing by target means dev, staging, and production instances of the same application typically consume separate licenses. Teams estimating cost from a single production URL routinely undercount their actual target count once every environment is added.
- License slots lock until renewal, even if a target is removed
This is a specific, documented friction point in G2 reviews: deleting a target URL from your scan scope doesn’t free up that license slot until the contract renews, which matters for teams that rotate scan targets during a project.
- Resource intensive on large or complex applications
Deep scans, particularly with AcuSensor instrumentation and JavaScript execution enabled, can take meaningful time and system resources on large applications. This isn’t a defect so much as the cost of thorough coverage, but it’s worth planning to scan windows around rather than assuming a quick turnaround.
- Doesn’t cover business logic or access control the way manual testing does
Like any automated DAST tool, Acunetix is strong on injection, XSS, and misconfiguration classes, and weaker on the categories that require understanding what an application is supposed to do: broken access control, authorization chains, and multi-step business logic abuse. These are exactly the vulnerability classes at the top of the current OWASP Top 10, and closing that gap generally requires manual penetration testing alongside automated scanning, not instead of it.
Pricing
Acunetix licenses per FQDN (fully qualified domain name), meaning each distinct website, application, or API endpoint you want scanned counts as a separate target. There’s no public price list; every quote goes through Invicti’s sales team.
Based on current third party pricing data and marketplace listings rather than a single published rate card:
Entry level (5 target bundle): commonly cited around $7,000 a year, with some reported deals landing between $4,500 and $7,000 depending on negotiation and contract length.
Enterprise and MSSP: custom, quoted based on scale, deployment model, and support requirements.
Multi year contracts (commonly two years, billed annually) are typical and can improve per target pricing, though Invicti doesn’t publish discount tiers. The practical budgeting trap is undercounting targets: dev, staging, and API subdomains of the same application each typically require their own license, so the effective cost of “one application” is often three licenses, not one.
Separately, Acunetix Manual Tools , a suite of standalone manual testing utilities, remains free for both private and commercial use. It’s a companion toolset for manual testing work, not a substitute for the licensed automated scanner.
Summing up: Acunetix review
Acunetix, now branded Invicti Web + API, holds up well against a fresh 2026 evaluation. Proof based scanning genuinely reduces triage overhead, AcuSensor’s code level detail is a real differentiator over pure black box scanners, and the modern application support, SPAs, GraphQL, macro based authentication, corrects what older reviews used to flag as weaknesses. For a security team running scheduled, compliance driven scans across a known set of web applications, it’s a defensible, well supported choice.
The trade offs worth weighing are cost predictability and scope. Per FQDN pricing means the real cost of a portfolio with multiple environments adds up faster than a single quoted number suggests, and no automated DAST scanner, this one included, closes the gap on business logic and access control issues the way a human led penetration test does.
For teams whose priority is testing modern, API driven applications continuously through the development pipeline, including authenticated workflows and business logic that a scheduled DAST scan alone won’t reach, Beagle Security is an agentic AI penetration testing platform built specifically around that layer, with native GraphQL support and pricing that doesn’t scale by counting FQDNs. The two approaches solve different parts of the same problem rather than competing head to head. Start a 14 day free trial or explore the interactive demo to see whether that fits alongside or instead of a scheduled DAST scanner for your team.
FAQs
What is Acunetix used for?
Acunetix is used for automated dynamic application security testing, scanning web applications, websites, and APIs for vulnerabilities like SQL injection, XSS, and other OWASP Top 10 issues. It’s also used to generate compliance mapped reports for frameworks like PCI DSS, HIPAA, and GDPR.
Is Acunetix part of Invicti?
As of September 2026, Acunetix has been renamed Invicti Web + API. It’s no longer accurate to describe Acunetix and Invicti as two separate product lines under a shared parent company; Invicti’s own current site describes the Acunetix legacy as part of its broader DAST engine, not a parallel product. That DAST engine is itself distinct from the wider Invicti AppSec Platform, which adds SAST, SCA, and other capabilities on top of it.
Is Acunetix a DAST or IAST tool?
Primarily DAST. Its AcuSensor component adds genuine IAST style capability, runtime instrumentation and code level correlation, for applications running .NET, Java, PHP, or Node.js. For other languages or when AcuSensor isn’t deployed, it functions as a standard external DAST scanner.
How much does Acunetix cost in 2026?
There’s no public price list; Acunetix licenses per FQDN in bundles of 5, 10, or 20 targets, with entry pricing commonly cited around $7,000 a year for a 5 target bundle. Actual cost depends on target count, contract length, and deployment requirements, so a direct quote from Invicti’s sales team is necessary for an accurate number.
![Top 10 penetration testing companies [2026] Top 10 penetration testing companies [2026]](/blog/images/top-penetration-testing-companies-cover.webp)




![Top Snyk alternatives & competitors [2026] Top Snyk alternatives & competitors [2026]](/blog/images/top-snyk-alternatives-cover.webp)

![BurpSuite vs Acunetix: Which is the best choice for you? [2026] BurpSuite vs Acunetix: Which is the best choice for you? [2026]](/blog/images/burpsuite-vs-acunetix-cover.webp)


![The 7 best Veracode alternatives in the market today [2026] The 7 best Veracode alternatives in the market today [2026]](/blog/images/veracode-alternatives-cover.webp)

![Burp Suite vs ZAP: Which is the best choice for you? [2026] Burp Suite vs ZAP: Which is the best choice for you? [2026]](/blog/images/burpsuite-vs-zap-cover.webp)
