Acunetix

4.4 (34)
Write a Review!
All-in-one automated web application security solution

Overall rating

4.4 /5
(34)
Value for Money
4/5
Features
4.2/5
Ease of Use
4.4/5
Customer Support
4.2/5

88%
recommended this app
Sort by

34 Reviews

Mohit
Mohit
Overall rating
  • Industry: Computer & Network Security
  • Company size: 11–50 Employees
  • Used Daily for 6-12 months
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Likelihood to recommend 7.0 /10

Vulnetability scanner

Reviewed on 2019/05/04

Cool tool and deserves to get tried once.

Cool tool and deserves to get tried once.

Pros

- No doubt, easy to setup
- Easy to manage vulnerabilities
- Network level scanning is cool
- Good for Blackbox testing

Cons

- I believe post authentication scripts need improvement as it still throws duplicates and few bugs are duplicates the accuracy rate is quite high but still need improvement in existing scripts.

- Needs more modern vulnerabilities detection it might got lots of vulnerabilities in the existing database and its good but not sufficient.

Response from Invicti

Thank you for your feedback. We will look into improving our vulnerability detection.

Verified Reviewer
Overall rating
  • Industry: Information Technology & Services
  • Company size: 201–500 Employees
  • Used Weekly for 6-12 months
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 8.0 /10

Simple, but very powerful web vunlerability scanner

Reviewed on 2018/08/13

Good thing for a web application pentesting, can give You insight of a present vulnerabilities....

Good thing for a web application pentesting, can give You insight of a present vulnerabilities. Would recommend using in tandem with infrastructure scanner (like Nessus) to create a complete testing solution. Also presence of continous scanning and scheduler could be used for a regular security assesment of Your web applications.

Pros

Ease of use, good customer support, very insightful reports (especially Developer raport), good vulnerability management. Also continous scanning option is an interesting thing for having continous security awareness of Your vulnerability level. Also login sequence recorder is an awesome tool.

Cons

Not a lot of scan options to configure - especially in comparison to Nessus - every check is done in default, You can't choose specifically which test is done in selected scan, only the type of scan (full, high-risk vulnerabilities, xss, sqli, weak passwords, crawl only ) or technology in which the scanned web app is written.

Response from Invicti

Thank you for your feedback ¿ we¿re glad that Acuneix is working for you.

Regarding your comment about choosing what to scan for ¿ you can already do this in Acunetix, although the feature is slightly hidden away in Settings > Scan Types. Here you can create your own custom Scan Types, and you will be able to choose which vulnerabilities to check for. When creating a new custom Scan Type, you can filter the vulnerability checks from the top right hand corner of the page.

Remember that you can also easily retest for a specific vulnerability identified in a previous scan.

Verified Reviewer
Overall rating
  • Industry: Computer & Network Security
  • Company size: 11–50 Employees
  • Used Daily for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 7.0 /10

Ok tool, but fix your business model and add more settings to the interface

Reviewed on 2018/08/17

Continuation of the cons section (number of chars was limited).

* Settings are sometimes unclear,...

Continuation of the cons section (number of chars was limited).

* Settings are sometimes unclear, an info icon with a popup would be nice.

Example 1: In the "Site Structure" of a scan it is possible to press "exclude", does it exlude the path from futre scans? If so why don't I see anything in the target settings? Or does "exlude" exclude vulnerabilities from the report? BTW after pressing exlude I'm not able to "include" it again.

Example 2: "scan speed", how many threads per setting are we talking about?

* Would definitly like to get some more feedback from scans directly in the interface, what is it doing, why did it fail, did all the "allowed hosts" got scanned etc. I know you can debug a target, but this is not what I mean.

Pros

* The number of checks that take place.

* The quality of the issues found.

* After years it is finally possible to pause a scan, hallelujah.

Cons

* As a pentester I absolutely miss a more flexible way to configure settings like it was possible in v10. The interface is built as "point a shoot", idiot proof. Currently, If I want to configure things I need to change xml config files on the server and reload acunetix...

* After the release of v12 we were called by a sales agent as we suddently couldn't add targets anymore. The license model suddenly changed completely. The entire business model is now based on scanning an applications continuously over the year. However, as a pentesting business for we mostly scan apps just 1 time for our security assessments. It absolutely makes no sense to apply the same costs! Just like Netsparker, acunetix should have plans for pentesters and consultants.

* Scanning an app that spans multiple domains always results in problems. Currently you have the "Allowed hosts" settings which is crappy in setting up. I need to set all (sub) domains to a different target. And ofcourse with the current business model you are charged per target, lol.

Response from Invicti

Thank you for your honest feedback:

As you rightly say, we try to keep an easy to use interface, with the intention of automatically detecting the best way to scan the site. There are some settings which are not used by most of our customers, and which can be manually tweaked from the settings file.

I think you might have missed the little help icon at the top right corner of the Acunetix interface. When clicked, this provides help on the settings loaded in the current page. But to answer your queries:

Example 1 - When you Exclude a path from the Site Structure, the exclusion will be stored with the Target, and will affect subsequent scans. You can delete the exclusion from the Target settings.

Example 2: this is explained on our website at https://www.acunetix.com/blog/docs/configure-scan-speed-acunetix/. I have forwarded your comment about the scan feedback to the product team.

Regarding licensing, I would suggest that you get in touch with our sales team, who can work

Verified Reviewer
Overall rating
  • Industry: Financial Services
  • Company size: 51–200 Employees
  • Used Weekly for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 8.0 /10

Easy to setup, nice results

Reviewed on 2018/08/13

As a scanner it is quite good, relevant and well described findings, so far no false positives....

As a scanner it is quite good, relevant and well described findings, so far no false positives. Following an initial trial and PoC with couple of competitors, Acunetix had the best features, most suitable licensing model, good support, so we purchased a three year license. However, at some point, it all changed. The license became based on other criteria, the testing and verification tools were removed, there is no support or way of reverting to a previous version, after you realise that the changes introduced and making the software unusable or insufficient. Overall, unless there are guarantees that it won't happen again, I will be very reluctant to renew.

Pros

Very easy to setup initially, running scans quite fast, good crawler, very nice and understandable results.

Cons

The license model changed somehow in the middle of the three years, so it became impossible to continue to use it as planned without paying much more. Tools were removed.

Response from Invicti

Thank you for your feedback.

You can download the free Acunetix Manual Pentesting Tools from https://www.acunetix.com/vulnerability-scanner/free-manual-pen-testing-tools/. You can copy the Request done by Acunetix from the Vulnerability details, and use this in the Acuneix Manual Tools

Verified Reviewer
Overall rating
  • Company size: 501–1,000 Employees
  • Used Daily for 1+ year
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 9.0 /10

Great for developers for self evaluation

Reviewed on 2018/07/19

Pros

I have been using acunetix web vulnerability scanner since last 2 years as I develop Web apps and Websites in my professional career so I like to test it by myself for the vulnerabilities.
It gives me scope for improvement in my programming skills.
As it gives the developer report as a part of the report its very indepth report and very useful for me to develop secure web apps
I really like the web interface they have provided It reduces the dependancy of a device to carry.
really good.

Cons

There is nothing so far to dislike this software.
As my needs are getting fulfilled by the available functionalities.
Looking forward to new updates.

Response from Invicti

Thank you for your feedback

Hayrani
Hayrani
Overall rating
  • Industry: Computer & Network Security
  • Company size: 2–10 Employees
  • Used Weekly for Free Trial
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 0.0 /10

Terrible sales team!

Reviewed on 2023/01/18

Not interested with this anymore

Not interested with this anymore

Cons

We could not even try the trial the program. The first thing they asked without seeing the demo are you going to purchase the licence or not :) I am working more +10 years experience as a security expert. I never had an experience like that before. I already emailed the invicti about this.

Verified Reviewer
Overall rating
  • Company size: 501–1,000 Employees
  • Used Weekly for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 4.0 /10

I've been using Acunetix for 5 years already, and it's getting worst instead of getting...

Reviewed on 2018/07/09

Pros

- easy to use
- friendly UI
- easy to read reports
- the support is all right
- price used to be a pro

Cons

- they removed a lot of functionality in the last 2 years (starting with version 10): you are not able to crawl and scan only some of the parts of the website, based on the crawling made, you were not able to pause the scan (they re-introduced that in v12), not able to see the reply from the server for found vulnerabilities, in order to confirm them, it's not properly working for some login pages, it's not properly working on big websites, webshops, etc (the crawling takes ages!)

Response from Invicti

Thank you for your feedback.

Most of the features that you are missing have been re-introduced in newer updates.

You can now select to exclude parts of a site using the Site Structure identified in a previous scan.

As you rightly say, you can Pause scans in the latest version of Acunetix. You can also change the Target Settings and resume the scan with the new settings.

Response headers have also been re-introduced recently.

We would appreciate if you can provide more details on the issues with the Login of some sites and larger sites. Please send this info to our support team at [email protected]

Will
Will
Overall rating
  • Industry: Internet
  • Company size: 11–50 Employees
  • Used Weekly for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 8.0 /10

A well priced, cloud based vulnerability scanner

Reviewed on 2018/01/21

Pros

I can schedule daily, weekly or monthly scans of targets which checks for vulnerabilities in our cloud infrastructure from one control panel. The ability to send different types of reports to various parties, for example a 'Board level' report or 'Developer' report is handy for tailoring content to the audience.

Cons

It perhaps could be improved by adding a section for commenting on how a vulnerability was fixed and a link to a relevant URL to confirm this. Pricing is good for a small amount of targets, but quickly becomes expensive for multiple target locations.

Response from Invicti

Thank you for your feedback

Darshana
Darshana
Overall rating
  • Industry: Computer & Network Security
  • Company size: 11–50 Employees
  • Used Monthly for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 10.0 /10

Delivers what it promises | Automated Web Security Scanning

Reviewed on 2019/08/23

Modular and complete application level testing of agreed upon domains is usually done with ease and...

Modular and complete application level testing of agreed upon domains is usually done with ease and reports are generated with rich content.

Pros

With self-explanatory reports, the assessment procedure is easy to setup and configure. Prioritization and classification help resolve issues that are vital to the organization.

Cons

Since a comprehensive scan takes place with advanced crawling and authentication capabilities, the process might take a bit longer than expected, which is nothing in comparison to the information rendered.

Response from Invicti

Thank you for submitting your review of Acunetix on Capterra, we appreciate your time and are glad to hear we are of service to your business.

Regards
Acunetix Team

Tejas
Tejas
Overall rating
  • Industry: Computer & Network Security
  • Company size: 51–200 Employees
  • Used Monthly for 6-12 months
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 8.0 /10

Good web application vulnerability scanner but not recommended.

Reviewed on 2018/10/02

Pros

This is a good tool for performing web application scan vulnerability assessment. It’s as automated tool which supports application scan provided the URL of applications.

It can give compliance reports including PCI DSS, HIPPAA, OWASP TOP 10 etc.

Acunetix can do credential based scan for web applications.

Cons

Al tough its good tool, from the past experiences of using it, Sometimes acunetic automatically logs out of session while performing the test.

Also, acuneix could provide many false positives, as result have to cross check manually about the details of the scan results.

Response from Invicti

Thank you for your candid feedback.

During an automated scan, Acunetix will make a lot of requests, some of which will invalidate the session. Acunetix is able to automatically detect this and will login to the web application to continue scanning the restricted area. As regards false positives, we would be very interested in getting to know about these. Would you be able to forward samples to our team at [email protected]?

Verified Reviewer
Overall rating
  • Industry: Computer & Network Security
  • Company size: 1,001–5,000 Employees
  • Used Daily for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 10.0 /10

Great audit tool

Reviewed on 2018/08/13

after using the tool for several years I can say that it is one of the best web vulnerability...

after using the tool for several years I can say that it is one of the best web vulnerability scaners on the market

Pros

Faster analysis, low false positives and intuitive interface

Cons

Take out the manual tools from the acunetix web has been an error.

Response from Invicti

Thank you for your feedback.

You can download the free Acunetix Manual Pentesting Tools from https://www.acunetix.com/vulnerability-scanner/free-manual-pen-testing-tools/. You can copy the Request done by Acunetix from the Vulnerability details, and use this in the Acuneix Manual Tools

Verified Reviewer
Overall rating
  • Industry: Financial Services
  • Company size: 1,001–5,000 Employees
  • Used Monthly for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 8.0 /10

Best Web assessment tool

Reviewed on 2020/09/27

Acunetix is quite a strong tool for web assessments even though it did not support other types of...

Acunetix is quite a strong tool for web assessments even though it did not support other types of assessments. Both on prem and cloud scanners are available. Less false positives compared to other tools and price is a bit expensive. Lots of options available to download reports. Overall its a good tool for web assessment.

Pros

User-friendly simple graphical interface with point and shoot approach makes the assessment conducting easy even for non-technical people. Provide detailed vulnerability assessment reports with testing examples. It provides reports for developers for developing options and reports can be generated according to the required compliance standard like

Cons

Acunetix doesn’t provide comprehensive CSV format downloads. Provided CSV files format needs to improve. Accunetix currently supports only web assessment. It can.not be used as all in one tool. Recently they have changed their licensing method and price is quite expensive compared to other tools.

Kai
Overall rating
  • Industry: Information Technology & Services
  • Company size: 51–200 Employees
  • Used Weekly for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 9.0 /10

Acunetix always gives me a very good first impression

Reviewed on 2018/08/10

Pros

We are using Acunetix now for more than 5 years. It is very easy to create new targets and quickly start automatic scans. The AcuSensor often gives me a good hint where I should take a closer look manually.
Our management likes the well structured reports.

Cons

If a web application is very complex, the scanner sometimes does not really manage to find its path through the process.
Since the application changed to the web gui, it is more complicated to specify pre-recorded login sequence. The user has to log into the server, where Acunetix is hostet and start a different application to record the sequence.

Response from Invicti

Thank you for your feedback.

We are planning on integrating the Acunetix Login Sequence Recorder in the Acunetix web UI. This will make it easier to record login sequences moving forward. If all goes well, we will have this feature in place by the end of Q3 / beginning Q4 this year.

Verified Reviewer
Overall rating
  • Industry: Computer & Network Security
  • Company size: 2–10 Employees
  • Used Weekly for 1+ year
  • Review Source

Overall rating

  • Ease of Use
  • Likelihood to recommend 10.0 /10

Scanning made Simplified

Reviewed on 2018/12/19

Pros

Acunetix has a variety of network vulnerability scanning methods called "tests" which can be easily configures with a quick setup. Also, the GUI is very pleasant and user friendly plus you don't have to be an expert on the subject matter to use this.

Cons

Does not support Active Directory and static review process. And scan time is highly dependent on your down-link.

Response from Invicti

Thank you for your feedback

Verified Reviewer
Overall rating
  • Industry: Higher Education
  • Company size: 1,001–5,000 Employees
  • Used Daily for 6-12 months
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 10.0 /10

Accunetix in Education

Reviewed on 2018/10/30

Dynamic Application Security Testing.

Dynamic Application Security Testing.

Pros

Ease of use and cost makes this product's RIO right on the money.

Cons

LAck of AD support, and static review process.

Response from Invicti

Thank you for your feedbcak

Andreas
Overall rating
  • Industry: Telecommunications
  • Company size: 1,001–5,000 Employees
  • Used Weekly for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 10.0 /10

Automated Web Vulnerability Scanning with Acunetix

Reviewed on 2018/08/13

I use Acunetix to scan our Websites and web applications, usually on the test machines, in order to...

I use Acunetix to scan our Websites and web applications, usually on the test machines, in order to spot vulnerabilities before moving things to production. The nice thing with Acunetix is that you can schedule automated scans, daily, weekly or monthly, so you can just check the reports with the affected items.

Pros

I have been using the On Premises version for a few years now. Acunetix is really easy to use with a very user-friendly web portal to manage the targets, scans, reports, settings, etc. I really like the reports, after every scan, from which you can easily spot the important and high risk vulnerabilities, with recommendations on how to fix each issue.

Cons

nothing, everything is perfect! the only catch is the price change, but I believe it's worth it.

Response from Invicti

Thank you for an excellent review. We are really happy Acunetix is working out for you

Gianni
Overall rating
  • Industry: Computer & Network Security
  • Company size: 2–10 Employees
  • Used Daily for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 10.0 /10

excellent quality!

Reviewed on 2018/08/12

We worked very well with Acunetix in the last years, we look forward to go on this way

We worked very well with Acunetix in the last years, we look forward to go on this way

Pros

an intuitive, efficient, affordable application

Cons

customer support is quite slow to answer; network scan has been removed, it was a useful function; price increase didn't make us happier

Response from Invicti

Thank you for your feedback. Network Scans are still available with Acunetix Online. We will work on improving our Support.

Jesper
Jesper
Overall rating
  • Industry: Computer Software
  • Company size: 501–1,000 Employees
  • Used Weekly for 1+ year
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 3.0 /10

Too many issues not found

Reviewed on 2018/08/10

Acunetix helped us get going with security scans. In the end, the lack of support for certain...

Acunetix helped us get going with security scans. In the end, the lack of support for certain attacks made us change.

Pros

Very easy to use, nice GUI and reports...

Cons

Too many issues were not discovered by Acunetix, and subsequently found by customers wielding different tools.

Response from Invicti

Sorry to see you go

Verified Reviewer
Overall rating
  • Industry: Banking
  • Company size: 201–500 Employees
  • Used Weekly for 1+ year
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 10.0 /10

Acunetix perfect vulnerability manager solution

Reviewed on 2019/01/15

We use on premise solution. Great solution for small and big enterprises

We use on premise solution. Great solution for small and big enterprises

Pros

User friendly interface. Fast scan. Great on premise and cloud solution

Cons

The solution work great. I don`t have something that i like least

Response from Invicti

Thank you for your positive review

Brittane
Overall rating
  • Used Weekly for 6-12 months
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support

Most user friendly vulnerability scanner i've used

Reviewed on 2018/02/18

Pros

Acunetix user experience (UX) is one of the best i've encountered. The dashboard feature is very useful for technically inclined and non-technically inclined users. The user interface is appealing and you can find all your statistics on the dashboard. You don't have to look very far to see a summary report of previous or current scans. The dashboard can show you an app's vulnerabilities based on severity by colour coding severities. You can also generate easy to read reports with a click of a button based on the type of report you want.

Cons

The only con I found in this software is lack of support. The response time of the customer service team is poor. I waited weeks to get a response from the team and even then, the back and forth was not helpful as I was not able to get help fast enough.

Response from Invicti

Thank you for taking the time to review Acunetix. We are glad you like our new dashboard. We will look at improving our support process.

Verified Reviewer
Overall rating
  • Industry: Food & Beverages
  • Company size: 201–500 Employees
  • Used Weekly for 6-12 months
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 10.0 /10

Perfect vulnerability management solution

Reviewed on 2019/01/16

We use cloud solution. It can be used by small and big companies

We use cloud solution. It can be used by small and big companies

Pros

Perfect vulnerability management solution. Easy to use. User friendly interface

Cons

Nothing, everything work perfect. Recommend

Response from Invicti

Thank you for your positive review. We are very happy that Acunetix is working out well for you.

Malkit
Overall rating
  • Industry: Information Technology & Services
  • Company size: 501–1,000 Employees
  • Used Daily for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 9.0 /10

Overall Review of Acunetix

Reviewed on 2018/12/10

This is the best and easiest tool to Scanning for Penetration testing

This is the best and easiest tool to Scanning for Penetration testing

Pros

Ease of use
Features and Functionalities

Cons

Scanning time
Concurrent Scans
Pricing and license timing

Response from Invicti

Many thanks for your feedback

Jacek
Overall rating
  • Industry: Outsourcing/Offshoring
  • Company size: 501–1,000 Employees
  • Used Weekly for 2+ years
  • Review Source

Overall rating

  • Ease of Use
  • Likelihood to recommend 9.0 /10

Great tool supporting secure SDLC process

Reviewed on 2018/08/20

Pros

+ Ease of use
+ Point&shoot approach allowing for quick validation of target's overal security
+ Support for various login mechanisms (including OAuth/SSO)
+ Great as part of SDL process

Cons

- Scans might sometimes be slow when run over the internet

Response from Invicti

Thank you for your feedback. We are happy you are satisfied with the product.

Alvaro
Overall rating
  • Industry: Wireless
  • Company size: 1,001–5,000 Employees
  • Used Weekly for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 8.0 /10

Amazing Pentesting tool

Reviewed on 2018/08/10

Pros

It is a very fast and stable tool, Acunetix allows you to perform a security audit in an easy and intuitive way.

Cons

Does not allow to audit webservice in the latest version

Response from Invicti

Thank you for your feedback.

In the most recent versions, the auditing of a web service has been integrated in the scanner. You can just create a normal scan for the web service, and Acunetix will proceed with scanning it as it used to do before.

Tobias
Overall rating
  • Industry: Government Administration
  • Company size: 10,000+ Employees
  • Used Weekly for 2+ years
  • Review Source

Overall rating

  • Value for Money
  • Ease of Use
  • Customer Support
  • Likelihood to recommend 8.0 /10

Quick and easy to use

Reviewed on 2018/09/05

Very positive, support top. Software perfect for a quick, general overview of the web application...

Very positive, support top. Software perfect for a quick, general overview of the web application security.

Pros

Quick setup, with a wide range of tests.

Cons

The built in login broweser, as it is outdated and does not support technology like index.db etc.

Response from Invicti

Thank you for your feedback. We are currently working on a new version of the Login Sequence Recorder which will be able to support a large number of new technologies