Skip to content
SocialAtoZ

Acunetix

Verified

Enterprise DAST and API security scanner now part of Invicti's AppSec platform

Not yet rated. Be the first to review Acunetix.

Acunetix screenshot See all screenshots
  • Deployment Cloud Based, On Premises
  • Starting price Custom
  • Free trial Available
  • Best for SMEs, Agencies, Enterprises

What is Acunetix?

Acunetix is a dynamic application security testing (DAST) scanner originally founded in Malta in 2005, now operating as part of Invicti Security's application security platform, with a primary office in Austin, Texas alongside teams in Malta, the UK, and Turkey. It scans web applications and APIs for over 7,000 vulnerability types, including OWASP Top 10 issues, using proof-based scanning to confirm findings and reduce false positives.

The platform adds AcuSensor for runtime code-level insight in PHP, ASP.NET, Java, and Node.js applications, plus AcuMonitor for out-of-band detection of blind XSS, XXE, and SSRF flaws. Acunetix is sold in Essentials, Professional, and Ultimate tiers, all priced through a custom quote rather than published rates, and it targets security teams at growing and enterprise organizations.

Key Features of Acunetix

Acunetix lists 10 documented features, including Dynamic Application Security Testing (DAST) detecting 7,000+ vulnerability types, AI-powered DAST scanning on Professional and Ultimate tiers and API security scanning for REST, SOAP, and GraphQL. The list below covers what the product does rather than how it is marketed.

  • Dynamic Application Security Testing (DAST) detecting 7,000+ vulnerability types
  • AI-powered DAST scanning on Professional and Ultimate tiers
  • API security scanning for REST, SOAP, and GraphQL
  • AcuSensor runtime sensor for PHP, ASP.NET, Java, and Node.js
  • AcuMonitor out-of-band detection for blind XSS, XXE, and SSRF
  • Proof-based scanning to reduce false positives
  • LLM application scanning
  • Runtime Software Composition Analysis (SCA) via Mend integration
  • Predictive risk scoring for vulnerability prioritization
  • Integrations with Jira, GitHub, GitLab, and CI/CD pipelines

Acunetix Pricing

Acunetix lists 3 plans without published figures. Pricing is quoted on request.

Essentials

Custom

Priced per FQDN target

Core DAST scanning, standard API scanning, LLM scanning, predictive risk scoring, runtime SCA, cloud-only hosting

Professional

Custom

Priced per FQDN target

Adds AI-powered DAST, advanced automations, CI/CD and ticketing integrations, internal app scanning via agents

Ultimate

Custom

Priced per FQDN target

Adds full API security, customizable RBAC, bring-your-own-cloud, on-premises and air-gapped deployment, IAST, audit logs

Acunetix Specifications

Acunetix is available on web app. It offers an API and has a free trial.

Deployment
  • Cloud Based
  • On Premises
Billing cycle
Yearly
Desktop
  • Web App
Languages
  • English
Built for
  • SMEs
  • Agencies
  • Enterprises
Support
  • Email
  • Phone
  • Live Support
  • Tickets
Integrations
Jira, GitHub, GitLab, Azure DevOps, CI/CD pipelines, Mend SAST/SCA/Container Security
Public API
Yes
Free trial
Yes
Free plan
No
Runs in browser
Yes
Customisable
Yes
Website
acunetix.com

Acunetix Videos

Acunetix Screenshots

Acunetix Reviews

No reviews yet

Used Acunetix? Share your experience and help other buyers decide.

Acunetix FAQs

Acunetix's own FAQ confirms a trial option is available; prospects request access via the demo/quote form rather than a self-serve signup.

Acunetix operates as a brand under Invicti Security, formed when Invicti brought together Netsparker and Acunetix; the site itself states Acunetix DAST now powers runtime capabilities within Invicti's platform.

Pricing is not published; all three tiers (Essentials, Professional, Ultimate) require a custom quote based on the number of FQDN targets scanned.

On-premises is available on the Ultimate tier and listed as coming soon as an add-on for Professional; Essentials is cloud-only.

AcuSensor is an optional runtime sensor installed alongside PHP, ASP.NET, Java, or Node.js applications that gives Acunetix deeper, code-level diagnostic insight into confirmed vulnerabilities.