Compare
Compare anything, side by side
Pick up to 4 security testing and we'll lay out their specifications side by side. Apples to apples only — once you pick the first item, the picker locks to its category so you don't end up comparing Selenium with OWASP Top 10.
×
OWASP ZAP
OWASP
Open Source
Free Tier
Self-Hosted
Free, open-source web app security scanner.
Visit website ↗
×
Invicti (Netsparker)
Invicti
Commercial
Cloud / SaaS
Enterprise
Automated DAST with proof-based scanning.
Visit website ↗Side-by-side
Specification comparison
Schema: Tools. Missing values are marked "Not available yet" — those are next on our research list.
Rating key:
Positive / Free / Fast
Limited / Moderate
Difficult / Steep
Informational
| Attribute | ||
|---|---|---|
| Pricing | Free |
Standard
from ~$4,495/yr; Enterprise custom
|
| Free tier / OSS |
100%
open source
|
Demo
only
|
| License |
Apache
2.0
|
Commercial |
| Testing type | Security / DAST | Security / DAST |
| Languages / SDKs | Python, Groovy (ZAP scripting API) | N/A (agent-less scanner) |
| Supported platforms | Windows, macOS, Linux, Docker | SaaS (Invicti Cloud), on-premises (Windows) |
| Parallel testing |
Yes
— headless/daemon mode
|
Yes
— concurrent scans
|
| Speed | Moderate |
Fast
— proof-based scanning engine
|
| Key integrations | Jenkins, GitHub Actions, Azure DevOps, Selenium | Jira, GitHub, GitLab, Jenkins, Azure DevOps |
| Learning curve | Moderate | Easy |
| Community / Support |
Very
large — OWASP global community
|
Enterprise-focused; Invicti support |
| Maintained by | OWASP / Software Security Project | Invicti Security |
| First released | 2010 | 2009 |
| Latest version | See website | See website |
| Best suited for | Free DAST scanning in CI/CD pipelines | Enterprise DAST with false-positive elimination |
| Official site | www.zaproxy.org ↗ | www.invicti.com ↗ |
Missing something?
Submit a tool, certification or service provider and we'll add it to the catalogue.