Comparison
Acunetix vs. HostedScan
Acunetix is a web vulnerability scanner for smaller AppSec teams, sold under the Invicti brand today. HostedScan scans web apps with OWASP ZAP and adds the network, TLS, and port coverage Acunetix leaves to other tools.
Try the Premium plan free for 14 days. No credit card required.

At a glance
HostedScan
Acunetix
Starting price
$468 / year, 5 targets
Quote
Scanners
OpenVAS, Nuclei, ZAP, Nmap, SSLyze; Nessus on Professional
Invicti DAST scanner
Internal scanning
Included from Premium
Web apps only, via agent
Trial
14 days, no card
Demo through sales
Differences
What sets HostedScan apart from Acunetix
Infrastructure included
Greenbone OpenVAS, Nuclei, Nmap, and SSLyze scan the servers, networks, and certificates behind the application. Acunetix stops at the web layer.
Per target, published
HostedScan starts at $39 per month billed annually for five targets. Acunetix is quoted with no public price, historically in bundles of 5, 10, or 20 targets.
No install, no license file
Hosted scanners start from the browser. Acunetix on-premises is installed software you maintain on Windows or Linux; Acunetix Premium Online and Acunetix 360 are cloud.
Nessus on Professional
Tenable Nessus for external, internal, and agent scanning on the Professional plan, alongside the open-source scanners.
Inside the product
What you get on day one
Web findings from ZAP next to host findings from Nuclei and SSLyze, so the fix list covers the whole stack behind the application.

Which one fits
Choose HostedScan if
- You want web apps and the infrastructure behind them in one product.
- You have fewer than five targets, which is the smallest Acunetix bundle.
- You want unlimited scans at a published per-target price.
- You want Tenable Nessus available when an auditor asks.
Choose Acunetix if
- You need proof-based DAST that confirms exploitability.
- You pentest web apps and want a single-instance scanner you control.
- You need IAST sensors alongside DAST.
- You already license Invicti and want the same scanner.
Capability matrix
Feature by feature
Differences come first. A half circle marks a limited capability, and its note names the limit. Notes about Acunetix link to their source.
Feature

Scanners
Proof-based exploit confirmation
No exploitation tools. Findings ship with evidence and remediation steps.
Confirms many findings by safe exploitation.
SourceNetwork CVE scanning
Greenbone OpenVAS and Nuclei CVE scanning plus Nmap TCP and UDP port scans on every plan, and Tenable Nessus on Professional.
Network scanning through an OpenVAS integration on the on-premises install, configured separately from the web scanner.
SourceDedicated TLS and port scanners
SSLyze certificate, protocol, and cipher checks on every plan.
TLS checks within the web scan only.
SourceTenable Nessus
Nessus cloud scanning, Nessus scanners for internal networks, and Nessus Agents, all on Professional.
No Nessus.
SourceIAST sensor
No IAST sensor. Scanning is black-box from outside the application.
AcuSensor IAST for supported languages.
SourceCoverage
Internal network scanning
An internal scanner runs inside your network on Premium. Nessus scanners and Nessus Agents on Professional.
SourceInternal agents reach internal web apps; network scanning depends on the OpenVAS integration.
SourceReporting and risk management
Health score over time
A health score per target and per account, trended over time.
No target or account score.
SourceWhite-label reports
White-label PDF reports with your branding on Professional.
No white-label option published.
Import results from other scanners
Connect GitHub Dependabot and Snyk, and upload Nmap, OpenVAS, or ZAP results through the API.
SourceImports Burp Suite and other tool output to seed crawls; no import of vulnerability results.
SourceIntegrations and API
REST API and webhooks
REST API and webhooks on Premium and above, no add-on fee.
SourceREST API documented for Acunetix Premium and Acunetix 360.
SourceSAML SSO
SAML SSO, access controls, and workspaces on Professional.
SourceHistorically Acunetix 360 only; the Invicti Web + API plan Acunetix now sells under lists SSO.
SourceLicensing, pricing, and support
Published price list
Published plans from $39 per month billed annually. Per-target rates on the pricing page.
Quote-based. Historically quoted in bundles of 5, 10, or 20 targets; current pricing is by quote.
SourceStart without a sales call
Sign up, add a target, scan. Sales is optional at any size.
Demo request through sales.
SourceTrial without a card
14-day Premium trial, no credit card.
Proof-of-concept licenses arranged through sales.
SourceMSP and reseller program
MSP program with workspaces, white-label reports, and reseller pricing.
No published MSP program or reseller pricing for Acunetix.
How the two products run
External scanning
Hosted scanners. Add a URL and scan.
Acunetix on-premises installs on Windows or Linux; Acunetix Premium Online and Acunetix 360 are cloud.
Internal scanning
The internal scanner on Premium reaches internal apps and hosts.
Internal agents for web apps behind the firewall.
Scanner upkeep
HostedScan maintains the scanners and syncs the Greenbone feed daily.
Acunetix updates; on-premises installs apply them.
Where data lives
HostedScan cloud with export and API.
On the install host, or Acunetix cloud.
What your team does weekly
Triage one list across apps and infrastructure.
Run and tune web scans, triage findings.
Pricing example
5 web applications with authenticated scanning, plus the hosts behind them
One scenario priced on both products. HostedScan totals come from the published plan and per-target rates. Acunetix figures were checked in September 2026 and link to the source.
HostedScan Premium
$1,308 / year
$109 per month billed annually. 5 targets included.
Premium includes authenticated ZAP scans, API scanning, OpenVAS and Nuclei for the hosts, Nmap, SSLyze, the internal scanner, and the API.
Acunetix
Quote
Historically quoted in bundles of 5, 10, or 20 targets; current pricing is by quote under the Invicti Web + API plan.
From our customers
What our customers say
“HostedScan is our trusted partner for OWASP Top 10 testing and proactive security. Their platform is powerful, but it’s their dedicated support team that truly sets them apart.”
Victor Beitner • Founder

“HostedScan is a unified platform offering multiple scanning tools, and it's reasonably priced compared to leading scanners”

“I found your platform to be best-in-class for automated vulnerability assessment and reporting. I've already started suggesting it to other software teams.”
Orane Cole • Founder & CEO
Quick Answers
Frequently asked questions
Our knowledge base contains answers to technical questions, and you can always contact us for more details on our plans, pricing, or any questions.
Speed and power,
without the complexity
The world's leading vulnerability scanners, all in one platform.