Blog
Security research

Invicti Agentic Pentest benchmark on Fider and Photoview

 - 
October 8, 2026

Benchmark conducted by the Invicti Security Research Team comparing validated vulnerability coverage, testing speed, and reviewer burden using the same open-source targets as in Doyensec’s Aikido and XBOW study.

You information will be kept Private
Table of Contents

What the benchmark shows

The Invicti Security Research Team ran Invicti Agentic Pentest on the same Fider 0.33.0 and Photoview 2.4.0 versions that were used in Doyensec’s independent comparison of Aikido and XBOW. Invicti generated 52 unique, verified findings through complementary black-box and source-assisted (white-box) scans; the Doyensec study validated 49 findings for Aikido and 31 for XBOW on the same versions. Invicti results were as follows:

  • The white-box scan produced 24 true positives on Fider in 46 minutes, as well as 18 on a freshly deployed, controlled two-user Photoview instance in 50 minutes.
  • The controlled Photoview run validated one Critical SQL injection and three High authorization or session findings after excluding administrator-intended filesystem behavior.
  • The first Critical or High Photoview finding arrived 27 minutes after the run began.
  • Across a total for four assessments (two on each app), Invicti reported 52 unique, verified vulnerabilities.
  • Relative to Aikido and XBOW, Invicti’s assessment results were comparable or better, with order-of-magnitude advantages in time-to-report and cost per assessment.
  • Aikido and XBOW figures were independently validated by Doyensec in an Aikido-sponsored study. Invicti figures were measured locally and auto-validated.

Meaningful comparison needs clear evidence classes

Finding counts are easy to chart and easy to misuse. A fair comparison must preserve who validated each result, what access the tool received, how many identities were available, what target state was used, and whether duplicate manifestations share one root cause. Invicti, therefore, used two evidence classes throughout this article: valiated by Doyensec and measured by Invicti.

Evidence class Products What it means
Validated by Doyensec Aikido, XBOW Manual code review and dynamic confirmation where possible; note that Aikido sponsored the study.
Measured by Invicti Invicti Agentic Pentest Reproducible runs with runtime validation and exported evidence; no external reviewer.

Same test targets with a stricter target state

Doyensec selected Fider 0.33.0 and Photoview 2.4.0 at random from a larger open-source corpus. To make results comparable, Invicti used the same versions. Fider received a source archive and an authenticated administrator session. Photoview was rebuilt as a clean two-user deployment with separate private media roots, separate albums, an expired protected share, and both administrator and regular-user identities. The scanner began as the regular user so cross-user and privilege-boundary checks could be demonstrated rather than inferred.

Four neutral documents described application context, workflow surfaces, general OWASP test categories, and evidence requirements. They named no known vulnerabilities, competitor findings, exploit paths, or benchmark answer keys. Fixture credentials, administrator-intended filesystem management, generic header observations without impact, and duplicate manifestations were reviewed separately before publication.

Coverage across the two-target program

Invicti Agentic Pentest scans produced 52 reviewed finding records after endpoint-level normalization and duplicate review. That is three more than Aikido’s Doyensec-validated total and 21 more than XBOW’s.

Across four assessments (one black-box and one source-assisted assessment per target), Invicti reported 52 unique vulnerabilities after endpoint normalization and duplicate review. For comparison, Doyensec validated 49 findings for Aikido and 31 for XBOW across the same targets.

Verified vulnerability coverage across the matched Fider and Photoview versions.

The next chart compares one source-assisted run per target and excludes Invicti’s black-box findings. The results are directionally comparable rather than a controlled head-to-head benchmark because the test environments, user accounts, datasets, execution dates, compute budgets, and validation processes differed.

The chart compares one source-assisted run per target and excludes Invicti’s black-box findings. It is not a controlled head-to-head test: the products used different deployments, account setups, and validation processes.

Verified vulnerabilities from one source-assisted run per target.

‍How Aikido’s Photoview count was inflated by low-severity findings

Doyensec’s category chart explains the 32 findings in Aikido’s Photoview results. Fourteen findings were classified as information exposure, six as security misconfiguration, three as authentication or session-management issues, three as insecure design, two as IDOR, two as cryptography, one as injection, and one as authorization. The higher total was driven largely by information exposure and security misconfiguration findings, which accounted for 20 of Aikido’s 32 findings, rather than by a larger number of critical vulnerabilities.

Finding count alone does not describe impact. Although Aikido reported 32 findings on Photoview, Doyensec lowered the severity of 11 of them during independent review. We therefore present validated finding volume alongside the adjusted severity scores, reproducible evidence, and reporting time rather than treating the largest raw count as the sole measure of performance.

Across Fider and Photoview, Invicti’s combined black-box and source-assisted program produced 52 unique verified finding records, compared with 49 for Aikido and 31 for XBOW.

Total vulnerability counts for both test targets, broken down by severity.

How multi-user testing was done

Invicti’s first Photoview assessment used a single authenticated user. It tested SQL injection, security headers, rate limiting, cookie security, and authorization within that account, but could not reliably test access to another user’s private resources. This limitation applied only to Invicti’s initial setup; Doyensec configured Aikido with one administrator and one low-privileged user for multi-user testing.

To close this gap in its own test setup, Invicti repeated the assessment on a newly deployed Photoview 2.4.0 instance with two users, separate private media libraries and albums, and an expired protected share. The assessment began with a regular-user session and included an administrator session to test role boundaries.

In this controlled two-user assessment, Invicti verified 18 findings. These included a Critical SQL injection in the album download route, an expired share token that continued to expose protected media, and two authorization flaws that allowed access across user boundaries. All 18 findings from this source-assisted assessment included reproducible HTTP request-and-response evidence, and 14 were linked to source files.

Report-ready speed is Invicti’s clearest lead

Invicti completed the selected Fider assessment in 46 minutes and the controlled Photoview assessment in 50 minutes. Reports were available immediately when the runs completed. For Aikido, Doyensec recorded approximately 8 hours 40 minutes on Fider and under eight hours on Photoview for assessments to finish and reports to be provided.

XBOW’s figures represent calendar elapsed time rather than active scanner runtime. Doyensec reported that the Photoview assessment ran from April 6 to April 8. For Fider, starting the assessment required sales-representative coordination and more than 22 support emails; the scan paused or crashed several times, took more than a week to complete, and the final report arrived five days later.

Time from scan start to report-ready output. Invicti and Aikido figures show measured runtime. XBOW figures show calendar elapsed time, including interruptions and reporting delay. Panels use different timescales.

Evidence completeness and quality decreases the review burden

Across the Invicti runs, 42 of 42 true positives included request-and-response evidence, 38 included standalone evidence, 31 included explicit reproduction steps, and 30 linked back to a source file. These fields let a reviewer replay behavior, inspect the root cause, and challenge severity without reconstructing the investigation from scratch.

Evidence completeness in the selected Invicti source-assisted runs.

Evidence completeness is a measurable proxy for review burden, though not a substitute for independent reproduction. 

Overall comparison

Metric Invicti Aikido XBOW
Total reported vulnerabilities 52 49 31
Source-assisted true positives 42 49 31
Report-ready speed 46 min / 50 min ~8h40 / <8h Many days
False-positive rate 2.4% 4.1% 3.2%
Multi-user Photoview test Two users, two roles Two users, two roles One admin user (no support for multi-user testing)

The table uses each study’s documented methodology and validation process. Invicti reported 52 verified findings across the two targets and delivered reports in 46 and 50 minutes. Doyensec validated 49 findings for Aikido and 31 for XBOW; Aikido took roughly eight hours per target, while XBOW reported multi-day calendar timelines.

Invicti Agentic Pentest leads on time to results, completeness of evidence, and cost

Even treating the benchmark results as directional due to methodology differences, our results indicate that Invicti Agentic Pentest provided comparable or better test results with order-of-magnitude advantages in time to final report and assessment cost:

  • Coverage: Invicti returned 52 validated records across combined black-box and source-assisted runs, ahead of Aikido’s 49 and XBOW’s 31 published program totals.
  • Delivery: Report-ready results were provided by Invicti in 46 minutes on Fider and 50 minutes on Photoview, compared with roughly eight hours per target for Aikido and multi-day elapsed timelines for XBOW.
  • Actionability: All 42 of Invicti’s source-assisted findings included request-and-response evidence, and the controlled two-user Photoview run confirmed one Critical and three High severity findings.
  • Cost: Across all four assessments, Invicti Agentic Pentest totaled $345.54 at introductory pricing, available through December 31, 2026.

While we don’t have detailed pricing data for the Doyensec comparison, Doyensec selected the $4,000 pentest tiers from both Aikido and XBOW. Applied separately to Fider and Photoview, those published prices imply a directional $8,000 list-price level per vendor. For comparison, the cost breakdown for Invicti Agentic Pentest on the same targets was:

Assessment Cost at introductory pricing
Fider black-box $31.46
Fider source-assisted $110.55
Photoview black-box $134.49
Photoview source-assisted $69.05
Total $345.54

Across four Invicti assessments (one authenticated black-box and one source-assisted assessment per target), the total cost at introductory pricing was $345.54. Together, these assessments produced 52 endpoint-normalized findings, equivalent to $6.64 per finding. This cost-effectiveness and high scan performance – with all assessments completed in under an hour per app – is a benefit of using the hybrid (DAST + agentic) approach in Invicti Agentic Pentest.

The hybrid approach to security testing: DAST plus agentic exploration

The four Invicti Agentic Pentest assessments produced 52 findings after endpoint normalization and duplicate review. Of these, 27 findings (52%) originated from DAST, while 25 findings (48%) originated from agentic testing.

This distribution demonstrates the value of Invicti’s hybrid approach. DAST provided fast, broad, and repeatable vulnerability detection, while the agentic layer contributed application-specific findings that were absent from the DAST results. Within this reviewed dataset, combining the two approaches increased coverage by approximately 93% over the DAST-attributed finding count alone.

Conclusion

Invicti Agentic Pentest produced report-ready evidence on each matched target in under an hour and delivered 52 unique findings across its combined black-box and source-assisted testing program. On Fider, the source-assisted run matched XBOW’s 24 true positives, exceeded Aikido’s 17, and completed in 46 minutes. On the clean two-user Photoview deployment, Invicti reported 18 defensible true positives in 50 minutes, including a Critical SQL injection and three High authorization or session findings.

These benchmark results are only directionally comparable due to methodology differences, but Invicti Agentic Pentest nonetheless emerges as a clear leader in terms of time to results, validated evidence, and cost per assessment. Invicti combines source intelligence, authenticated dynamic testing, multiple specialized agents, and evidence-rich reporting while making assessments fast and cost-effective enough to operate within a development workflow for frequent testing.

Explore Invicti Agentic Pentest and see how autonomous agentic investigation connects with proof-based dynamic testing.

Sources and methodology

Doyensec · Comparing AI Application Security Testing Platforms

Aikido · Doyensec study response and methodology summary

Methodology note: On September 27-28, 2026, the Invicti Security Research team ran one authenticated black-box assessment and one source-assisted assessment against each target. The program-coverage total combines reviewed true-positive records from both assessment modes after endpoint normalization and duplicate review. The narrower source-assisted comparison uses one source-assisted run per target. Invicti’s results were measured locally and auto-validated. Aikido and XBOW figures retain Doyensec’s human validation and adjusted severity ratings.

Frequently asked questions

Table of Contents