#1Automated tools for detecting common web application flaws (e.g., XSS, SQLi).
Kitploit recommended

Http request smuggling vulnerability scanner

Community curated list of nuclei templates for finding "unknown" security vulnerabilities.

SPIP (CMS) Scanner for penetration testing purpose written in Python

Web Vulnerability Scanner using Shell Script

Probe and discover HTTP pathname using brute-force methodology and filtered by specific word or 2 words at once

Ruby client for the Qualys SSL Labs API enabling automated SSL/TLS server assessment, vulnerability detection (e.g., BEAST), and security grade…

A threaded, recursive, web directory brute-force scanner over HTTP/2.

Application scanning component of purpleteam