#1Automated tools for detecting common web application flaws (e.g., XSS, SQLi).
Kitploit recommended

SQL Vulnerability Scanner

A fast DOM based XSS vulnerability scanner with simplicity.

WPScan rewritten in Python + some WPSeku ideas

BruteXSS is a tool written in python simply to find XSS vulnerabilities in web application. This tool was originally developed by Shawar Khan in CLI.…

automated web assets enumeration & scanning [DEPRECATED]

A black box, Ruby powered, Joomla vulnerability scanner

Arachni's Web User Interface.

Http request smuggling vulnerability scanner

Community curated list of nuclei templates for finding "unknown" security vulnerabilities.

SPIP (CMS) Scanner for penetration testing purpose written in Python

Web Vulnerability Scanner using Shell Script

Probe and discover HTTP pathname using brute-force methodology and filtered by specific word or 2 words at once

Ruby client for the Qualys SSL Labs API enabling automated SSL/TLS server assessment, vulnerability detection (e.g., BEAST), and security grade…

A threaded, recursive, web directory brute-force scanner over HTTP/2.

Application scanning component of purpleteam