Take it like a gift

tplmap
tplmap

Server-Side Template Injection and Code Injection Detection and Exploitation Tool.

Scumblr
Scumblr

Perform periodic syncs of data sources and performing analysis on the identified results.

WSDL Wizard
WSDL Wizard

Burp Suite plugin to detect current and discover new WSDL files.

Burp Suite
Burp Suite

The class-leading vulnerability scanning, penetration testing, and web app security platform.

As3nt
As3nt

Another Subdomain ENumeration Tool.

Commix
Commix

Automated All-in-One OS Command Injection Exploitation Tool.

domain_hunter
domain_hunter

Try to find all subdomains, similar-domains and related-domains of an organization.

ScriptSentry
ScriptSentry

ScriptSentry finds misconfigured and dangerous logon scripts.

SQLninja
SQLninja

Exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server.

shhgit
shhgit

Secrets detection for your GitHub, GitLab and Bitbucket repositories.

DalFox
DalFox

Powerful open source XSS scanning tool and parameter analyzer.

vcsmap
vcsmap

Plugin-based tool to scan public version control systems for sensitive information.

SecretMagpie
SecretMagpie

Secret Detection Tool.

hauditor
hauditor

Analyze the security headers returned by a web page and report dangerous configurations.

SearchSploit
SearchSploit

Cli tool for Exploit-DB that also allows you to take a copy of Exploit Database with you.