SSL Server Test : This free online service performs a deep analysis of the configuration of any SSL web server on the public Internet.
Prototype : Easy Ajax and DOM manipulation for dynamic web applications
XSS Filter Evasion Cheat Sheet - OWASP : This article is focused on providing application security testing professionals with a guide to assist in Cross Site Scripting testing.
Zombie.js : Zombie.js is a lightweight framework for testing client-side JavaScript code in a simulated environment. No browser required.
OpenVAS : OpenVAS is a full-featured vulnerability scanner. Its capabilities include unauthenticated testing, authenticated testing, various high level and low ...
A passive reconnaissance tool inside the DOM (experimental)