It's critical when you're looking at a new piece of pentesting software to analyze the value it brings to your workflow. It's also critical to ask many of the same questions you'd be asking of an open source, SaaS, or paid app in any other space. Questions should include the following:
- What capabilities does this add to my workflow that I don't already possess?
- How important are these new features? What do I predict their impact being?
- Does this lock me into plans or services or a particular design?
- Does it have a mature CLI?
- How does it perform against known positive cases (in the case of scanners and other detection software)?
- If it's open source, how old is the project? When was the last commit and what's the general frequency of commits? Are there a lot of outstanding issues? Are issues addressed...