Problem:
It is awkward to introduce and talk all about a tool (Ex4) that they’re not going to be able to actually use until later (Ex5). Both exercises are pretty short, especially if the other suggestion of moving Ex4 pt2 to Ex2 is taken. Additionally, I don't like OWASP here as its discussion adds little value and it doesn’t even work in the pipeline.
Proposed solution:
Crunch em together. Cut OWASP out (or fix).